This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible malware/trojan

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

My anti-virus software flagged up a trojan a few days ago (Win32:Trojan-gen). I've run Ccleaner, Malwarebytes' Anti-Malware and SUPERAntiSpyware Free Edition. A boot scan using Avast shows my system as clean but I'm still a little worried.

I've installed and run Hijackthis, and attach the log file. I'd really appreciate any feedback.

Many thanks,

Simon


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:09:19, on 18/11/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe
C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Xerox One Touch\OneTouchMon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:50370
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: XBTP01650 - {9D0A3CDB-A952-4767-A6B3-4FB176095619} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: XBTB01650 - {E3B939DA-B105-49ee-9D75-0C1875B7961B} - (no file)
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [C:\WINDOWS\system32\V0260Ext.ax] C:\WINDOWS\system32\RegSvr32.exe /s C:\WINDOWS\system32\V0260Ext.ax
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OneTouch Monitor] "C:\Program Files\Xerox One Touch\OneTouchMon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…t;ver=10.0.1152
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - http://www.warwick.ac.uk/newwebcam/AxisCamControl.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Emma Device Management (EmmaDevMgmtSvc) - Sony Ericsson Mobile Communications - C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe
O23 - Service: Emma Update Management (EmmaUpdMgmtSvc) - Sony Ericsson Mobile Communications - C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe

–
End of file - 13749 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post




Please do the following.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.







[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.



In your next reply please post the following.
  • Both OTL logs
  • GMER log
Hello mowman, Thanks for your reply. We're away for the coming weekend so I'll post the results on Sunday evening (UK time). Hope this is ok. Thanks again, Simon
Hi mowman,

Contents of OTL file:

OTL logfile created on: 20/11/2010 01:29:25 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Simon Hibbott\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 360.00 Mb Available Physical Memory | 35.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 146.21 Gb Total Space | 90.00 Gb Free Space | 61.56% Space Free | Partition Type: NTFS

Computer Name: DIMENSION | User Name: Simon Hibbott | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Simon Hibbott\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe (Sony Ericsson Mobile Communications)
PRC - C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe (Sony Ericsson Mobile Communications)
PRC - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
PRC - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Kontiki\KService.exe ()
PRC - C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
PRC - C:\Program Files\Xerox One Touch\OneTouchMon.exe (Visioneer Inc)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Simon Hibbott\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll (Trusteer Ltd.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\ime\sptip.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)
MOD - C:\WINDOWS\ime\spgrmr.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (EmmaDevMgmtSvc) – C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe (Sony Ericsson Mobile Communications)
SRV - (EmmaUpdMgmtSvc) – C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe (Sony Ericsson Mobile Communications)
SRV - (OMSI download service) – C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe ()
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (KService) – C:\Program Files\Kontiki\KService.exe ()
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()


========== Driver Services (SafeList) ==========

DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (RapportCerberus_19917) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys (Trusteer Ltd.)
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\WINDOWS\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (RapportBuka) – C:\WINDOWS\system32\drivers\RapportBuka.sys (Trusteer Ltd.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ggsemc) – C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (s1018mdm) – C:\WINDOWS\system32\drivers\s1018mdm.sys (MCCI Corporation)
DRV - (s1018unic) Sony Ericsson Device 1018 USB Ethernet Emulation (WDM) – C:\WINDOWS\system32\drivers\s1018unic.sys (MCCI Corporation)
DRV - (s1018mgmt) Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s1018mgmt.sys (MCCI Corporation)
DRV - (s1018obex) – C:\WINDOWS\system32\drivers\s1018obex.sys (MCCI Corporation)
DRV - (s1018bus) Sony Ericsson Device 1018 driver (WDM) – C:\WINDOWS\system32\drivers\s1018bus.sys (MCCI Corporation)
DRV - (s1018nd5) Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS) – C:\WINDOWS\system32\drivers\s1018nd5.sys (MCCI Corporation)
DRV - (s1018mdfl) – C:\WINDOWS\system32\drivers\s1018mdfl.sys (MCCI Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (V0260VID) – C:\WINDOWS\system32\drivers\V0260Vid.sys (Creative Technology Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (k750obex) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (k750mgmt) – C:\WINDOWS\system32\drivers\k750mgmt.sys (MCCI)
DRV - (k750mdm) – C:\WINDOWS\system32\drivers\k750mdm.sys (MCCI)
DRV - (k750mdfl) – C:\WINDOWS\system32\drivers\k750mdfl.sys (MCCI)
DRV - (k750bus) Sony Ericsson 750 driver (WDM) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (CamAv) – C:\WINDOWS\system32\drivers\CamAv.sys (Samsung electronics, Inc)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (atapi) – C:\WINDOWS\system32\DRIVERS\atapi.sys ()
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (a347bus) – C:\WINDOWS\system32\DRIVERS\a347bus.sys ( )
DRV - (a347scsi) – C:\WINDOWS\System32\Drivers\a347scsi.sys ( )
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (Ca533av) – C:\WINDOWS\system32\drivers\Ca533av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk533.sys (USB BULK)
DRV - (DCamUSBSQTECH) Dual-Mode DSC(2770) – C:\WINDOWS\system32\drivers\SQCaptur.sys (Service & Quality Technology.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google UK"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.bbc.co.uk/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {d57c9ff1-6389-48fc-b770-f78bd89b6e8a}:1.33
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50370
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 19:03:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/17 09:25:47 | 000,000,000 | —D | M]

[2008/12/07 18:26:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Extensions
[2010/11/19 10:07:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\extensions
[2010/07/12 22:17:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/18 10:07:40 | 000,000,000 | —D | M] (SeoQuake) – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2009/07/01 13:47:41 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/01/20 09:21:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\extensions\{d57c9ff1-6389-48fc-b770-f78bd89b6e8a}
[2010/02/23 19:51:07 | 000,003,449 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\searchplugins\google-uk.xml
[2010/11/19 10:07:34 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2004/11/13 03:36:20 | 000,005,120 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
[2010/10/15 23:12:10 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/10/15 23:12:10 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/10/15 23:12:11 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/10/15 23:12:11 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2005/11/28 18:38:32 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {9D0A3CDB-A952-4767-A6B3-4FB176095619} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (no name) - {E3B939DA-B105-49ee-9D75-0C1875B7961B} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [C:\WINDOWS\system32\V0260Ext.ax] C:\WINDOWS\system32\V0260Ext.ax (Creative Technology Ltd.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\scansoft\paperport\IndexSearch.exe ()
O4 - HKLM..\Run: [OneTouch Monitor] C:\Program Files\Xerox One Touch\OneTouchMon.exe (Visioneer Inc)
O4 - HKLM..\Run: [RegisterDropHandler] C:\Program Files\TextBridge Pro 9.0\Bin\RegisterDropHandler.exe ()
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
O4 - HKCU..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunServices: [RegisterDropHandler] C:\Program Files\TextBridge Pro 9.0\Bin\RegisterDropHandler.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_19.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Reg Error: Key error.)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?LinkId=39204&clcid;=0x409 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} http://www.cult3d.com/download/cult.cab (Cult3D ActiveX Player)
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} https://moneymanager.egg.com/Pinsafe/accounttracking.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab (Reg Error: Key error.)
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Yahoo! Audio UI1)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Reg Error: Key error.)
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} http://chat.yahoo.com/cab/yuplapp.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://www.warwick.ac.uk/newwebcam/AxisCamControl.ocx (Reg Error: Key error.)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.2
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/10/19 15:52:10 | 000,000,398 | —- | M] () - C:\AUTOEXEC.UP – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.SMP4 - C:\WINDOWS\System32\mcs_vfw.dll ()
Drivers32: VIDC.SP54 - SP5X_32.DLL File not found
Drivers32: VIDC.SP55 - SP5X_32.DLL File not found
Drivers32: VIDC.SP56 - SP5X_32.DLL File not found
Drivers32: VIDC.SP57 - SP5X_32.DLL File not found
Drivers32: VIDC.SP58 - SP5X_32.DLL File not found
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2010/11/20 01:25:24 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Simon Hibbott\Desktop\OTL.exe
[2010/11/18 10:09:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\My Documents\Hijackthis
[2010/11/18 10:05:38 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/11/17 13:09:09 | 000,000,000 | —D | C] – C:\Program Files\CamStudio
[2010/11/17 10:01:32 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/11/17 10:01:09 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/11/17 03:24:46 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Simon Hibbott\Recent
[2010/11/11 16:09:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\Application Data\SUPERAntiSpyware.com
[2010/11/11 16:09:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/11/11 16:09:32 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/11/10 18:20:36 | 000,017,744 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/11/10 18:20:35 | 000,165,584 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2010/11/10 18:20:34 | 000,023,376 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/11/10 18:20:32 | 000,046,672 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/11/10 18:20:29 | 000,100,176 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/11/10 18:20:29 | 000,094,544 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2010/11/10 18:20:28 | 000,028,880 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/11/10 18:20:03 | 000,167,592 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2010/11/10 18:20:03 | 000,038,848 | —- | C] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2010/11/10 12:46:15 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/11/10 12:46:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/11/10 12:15:36 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/11/09 19:17:08 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/09 19:17:04 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/09 10:19:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\My Documents\CCleaner
[2010/11/09 09:57:28 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/11/09 09:56:46 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie7
[2010/11/09 09:55:53 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\GARMIN
[2010/11/08 20:55:25 | 000,000,000 | —D | C] – C:\WINDOWS\ie8(2)
[2010/11/08 16:55:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\Application Data\ElevatedDiagnostics
[2010/11/08 16:53:19 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2010/11/08 13:41:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\Application Data\Malwarebytes
[2010/11/08 13:41:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/11/08 13:41:20 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/05 10:51:13 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/11/05 10:50:22 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Trusteer
[2010/11/05 10:46:04 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2010/11/01 19:25:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2010/10/29 13:22:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\My Documents\5BX
[2010/10/28 09:59:02 | 000,000,000 | —D | C] – C:\Program Files\Opera Mobile
[2010/10/21 13:50:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\AVG Security Toolbar
[2010/10/21 10:22:59 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2010/10/21 10:21:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/10/21 10:15:24 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/06/12 18:02:04 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Simon Hibbott\Application Data\pcouffin.sys
[2009/12/18 15:56:42 | 000,148,736 | —- | C] (Avanquest Software) – C:\Documents and Settings\All Users\Application Data\hpe99.dll
[2005/09/27 11:57:26 | 000,160,640 | —- | C] ( ) – C:\WINDOWS\System32\drivers\a347bus.sys
[2005/09/27 11:57:26 | 000,005,248 | —- | C] ( ) – C:\WINDOWS\System32\drivers\a347scsi.sys
[30 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[1276 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/20 01:27:11 | 1840,661,504 | —- | M] () – C:\WINDOWS\outlook.pst
[2010/11/20 01:25:25 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Simon Hibbott\Desktop\OTL.exe
[2010/11/20 00:57:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/19 18:57:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/19 09:57:00 | 000,106,496 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Desktop\Health.xls
[2010/11/19 09:11:06 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/19 09:08:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/19 09:08:00 | 1071,697,920 | -HS- | M] () – C:\hiberfil.sys
[2010/11/18 10:05:39 | 000,002,000 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Desktop\HiJackThis.lnk
[2010/11/18 09:43:38 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/11/17 15:04:14 | 000,040,960 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/17 13:09:14 | 000,000,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CamStudio.lnk
[2010/11/17 10:02:17 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/11/17 09:38:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/11/17 09:25:48 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/11/11 16:09:36 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/11/11 15:19:29 | 000,000,000 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\prvlcl.dat
[2010/11/11 11:16:28 | 000,000,792 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2010/11/10 18:20:37 | 000,001,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/11/10 18:20:30 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/11/10 12:22:39 | 000,574,048 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/10 12:15:38 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2010/11/09 19:18:31 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/05 17:09:11 | 000,002,205 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/11/05 15:22:02 | 000,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2010/10/31 09:31:00 | 000,450,218 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/10/31 09:31:00 | 000,074,842 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/10/28 21:54:49 | 000,000,624 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/10/28 21:54:49 | 000,000,606 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/10/28 09:59:08 | 000,001,575 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera Widgets Mobile Emulator.lnk
[2010/10/28 09:59:08 | 000,000,665 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera Mobile.lnk
[1276 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/18 10:05:39 | 000,002,000 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Desktop\HiJackThis.lnk
[2010/11/17 13:09:14 | 000,000,689 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CamStudio.lnk
[2010/11/17 10:02:17 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/11/11 20:30:14 | 1071,697,920 | -HS- | C] () – C:\hiberfil.sys
[2010/11/11 16:09:36 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/11/10 18:20:37 | 000,001,700 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/11/10 12:15:38 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2010/11/09 19:17:11 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/28 09:59:08 | 000,001,575 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Opera Widgets Mobile Emulator.lnk
[2010/10/28 09:59:08 | 000,000,665 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Opera Mobile.lnk
[2010/06/12 18:02:17 | 000,000,034 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Application Data\pcouffin.log
[2010/06/12 18:02:04 | 000,087,608 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Application Data\inst.exe
[2010/06/12 18:02:04 | 000,007,887 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Application Data\pcouffin.cat
[2010/06/12 18:02:04 | 000,001,144 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Application Data\pcouffin.inf
[2009/06/24 21:59:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\prvlcl.dat
[2008/06/04 11:06:40 | 000,017,403 | —- | C] () – C:\WINDOWS\wwdslcfg.ini
[2007/11/20 11:48:55 | 000,000,136 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\fusioncache.dat
[2007/07/03 10:18:21 | 000,021,944 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft Excel.ADR
[2007/06/09 09:43:26 | 000,536,576 | R— | C] () – C:\WINDOWS\System32\mcs_core.dll
[2007/06/09 09:43:26 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\mcs_vfw.dll
[2007/06/09 09:43:16 | 000,147,456 | R— | C] () – C:\WINDOWS\mcs_vfw.dll
[2007/06/09 09:43:15 | 000,536,576 | R— | C] () – C:\WINDOWS\mcs_core.dll
[2007/06/09 09:43:12 | 000,057,344 | R— | C] () – C:\WINDOWS\HAJEInstall.dll
[2006/06/20 16:19:27 | 000,001,703 | R— | C] () – C:\WINDOWS\CA533A.INI
[2006/04/18 15:09:13 | 000,000,457 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2006/04/18 15:01:04 | 000,011,934 | —- | C] () – C:\WINDOWS\System32\Pixpnr.dll
[2006/04/18 15:01:03 | 000,012,126 | —- | C] () – C:\WINDOWS\System32\Pixpcz.dll
[2006/04/18 14:54:01 | 000,000,752 | —- | C] () – C:\WINDOWS\maxlink.ini
[2006/04/18 14:52:47 | 000,000,663 | —- | C] () – C:\WINDOWS\fe.INI
[2006/04/14 10:09:52 | 000,002,917 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/21 10:39:39 | 000,000,414 | —- | C] () – C:\WINDOWS\dellstat.ini
[2006/02/04 15:26:04 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2006/01/13 13:16:47 | 000,000,044 | —- | C] () – C:\WINDOWS\liveup.ini
[2005/12/27 17:34:35 | 000,001,860 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/11/21 20:31:13 | 000,000,333 | —- | C] () – C:\WINDOWS\lexstat.ini
[2005/11/16 18:59:41 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2005/09/29 16:19:46 | 000,007,912 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2005/09/27 13:12:55 | 000,777,728 | —- | C] () – C:\WINDOWS\System32\SSLSVC.DLL
[2005/09/27 13:12:54 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\lang_cfml.dll
[2005/09/27 13:12:54 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2005/09/27 13:12:54 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\cfmsg.dll
[2005/09/27 13:12:54 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2005/09/27 13:12:53 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\xml_datagrove.dll
[2005/09/14 18:03:16 | 000,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/06/24 09:10:15 | 000,040,960 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/03/20 08:59:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/03/20 08:58:16 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/03/20 08:34:46 | 000,000,283 | —- | C] () – C:\WINDOWS\System32\dlbcplc.ini
[2005/03/20 08:33:14 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2005/03/20 08:32:48 | 000,000,375 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/02/11 17:38:14 | 000,749,568 | —- | C] () – C:\WINDOWS\System32\SWFGen.dll
[2004/09/15 22:03:14 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 13:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:52 | 000,004,346 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 12:51:23 | 000,022,040 | —- | C] () – C:\WINDOWS\System32\_004627_.tmp.dll
[2004/08/10 12:51:10 | 000,249,270 | —- | C] () – C:\WINDOWS\System32\_004659_.tmp.dll
[2004/08/03 22:59:44 | 000,095,360 | —- | C] () – C:\WINDOWS\System32\drivers\atapi.sys
[2003/08/18 14:46:38 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\LXBKLCNP.DLL
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/11/13 19:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxbkvs.dll
[2002/09/13 15:40:06 | 000,000,266 | —- | C] () – C:\WINDOWS\System32\lxbkcoin.ini
[2002/08/09 12:15:16 | 000,101,376 | —- | C] () – C:\WINDOWS\System32\Welsof32.dll
[2002/01/08 15:57:34 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\Jpeg32.dll
[1997/07/10 23:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/10 23:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/10 23:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL

========== LOP Check ==========

[2010/11/10 12:46:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/11/11 15:45:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/18 14:21:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/12/18 15:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/10/18 14:37:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2007/11/15 22:28:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Documents
[2008/06/09 10:27:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2010/11/20 01:33:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2010/10/18 14:17:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2006/04/18 14:59:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/10/20 16:47:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/01/18 09:19:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2007/05/16 18:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/11/03 13:16:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\xml_param
[2008/06/09 15:11:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ZoneFiveSoftware
[2010/10/21 10:22:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2005/09/24 19:15:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Alien Skin
[2006/06/06 11:23:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Allume Systems
[2008/12/08 16:32:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Any Video Converter Professional
[2010/10/20 15:34:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\AVG
[2010/10/18 14:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\AVG10
[2010/11/10 12:17:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\BitTorrent
[2008/11/09 12:13:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Charles
[2010/11/08 16:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\ElevatedDiagnostics
[2010/04/21 19:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\FUJIFILM
[2008/06/09 10:27:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\GARMIN
[2010/11/08 13:24:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\ImgBurn
[2010/01/14 11:44:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\JGsoft
[2005/08/03 22:40:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Leadertech
[2008/06/09 12:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\MotionBased
[2008/02/23 13:50:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\ObjectiveIELTSIntermediate
[2008/12/18 21:21:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\OpenOffice.org
[2007/02/07 13:57:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Opera
[2007/05/11 12:00:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\SecondLife
[2006/07/19 13:27:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\slooz.com
[2009/12/22 16:23:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Sony
[2009/12/22 16:15:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Sony Setup
[2010/06/02 09:34:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Spotify
[2005/04/15 17:07:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Template
[2010/01/18 09:20:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Trusteer
[2007/05/16 18:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Viewpoint
[2010/06/12 18:02:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Vso
[2005/03/22 18:23:32 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2004/10/19 15:52:10 | 000,000,398 | —- | M] () – C:\AUTOEXEC.UP
[2009/11/29 13:17:14 | 000,000,002 | —- | M] () – C:\AWPMENU.DAT
[2010/11/18 09:43:38 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2004/10/19 15:52:18 | 000,000,077 | —- | M] () – C:\CONFIG.UP
[2004/10/19 15:52:20 | 000,000,085 | —- | M] () – C:\COPYUP.BAT
[2005/03/20 08:37:56 | 000,003,856 | RH– | M] () – C:\dell.sdr
[2004/10/19 15:52:36 | 000,002,613 | —- | M] () – C:\Dellboot.exe
[2004/10/19 15:52:26 | 000,000,799 | —- | M] () – C:\DIR.LST
[2010/11/05 16:13:49 | 000,015,094 | —- | M] () – C:\EyeCandyLog.txt
[2005/10/14 18:13:18 | 000,005,121 | -H– | M] () – C:\ffastun.ffa
[2005/10/14 18:13:14 | 006,430,720 | -H– | M] () – C:\ffastun.ffl
[2005/10/14 18:13:18 | 005,390,336 | -H– | M] () – C:\ffastun.ffo
[2005/10/14 18:13:14 | 002,576,384 | -H– | M] () – C:\ffastun0.ffx
[2010/11/19 09:08:00 | 1071,697,920 | -HS- | M] () – C:\hiberfil.sys
[2005/04/15 15:36:49 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2005/03/20 08:55:33 | 000,000,812 | -H– | M] () – C:\IPH.PH
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/11/21 09:49:49 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/19 09:07:59 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2005/10/14 08:40:55 | 000,000,021 | —- | M] () – C:\qpmd8377.bin
[2008/02/05 08:00:47 | 000,001,529 | —- | M] () – C:\SMax.log
[2005/03/20 08:43:37 | 000,001,526 | —- | M] () – C:\SMax.log.bak
[2005/10/07 22:30:19 | 000,002,136 | —- | M] () – C:\Websync_debug.log
[2010/10/11 17:11:32 | 001,491,464 | —- | M] () – C:\wialog.txt
[2008/06/16 17:50:22 | 000,000,158 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[30 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 13:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
[30 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/07/29 13:27:40 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBKPP5C.DLL
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2002/01/08 14:51:00 | 000,047,616 | —- | M] (Black Ice Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ppbiPr.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/07 16:12:17 | 000,038,848 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[1999/08/17 11:10:12 | 000,028,672 | —- | M] (Ulead Systems, Inc.) – C:\WINDOWS\Photo Express 3.scr
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[1997/07/10 23:00:00 | 000,000,002 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft\ArtGalry.cag
[2010/11/04 21:01:15 | 000,001,635 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft\stor.cfg

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 12:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 12:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 12:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/11/21 09:58:35 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/03/22 18:24:43 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 13:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/11/20 01:25:25 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Simon Hibbott\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2004/08/04 05:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >
[2002/08/23 14:06:10 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Driver Cache\Usbscan.sys

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2005/03/22 18:24:42 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Simon Hibbott\Favorites\Desktop.ini
[2005/09/15 05:45:25 | 000,000,474 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Favorites\My Documents.lnk

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/11/08 21:26:53 | 000,000,067 | -HS- | M] () – C:\Documents and Settings\Simon Hibbott\Cookies\desktop.ini
[2010/11/20 01:01:18 | 002,736,128 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-10 12:06:52

========== Alternate Data Streams ==========

@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:661DFA1C

< End of report >
Hi mowman,

Contents of OTL extras file:

OTL Extras logfile created on: 20/11/2010 01:29:25 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Simon Hibbott\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 360.00 Mb Available Physical Memory | 35.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 146.21 Gb Total Space | 90.00 Gb Free Space | 61.56% Space Free | Partition Type: NTFS

Computer Name: DIMENSION | User Name: Simon Hibbott | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
jsfile – "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Documents and Settings\Simon Hibbott\My Documents\My Downloads\WS FTP\WS_FTP\WS_FTP95.exe" = C:\Documents and Settings\Simon Hibbott\My Documents\My Downloads\WS FTP\WS_FTP\WS_FTP95.exe:*:Enabled:WS_FTP 95 – (Ipswitch, Inc. 81 Hartwell Ave. Lexington, MA)
"C:\Program Files\Yahoo!\Messenger\ypager.exe" = C:\Program Files\Yahoo!\Messenger\ypager.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"C:\Documents and Settings\Simon Hibbott\Local Settings\Temp\WZS44.tmp\AswApp.exe" = C:\Documents and Settings\Simon Hibbott\Local Settings\Temp\WZS44.tmp\AswApp.exe:*:Enabled:AswApp – File not found
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\JSAS\http_root\usr\local\Apache2\bin\Apache.exe" = C:\Program Files\JSAS\http_root\usr\local\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server – File not found
"C:\Program Files\JSAS\http_root\usr\local\mysql\bin\mysqld-opt.exe" = C:\Program Files\JSAS\http_root\usr\local\mysql\bin\mysqld-opt.exe:*:Enabled:mysqld-opt – File not found
"C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" = C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe:*:Enabled:Dreamweaver MX 2004 – (Macromedia, Inc.)
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Program Files\BlogTorrent\btdownloadgui.exe" = C:\Program Files\BlogTorrent\btdownloadgui.exe:*:Enabled:btdownloadgui – File not found
"C:\Program Files\Grisoft\AVG7\avginet.exe" = C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe – File not found
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe" = C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe – File not found
"C:\Program Files\Grisoft\AVG7\avgcc.exe" = C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe – File not found
"C:\Program Files\Kontiki\KService.exe" = C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service – ()
"C:\Program Files\BitTorrent_DNA\dna.exe" = C:\Program Files\BitTorrent_DNA\dna.exe:*:Enabled:BitTorrent DNA – File not found
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – File not found
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – File not found
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Java\jre1.6.0_07\bin\javaw.exe" = C:\Program Files\Java\jre1.6.0_07\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Charles\Charles.exe" = C:\Program Files\Charles\Charles.exe:*:Enabled:Charles Web Debugging Proxy – (XK72 Ltd)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\vixy.net\vixy.exe" = C:\Program Files\vixy.net\vixy.exe:*:Enabled:vixy converter beta – File not found
"C:\Program Files\TEAMtrader\TEAMtrader.exe" = C:\Program Files\TEAMtrader\TEAMtrader.exe:*:Enabled:TEAMtrader – File not found
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – File not found
"C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe" = C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe:*:Enabled:Dreamweaver 8 – (Macromedia, Inc.)
"C:\Program Files\NetMeeting\conf.exe" = C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® – (Microsoft Corporation)
"C:\Program Files\Sony Ericsson\Update Service\Update Service.exe" = C:\Program Files\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service – ()
"C:\Program Files\Sony Ericsson\SEMC OMSI Module\SEMC OMSI Module.exe" = C:\Program Files\Sony Ericsson\SEMC OMSI Module\SEMC OMSI Module.exe:*:Enabled:SEMC OMSI Module – ()
"C:\Program Files\Opera 9\opera.exe" = C:\Program Files\Opera 9\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation®Store
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{17424F35-8B77-4ADF-BC63-BF9B81418539}" = Apple Application Support
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20ACB2F8-3BCA-45A8-80A2-9D3CB5C25F43}" = Safari
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD
"{225AF9A1-B556-88D5-94AA-0010B5426419}" = My DSC
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{265C893D-9D3D-4CE6-A317-9FFF1C6C9C44}" = RealProducer Basic 11
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 19
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.1
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 6.009.00
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{32486EED-2D1C-42B2-9E3A-D1AF6E5BD069}" = Album Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150080}" = J2SE Runtime Environment 5.0 Update 8
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33BABF46-8430-47A8-A98C-88B1E9DA5DE6}" = Garmin Training Center 3.4.1
"{34BDF3BF-AA61-42E7-8818-C16A304910FC}" = Emma Core
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3686E7AE-19F9-470B-8D8C-02AE68A7B11B}" = Sony Ericsson PC Suite
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}" = Macromedia Flash MX
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold
"{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}" = StuffIt Standard
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A13289B-7B2D-47ED-AB28-CA2713057163}" = Microsoft Expression Web 3 SuperPreview for Internet Explorer
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{52C8CFE4-7C7C-11D7-A021-0060979CE4D3}" = Zoom ADSL Modem
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.3
"{70C4EFA5-F8B8-4015-9378-FCAA9000DF19}" = MotionBased Agent
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87CC8013-56D1-43E1-A0A5-AD406B4EBA95}" = Opera 10.63
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8B4AB829-DFD3-436D-B808-D9733D76C590}" = Macromedia Dreamweaver MX
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{903B0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Project Professional 2003
"{90510409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio Professional 2003
"{930B2432-43D4-11D5-9871-00C04F8EEB39}" = Macromedia Fireworks MX
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}" = Google Earth
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AEF2D1F3-0696-11D5-8E6A-00C04F7FA234}" = PaperPort 8.0 SE
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation®Network Downloader
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E583ED6F-BD99-4066-A420-C815BF692B69}" = Macromedia Fireworks MX 2004
"{E6FA148F-1E7D-4A42-A9A2-7DFABC2C6A2B}" = SportTracks 2.1
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E8843212-F0FC-4C3B-BFF3-D51829CB4F19}" = iTunes
"{E9F81423-211E-46B6-9AE0-38568BC5CF6F}" =
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F6970FBD-809A-4C51-BAB3-D94A04C6C8E7}" = Garmin Communicator Plugin
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FA55C144-16EC-4C19-ABFF-2E172C26950D}_is1" = Opera Mobile
"{FBE5AA96-22F0-4C4A-8E92-4BE3498D4CCB}" = Media Go
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"America Online uk" = AOL UK (Choose which version to remove)
"avast5" = avast! Free Antivirus
"BetTraderPro" = BetTrader PRO
"CamStudio" = CamStudio
"CCleaner" = CCleaner
"Charles_XK72" = Charles
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative VF0260" = Creative Live! Cam Vista IM Driver (1.01.03.1104)
"Daniusoft Video Converter Free_is1" = Daniusoft Video Converter Free(Build 2.3.1.0)
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab 7_is1" = DVDFab 7.0.7.0 (08/06/2010)
"EditPad Lite" = Just Great Software EditPad Lite 6.6.0
"EyeCandy5Textures" = Alien Skin Eye Candy 5 Textures
"Flipz IV Flash Character Pack 1_is1" = Flipz IV Flash Character Pack 1
"Flipz IV Flash_is1" = Flipz IV Flash
"Icon Craft" = Icon Craft
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Image Doctor" = Alien Skin Image Doctor 1.0
"ImgBurn" = ImgBurn (Remove Only)
"InstallShield_{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}" = StuffIt Standard
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"JSAS1.0.3" = JSAS
"JSAS1.08" = JSAS
"Lexmark X1100 Series" = Lexmark X1100 Series
"Lynx Web Browser_is1" = Lynx 2.8.5rel.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.12)" = Mozilla Firefox (3.6.12)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"Rapport_msi" = Rapport
"RealPlayer 6.0" = RealPlayer
"Samsung_SMP4" = Samsung SMP4 Video Codec Uninstall
"SamsungCamCorderDriver" = Samsung CamCorder Driver
"SecondLife" = SecondLife (remove only)
"SecondLifeADITI" = SecondLifeADITI (remove only)
"SEMC OMSI Module" = SEMC OMSI Module
"Skype_is1" = Skype 2.5
"Spotify" = Spotify
"Sunplus CA533A" = Icatch(IV) Camera Driver
"SuperPreviewIE_3.0.1776.0" = Microsoft Expression Web 3 SuperPreview for Internet Explorer
"TextBridge Pro 9.0" = TextBridge Pro 9.0
"TopStyle Lite (Version 3.0)" = TopStyle Lite (Version 3.0)
"Ulead Photo Express 3.0 SE" = Ulead Photo Express 3.0 SE
"Update Service" = Update Service
"VDMSound" = VDMSound
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 0.9.8a
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinMerge_is1" = WinMerge [removed]
"WinMorse 2" = WinMorse 2
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xerox One Touch" = Xerox One Touch
"Yahoo! Anti-Spy" = Yahoo! Anti-Spy
"Yahoo! Companion" = Yahoo! ¤u¨ã¦C
"Yahoo! Customizations" = Yahoo! Extras
"Yahoo! Internet Mail" = Yahoo! Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Zoom ADSL Modem" = Zoom ADSL Modem

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CheckBoxDemo" = CheckBoxDemo
"Flash Domination" = Flash Domination
"Sloppy" = Sloppy

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 16/11/2010 06:09:42 | Computer Name = DIMENSION | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 40960141

Error - 16/11/2010 06:09:43 | Computer Name = DIMENSION | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 16/11/2010 06:09:43 | Computer Name = DIMENSION | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 40962094

Error - 16/11/2010 06:09:43 | Computer Name = DIMENSION | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 40962094

Error - 16/11/2010 06:09:45 | Computer Name = DIMENSION | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 16/11/2010 06:09:45 | Computer Name = DIMENSION | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 40964047

Error - 16/11/2010 06:09:45 | Computer Name = DIMENSION | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 40964047

Error - 16/11/2010 06:09:47 | Computer Name = DIMENSION | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 16/11/2010 06:09:47 | Computer Name = DIMENSION | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 40966000

Error - 16/11/2010 06:09:47 | Computer Name = DIMENSION | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 40966000

[ System Events ]
Error - 18/11/2010 05:40:42 | Computer Name = DIMENSION | Source = Service Control Manager | ID = 7022
Description = The KService service hung on starting.

Error - 18/11/2010 05:42:38 | Computer Name = DIMENSION | Source = Service Control Manager | ID = 7000
Description = The Polaroid Video Camera Device service failed to start due to the
following error: %%1058

Error - 18/11/2010 05:43:59 | Computer Name = DIMENSION | Source = Service Control Manager | ID = 7022
Description = The KService service hung on starting.

Error - 18/11/2010 05:45:39 | Computer Name = DIMENSION | Source = Service Control Manager | ID = 7000
Description = The Polaroid Video Camera Device service failed to start due to the
following error: %%1058

Error - 18/11/2010 05:47:00 | Computer Name = DIMENSION | Source = Service Control Manager | ID = 7022
Description = The KService service hung on starting.

Error - 19/11/2010 05:08:33 | Computer Name = DIMENSION | Source = Service Control Manager | ID = 7000
Description = The Polaroid Video Camera Device service failed to start due to the
following error: %%1058

Error - 19/11/2010 05:09:54 | Computer Name = DIMENSION | Source = Service Control Manager | ID = 7022
Description = The KService service hung on starting.

Error - 19/11/2010 18:25:19 | Computer Name = DIMENSION | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
ACER-B0474DC4D4 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{045939AE-CF4. The master browser is stopping or an election is being
forced.

Error - 19/11/2010 21:30:38 | Computer Name = DIMENSION | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 19/11/2010 21:30:38 | Computer Name = DIMENSION | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2


< End of report >

GMER results to follow.
Dear mowman,

GMER report follows. GMER crashed with and without Devices unchecked, but ran in safe mode.

Sorry for the delay in getting these to you, and hope the format is ok.

Thanks,

Simon

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-22 10:48:31
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1600JB-75GVA0 rev.08.02D08
Running: gmer.exe; Driver: C:\DOCUME~1\SIMONH~1\LOCALS~1\Temp\awtdqpow.sys


—- System - GMER 1.0.15 —-

SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwClose [0xF765C028]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwCreateKey [0xF765BFE0]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwCreatePagingFile [0xF764FB00]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwEnumerateKey [0xF76505DC]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwEnumerateValueKey [0xF765C120]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwOpenFile [0xF764FB40]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwOpenKey [0xF765BFA4]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwQueryKey [0xF76505FC]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwQueryValueKey [0xF765C076]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwSetSystemPowerState [0xF765B550]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[1860] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 87386F38
Device \Driver\Cdrom \Device\CdRom0 873CF150
Device \FileSystem\Rdbss \Device\FsWrap 8711A578
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 8737A180
Device \Driver\atapi \Device\Ide\IdePort0 8737A180
Device \Driver\atapi \Device\Ide\IdePort1 8737A180
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 8737A180
Device \Driver\Cdrom \Device\CdRom1 873CF150
Device \FileSystem\Srv \Device\LanmanServer 86FD5FB0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8721CFB0
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8721CFB0
Device \FileSystem\Npfs \Device\NamedPipe 870F94A8
Device \FileSystem\Msfs \Device\Mailslot 87112200
Device \Driver\a347scsi \Device\Scsi\a347scsi1 871FFAD8
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 871FFAD8
Device \FileSystem\Fastfat \Fat F69CBD20
Device \FileSystem\Fastfat \Fat 86F20AD8
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 8711C320
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 8711C320
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 8711C320
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 8711C320
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 8711C320
Device \FileSystem\Cdfs \Cdfs 870BDCC8

—- Modules - GMER 1.0.15 —-

Module _________ F75D8000-F75F0000 (98304 bytes)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}@DisplayName Alcohol 120%
Reg HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6@ProductName Alcohol 120%

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\Simon Hibbott\My Documents\GenX Admin\Mobile Phone\ORANGE Phones, ORANGE deals, mobile phone insurance, free bluetooth, half price line rental, cashback, cash back, free phones, best deals, free pay as you go phones, ORANGE from SimplyORANGE_files\CSSCRI~1.JS 89417 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\GenX Admin\Mobile Phone\ORANGE Phones, ORANGE deals, mobile phone insurance, free bluetooth, half price line rental, cashback, cash back, free phones, best deals, free pay as you go phones, ORANGE from SimplyORANGE_files\simply3g.css 5546 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\css 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\css\style.css 3843 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\css\WS_FTP.LOG 2503 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\fadeslideshow.js 14188 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\link.gif 223 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\architects_shropshire_after.jpg 16329 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\architects_shropshire_after2.jpg 16207 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\architects_shropshire_after3.jpg 18765 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\architects_shropshire_after4.jpg 18253 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\architects_shropshire_before.jpg 14495 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\architects_shropshire_before3.jpg 17473 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\architects_shropshire_before4.jpg 16805 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\bullet.gif 182 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\close-quote.gif 159 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\greenspace_architects.gif 3594 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\h2.jpg 594 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\input.jpg 1149 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\item_bg.jpg 1824 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\item_bg_hover.jpg 1967 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\open-quote.gif 147 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\submit.jpg 1184 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\sustainable_student_village.jpg 23522 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\td.jpg 361 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\textarea.jpg 2331 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\Thumbs.db 88576 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\WS_FTP.LOG 16570 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\_notes 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\_notes\bullet.gif.mno 143 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\_notes\link.gif.mno 134 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\_notes\logo_revit_guru.gif.mno 209 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\_notes\logo_revit_guru.jpg.mno 209 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\_notes\logo_revit_ruru.jpg.mno 210 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\images\_notes\WS_FTP.LOG 4193 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\index.html 10747 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\js 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\js\accordian.pack.js 1149 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\js\WS_FTP.LOG 1694 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\loading.gif 1924 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\restore.png 227 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\Thumbs.db 6656 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\WS_FTP.LOG 2913 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding\x.png 171 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.01\images\_notes\bullet.gif.mno 143 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.01\images\_notes\link.gif.mno 134 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.01\images\_notes\logo_revit_guru.gif.mno 209 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.01\images\_notes\logo_revit_guru.jpg.mno 209 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.01\images\_notes\logo_revit_ruru.jpg.mno 210 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.01\images\_notes\WS_FTP.LOG 1361 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\box_revit.jpg 6250 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\bullet.gif 182 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\close-quote.gif 159 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\community_architecture.jpg 11501 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\greenspace_architects.gif 3594 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\h2.jpg 594 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\input.jpg 1149 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\item_bg.jpg 1824 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\item_bg_hover.jpg 1967 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\link.gif 223 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\logo_revit_guru.gif 6101 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\logo_revit_guru.jpg 6768 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\open-quote.gif 147 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\revit_architecture.gif 19205 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\revit_architecture.jpg 11760 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\submit.jpg 3339 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\td.jpg 361 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\textarea.jpg 2331 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\Thumbs.db 36864 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\WS_FTP.LOG 6368 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\_notes 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\_notes\bullet.gif.mno 143 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\_notes\link.gif.mno 134 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\_notes\logo_revit_guru.gif.mno 209 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\_notes\logo_revit_guru.jpg.mno 209 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\_notes\logo_revit_ruru.jpg.mno 210 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.02\images\_notes\WS_FTP.LOG 1361 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\css 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\css\style.css 3843 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\css\WS_FTP.LOG 1703 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\fadeslideshow.js 14188 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\box_revit.jpg 6250 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\bullet.gif 182 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\close-quote.gif 159 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\community_architecture.jpg 11501 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\greenspace_architects.gif 3594 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\h2.jpg 594 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\input.jpg 1149 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\item_bg.jpg 1824 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\item_bg_hover.jpg 1967 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\kevin_slack.jpg 11657 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\link.gif 223 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\logo_revit_guru.gif 6101 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\logo_revit_guru.jpg 6768 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\open-quote.gif 147 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\revit_architecture.gif 19205 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\revit_architecture.jpg 11760 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\robert_netherwood.jpg 10649 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\submit.jpg 3339 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\td.jpg 361 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\textarea.jpg 2331 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\Thumbs.db 44544 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\WS_FTP.LOG 6368 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\_notes 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\_notes\bullet.gif.mno 143 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\_notes\link.gif.mno 134 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\_notes\logo_revit_guru.gif.mno 209 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\_notes\logo_revit_guru.jpg.mno 209 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\_notes\logo_revit_ruru.jpg.mno 210 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\images\_notes\WS_FTP.LOG 1361 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\index.html 10691 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\js 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\js\accordian.pack.js 1149 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\js\WS_FTP.LOG 870 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\loading.gif 1924 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\restore.png 227 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\Thumbs.db 6656 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.03\x.png 171 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\css 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\css\style.css 3843 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\css\WS_FTP.LOG 2107 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\fadeslideshow.js 14188 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\box_revit.jpg 6250 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\bullet.gif 182 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\close-quote.gif 159 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\community_architecture.jpg 11501 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\greenspace_architects.gif 3594 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\h2.jpg 594 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\input.jpg 1149 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\item_bg.jpg 1824 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\item_bg_hover.jpg 1967 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\kevin_slack.jpg 11657 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\link.gif 223 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\logo_revit_guru.gif 6101 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\logo_revit_guru.jpg 6768 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\open-quote.gif 147 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\revit_architecture.gif 19205 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\revit_architecture.jpg 11760 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\robert_netherwood.jpg 10649 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\submit.jpg 1184 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\td.jpg 361 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\textarea.jpg 2331 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\Thumbs.db 51712 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\WS_FTP.LOG 11164 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\_notes 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\_notes\bullet.gif.mno 143 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\_notes\link.gif.mno 134 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\_notes\logo_revit_guru.gif.mno 209 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\_notes\logo_revit_guru.jpg.mno 209 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\_notes\logo_revit_ruru.jpg.mno 210 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\images\_notes\WS_FTP.LOG 2789 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\index.html 10207 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\js 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\js\accordian.pack.js 1149 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\js\WS_FTP.LOG 1286 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\loading.gif 1924 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\restore.png 227 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\Thumbs.db 6656 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\WS_FTP.LOG 1176 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Greenspace\web holding\holding1.04\x.png 171 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\360_tours\ColoradoSpin01.jpg 174746 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\360_tours\ColoradoSpin02.jpg 137876 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\360_tours\SunriseSpin01.jpg 175670 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\360_tours\SunriseSpin02.jpg 167925 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Copy\anthony letter.doc 29696 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Copy\chris letter.doc 29184 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Copy\Home Page.doc 26112 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Copy\images 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Copy\images\static_holiday_homes_brochure.jpg 10067 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Copy\price includes.doc 96256 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Copy\website.ppt 784896 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\ball.jpg 6305 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\ball2.jpg 66074 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\favicon.gif 508 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\favicon_20070614_3758 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\favicon_20070614_3758\extra 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\favicon_20070614_3758\extra\preview_16x16.png 835 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\favicon_20070614_3758\extra\ReadMe.txt 1042 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\favicon_20070614_3758\favicon.ico 1406 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\favicon_20070614_3758\Thumbs.db 6144 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\favicon_20070614_3758\WS_FTP.LOG 203 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\favicon_20070614_3758.zip 4104 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\favicon\Thumbs.db 15360 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\blueflex 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\blueflex\html_2007.06.26_001.txt 4024 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Copy 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Copy\anthony letter.doc 29696 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Copy\chris letter.doc 29184 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Copy\GOLDENSANDS2007LOW_map.pdf 1036871 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Copy\price includes.doc 96256 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Copy\website.ppt 784896 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\haven.gif 2578 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Sales Funnel.png 155364 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\appointments_kept.gif 800 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\appointments_made.gif 879 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\arrow_down.gif 355 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\arrow_up.gif 364 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\background.gif 19800 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\box_gray.gif 85 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\completions.gif 576 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\customers_gray.gif 516 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Funnel.xls 21504 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\funnelCalc[1].html 15865 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\leakage.gif 449 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\of_your.gif 1945 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\percent.gif 199 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Prospecting Activity Rate Calculator.xls 15872 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\prospects.gif 520 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\prospects_gray.gif 520 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\prospects_yield.gif 1038 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Sales Funnel Excel.gif 83183 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Sales Funnel Presentation.xls 20480 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Sales Funnel Quarter 3.xls 38912 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Sales Funnel web.gif 104595 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Sales Funnel.gif 27591 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Sales Funnel.xls 45056 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Sales Funnel1.00.xls 41984 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\sales_made.gif 584 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\speaks.gif 498 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\telephone_calls.gif 783 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\text_customers.gif 878 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\text_customers2.gif 619 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\text_prospects.gif 643 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\text_to_win.gif 419 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\text_you_will.gif 1231 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\Thumbs.db 43008 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Sales Funnel\your.gif 351 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Haven\Thumbs.db 11776 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\holding page\images 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\holding page\images\footer.gif 16826 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\holding page\images\static_holiday_homes.gif 21851 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\holding page\images\Thumbs.db 6656 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\holding page\images\WS_FTP.LOG 438 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\holding page\index.html 878 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\holding page\WS_FTP.LOG 531 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\3_star_caravan_bedroom.jpg 18236 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\3_star_caravan_kitchen.jpg 22859 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\3_star_caravan_lounge.jpg 26710 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\4_star_caravan_bedroom.jpg 27499 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\4_star_caravan_kitchen.jpg 29952 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\4_star_caravan_lounge.jpg 25566 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\adapted_bathroom.jpg 15980 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\adapted_bedroom.jpg 17231 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\adapted_lounge.jpg 26237 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\adapted_static_caravan.jpg 20917 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\bronze_caravan_bedroom.jpg 17635 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\bronze_caravan_kitchen.jpg 22115 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\bronze_caravan_lounge.jpg 26303 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\gold_caravan_bedroom.jpg 21537 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\gold_caravan_kitchen.jpg 22814 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\gold_caravan_lounge.jpg 24146 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\silver_caravan_bedroom.jpg 12485 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\silver_caravan_kitchen.jpg 19883 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\silver_caravan_lounge.jpg 22396 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\accommodation\Thumbs.db 60928 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\aquacise.jpg 37732 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\aquajets.jpg 23839 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\aqua_gliders.jpg 23390 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\bar.jpg 35028 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\bouncy_castle.jpg 19983 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\convenience_store.jpg 42070 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\discover_archery.jpg 17893 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\discover_fencing.jpg 20270 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\football_coaching.jpg 23951 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\indoor_pool.jpg 30850 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\learn2swim.jpg 21797 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\mini_ten_pin_bowling.jpg 31763 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\outdoor_family_funzone.jpg 27659 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\play_area.jpg 31648 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\show_bar.jpg 33437 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\show_bar_couple.jpg 27480 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\surf_rider.jpg 23675 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\terrace_area.jpg 35218 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\Thumbs.db 70144 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\tiger_treasure_shop.jpg 49073 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\activities_and_facilities\water_dodgems.jpg 39899 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\entertainment 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\entertainment\family_fun_shows.jpg 29424 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\entertainment\fantastic_funstars.jpg 31010 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\entertainment\live_bands.jpg 19780 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\entertainment\pop_and_rock.jpg 21460 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\entertainment\retro_sounds.jpg 25533 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\entertainment\stage_shows.jpg 26554 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\entertainment\Thumbs.db 7680 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\entertainment\tribute_bands.jpg 32882 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\entertainment\variety_shows.jpg 19636 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands.jpg 588544 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands_images 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands_images\arrange_a_visit.jpg 5350 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands_images\beach.jpg 16106 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands_images\direct_beach_access.jpg 19077 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands_images\family_on_beach.jpg 3294 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands_images\fishing_lake.jpg 22659 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands_images\free_brochure.jpg 10067 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands_images\golden_sands_park_view.jpg 40298 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands_images\seal.jpg 4777 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\golden_sands_images\Thumbs.db 30720 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\ContactSheet-001.tif 16996428 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS - Caravan View [1].jpg 2923346 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS - Caravan View [2].jpg 7769914 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS - Falcon Family Club.jpg 2603641 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS - Indoor Pool.jpg 2657978 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS - Owners Enquiry Centre.jpg 2739251 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS - Quayside Bar.jpg 2612391 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS BASKETBALL.jpg 2579764 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\gs.carext.02.05.jpg 10288396 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS_A3_RESCAN_1 30%.jpg 2973810 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS_BarCouple-HAB.jpg 276740 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS_Bowling-HAB.jpg 283496 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS_Entrance-HAB.jpg 273972 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\GS_OPool-HAB.jpg 282350 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\GS Images\Thumbs.db 81920 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\holiday_homes.jpg 990761 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\kids_clubs 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\kids_clubs\funtime_making_day.jpg 22996 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\kids_clubs\games_and_competitions.jpg 28032 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\kids_clubs\musical_fun_time.jpg 30922 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\kids_clubs\PAWS_making_day.jpg 25640 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\kids_clubs\PAWS_toy_time.jpg 20891 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\kids_clubs\t-co_choice.jpg 19278 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\kids_clubs\t-co_fun_in_the_sun.jpg 23578 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\kids_clubs\t-co_tech.jpg 28280 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\kids_clubs\Thumbs.db 31744 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\logo_award_winning_holidays.gif 6427 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\logo_haven.gif 2940 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\logo_haven_british_holidays.gif 4545 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\logo_holiday_park_fair_trader.gif 1905 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\logo_owners_exclusive.gif 1237 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\out_and_about 0 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\out_and_about\beach.jpg 17225 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\out_and_about\outdoor_terrace.jpg 32600 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\out_and_about\park_view.jpg 28776 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\out_and_about\Thumbs.db 6144 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\owners_exclusive_tcm9-38212.gif 2262 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\owners_logo.gif 3189 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\page_bkgd.jpg 100903 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\Images\Thumbs.db 32768 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\image_rotator_images\lincolnshire_beach.jpg 15120 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\image_rotator_images\site_leisure_facilities.jpg 19043 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\image_rotator_images\static_holiday_homes.jpg 19604 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\image_rotator_images\static_holiday_homes.png 413298 bytes
File C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\Haven\image_rotator_images\WS_FTP.LOG 3806 bytes

—- EOF - GMER 1.0.15 —-
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Log file details follow, as requested:

ComboFix 10-11-21.02 - Simon Hibbott 22/11/2010 15:10:14.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.536 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\hpe99.dll
c:\documents and settings\Simon Hibbott\Application Data\inst.exe
c:\documents and settings\Simon Hibbott\Application Data\Microsoft\stor.cfg
c:\progra~1\TEXTBR~1.0\Bin\REGIST~1.EXE
c:\windows\system32\_004616_.tmp.dll
c:\windows\system32\_004617_.tmp.dll
c:\windows\system32\_004618_.tmp.dll
c:\windows\system32\_004619_.tmp.dll
c:\windows\system32\_004626_.tmp.dll
c:\windows\system32\_004627_.tmp.dll
c:\windows\system32\_004628_.tmp.dll
c:\windows\system32\_004629_.tmp.dll
c:\windows\system32\_004630_.tmp.dll
c:\windows\system32\_004631_.tmp.dll
c:\windows\system32\_004632_.tmp.dll
c:\windows\system32\_004633_.tmp.dll
c:\windows\system32\_004634_.tmp.dll
c:\windows\system32\_004635_.tmp.dll
c:\windows\system32\_004636_.tmp.dll
c:\windows\system32\_004637_.tmp.dll
c:\windows\system32\_004638_.tmp.dll
c:\windows\system32\_004639_.tmp.dll
c:\windows\system32\_004640_.tmp.dll
c:\windows\system32\_004641_.tmp.dll
c:\windows\system32\_004642_.tmp.dll
c:\windows\system32\_004643_.tmp.dll
c:\windows\system32\_004644_.tmp.dll
c:\windows\system32\_004645_.tmp.dll
c:\windows\system32\_004646_.tmp.dll
c:\windows\system32\_004647_.tmp.dll
c:\windows\system32\_004648_.tmp.dll
c:\windows\system32\_004649_.tmp.dll
c:\windows\system32\_004650_.tmp.dll
c:\windows\system32\_004651_.tmp.dll
c:\windows\system32\_004652_.tmp.dll
c:\windows\system32\_004653_.tmp.dll
c:\windows\system32\_004654_.tmp.dll
c:\windows\system32\_004655_.tmp.dll
c:\windows\system32\_004656_.tmp.dll
c:\windows\system32\_004657_.tmp.dll
c:\windows\system32\_004658_.tmp.dll
c:\windows\system32\_004659_.tmp.dll
c:\windows\system32\_004660_.tmp.dll
c:\windows\system32\_004661_.tmp.dll
c:\windows\system32\_004662_.tmp.dll
c:\windows\system32\_004663_.tmp.dll
c:\windows\system32\_004664_.tmp.dll
c:\windows\system32\_004665_.tmp.dll
c:\windows\system32\_004666_.tmp.dll
c:\windows\system32\_004667_.tmp.dll
c:\windows\system32\_004668_.tmp.dll
c:\windows\system32\_004669_.tmp.dll
c:\windows\system32\_004670_.tmp.dll
c:\windows\system32\_004671_.tmp.dll
c:\windows\system32\_004672_.tmp.dll
c:\windows\system32\_004673_.tmp.dll
c:\windows\system32\_004674_.tmp.dll
c:\windows\system32\_004675_.tmp.dll
c:\windows\system32\_004676_.tmp.dll
c:\windows\system32\_004677_.tmp.dll
c:\windows\system32\_004678_.tmp.dll
c:\windows\system32\_004679_.tmp.dll
c:\windows\system32\_004680_.tmp.dll
c:\windows\system32\_004681_.tmp.dll
c:\windows\system32\_004682_.tmp.dll
c:\windows\system32\_004683_.tmp.dll
c:\windows\system32\_004684_.tmp.dll
c:\windows\system32\_004685_.tmp.dll
c:\windows\system32\_004686_.tmp.dll
c:\windows\system32\_004687_.tmp.dll
c:\windows\system32\_004688_.tmp.dll
c:\windows\system32\_004689_.tmp.dll
c:\windows\system32\_004690_.tmp.dll
c:\windows\system32\_004691_.tmp.dll
c:\windows\system32\_004692_.tmp.dll
c:\windows\system32\_004693_.tmp.dll
c:\windows\system32\_004694_.tmp.dll
c:\windows\system32\_004696_.tmp.dll
c:\windows\system32\_004697_.tmp.dll
c:\windows\system32\_004698_.tmp.dll
c:\windows\system32\_004699_.tmp.dll
c:\windows\system32\_004700_.tmp.dll
c:\windows\system32\_004701_.tmp.dll
c:\windows\system32\_004702_.tmp.dll
c:\windows\system32\_004704_.tmp.dll
c:\windows\system32\_004705_.tmp.dll
c:\windows\system32\_004706_.tmp.dll
c:\windows\system32\_004707_.tmp.dll
c:\windows\system32\_004708_.tmp.dll
c:\windows\system32\_004709_.tmp.dll
c:\windows\system32\_004710_.tmp.dll
c:\windows\system32\_004711_.tmp.dll
c:\windows\system32\_004712_.tmp.dll
c:\windows\system32\_004713_.tmp.dll
c:\windows\system32\_004714_.tmp.dll
c:\windows\system32\_004715_.tmp.dll
c:\windows\system32\_004716_.tmp.dll
c:\windows\system32\_004717_.tmp.dll
c:\windows\system32\_004718_.tmp.dll
c:\windows\system32\_004719_.tmp.dll
c:\windows\system32\_004721_.tmp.dll
c:\windows\system32\_004722_.tmp.dll
c:\windows\system32\_004723_.tmp.dll
c:\windows\system32\_004724_.tmp.dll
c:\windows\system32\_004726_.tmp.dll
c:\windows\system32\_004728_.tmp.dll
c:\windows\system32\_004729_.tmp.dll
c:\windows\system32\_004730_.tmp.dll
c:\windows\system32\_004731_.tmp.dll
c:\windows\system32\_004732_.tmp.dll
c:\windows\system32\_004733_.tmp.dll
c:\windows\system32\_004734_.tmp.dll
c:\windows\system32\_004736_.tmp.dll
c:\windows\system32\_004737_.tmp.dll
c:\windows\system32\_004738_.tmp.dll
c:\windows\system32\_004739_.tmp.dll
c:\windows\system32\_004740_.tmp.dll
c:\windows\system32\_004741_.tmp.dll
c:\windows\system32\_004742_.tmp.dll
c:\windows\system32\_004743_.tmp.dll
c:\windows\system32\_004744_.tmp.dll
c:\windows\system32\_004745_.tmp.dll
c:\windows\system32\_004746_.tmp.dll
c:\windows\system32\_004747_.tmp.dll
c:\windows\system32\_004748_.tmp.dll
c:\windows\system32\_004749_.tmp.dll
c:\windows\system32\_004750_.tmp.dll
c:\windows\system32\_004751_.tmp.dll
c:\windows\system32\_004752_.tmp.dll
c:\windows\system32\_004754_.tmp.dll
c:\windows\system32\_004755_.tmp.dll
c:\windows\system32\_004756_.tmp.dll
c:\windows\system32\_004757_.tmp.dll
c:\windows\system32\_004758_.tmp.dll
c:\windows\system32\_004761_.tmp.dll
c:\windows\system32\_004762_.tmp.dll
c:\windows\system32\_004763_.tmp.dll
c:\windows\system32\_004764_.tmp.dll
c:\windows\system32\_004765_.tmp.dll
c:\windows\system32\_004766_.tmp.dll
c:\windows\system32\_004767_.tmp.dll
c:\windows\system32\_004769_.tmp.dll
c:\windows\system32\_004770_.tmp.dll
c:\windows\system32\_004771_.tmp.dll
c:\windows\system32\_004772_.tmp.dll
c:\windows\system32\_004773_.tmp.dll
c:\windows\system32\_004774_.tmp.dll
c:\windows\system32\_004775_.tmp.dll
c:\windows\system32\_004776_.tmp.dll
c:\windows\system32\_004778_.tmp.dll
c:\windows\system32\_004779_.tmp.dll
c:\windows\system32\_004780_.tmp.dll
c:\windows\system32\_004781_.tmp.dll
c:\windows\system32\_004784_.tmp.dll
c:\windows\system32\_004785_.tmp.dll
c:\windows\system32\_004789_.tmp.dll
c:\windows\system32\_004790_.tmp.dll
c:\windows\system32\_004792_.tmp.dll
c:\windows\system32\_004795_.tmp.dll
c:\windows\system32\_004797_.tmp.dll
c:\windows\system32\_004798_.tmp.dll
c:\windows\system32\_004799_.tmp.dll
c:\windows\system32\_004800_.tmp.dll
c:\windows\system32\_004803_.tmp.dll
c:\windows\system32\_004804_.tmp.dll
c:\windows\system32\_004805_.tmp.dll
c:\windows\system32\_004806_.tmp.dll
c:\windows\system32\_004807_.tmp.dll
c:\windows\system32\_004812_.tmp.dll
c:\windows\system32\_004814_.tmp.dll
c:\windows\system32\ReadMe.txt
c:\windows\XSxS

.
((((((((((((((((((((((((( Files Created from 2010-10-22 to 2010-11-22 )))))))))))))))))))))))))))))))
.

2010-11-18 10:05 . 2010-11-18 10:05 388096 —-a-r- c:\documents and settings\Simon Hibbott\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-11-18 10:05 . 2010-11-18 10:05 ——– d—–w- c:\program files\Trend Micro
2010-11-17 13:09 . 2010-11-17 13:19 ——– d—–w- c:\program files\CamStudio
2010-11-17 10:01 . 2010-11-17 10:01 ——– d—–w- c:\program files\iPod
2010-11-17 10:01 . 2010-11-17 10:02 ——– d—–w- c:\program files\iTunes
2010-11-11 18:27 . 2010-11-11 18:28 ——– d—–w- c:\documents and settings\Administrator
2010-11-11 16:09 . 2010-11-11 16:09 ——– d—–w- c:\documents and settings\Simon Hibbott\Application Data\SUPERAntiSpyware.com
2010-11-11 16:09 . 2010-11-11 16:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-11-11 16:09 . 2010-11-11 16:10 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-11-10 18:20 . 2010-09-07 15:47 17744 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-11-10 18:20 . 2010-09-07 15:52 165584 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-11-10 18:20 . 2010-09-07 15:47 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-11-10 18:20 . 2010-09-07 15:52 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-11-10 18:20 . 2010-09-07 15:47 100176 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-11-10 18:20 . 2010-09-07 15:47 94544 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-11-10 18:20 . 2010-09-07 15:46 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-11-10 18:20 . 2010-09-07 16:12 38848 —-a-w- c:\windows\avastSS.scr
2010-11-10 18:20 . 2010-09-07 16:11 167592 —-a-w- c:\windows\system32\aswBoot.exe
2010-11-10 12:46 . 2010-11-10 12:46 ——– d—–w- c:\program files\Alwil Software
2010-11-10 12:46 . 2010-11-10 12:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-11-10 12:15 . 2010-11-10 12:15 ——– d—–w- c:\program files\CCleaner
2010-11-09 19:17 . 2010-04-29 15:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-09 19:17 . 2010-04-29 15:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-11-09 12:23 . 2010-11-09 12:23 ——– d—–w- c:\windows\system32\wbem\Repository
2010-11-09 09:57 . 2010-11-09 09:58 ——– d–h–w- c:\windows\ie8
2010-11-09 09:55 . 2010-11-09 09:55 ——– d—–w- c:\documents and settings\LocalService\Application Data\GARMIN
2010-11-08 16:55 . 2010-11-08 16:55 ——– d—–w- c:\documents and settings\Simon Hibbott\Application Data\ElevatedDiagnostics
2010-11-08 13:41 . 2010-11-08 13:41 ——– d—–w- c:\documents and settings\Simon Hibbott\Application Data\Malwarebytes
2010-11-08 13:41 . 2010-11-08 13:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-11-08 13:41 . 2010-11-09 19:21 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-11-06 11:37 . 2010-11-06 11:37 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-11-06 11:37 . 2010-11-06 11:37 103864 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2010-11-05 10:50 . 2010-11-05 10:50 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2010-11-05 10:50 . 2010-11-05 10:50 ——– d-sh–w- c:\documents and settings\LocalService\IECompatCache
2010-11-05 10:50 . 2010-11-05 10:50 ——– d—–w- c:\documents and settings\LocalService\Application Data\Trusteer
2010-11-05 10:46 . 2010-11-05 10:46 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2010-11-01 19:25 . 2010-11-01 19:25 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-10-28 09:59 . 2010-10-28 10:12 ——– d—–w- c:\program files\Opera Mobile

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-03 22:43 . 2010-10-03 22:43 59240 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2010-09-18 11:23 . 2004-08-10 12:51 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-10 12:51 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-08-10 12:51 954368 —-a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-08-10 12:51 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58 . 2004-08-10 12:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2004-08-10 12:51 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2004-08-10 12:51 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-08 10:17 . 2010-09-08 10:17 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 10:17 . 2010-09-08 10:17 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-09-01 11:51 . 2004-08-10 12:50 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2008-11-20 15:39 1852800 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-08-10 12:51 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2008-11-20 15:39 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2008-11-20 15:38 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-16 09:43 5120 —-a-w- c:\windows\system32\xpsp4res.dll
.

——- Sigcheck ——-

[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
[-] 2004-08-03 22:59 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [——] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 68856]
"kdx"="c:\program files\Kontiki\KHost.exe" [2006-11-08 1040832]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-09-24 434176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"c:\windows\system32\V0260Ext.ax"="c:\windows\system32\V0260Ext.ax" [X]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"IndexSearch"="c:\program files\Scansoft\PaperPort\IndexSearch.exe" [2002-09-23 36864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"OneTouch Monitor"="c:\program files\Xerox One Touch\OneTouchMon.exe" [2003-06-12 86016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-11 421160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 68856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Simon Hibbott\\My Documents\\My Downloads\\WS FTP\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
"c:\\Program Files\\Charles\\Charles.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver 8\\Dreamweaver.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Sony Ericsson\\SEMC OMSI Module\\SEMC OMSI Module.exe"=
"c:\\Program Files\\Opera 9\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [27/09/2005 11:57 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [27/09/2005 11:57 5248]
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [03/10/2010 22:43 59240]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [10/11/2010 18:20 165584]
R1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [28/02/2010 15:56 390528]
R1 RapportCerberus_19917;RapportCerberus_19917;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys [03/10/2010 22:54 34792]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [03/10/2010 22:43 169320]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 18:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 18:41 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [10/11/2010 18:20 17744]
R2 EmmaDevMgmtSvc;Emma Device Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe [16/12/2009 13:36 306296]
R2 EmmaUpdMgmtSvc;Emma Update Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe [16/12/2009 13:36 162936]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [18/12/2009 15:56 90112]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [03/10/2010 22:43 767208]
S2 Ca533av;Polaroid Video Camera Device;c:\windows\system32\drivers\Ca533av.sys [20/06/2006 16:19 515803]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [01/02/2010 08:32 135664]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [18/12/2009 15:46 13224]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe" –> c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [?]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [18/12/2009 15:58 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [18/12/2009 15:58 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [18/12/2009 15:58 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [18/12/2009 15:58 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [18/12/2009 15:58 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [18/12/2009 15:58 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [18/12/2009 15:58 109864]
S3 V0260VID;Live! Cam Vista IM;c:\windows\system32\drivers\V0260Vid.sys [03/03/2008 13:16 178913]
.
Contents of the 'Scheduled Tasks' folder

2010-11-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]

2010-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-01 08:32]

2010-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-01 08:32]

2005-03-22 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-10 00:12]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.bbc.co.uk/
uInternet Connection Wizard,ShellNext = hxxp://www.dell.co.uk/myway
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:50370
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
FF - ProfilePath - c:\documents and settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\
FF - prefs.js: browser.search.selectedEngine - Google UK
FF - prefs.js: browser.startup.homepage - hxxp://www.bbc.co.uk/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50370
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npdsplay.dll
FF - plugin: c:\program files\Opera 9\program\plugins\NPOFFICE.DLL
FF - plugin: c:\program files\Opera 9\program\plugins\NPOFFICE.DLL
FF - plugin: c:\program files\Opera 9\program\plugins\nppdf32.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npwmsdrm.dll
FF - plugin: c:\program files\Sony\Media Go\npmediago.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

BHO-{9D0A3CDB-A952-4767-A6B3-4FB176095619} - (no file)
BHO-{E3B939DA-B105-49ee-9D75-0C1875B7961B} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-RegisterDropHandler - c:\progra~1\TEXTBR~1.0\Bin\REGIST~1.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-22 15:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(700)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(7128)
c:\windows\system32\WININET.dll
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\windows\IME\SPGRMR.DLL
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-11-22 15:46:13 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-22 15:46

Pre-Run: 99,476,717,568 bytes free
Post-Run: 99,679,596,544 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 6D9DCCFA99F62F0B2BDA80C249324437
Please do the following

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    FCopy::
    c:\windows\$NtServicePackUninstall$\atapi.sys | c:\windows\system32\drivers\atapi.sys
    
    DDS::
    uInternet Settings,ProxyOverride = *.local
    uInternet Settings,ProxyServer = http=127.0.0.1:50370
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 50370
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.





Next

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.



Next

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Result of running ComboFix with CFScript.txt. Other results to follow shortly :

ComboFix 10-11-22.04 - Simon Hibbott 23/11/2010 0:09.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.502 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Simon Hibbott\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
————— FCopy —————

c:\windows\$NtServicePackUninstall$\atapi.sys –> c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((( Files Created from 2010-10-23 to 2010-11-23 )))))))))))))))))))))))))))))))
.

2010-11-18 10:05 . 2010-11-18 10:05 388096 —-a-r- c:\documents and settings\Simon Hibbott\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-11-18 10:05 . 2010-11-18 10:05 ——– d—–w- c:\program files\Trend Micro
2010-11-17 13:09 . 2010-11-17 13:19 ——– d—–w- c:\program files\CamStudio
2010-11-17 10:01 . 2010-11-17 10:01 ——– d—–w- c:\program files\iPod
2010-11-17 10:01 . 2010-11-17 10:02 ——– d—–w- c:\program files\iTunes
2010-11-11 18:27 . 2010-11-11 18:28 ——– d—–w- c:\documents and settings\Administrator
2010-11-11 16:09 . 2010-11-11 16:09 ——– d—–w- c:\documents and settings\Simon Hibbott\Application Data\SUPERAntiSpyware.com
2010-11-11 16:09 . 2010-11-11 16:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-11-11 16:09 . 2010-11-11 16:10 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-11-10 18:20 . 2010-09-07 15:47 17744 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-11-10 18:20 . 2010-09-07 15:52 165584 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-11-10 18:20 . 2010-09-07 15:47 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-11-10 18:20 . 2010-09-07 15:52 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-11-10 18:20 . 2010-09-07 15:47 100176 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-11-10 18:20 . 2010-09-07 15:47 94544 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-11-10 18:20 . 2010-09-07 15:46 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-11-10 18:20 . 2010-09-07 16:12 38848 —-a-w- c:\windows\avastSS.scr
2010-11-10 18:20 . 2010-09-07 16:11 167592 —-a-w- c:\windows\system32\aswBoot.exe
2010-11-10 12:46 . 2010-11-10 12:46 ——– d—–w- c:\program files\Alwil Software
2010-11-10 12:46 . 2010-11-10 12:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-11-10 12:15 . 2010-11-10 12:15 ——– d—–w- c:\program files\CCleaner
2010-11-09 19:17 . 2010-04-29 15:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-09 19:17 . 2010-04-29 15:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-11-09 12:23 . 2010-11-09 12:23 ——– d—–w- c:\windows\system32\wbem\Repository
2010-11-09 09:57 . 2010-11-09 09:58 ——– d–h–w- c:\windows\ie8
2010-11-09 09:55 . 2010-11-09 09:55 ——– d—–w- c:\documents and settings\LocalService\Application Data\GARMIN
2010-11-08 16:55 . 2010-11-08 16:55 ——– d—–w- c:\documents and settings\Simon Hibbott\Application Data\ElevatedDiagnostics
2010-11-08 13:41 . 2010-11-08 13:41 ——– d—–w- c:\documents and settings\Simon Hibbott\Application Data\Malwarebytes
2010-11-08 13:41 . 2010-11-08 13:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-11-08 13:41 . 2010-11-09 19:21 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-11-06 11:37 . 2010-11-06 11:37 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-11-06 11:37 . 2010-11-06 11:37 103864 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2010-11-05 10:50 . 2010-11-05 10:50 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2010-11-05 10:50 . 2010-11-05 10:50 ——– d-sh–w- c:\documents and settings\LocalService\IECompatCache
2010-11-05 10:50 . 2010-11-05 10:50 ——– d—–w- c:\documents and settings\LocalService\Application Data\Trusteer
2010-11-05 10:46 . 2010-11-05 10:46 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2010-11-01 19:25 . 2010-11-01 19:25 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-10-28 09:59 . 2010-10-28 10:12 ——– d—–w- c:\program files\Opera Mobile

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-03 22:43 . 2010-10-03 22:43 59240 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2010-09-18 11:23 . 2004-08-10 12:51 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-10 12:51 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-08-10 12:51 954368 —-a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-08-10 12:51 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58 . 2004-08-10 12:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2004-08-10 12:51 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2004-08-10 12:51 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-08 10:17 . 2010-09-08 10:17 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 10:17 . 2010-09-08 10:17 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-09-01 11:51 . 2004-08-10 12:50 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2008-11-20 15:39 1852800 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-08-10 12:51 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2008-11-20 15:39 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2008-11-20 15:38 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-16 09:43 5120 —-a-w- c:\windows\system32\xpsp4res.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 68856]
"kdx"="c:\program files\Kontiki\KHost.exe" [2006-11-08 1040832]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-09-24 434176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"c:\windows\system32\V0260Ext.ax"="c:\windows\system32\V0260Ext.ax" [X]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"IndexSearch"="c:\program files\Scansoft\PaperPort\IndexSearch.exe" [2002-09-23 36864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"OneTouch Monitor"="c:\program files\Xerox One Touch\OneTouchMon.exe" [2003-06-12 86016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-11 421160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 68856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Simon Hibbott\\My Documents\\My Downloads\\WS FTP\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
"c:\\Program Files\\Charles\\Charles.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver 8\\Dreamweaver.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Sony Ericsson\\SEMC OMSI Module\\SEMC OMSI Module.exe"=
"c:\\Program Files\\Opera 9\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [27/09/2005 11:57 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [27/09/2005 11:57 5248]
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [03/10/2010 22:43 59240]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [10/11/2010 18:20 165584]
R1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [28/02/2010 15:56 390528]
R1 RapportCerberus_19917;RapportCerberus_19917;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys [03/10/2010 22:54 34792]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [03/10/2010 22:43 169320]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 18:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 18:41 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [10/11/2010 18:20 17744]
R2 EmmaDevMgmtSvc;Emma Device Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe [16/12/2009 13:36 306296]
R2 EmmaUpdMgmtSvc;Emma Update Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe [16/12/2009 13:36 162936]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [03/10/2010 22:43 767208]
S2 Ca533av;Polaroid Video Camera Device;c:\windows\system32\drivers\Ca533av.sys [20/06/2006 16:19 515803]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [01/02/2010 08:32 135664]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [18/12/2009 15:56 90112]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [18/12/2009 15:46 13224]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe" –> c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [?]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [18/12/2009 15:58 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [18/12/2009 15:58 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [18/12/2009 15:58 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [18/12/2009 15:58 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [18/12/2009 15:58 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [18/12/2009 15:58 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [18/12/2009 15:58 109864]
S3 V0260VID;Live! Cam Vista IM;c:\windows\system32\drivers\V0260Vid.sys [03/03/2008 13:16 178913]
.
Contents of the 'Scheduled Tasks' folder

2010-11-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]

2010-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-01 08:32]

2010-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-01 08:32]

2005-03-22 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-10 00:12]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.bbc.co.uk/
uInternet Connection Wizard,ShellNext = hxxp://www.dell.co.uk/myway
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
FF - ProfilePath - c:\documents and settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\
FF - prefs.js: browser.search.selectedEngine - Google UK
FF - prefs.js: browser.startup.homepage - hxxp://www.bbc.co.uk/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50370
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npdsplay.dll
FF - plugin: c:\program files\Opera 9\program\plugins\NPOFFICE.DLL
FF - plugin: c:\program files\Opera 9\program\plugins\NPOFFICE.DLL
FF - plugin: c:\program files\Opera 9\program\plugins\nppdf32.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Opera 9\program\plugins\npwmsdrm.dll
FF - plugin: c:\program files\Sony\Media Go\npmediago.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-23 00:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(696)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(18260)
c:\windows\system32\WININET.dll
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\windows\IME\SPGRMR.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-11-23 00:34:12
ComboFix-quarantined-files.txt 2010-11-23 00:34
ComboFix2.txt 2010-11-22 15:46

Pre-Run: 99,630,346,240 bytes free
Post-Run: 99,612,291,072 bytes free

- - End Of File - - EE47BFDCD040CC7D5C1F9FCDDB48BA5C
Result of MalwareBytes scan. Whilst this was running Avast informed me that it had detected a Win32:Trojan-gen threat (gmer.exe), and quarantined it before it had a chance to run. Eset Online Scanner results to follow: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5173 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 23/11/2010 01:04:57 mbam-log-2010-11-23 (01-04-57).txt Scan type: Quick scan Objects scanned: 160578 Time elapsed: 22 minute(s), 58 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
I had thought I'd missed part of the Malware Bytes procedure, but I think that because no infections were detected the Show Results and Remove Detected part of the instructions is not required. Please advise if I've misunderstood. I'll run the Eset scan and post the results in the morning.
Results of ESET scan: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=e5129f545c497d4bb5578facb8da7ec1 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-11-23 05:21:50 # local_time=2010-11-23 05:21:50 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 405191 405191 0 0 # compatibility_mode=768 16777215 100 0 1086754 1086754 0 0 # compatibility_mode=1024 16777215 100 0 46332 46332 0 0 # compatibility_mode=8192 67108863 100 0 3768 3768 0 0 # scanned=418827 # found=8 # cleaned=8 # scan_time=13383 C:\Documents and Settings\Simon Hibbott\My Documents\My Downloads\Wordpress\themes\Branford 2\PRiNZ_BranfordMagazine_latest\outdoor_activities\footer.php PHP/Kryptik.AB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\Simon Hibbott\My Documents\My Downloads\Wordpress\themes\Branford 2\PRiNZ_BranfordMagazine_latest\outdoor_activities0.00\footer.php PHP/Kryptik.AB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\AGameIn.co.uk\branford theme\PRiNZ_BranfordMagazine_latest\Original PRiNZ_BranfordMagazine_latest\footer.php PHP/Kryptik.AB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\AGameIn.co.uk\branford theme\PRiNZ_BranfordMagazine_latest\PRiNZ_BranfordMagazine_latest\footer.php PHP/Kryptik.AB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\MartinDigby.com\blog\template\outdoor_activities0.00\footer.php PHP/Kryptik.AB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\Simon Hibbott\My Documents\Work in Progress\MartinDigby.com\blog\template\outdoor_activities1.00\footer.php PHP/Kryptik.AB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\i386\GTDownDE_87.ocx probably a variant of Win32/Adware.Agent.LCKGTSG application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000705.ocx probably a variant of Win32/Adware.Agent.LCKGTSG application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
Hi mowman,

Scan result follows. Computer is not noticeably faster - from boot to running Avast and opening Firefox and Outlook takes over 5 minutes. Having said that security rather than speed is my main concern. Is there any way for me to safely analyse the code identified in the footer.php file of a wordpress template as Kryptik.AB trojan (in the ESET scan) in order to determine whether it might be a false positive based on eval+base64_decode obfuscation as mentioned here http://www.chronoengine.com/forums/viewtop…f=3&t;=19831

I have a backup of the My Documents file on a disconnected external drive. Is there a safe way to check this for malware without compromising the work we've done to date?

Simon

OTL logfile created on: 23/11/2010 13:50:19 - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Simon Hibbott\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 525.00 Mb Available Physical Memory | 51.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 146.21 Gb Total Space | 92.61 Gb Free Space | 63.34% Space Free | Partition Type: NTFS

Computer Name: DIMENSION | User Name: Simon Hibbott | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Simon Hibbott\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe (Sony Ericsson Mobile Communications)
PRC - C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe (Sony Ericsson Mobile Communications)
PRC - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
PRC - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Kontiki\KService.exe ()
PRC - C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
PRC - C:\Program Files\Xerox One Touch\OneTouchMon.exe (Visioneer Inc)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Simon Hibbott\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll (Trusteer Ltd.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\ime\sptip.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)
MOD - C:\WINDOWS\ime\spgrmr.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (EmmaDevMgmtSvc) – C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe (Sony Ericsson Mobile Communications)
SRV - (EmmaUpdMgmtSvc) – C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe (Sony Ericsson Mobile Communications)
SRV - (OMSI download service) – C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe ()
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (KService) – C:\Program Files\Kontiki\KService.exe ()
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()


========== Driver Services (SafeList) ==========

DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (catchme) – C:\DOCUME~1\SIMONH~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (RapportCerberus_19917) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys (Trusteer Ltd.)
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\WINDOWS\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (RapportBuka) – C:\WINDOWS\system32\drivers\RapportBuka.sys (Trusteer Ltd.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ggsemc) – C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (s1018mdm) – C:\WINDOWS\system32\drivers\s1018mdm.sys (MCCI Corporation)
DRV - (s1018unic) Sony Ericsson Device 1018 USB Ethernet Emulation (WDM) – C:\WINDOWS\system32\drivers\s1018unic.sys (MCCI Corporation)
DRV - (s1018mgmt) Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s1018mgmt.sys (MCCI Corporation)
DRV - (s1018obex) – C:\WINDOWS\system32\drivers\s1018obex.sys (MCCI Corporation)
DRV - (s1018bus) Sony Ericsson Device 1018 driver (WDM) – C:\WINDOWS\system32\drivers\s1018bus.sys (MCCI Corporation)
DRV - (s1018nd5) Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS) – C:\WINDOWS\system32\drivers\s1018nd5.sys (MCCI Corporation)
DRV - (s1018mdfl) – C:\WINDOWS\system32\drivers\s1018mdfl.sys (MCCI Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (V0260VID) – C:\WINDOWS\system32\drivers\V0260Vid.sys (Creative Technology Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (k750obex) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (k750mgmt) – C:\WINDOWS\system32\drivers\k750mgmt.sys (MCCI)
DRV - (k750mdm) – C:\WINDOWS\system32\drivers\k750mdm.sys (MCCI)
DRV - (k750mdfl) – C:\WINDOWS\system32\drivers\k750mdfl.sys (MCCI)
DRV - (k750bus) Sony Ericsson 750 driver (WDM) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (CamAv) – C:\WINDOWS\system32\drivers\CamAv.sys (Samsung electronics, Inc)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (atapi) – C:\WINDOWS\system32\DRIVERS\atapi.sys ()
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (a347bus) – C:\WINDOWS\system32\DRIVERS\a347bus.sys ( )
DRV - (a347scsi) – C:\WINDOWS\System32\Drivers\a347scsi.sys ( )
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (Ca533av) – C:\WINDOWS\system32\drivers\Ca533av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk533.sys (USB BULK)
DRV - (DCamUSBSQTECH) Dual-Mode DSC(2770) – C:\WINDOWS\system32\drivers\SQCaptur.sys (Service & Quality Technology.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google UK"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.bbc.co.uk/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {d57c9ff1-6389-48fc-b770-f78bd89b6e8a}:1.33
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50370
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 19:03:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/17 09:25:47 | 000,000,000 | —D | M]

[2008/12/07 18:26:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Extensions
[2010/11/22 19:25:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\extensions
[2010/07/12 22:17:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/18 10:07:40 | 000,000,000 | —D | M] (SeoQuake) – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2009/07/01 13:47:41 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/01/20 09:21:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\extensions\{d57c9ff1-6389-48fc-b770-f78bd89b6e8a}
[2010/02/23 19:51:07 | 000,003,449 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Mozilla\Firefox\Profiles\q6tt40sn.default\searchplugins\google-uk.xml
[2010/11/22 19:25:58 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2004/11/13 03:36:20 | 000,005,120 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
[2010/10/15 23:12:10 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/10/15 23:12:10 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/10/15 23:12:11 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/10/15 23:12:11 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/11/22 15:33:01 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [C:\WINDOWS\system32\V0260Ext.ax] C:\WINDOWS\system32\V0260Ext.ax (Creative Technology Ltd.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\scansoft\paperport\IndexSearch.exe ()
O4 - HKLM..\Run: [OneTouch Monitor] C:\Program Files\Xerox One Touch\OneTouchMon.exe (Visioneer Inc)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
O4 - HKCU..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_19.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Reg Error: Key error.)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?LinkId=39204&clcid;=0x409 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} http://www.cult3d.com/download/cult.cab (Cult3D ActiveX Player)
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} https://moneymanager.egg.com/Pinsafe/accounttracking.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Yahoo! Audio UI1)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Reg Error: Key error.)
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} http://chat.yahoo.com/cab/yuplapp.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://www.warwick.ac.uk/newwebcam/AxisCamControl.ocx (Reg Error: Key error.)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.2
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/10/19 15:52:10 | 000,000,398 | —- | M] () - C:\AUTOEXEC.UP – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/23 01:36:01 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/11/22 14:45:51 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/11/22 13:48:53 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/11/22 13:48:53 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/11/22 13:48:53 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/11/22 13:48:53 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/11/22 13:48:31 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/11/22 13:44:53 | 000,000,000 | —D | C] – C:\Qoobox
[2010/11/20 01:25:24 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Simon Hibbott\Desktop\OTL.exe
[2010/11/18 10:09:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\My Documents\Hijackthis
[2010/11/18 10:05:38 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/11/17 13:09:09 | 000,000,000 | —D | C] – C:\Program Files\CamStudio
[2010/11/17 10:01:32 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/11/17 10:01:09 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/11/17 03:24:46 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Simon Hibbott\Recent
[2010/11/11 16:09:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\Application Data\SUPERAntiSpyware.com
[2010/11/11 16:09:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/11/11 16:09:32 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/11/10 18:20:36 | 000,017,744 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/11/10 18:20:35 | 000,165,584 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2010/11/10 18:20:34 | 000,023,376 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/11/10 18:20:32 | 000,046,672 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/11/10 18:20:29 | 000,100,176 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/11/10 18:20:29 | 000,094,544 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2010/11/10 18:20:28 | 000,028,880 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/11/10 18:20:03 | 000,167,592 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2010/11/10 18:20:03 | 000,038,848 | —- | C] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2010/11/10 12:46:15 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/11/10 12:46:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/11/10 12:15:36 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/11/09 19:17:08 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/09 19:17:04 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/09 10:19:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\My Documents\CCleaner
[2010/11/09 09:57:28 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/11/09 09:56:46 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie7
[2010/11/09 09:55:53 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\GARMIN
[2010/11/08 20:55:25 | 000,000,000 | —D | C] – C:\WINDOWS\ie8(2)
[2010/11/08 16:55:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\Application Data\ElevatedDiagnostics
[2010/11/08 16:53:19 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2010/11/08 13:41:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\Application Data\Malwarebytes
[2010/11/08 13:41:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/11/08 13:41:20 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/05 10:51:13 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/11/05 10:50:22 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Trusteer
[2010/11/05 10:46:04 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2010/11/01 19:25:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2010/10/29 13:22:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Simon Hibbott\My Documents\5BX
[2010/10/28 09:59:02 | 000,000,000 | —D | C] – C:\Program Files\Opera Mobile
[2010/06/12 18:02:04 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Simon Hibbott\Application Data\pcouffin.sys
[2005/09/27 11:57:26 | 000,160,640 | —- | C] ( ) – C:\WINDOWS\System32\drivers\a347bus.sys
[2005/09/27 11:57:26 | 000,005,248 | —- | C] ( ) – C:\WINDOWS\System32\drivers\a347scsi.sys
[30 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[1276 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/23 13:57:01 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/23 13:50:03 | 1844,724,736 | —- | M] () – C:\WINDOWS\outlook.pst
[2010/11/23 08:49:18 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/23 08:46:08 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/23 08:45:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/23 08:45:18 | 1071,697,920 | -HS- | M] () – C:\hiberfil.sys
[2010/11/23 00:06:12 | 003,913,898 | R— | M] () – C:\Documents and Settings\Simon Hibbott\Desktop\ComboFix.exe
[2010/11/22 15:33:01 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/11/22 14:46:01 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2010/11/20 01:43:03 | 000,288,107 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Desktop\gmer.zip
[2010/11/20 01:25:25 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Simon Hibbott\Desktop\OTL.exe
[2010/11/19 09:57:00 | 000,106,496 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Desktop\Health.xls
[2010/11/18 10:05:39 | 000,002,000 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Desktop\HiJackThis.lnk
[2010/11/18 09:43:38 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/11/17 15:04:14 | 000,040,960 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/17 13:09:14 | 000,000,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CamStudio.lnk
[2010/11/17 10:02:17 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/11/17 09:38:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/11/17 09:25:48 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/11/11 16:09:36 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/11/11 15:19:29 | 000,000,000 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\prvlcl.dat
[2010/11/11 11:16:28 | 000,000,792 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2010/11/10 18:20:37 | 000,001,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/11/10 18:20:30 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/11/10 12:22:39 | 000,574,048 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/10 12:15:38 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2010/11/09 19:18:31 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/08 01:20:24 | 000,089,088 | —- | M] () – C:\WINDOWS\MBR.exe
[2010/11/05 17:09:11 | 000,002,205 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/11/05 15:22:02 | 000,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2010/10/31 09:31:00 | 000,450,218 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/10/31 09:31:00 | 000,074,842 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/10/28 21:54:49 | 000,000,624 | —- | M] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/10/28 21:54:49 | 000,000,606 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/10/28 09:59:08 | 000,001,575 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera Widgets Mobile Emulator.lnk
[2010/10/28 09:59:08 | 000,000,665 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera Mobile.lnk
[1276 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/22 14:46:00 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/11/22 14:45:56 | 000,260,272 | RHS- | C] () – C:\cmldr
[2010/11/22 13:48:53 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/11/22 13:48:53 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/11/22 13:48:53 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/11/22 13:48:53 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/11/22 13:48:53 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/11/22 13:35:09 | 003,913,898 | R— | C] () – C:\Documents and Settings\Simon Hibbott\Desktop\ComboFix.exe
[2010/11/22 10:53:41 | 1071,697,920 | -HS- | C] () – C:\hiberfil.sys
[2010/11/20 01:43:01 | 000,288,107 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Desktop\gmer.zip
[2010/11/18 10:05:39 | 000,002,000 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Desktop\HiJackThis.lnk
[2010/11/17 13:09:14 | 000,000,689 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CamStudio.lnk
[2010/11/17 10:02:17 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/11/11 16:09:36 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/11/10 18:20:37 | 000,001,700 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/11/10 12:15:38 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2010/11/09 19:17:11 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/28 09:59:08 | 000,001,575 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Opera Widgets Mobile Emulator.lnk
[2010/10/28 09:59:08 | 000,000,665 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Opera Mobile.lnk
[2010/06/12 18:02:17 | 000,000,034 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Application Data\pcouffin.log
[2010/06/12 18:02:04 | 000,007,887 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Application Data\pcouffin.cat
[2010/06/12 18:02:04 | 000,001,144 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Application Data\pcouffin.inf
[2009/06/24 21:59:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\prvlcl.dat
[2008/06/04 11:06:40 | 000,017,403 | —- | C] () – C:\WINDOWS\wwdslcfg.ini
[2007/11/20 11:48:55 | 000,000,136 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\fusioncache.dat
[2007/07/03 10:18:21 | 000,021,944 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Application Data\Microsoft Excel.ADR
[2007/06/09 09:43:26 | 000,536,576 | R— | C] () – C:\WINDOWS\System32\mcs_core.dll
[2007/06/09 09:43:26 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\mcs_vfw.dll
[2007/06/09 09:43:16 | 000,147,456 | R— | C] () – C:\WINDOWS\mcs_vfw.dll
[2007/06/09 09:43:15 | 000,536,576 | R— | C] () – C:\WINDOWS\mcs_core.dll
[2007/06/09 09:43:12 | 000,057,344 | R— | C] () – C:\WINDOWS\HAJEInstall.dll
[2006/06/20 16:19:27 | 000,001,703 | R— | C] () – C:\WINDOWS\CA533A.INI
[2006/04/18 15:09:13 | 000,000,457 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2006/04/18 15:01:04 | 000,011,934 | —- | C] () – C:\WINDOWS\System32\Pixpnr.dll
[2006/04/18 15:01:03 | 000,012,126 | —- | C] () – C:\WINDOWS\System32\Pixpcz.dll
[2006/04/18 14:54:01 | 000,000,752 | —- | C] () – C:\WINDOWS\maxlink.ini
[2006/04/18 14:52:47 | 000,000,663 | —- | C] () – C:\WINDOWS\fe.INI
[2006/04/14 10:09:52 | 000,002,917 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/21 10:39:39 | 000,000,414 | —- | C] () – C:\WINDOWS\dellstat.ini
[2006/02/04 15:26:04 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2006/01/13 13:16:47 | 000,000,044 | —- | C] () – C:\WINDOWS\liveup.ini
[2005/12/27 17:34:35 | 000,001,860 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/11/21 20:31:13 | 000,000,333 | —- | C] () – C:\WINDOWS\lexstat.ini
[2005/11/16 18:59:41 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2005/09/29 16:19:46 | 000,007,912 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2005/09/27 13:12:55 | 000,777,728 | —- | C] () – C:\WINDOWS\System32\SSLSVC.DLL
[2005/09/27 13:12:54 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\lang_cfml.dll
[2005/09/27 13:12:54 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2005/09/27 13:12:54 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\cfmsg.dll
[2005/09/27 13:12:54 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2005/09/27 13:12:53 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\xml_datagrove.dll
[2005/09/14 18:03:16 | 000,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/06/24 09:10:15 | 000,040,960 | —- | C] () – C:\Documents and Settings\Simon Hibbott\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/03/20 08:59:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/03/20 08:58:16 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/03/20 08:34:46 | 000,000,283 | —- | C] () – C:\WINDOWS\System32\dlbcplc.ini
[2005/03/20 08:33:14 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2005/03/20 08:32:48 | 000,000,375 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/02/11 17:38:14 | 000,749,568 | —- | C] () – C:\WINDOWS\System32\SWFGen.dll
[2004/09/15 22:03:14 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 13:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:52 | 000,004,346 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/03 22:59:44 | 000,095,360 | —- | C] () – C:\WINDOWS\System32\drivers\atapi.sys
[2003/08/18 14:46:38 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\LXBKLCNP.DLL
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/11/13 19:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxbkvs.dll
[2002/09/13 15:40:06 | 000,000,266 | —- | C] () – C:\WINDOWS\System32\lxbkcoin.ini
[2002/08/09 12:15:16 | 000,101,376 | —- | C] () – C:\WINDOWS\System32\Welsof32.dll
[2002/01/08 15:57:34 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\Jpeg32.dll
[1997/07/10 23:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/10 23:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/10 23:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL

========== Alternate Data Streams ==========

@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:661DFA1C

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI