Nick23
Topic Starter
Hello,
I have Windows XP - Vienna (or some kind of weird version of windows) My computer started acting weird about a week or so ago. I did a Spybot scan and it came up with some viruses so i used the fix on it hoping to fix it, but it didn't. Every time I go to get into a program or try to do anything a box comes up telling me that that file or program is infected (ex. rundll32.exe is infected) and wants me to run a scan. If I run the scan it wants me to purchase antivirus software to supposedly fix everything. So, I've been clicking the not run and keep computer infected to get it off my screen. Also a box keep popping up at the bottom right corner wanting me to purchase antivirus software. And The internet opens automatically and goes to prono or viagra sites, so I close them down. I had to go into tast manager and end a couple processes ( I know I shouldn't do that but it was the only way I could get online to get some help) I ended things that didn't look right like something that started with psg —-(something or other).exe (I dont remember the rest) also hkcmd.exe, svchost.exe and a thing i have on my desktop called vienna. Once I boot up the computer I only have about 10 seconds (if that) to do anything before the viruses take over the whole computer, which doesn't give me much time to do anything. I also did a Malwarebytes scan and it came up with some Trojans but I quarentined them and might have tried to delete them, but I had to go into safe made and do the scan because I couldn't get into it otherwise. But even though I did those scans and they found things and supposedely fixed it, my computer is still doing the same thing….not letting me get into ANYTHING and wanting me to purchase some antivirus software program. I did the OTL scan and I did what it said but it only gave me one report which I am including here —- Can you please try to help me, please?! Thank you! Nick
OTL logfile created on: 12/14/2010 3:40:00 AM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Nick\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.00 Mb Total Physical Memory | 164.00 Mb Available Physical Memory | 33.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 128.16 Gb Free Space | 68.79% Space Free | Partition Type: NTFS
Computer Name: XPWINDOWS7 | User Name: Nick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Nick\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe (DivX, LLC)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Online Vault\OnlineVault.exe (Xacti Corporation)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows7\VisualTaskTips\VisualTaskTips.exe (VisualTaskTips.com)
PRC - C:\Program Files\RocketDock\RocketDock.exe ()
PRC - C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
PRC - C:\Program Files\Windows7\RunMe\RunMe.exe (KSoft)
PRC - C:\WINDOWS\system32\lxctcoms.exe ( )
PRC - C:\Program Files\Lexmark 5400 Series\lxctmon.exe ()
PRC - C:\Program Files\Windows7\Analog Clock\AnalogClock.exe (Excode Software)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Nick\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Windows7\VisualTaskTips\VttHooks.dll ()
MOD - C:\Program Files\RocketDock\RocketDock.dll ()
========== Win32 Services (SafeList) ==========
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe File not found
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (DfSdkS) – C:\Documents and Settings\Nick\My Documents\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe (mst software GmbH, Germany)
SRV - (lxct_device) – C:\WINDOWS\System32\lxctcoms.exe ( )
========== Driver Services (SafeList) ==========
DRV - (RimUsb) – C:\WINDOWS\System32\Drivers\RimUsb.sys File not found
DRV - (mcdbus) – C:\WINDOWS\System32\DRIVERS\mcdbus.sys File not found
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (VClone) – C:\WINDOWS\system32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (es1371) Creative AudioPCI (ES1371,ES1373) (WDM) – C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=ZUGO&form;=ZGAPHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:59274
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.1.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.23
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4cbb8f56&v;=6.010.023.001&i;=23&tp;=ab&iy;=&ychte;=us&lng;=en-US&q;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 5555
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2010/02/24 13:19:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/04/21 16:10:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2010/12/10 17:55:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2010/12/10 17:55:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/11 20:33:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/13 07:34:34 | 000,000,000 | —D | M]
[2010/04/02 01:24:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla\Extensions
[2010/04/02 01:24:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Nick\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/13 16:19:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla\Extensions\[removed]
[2010/12/14 03:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\4zniteye.default\extensions
[2010/10/16 23:53:22 | 000,000,000 | —D | M] (BitComet Video Downloader) – C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\4zniteye.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010/12/06 18:11:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\4zniteye.default\extensions\[removed]
[2010/12/11 18:20:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\4zniteye.default\extensions\[removed]
[2010/12/06 08:06:40 | 000,001,919 | —- | M] () – C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\4zniteye.default\searchplugins\bing-zugo.xml
[2010/12/11 18:02:02 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/12/11 18:01:51 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/12/03 14:35:08 | 000,025,048 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/12/03 14:35:08 | 000,140,248 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2010/12/03 14:35:08 | 000,066,520 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2010/12/03 12:36:32 | 000,001,394 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/12/03 12:36:32 | 000,002,193 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/12/03 12:36:32 | 000,001,534 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/12/03 12:36:32 | 000,002,344 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2010/12/03 12:36:32 | 000,002,371 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/12/03 12:36:32 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/12/03 12:36:32 | 000,001,096 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml
O1 HOSTS File: ([2010/12/11 00:53:16 | 000,427,122 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.127.227 antiviraprof-2009.microsoft.com
O1 - Hosts: 91.212.127.227 antiviraprof2009.com
O1 - Hosts: 91.212.127.227 www.antiviraprof2009.com
O1 - Hosts: 78.159.110.45 www.google.com
O1 - Hosts: 78.159.110.45 www.google.de
O1 - Hosts: 78.159.110.45 www.google.fr
O1 - Hosts: 78.159.110.45 www.google.co.uk
O1 - Hosts: 78.159.110.45 www.google.com.br
O1 - Hosts: 78.159.110.45 www.google.it
O1 - Hosts: 78.159.110.45 www.google.es
O1 - Hosts: 78.159.110.45 www.google.co.jp
O1 - Hosts: 78.159.110.45 www.google.com.mx
O1 - Hosts: 78.159.110.45 www.google.ca
O1 - Hosts: 78.159.110.45 www.google.com.au
O1 - Hosts: 78.159.110.45 www.google.nl
O1 - Hosts: 78.159.110.45 www.google.co.za
O1 - Hosts: 78.159.110.45 www.google.be
O1 - Hosts: 78.159.110.45 www.google.gr
O1 - Hosts: 78.159.110.45 www.google.at
O1 - Hosts: 78.159.110.45 www.google.se
O1 - Hosts: 78.159.110.45 www.google.ch
O1 - Hosts: 78.159.110.45 www.google.pt
O1 - Hosts: 78.159.110.45 www.google.dk
O1 - Hosts: 14735 more lines…
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Documents and Settings\Nick\My Documents\BitComet\tools\BitCometBHO_1.4.8.11.dll (BitComet)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (no name) - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - No CLSID value found.
O2 - BHO: (no name) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - No CLSID value found.
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe File not found
O4 - HKLM..\Run: [AGRSMMSG] C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe File not found
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Documents and Settings\Nick\My Documents\Programs\iTunes.Resources\Itunes\iTunesHelper.exe File not found
O4 - HKLM..\Run: [KBD] C:\HP\KBD\kbd.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [KRun] C:\Program Files\Windows7\RunMe\RunMe.exe (KSoft)
O4 - HKLM..\Run: [LXCTCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.DLL (Lexmark International Inc.)
O4 - HKLM..\Run: [lxctmon.exe] C:\Program Files\Lexmark 5400 Series\lxctmon.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Viena Explorer] C:\Program Files\Windows7\Vienna Explorer\Vienna Explorer.exe ()
O4 - HKLM..\Run: [Visual Task Tips] C:\Program Files\Windows7\VisualTaskTips\VisualTaskTips.exe (VisualTaskTips.com)
O4 - HKCU..\Run: [AnalogClock] C:\Program Files\Windows7\Analog Clock\AnalogClock.exe (Excode Software)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKCU..\Run: [gnqtkxsx] C:\DOCUME~1\Nick\LOCALS~1\Temp\cgggjetiy\pgsgaovaffm.exe File not found
O4 - HKCU..\Run: [OnlineVault] C:\Program Files\Online Vault\OnlineVault.exe (Xacti Corporation)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKCU..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [TransBar] C:\Program Files\Windows7\TransBar\TransBar.exe (AKSoftware)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk = C:\Documents and Settings\Nick\My Documents\Programs\WSTrayDictMode.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMFUprogramsList = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O8 - Extra context menu item: &D;&ownload; &with; BitComet - C:\Documents and Settings\Nick\My Documents\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all with BitComet - C:\Documents and Settings\Nick\My Documents\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Expression\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Documents and Settings\Nick\My Documents\BitComet\tools\BitCometBHO_1.4.8.11.dll (BitComet)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O16 - DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} http://intel-drv-cdn.systemrequirementslab…reqlab_srlx.cab (System Requirements Lab Class)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro2.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - c:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Nick\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Nick\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/11 09:43:34 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\PROGRA~1\AVG\AVG10\avgchsvx.exe File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\PROGRA~1\AVG\AVG10\avgrsx.exe File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183528496136192)
========== Files/Folders - Created Within 30 Days ==========
[2010/12/13 07:23:13 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/12/13 01:21:54 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/12 19:30:33 | 190,219,598 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Nick\My Documents\MSOfficePro2007X12-30196.exe.part
[2010/12/12 19:29:47 | 407,010,384 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Nick\My Documents\MSOfficePro2007X12-30196.exe
[2010/12/12 19:29:31 | 003,412,768 | —- | C] (Crawler, LLC ) – C:\Documents and Settings\Nick\My Documents\OnlineVault_Setup.exe
[2010/12/12 19:29:26 | 005,373,672 | —- | C] (Crawler.Com ) – C:\Documents and Settings\Nick\My Documents\WebSecurityGuardSetup.exe
[2010/12/12 19:27:06 | 407,010,384 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Nick\Desktop\MSOfficePro2007X12-30196.exe
[2010/12/12 19:24:59 | 000,000,000 | —D | C] – C:\Program Files\Online Vault
[2010/12/12 19:23:48 | 000,000,000 | —D | C] – C:\Program Files\System Protect
[2010/12/12 19:18:02 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Nick\Recent
[2010/12/12 00:18:24 | 000,603,648 | —- | C] (PPtJCIHx) – C:\Documents and Settings\Nick\Local Settings\Application Data\syssvc.exe
[2010/12/11 23:30:56 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Expression
[2010/12/11 21:33:23 | 000,000,000 | —D | C] – C:\Program Files\DAEMON Tools
[2010/12/11 21:19:30 | 000,030,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mdimon.dll
[2010/12/11 21:02:09 | 000,032,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msonpmon.dll
[2010/12/11 20:56:33 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2010/12/11 20:20:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\CCleaner
[2010/12/11 18:53:56 | 000,000,000 | —D | C] – C:\Program Files\MagicISO
[2010/12/11 18:01:50 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/12/11 16:59:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\Local Settings\Application Data\PCHealth
[2010/12/11 16:22:29 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2010/12/11 16:22:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2010/12/11 16:09:57 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2010/12/11 16:05:17 | 000,000,000 | RH-D | C] – C:\MSOCache
[2010/12/11 01:35:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\Finished Movies
[2010/12/10 23:15:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/12/10 23:12:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\Spybot - Search & Destroy
[2010/12/10 23:10:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\Malwarebytes' Anti-Malware
[2010/12/10 22:47:31 | 000,000,000 | —D | C] – C:\Downloads
[2010/12/10 22:35:22 | 000,028,160 | —- | C] (mst software GmbH, Germany) – C:\WINDOWS\System32\DfSdkBt.exe
[2010/12/10 22:12:08 | 000,000,000 | —D | C] – C:\Program Files\Security Programs
[2010/12/10 17:55:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\Application Data\Local
[2010/12/10 17:55:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\Application Data\DivX
[2010/12/10 17:54:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\DivX Movies
[2010/12/10 17:54:16 | 000,126,448 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxinsi64.exe
[2010/12/10 17:54:16 | 000,123,888 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxcpyi64.exe
[2010/12/10 17:54:16 | 000,068,592 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxinsa64.exe
[2010/12/10 17:54:16 | 000,068,080 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxcpya64.exe
[2010/12/10 17:54:16 | 000,009,200 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys
[2010/12/10 17:54:16 | 000,009,072 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys
[2010/12/10 17:54:15 | 002,120,176 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxsfs.dll
[2010/12/10 17:54:15 | 000,567,792 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxdrv.dll
[2010/12/10 17:54:15 | 000,133,616 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxafs.dll
[2010/12/10 17:54:15 | 000,100,848 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\vxblock.dll
[2010/12/10 17:54:15 | 000,072,176 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxhpinst.exe
[2010/12/10 17:54:14 | 000,440,816 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxwave.dll
[2010/12/10 17:54:14 | 000,219,632 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxmas.dll
[2010/12/10 17:54:13 | 000,698,864 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\px.dll
[2010/12/10 17:53:14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2010/12/10 17:52:18 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2010/12/10 17:49:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DivX
[2010/12/10 17:12:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\Nero 7.10.1.0
[2010/12/09 17:40:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\hIjGo01570
[2010/12/08 03:00:50 | 000,000,000 | —D | C] – C:\WINDOWS\System32\dumps
[2010/12/07 23:32:22 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/12/07 23:29:19 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/12/07 23:27:33 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/12/07 23:25:50 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2010/12/07 23:23:55 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/12/06 08:05:09 | 000,000,000 | —D | C] – C:\Program Files\Quick Web Player
[2010/12/03 19:00:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\Local Settings\Application Data\PackageAware
[2010/12/03 18:53:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\Ashampoo
[2010/12/03 17:02:51 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/03 17:02:48 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/03 15:55:08 | 000,000,000 | —D | C] – C:\Program Files\Template
[2010/12/03 15:54:28 | 000,000,000 | —D | C] – C:\Program Files\Data Migration Wizard
[2010/12/03 15:54:27 | 000,000,000 | —D | C] – C:\Program Files\Transaction Manager
[2010/12/03 15:54:27 | 000,000,000 | —D | C] – C:\Program Files\Action Engine
[2010/03/01 17:21:32 | 000,323,584 | —- | C] ( ) – C:\WINDOWS\System32\LXCThcp.dll
[2010/03/01 17:21:31 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\lxctinpa.dll
[2010/03/01 17:21:31 | 000,397,312 | —- | C] ( ) – C:\WINDOWS\System32\lxctiesc.dll
[2010/03/01 17:21:30 | 001,224,704 | —- | C] ( ) – C:\WINDOWS\System32\lxctserv.dll
[2010/03/01 17:21:30 | 000,991,232 | —- | C] ( ) – C:\WINDOWS\System32\lxctusb1.dll
[2010/03/01 17:21:29 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxctpmui.dll
[2010/03/01 17:21:29 | 000,585,728 | —- | C] ( ) – C:\WINDOWS\System32\lxctlmpm.dll
[2010/03/01 17:21:29 | 000,163,840 | —- | C] ( ) – C:\WINDOWS\System32\lxctprox.dll
[2010/03/01 17:21:29 | 000,094,208 | —- | C] ( ) – C:\WINDOWS\System32\lxctpplc.dll
[2010/03/01 17:21:27 | 000,696,320 | —- | C] ( ) – C:\WINDOWS\System32\lxcthbn3.dll
[2010/03/01 17:21:25 | 000,684,032 | —- | C] ( ) – C:\WINDOWS\System32\lxctcomc.dll
[2010/03/01 17:21:25 | 000,421,888 | —- | C] ( ) – C:\WINDOWS\System32\lxctcomm.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/14 03:01:01 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/12/14 02:46:40 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/14 02:46:29 | 000,000,244 | —- | M] () – C:\WINDOWS\tasks\SpeedOptimizer Startup.job
[2010/12/14 02:46:18 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/14 01:52:21 | 000,001,387 | —- | M] () – C:\Documents and Settings\Nick\1.bak
[2010/12/13 08:02:11 | 000,352,176 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/13 01:22:01 | 000,000,714 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/12 19:28:44 | 000,000,759 | —- | M] () – C:\Documents and Settings\All Users\Desktop\System Protect.lnk
[2010/12/12 19:27:16 | 000,000,527 | —- | M] () – C:\Documents and Settings\Nick\My Documents\SystemProtect_Setup.lnk
[2010/12/12 19:25:19 | 000,000,751 | —- | M] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Online Vault.lnk
[2010/12/12 19:25:19 | 000,000,733 | —- | M] () – C:\Documents and Settings\Nick\Desktop\Online Vault.lnk
[2010/12/12 19:23:51 | 000,012,288 | —- | M] () – C:\WINDOWS\System32\drivers\sp_prot.sys
[2010/12/12 00:18:25 | 000,603,648 | —- | M] (PPtJCIHx) – C:\Documents and Settings\Nick\Local Settings\Application Data\syssvc.exe
[2010/12/12 00:03:02 | 407,010,384 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Nick\My Documents\MSOfficePro2007X12-30196.exe
[2010/12/12 00:03:02 | 407,010,384 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Nick\Desktop\MSOfficePro2007X12-30196.exe
[2010/12/12 00:00:50 | 190,219,598 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Nick\My Documents\MSOfficePro2007X12-30196.exe.part
[2010/12/11 21:33:23 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DAEMON Tools.lnk
[2010/12/11 20:20:17 | 000,000,650 | —- | M] () – C:\Documents and Settings\Nick\Desktop\CCleaner.lnk
[2010/12/11 18:53:57 | 000,001,486 | —- | M] () – C:\Documents and Settings\Nick\Desktop\MagicISO.lnk
[2010/12/11 18:01:54 | 000,001,626 | —- | M] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/12/11 18:01:54 | 000,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/12/11 13:12:53 | 000,031,744 | —- | M] () – C:\Documents and Settings\Nick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/11 13:03:42 | 000,001,576 | —- | M] () – C:\Documents and Settings\Nick\Desktop\DivX Movies.lnk
[2010/12/11 01:30:34 | 000,001,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/11 00:53:16 | 000,427,122 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/10 22:35:24 | 000,002,133 | —- | M] () – C:\Documents and Settings\All Users\Desktop\One-Click-Optimizer.lnk
[2010/12/10 22:35:24 | 000,001,069 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ashampoo WinOptimizer 2010 Advanced.lnk
[2010/12/10 22:35:24 | 000,001,019 | —- | M] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo WinOptimizer 2010 Advanced.lnk
[2010/12/10 22:25:21 | 000,000,650 | —- | M] () – C:\Documents and Settings\Nick\Desktop\BitComet.lnk
[2010/12/10 17:54:46 | 000,000,793 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/12/10 11:18:24 | 000,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Desktop Manager.lnk
[2010/12/10 10:23:13 | 101,497,532 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2010/12/07 23:30:02 | 000,001,610 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/12/07 23:27:40 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/05 02:46:00 | 000,000,454 | —- | M] () – C:\WINDOWS\tasks\Driver Robot.job
[2010/12/03 01:36:57 | 000,000,422 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
[2010/11/17 23:22:58 | 000,000,124 | —- | M] () – C:\Documents and Settings\Nick\Desktop\Control Panel.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/13 01:22:01 | 000,000,714 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/12 19:48:39 | 000,001,387 | —- | C] () – C:\Documents and Settings\Nick\1.bak
[2010/12/12 19:27:16 | 000,000,527 | —- | C] () – C:\Documents and Settings\Nick\My Documents\SystemProtect_Setup.lnk
[2010/12/12 19:25:19 | 000,000,751 | —- | C] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Online Vault.lnk
[2010/12/12 19:25:19 | 000,000,733 | —- | C] () – C:\Documents and Settings\Nick\Desktop\Online Vault.lnk
[2010/12/12 19:24:39 | 000,000,759 | —- | C] () – C:\Documents and Settings\All Users\Desktop\System Protect.lnk
[2010/12/12 19:23:51 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\drivers\sp_prot.sys
[2010/12/11 21:33:23 | 000,000,702 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DAEMON Tools.lnk
[2010/12/11 20:20:17 | 000,000,650 | —- | C] () – C:\Documents and Settings\Nick\Desktop\CCleaner.lnk
[2010/12/11 18:53:57 | 000,001,486 | —- | C] () – C:\Documents and Settings\Nick\Desktop\MagicISO.lnk
[2010/12/11 18:01:54 | 000,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/12/10 23:26:05 | 005,792,131 | —- | C] () – C:\Documents and Settings\Nick\Desktop\SpyBot Startup.tnfo
[2010/12/10 22:35:24 | 000,002,133 | —- | C] () – C:\Documents and Settings\All Users\Desktop\One-Click-Optimizer.lnk
[2010/12/10 22:35:24 | 000,001,069 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ashampoo WinOptimizer 2010 Advanced.lnk
[2010/12/10 22:35:24 | 000,001,019 | —- | C] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo WinOptimizer 2010 Advanced.lnk
[2010/12/10 17:55:43 | 000,001,576 | —- | C] () – C:\Documents and Settings\Nick\Desktop\DivX Movies.lnk
[2010/12/10 17:54:46 | 000,000,793 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/12/07 23:33:23 | 000,001,690 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/07 23:30:02 | 000,001,610 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/12/07 23:27:40 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/03 15:55:13 | 000,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Desktop Manager.lnk
[2010/11/17 23:22:58 | 000,000,124 | —- | C] () – C:\Documents and Settings\Nick\Desktop\Control Panel.lnk
[2010/04/11 17:12:02 | 000,000,664 | —- | C] () – C:\Documents and Settings\Nick\Local Settings\Application Data\FASTWiz.html
[2010/04/11 17:11:04 | 000,000,076 | —- | C] () – C:\Documents and Settings\Nick\Local Settings\Application Data\FASTWiz.log
[2010/03/01 17:26:30 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxctvs.dll
[2010/03/01 17:26:22 | 000,331,776 | —- | C] () – C:\WINDOWS\System32\lxctcoin.dll
[2010/03/01 17:25:45 | 000,692,224 | —- | C] () – C:\WINDOWS\System32\lxctdrs.dll
[2010/03/01 17:25:45 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\lxctcaps.dll
[2010/03/01 17:25:44 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\lxctcnv4.dll
[2010/03/01 17:24:42 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\lxctpmon.dll
[2010/03/01 17:24:42 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\LXCTFXPU.DLL
[2010/03/01 17:21:32 | 000,274,432 | —- | C] () – C:\WINDOWS\System32\LXCTinst.dll
[2010/03/01 17:21:27 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\lxctgrd.dll
[2009/10/26 12:55:08 | 000,691,696 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/10/03 01:43:23 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2009/10/03 01:43:23 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2009/10/03 01:43:23 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2009/09/29 22:06:06 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\viscomtran.dll
[2009/09/29 22:06:05 | 006,963,712 | —- | C] () – C:\WINDOWS\System32\videotrans.dll
[2009/09/29 22:06:05 | 000,452,608 | —- | C] () – C:\WINDOWS\System32\videoformat.dll
[2009/09/29 22:06:05 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/09/29 22:06:05 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2009/09/29 22:06:05 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\viscomgifenc.dll
[2009/09/29 22:06:05 | 000,154,624 | —- | C] () – C:\WINDOWS\System32\imgscaler.dll
[2009/09/29 22:06:05 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\img_utils.dll
[2009/09/29 22:06:05 | 000,019,456 | —- | C] () – C:\WINDOWS\System32\videocore.dll
[2009/09/02 15:38:13 | 000,307,200 | —- | C] () – C:\WINDOWS\System32\AscSQLite.dll
[2009/08/19 02:14:01 | 000,031,744 | —- | C] () – C:\Documents and Settings\Nick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/11 16:33:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/05/18 19:46:40 | 000,000,215 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
========== LOP Check ==========
[2010/03/01 17:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\5400 Series
[2009/09/29 22:22:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2010/10/18 00:17:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/12/13 07:24:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/17 18:43:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2010/06/01 01:01:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverScanner
[2010/12/09 17:41:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\hIjGo01570
[2009/10/06 17:19:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Innovative Solutions
[2010/12/13 07:20:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/08/18 23:54:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/10/06 18:33:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/04/20 01:36:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/08/11 01:56:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Slapdash Games
[2009/11/08 20:01:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpeedBit
[2009/11/08 20:01:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/13 03:33:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Toolbar4
[2010/04/07 16:58:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/18 12:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/01 17:27:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\5400 Series
[2009/09/29 22:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Ashampoo
[2010/10/17 18:44:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\AVG10
[2010/12/11 23:05:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\BitComet
[2009/09/16 18:31:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\BitCometLite
[2009/10/06 17:04:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Blitware
[2009/08/16 23:05:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\com.adobe.ExMan
[2009/08/14 12:54:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\GetRightToGo
[2010/12/10 17:55:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Local
[2010/04/01 16:07:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\MSNInstaller
[2010/02/28 18:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\OpenOffice.org
[2009/08/11 09:53:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\OtakuSoftware
[2010/04/13 17:43:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Research In Motion
[2009/08/13 23:37:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\RiotBall_demo
[2009/08/29 01:18:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\TigerPlayer
[2010/12/03 19:01:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Uniblue
[2009/08/13 22:49:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\uTorrent
[2010/12/05 02:46:00 | 000,000,454 | —- | M] () – C:\WINDOWS\Tasks\Driver Robot.job
[2010/03/28 13:01:14 | 000,000,402 | —- | M] () – C:\WINDOWS\Tasks\peaks.job
[2010/12/14 03:01:01 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2010/12/14 02:46:29 | 000,000,244 | —- | M] () – C:\WINDOWS\Tasks\SpeedOptimizer Startup.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/08/11 09:43:34 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/08/11 09:36:34 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/08/11 09:43:34 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/08/11 09:43:34 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/08/11 09:43:34 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 10:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 12:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/14 02:46:15 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/08/11 09:43:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/01/17 20:25:06 | 000,118,784 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxctdrpp.dll
[2006/10/26 19:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/08/11 16:30:41 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/08/11 16:30:41 | 001,085,440 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/08/11 16:30:41 | 000,925,696 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/08/11 09:43:40 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/11 09:53:52 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/08/11 09:53:51 | 000,000,079 | —- | M] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/12/12 00:03:02 | 407,010,384 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Nick\Desktop\MSOfficePro2007X12-30196.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-03 23:45:41
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CD060F93
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D74B6CF5
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60A4BB64
< End of report >
Please help, Thank you! ………………
I have Windows XP - Vienna (or some kind of weird version of windows) My computer started acting weird about a week or so ago. I did a Spybot scan and it came up with some viruses so i used the fix on it hoping to fix it, but it didn't. Every time I go to get into a program or try to do anything a box comes up telling me that that file or program is infected (ex. rundll32.exe is infected) and wants me to run a scan. If I run the scan it wants me to purchase antivirus software to supposedly fix everything. So, I've been clicking the not run and keep computer infected to get it off my screen. Also a box keep popping up at the bottom right corner wanting me to purchase antivirus software. And The internet opens automatically and goes to prono or viagra sites, so I close them down. I had to go into tast manager and end a couple processes ( I know I shouldn't do that but it was the only way I could get online to get some help) I ended things that didn't look right like something that started with psg —-(something or other).exe (I dont remember the rest) also hkcmd.exe, svchost.exe and a thing i have on my desktop called vienna. Once I boot up the computer I only have about 10 seconds (if that) to do anything before the viruses take over the whole computer, which doesn't give me much time to do anything. I also did a Malwarebytes scan and it came up with some Trojans but I quarentined them and might have tried to delete them, but I had to go into safe made and do the scan because I couldn't get into it otherwise. But even though I did those scans and they found things and supposedely fixed it, my computer is still doing the same thing….not letting me get into ANYTHING and wanting me to purchase some antivirus software program. I did the OTL scan and I did what it said but it only gave me one report which I am including here —- Can you please try to help me, please?! Thank you! Nick
OTL logfile created on: 12/14/2010 3:40:00 AM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Nick\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.00 Mb Total Physical Memory | 164.00 Mb Available Physical Memory | 33.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 128.16 Gb Free Space | 68.79% Space Free | Partition Type: NTFS
Computer Name: XPWINDOWS7 | User Name: Nick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Nick\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe (DivX, LLC)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Online Vault\OnlineVault.exe (Xacti Corporation)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows7\VisualTaskTips\VisualTaskTips.exe (VisualTaskTips.com)
PRC - C:\Program Files\RocketDock\RocketDock.exe ()
PRC - C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
PRC - C:\Program Files\Windows7\RunMe\RunMe.exe (KSoft)
PRC - C:\WINDOWS\system32\lxctcoms.exe ( )
PRC - C:\Program Files\Lexmark 5400 Series\lxctmon.exe ()
PRC - C:\Program Files\Windows7\Analog Clock\AnalogClock.exe (Excode Software)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Nick\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Windows7\VisualTaskTips\VttHooks.dll ()
MOD - C:\Program Files\RocketDock\RocketDock.dll ()
========== Win32 Services (SafeList) ==========
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe File not found
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (DfSdkS) – C:\Documents and Settings\Nick\My Documents\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe (mst software GmbH, Germany)
SRV - (lxct_device) – C:\WINDOWS\System32\lxctcoms.exe ( )
========== Driver Services (SafeList) ==========
DRV - (RimUsb) – C:\WINDOWS\System32\Drivers\RimUsb.sys File not found
DRV - (mcdbus) – C:\WINDOWS\System32\DRIVERS\mcdbus.sys File not found
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (VClone) – C:\WINDOWS\system32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (es1371) Creative AudioPCI (ES1371,ES1373) (WDM) – C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=ZUGO&form;=ZGAPHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:59274
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.1.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.23
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4cbb8f56&v;=6.010.023.001&i;=23&tp;=ab&iy;=&ychte;=us&lng;=en-US&q;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 5555
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2010/02/24 13:19:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/04/21 16:10:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2010/12/10 17:55:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2010/12/10 17:55:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/11 20:33:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/13 07:34:34 | 000,000,000 | —D | M]
[2010/04/02 01:24:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla\Extensions
[2010/04/02 01:24:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Nick\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/13 16:19:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla\Extensions\[removed]
[2010/12/14 03:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\4zniteye.default\extensions
[2010/10/16 23:53:22 | 000,000,000 | —D | M] (BitComet Video Downloader) – C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\4zniteye.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010/12/06 18:11:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\4zniteye.default\extensions\[removed]
[2010/12/11 18:20:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\4zniteye.default\extensions\[removed]
[2010/12/06 08:06:40 | 000,001,919 | —- | M] () – C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\4zniteye.default\searchplugins\bing-zugo.xml
[2010/12/11 18:02:02 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/12/11 18:01:51 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/12/03 14:35:08 | 000,025,048 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/12/03 14:35:08 | 000,140,248 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2010/12/03 14:35:08 | 000,066,520 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2010/12/03 12:36:32 | 000,001,394 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/12/03 12:36:32 | 000,002,193 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/12/03 12:36:32 | 000,001,534 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/12/03 12:36:32 | 000,002,344 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2010/12/03 12:36:32 | 000,002,371 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/12/03 12:36:32 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/12/03 12:36:32 | 000,001,096 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml
O1 HOSTS File: ([2010/12/11 00:53:16 | 000,427,122 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.127.227 antiviraprof-2009.microsoft.com
O1 - Hosts: 91.212.127.227 antiviraprof2009.com
O1 - Hosts: 91.212.127.227 www.antiviraprof2009.com
O1 - Hosts: 78.159.110.45 www.google.com
O1 - Hosts: 78.159.110.45 www.google.de
O1 - Hosts: 78.159.110.45 www.google.fr
O1 - Hosts: 78.159.110.45 www.google.co.uk
O1 - Hosts: 78.159.110.45 www.google.com.br
O1 - Hosts: 78.159.110.45 www.google.it
O1 - Hosts: 78.159.110.45 www.google.es
O1 - Hosts: 78.159.110.45 www.google.co.jp
O1 - Hosts: 78.159.110.45 www.google.com.mx
O1 - Hosts: 78.159.110.45 www.google.ca
O1 - Hosts: 78.159.110.45 www.google.com.au
O1 - Hosts: 78.159.110.45 www.google.nl
O1 - Hosts: 78.159.110.45 www.google.co.za
O1 - Hosts: 78.159.110.45 www.google.be
O1 - Hosts: 78.159.110.45 www.google.gr
O1 - Hosts: 78.159.110.45 www.google.at
O1 - Hosts: 78.159.110.45 www.google.se
O1 - Hosts: 78.159.110.45 www.google.ch
O1 - Hosts: 78.159.110.45 www.google.pt
O1 - Hosts: 78.159.110.45 www.google.dk
O1 - Hosts: 14735 more lines…
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Documents and Settings\Nick\My Documents\BitComet\tools\BitCometBHO_1.4.8.11.dll (BitComet)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (no name) - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - No CLSID value found.
O2 - BHO: (no name) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - No CLSID value found.
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe File not found
O4 - HKLM..\Run: [AGRSMMSG] C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe File not found
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Documents and Settings\Nick\My Documents\Programs\iTunes.Resources\Itunes\iTunesHelper.exe File not found
O4 - HKLM..\Run: [KBD] C:\HP\KBD\kbd.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [KRun] C:\Program Files\Windows7\RunMe\RunMe.exe (KSoft)
O4 - HKLM..\Run: [LXCTCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.DLL (Lexmark International Inc.)
O4 - HKLM..\Run: [lxctmon.exe] C:\Program Files\Lexmark 5400 Series\lxctmon.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Viena Explorer] C:\Program Files\Windows7\Vienna Explorer\Vienna Explorer.exe ()
O4 - HKLM..\Run: [Visual Task Tips] C:\Program Files\Windows7\VisualTaskTips\VisualTaskTips.exe (VisualTaskTips.com)
O4 - HKCU..\Run: [AnalogClock] C:\Program Files\Windows7\Analog Clock\AnalogClock.exe (Excode Software)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKCU..\Run: [gnqtkxsx] C:\DOCUME~1\Nick\LOCALS~1\Temp\cgggjetiy\pgsgaovaffm.exe File not found
O4 - HKCU..\Run: [OnlineVault] C:\Program Files\Online Vault\OnlineVault.exe (Xacti Corporation)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKCU..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (Speedbit Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [TransBar] C:\Program Files\Windows7\TransBar\TransBar.exe (AKSoftware)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk = C:\Documents and Settings\Nick\My Documents\Programs\WSTrayDictMode.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMFUprogramsList = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O8 - Extra context menu item: &D;&ownload; &with; BitComet - C:\Documents and Settings\Nick\My Documents\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all with BitComet - C:\Documents and Settings\Nick\My Documents\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Expression\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Documents and Settings\Nick\My Documents\BitComet\tools\BitCometBHO_1.4.8.11.dll (BitComet)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O16 - DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} http://intel-drv-cdn.systemrequirementslab…reqlab_srlx.cab (System Requirements Lab Class)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro2.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - c:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Nick\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Nick\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/11 09:43:34 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\PROGRA~1\AVG\AVG10\avgchsvx.exe File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\PROGRA~1\AVG\AVG10\avgrsx.exe File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183528496136192)
========== Files/Folders - Created Within 30 Days ==========
[2010/12/13 07:23:13 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/12/13 01:21:54 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/12 19:30:33 | 190,219,598 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Nick\My Documents\MSOfficePro2007X12-30196.exe.part
[2010/12/12 19:29:47 | 407,010,384 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Nick\My Documents\MSOfficePro2007X12-30196.exe
[2010/12/12 19:29:31 | 003,412,768 | —- | C] (Crawler, LLC ) – C:\Documents and Settings\Nick\My Documents\OnlineVault_Setup.exe
[2010/12/12 19:29:26 | 005,373,672 | —- | C] (Crawler.Com ) – C:\Documents and Settings\Nick\My Documents\WebSecurityGuardSetup.exe
[2010/12/12 19:27:06 | 407,010,384 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Nick\Desktop\MSOfficePro2007X12-30196.exe
[2010/12/12 19:24:59 | 000,000,000 | —D | C] – C:\Program Files\Online Vault
[2010/12/12 19:23:48 | 000,000,000 | —D | C] – C:\Program Files\System Protect
[2010/12/12 19:18:02 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Nick\Recent
[2010/12/12 00:18:24 | 000,603,648 | —- | C] (PPtJCIHx) – C:\Documents and Settings\Nick\Local Settings\Application Data\syssvc.exe
[2010/12/11 23:30:56 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Expression
[2010/12/11 21:33:23 | 000,000,000 | —D | C] – C:\Program Files\DAEMON Tools
[2010/12/11 21:19:30 | 000,030,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mdimon.dll
[2010/12/11 21:02:09 | 000,032,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msonpmon.dll
[2010/12/11 20:56:33 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2010/12/11 20:20:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\CCleaner
[2010/12/11 18:53:56 | 000,000,000 | —D | C] – C:\Program Files\MagicISO
[2010/12/11 18:01:50 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/12/11 16:59:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\Local Settings\Application Data\PCHealth
[2010/12/11 16:22:29 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2010/12/11 16:22:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2010/12/11 16:09:57 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2010/12/11 16:05:17 | 000,000,000 | RH-D | C] – C:\MSOCache
[2010/12/11 01:35:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\Finished Movies
[2010/12/10 23:15:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/12/10 23:12:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\Spybot - Search & Destroy
[2010/12/10 23:10:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\Malwarebytes' Anti-Malware
[2010/12/10 22:47:31 | 000,000,000 | —D | C] – C:\Downloads
[2010/12/10 22:35:22 | 000,028,160 | —- | C] (mst software GmbH, Germany) – C:\WINDOWS\System32\DfSdkBt.exe
[2010/12/10 22:12:08 | 000,000,000 | —D | C] – C:\Program Files\Security Programs
[2010/12/10 17:55:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\Application Data\Local
[2010/12/10 17:55:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\Application Data\DivX
[2010/12/10 17:54:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\DivX Movies
[2010/12/10 17:54:16 | 000,126,448 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxinsi64.exe
[2010/12/10 17:54:16 | 000,123,888 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxcpyi64.exe
[2010/12/10 17:54:16 | 000,068,592 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxinsa64.exe
[2010/12/10 17:54:16 | 000,068,080 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxcpya64.exe
[2010/12/10 17:54:16 | 000,009,200 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys
[2010/12/10 17:54:16 | 000,009,072 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys
[2010/12/10 17:54:15 | 002,120,176 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxsfs.dll
[2010/12/10 17:54:15 | 000,567,792 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxdrv.dll
[2010/12/10 17:54:15 | 000,133,616 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxafs.dll
[2010/12/10 17:54:15 | 000,100,848 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\vxblock.dll
[2010/12/10 17:54:15 | 000,072,176 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxhpinst.exe
[2010/12/10 17:54:14 | 000,440,816 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxwave.dll
[2010/12/10 17:54:14 | 000,219,632 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxmas.dll
[2010/12/10 17:54:13 | 000,698,864 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\px.dll
[2010/12/10 17:53:14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2010/12/10 17:52:18 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2010/12/10 17:49:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DivX
[2010/12/10 17:12:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\Nero 7.10.1.0
[2010/12/09 17:40:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\hIjGo01570
[2010/12/08 03:00:50 | 000,000,000 | —D | C] – C:\WINDOWS\System32\dumps
[2010/12/07 23:32:22 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/12/07 23:29:19 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/12/07 23:27:33 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/12/07 23:25:50 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2010/12/07 23:23:55 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/12/06 08:05:09 | 000,000,000 | —D | C] – C:\Program Files\Quick Web Player
[2010/12/03 19:00:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\Local Settings\Application Data\PackageAware
[2010/12/03 18:53:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Nick\My Documents\Ashampoo
[2010/12/03 17:02:51 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/03 17:02:48 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/03 15:55:08 | 000,000,000 | —D | C] – C:\Program Files\Template
[2010/12/03 15:54:28 | 000,000,000 | —D | C] – C:\Program Files\Data Migration Wizard
[2010/12/03 15:54:27 | 000,000,000 | —D | C] – C:\Program Files\Transaction Manager
[2010/12/03 15:54:27 | 000,000,000 | —D | C] – C:\Program Files\Action Engine
[2010/03/01 17:21:32 | 000,323,584 | —- | C] ( ) – C:\WINDOWS\System32\LXCThcp.dll
[2010/03/01 17:21:31 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\lxctinpa.dll
[2010/03/01 17:21:31 | 000,397,312 | —- | C] ( ) – C:\WINDOWS\System32\lxctiesc.dll
[2010/03/01 17:21:30 | 001,224,704 | —- | C] ( ) – C:\WINDOWS\System32\lxctserv.dll
[2010/03/01 17:21:30 | 000,991,232 | —- | C] ( ) – C:\WINDOWS\System32\lxctusb1.dll
[2010/03/01 17:21:29 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxctpmui.dll
[2010/03/01 17:21:29 | 000,585,728 | —- | C] ( ) – C:\WINDOWS\System32\lxctlmpm.dll
[2010/03/01 17:21:29 | 000,163,840 | —- | C] ( ) – C:\WINDOWS\System32\lxctprox.dll
[2010/03/01 17:21:29 | 000,094,208 | —- | C] ( ) – C:\WINDOWS\System32\lxctpplc.dll
[2010/03/01 17:21:27 | 000,696,320 | —- | C] ( ) – C:\WINDOWS\System32\lxcthbn3.dll
[2010/03/01 17:21:25 | 000,684,032 | —- | C] ( ) – C:\WINDOWS\System32\lxctcomc.dll
[2010/03/01 17:21:25 | 000,421,888 | —- | C] ( ) – C:\WINDOWS\System32\lxctcomm.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/14 03:01:01 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/12/14 02:46:40 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/14 02:46:29 | 000,000,244 | —- | M] () – C:\WINDOWS\tasks\SpeedOptimizer Startup.job
[2010/12/14 02:46:18 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/14 01:52:21 | 000,001,387 | —- | M] () – C:\Documents and Settings\Nick\1.bak
[2010/12/13 08:02:11 | 000,352,176 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/13 01:22:01 | 000,000,714 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/12 19:28:44 | 000,000,759 | —- | M] () – C:\Documents and Settings\All Users\Desktop\System Protect.lnk
[2010/12/12 19:27:16 | 000,000,527 | —- | M] () – C:\Documents and Settings\Nick\My Documents\SystemProtect_Setup.lnk
[2010/12/12 19:25:19 | 000,000,751 | —- | M] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Online Vault.lnk
[2010/12/12 19:25:19 | 000,000,733 | —- | M] () – C:\Documents and Settings\Nick\Desktop\Online Vault.lnk
[2010/12/12 19:23:51 | 000,012,288 | —- | M] () – C:\WINDOWS\System32\drivers\sp_prot.sys
[2010/12/12 00:18:25 | 000,603,648 | —- | M] (PPtJCIHx) – C:\Documents and Settings\Nick\Local Settings\Application Data\syssvc.exe
[2010/12/12 00:03:02 | 407,010,384 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Nick\My Documents\MSOfficePro2007X12-30196.exe
[2010/12/12 00:03:02 | 407,010,384 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Nick\Desktop\MSOfficePro2007X12-30196.exe
[2010/12/12 00:00:50 | 190,219,598 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Nick\My Documents\MSOfficePro2007X12-30196.exe.part
[2010/12/11 21:33:23 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DAEMON Tools.lnk
[2010/12/11 20:20:17 | 000,000,650 | —- | M] () – C:\Documents and Settings\Nick\Desktop\CCleaner.lnk
[2010/12/11 18:53:57 | 000,001,486 | —- | M] () – C:\Documents and Settings\Nick\Desktop\MagicISO.lnk
[2010/12/11 18:01:54 | 000,001,626 | —- | M] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/12/11 18:01:54 | 000,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/12/11 13:12:53 | 000,031,744 | —- | M] () – C:\Documents and Settings\Nick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/11 13:03:42 | 000,001,576 | —- | M] () – C:\Documents and Settings\Nick\Desktop\DivX Movies.lnk
[2010/12/11 01:30:34 | 000,001,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/11 00:53:16 | 000,427,122 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/10 22:35:24 | 000,002,133 | —- | M] () – C:\Documents and Settings\All Users\Desktop\One-Click-Optimizer.lnk
[2010/12/10 22:35:24 | 000,001,069 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ashampoo WinOptimizer 2010 Advanced.lnk
[2010/12/10 22:35:24 | 000,001,019 | —- | M] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo WinOptimizer 2010 Advanced.lnk
[2010/12/10 22:25:21 | 000,000,650 | —- | M] () – C:\Documents and Settings\Nick\Desktop\BitComet.lnk
[2010/12/10 17:54:46 | 000,000,793 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/12/10 11:18:24 | 000,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Desktop Manager.lnk
[2010/12/10 10:23:13 | 101,497,532 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2010/12/07 23:30:02 | 000,001,610 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/12/07 23:27:40 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/05 02:46:00 | 000,000,454 | —- | M] () – C:\WINDOWS\tasks\Driver Robot.job
[2010/12/03 01:36:57 | 000,000,422 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
[2010/11/17 23:22:58 | 000,000,124 | —- | M] () – C:\Documents and Settings\Nick\Desktop\Control Panel.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/13 01:22:01 | 000,000,714 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/12 19:48:39 | 000,001,387 | —- | C] () – C:\Documents and Settings\Nick\1.bak
[2010/12/12 19:27:16 | 000,000,527 | —- | C] () – C:\Documents and Settings\Nick\My Documents\SystemProtect_Setup.lnk
[2010/12/12 19:25:19 | 000,000,751 | —- | C] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Online Vault.lnk
[2010/12/12 19:25:19 | 000,000,733 | —- | C] () – C:\Documents and Settings\Nick\Desktop\Online Vault.lnk
[2010/12/12 19:24:39 | 000,000,759 | —- | C] () – C:\Documents and Settings\All Users\Desktop\System Protect.lnk
[2010/12/12 19:23:51 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\drivers\sp_prot.sys
[2010/12/11 21:33:23 | 000,000,702 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DAEMON Tools.lnk
[2010/12/11 20:20:17 | 000,000,650 | —- | C] () – C:\Documents and Settings\Nick\Desktop\CCleaner.lnk
[2010/12/11 18:53:57 | 000,001,486 | —- | C] () – C:\Documents and Settings\Nick\Desktop\MagicISO.lnk
[2010/12/11 18:01:54 | 000,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/12/10 23:26:05 | 005,792,131 | —- | C] () – C:\Documents and Settings\Nick\Desktop\SpyBot Startup.tnfo
[2010/12/10 22:35:24 | 000,002,133 | —- | C] () – C:\Documents and Settings\All Users\Desktop\One-Click-Optimizer.lnk
[2010/12/10 22:35:24 | 000,001,069 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ashampoo WinOptimizer 2010 Advanced.lnk
[2010/12/10 22:35:24 | 000,001,019 | —- | C] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo WinOptimizer 2010 Advanced.lnk
[2010/12/10 17:55:43 | 000,001,576 | —- | C] () – C:\Documents and Settings\Nick\Desktop\DivX Movies.lnk
[2010/12/10 17:54:46 | 000,000,793 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/12/07 23:33:23 | 000,001,690 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/07 23:30:02 | 000,001,610 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/12/07 23:27:40 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/03 15:55:13 | 000,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Desktop Manager.lnk
[2010/11/17 23:22:58 | 000,000,124 | —- | C] () – C:\Documents and Settings\Nick\Desktop\Control Panel.lnk
[2010/04/11 17:12:02 | 000,000,664 | —- | C] () – C:\Documents and Settings\Nick\Local Settings\Application Data\FASTWiz.html
[2010/04/11 17:11:04 | 000,000,076 | —- | C] () – C:\Documents and Settings\Nick\Local Settings\Application Data\FASTWiz.log
[2010/03/01 17:26:30 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxctvs.dll
[2010/03/01 17:26:22 | 000,331,776 | —- | C] () – C:\WINDOWS\System32\lxctcoin.dll
[2010/03/01 17:25:45 | 000,692,224 | —- | C] () – C:\WINDOWS\System32\lxctdrs.dll
[2010/03/01 17:25:45 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\lxctcaps.dll
[2010/03/01 17:25:44 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\lxctcnv4.dll
[2010/03/01 17:24:42 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\lxctpmon.dll
[2010/03/01 17:24:42 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\LXCTFXPU.DLL
[2010/03/01 17:21:32 | 000,274,432 | —- | C] () – C:\WINDOWS\System32\LXCTinst.dll
[2010/03/01 17:21:27 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\lxctgrd.dll
[2009/10/26 12:55:08 | 000,691,696 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/10/03 01:43:23 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2009/10/03 01:43:23 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2009/10/03 01:43:23 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2009/09/29 22:06:06 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\viscomtran.dll
[2009/09/29 22:06:05 | 006,963,712 | —- | C] () – C:\WINDOWS\System32\videotrans.dll
[2009/09/29 22:06:05 | 000,452,608 | —- | C] () – C:\WINDOWS\System32\videoformat.dll
[2009/09/29 22:06:05 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/09/29 22:06:05 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2009/09/29 22:06:05 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\viscomgifenc.dll
[2009/09/29 22:06:05 | 000,154,624 | —- | C] () – C:\WINDOWS\System32\imgscaler.dll
[2009/09/29 22:06:05 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\img_utils.dll
[2009/09/29 22:06:05 | 000,019,456 | —- | C] () – C:\WINDOWS\System32\videocore.dll
[2009/09/02 15:38:13 | 000,307,200 | —- | C] () – C:\WINDOWS\System32\AscSQLite.dll
[2009/08/19 02:14:01 | 000,031,744 | —- | C] () – C:\Documents and Settings\Nick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/11 16:33:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/05/18 19:46:40 | 000,000,215 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
========== LOP Check ==========
[2010/03/01 17:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\5400 Series
[2009/09/29 22:22:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2010/10/18 00:17:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/12/13 07:24:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/17 18:43:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2010/06/01 01:01:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverScanner
[2010/12/09 17:41:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\hIjGo01570
[2009/10/06 17:19:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Innovative Solutions
[2010/12/13 07:20:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/08/18 23:54:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/10/06 18:33:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/04/20 01:36:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/08/11 01:56:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Slapdash Games
[2009/11/08 20:01:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpeedBit
[2009/11/08 20:01:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/13 03:33:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Toolbar4
[2010/04/07 16:58:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/18 12:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/01 17:27:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\5400 Series
[2009/09/29 22:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Ashampoo
[2010/10/17 18:44:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\AVG10
[2010/12/11 23:05:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\BitComet
[2009/09/16 18:31:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\BitCometLite
[2009/10/06 17:04:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Blitware
[2009/08/16 23:05:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\com.adobe.ExMan
[2009/08/14 12:54:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\GetRightToGo
[2010/12/10 17:55:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Local
[2010/04/01 16:07:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\MSNInstaller
[2010/02/28 18:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\OpenOffice.org
[2009/08/11 09:53:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\OtakuSoftware
[2010/04/13 17:43:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Research In Motion
[2009/08/13 23:37:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\RiotBall_demo
[2009/08/29 01:18:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\TigerPlayer
[2010/12/03 19:01:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Uniblue
[2009/08/13 22:49:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\uTorrent
[2010/12/05 02:46:00 | 000,000,454 | —- | M] () – C:\WINDOWS\Tasks\Driver Robot.job
[2010/03/28 13:01:14 | 000,000,402 | —- | M] () – C:\WINDOWS\Tasks\peaks.job
[2010/12/14 03:01:01 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2010/12/14 02:46:29 | 000,000,244 | —- | M] () – C:\WINDOWS\Tasks\SpeedOptimizer Startup.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/08/11 09:43:34 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/08/11 09:36:34 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/08/11 09:43:34 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/08/11 09:43:34 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/08/11 09:43:34 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 10:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 12:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/14 02:46:15 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/08/11 09:43:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/01/17 20:25:06 | 000,118,784 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxctdrpp.dll
[2006/10/26 19:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/08/11 16:30:41 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/08/11 16:30:41 | 001,085,440 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/08/11 16:30:41 | 000,925,696 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/08/11 09:43:40 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/11 09:53:52 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/08/11 09:53:51 | 000,000,079 | —- | M] () – C:\Documents and Settings\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/12/12 00:03:02 | 407,010,384 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Nick\Desktop\MSOfficePro2007X12-30196.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-03 23:45:41
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CD060F93
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D74B6CF5
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60A4BB64
< End of report >
Please help, Thank you! ………………