readyshootaim
Topic Starter
Temporarily plugging in a new PCI based network interface card solves the problem. But i need to use the onboard network adapter of the mother board. how can this port suddenly stop working after only 2 years, with no physical trauma or anything at all?
When im in the command prompt and try to do " ipconfig /release " then renew after it times out. Something software related is preventing me from connecting to the internet.
Please help me
Malwarebytes finds nothing and neither does AVG full scan.
HJT log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:55:35 AM, on 12/28/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\CTHELPER.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\vVX3000.exe
C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
I:\nero8\Nero 8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "I:\nero8\Nero 8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1187569940500
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate1c95c105d981590) (gupdate1c95c105d981590) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - I:\nero8\Nero 8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 7811 bytes
OTL log:
OTL logfile created on: 12/28/2010 10:05:58 AM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,023.00 Mb Total Physical Memory | 340.00 Mb Available Physical Memory | 33.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 1000 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 6.96 Gb Free Space | 18.66% Space Free | Partition Type: NTFS
Drive H: | 120.16 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive I: | 148.89 Gb Total Space | 39.19 Gb Free Space | 26.32% Space Free | Partition Type: FAT32
Drive J: | 37.27 Gb Total Space | 3.80 Gb Free Space | 10.19% Space Free | Partition Type: NTFS
Drive K: | 3.88 Gb Total Space | 2.86 Gb Free Space | 73.80% Space Free | Partition Type: FAT32
Drive P: | 55.88 Gb Total Space | 14.00 Gb Free Space | 25.05% Space Free | Partition Type: NTFS
Computer Name: OFFICE | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - I:\nero8\Nero 8\Nero BackItUp\NBService.exe (Nero AG)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
PRC - C:\Program Files\Winamp\winamp.exe (Nullsoft)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)
MOD - C:\Program Files\Logitech\iTouch\itchhk.dll (Logitech Inc.)
MOD - C:\Program Files\Common Files\Logitech\Scrolling\LGMSGHK.DLL (Logitech Inc.)
MOD - C:\Program Files\Logitech\iTouch\KbdHook.dll (Logitech Inc.)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Crypkey License) – C:\WINDOWS\System32\Crypserv.exe (CrypKey (Canada) Ltd.)
SRV - (msvsmon90) – P:\VS\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 3) – I:\nero8\Nero 8\Nero BackItUp\NBService.exe (Nero AG)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (mi-raysat_3dsmax8) – J:\3ds Max 8\mentalray\satellite\raysat_3dsmax8server.exe ()
SRV - (EPSONStatusAgent2) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (SYMIDSCO) – C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20051208.051\symidsco.sys File not found
DRV - (mcdbus) – C:\WINDOWS\System32\DRIVERS\mcdbus.sys File not found
DRV - (LHidFlt2) – C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys File not found
DRV - (iMSPCLOj) – C:\DOCUME~1\User\LOCALS~1\Temp\iMSPCLOj.sys File not found
DRV - (ENTECH) – C:\WINDOWS\System32\DRIVERS\ENTECH.sys File not found
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ggsemc) – C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (s0017mdm) – C:\WINDOWS\system32\drivers\s0017mdm.sys (MCCI Corporation)
DRV - (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM) – C:\WINDOWS\system32\drivers\s0017unic.sys (MCCI Corporation)
DRV - (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s0017mgmt.sys (MCCI Corporation)
DRV - (s0017obex) – C:\WINDOWS\system32\drivers\s0017obex.sys (MCCI Corporation)
DRV - (s0017bus) Sony Ericsson Device 0017 driver (WDM) – C:\WINDOWS\system32\drivers\s0017bus.sys (MCCI Corporation)
DRV - (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS) – C:\WINDOWS\system32\drivers\s0017nd5.sys (MCCI Corporation)
DRV - (s0017mdfl) – C:\WINDOWS\system32\drivers\s0017mdfl.sys (MCCI Corporation)
DRV - (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM) – C:\WINDOWS\system32\drivers\s0016unic.sys (MCCI Corporation)
DRV - (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS) – C:\WINDOWS\system32\drivers\s0016nd5.sys (MCCI Corporation)
DRV - (s0016mdfl) – C:\WINDOWS\system32\drivers\s0016mdfl.sys (MCCI Corporation)
DRV - (s0016mdm) – C:\WINDOWS\system32\drivers\s0016mdm.sys (MCCI Corporation)
DRV - (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s0016mgmt.sys (MCCI Corporation)
DRV - (s0016obex) – C:\WINDOWS\system32\drivers\s0016obex.sys (MCCI Corporation)
DRV - (s0016bus) Sony Ericsson Device 0016 driver (WDM) – C:\WINDOWS\system32\drivers\s0016bus.sys (MCCI Corporation)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (NetworkX) – C:\WINDOWS\system32\ckldrv.sys ()
DRV - (seehcri) – C:\WINDOWS\system32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (Ser2pl) – C:\WINDOWS\system32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (Applied Networking Inc.)
DRV - (dtscsi) – C:\WINDOWS\System32\Drivers\dtscsi.sys ()
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (VX3000) – C:\WINDOWS\system32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (hap17v2k) – C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (z520obex) – C:\WINDOWS\system32\drivers\z520obex.sys (MCCI)
DRV - (z520mgmt) – C:\WINDOWS\system32\drivers\z520mgmt.sys (MCCI)
DRV - (z520mdm) – C:\WINDOWS\system32\drivers\z520mdm.sys (MCCI)
DRV - (z520mdfl) – C:\WINDOWS\system32\drivers\z520mdfl.sys (MCCI)
DRV - (z520bus) Sony Ericsson 520 driver (WDM) – C:\WINDOWS\system32\drivers\z520bus.sys (MCCI)
DRV - (w810obex) – C:\WINDOWS\system32\drivers\w810obex.sys (MCCI)
DRV - (w810mdm) – C:\WINDOWS\system32\drivers\w810mdm.sys (MCCI)
DRV - (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\w810mgmt.sys (MCCI)
DRV - (w810mdfl) – C:\WINDOWS\system32\drivers\w810mdfl.sys (MCCI)
DRV - (w810bus) Sony Ericsson W810 Driver driver (WDM) – C:\WINDOWS\system32\drivers\w810bus.sys (MCCI)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (libusb0) – C:\WINDOWS\system32\drivers\libusb0.sys ()
DRV - (SER120) – C:\WINDOWS\system32\drivers\ser120.sys (USB Com port.)
DRV - (itchfltr) – C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
DRV - (LHidUsb) – C:\WINDOWS\system32\drivers\LHidUsb.sys (Logitech, Inc.)
DRV - (LCcfltr) – C:\WINDOWS\system32\drivers\LCcfltr.sys (Logitech, Inc.)
DRV - (TIEHDUSB) – C:\WINDOWS\system32\drivers\tiehdusb.sys (Texas Instruments Incorporated)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (RTWTKRNL) – C:\WINDOWS\system32\drivers\RTWTKRNL.sys ()
DRV - (sonyhcs) – C:\WINDOWS\system32\drivers\sonyhcs.sys (Sony Corporation)
DRV - (sonyhcb) – C:\WINDOWS\System32\DRIVERS\sonyhcb.sys (Sony Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PEDRV) – C:\WINDOWS\System32\drivers\pedrv.sys ()
DRV - (VICHW11) – C:\WINDOWS\System32\drivers\vichw11.sys ()
DRV - (GIVEIO) – C:\WINDOWS\System32\drivers\GIVEIO.SYS ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 18 34 AB 7E 1D 81 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/21 09:02:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/14 09:41:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/12 10:01:01 | 000,000,000 | —D | M]
[2008/08/25 20:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/12/25 15:34:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions
[2010/04/28 13:40:30 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/07/14 17:25:54 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions\[removed]
[2010/10/03 13:05:49 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions\vshare@toolbar
[2010/12/27 16:05:48 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/12/11 23:58:40 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/11 23:58:14 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/04/16 09:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2010/12/27 16:51:26 | 000,000,736 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EM_EXEC] C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc. )
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NBKeyScan] I:\nero8\Nero 8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [VX3000] C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe File not found
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/d/4…0367/wmavax.CAB (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1187569940500 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/09/05 19:22:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/09/22 21:25:28 | 000,000,043 | R— | M] () - H:\AUTORUN.INF – [ CDFS ]
O32 - AutoRun File - [2006/11/02 11:00:34 | 000,909,530 | R— | M] (InstallShield Software Corporation) - H:\Autopoll Application V1.04.exe – [ CDFS ]
O32 - AutoRun File - [2008/09/14 19:38:08 | 000,000,122 | RHS- | M] () - I:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{01b326cd-ea62-11de-98fd-000d61c1efb2}\Shell\AutoRun\command - "" = P:\Xilinx\EDK\bin\nt\setup.exe – [2008/02/20 09:47:10 | 000,012,288 | —- | M] ()
O33 - MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{607f01e2-1531-11dd-970c-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{607f01e2-1531-11dd-970c-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{607f01e2-1531-11dd-970c-000d61c1efb2}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{abe72b8c-d273-11db-8c4a-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{abe72b8c-d273-11db-8c4a-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{abe72b8c-d273-11db-8c4a-000d61c1efb2}\Shell\AutoRun\command - "" = H:\ONSPCLCK.exe – [2006/11/02 12:55:10 | 002,519,040 | R— | M] (OnSpec Electronic, Inc.)
O33 - MountPoints2\{abe72b8f-d273-11db-8c4a-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{abe72b8f-d273-11db-8c4a-000d61c1efb2}\Shell\1\Command - "" = .\recycled\info.exe
O33 - MountPoints2\{abe72b8f-d273-11db-8c4a-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\KODAK_Software_Downloader.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\ONSPCLCK.exe – [2006/11/02 12:55:10 | 002,519,040 | R— | M] (OnSpec Electronic, Inc.)
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\1\Command - "" = .\recycled\info.exe
O33 - MountPoints2\I\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/12/28 10:02:06 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/12/28 09:40:31 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/28 09:40:26 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/28 09:40:25 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/20 16:53:56 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Cubic
[2010/12/20 12:35:53 | 000,000,000 | —D | C] – C:\Program Files\DVDFab 7
[2010/12/20 12:33:38 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\DVDFab.Platinum.7070
[2010/12/15 14:13:11 | 000,000,000 | —D | C] – C:\Documents and Settings\User\final5
[2010/12/15 04:05:00 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2010/12/14 20:13:11 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\AdvancedReliableSoftware
[2010/12/14 20:12:11 | 000,000,000 | —D | C] – C:\Program Files\AdvancedReliableSoftware
[2010/12/13 20:43:58 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\FileZilla
[2010/12/13 20:43:22 | 000,000,000 | —D | C] – C:\Program Files\FileZilla FTP Client
[2010/12/12 20:52:10 | 000,454,656 | —- | C] (Simon Tatham) – C:\Documents and Settings\User\Desktop\putty.exe
[2010/12/12 16:17:11 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Masharoni and Cheese
[2010/12/12 16:11:51 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\vice-breakfast-clubbin
[2010/12/12 16:11:45 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\DJ-Vice-Vice-Vice-Baby-CD
[2010/12/12 16:05:28 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\DJVice-LateNights.mp3
[2010/12/11 23:59:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Sun
[2010/12/11 23:58:36 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/12/11 23:58:36 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/11 23:58:36 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/12/11 23:58:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/11 23:58:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/02 19:47:19 | 000,000,000 | —D | C] – C:\Program Files\FoxTabFlvConverter
[2010/12/02 19:17:30 | 000,000,000 | —D | C] – C:\Program Files\Xesc & Technology
[2008/07/26 16:05:52 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\User\Application Data\pcouffin.sys
[2006/08/11 14:56:28 | 000,033,792 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/28 10:11:50 | 000,001,065 | —- | M] () – C:\WINDOWS\winamp.ini
[2010/12/28 09:59:46 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/12/28 09:59:12 | 000,359,929 | —- | M] () – C:\Documents and Settings\User\Desktop\dds.scr
[2010/12/28 09:46:56 | 000,001,982 | —- | M] () – C:\Documents and Settings\User\Desktop\HiJackThis.lnk
[2010/12/28 09:39:58 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/28 09:38:46 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/12/28 09:37:41 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/28 09:35:58 | 000,031,656 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,031,656 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,028,968 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,028,968 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2010/12/28 09:35:58 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2010/12/28 09:35:44 | 003,162,278 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-00511102}.CDF
[2010/12/28 09:35:44 | 003,162,278 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-00511102}.BAK
[2010/12/28 09:22:14 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/27 18:41:22 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk
[2010/12/27 16:33:05 | 000,000,032 | —- | M] () – C:\WINDOWS\System32\thxcfg.ini
[2010/12/27 16:29:56 | 000,134,144 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/27 16:12:00 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/12/27 15:47:27 | 000,548,546 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/12/27 15:47:27 | 000,098,270 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/12/24 13:13:36 | 008,755,789 | —- | M] () – C:\Documents and Settings\User\Desktop\Dwyck.mp3
[2010/12/24 13:11:42 | 005,931,008 | —- | M] () – C:\Documents and Settings\User\Desktop\16_Deadmau5_-_Ghosts_N_Stuff.mp3
[2010/12/24 13:11:42 | 004,769,792 | —- | M] () – C:\Documents and Settings\User\Desktop\techn9ne-im_a_playa.mp3
[2010/12/24 13:09:18 | 005,060,080 | —- | M] () – C:\Documents and Settings\User\Desktop\bon_jovi.mp3
[2010/12/24 13:09:10 | 004,015,461 | —- | M] () – C:\Documents and Settings\User\Desktop\Indeep - Last Night The DJ Save my Life.mp3
[2010/12/24 13:08:27 | 009,684,238 | —- | M] () – C:\Documents and Settings\User\Desktop\ontheroad.mp3
[2010/12/24 13:07:54 | 003,107,158 | —- | M] () – C:\Documents and Settings\User\Desktop\preview.mp3
[2010/12/24 09:21:56 | 069,305,001 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/12/23 20:22:47 | 001,091,284 | —- | M] () – C:\Documents and Settings\User\Desktop\us.JPG
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/20 12:36:01 | 000,000,618 | —- | M] () – C:\Documents and Settings\User\Desktop\DVDFab 7.lnk
[2010/12/19 20:56:31 | 020,389,892 | —- | M] () – C:\Documents and Settings\User\Desktop\DVDFab.Platinum.7070.rar
[2010/12/19 20:20:40 | 000,099,557 | —- | M] () – C:\Documents and Settings\User\Desktop\attachments_2010_12_19.zip
[2010/12/19 12:10:49 | 005,073,765 | —- | M] () – C:\Documents and Settings\User\Desktop\Smoke Gets In Your EyesThe Platters.mp3
[2010/12/19 12:09:00 | 001,111,286 | —- | M] () – C:\Documents and Settings\User\Desktop\01 O Fortuna (Carmina Burana).m4r
[2010/12/19 11:46:42 | 096,698,408 | —- | M] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].wav
[2010/12/19 11:44:20 | 019,847,934 | —- | M] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].mp4
[2010/12/19 11:42:24 | 000,813,858 | —- | M] () – C:\Documents and Settings\User\Desktop\Carl Orff - O Fortuna.mp3
[2010/12/19 11:28:02 | 002,048,449 | —- | M] () – C:\Documents and Settings\User\Desktop\Bed-Intruder-Song-wwwLINKWHIPcom.mp3
[2010/12/19 11:27:12 | 003,522,560 | —- | M] () – C:\Documents and Settings\User\Desktop\carl_orff-o_fortuna_(carmina_burana).mp3
[2010/12/17 21:49:52 | 004,087,794 | —- | M] () – C:\Documents and Settings\User\Desktop\DSCN3264.JPG
[2010/12/16 14:14:31 | 000,000,600 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\PUTTY.RND
[2010/12/16 10:58:40 | 000,002,483 | —- | M] () – C:\Documents and Settings\User\Desktop\Microsoft Word.lnk
[2010/12/15 20:26:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/15 13:09:30 | 000,189,000 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/15 10:22:34 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/12/15 08:13:58 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/12/14 22:30:02 | 000,000,392 | —- | M] () – C:\Documents and Settings\User\Desktop\AdjustiTunesPlayCount.js
[2010/12/14 20:13:30 | 000,162,816 | —- | M] (Firelight Technologies Pty, Ltd) – C:\WINDOWS\System32\fmod.dll
[2010/12/13 20:43:29 | 000,001,663 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\FileZilla Client.lnk
[2010/12/12 20:52:21 | 000,454,656 | —- | M] (Simon Tatham) – C:\Documents and Settings\User\Desktop\putty.exe
[2010/12/12 15:48:19 | 075,370,256 | —- | M] () – C:\Documents and Settings\User\Desktop\01LateNights.mp3
[2010/12/12 15:47:28 | 141,947,581 | —- | M] () – C:\Documents and Settings\User\Desktop\Breakfast-Clubbin.mp3
[2010/12/12 15:46:49 | 033,966,744 | —- | M] () – C:\Documents and Settings\User\Desktop\Vice-Vice-Baby.mp3
[2010/12/12 15:23:16 | 000,071,447 | —- | M] () – C:\Documents and Settings\User\Desktop\tumblr_lc9girUWfW1qctkcl.jpg
[2010/12/12 15:21:00 | 000,064,914 | —- | M] () – C:\Documents and Settings\User\Desktop\tumblr_ld48hjE7JF1qctkcl.jpg
[2010/12/12 15:05:55 | 075,765,411 | —- | M] () – C:\Documents and Settings\User\Desktop\THEBLASTOFF3THEROCKITSCIENTISTS.mp3
[2010/12/12 15:03:41 | 062,980,935 | —- | M] () – C:\Documents and Settings\User\Desktop\rockitBLASTOFF2.mp3
[2010/12/11 23:58:12 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/12/11 23:58:12 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/11 23:58:12 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/11 23:58:12 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/11 23:58:12 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/28 10:02:06 | 000,359,929 | —- | C] () – C:\Documents and Settings\User\Desktop\dds.scr
[2010/12/28 09:46:56 | 000,001,982 | —- | C] () – C:\Documents and Settings\User\Desktop\HiJackThis.lnk
[2010/12/27 16:20:01 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\swsc.exe
[2010/12/24 13:11:36 | 004,769,792 | —- | C] () – C:\Documents and Settings\User\Desktop\techn9ne-im_a_playa.mp3
[2010/12/24 13:11:16 | 005,931,008 | —- | C] () – C:\Documents and Settings\User\Desktop\16_Deadmau5_-_Ghosts_N_Stuff.mp3
[2010/12/24 13:09:34 | 008,755,789 | —- | C] () – C:\Documents and Settings\User\Desktop\Dwyck.mp3
[2010/12/24 13:09:12 | 005,060,080 | —- | C] () – C:\Documents and Settings\User\Desktop\bon_jovi.mp3
[2010/12/24 13:08:47 | 004,015,461 | —- | C] () – C:\Documents and Settings\User\Desktop\Indeep - Last Night The DJ Save my Life.mp3
[2010/12/24 13:08:20 | 009,684,238 | —- | C] () – C:\Documents and Settings\User\Desktop\ontheroad.mp3
[2010/12/24 13:07:48 | 003,107,158 | —- | C] () – C:\Documents and Settings\User\Desktop\preview.mp3
[2010/12/24 09:52:42 | 004,087,794 | —- | C] () – C:\Documents and Settings\User\Desktop\DSCN3264.JPG
[2010/12/23 20:22:37 | 001,091,284 | —- | C] () – C:\Documents and Settings\User\Desktop\us.JPG
[2010/12/20 12:36:01 | 000,000,618 | —- | C] () – C:\Documents and Settings\User\Desktop\DVDFab 7.lnk
[2010/12/19 20:54:59 | 020,389,892 | —- | C] () – C:\Documents and Settings\User\Desktop\DVDFab.Platinum.7070.rar
[2010/12/19 20:20:38 | 000,099,557 | —- | C] () – C:\Documents and Settings\User\Desktop\attachments_2010_12_19.zip
[2010/12/19 12:11:57 | 001,111,286 | —- | C] () – C:\Documents and Settings\User\Desktop\01 O Fortuna (Carmina Burana).m4r
[2010/12/19 12:10:33 | 005,073,765 | —- | C] () – C:\Documents and Settings\User\Desktop\Smoke Gets In Your EyesThe Platters.mp3
[2010/12/19 11:43:32 | 096,698,408 | —- | C] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].wav
[2010/12/19 11:42:24 | 000,813,858 | —- | C] () – C:\Documents and Settings\User\Desktop\Carl Orff - O Fortuna.mp3
[2010/12/19 11:37:35 | 019,847,934 | —- | C] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].mp4
[2010/12/19 11:28:02 | 002,048,449 | —- | C] () – C:\Documents and Settings\User\Desktop\Bed-Intruder-Song-wwwLINKWHIPcom.mp3
[2010/12/19 11:27:12 | 003,522,560 | —- | C] () – C:\Documents and Settings\User\Desktop\carl_orff-o_fortuna_(carmina_burana).mp3
[2010/12/14 22:20:55 | 000,000,392 | —- | C] () – C:\Documents and Settings\User\Desktop\AdjustiTunesPlayCount.js
[2010/12/13 20:43:29 | 000,001,663 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\FileZilla Client.lnk
[2010/12/12 21:59:01 | 000,000,600 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\PUTTY.RND
[2010/12/12 15:46:11 | 033,966,744 | —- | C] () – C:\Documents and Settings\User\Desktop\Vice-Vice-Baby.mp3
[2010/12/12 15:45:31 | 141,947,581 | —- | C] () – C:\Documents and Settings\User\Desktop\Breakfast-Clubbin.mp3
[2010/12/12 15:41:20 | 075,370,256 | —- | C] () – C:\Documents and Settings\User\Desktop\01LateNights.mp3
[2010/12/12 15:23:15 | 000,071,447 | —- | C] () – C:\Documents and Settings\User\Desktop\tumblr_lc9girUWfW1qctkcl.jpg
[2010/12/12 15:20:59 | 000,064,914 | —- | C] () – C:\Documents and Settings\User\Desktop\tumblr_ld48hjE7JF1qctkcl.jpg
[2010/12/12 14:59:24 | 075,765,411 | —- | C] () – C:\Documents and Settings\User\Desktop\THEBLASTOFF3THEROCKITSCIENTISTS.mp3
[2010/12/12 14:58:46 | 062,980,935 | —- | C] () – C:\Documents and Settings\User\Desktop\rockitBLASTOFF2.mp3
[2010/04/01 15:11:40 | 000,012,298 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\8Cq4r
[2010/04/01 15:11:40 | 000,012,298 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\8Cq4r
[2009/12/13 21:36:39 | 000,123,083 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\debuggee.mdmp
[2009/09/23 20:17:42 | 000,000,965 | —- | C] () – C:\WINDOWS\mcutools.ini
[2009/09/05 20:34:56 | 000,000,018 | -HS- | C] () – C:\WINDOWS\WINPROD.DLL
[2009/09/03 00:20:12 | 000,000,000 | —- | C] () – C:\WINDOWS\EEventManager.INI
[2009/09/01 18:59:11 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/09/01 18:53:31 | 000,000,079 | —- | C] () – C:\WINDOWS\EPNX510.ini
[2009/06/06 16:20:31 | 000,000,068 | —- | C] () – C:\WINDOWS\spwdr.INI
[2009/06/06 16:19:56 | 000,000,071 | —- | C] () – C:\WINDOWS\Crypkey.ini
[2009/06/06 16:19:53 | 000,019,584 | —- | C] () – C:\WINDOWS\System32\Ckldrv.sys
[2009/06/06 16:19:53 | 000,018,432 | —- | C] () – C:\WINDOWS\Setup_ck.dll
[2009/06/06 11:59:34 | 000,000,072 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\FASTWiz.log
[2009/02/28 18:30:21 | 000,087,608 | —- | C] () – C:\Documents and Settings\User\Application Data\inst.exe
[2009/02/27 15:53:43 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/01/29 16:08:39 | 000,015,498 | —- | C] () – C:\WINDOWS\VX3000.ini
[2008/09/08 19:21:19 | 000,027,008 | —- | C] () – C:\WINDOWS\System32\drivers\RTWTKRNL.sys
[2008/09/08 19:17:03 | 000,000,158 | —- | C] () – C:\WINDOWS\matlab.ini
[2008/07/26 16:06:05 | 000,000,034 | —- | C] () – C:\Documents and Settings\User\Application Data\pcouffin.log
[2008/07/26 16:05:52 | 000,081,920 | —- | C] () – C:\Documents and Settings\User\Application Data\ezpinst.exe
[2008/07/26 16:05:52 | 000,007,887 | —- | C] () – C:\Documents and Settings\User\Application Data\pcouffin.cat
[2008/07/26 16:05:52 | 000,001,144 | —- | C] () – C:\Documents and Settings\User\Application Data\pcouffin.inf
[2008/06/17 13:37:52 | 000,044,032 | —- | C] () – C:\WINDOWS\System32\tbdml.dll
[2008/05/04 14:31:37 | 000,086,446 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2008/03/25 16:29:20 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\thxcfg.ini
[2007/12/03 20:14:05 | 000,000,060 | —- | C] () – C:\WINDOWS\EntPack.ini
[2007/08/18 11:57:47 | 000,059,392 | R— | C] () – C:\WINDOWS\System32\streamhlp.dll
[2007/07/07 12:29:00 | 000,000,136 | —- | C] () – C:\WINDOWS\REDEMUNINS.INI
[2007/06/03 14:44:23 | 000,096,384 | —- | C] () – C:\WINDOWS\System32\drivers\sptd8237.sys
[2007/05/29 11:38:02 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/04/23 15:17:25 | 000,000,110 | —- | C] () – C:\WINDOWS\gui.INI
[2007/03/14 17:53:25 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2007/03/14 17:53:25 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/03/02 17:51:26 | 000,003,072 | —- | C] () – C:\WINDOWS\CTXFIRES.DLL
[2007/02/02 18:25:12 | 000,000,080 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\.zreglib
[2006/10/20 15:43:48 | 000,051,712 | —- | C] () – C:\WINDOWS\System32\wglhlvh.dll
[2006/10/10 23:25:38 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2006/09/06 18:32:03 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\User\Application Data\.zreglib
[2006/08/11 13:57:18 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\CTBURST.DLL
[2006/08/06 15:45:44 | 000,001,334 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\QTSBandwidthCache
[2006/07/07 19:57:50 | 000,000,225 | —- | C] () – C:\WINDOWS\em06y.ini
[2006/07/07 19:57:42 | 000,000,410 | —- | C] () – C:\WINDOWS\ptrol.dll
[2006/05/23 11:40:34 | 000,000,269 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2006/05/20 09:37:34 | 000,000,339 | —- | C] () – C:\WINDOWS\dellstat.ini
[2006/03/23 12:18:37 | 000,000,067 | —- | C] () – C:\WINDOWS\A1 DVD Audio Ripper.INI
[2006/03/23 12:05:25 | 000,000,067 | —- | C] () – C:\WINDOWS\#1 DVD Audio Ripper.INI
[2006/02/23 00:31:16 | 000,001,047 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/02/23 00:11:59 | 000,000,127 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\fusioncache.dat
[2006/02/12 18:15:58 | 000,000,051 | —- | C] () – C:\WINDOWS\iTouch.ini
[2006/02/12 17:25:37 | 000,001,223 | —- | C] () – C:\WINDOWS\System32\04ugri2o.sys
[2005/12/15 19:53:40 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/12/15 09:47:41 | 000,223,128 | —- | C] () – C:\WINDOWS\System32\drivers\dtscsi.sys
[2005/12/15 09:45:26 | 000,664,064 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2005/08/25 18:35:52 | 000,105,472 | —- | C] () – C:\WINDOWS\System32\LGUICOM.DLL
[2005/08/25 18:35:52 | 000,000,488 | —- | C] () – C:\WINDOWS\Cmousecc.ini
[2005/06/16 17:17:16 | 000,071,680 | —- | C] () – C:\WINDOWS\System32\CTMMACTL.DLL
[2005/03/09 19:50:20 | 000,033,792 | —- | C] () – C:\WINDOWS\System32\drivers\libusb0.sys
[2005/01/28 11:44:48 | 000,000,035 | —- | C] () – C:\WINDOWS\WorldBuilder.INI
[2004/09/20 12:19:02 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/09/15 15:59:53 | 000,000,077 | —- | C] () – C:\WINDOWS\PTFileExplorer.INI
[2004/09/01 06:27:40 | 000,000,023 | —- | C] () – C:\WINDOWS\kodakpcd.User.ini
[2004/07/14 15:34:53 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2004/07/14 15:34:53 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\TrackerNET.dll
[2004/05/29 13:42:27 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/05/29 13:41:56 | 000,037,727 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2004/05/29 13:32:58 | 000,000,191 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/05/29 13:10:40 | 000,000,011 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/05/12 19:56:36 | 000,634,880 | —- | C] () – C:\WINDOWS\System32\pemicro_serialcm2.dll
[2004/04/29 13:41:42 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\ungwum.dll
[2004/03/23 23:24:46 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\frapsvid.dll
[2004/03/22 17:10:03 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2004/03/22 14:52:26 | 000,000,520 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/03/20 17:02:53 | 000,022,014 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/03/17 23:15:18 | 000,134,144 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/03/17 10:58:03 | 000,001,065 | —- | C] () – C:\WINDOWS\winamp.ini
[2004/03/17 01:59:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2000/08/03 13:25:12 | 000,023,296 | —- | C] () – C:\WINDOWS\System32\pedrv.sys
[2000/08/03 13:25:12 | 000,023,296 | —- | C] () – C:\WINDOWS\System32\drivers\pedrv.sys
[1998/10/02 09:20:46 | 000,005,200 | —- | C] () – C:\WINDOWS\System32\drivers\vichw11.sys
[1996/05/29 16:20:04 | 000,035,072 | —- | C] () – C:\WINDOWS\System32\SENDKEY.DLL
[1996/04/03 21:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\drivers\GIVEIO.SYS
========== LOP Check ==========
[2008/12/09 22:14:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore
[2010/05/18 07:40:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM
[2005/12/14 20:34:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Autodesk
[2009/12/31 12:19:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\BVRP Software
[2009/09/01 19:00:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON
[2009/10/06 20:18:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\FlashFXP
[2008/05/04 17:31:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
[2005/04/15 18:49:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Groove Games
[2009/09/03 21:36:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PreEmptive Solutions
[2009/09/05 20:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Processor Expert
[2005/12/15 20:01:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Propellerhead Software
[2009/06/06 12:39:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Seagate
[2007/06/03 17:37:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\SlySoft
[2010/02/01 14:04:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2009/07/02 19:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
[2009/01/26 10:07:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\vsosdk
[2010/06/22 16:42:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/11/22 19:20:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2008/12/09 22:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\acccore
[2006/02/21 11:52:26 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Aim
[2009/11/28 17:42:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\com.directv.supercast.AA1ECC8BBAFE4E1BBF2D418DC006AF207FACE6CA.1
[2008/04/07 12:44:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Command & Conquer 3 Kane's Wrath
[2007/03/30 16:56:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Command & Conquer 3 Tiberium Wars
[2010/12/28 09:38:26 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Dropbox
[2004/12/05 17:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\EBookSys
[2009/11/04 09:05:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Epson
[2010/05/04 09:26:45 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Facebook
[2010/12/16 14:58:12 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FileZilla
[2009/11/18 20:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\hte
[2009/01/07 13:56:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ImTOO Software Studio
[2009/09/01 19:02:30 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Leadertech
[2010/09/15 16:44:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Notepad++
[2009/12/13 22:58:37 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\NwDocx
[2009/09/05 20:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Processor Expert
[2005/12/15 20:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Propellerhead Software
[2008/11/15 15:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Red Alert 3
[2007/07/07 12:30:43 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Redemption
[2009/09/06 21:30:16 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SealedMedia
[2006/09/06 18:33:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SlySoft
[2009/02/27 09:58:01 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Teleca
[2007/08/18 11:58:46 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\TrojanHunter
[2010/04/02 11:24:17 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Ubisoft
[2009/10/23 13:58:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Viewpoint
[2010/12/20 12:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Vso
[2009/09/09 09:04:52 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilinx
[2010/12/19 11:43:53 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\xVideoServiceThief
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2003/09/05 19:22:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/03/07 18:10:28 | 000,000,003 | —- | M] () – C:\binaryFile.bin
[2010/12/27 16:12:00 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/04/02 10:05:20 | 000,782,398 | —- | M] () – C:\cc_20100402_110457.reg
[2009/06/07 14:59:16 | 000,000,348 | —- | M] () – C:\CKINFO.TXT
[2007/01/04 20:34:52 | 000,008,234 | —- | M] () – C:\clean.bat
[2008/08/27 12:26:48 | 000,011,330 | —- | M] () – C:\ComboFix.txt
[2007/04/01 10:56:33 | 000,014,875 | —- | M] () – C:\ComboFix2.txt
[2007/03/30 13:23:37 | 000,016,562 | —- | M] () – C:\ComboFix3.txt
[2003/09/05 19:22:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/09/01 15:52:58 | 000,000,060 | —- | M] () – C:\CorrectAnswers.txt
[2007/06/16 16:14:23 | 000,062,373 | —- | M] () – C:\debug.log
[2010/12/27 16:20:24 | 000,000,432 | —- | M] () – C:\haxfix.txt
[2007/08/16 13:16:52 | 000,000,753 | —- | M] () – C:\haxlog.txt
[2010/04/24 06:36:09 | 000,460,824 | —- | M] () – C:\img2-001.raw
[2003/09/05 19:22:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/18 07:40:13 | 000,001,106 | -H– | M] () – C:\IPH.PH
[2004/05/22 08:23:26 | 000,000,000 | —- | M] () – C:\itouch_config_crash_info.txt
[2006/05/31 08:23:37 | 000,000,374 | —- | M] () – C:\itouch_crash_info.txt
[2004/08/24 09:05:28 | 000,000,004 | —- | M] () – C:\loadcounter.dat
[2009/09/06 20:55:27 | 000,000,302 | —- | M] () – C:\lxbt.log
[2004/03/22 14:42:04 | 000,000,062 | —- | M] () – C:\MMCD.INI
[2003/09/05 19:22:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/09/29 13:21:39 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/10 15:22:10 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/28 09:36:51 | 1048,576,000 | -HS- | M] () – C:\pagefile.sys
[2009/09/06 20:51:46 | 000,000,744 | —- | M] () – C:\pedriver.txt
[2004/03/22 14:42:10 | 000,000,207 | —- | M] () – C:\RECache.idx
[2010/03/03 14:38:21 | 000,000,370 | —- | M] () – C:\rkill.log
[2004/07/15 10:31:18 | 000,393,216 | —- | M] () – C:\t18g
[2004/07/15 11:29:14 | 000,073,728 | —- | M] () – C:\t18g.1
[2010/04/01 15:39:41 | 000,000,319 | —- | M] () – C:\trojan_fakerean_exe_fix.reg
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/03/17 10:08:08 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 04:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\W32X86\filterpipelineprintproc.dll
[2008/07/06 02:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\W32X86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/03/17 01:57:02 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/03/17 01:57:02 | 000,606,208 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/03/17 01:57:02 | 000,409,600 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/10 15:31:56 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/09/29 13:34:49 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/04/16 15:31:49 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/12/28 09:59:46 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/12/12 20:52:21 | 000,454,656 | —- | M] (Simon Tatham) – C:\Documents and Settings\User\Desktop\putty.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2007/04/10 13:46:48 | 000,013,023 | —- | M] () – C:\WINDOWS\VX3000.src
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-15 18:22:44
========== Files - Unicode (All) ==========
[2006/10/20 18:54:55 | 000,131,072 | —- | M] ()(C:\WINDOWS\System32\??????????) – C:\WINDOWS\System32\߆ᜮ⹒铮鿭☠㟺姱㬭湁
[2006/10/20 15:43:46 | 000,131,072 | —- | C] ()(C:\WINDOWS\System32\??????????) – C:\WINDOWS\System32\߆ᜮ⹒铮鿭☠㟺姱㬭湁
========== Alternate Data Streams ==========
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:0CE7F3C9
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:3B71D0B4
< End of report >
DDS log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:25:49.65 on Tue 12/28/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.343 [GMT -8:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\CTHELPER.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\vVX3000.exe
C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
I:\nero8\Nero 8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Intel\NCS2\WMIProv\NCS2Prov.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\User\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [zBrowser Launcher] c:\program files\logitech\itouch\iTouch.exe
mRun: [EM_EXEC] c:\progra~1\logitech\mousew~1\system\EM_EXEC.EXE
mRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "i:\nero8\nero 8\nero backitup\NBKeyScan.exe"
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [VX3000] c:\windows\vVX3000.exe
mRun: [EEventManager] c:\progra~1\epsons~1\eventm~1\EEventManager.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\user\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\user\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\user\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office10\OSA.EXE
uPolicies-system: WallpaperStyle = 1
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1187569940500
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\46wl92zj.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\user\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\user\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 sonyhcb;Sony Digital Imaging Base;c:\windows\system32\drivers\sonyhcb.sys [2004-3-22 6097]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-4 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-5-4 27784]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-8 297752]
R2 PEDRV;P&E; Microcomputer System PCI Driver.;c:\windows\system32\drivers\pedrv.sys [2000-8-3 23296]
R2 RTWTKRNL;Real-Time Windows Target;c:\windows\system32\drivers\RTWTKRNL.sys [2008-9-8 27008]
R2 VICHW11;P&E; BDM Cable Driver II;c:\windows\system32\drivers\vichw11.sys [1998-10-2 5200]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-12-9 24652]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2009-12-31 27632]
R4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-12-28 38224]
S2 gupdate1c95c105d981590;Google Update Service (gupdate1c95c105d981590);c:\program files\google\update\GoogleUpdate.exe [2008-12-11 133104]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-2-27 13224]
S3 iMSPCLOj;iMSPCLOj;\??\c:\docume~1\user\locals~1\temp\imspcloj.sys –> c:\docume~1\user\locals~1\temp\iMSPCLOj.sys [?]
S3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCcfltr.sys [2003-9-22 14095]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-3-9 33792]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2009-2-27 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2009-2-27 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2009-2-27 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2009-2-27 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2009-2-27 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2009-2-27 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2009-2-27 115752]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [2009-12-31 86824]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [2009-12-31 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [2009-12-31 114600]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [2009-12-31 108328]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [2009-12-31 26024]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [2009-12-31 104616]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [2009-12-31 109736]
S3 SER120;OTI Serial port driver;c:\windows\system32\drivers\ser120.sys [2005-11-17 32750]
S3 sonyhcs;Sony Digital Imaging Video;c:\windows\system32\drivers\sonyhcs.sys [2004-3-22 299923]
S3 z520bus;Sony Ericsson 520 driver (WDM);c:\windows\system32\drivers\z520bus.sys [2005-7-26 57648]
S3 z520mdfl;Sony Ericsson 520 USB WMC Modem Filter;c:\windows\system32\drivers\z520mdfl.sys [2005-7-26 8336]
S3 z520mdm;Sony Ericsson 520 USB WMC Modem Drivers;c:\windows\system32\drivers\z520mdm.sys [2005-7-26 93488]
S3 z520mgmt;Sony Ericsson 520 USB WMC Device Management Drivers;c:\windows\system32\drivers\z520mgmt.sys [2005-7-26 84928]
S3 z520obex;Sony Ericsson 520 USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\z520obex.sys [2005-7-26 82864]
S4 Mnmloidsduaw;Mnmloidsduaw; [x]
=============== Created Last 30 ================
2010-12-28 09:40 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-28 09:40 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-12-28 09:40 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-12-20 12:35 –d—– c:\program files\DVDFab 7
2010-12-15 14:13 –d—– c:\documents and settings\user\final5
2010-12-15 04:05 40,960 -c—— c:\windows\system32\dllcache\ndproxy.sys
2010-12-14 20:12 –d—– c:\program files\AdvancedReliableSoftware
2010-12-11 23:58 472,808 a——- c:\windows\system32\deployJava1.dll
2010-12-11 23:58 73,728 a——- c:\windows\system32\javacpl.cpl
2010-12-02 19:47 –d—– c:\program files\FoxTabFlvConverter
2010-12-02 19:17 –d—– c:\program files\Xesc & Technology
==================== Find3M ====================
2010-12-14 20:13 162,816 a——- c:\windows\system32\fmod.dll
2010-11-18 10:12 81,920 a——- c:\windows\system32\isign32.dll
2010-11-05 16:26 916,480 a——- c:\windows\system32\wininet.dll
2010-11-05 16:26 43,520 a——- c:\windows\system32\licmgr10.dll
2010-11-02 07:17 40,960 a——- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 05:13 290,048 a——- c:\windows\system32\atmfd.dll
2010-10-26 05:25 1,853,312 a——- c:\windows\system32\win32k.sys
2010-01-20 13:33 40,896 ac—— c:\docume~1\user\applic~1\GDIPFONTCACHEV1.DAT
2009-04-29 12:17 87,608 ac—— c:\docume~1\user\applic~1\inst.exe
2009-04-29 12:17 47,360 ac—— c:\docume~1\user\applic~1\pcouffin.sys
2008-08-09 17:38 81,920 ac—— c:\docume~1\user\applic~1\ezpinst.exe
2006-04-29 11:31 1 ac—— c:\documents and settings\user\SI.bin
2009-09-05 20:34 18 ac-sh— c:\windows\WINPROD.DLL
2008-09-10 15:40 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091020080911\index.dat
2009-12-19 18:39 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat
============= FINISH: 10:26:11.20 ===============
When im in the command prompt and try to do " ipconfig /release " then renew after it times out. Something software related is preventing me from connecting to the internet.
Please help me
Malwarebytes finds nothing and neither does AVG full scan.
HJT log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:55:35 AM, on 12/28/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\CTHELPER.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\vVX3000.exe
C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
I:\nero8\Nero 8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "I:\nero8\Nero 8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1187569940500
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate1c95c105d981590) (gupdate1c95c105d981590) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - I:\nero8\Nero 8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 7811 bytes
OTL log:
OTL logfile created on: 12/28/2010 10:05:58 AM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,023.00 Mb Total Physical Memory | 340.00 Mb Available Physical Memory | 33.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 1000 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 6.96 Gb Free Space | 18.66% Space Free | Partition Type: NTFS
Drive H: | 120.16 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive I: | 148.89 Gb Total Space | 39.19 Gb Free Space | 26.32% Space Free | Partition Type: FAT32
Drive J: | 37.27 Gb Total Space | 3.80 Gb Free Space | 10.19% Space Free | Partition Type: NTFS
Drive K: | 3.88 Gb Total Space | 2.86 Gb Free Space | 73.80% Space Free | Partition Type: FAT32
Drive P: | 55.88 Gb Total Space | 14.00 Gb Free Space | 25.05% Space Free | Partition Type: NTFS
Computer Name: OFFICE | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - I:\nero8\Nero 8\Nero BackItUp\NBService.exe (Nero AG)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
PRC - C:\Program Files\Winamp\winamp.exe (Nullsoft)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)
MOD - C:\Program Files\Logitech\iTouch\itchhk.dll (Logitech Inc.)
MOD - C:\Program Files\Common Files\Logitech\Scrolling\LGMSGHK.DLL (Logitech Inc.)
MOD - C:\Program Files\Logitech\iTouch\KbdHook.dll (Logitech Inc.)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Crypkey License) – C:\WINDOWS\System32\Crypserv.exe (CrypKey (Canada) Ltd.)
SRV - (msvsmon90) – P:\VS\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 3) – I:\nero8\Nero 8\Nero BackItUp\NBService.exe (Nero AG)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (mi-raysat_3dsmax8) – J:\3ds Max 8\mentalray\satellite\raysat_3dsmax8server.exe ()
SRV - (EPSONStatusAgent2) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (SYMIDSCO) – C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20051208.051\symidsco.sys File not found
DRV - (mcdbus) – C:\WINDOWS\System32\DRIVERS\mcdbus.sys File not found
DRV - (LHidFlt2) – C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys File not found
DRV - (iMSPCLOj) – C:\DOCUME~1\User\LOCALS~1\Temp\iMSPCLOj.sys File not found
DRV - (ENTECH) – C:\WINDOWS\System32\DRIVERS\ENTECH.sys File not found
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ggsemc) – C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (s0017mdm) – C:\WINDOWS\system32\drivers\s0017mdm.sys (MCCI Corporation)
DRV - (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM) – C:\WINDOWS\system32\drivers\s0017unic.sys (MCCI Corporation)
DRV - (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s0017mgmt.sys (MCCI Corporation)
DRV - (s0017obex) – C:\WINDOWS\system32\drivers\s0017obex.sys (MCCI Corporation)
DRV - (s0017bus) Sony Ericsson Device 0017 driver (WDM) – C:\WINDOWS\system32\drivers\s0017bus.sys (MCCI Corporation)
DRV - (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS) – C:\WINDOWS\system32\drivers\s0017nd5.sys (MCCI Corporation)
DRV - (s0017mdfl) – C:\WINDOWS\system32\drivers\s0017mdfl.sys (MCCI Corporation)
DRV - (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM) – C:\WINDOWS\system32\drivers\s0016unic.sys (MCCI Corporation)
DRV - (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS) – C:\WINDOWS\system32\drivers\s0016nd5.sys (MCCI Corporation)
DRV - (s0016mdfl) – C:\WINDOWS\system32\drivers\s0016mdfl.sys (MCCI Corporation)
DRV - (s0016mdm) – C:\WINDOWS\system32\drivers\s0016mdm.sys (MCCI Corporation)
DRV - (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s0016mgmt.sys (MCCI Corporation)
DRV - (s0016obex) – C:\WINDOWS\system32\drivers\s0016obex.sys (MCCI Corporation)
DRV - (s0016bus) Sony Ericsson Device 0016 driver (WDM) – C:\WINDOWS\system32\drivers\s0016bus.sys (MCCI Corporation)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (NetworkX) – C:\WINDOWS\system32\ckldrv.sys ()
DRV - (seehcri) – C:\WINDOWS\system32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (Ser2pl) – C:\WINDOWS\system32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (Applied Networking Inc.)
DRV - (dtscsi) – C:\WINDOWS\System32\Drivers\dtscsi.sys ()
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (VX3000) – C:\WINDOWS\system32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (hap17v2k) – C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (z520obex) – C:\WINDOWS\system32\drivers\z520obex.sys (MCCI)
DRV - (z520mgmt) – C:\WINDOWS\system32\drivers\z520mgmt.sys (MCCI)
DRV - (z520mdm) – C:\WINDOWS\system32\drivers\z520mdm.sys (MCCI)
DRV - (z520mdfl) – C:\WINDOWS\system32\drivers\z520mdfl.sys (MCCI)
DRV - (z520bus) Sony Ericsson 520 driver (WDM) – C:\WINDOWS\system32\drivers\z520bus.sys (MCCI)
DRV - (w810obex) – C:\WINDOWS\system32\drivers\w810obex.sys (MCCI)
DRV - (w810mdm) – C:\WINDOWS\system32\drivers\w810mdm.sys (MCCI)
DRV - (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\w810mgmt.sys (MCCI)
DRV - (w810mdfl) – C:\WINDOWS\system32\drivers\w810mdfl.sys (MCCI)
DRV - (w810bus) Sony Ericsson W810 Driver driver (WDM) – C:\WINDOWS\system32\drivers\w810bus.sys (MCCI)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (libusb0) – C:\WINDOWS\system32\drivers\libusb0.sys ()
DRV - (SER120) – C:\WINDOWS\system32\drivers\ser120.sys (USB Com port.)
DRV - (itchfltr) – C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
DRV - (LHidUsb) – C:\WINDOWS\system32\drivers\LHidUsb.sys (Logitech, Inc.)
DRV - (LCcfltr) – C:\WINDOWS\system32\drivers\LCcfltr.sys (Logitech, Inc.)
DRV - (TIEHDUSB) – C:\WINDOWS\system32\drivers\tiehdusb.sys (Texas Instruments Incorporated)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (RTWTKRNL) – C:\WINDOWS\system32\drivers\RTWTKRNL.sys ()
DRV - (sonyhcs) – C:\WINDOWS\system32\drivers\sonyhcs.sys (Sony Corporation)
DRV - (sonyhcb) – C:\WINDOWS\System32\DRIVERS\sonyhcb.sys (Sony Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PEDRV) – C:\WINDOWS\System32\drivers\pedrv.sys ()
DRV - (VICHW11) – C:\WINDOWS\System32\drivers\vichw11.sys ()
DRV - (GIVEIO) – C:\WINDOWS\System32\drivers\GIVEIO.SYS ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 18 34 AB 7E 1D 81 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/21 09:02:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/14 09:41:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/12 10:01:01 | 000,000,000 | —D | M]
[2008/08/25 20:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/12/25 15:34:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions
[2010/04/28 13:40:30 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/07/14 17:25:54 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions\[removed]
[2010/10/03 13:05:49 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions\vshare@toolbar
[2010/12/27 16:05:48 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/12/11 23:58:40 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/11 23:58:14 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/04/16 09:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2010/12/27 16:51:26 | 000,000,736 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EM_EXEC] C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc. )
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NBKeyScan] I:\nero8\Nero 8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [VX3000] C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe File not found
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/d/4…0367/wmavax.CAB (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1187569940500 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/09/05 19:22:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/09/22 21:25:28 | 000,000,043 | R— | M] () - H:\AUTORUN.INF – [ CDFS ]
O32 - AutoRun File - [2006/11/02 11:00:34 | 000,909,530 | R— | M] (InstallShield Software Corporation) - H:\Autopoll Application V1.04.exe – [ CDFS ]
O32 - AutoRun File - [2008/09/14 19:38:08 | 000,000,122 | RHS- | M] () - I:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{01b326cd-ea62-11de-98fd-000d61c1efb2}\Shell\AutoRun\command - "" = P:\Xilinx\EDK\bin\nt\setup.exe – [2008/02/20 09:47:10 | 000,012,288 | —- | M] ()
O33 - MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{607f01e2-1531-11dd-970c-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{607f01e2-1531-11dd-970c-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{607f01e2-1531-11dd-970c-000d61c1efb2}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{abe72b8c-d273-11db-8c4a-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{abe72b8c-d273-11db-8c4a-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{abe72b8c-d273-11db-8c4a-000d61c1efb2}\Shell\AutoRun\command - "" = H:\ONSPCLCK.exe – [2006/11/02 12:55:10 | 002,519,040 | R— | M] (OnSpec Electronic, Inc.)
O33 - MountPoints2\{abe72b8f-d273-11db-8c4a-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{abe72b8f-d273-11db-8c4a-000d61c1efb2}\Shell\1\Command - "" = .\recycled\info.exe
O33 - MountPoints2\{abe72b8f-d273-11db-8c4a-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\KODAK_Software_Downloader.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\ONSPCLCK.exe – [2006/11/02 12:55:10 | 002,519,040 | R— | M] (OnSpec Electronic, Inc.)
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\1\Command - "" = .\recycled\info.exe
O33 - MountPoints2\I\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/12/28 10:02:06 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/12/28 09:40:31 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/28 09:40:26 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/28 09:40:25 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/20 16:53:56 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Cubic
[2010/12/20 12:35:53 | 000,000,000 | —D | C] – C:\Program Files\DVDFab 7
[2010/12/20 12:33:38 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\DVDFab.Platinum.7070
[2010/12/15 14:13:11 | 000,000,000 | —D | C] – C:\Documents and Settings\User\final5
[2010/12/15 04:05:00 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2010/12/14 20:13:11 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\AdvancedReliableSoftware
[2010/12/14 20:12:11 | 000,000,000 | —D | C] – C:\Program Files\AdvancedReliableSoftware
[2010/12/13 20:43:58 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\FileZilla
[2010/12/13 20:43:22 | 000,000,000 | —D | C] – C:\Program Files\FileZilla FTP Client
[2010/12/12 20:52:10 | 000,454,656 | —- | C] (Simon Tatham) – C:\Documents and Settings\User\Desktop\putty.exe
[2010/12/12 16:17:11 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Masharoni and Cheese
[2010/12/12 16:11:51 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\vice-breakfast-clubbin
[2010/12/12 16:11:45 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\DJ-Vice-Vice-Vice-Baby-CD
[2010/12/12 16:05:28 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\DJVice-LateNights.mp3
[2010/12/11 23:59:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Sun
[2010/12/11 23:58:36 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/12/11 23:58:36 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/11 23:58:36 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/12/11 23:58:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/11 23:58:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/02 19:47:19 | 000,000,000 | —D | C] – C:\Program Files\FoxTabFlvConverter
[2010/12/02 19:17:30 | 000,000,000 | —D | C] – C:\Program Files\Xesc & Technology
[2008/07/26 16:05:52 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\User\Application Data\pcouffin.sys
[2006/08/11 14:56:28 | 000,033,792 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/28 10:11:50 | 000,001,065 | —- | M] () – C:\WINDOWS\winamp.ini
[2010/12/28 09:59:46 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/12/28 09:59:12 | 000,359,929 | —- | M] () – C:\Documents and Settings\User\Desktop\dds.scr
[2010/12/28 09:46:56 | 000,001,982 | —- | M] () – C:\Documents and Settings\User\Desktop\HiJackThis.lnk
[2010/12/28 09:39:58 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/28 09:38:46 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/12/28 09:37:41 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/28 09:35:58 | 000,031,656 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,031,656 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,028,968 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,028,968 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2010/12/28 09:35:58 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2010/12/28 09:35:44 | 003,162,278 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-00511102}.CDF
[2010/12/28 09:35:44 | 003,162,278 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-00511102}.BAK
[2010/12/28 09:22:14 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/27 18:41:22 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk
[2010/12/27 16:33:05 | 000,000,032 | —- | M] () – C:\WINDOWS\System32\thxcfg.ini
[2010/12/27 16:29:56 | 000,134,144 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/27 16:12:00 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/12/27 15:47:27 | 000,548,546 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/12/27 15:47:27 | 000,098,270 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/12/24 13:13:36 | 008,755,789 | —- | M] () – C:\Documents and Settings\User\Desktop\Dwyck.mp3
[2010/12/24 13:11:42 | 005,931,008 | —- | M] () – C:\Documents and Settings\User\Desktop\16_Deadmau5_-_Ghosts_N_Stuff.mp3
[2010/12/24 13:11:42 | 004,769,792 | —- | M] () – C:\Documents and Settings\User\Desktop\techn9ne-im_a_playa.mp3
[2010/12/24 13:09:18 | 005,060,080 | —- | M] () – C:\Documents and Settings\User\Desktop\bon_jovi.mp3
[2010/12/24 13:09:10 | 004,015,461 | —- | M] () – C:\Documents and Settings\User\Desktop\Indeep - Last Night The DJ Save my Life.mp3
[2010/12/24 13:08:27 | 009,684,238 | —- | M] () – C:\Documents and Settings\User\Desktop\ontheroad.mp3
[2010/12/24 13:07:54 | 003,107,158 | —- | M] () – C:\Documents and Settings\User\Desktop\preview.mp3
[2010/12/24 09:21:56 | 069,305,001 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/12/23 20:22:47 | 001,091,284 | —- | M] () – C:\Documents and Settings\User\Desktop\us.JPG
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/20 12:36:01 | 000,000,618 | —- | M] () – C:\Documents and Settings\User\Desktop\DVDFab 7.lnk
[2010/12/19 20:56:31 | 020,389,892 | —- | M] () – C:\Documents and Settings\User\Desktop\DVDFab.Platinum.7070.rar
[2010/12/19 20:20:40 | 000,099,557 | —- | M] () – C:\Documents and Settings\User\Desktop\attachments_2010_12_19.zip
[2010/12/19 12:10:49 | 005,073,765 | —- | M] () – C:\Documents and Settings\User\Desktop\Smoke Gets In Your EyesThe Platters.mp3
[2010/12/19 12:09:00 | 001,111,286 | —- | M] () – C:\Documents and Settings\User\Desktop\01 O Fortuna (Carmina Burana).m4r
[2010/12/19 11:46:42 | 096,698,408 | —- | M] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].wav
[2010/12/19 11:44:20 | 019,847,934 | —- | M] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].mp4
[2010/12/19 11:42:24 | 000,813,858 | —- | M] () – C:\Documents and Settings\User\Desktop\Carl Orff - O Fortuna.mp3
[2010/12/19 11:28:02 | 002,048,449 | —- | M] () – C:\Documents and Settings\User\Desktop\Bed-Intruder-Song-wwwLINKWHIPcom.mp3
[2010/12/19 11:27:12 | 003,522,560 | —- | M] () – C:\Documents and Settings\User\Desktop\carl_orff-o_fortuna_(carmina_burana).mp3
[2010/12/17 21:49:52 | 004,087,794 | —- | M] () – C:\Documents and Settings\User\Desktop\DSCN3264.JPG
[2010/12/16 14:14:31 | 000,000,600 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\PUTTY.RND
[2010/12/16 10:58:40 | 000,002,483 | —- | M] () – C:\Documents and Settings\User\Desktop\Microsoft Word.lnk
[2010/12/15 20:26:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/15 13:09:30 | 000,189,000 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/15 10:22:34 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/12/15 08:13:58 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/12/14 22:30:02 | 000,000,392 | —- | M] () – C:\Documents and Settings\User\Desktop\AdjustiTunesPlayCount.js
[2010/12/14 20:13:30 | 000,162,816 | —- | M] (Firelight Technologies Pty, Ltd) – C:\WINDOWS\System32\fmod.dll
[2010/12/13 20:43:29 | 000,001,663 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\FileZilla Client.lnk
[2010/12/12 20:52:21 | 000,454,656 | —- | M] (Simon Tatham) – C:\Documents and Settings\User\Desktop\putty.exe
[2010/12/12 15:48:19 | 075,370,256 | —- | M] () – C:\Documents and Settings\User\Desktop\01LateNights.mp3
[2010/12/12 15:47:28 | 141,947,581 | —- | M] () – C:\Documents and Settings\User\Desktop\Breakfast-Clubbin.mp3
[2010/12/12 15:46:49 | 033,966,744 | —- | M] () – C:\Documents and Settings\User\Desktop\Vice-Vice-Baby.mp3
[2010/12/12 15:23:16 | 000,071,447 | —- | M] () – C:\Documents and Settings\User\Desktop\tumblr_lc9girUWfW1qctkcl.jpg
[2010/12/12 15:21:00 | 000,064,914 | —- | M] () – C:\Documents and Settings\User\Desktop\tumblr_ld48hjE7JF1qctkcl.jpg
[2010/12/12 15:05:55 | 075,765,411 | —- | M] () – C:\Documents and Settings\User\Desktop\THEBLASTOFF3THEROCKITSCIENTISTS.mp3
[2010/12/12 15:03:41 | 062,980,935 | —- | M] () – C:\Documents and Settings\User\Desktop\rockitBLASTOFF2.mp3
[2010/12/11 23:58:12 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/12/11 23:58:12 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/11 23:58:12 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/11 23:58:12 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/11 23:58:12 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/28 10:02:06 | 000,359,929 | —- | C] () – C:\Documents and Settings\User\Desktop\dds.scr
[2010/12/28 09:46:56 | 000,001,982 | —- | C] () – C:\Documents and Settings\User\Desktop\HiJackThis.lnk
[2010/12/27 16:20:01 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\swsc.exe
[2010/12/24 13:11:36 | 004,769,792 | —- | C] () – C:\Documents and Settings\User\Desktop\techn9ne-im_a_playa.mp3
[2010/12/24 13:11:16 | 005,931,008 | —- | C] () – C:\Documents and Settings\User\Desktop\16_Deadmau5_-_Ghosts_N_Stuff.mp3
[2010/12/24 13:09:34 | 008,755,789 | —- | C] () – C:\Documents and Settings\User\Desktop\Dwyck.mp3
[2010/12/24 13:09:12 | 005,060,080 | —- | C] () – C:\Documents and Settings\User\Desktop\bon_jovi.mp3
[2010/12/24 13:08:47 | 004,015,461 | —- | C] () – C:\Documents and Settings\User\Desktop\Indeep - Last Night The DJ Save my Life.mp3
[2010/12/24 13:08:20 | 009,684,238 | —- | C] () – C:\Documents and Settings\User\Desktop\ontheroad.mp3
[2010/12/24 13:07:48 | 003,107,158 | —- | C] () – C:\Documents and Settings\User\Desktop\preview.mp3
[2010/12/24 09:52:42 | 004,087,794 | —- | C] () – C:\Documents and Settings\User\Desktop\DSCN3264.JPG
[2010/12/23 20:22:37 | 001,091,284 | —- | C] () – C:\Documents and Settings\User\Desktop\us.JPG
[2010/12/20 12:36:01 | 000,000,618 | —- | C] () – C:\Documents and Settings\User\Desktop\DVDFab 7.lnk
[2010/12/19 20:54:59 | 020,389,892 | —- | C] () – C:\Documents and Settings\User\Desktop\DVDFab.Platinum.7070.rar
[2010/12/19 20:20:38 | 000,099,557 | —- | C] () – C:\Documents and Settings\User\Desktop\attachments_2010_12_19.zip
[2010/12/19 12:11:57 | 001,111,286 | —- | C] () – C:\Documents and Settings\User\Desktop\01 O Fortuna (Carmina Burana).m4r
[2010/12/19 12:10:33 | 005,073,765 | —- | C] () – C:\Documents and Settings\User\Desktop\Smoke Gets In Your EyesThe Platters.mp3
[2010/12/19 11:43:32 | 096,698,408 | —- | C] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].wav
[2010/12/19 11:42:24 | 000,813,858 | —- | C] () – C:\Documents and Settings\User\Desktop\Carl Orff - O Fortuna.mp3
[2010/12/19 11:37:35 | 019,847,934 | —- | C] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].mp4
[2010/12/19 11:28:02 | 002,048,449 | —- | C] () – C:\Documents and Settings\User\Desktop\Bed-Intruder-Song-wwwLINKWHIPcom.mp3
[2010/12/19 11:27:12 | 003,522,560 | —- | C] () – C:\Documents and Settings\User\Desktop\carl_orff-o_fortuna_(carmina_burana).mp3
[2010/12/14 22:20:55 | 000,000,392 | —- | C] () – C:\Documents and Settings\User\Desktop\AdjustiTunesPlayCount.js
[2010/12/13 20:43:29 | 000,001,663 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\FileZilla Client.lnk
[2010/12/12 21:59:01 | 000,000,600 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\PUTTY.RND
[2010/12/12 15:46:11 | 033,966,744 | —- | C] () – C:\Documents and Settings\User\Desktop\Vice-Vice-Baby.mp3
[2010/12/12 15:45:31 | 141,947,581 | —- | C] () – C:\Documents and Settings\User\Desktop\Breakfast-Clubbin.mp3
[2010/12/12 15:41:20 | 075,370,256 | —- | C] () – C:\Documents and Settings\User\Desktop\01LateNights.mp3
[2010/12/12 15:23:15 | 000,071,447 | —- | C] () – C:\Documents and Settings\User\Desktop\tumblr_lc9girUWfW1qctkcl.jpg
[2010/12/12 15:20:59 | 000,064,914 | —- | C] () – C:\Documents and Settings\User\Desktop\tumblr_ld48hjE7JF1qctkcl.jpg
[2010/12/12 14:59:24 | 075,765,411 | —- | C] () – C:\Documents and Settings\User\Desktop\THEBLASTOFF3THEROCKITSCIENTISTS.mp3
[2010/12/12 14:58:46 | 062,980,935 | —- | C] () – C:\Documents and Settings\User\Desktop\rockitBLASTOFF2.mp3
[2010/04/01 15:11:40 | 000,012,298 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\8Cq4r
[2010/04/01 15:11:40 | 000,012,298 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\8Cq4r
[2009/12/13 21:36:39 | 000,123,083 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\debuggee.mdmp
[2009/09/23 20:17:42 | 000,000,965 | —- | C] () – C:\WINDOWS\mcutools.ini
[2009/09/05 20:34:56 | 000,000,018 | -HS- | C] () – C:\WINDOWS\WINPROD.DLL
[2009/09/03 00:20:12 | 000,000,000 | —- | C] () – C:\WINDOWS\EEventManager.INI
[2009/09/01 18:59:11 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/09/01 18:53:31 | 000,000,079 | —- | C] () – C:\WINDOWS\EPNX510.ini
[2009/06/06 16:20:31 | 000,000,068 | —- | C] () – C:\WINDOWS\spwdr.INI
[2009/06/06 16:19:56 | 000,000,071 | —- | C] () – C:\WINDOWS\Crypkey.ini
[2009/06/06 16:19:53 | 000,019,584 | —- | C] () – C:\WINDOWS\System32\Ckldrv.sys
[2009/06/06 16:19:53 | 000,018,432 | —- | C] () – C:\WINDOWS\Setup_ck.dll
[2009/06/06 11:59:34 | 000,000,072 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\FASTWiz.log
[2009/02/28 18:30:21 | 000,087,608 | —- | C] () – C:\Documents and Settings\User\Application Data\inst.exe
[2009/02/27 15:53:43 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/01/29 16:08:39 | 000,015,498 | —- | C] () – C:\WINDOWS\VX3000.ini
[2008/09/08 19:21:19 | 000,027,008 | —- | C] () – C:\WINDOWS\System32\drivers\RTWTKRNL.sys
[2008/09/08 19:17:03 | 000,000,158 | —- | C] () – C:\WINDOWS\matlab.ini
[2008/07/26 16:06:05 | 000,000,034 | —- | C] () – C:\Documents and Settings\User\Application Data\pcouffin.log
[2008/07/26 16:05:52 | 000,081,920 | —- | C] () – C:\Documents and Settings\User\Application Data\ezpinst.exe
[2008/07/26 16:05:52 | 000,007,887 | —- | C] () – C:\Documents and Settings\User\Application Data\pcouffin.cat
[2008/07/26 16:05:52 | 000,001,144 | —- | C] () – C:\Documents and Settings\User\Application Data\pcouffin.inf
[2008/06/17 13:37:52 | 000,044,032 | —- | C] () – C:\WINDOWS\System32\tbdml.dll
[2008/05/04 14:31:37 | 000,086,446 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2008/03/25 16:29:20 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\thxcfg.ini
[2007/12/03 20:14:05 | 000,000,060 | —- | C] () – C:\WINDOWS\EntPack.ini
[2007/08/18 11:57:47 | 000,059,392 | R— | C] () – C:\WINDOWS\System32\streamhlp.dll
[2007/07/07 12:29:00 | 000,000,136 | —- | C] () – C:\WINDOWS\REDEMUNINS.INI
[2007/06/03 14:44:23 | 000,096,384 | —- | C] () – C:\WINDOWS\System32\drivers\sptd8237.sys
[2007/05/29 11:38:02 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/04/23 15:17:25 | 000,000,110 | —- | C] () – C:\WINDOWS\gui.INI
[2007/03/14 17:53:25 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2007/03/14 17:53:25 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/03/02 17:51:26 | 000,003,072 | —- | C] () – C:\WINDOWS\CTXFIRES.DLL
[2007/02/02 18:25:12 | 000,000,080 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\.zreglib
[2006/10/20 15:43:48 | 000,051,712 | —- | C] () – C:\WINDOWS\System32\wglhlvh.dll
[2006/10/10 23:25:38 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2006/09/06 18:32:03 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\User\Application Data\.zreglib
[2006/08/11 13:57:18 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\CTBURST.DLL
[2006/08/06 15:45:44 | 000,001,334 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\QTSBandwidthCache
[2006/07/07 19:57:50 | 000,000,225 | —- | C] () – C:\WINDOWS\em06y.ini
[2006/07/07 19:57:42 | 000,000,410 | —- | C] () – C:\WINDOWS\ptrol.dll
[2006/05/23 11:40:34 | 000,000,269 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2006/05/20 09:37:34 | 000,000,339 | —- | C] () – C:\WINDOWS\dellstat.ini
[2006/03/23 12:18:37 | 000,000,067 | —- | C] () – C:\WINDOWS\A1 DVD Audio Ripper.INI
[2006/03/23 12:05:25 | 000,000,067 | —- | C] () – C:\WINDOWS\#1 DVD Audio Ripper.INI
[2006/02/23 00:31:16 | 000,001,047 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/02/23 00:11:59 | 000,000,127 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\fusioncache.dat
[2006/02/12 18:15:58 | 000,000,051 | —- | C] () – C:\WINDOWS\iTouch.ini
[2006/02/12 17:25:37 | 000,001,223 | —- | C] () – C:\WINDOWS\System32\04ugri2o.sys
[2005/12/15 19:53:40 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/12/15 09:47:41 | 000,223,128 | —- | C] () – C:\WINDOWS\System32\drivers\dtscsi.sys
[2005/12/15 09:45:26 | 000,664,064 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2005/08/25 18:35:52 | 000,105,472 | —- | C] () – C:\WINDOWS\System32\LGUICOM.DLL
[2005/08/25 18:35:52 | 000,000,488 | —- | C] () – C:\WINDOWS\Cmousecc.ini
[2005/06/16 17:17:16 | 000,071,680 | —- | C] () – C:\WINDOWS\System32\CTMMACTL.DLL
[2005/03/09 19:50:20 | 000,033,792 | —- | C] () – C:\WINDOWS\System32\drivers\libusb0.sys
[2005/01/28 11:44:48 | 000,000,035 | —- | C] () – C:\WINDOWS\WorldBuilder.INI
[2004/09/20 12:19:02 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/09/15 15:59:53 | 000,000,077 | —- | C] () – C:\WINDOWS\PTFileExplorer.INI
[2004/09/01 06:27:40 | 000,000,023 | —- | C] () – C:\WINDOWS\kodakpcd.User.ini
[2004/07/14 15:34:53 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2004/07/14 15:34:53 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\TrackerNET.dll
[2004/05/29 13:42:27 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/05/29 13:41:56 | 000,037,727 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2004/05/29 13:32:58 | 000,000,191 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/05/29 13:10:40 | 000,000,011 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/05/12 19:56:36 | 000,634,880 | —- | C] () – C:\WINDOWS\System32\pemicro_serialcm2.dll
[2004/04/29 13:41:42 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\ungwum.dll
[2004/03/23 23:24:46 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\frapsvid.dll
[2004/03/22 17:10:03 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2004/03/22 14:52:26 | 000,000,520 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/03/20 17:02:53 | 000,022,014 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/03/17 23:15:18 | 000,134,144 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/03/17 10:58:03 | 000,001,065 | —- | C] () – C:\WINDOWS\winamp.ini
[2004/03/17 01:59:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2000/08/03 13:25:12 | 000,023,296 | —- | C] () – C:\WINDOWS\System32\pedrv.sys
[2000/08/03 13:25:12 | 000,023,296 | —- | C] () – C:\WINDOWS\System32\drivers\pedrv.sys
[1998/10/02 09:20:46 | 000,005,200 | —- | C] () – C:\WINDOWS\System32\drivers\vichw11.sys
[1996/05/29 16:20:04 | 000,035,072 | —- | C] () – C:\WINDOWS\System32\SENDKEY.DLL
[1996/04/03 21:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\drivers\GIVEIO.SYS
========== LOP Check ==========
[2008/12/09 22:14:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore
[2010/05/18 07:40:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM
[2005/12/14 20:34:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Autodesk
[2009/12/31 12:19:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\BVRP Software
[2009/09/01 19:00:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON
[2009/10/06 20:18:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\FlashFXP
[2008/05/04 17:31:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
[2005/04/15 18:49:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Groove Games
[2009/09/03 21:36:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PreEmptive Solutions
[2009/09/05 20:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Processor Expert
[2005/12/15 20:01:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Propellerhead Software
[2009/06/06 12:39:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Seagate
[2007/06/03 17:37:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\SlySoft
[2010/02/01 14:04:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2009/07/02 19:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
[2009/01/26 10:07:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\vsosdk
[2010/06/22 16:42:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/11/22 19:20:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2008/12/09 22:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\acccore
[2006/02/21 11:52:26 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Aim
[2009/11/28 17:42:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\com.directv.supercast.AA1ECC8BBAFE4E1BBF2D418DC006AF207FACE6CA.1
[2008/04/07 12:44:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Command & Conquer 3 Kane's Wrath
[2007/03/30 16:56:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Command & Conquer 3 Tiberium Wars
[2010/12/28 09:38:26 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Dropbox
[2004/12/05 17:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\EBookSys
[2009/11/04 09:05:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Epson
[2010/05/04 09:26:45 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Facebook
[2010/12/16 14:58:12 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FileZilla
[2009/11/18 20:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\hte
[2009/01/07 13:56:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ImTOO Software Studio
[2009/09/01 19:02:30 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Leadertech
[2010/09/15 16:44:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Notepad++
[2009/12/13 22:58:37 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\NwDocx
[2009/09/05 20:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Processor Expert
[2005/12/15 20:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Propellerhead Software
[2008/11/15 15:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Red Alert 3
[2007/07/07 12:30:43 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Redemption
[2009/09/06 21:30:16 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SealedMedia
[2006/09/06 18:33:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SlySoft
[2009/02/27 09:58:01 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Teleca
[2007/08/18 11:58:46 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\TrojanHunter
[2010/04/02 11:24:17 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Ubisoft
[2009/10/23 13:58:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Viewpoint
[2010/12/20 12:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Vso
[2009/09/09 09:04:52 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilinx
[2010/12/19 11:43:53 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\xVideoServiceThief
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2003/09/05 19:22:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/03/07 18:10:28 | 000,000,003 | —- | M] () – C:\binaryFile.bin
[2010/12/27 16:12:00 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/04/02 10:05:20 | 000,782,398 | —- | M] () – C:\cc_20100402_110457.reg
[2009/06/07 14:59:16 | 000,000,348 | —- | M] () – C:\CKINFO.TXT
[2007/01/04 20:34:52 | 000,008,234 | —- | M] () – C:\clean.bat
[2008/08/27 12:26:48 | 000,011,330 | —- | M] () – C:\ComboFix.txt
[2007/04/01 10:56:33 | 000,014,875 | —- | M] () – C:\ComboFix2.txt
[2007/03/30 13:23:37 | 000,016,562 | —- | M] () – C:\ComboFix3.txt
[2003/09/05 19:22:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/09/01 15:52:58 | 000,000,060 | —- | M] () – C:\CorrectAnswers.txt
[2007/06/16 16:14:23 | 000,062,373 | —- | M] () – C:\debug.log
[2010/12/27 16:20:24 | 000,000,432 | —- | M] () – C:\haxfix.txt
[2007/08/16 13:16:52 | 000,000,753 | —- | M] () – C:\haxlog.txt
[2010/04/24 06:36:09 | 000,460,824 | —- | M] () – C:\img2-001.raw
[2003/09/05 19:22:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/18 07:40:13 | 000,001,106 | -H– | M] () – C:\IPH.PH
[2004/05/22 08:23:26 | 000,000,000 | —- | M] () – C:\itouch_config_crash_info.txt
[2006/05/31 08:23:37 | 000,000,374 | —- | M] () – C:\itouch_crash_info.txt
[2004/08/24 09:05:28 | 000,000,004 | —- | M] () – C:\loadcounter.dat
[2009/09/06 20:55:27 | 000,000,302 | —- | M] () – C:\lxbt.log
[2004/03/22 14:42:04 | 000,000,062 | —- | M] () – C:\MMCD.INI
[2003/09/05 19:22:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/09/29 13:21:39 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/10 15:22:10 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/28 09:36:51 | 1048,576,000 | -HS- | M] () – C:\pagefile.sys
[2009/09/06 20:51:46 | 000,000,744 | —- | M] () – C:\pedriver.txt
[2004/03/22 14:42:10 | 000,000,207 | —- | M] () – C:\RECache.idx
[2010/03/03 14:38:21 | 000,000,370 | —- | M] () – C:\rkill.log
[2004/07/15 10:31:18 | 000,393,216 | —- | M] () – C:\t18g
[2004/07/15 11:29:14 | 000,073,728 | —- | M] () – C:\t18g.1
[2010/04/01 15:39:41 | 000,000,319 | —- | M] () – C:\trojan_fakerean_exe_fix.reg
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/03/17 10:08:08 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 04:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\W32X86\filterpipelineprintproc.dll
[2008/07/06 02:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\W32X86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/03/17 01:57:02 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/03/17 01:57:02 | 000,606,208 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/03/17 01:57:02 | 000,409,600 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/10 15:31:56 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/09/29 13:34:49 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/04/16 15:31:49 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/12/28 09:59:46 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/12/12 20:52:21 | 000,454,656 | —- | M] (Simon Tatham) – C:\Documents and Settings\User\Desktop\putty.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2007/04/10 13:46:48 | 000,013,023 | —- | M] () – C:\WINDOWS\VX3000.src
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-15 18:22:44
========== Files - Unicode (All) ==========
[2006/10/20 18:54:55 | 000,131,072 | —- | M] ()(C:\WINDOWS\System32\??????????) – C:\WINDOWS\System32\߆ᜮ⹒铮鿭☠㟺姱㬭湁
[2006/10/20 15:43:46 | 000,131,072 | —- | C] ()(C:\WINDOWS\System32\??????????) – C:\WINDOWS\System32\߆ᜮ⹒铮鿭☠㟺姱㬭湁
========== Alternate Data Streams ==========
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:0CE7F3C9
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:3B71D0B4
< End of report >
DDS log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:25:49.65 on Tue 12/28/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.343 [GMT -8:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\CTHELPER.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\vVX3000.exe
C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
I:\nero8\Nero 8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Intel\NCS2\WMIProv\NCS2Prov.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\User\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [zBrowser Launcher] c:\program files\logitech\itouch\iTouch.exe
mRun: [EM_EXEC] c:\progra~1\logitech\mousew~1\system\EM_EXEC.EXE
mRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "i:\nero8\nero 8\nero backitup\NBKeyScan.exe"
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [VX3000] c:\windows\vVX3000.exe
mRun: [EEventManager] c:\progra~1\epsons~1\eventm~1\EEventManager.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\user\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\user\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\user\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office10\OSA.EXE
uPolicies-system: WallpaperStyle = 1
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1187569940500
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\46wl92zj.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\user\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\user\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 sonyhcb;Sony Digital Imaging Base;c:\windows\system32\drivers\sonyhcb.sys [2004-3-22 6097]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-4 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-5-4 27784]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-8 297752]
R2 PEDRV;P&E; Microcomputer System PCI Driver.;c:\windows\system32\drivers\pedrv.sys [2000-8-3 23296]
R2 RTWTKRNL;Real-Time Windows Target;c:\windows\system32\drivers\RTWTKRNL.sys [2008-9-8 27008]
R2 VICHW11;P&E; BDM Cable Driver II;c:\windows\system32\drivers\vichw11.sys [1998-10-2 5200]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-12-9 24652]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2009-12-31 27632]
R4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-12-28 38224]
S2 gupdate1c95c105d981590;Google Update Service (gupdate1c95c105d981590);c:\program files\google\update\GoogleUpdate.exe [2008-12-11 133104]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-2-27 13224]
S3 iMSPCLOj;iMSPCLOj;\??\c:\docume~1\user\locals~1\temp\imspcloj.sys –> c:\docume~1\user\locals~1\temp\iMSPCLOj.sys [?]
S3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCcfltr.sys [2003-9-22 14095]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-3-9 33792]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2009-2-27 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2009-2-27 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2009-2-27 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2009-2-27 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2009-2-27 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2009-2-27 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2009-2-27 115752]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [2009-12-31 86824]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [2009-12-31 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [2009-12-31 114600]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [2009-12-31 108328]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [2009-12-31 26024]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [2009-12-31 104616]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [2009-12-31 109736]
S3 SER120;OTI Serial port driver;c:\windows\system32\drivers\ser120.sys [2005-11-17 32750]
S3 sonyhcs;Sony Digital Imaging Video;c:\windows\system32\drivers\sonyhcs.sys [2004-3-22 299923]
S3 z520bus;Sony Ericsson 520 driver (WDM);c:\windows\system32\drivers\z520bus.sys [2005-7-26 57648]
S3 z520mdfl;Sony Ericsson 520 USB WMC Modem Filter;c:\windows\system32\drivers\z520mdfl.sys [2005-7-26 8336]
S3 z520mdm;Sony Ericsson 520 USB WMC Modem Drivers;c:\windows\system32\drivers\z520mdm.sys [2005-7-26 93488]
S3 z520mgmt;Sony Ericsson 520 USB WMC Device Management Drivers;c:\windows\system32\drivers\z520mgmt.sys [2005-7-26 84928]
S3 z520obex;Sony Ericsson 520 USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\z520obex.sys [2005-7-26 82864]
S4 Mnmloidsduaw;Mnmloidsduaw; [x]
=============== Created Last 30 ================
2010-12-28 09:40 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-28 09:40 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-12-28 09:40 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-12-20 12:35 –d—– c:\program files\DVDFab 7
2010-12-15 14:13 –d—– c:\documents and settings\user\final5
2010-12-15 04:05 40,960 -c—— c:\windows\system32\dllcache\ndproxy.sys
2010-12-14 20:12 –d—– c:\program files\AdvancedReliableSoftware
2010-12-11 23:58 472,808 a——- c:\windows\system32\deployJava1.dll
2010-12-11 23:58 73,728 a——- c:\windows\system32\javacpl.cpl
2010-12-02 19:47 –d—– c:\program files\FoxTabFlvConverter
2010-12-02 19:17 –d—– c:\program files\Xesc & Technology
==================== Find3M ====================
2010-12-14 20:13 162,816 a——- c:\windows\system32\fmod.dll
2010-11-18 10:12 81,920 a——- c:\windows\system32\isign32.dll
2010-11-05 16:26 916,480 a——- c:\windows\system32\wininet.dll
2010-11-05 16:26 43,520 a——- c:\windows\system32\licmgr10.dll
2010-11-02 07:17 40,960 a——- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 05:13 290,048 a——- c:\windows\system32\atmfd.dll
2010-10-26 05:25 1,853,312 a——- c:\windows\system32\win32k.sys
2010-01-20 13:33 40,896 ac—— c:\docume~1\user\applic~1\GDIPFONTCACHEV1.DAT
2009-04-29 12:17 87,608 ac—— c:\docume~1\user\applic~1\inst.exe
2009-04-29 12:17 47,360 ac—— c:\docume~1\user\applic~1\pcouffin.sys
2008-08-09 17:38 81,920 ac—— c:\docume~1\user\applic~1\ezpinst.exe
2006-04-29 11:31 1 ac—— c:\documents and settings\user\SI.bin
2009-09-05 20:34 18 ac-sh— c:\windows\WINPROD.DLL
2008-09-10 15:40 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091020080911\index.dat
2009-12-19 18:39 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat
============= FINISH: 10:26:11.20 ===============