This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Limited or no Connectivity, Cant renew IP address

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Temporarily plugging in a new PCI based network interface card solves the problem. But i need to use the onboard network adapter of the mother board. how can this port suddenly stop working after only 2 years, with no physical trauma or anything at all?

When im in the command prompt and try to do " ipconfig /release " then renew after it times out. Something software related is preventing me from connecting to the internet.

Please help me
Malwarebytes finds nothing and neither does AVG full scan.

HJT log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:55:35 AM, on 12/28/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\CTHELPER.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\vVX3000.exe
C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
I:\nero8\Nero 8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "I:\nero8\Nero 8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1187569940500
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate1c95c105d981590) (gupdate1c95c105d981590) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - I:\nero8\Nero 8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7811 bytes


OTL log:
OTL logfile created on: 12/28/2010 10:05:58 AM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 340.00 Mb Available Physical Memory | 33.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 1000 2000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 6.96 Gb Free Space | 18.66% Space Free | Partition Type: NTFS
Drive H: | 120.16 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive I: | 148.89 Gb Total Space | 39.19 Gb Free Space | 26.32% Space Free | Partition Type: FAT32
Drive J: | 37.27 Gb Total Space | 3.80 Gb Free Space | 10.19% Space Free | Partition Type: NTFS
Drive K: | 3.88 Gb Total Space | 2.86 Gb Free Space | 73.80% Space Free | Partition Type: FAT32
Drive P: | 55.88 Gb Total Space | 14.00 Gb Free Space | 25.05% Space Free | Partition Type: NTFS

Computer Name: OFFICE | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - I:\nero8\Nero 8\Nero BackItUp\NBService.exe (Nero AG)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
PRC - C:\Program Files\Winamp\winamp.exe (Nullsoft)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)
MOD - C:\Program Files\Logitech\iTouch\itchhk.dll (Logitech Inc.)
MOD - C:\Program Files\Common Files\Logitech\Scrolling\LGMSGHK.DLL (Logitech Inc.)
MOD - C:\Program Files\Logitech\iTouch\KbdHook.dll (Logitech Inc.)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Crypkey License) – C:\WINDOWS\System32\Crypserv.exe (CrypKey (Canada) Ltd.)
SRV - (msvsmon90) – P:\VS\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 3) – I:\nero8\Nero 8\Nero BackItUp\NBService.exe (Nero AG)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (mi-raysat_3dsmax8) – J:\3ds Max 8\mentalray\satellite\raysat_3dsmax8server.exe ()
SRV - (EPSONStatusAgent2) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (SYMIDSCO) – C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20051208.051\symidsco.sys File not found
DRV - (mcdbus) – C:\WINDOWS\System32\DRIVERS\mcdbus.sys File not found
DRV - (LHidFlt2) – C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys File not found
DRV - (iMSPCLOj) – C:\DOCUME~1\User\LOCALS~1\Temp\iMSPCLOj.sys File not found
DRV - (ENTECH) – C:\WINDOWS\System32\DRIVERS\ENTECH.sys File not found
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ggsemc) – C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (s0017mdm) – C:\WINDOWS\system32\drivers\s0017mdm.sys (MCCI Corporation)
DRV - (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM) – C:\WINDOWS\system32\drivers\s0017unic.sys (MCCI Corporation)
DRV - (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s0017mgmt.sys (MCCI Corporation)
DRV - (s0017obex) – C:\WINDOWS\system32\drivers\s0017obex.sys (MCCI Corporation)
DRV - (s0017bus) Sony Ericsson Device 0017 driver (WDM) – C:\WINDOWS\system32\drivers\s0017bus.sys (MCCI Corporation)
DRV - (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS) – C:\WINDOWS\system32\drivers\s0017nd5.sys (MCCI Corporation)
DRV - (s0017mdfl) – C:\WINDOWS\system32\drivers\s0017mdfl.sys (MCCI Corporation)
DRV - (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM) – C:\WINDOWS\system32\drivers\s0016unic.sys (MCCI Corporation)
DRV - (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS) – C:\WINDOWS\system32\drivers\s0016nd5.sys (MCCI Corporation)
DRV - (s0016mdfl) – C:\WINDOWS\system32\drivers\s0016mdfl.sys (MCCI Corporation)
DRV - (s0016mdm) – C:\WINDOWS\system32\drivers\s0016mdm.sys (MCCI Corporation)
DRV - (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s0016mgmt.sys (MCCI Corporation)
DRV - (s0016obex) – C:\WINDOWS\system32\drivers\s0016obex.sys (MCCI Corporation)
DRV - (s0016bus) Sony Ericsson Device 0016 driver (WDM) – C:\WINDOWS\system32\drivers\s0016bus.sys (MCCI Corporation)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (NetworkX) – C:\WINDOWS\system32\ckldrv.sys ()
DRV - (seehcri) – C:\WINDOWS\system32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (Ser2pl) – C:\WINDOWS\system32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (Applied Networking Inc.)
DRV - (dtscsi) – C:\WINDOWS\System32\Drivers\dtscsi.sys ()
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (VX3000) – C:\WINDOWS\system32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (hap17v2k) – C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (z520obex) – C:\WINDOWS\system32\drivers\z520obex.sys (MCCI)
DRV - (z520mgmt) – C:\WINDOWS\system32\drivers\z520mgmt.sys (MCCI)
DRV - (z520mdm) – C:\WINDOWS\system32\drivers\z520mdm.sys (MCCI)
DRV - (z520mdfl) – C:\WINDOWS\system32\drivers\z520mdfl.sys (MCCI)
DRV - (z520bus) Sony Ericsson 520 driver (WDM) – C:\WINDOWS\system32\drivers\z520bus.sys (MCCI)
DRV - (w810obex) – C:\WINDOWS\system32\drivers\w810obex.sys (MCCI)
DRV - (w810mdm) – C:\WINDOWS\system32\drivers\w810mdm.sys (MCCI)
DRV - (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\w810mgmt.sys (MCCI)
DRV - (w810mdfl) – C:\WINDOWS\system32\drivers\w810mdfl.sys (MCCI)
DRV - (w810bus) Sony Ericsson W810 Driver driver (WDM) – C:\WINDOWS\system32\drivers\w810bus.sys (MCCI)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (libusb0) – C:\WINDOWS\system32\drivers\libusb0.sys ()
DRV - (SER120) – C:\WINDOWS\system32\drivers\ser120.sys (USB Com port.)
DRV - (itchfltr) – C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
DRV - (LHidUsb) – C:\WINDOWS\system32\drivers\LHidUsb.sys (Logitech, Inc.)
DRV - (LCcfltr) – C:\WINDOWS\system32\drivers\LCcfltr.sys (Logitech, Inc.)
DRV - (TIEHDUSB) – C:\WINDOWS\system32\drivers\tiehdusb.sys (Texas Instruments Incorporated)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (RTWTKRNL) – C:\WINDOWS\system32\drivers\RTWTKRNL.sys ()
DRV - (sonyhcs) – C:\WINDOWS\system32\drivers\sonyhcs.sys (Sony Corporation)
DRV - (sonyhcb) – C:\WINDOWS\System32\DRIVERS\sonyhcb.sys (Sony Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PEDRV) – C:\WINDOWS\System32\drivers\pedrv.sys ()
DRV - (VICHW11) – C:\WINDOWS\System32\drivers\vichw11.sys ()
DRV - (GIVEIO) – C:\WINDOWS\System32\drivers\GIVEIO.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 18 34 AB 7E 1D 81 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/21 09:02:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/14 09:41:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/12 10:01:01 | 000,000,000 | —D | M]

[2008/08/25 20:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/12/25 15:34:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions
[2010/04/28 13:40:30 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/07/14 17:25:54 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions\[removed]
[2010/10/03 13:05:49 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\extensions\vshare@toolbar
[2010/12/27 16:05:48 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/12/11 23:58:40 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/11 23:58:14 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/04/16 09:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2010/12/27 16:51:26 | 000,000,736 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EM_EXEC] C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc. )
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NBKeyScan] I:\nero8\Nero 8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [VX3000] C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe File not found
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/d/4…0367/wmavax.CAB (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1187569940500 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/09/05 19:22:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/09/22 21:25:28 | 000,000,043 | R— | M] () - H:\AUTORUN.INF – [ CDFS ]
O32 - AutoRun File - [2006/11/02 11:00:34 | 000,909,530 | R— | M] (InstallShield Software Corporation) - H:\Autopoll Application V1.04.exe – [ CDFS ]
O32 - AutoRun File - [2008/09/14 19:38:08 | 000,000,122 | RHS- | M] () - I:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{01b326cd-ea62-11de-98fd-000d61c1efb2}\Shell\AutoRun\command - "" = P:\Xilinx\EDK\bin\nt\setup.exe – [2008/02/20 09:47:10 | 000,012,288 | —- | M] ()
O33 - MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{607f01e2-1531-11dd-970c-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{607f01e2-1531-11dd-970c-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{607f01e2-1531-11dd-970c-000d61c1efb2}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{abe72b8c-d273-11db-8c4a-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{abe72b8c-d273-11db-8c4a-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{abe72b8c-d273-11db-8c4a-000d61c1efb2}\Shell\AutoRun\command - "" = H:\ONSPCLCK.exe – [2006/11/02 12:55:10 | 002,519,040 | R— | M] (OnSpec Electronic, Inc.)
O33 - MountPoints2\{abe72b8f-d273-11db-8c4a-000d61c1efb2}\Shell - "" = AutoRun
O33 - MountPoints2\{abe72b8f-d273-11db-8c4a-000d61c1efb2}\Shell\1\Command - "" = .\recycled\info.exe
O33 - MountPoints2\{abe72b8f-d273-11db-8c4a-000d61c1efb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\KODAK_Software_Downloader.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\ONSPCLCK.exe – [2006/11/02 12:55:10 | 002,519,040 | R— | M] (OnSpec Electronic, Inc.)
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\1\Command - "" = .\recycled\info.exe
O33 - MountPoints2\I\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/12/28 10:02:06 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/12/28 09:40:31 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/28 09:40:26 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/28 09:40:25 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/20 16:53:56 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Cubic
[2010/12/20 12:35:53 | 000,000,000 | —D | C] – C:\Program Files\DVDFab 7
[2010/12/20 12:33:38 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\DVDFab.Platinum.7070
[2010/12/15 14:13:11 | 000,000,000 | —D | C] – C:\Documents and Settings\User\final5
[2010/12/15 04:05:00 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2010/12/14 20:13:11 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\AdvancedReliableSoftware
[2010/12/14 20:12:11 | 000,000,000 | —D | C] – C:\Program Files\AdvancedReliableSoftware
[2010/12/13 20:43:58 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\FileZilla
[2010/12/13 20:43:22 | 000,000,000 | —D | C] – C:\Program Files\FileZilla FTP Client
[2010/12/12 20:52:10 | 000,454,656 | —- | C] (Simon Tatham) – C:\Documents and Settings\User\Desktop\putty.exe
[2010/12/12 16:17:11 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Masharoni and Cheese
[2010/12/12 16:11:51 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\vice-breakfast-clubbin
[2010/12/12 16:11:45 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\DJ-Vice-Vice-Vice-Baby-CD
[2010/12/12 16:05:28 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\DJVice-LateNights.mp3
[2010/12/11 23:59:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Sun
[2010/12/11 23:58:36 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/12/11 23:58:36 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/11 23:58:36 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/12/11 23:58:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/11 23:58:35 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/02 19:47:19 | 000,000,000 | —D | C] – C:\Program Files\FoxTabFlvConverter
[2010/12/02 19:17:30 | 000,000,000 | —D | C] – C:\Program Files\Xesc & Technology
[2008/07/26 16:05:52 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\User\Application Data\pcouffin.sys
[2006/08/11 14:56:28 | 000,033,792 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/28 10:11:50 | 000,001,065 | —- | M] () – C:\WINDOWS\winamp.ini
[2010/12/28 09:59:46 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/12/28 09:59:12 | 000,359,929 | —- | M] () – C:\Documents and Settings\User\Desktop\dds.scr
[2010/12/28 09:46:56 | 000,001,982 | —- | M] () – C:\Documents and Settings\User\Desktop\HiJackThis.lnk
[2010/12/28 09:39:58 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/28 09:38:46 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/12/28 09:37:41 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/28 09:35:58 | 000,031,656 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,031,656 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,028,968 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,028,968 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000004-00511102}.rfx
[2010/12/28 09:35:58 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2010/12/28 09:35:58 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2010/12/28 09:35:44 | 003,162,278 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-00511102}.CDF
[2010/12/28 09:35:44 | 003,162,278 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-00511102}.BAK
[2010/12/28 09:22:14 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/27 18:41:22 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk
[2010/12/27 16:33:05 | 000,000,032 | —- | M] () – C:\WINDOWS\System32\thxcfg.ini
[2010/12/27 16:29:56 | 000,134,144 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/27 16:12:00 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/12/27 15:47:27 | 000,548,546 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/12/27 15:47:27 | 000,098,270 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/12/24 13:13:36 | 008,755,789 | —- | M] () – C:\Documents and Settings\User\Desktop\Dwyck.mp3
[2010/12/24 13:11:42 | 005,931,008 | —- | M] () – C:\Documents and Settings\User\Desktop\16_Deadmau5_-_Ghosts_N_Stuff.mp3
[2010/12/24 13:11:42 | 004,769,792 | —- | M] () – C:\Documents and Settings\User\Desktop\techn9ne-im_a_playa.mp3
[2010/12/24 13:09:18 | 005,060,080 | —- | M] () – C:\Documents and Settings\User\Desktop\bon_jovi.mp3
[2010/12/24 13:09:10 | 004,015,461 | —- | M] () – C:\Documents and Settings\User\Desktop\Indeep - Last Night The DJ Save my Life.mp3
[2010/12/24 13:08:27 | 009,684,238 | —- | M] () – C:\Documents and Settings\User\Desktop\ontheroad.mp3
[2010/12/24 13:07:54 | 003,107,158 | —- | M] () – C:\Documents and Settings\User\Desktop\preview.mp3
[2010/12/24 09:21:56 | 069,305,001 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/12/23 20:22:47 | 001,091,284 | —- | M] () – C:\Documents and Settings\User\Desktop\us.JPG
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/20 12:36:01 | 000,000,618 | —- | M] () – C:\Documents and Settings\User\Desktop\DVDFab 7.lnk
[2010/12/19 20:56:31 | 020,389,892 | —- | M] () – C:\Documents and Settings\User\Desktop\DVDFab.Platinum.7070.rar
[2010/12/19 20:20:40 | 000,099,557 | —- | M] () – C:\Documents and Settings\User\Desktop\attachments_2010_12_19.zip
[2010/12/19 12:10:49 | 005,073,765 | —- | M] () – C:\Documents and Settings\User\Desktop\Smoke Gets In Your EyesThe Platters.mp3
[2010/12/19 12:09:00 | 001,111,286 | —- | M] () – C:\Documents and Settings\User\Desktop\01 O Fortuna (Carmina Burana).m4r
[2010/12/19 11:46:42 | 096,698,408 | —- | M] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].wav
[2010/12/19 11:44:20 | 019,847,934 | —- | M] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].mp4
[2010/12/19 11:42:24 | 000,813,858 | —- | M] () – C:\Documents and Settings\User\Desktop\Carl Orff - O Fortuna.mp3
[2010/12/19 11:28:02 | 002,048,449 | —- | M] () – C:\Documents and Settings\User\Desktop\Bed-Intruder-Song-wwwLINKWHIPcom.mp3
[2010/12/19 11:27:12 | 003,522,560 | —- | M] () – C:\Documents and Settings\User\Desktop\carl_orff-o_fortuna_(carmina_burana).mp3
[2010/12/17 21:49:52 | 004,087,794 | —- | M] () – C:\Documents and Settings\User\Desktop\DSCN3264.JPG
[2010/12/16 14:14:31 | 000,000,600 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\PUTTY.RND
[2010/12/16 10:58:40 | 000,002,483 | —- | M] () – C:\Documents and Settings\User\Desktop\Microsoft Word.lnk
[2010/12/15 20:26:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/15 13:09:30 | 000,189,000 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/15 10:22:34 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/12/15 08:13:58 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/12/14 22:30:02 | 000,000,392 | —- | M] () – C:\Documents and Settings\User\Desktop\AdjustiTunesPlayCount.js
[2010/12/14 20:13:30 | 000,162,816 | —- | M] (Firelight Technologies Pty, Ltd) – C:\WINDOWS\System32\fmod.dll
[2010/12/13 20:43:29 | 000,001,663 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\FileZilla Client.lnk
[2010/12/12 20:52:21 | 000,454,656 | —- | M] (Simon Tatham) – C:\Documents and Settings\User\Desktop\putty.exe
[2010/12/12 15:48:19 | 075,370,256 | —- | M] () – C:\Documents and Settings\User\Desktop\01LateNights.mp3
[2010/12/12 15:47:28 | 141,947,581 | —- | M] () – C:\Documents and Settings\User\Desktop\Breakfast-Clubbin.mp3
[2010/12/12 15:46:49 | 033,966,744 | —- | M] () – C:\Documents and Settings\User\Desktop\Vice-Vice-Baby.mp3
[2010/12/12 15:23:16 | 000,071,447 | —- | M] () – C:\Documents and Settings\User\Desktop\tumblr_lc9girUWfW1qctkcl.jpg
[2010/12/12 15:21:00 | 000,064,914 | —- | M] () – C:\Documents and Settings\User\Desktop\tumblr_ld48hjE7JF1qctkcl.jpg
[2010/12/12 15:05:55 | 075,765,411 | —- | M] () – C:\Documents and Settings\User\Desktop\THEBLASTOFF3THEROCKITSCIENTISTS.mp3
[2010/12/12 15:03:41 | 062,980,935 | —- | M] () – C:\Documents and Settings\User\Desktop\rockitBLASTOFF2.mp3
[2010/12/11 23:58:12 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/12/11 23:58:12 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/11 23:58:12 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/11 23:58:12 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/11 23:58:12 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/28 10:02:06 | 000,359,929 | —- | C] () – C:\Documents and Settings\User\Desktop\dds.scr
[2010/12/28 09:46:56 | 000,001,982 | —- | C] () – C:\Documents and Settings\User\Desktop\HiJackThis.lnk
[2010/12/27 16:20:01 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\swsc.exe
[2010/12/24 13:11:36 | 004,769,792 | —- | C] () – C:\Documents and Settings\User\Desktop\techn9ne-im_a_playa.mp3
[2010/12/24 13:11:16 | 005,931,008 | —- | C] () – C:\Documents and Settings\User\Desktop\16_Deadmau5_-_Ghosts_N_Stuff.mp3
[2010/12/24 13:09:34 | 008,755,789 | —- | C] () – C:\Documents and Settings\User\Desktop\Dwyck.mp3
[2010/12/24 13:09:12 | 005,060,080 | —- | C] () – C:\Documents and Settings\User\Desktop\bon_jovi.mp3
[2010/12/24 13:08:47 | 004,015,461 | —- | C] () – C:\Documents and Settings\User\Desktop\Indeep - Last Night The DJ Save my Life.mp3
[2010/12/24 13:08:20 | 009,684,238 | —- | C] () – C:\Documents and Settings\User\Desktop\ontheroad.mp3
[2010/12/24 13:07:48 | 003,107,158 | —- | C] () – C:\Documents and Settings\User\Desktop\preview.mp3
[2010/12/24 09:52:42 | 004,087,794 | —- | C] () – C:\Documents and Settings\User\Desktop\DSCN3264.JPG
[2010/12/23 20:22:37 | 001,091,284 | —- | C] () – C:\Documents and Settings\User\Desktop\us.JPG
[2010/12/20 12:36:01 | 000,000,618 | —- | C] () – C:\Documents and Settings\User\Desktop\DVDFab 7.lnk
[2010/12/19 20:54:59 | 020,389,892 | —- | C] () – C:\Documents and Settings\User\Desktop\DVDFab.Platinum.7070.rar
[2010/12/19 20:20:38 | 000,099,557 | —- | C] () – C:\Documents and Settings\User\Desktop\attachments_2010_12_19.zip
[2010/12/19 12:11:57 | 001,111,286 | —- | C] () – C:\Documents and Settings\User\Desktop\01 O Fortuna (Carmina Burana).m4r
[2010/12/19 12:10:33 | 005,073,765 | —- | C] () – C:\Documents and Settings\User\Desktop\Smoke Gets In Your EyesThe Platters.mp3
[2010/12/19 11:43:32 | 096,698,408 | —- | C] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].wav
[2010/12/19 11:42:24 | 000,813,858 | —- | C] () – C:\Documents and Settings\User\Desktop\Carl Orff - O Fortuna.mp3
[2010/12/19 11:37:35 | 019,847,934 | —- | C] () – C:\Documents and Settings\User\Desktop\IM THE JUGGERNAUT ###### - High Quality [File2HD.com].mp4
[2010/12/19 11:28:02 | 002,048,449 | —- | C] () – C:\Documents and Settings\User\Desktop\Bed-Intruder-Song-wwwLINKWHIPcom.mp3
[2010/12/19 11:27:12 | 003,522,560 | —- | C] () – C:\Documents and Settings\User\Desktop\carl_orff-o_fortuna_(carmina_burana).mp3
[2010/12/14 22:20:55 | 000,000,392 | —- | C] () – C:\Documents and Settings\User\Desktop\AdjustiTunesPlayCount.js
[2010/12/13 20:43:29 | 000,001,663 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\FileZilla Client.lnk
[2010/12/12 21:59:01 | 000,000,600 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\PUTTY.RND
[2010/12/12 15:46:11 | 033,966,744 | —- | C] () – C:\Documents and Settings\User\Desktop\Vice-Vice-Baby.mp3
[2010/12/12 15:45:31 | 141,947,581 | —- | C] () – C:\Documents and Settings\User\Desktop\Breakfast-Clubbin.mp3
[2010/12/12 15:41:20 | 075,370,256 | —- | C] () – C:\Documents and Settings\User\Desktop\01LateNights.mp3
[2010/12/12 15:23:15 | 000,071,447 | —- | C] () – C:\Documents and Settings\User\Desktop\tumblr_lc9girUWfW1qctkcl.jpg
[2010/12/12 15:20:59 | 000,064,914 | —- | C] () – C:\Documents and Settings\User\Desktop\tumblr_ld48hjE7JF1qctkcl.jpg
[2010/12/12 14:59:24 | 075,765,411 | —- | C] () – C:\Documents and Settings\User\Desktop\THEBLASTOFF3THEROCKITSCIENTISTS.mp3
[2010/12/12 14:58:46 | 062,980,935 | —- | C] () – C:\Documents and Settings\User\Desktop\rockitBLASTOFF2.mp3
[2010/04/01 15:11:40 | 000,012,298 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\8Cq4r
[2010/04/01 15:11:40 | 000,012,298 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\8Cq4r
[2009/12/13 21:36:39 | 000,123,083 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\debuggee.mdmp
[2009/09/23 20:17:42 | 000,000,965 | —- | C] () – C:\WINDOWS\mcutools.ini
[2009/09/05 20:34:56 | 000,000,018 | -HS- | C] () – C:\WINDOWS\WINPROD.DLL
[2009/09/03 00:20:12 | 000,000,000 | —- | C] () – C:\WINDOWS\EEventManager.INI
[2009/09/01 18:59:11 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/09/01 18:53:31 | 000,000,079 | —- | C] () – C:\WINDOWS\EPNX510.ini
[2009/06/06 16:20:31 | 000,000,068 | —- | C] () – C:\WINDOWS\spwdr.INI
[2009/06/06 16:19:56 | 000,000,071 | —- | C] () – C:\WINDOWS\Crypkey.ini
[2009/06/06 16:19:53 | 000,019,584 | —- | C] () – C:\WINDOWS\System32\Ckldrv.sys
[2009/06/06 16:19:53 | 000,018,432 | —- | C] () – C:\WINDOWS\Setup_ck.dll
[2009/06/06 11:59:34 | 000,000,072 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\FASTWiz.log
[2009/02/28 18:30:21 | 000,087,608 | —- | C] () – C:\Documents and Settings\User\Application Data\inst.exe
[2009/02/27 15:53:43 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/01/29 16:08:39 | 000,015,498 | —- | C] () – C:\WINDOWS\VX3000.ini
[2008/09/08 19:21:19 | 000,027,008 | —- | C] () – C:\WINDOWS\System32\drivers\RTWTKRNL.sys
[2008/09/08 19:17:03 | 000,000,158 | —- | C] () – C:\WINDOWS\matlab.ini
[2008/07/26 16:06:05 | 000,000,034 | —- | C] () – C:\Documents and Settings\User\Application Data\pcouffin.log
[2008/07/26 16:05:52 | 000,081,920 | —- | C] () – C:\Documents and Settings\User\Application Data\ezpinst.exe
[2008/07/26 16:05:52 | 000,007,887 | —- | C] () – C:\Documents and Settings\User\Application Data\pcouffin.cat
[2008/07/26 16:05:52 | 000,001,144 | —- | C] () – C:\Documents and Settings\User\Application Data\pcouffin.inf
[2008/06/17 13:37:52 | 000,044,032 | —- | C] () – C:\WINDOWS\System32\tbdml.dll
[2008/05/04 14:31:37 | 000,086,446 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2008/03/25 16:29:20 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\thxcfg.ini
[2007/12/03 20:14:05 | 000,000,060 | —- | C] () – C:\WINDOWS\EntPack.ini
[2007/08/18 11:57:47 | 000,059,392 | R— | C] () – C:\WINDOWS\System32\streamhlp.dll
[2007/07/07 12:29:00 | 000,000,136 | —- | C] () – C:\WINDOWS\REDEMUNINS.INI
[2007/06/03 14:44:23 | 000,096,384 | —- | C] () – C:\WINDOWS\System32\drivers\sptd8237.sys
[2007/05/29 11:38:02 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/04/23 15:17:25 | 000,000,110 | —- | C] () – C:\WINDOWS\gui.INI
[2007/03/14 17:53:25 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2007/03/14 17:53:25 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/03/02 17:51:26 | 000,003,072 | —- | C] () – C:\WINDOWS\CTXFIRES.DLL
[2007/02/02 18:25:12 | 000,000,080 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\.zreglib
[2006/10/20 15:43:48 | 000,051,712 | —- | C] () – C:\WINDOWS\System32\wglhlvh.dll
[2006/10/10 23:25:38 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2006/09/06 18:32:03 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\User\Application Data\.zreglib
[2006/08/11 13:57:18 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\CTBURST.DLL
[2006/08/06 15:45:44 | 000,001,334 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\QTSBandwidthCache
[2006/07/07 19:57:50 | 000,000,225 | —- | C] () – C:\WINDOWS\em06y.ini
[2006/07/07 19:57:42 | 000,000,410 | —- | C] () – C:\WINDOWS\ptrol.dll
[2006/05/23 11:40:34 | 000,000,269 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2006/05/20 09:37:34 | 000,000,339 | —- | C] () – C:\WINDOWS\dellstat.ini
[2006/03/23 12:18:37 | 000,000,067 | —- | C] () – C:\WINDOWS\A1 DVD Audio Ripper.INI
[2006/03/23 12:05:25 | 000,000,067 | —- | C] () – C:\WINDOWS\#1 DVD Audio Ripper.INI
[2006/02/23 00:31:16 | 000,001,047 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/02/23 00:11:59 | 000,000,127 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\fusioncache.dat
[2006/02/12 18:15:58 | 000,000,051 | —- | C] () – C:\WINDOWS\iTouch.ini
[2006/02/12 17:25:37 | 000,001,223 | —- | C] () – C:\WINDOWS\System32\04ugri2o.sys
[2005/12/15 19:53:40 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/12/15 09:47:41 | 000,223,128 | —- | C] () – C:\WINDOWS\System32\drivers\dtscsi.sys
[2005/12/15 09:45:26 | 000,664,064 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2005/08/25 18:35:52 | 000,105,472 | —- | C] () – C:\WINDOWS\System32\LGUICOM.DLL
[2005/08/25 18:35:52 | 000,000,488 | —- | C] () – C:\WINDOWS\Cmousecc.ini
[2005/06/16 17:17:16 | 000,071,680 | —- | C] () – C:\WINDOWS\System32\CTMMACTL.DLL
[2005/03/09 19:50:20 | 000,033,792 | —- | C] () – C:\WINDOWS\System32\drivers\libusb0.sys
[2005/01/28 11:44:48 | 000,000,035 | —- | C] () – C:\WINDOWS\WorldBuilder.INI
[2004/09/20 12:19:02 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/09/15 15:59:53 | 000,000,077 | —- | C] () – C:\WINDOWS\PTFileExplorer.INI
[2004/09/01 06:27:40 | 000,000,023 | —- | C] () – C:\WINDOWS\kodakpcd.User.ini
[2004/07/14 15:34:53 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2004/07/14 15:34:53 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\TrackerNET.dll
[2004/05/29 13:42:27 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/05/29 13:41:56 | 000,037,727 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2004/05/29 13:32:58 | 000,000,191 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/05/29 13:10:40 | 000,000,011 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/05/12 19:56:36 | 000,634,880 | —- | C] () – C:\WINDOWS\System32\pemicro_serialcm2.dll
[2004/04/29 13:41:42 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\ungwum.dll
[2004/03/23 23:24:46 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\frapsvid.dll
[2004/03/22 17:10:03 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2004/03/22 14:52:26 | 000,000,520 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/03/20 17:02:53 | 000,022,014 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/03/17 23:15:18 | 000,134,144 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/03/17 10:58:03 | 000,001,065 | —- | C] () – C:\WINDOWS\winamp.ini
[2004/03/17 01:59:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2000/08/03 13:25:12 | 000,023,296 | —- | C] () – C:\WINDOWS\System32\pedrv.sys
[2000/08/03 13:25:12 | 000,023,296 | —- | C] () – C:\WINDOWS\System32\drivers\pedrv.sys
[1998/10/02 09:20:46 | 000,005,200 | —- | C] () – C:\WINDOWS\System32\drivers\vichw11.sys
[1996/05/29 16:20:04 | 000,035,072 | —- | C] () – C:\WINDOWS\System32\SENDKEY.DLL
[1996/04/03 21:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\drivers\GIVEIO.SYS

========== LOP Check ==========

[2008/12/09 22:14:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore
[2010/05/18 07:40:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM
[2005/12/14 20:34:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Autodesk
[2009/12/31 12:19:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\BVRP Software
[2009/09/01 19:00:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON
[2009/10/06 20:18:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\FlashFXP
[2008/05/04 17:31:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
[2005/04/15 18:49:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Groove Games
[2009/09/03 21:36:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PreEmptive Solutions
[2009/09/05 20:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Processor Expert
[2005/12/15 20:01:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Propellerhead Software
[2009/06/06 12:39:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Seagate
[2007/06/03 17:37:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\SlySoft
[2010/02/01 14:04:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2009/07/02 19:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
[2009/01/26 10:07:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\vsosdk
[2010/06/22 16:42:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/11/22 19:20:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2008/12/09 22:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\acccore
[2006/02/21 11:52:26 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Aim
[2009/11/28 17:42:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\com.directv.supercast.AA1ECC8BBAFE4E1BBF2D418DC006AF207FACE6CA.1
[2008/04/07 12:44:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Command & Conquer 3 Kane's Wrath
[2007/03/30 16:56:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Command & Conquer 3 Tiberium Wars
[2010/12/28 09:38:26 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Dropbox
[2004/12/05 17:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\EBookSys
[2009/11/04 09:05:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Epson
[2010/05/04 09:26:45 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Facebook
[2010/12/16 14:58:12 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FileZilla
[2009/11/18 20:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\hte
[2009/01/07 13:56:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ImTOO Software Studio
[2009/09/01 19:02:30 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Leadertech
[2010/09/15 16:44:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Notepad++
[2009/12/13 22:58:37 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\NwDocx
[2009/09/05 20:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Processor Expert
[2005/12/15 20:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Propellerhead Software
[2008/11/15 15:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Red Alert 3
[2007/07/07 12:30:43 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Redemption
[2009/09/06 21:30:16 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SealedMedia
[2006/09/06 18:33:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SlySoft
[2009/02/27 09:58:01 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Teleca
[2007/08/18 11:58:46 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\TrojanHunter
[2010/04/02 11:24:17 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Ubisoft
[2009/10/23 13:58:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Viewpoint
[2010/12/20 12:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Vso
[2009/09/09 09:04:52 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilinx
[2010/12/19 11:43:53 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\xVideoServiceThief

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2003/09/05 19:22:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/03/07 18:10:28 | 000,000,003 | —- | M] () – C:\binaryFile.bin
[2010/12/27 16:12:00 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/04/02 10:05:20 | 000,782,398 | —- | M] () – C:\cc_20100402_110457.reg
[2009/06/07 14:59:16 | 000,000,348 | —- | M] () – C:\CKINFO.TXT
[2007/01/04 20:34:52 | 000,008,234 | —- | M] () – C:\clean.bat
[2008/08/27 12:26:48 | 000,011,330 | —- | M] () – C:\ComboFix.txt
[2007/04/01 10:56:33 | 000,014,875 | —- | M] () – C:\ComboFix2.txt
[2007/03/30 13:23:37 | 000,016,562 | —- | M] () – C:\ComboFix3.txt
[2003/09/05 19:22:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/09/01 15:52:58 | 000,000,060 | —- | M] () – C:\CorrectAnswers.txt
[2007/06/16 16:14:23 | 000,062,373 | —- | M] () – C:\debug.log
[2010/12/27 16:20:24 | 000,000,432 | —- | M] () – C:\haxfix.txt
[2007/08/16 13:16:52 | 000,000,753 | —- | M] () – C:\haxlog.txt
[2010/04/24 06:36:09 | 000,460,824 | —- | M] () – C:\img2-001.raw
[2003/09/05 19:22:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/18 07:40:13 | 000,001,106 | -H– | M] () – C:\IPH.PH
[2004/05/22 08:23:26 | 000,000,000 | —- | M] () – C:\itouch_config_crash_info.txt
[2006/05/31 08:23:37 | 000,000,374 | —- | M] () – C:\itouch_crash_info.txt
[2004/08/24 09:05:28 | 000,000,004 | —- | M] () – C:\loadcounter.dat
[2009/09/06 20:55:27 | 000,000,302 | —- | M] () – C:\lxbt.log
[2004/03/22 14:42:04 | 000,000,062 | —- | M] () – C:\MMCD.INI
[2003/09/05 19:22:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/09/29 13:21:39 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/10 15:22:10 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/28 09:36:51 | 1048,576,000 | -HS- | M] () – C:\pagefile.sys
[2009/09/06 20:51:46 | 000,000,744 | —- | M] () – C:\pedriver.txt
[2004/03/22 14:42:10 | 000,000,207 | —- | M] () – C:\RECache.idx
[2010/03/03 14:38:21 | 000,000,370 | —- | M] () – C:\rkill.log
[2004/07/15 10:31:18 | 000,393,216 | —- | M] () – C:\t18g
[2004/07/15 11:29:14 | 000,073,728 | —- | M] () – C:\t18g.1
[2010/04/01 15:39:41 | 000,000,319 | —- | M] () – C:\trojan_fakerean_exe_fix.reg

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/03/17 10:08:08 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 04:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\W32X86\filterpipelineprintproc.dll
[2008/07/06 02:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\W32X86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/03/17 01:57:02 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/03/17 01:57:02 | 000,606,208 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/03/17 01:57:02 | 000,409,600 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/10 15:31:56 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/09/29 13:34:49 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/04/16 15:31:49 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/12/28 09:59:46 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/12/12 20:52:21 | 000,454,656 | —- | M] (Simon Tatham) – C:\Documents and Settings\User\Desktop\putty.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2007/04/10 13:46:48 | 000,013,023 | —- | M] () – C:\WINDOWS\VX3000.src
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-15 18:22:44

========== Files - Unicode (All) ==========
[2006/10/20 18:54:55 | 000,131,072 | —- | M] ()(C:\WINDOWS\System32\??????????) – C:\WINDOWS\System32\߆ᜮ⹒铮鿭☠㟺姱㬭湁
[2006/10/20 15:43:46 | 000,131,072 | —- | C] ()(C:\WINDOWS\System32\??????????) – C:\WINDOWS\System32\߆ᜮ⹒铮鿭☠㟺姱㬭湁

========== Alternate Data Streams ==========

@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:0CE7F3C9
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:3B71D0B4

< End of report >


DDS log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:25:49.65 on Tue 12/28/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.343 [GMT -8:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\CTHELPER.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\vVX3000.exe
C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
I:\nero8\Nero 8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Intel\NCS2\WMIProv\NCS2Prov.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\User\Desktop\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = *.local
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [zBrowser Launcher] c:\program files\logitech\itouch\iTouch.exe
mRun: [EM_EXEC] c:\progra~1\logitech\mousew~1\system\EM_EXEC.EXE
mRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "i:\nero8\nero 8\nero backitup\NBKeyScan.exe"
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [VX3000] c:\windows\vVX3000.exe
mRun: [EEventManager] c:\progra~1\epsons~1\eventm~1\EEventManager.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\user\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\user\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\user\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office10\OSA.EXE
uPolicies-system: WallpaperStyle = 1
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1187569940500
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\46wl92zj.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\user\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\user\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 sonyhcb;Sony Digital Imaging Base;c:\windows\system32\drivers\sonyhcb.sys [2004-3-22 6097]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-4 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-5-4 27784]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-8 297752]
R2 PEDRV;P&E; Microcomputer System PCI Driver.;c:\windows\system32\drivers\pedrv.sys [2000-8-3 23296]
R2 RTWTKRNL;Real-Time Windows Target;c:\windows\system32\drivers\RTWTKRNL.sys [2008-9-8 27008]
R2 VICHW11;P&E; BDM Cable Driver II;c:\windows\system32\drivers\vichw11.sys [1998-10-2 5200]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-12-9 24652]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2009-12-31 27632]
R4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-12-28 38224]
S2 gupdate1c95c105d981590;Google Update Service (gupdate1c95c105d981590);c:\program files\google\update\GoogleUpdate.exe [2008-12-11 133104]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-2-27 13224]
S3 iMSPCLOj;iMSPCLOj;\??\c:\docume~1\user\locals~1\temp\imspcloj.sys –> c:\docume~1\user\locals~1\temp\iMSPCLOj.sys [?]
S3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCcfltr.sys [2003-9-22 14095]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-3-9 33792]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2009-2-27 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2009-2-27 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2009-2-27 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2009-2-27 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2009-2-27 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2009-2-27 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2009-2-27 115752]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [2009-12-31 86824]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [2009-12-31 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [2009-12-31 114600]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [2009-12-31 108328]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [2009-12-31 26024]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [2009-12-31 104616]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [2009-12-31 109736]
S3 SER120;OTI Serial port driver;c:\windows\system32\drivers\ser120.sys [2005-11-17 32750]
S3 sonyhcs;Sony Digital Imaging Video;c:\windows\system32\drivers\sonyhcs.sys [2004-3-22 299923]
S3 z520bus;Sony Ericsson 520 driver (WDM);c:\windows\system32\drivers\z520bus.sys [2005-7-26 57648]
S3 z520mdfl;Sony Ericsson 520 USB WMC Modem Filter;c:\windows\system32\drivers\z520mdfl.sys [2005-7-26 8336]
S3 z520mdm;Sony Ericsson 520 USB WMC Modem Drivers;c:\windows\system32\drivers\z520mdm.sys [2005-7-26 93488]
S3 z520mgmt;Sony Ericsson 520 USB WMC Device Management Drivers;c:\windows\system32\drivers\z520mgmt.sys [2005-7-26 84928]
S3 z520obex;Sony Ericsson 520 USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\z520obex.sys [2005-7-26 82864]
S4 Mnmloidsduaw;Mnmloidsduaw; [x]

=============== Created Last 30 ================

2010-12-28 09:40 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-28 09:40 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-12-28 09:40 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-12-20 12:35 –d—– c:\program files\DVDFab 7
2010-12-15 14:13 –d—– c:\documents and settings\user\final5
2010-12-15 04:05 40,960 -c—— c:\windows\system32\dllcache\ndproxy.sys
2010-12-14 20:12 –d—– c:\program files\AdvancedReliableSoftware
2010-12-11 23:58 472,808 a——- c:\windows\system32\deployJava1.dll
2010-12-11 23:58 73,728 a——- c:\windows\system32\javacpl.cpl
2010-12-02 19:47 –d—– c:\program files\FoxTabFlvConverter
2010-12-02 19:17 –d—– c:\program files\Xesc & Technology

==================== Find3M ====================

2010-12-14 20:13 162,816 a——- c:\windows\system32\fmod.dll
2010-11-18 10:12 81,920 a——- c:\windows\system32\isign32.dll
2010-11-05 16:26 916,480 a——- c:\windows\system32\wininet.dll
2010-11-05 16:26 43,520 a——- c:\windows\system32\licmgr10.dll
2010-11-02 07:17 40,960 a——- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 05:13 290,048 a——- c:\windows\system32\atmfd.dll
2010-10-26 05:25 1,853,312 a——- c:\windows\system32\win32k.sys
2010-01-20 13:33 40,896 ac—— c:\docume~1\user\applic~1\GDIPFONTCACHEV1.DAT
2009-04-29 12:17 87,608 ac—— c:\docume~1\user\applic~1\inst.exe
2009-04-29 12:17 47,360 ac—— c:\docume~1\user\applic~1\pcouffin.sys
2008-08-09 17:38 81,920 ac—— c:\docume~1\user\applic~1\ezpinst.exe
2006-04-29 11:31 1 ac—— c:\documents and settings\user\SI.bin
2009-09-05 20:34 18 ac-sh— c:\windows\WINPROD.DLL
2008-09-10 15:40 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091020080911\index.dat
2009-12-19 18:39 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat

============= FINISH: 10:26:11.20 ===============
Posted Image

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



The issues with your computer that you list, doesn't appear to be related to Malware/Spyware/Virus but we can have a look.


Internet Explorer (Windows)
1. Click "Tools", then click "Internet Options". This will bring up the Internet Options window.

2. Click the "Connections" tab, then click the "LAN Settings" button.

3. Uncheck the box labeled "Use a proxy server for your LAN". Click "OK", and click "OK" in the previous window. This will remove the proxy server settings in Internet Explorer.



Firefox (Windows)
1. Click "Tools", then click "Options" to bring up the Options window.

2. Click the "Advanced" button, then click the "Network" tab.

3. Click the "Settings" button, located next to "Configure how Firefox connects to the Internet".

4. Click the radio button labeled "No proxy". Click "OK" twice. This will remove the proxy server settings in Firefox.



Disable Internet Explorer Proxy Settings and Reset TCP/IP and Winsock

Disable Internet Explorer Proxy Settings and Reset TCP/IP

It is very important that these steps be carried out exactly as shown otherwise the fix will not work.
If you have any questions please ask before moving on.
  • Please start Notepad and using your mouse make sure you select and copy all the information below in the Code box into your new document.
  • Then save the file as "fixme.bat" to your Desktop
  • In the drop down box for Save as type: make sure you select All Files (*.*) and keep the quotes on the name as well. Then close the new file.
    @ECHO OFF
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyServer /f
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyOverride /f
    reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyEnable  /t REG_DWORD /d 0 /f
    reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v GlobalUserOffline /t REG_DWORD /d 0 /f
    netsh int ip reset resetlog.txt
    netsh winsock reset catalog
  • On Windows XP you can double-click the file to run it.
  • On Vista/Win7 you need to Right click the file and choose Run as administrator to run it. With User Account Control on it should ask permission to run it. Click Yes
  • This will flash a black DOS box very quickly and go away, this is normal.
  • Restart your computer now.
  • Launch Internet Explorer and see if you can connect to the Internet.
  • Launch MBAM and check for Updates
this works i can connect to the internet now on my desktop. Thanks, i don't know what is causing this but since I put in that new card my computer will turn itself on by itself after about 15 minutes of being shutdown. Does this sound hardware related?

this works i can connect to the internet now on my desktop. Thanks, i don't know what is causing this but since I put in that new card my computer will turn itself on by itself after about 15 minutes of being shutdown. Does this sound hardware related?

My guess is a software setting for you card
yea turns out it is a WOL wakeup-on-LAN card.. still strange though as its three pin WOL connector goes to nothing and im not sending any turn PC on "magic packets"
We can look further

Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI