This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

DDOS attack STORM?

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can anyone help me, My sons WOW account has been taken this morning and I wondered if it was related to the DOS storm attacks, not really sure what to do. Want to make sure its not a problem that will recurr. I dont really understand the log please help Thanks [Admin login] from source 192.168.1.4, Thursday, Feb 24,2011 15:01:33 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Thursday, Feb 24,2011 14:55:17 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Thursday, Feb 24,2011 14:48:50 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Thursday, Feb 24,2011 13:52:13 [DHCP IP: (192.168.1.8)] to MAC address 00:22:FA:0D:44:AA, Thursday, Feb 24,2011 13:21:21 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Thursday, Feb 24,2011 12:34:44 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Thursday, Feb 24,2011 09:04:00 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Thursday, Feb 24,2011 01:51:37 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 21:34:43 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 21:34:22 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 21:34:01 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 21:33:34 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 21:32:53 [LAN access from remote] from [removed]:15567 to 192.168.1.7:10000 Wednesday, Feb 23,2011 21:04:25 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Wednesday, Feb 23,2011 20:52:51 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Wednesday, Feb 23,2011 18:55:45 [LAN access from remote] from [removed]:20767 to 192.168.1.7:10000 Wednesday, Feb 23,2011 16:41:54 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:23:44 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:23:23 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:23:02 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:22:41 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:22:20 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:21:59 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:21:38 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:21:17 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:20:56 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:20:35 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:20:14 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:19:50 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:18:47 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:18:26 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:18:05 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:17:23 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:17:02 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:16:41 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 23,2011 16:16:20 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Wednesday, Feb 23,2011 16:13:57 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Wednesday, Feb 23,2011 13:31:36 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Wednesday, Feb 23,2011 11:40:44 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Wednesday, Feb 23,2011 08:52:36 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Wednesday, Feb 23,2011 01:13:42 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Wednesday, Feb 23,2011 00:30:57 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Wednesday, Feb 23,2011 00:30:36 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Wednesday, Feb 23,2011 00:30:15 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Tuesday, Feb 22,2011 23:41:35 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Tuesday, Feb 22,2011 23:12:07 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Tuesday, Feb 22,2011 23:11:25 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Tuesday, Feb 22,2011 18:40:54 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Tuesday, Feb 22,2011 18:40:42 [LAN access from remote] from [removed]:20767 to 192.168.1.7:10000 Tuesday, Feb 22,2011 17:57:51 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 22,2011 16:13:10 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 22,2011 16:12:49 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 22,2011 16:12:28 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 22,2011 16:12:07 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 22,2011 16:11:46 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 22,2011 16:11:23 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Tuesday, Feb 22,2011 14:34:58 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Tuesday, Feb 22,2011 14:00:08 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Tuesday, Feb 22,2011 13:13:39 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Tuesday, Feb 22,2011 11:21:34 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Tuesday, Feb 22,2011 08:57:34 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Tuesday, Feb 22,2011 06:51:37 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Monday, Feb 21,2011 23:38:26 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Monday, Feb 21,2011 21:42:10 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Monday, Feb 21,2011 21:41:37 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Monday, Feb 21,2011 21:41:14 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Monday, Feb 21,2011 18:55:11 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Monday, Feb 21,2011 18:51:47 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 15:43:32 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 15:43:11 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 15:42:51 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 15:42:29 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 15:42:08 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 15:41:47 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Monday, Feb 21,2011 14:38:33 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 14:21:42 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 14:21:21 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 14:21:00 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 14:20:39 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 14:20:18 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 21,2011 14:19:57 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Monday, Feb 21,2011 14:18:19 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Monday, Feb 21,2011 11:38:23 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Monday, Feb 21,2011 10:37:12 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Monday, Feb 21,2011 09:11:19 [Internet connected] IP address: [removed], Monday, Feb 21,2011 05:28:21 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Monday, Feb 21,2011 01:04:59 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Sunday, Feb 20,2011 21:52:25 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Sunday, Feb 20,2011 21:09:53 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Sunday, Feb 20,2011 14:23:16 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Sunday, Feb 20,2011 12:59:44 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Sunday, Feb 20,2011 12:57:37 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Sunday, Feb 20,2011 12:53:24 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Sunday, Feb 20,2011 12:44:59 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Sunday, Feb 20,2011 12:28:07 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Sunday, Feb 20,2011 11:54:22 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Sunday, Feb 20,2011 10:46:53 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:23:07 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:22:47 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:22:25 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:22:04 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:21:43 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:21:22 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:14:37 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:14:16 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:13:52 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:11:55 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:11:33 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:11:09 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:10:49 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:10:28 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Sunday, Feb 20,2011 10:10:07 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Sunday, Feb 20,2011 09:53:00 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Sunday, Feb 20,2011 09:52:22 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Sunday, Feb 20,2011 09:47:35 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Sunday, Feb 20,2011 08:31:55 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Sunday, Feb 20,2011 04:01:58 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Sunday, Feb 20,2011 02:28:17 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:22:24 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:21:57 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:21:30 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:20:49 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:20:29 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:20:07 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:09:50 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:09:29 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:09:02 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:08:35 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:08:08 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:07:47 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Sunday, Feb 20,2011 00:07:24 [LAN access from remote] from [removed]:20767 to 192.168.1.7:10000 Saturday, Feb 19,2011 21:41:27 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Saturday, Feb 19,2011 21:37:17 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Saturday, Feb 19,2011 21:36:56 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Saturday, Feb 19,2011 20:48:16 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Saturday, Feb 19,2011 20:47:54 [DoS attack: STORM] attack packets in last 20 sec from ip [[removed]], Saturday, Feb 19,2011 20:37:28 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Saturday, Feb 19,2011 16:18:19 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Saturday, Feb 19,2011 16:02:07 [LAN access from remote] from [removed]:15567 to 192.168.1.7:10000 Saturday, Feb 19,2011 14:48:39 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Saturday, Feb 19,2011 14:29:19 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Saturday, Feb 19,2011 14:29:09 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Saturday, Feb 19,2011 14:28:29 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Saturday, Feb 19,2011 08:45:19 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Friday, Feb 18,2011 22:39:44 [LAN access from remote] from [removed]:15567 to 192.168.1.7:10000 Friday, Feb 18,2011 21:20:41 [LAN access from remote] from [removed]:15567 to 192.168.1.7:10000 Friday, Feb 18,2011 20:40:36 [LAN access from remote] from [removed]:20267 to 192.168.1.7:10000 Friday, Feb 18,2011 20:34:35 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Friday, Feb 18,2011 20:33:44 [LAN access from remote] from [removed]:15567 to 192.168.1.7:10000 Friday, Feb 18,2011 19:59:47 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Friday, Feb 18,2011 19:17:17 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Friday, Feb 18,2011 19:15:41 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Friday, Feb 18,2011 18:37:54 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Friday, Feb 18,2011 18:37:33 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Friday, Feb 18,2011 18:37:12 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Friday, Feb 18,2011 18:36:51 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Friday, Feb 18,2011 18:36:30 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Friday, Feb 18,2011 18:36:09 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Friday, Feb 18,2011 18:30:22 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Friday, Feb 18,2011 18:23:52 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Friday, Feb 18,2011 18:18:52 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Friday, Feb 18,2011 17:42:21 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Friday, Feb 18,2011 14:46:53 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Friday, Feb 18,2011 12:55:29 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Friday, Feb 18,2011 08:55:58 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Friday, Feb 18,2011 03:01:27 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Friday, Feb 18,2011 01:38:52 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Friday, Feb 18,2011 00:56:54 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Friday, Feb 18,2011 00:40:55 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Thursday, Feb 17,2011 22:50:34 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Thursday, Feb 17,2011 22:50:13 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Thursday, Feb 17,2011 22:49:50 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Thursday, Feb 17,2011 22:30:13 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Thursday, Feb 17,2011 22:29:52 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Thursday, Feb 17,2011 22:29:31 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Thursday, Feb 17,2011 22:12:05 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Thursday, Feb 17,2011 22:11:44 [LAN access from remote] from [removed]:15567 to 192.168.1.7:10000 Thursday, Feb 17,2011 18:31:26 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Thursday, Feb 17,2011 18:20:45 [Internet connected] IP address: [removed], Thursday, Feb 17,2011 17:27:34 [LAN access from remote] from [removed]:15567 to 192.168.1.7:10000 Thursday, Feb 17,2011 16:40:38 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Thursday, Feb 17,2011 15:31:24 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Thursday, Feb 17,2011 15:31:03 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Thursday, Feb 17,2011 15:29:17 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Thursday, Feb 17,2011 15:28:56 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Thursday, Feb 17,2011 15:28:35 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Thursday, Feb 17,2011 15:18:14 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Thursday, Feb 17,2011 12:42:49 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Thursday, Feb 17,2011 12:40:53 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Thursday, Feb 17,2011 09:19:02 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Thursday, Feb 17,2011 06:31:06 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:26:55 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:26:34 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:26:13 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:25:52 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:25:31 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:25:10 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:24:42 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:24:21 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:23:32 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:23:11 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:22:50 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:21:57 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 22:21:36 [LAN access from remote] from [removed]:20767 to 192.168.1.7:10000 Wednesday, Feb 16,2011 21:41:58 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 21:15:36 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 21:15:14 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 21:04:44 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 21:04:23 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 21:04:03 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 21:03:41 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 21:03:20 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Wednesday, Feb 16,2011 21:03:00 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Wednesday, Feb 16,2011 18:31:15 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Wednesday, Feb 16,2011 18:24:37 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Wednesday, Feb 16,2011 15:30:16 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Wednesday, Feb 16,2011 13:58:22 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Wednesday, Feb 16,2011 13:58:11 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Wednesday, Feb 16,2011 13:57:32 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Wednesday, Feb 16,2011 12:49:59 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Wednesday, Feb 16,2011 10:28:44 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Wednesday, Feb 16,2011 10:01:29 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Wednesday, Feb 16,2011 09:39:05 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Wednesday, Feb 16,2011 01:04:36 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Tuesday, Feb 15,2011 21:57:16 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Tuesday, Feb 15,2011 21:46:06 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 15,2011 20:06:13 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 15,2011 20:05:52 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 15,2011 20:05:31 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 15,2011 20:05:10 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 15,2011 20:04:49 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 15,2011 20:04:28 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Tuesday, Feb 15,2011 15:32:04 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 15,2011 15:06:08 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Tuesday, Feb 15,2011 15:05:47 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Tuesday, Feb 15,2011 15:02:48 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Tuesday, Feb 15,2011 15:02:36 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Tuesday, Feb 15,2011 14:50:29 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Tuesday, Feb 15,2011 14:50:28 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Tuesday, Feb 15,2011 07:49:43 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Tuesday, Feb 15,2011 07:30:43 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Monday, Feb 14,2011 21:49:39 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Monday, Feb 14,2011 21:38:23 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.4], Monday, Feb 14,2011 21:37:38 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 14,2011 20:48:46 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Monday, Feb 14,2011 20:46:44 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 14,2011 18:53:34 [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.7], Monday, Feb 14,2011 18:53:13 [DHCP IP: (192.168.1.7)] to MAC address 00:1F:D0:01:7C:99, Monday, Feb 14,2011 18:45:30 [DHCP IP: (192.168.1.3)] to MAC address 00:06:4F:60:DC:40, Monday, Feb 14,2011 17:13:36 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Monday, Feb 14,2011 17:07:08 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Monday, Feb 14,2011 15:45:08 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Monday, Feb 14,2011 13:12:42 [DHCP IP: (192.168.1.4)] to MAC address 00:17:31:74:3F:C6, Monday, Feb 14,2011 07:47:25 [Internet connected] IP address: [removed], Monday, Feb 14,2011 05:26:29 [DHCP IP: (192.168.1.2)] to MAC address 00:25:4B:3E:9A:67, Monday, Feb 14,2011 00:24:22
Hi windyfish,


Welcome to WhattheTech. My name is Blottedisk and I will be helping you with your malware issues. Before we delve into this, please take a look at the following notes:

  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.
  • The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.

——————————————————-

Ok, let's get started. Please follow the steps below in order:



Step 1 | Please download OTL from one of the following mirrors:

This is THE Mirror

——————————————————————–

  • Save it to your desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it.
  • Double click inside the Custom Scan box at the bottom.
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel".
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop.
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in this topic.
  • You may need two posts to fit them both in.


Step 2 | Let's perform an ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go here then click on: [external image: Posted Image]
    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed make sure you first copy the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic.
  • Now click on: [external image: Posted Image] (Selecting Uninstall application on close if you so wish)
C:\Users\gails machine\AppData\Local\Temp\jar_cache2494682860385786476.tmp Java/TrojanDownloader.OpenStream.NBH trojan C:\Users\gails machine\AppData\Local\Temp\jar_cache5972069825202741384.tmp Java/TrojanDownloader.Agent.NBB trojan C:\Users\gails machine\Downloads\FullMsnChecker228.exe a variant of Win32/AIMMonitorSniffer.A application
OTL logfile created on: 25/02/2011 21:25:51 - Run 1
OTL by OldTimer - Version 3.2.21.0 Folder = C:\Users\gails machine\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 141.04 Gb Total Space | 101.55 Gb Free Space | 72.00% Space Free | Partition Type: NTFS

Computer Name: GAILSMACHINE-PC | User Name: gails machine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\gails machine\Downloads\OTL.com (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10k_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Virgin Media\Service Manager\ServicepointService.exe (Radialpoint Inc.)
PRC - C:\Program Files\Virgin Media\Service Manager\ServiceManager.exe (Virgin Media)
PRC - C:\Program Files\Virgin Media\Digital Home Support\HsdService.exe (Virgin Media)
PRC - C:\Program Files\Virgin Media\Digital Home Support\DHSClient.exe (Virgin Media)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\CSHelper.exe ()
PRC - C:\Program Files\O2CM-CE\O2 Connection Manager\tscui.exe (O2)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe ()
PRC - C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe ()
PRC - C:\Windows\System32\lxdicoms.exe ( )
PRC - C:\Windows\System32\spool\drivers\w32x86\3\lxdiserv.exe (Lexmark International, Inc.)
PRC - C:\Program Files\FinePixViewerS\QuickDCF2.exe (FUJIFILM Corporation)
PRC - C:\Windows\System32\lxbkcoms.exe ( )
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (Sonic Solutions)
PRC - C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe (Packard Bell BV)


========== Modules (SafeList) ==========

MOD - C:\Users\gails machine\Downloads\OTL.com (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msshsq.dll (Microsoft Corporation)
MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)
MOD - C:\Windows\System32\networkexplorer.dll (Microsoft Corporation)
MOD - C:\Windows\System32\SLC.dll (Microsoft Corporation)
MOD - C:\Windows\System32\EhStorShell.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cscapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\GdiPlus.dll (Microsoft Corporation)
MOD - C:\Windows\System32\thumbcache.dll (Microsoft Corporation)
MOD - C:\Windows\System32\duser.dll (Microsoft Corporation)
MOD - C:\Windows\System32\actxprxy.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (CLTNetCnService) – File not found
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ServicepointService) – C:\Program Files\Virgin Media\Service Manager\ServicepointService.exe (Radialpoint Inc.)
SRV - (HsdService) – C:\Program Files\Virgin Media\Digital Home Support\HsdService.exe (Virgin Media)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FsUsbExService) – C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (CSHelper) – C:\Windows\System32\CSHelper.exe ()
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (lxdi_device) – C:\Windows\System32\lxdicoms.exe ( )
SRV - (lxdiCATSCustConnectService) – C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe ()
SRV - (lxbk_device) – C:\Windows\System32\lxbkcoms.exe ( )
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (NetGroup - Politecnico di Torino)


========== Driver Services (SafeList) ==========

DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (FsUsbExDisk) – C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (pavboot) – C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (KMWDFILTER) – C:\Windows\System32\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (ss_mdm) – C:\Windows\System32\drivers\ss_mdm.sys (MCCI Corporation)
DRV - (ss_mdfl) – C:\Windows\System32\drivers\ss_mdfl.sys (MCCI Corporation)
DRV - (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM) – C:\Windows\System32\drivers\ss_bus.sys (MCCI Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\Windows\System32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (ST330) – C:\Windows\System32\drivers\st330.sys (THOMSON Telecom Belgium)
DRV - (STBUS) – C:\Windows\System32\drivers\stbus.sys (THOMSON Telecom Belgium)
DRV - (WPN111) – C:\Windows\System32\drivers\WPN111.sys (NETGEAR, Inc.)
DRV - (NPF) – C:\Windows\System32\drivers\npf.sys (NetGroup - Politecnico di Torino)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn1.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {a8864317-e18b-4292-99d9-e6e65ab905d3} - C:\Program Files\Runescape\tbRun1.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn1.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {a8864317-e18b-4292-99d9-e6e65ab905d3} - C:\Program Files\Runescape\tbRun1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/17 09:21:17 | 000,000,000 | —D | M]


O1 HOSTS File: ([2006/09/18 21:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn1.dll (Conduit Ltd.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (RuneScape Toolbar) - {a8864317-e18b-4292-99d9-e6e65ab905d3} - C:\Program Files\Runescape\tbRun1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (RuneScape Toolbar) - {a8864317-e18b-4292-99d9-e6e65ab905d3} - C:\Program Files\Runescape\tbRun1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\tbZyn1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (RuneScape Toolbar) - {A8864317-E18B-4292-99D9-E6E65AB905D3} - C:\Program Files\Runescape\tbRun1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DHSClient.exe] C:\Program Files\Virgin Media\Digital Home Support\DHSClient.exe (Virgin Media)
O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files\Lexmark Fax Solutions\fm3032.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [lxdiamon] C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe ()
O4 - HKLM..\Run: [lxdimon.exe] C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [O2Start] C:\Program Files\O2CM-CE\O2 Connection Manager\tscui.exe (O2)
O4 - HKLM..\Run: [ReimageFTP] File not found
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [ServiceManager.exe] C:\Program Files\Virgin Media\Service Manager\ServiceManager.exe (Virgin Media)
O4 - HKLM..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe ( )
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe (Packard Bell BV)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/pr02/resou…NPUplden-gb.cab (MSN Photo Upload Tool)
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} http://www.nanoscan.com/as/cabs/ascstubie.cab (TotalScan Installer Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab (InetDownload Class)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://games-uk.pogo.com/online2/pogo/beje…aploader_v6.cab (PopCapLoader Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…NPUplden-gb.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\gails machine\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\gails machine\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0b618c09-4620-11df-a7d3-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{0b618c09-4620-11df-a7d3-001731743fc6}\Shell\AutoRun\command - "" = J:\AUTORUN.EXE
O33 - MountPoints2\{0b618c0b-4620-11df-a7d3-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{0b618c0b-4620-11df-a7d3-001731743fc6}\Shell\AutoRun\command - "" = J:\AUTORUN.EXE
O33 - MountPoints2\{0b618c0d-4620-11df-a7d3-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{0b618c0d-4620-11df-a7d3-001731743fc6}\Shell\AutoRun\command - "" = J:\AUTORUN.EXE
O33 - MountPoints2\{11892e12-4f79-11df-ad14-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{11892e12-4f79-11df-ad14-001731743fc6}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE
O33 - MountPoints2\{866a7871-4607-11df-aad5-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{866a7871-4607-11df-aad5-001731743fc6}\Shell\AutoRun\command - "" = J:\AUTORUN.EXE
O33 - MountPoints2\{866a78d0-4607-11df-aad5-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{866a78d0-4607-11df-aad5-001731743fc6}\Shell\AutoRun\command - "" = J:\AUTORUN.EXE
O33 - MountPoints2\{8b4c8ed4-46d6-11df-80c7-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{8b4c8ed4-46d6-11df-80c7-001731743fc6}\Shell\AutoRun\command - "" = J:\AUTORUN.EXE
O33 - MountPoints2\{8b4c8edc-46d6-11df-80c7-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{8b4c8edc-46d6-11df-80c7-001731743fc6}\Shell\AutoRun\command - "" = J:\AUTORUN.EXE
O33 - MountPoints2\{8b4c8f00-46d6-11df-80c7-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{8b4c8f00-46d6-11df-80c7-001731743fc6}\Shell\AutoRun\command - "" = J:\AUTORUN.EXE
O33 - MountPoints2\{a64fcdda-4606-11df-abe6-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{a64fcdda-4606-11df-abe6-001731743fc6}\Shell\AutoRun\command - "" = J:\AUTORUN.EXE
O33 - MountPoints2\{ed353f0d-4eef-11df-a3da-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{ed353f0d-4eef-11df-a3da-001731743fc6}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE
O33 - MountPoints2\{ed353f0f-4eef-11df-a3da-001731743fc6}\Shell - "" = AutoRun
O33 - MountPoints2\{ed353f0f-4eef-11df-a3da-001731743fc6}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0

SafeBootMin: aawservice - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: aawservice - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {0EEB34F6-991D-4a1b-8EEB-772DA0EADB22} - Microsoft Office Communicator 2007
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Adobe Shockwave Director 10.1
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 10.1
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2F6EFCE6-10DF-49F9-9E64-9AE3775B2588} - Microsoft .NET Framework 1.1 Security Update (KB2416447)
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

========== Files/Folders - Created Within 30 Days ==========

[2011/02/25 18:38:58 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/02/24 16:39:45 | 000,028,552 | —- | C] (Panda Security, S.L.) – C:\Windows\System32\drivers\pavboot.sys
[2011/02/09 09:33:09 | 002,039,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/02/09 09:33:06 | 003,602,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/02/09 09:33:05 | 003,550,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/02/09 09:32:56 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/02/09 09:32:56 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/02/09 09:32:56 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/02/09 09:32:56 | 000,797,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FntCache.dll
[2011/02/09 09:32:56 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/02/09 09:32:56 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/02/09 09:32:55 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/02/09 09:32:55 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/02/09 09:32:55 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/02/09 09:32:55 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/02/09 09:32:54 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/02/09 09:32:54 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/02/09 09:32:54 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/02/09 09:32:54 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/02/09 09:32:54 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/02/09 09:32:53 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/02/09 09:32:53 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/02/09 09:32:53 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/02/09 09:32:52 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/02/09 09:32:52 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/02/09 09:32:52 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/02/09 09:32:52 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/02/09 09:32:51 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/02/09 09:32:51 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/02/09 09:32:50 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/02/09 09:32:33 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/02/09 09:32:33 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/02/09 09:32:33 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/02/09 09:32:33 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/02/09 09:32:33 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/02/09 09:32:32 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/02/09 09:32:32 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/02/09 09:32:32 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/02/09 09:32:32 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/02/09 09:32:32 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/02/09 09:32:32 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/02/09 09:32:32 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/02/09 09:32:32 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/02/09 09:32:32 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/02/09 09:32:32 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/02/09 09:32:32 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/02/09 09:32:31 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/02/09 09:32:27 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/02/09 09:32:27 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/02/03 23:00:20 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/02/03 23:00:20 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/02/03 23:00:20 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/02/03 23:00:09 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/01/30 21:18:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virgin Media
[2007/12/22 16:58:00 | 000,356,352 | —- | C] ( ) – C:\Windows\System32\lxdiinpa.dll
[2007/12/22 16:58:00 | 000,311,296 | —- | C] ( ) – C:\Windows\System32\lxdihcp.dll
[2007/12/22 16:57:59 | 000,942,080 | —- | C] ( ) – C:\Windows\System32\lxdiusb1.dll
[2007/12/22 16:57:59 | 000,339,968 | —- | C] ( ) – C:\Windows\System32\lxdiiesc.dll
[2007/12/22 16:57:58 | 001,187,840 | —- | C] ( ) – C:\Windows\System32\lxdiserv.dll
[2007/12/22 16:57:58 | 000,614,400 | —- | C] ( ) – C:\Windows\System32\lxdipmui.dll
[2007/12/22 16:57:58 | 000,053,248 | —- | C] ( ) – C:\Windows\System32\lxdiprox.dll
[2007/12/22 16:57:58 | 000,053,248 | —- | C] ( ) – C:\Windows\System32\lxdipplc.dll
[2007/12/22 16:57:57 | 000,532,480 | —- | C] ( ) – C:\Windows\System32\lxdilmpm.dll
[2007/12/22 16:57:55 | 000,671,744 | —- | C] ( ) – C:\Windows\System32\lxdihbn3.dll
[2007/12/22 16:57:54 | 000,765,952 | —- | C] ( ) – C:\Windows\System32\lxdicomc.dll
[2007/12/22 16:57:54 | 000,360,448 | —- | C] ( ) – C:\Windows\System32\lxdicomm.dll
[2006/11/06 15:37:46 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxbkpmui.dll
[2006/11/06 15:35:50 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxbkserv.dll
[2006/11/06 15:28:08 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxbkcomm.dll
[2006/11/06 15:26:14 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbklmpm.dll
[2006/11/06 15:24:44 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbkiesc.dll
[2006/11/06 15:21:48 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxbkpplc.dll
[2006/11/06 15:20:48 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxbkcomc.dll
[2006/11/06 15:20:14 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxbkprox.dll
[2006/11/06 15:12:44 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxbkinpa.dll
[2006/11/06 15:11:58 | 000,991,232 | —- | C] ( ) – C:\Windows\System32\lxbkusb1.dll
[2006/11/06 15:07:04 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxbkhbn3.dll
[34 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[34 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\gails machine\Documents\*.tmp files -> C:\Users\gails machine\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/25 21:12:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/25 20:02:53 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/25 20:02:53 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/25 18:12:03 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/25 15:33:45 | 000,000,434 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{540671EF-E969-4EEC-9FD7-E8B52534BFBB}.job
[2011/02/25 09:20:54 | 107,109,175 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2011/02/25 08:02:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/02/25 08:02:40 | 3756,462,080 | -HS- | M] () – C:\hiberfil.sys
[2011/02/24 23:32:18 | 000,000,117 | —- | M] () – C:\Users\gails machine\jagex_runescape_preferences2.dat
[2011/02/24 23:32:18 | 000,000,046 | —- | M] () – C:\Users\gails machine\jagex_runescape_preferences.dat
[2011/02/18 09:47:19 | 000,373,134 | —- | M] () – C:\Windows\System32\drivers\AVG\iavichjg.avm
[2011/02/12 19:40:32 | 000,014,789 | —- | M] () – C:\Users\gails machine\Documents\Ellis Fisher C.V.docx
[2011/02/11 15:59:34 | 000,606,128 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/02/11 15:59:34 | 000,108,854 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/02/11 15:51:26 | 000,422,232 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/02/07 16:01:13 | 000,006,601 | —- | M] () – C:\ProgramData\lxdi
[2011/02/03 23:00:11 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/02/03 23:00:11 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/02/03 23:00:11 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/02/03 23:00:11 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/01/30 21:19:41 | 000,001,941 | —- | M] () – C:\Users\Public\Desktop\Virgin Media Digital Home Support.lnk
[2011/01/29 23:49:41 | 014,596,608 | —- | M] () – C:\Users\gails machine\Documents\Publication2.pub
[2011/01/29 20:51:19 | 000,011,588 | —- | M] () – C:\Users\gails machine\Documents\Rainbow Nursery.docx
[2011/01/29 20:50:29 | 024,493,056 | —- | M] () – C:\Users\gails machine\Documents\euan picture.pub
[2011/01/27 09:34:07 | 000,000,833 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[34 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[34 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\gails machine\Documents\*.tmp files -> C:\Users\gails machine\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/12 19:32:01 | 000,014,789 | —- | C] () – C:\Users\gails machine\Documents\Ellis Fisher C.V.docx
[2011/01/30 21:19:41 | 000,001,941 | —- | C] () – C:\Users\Public\Desktop\Virgin Media Digital Home Support.lnk
[2011/01/29 22:02:29 | 014,596,608 | —- | C] () – C:\Users\gails machine\Documents\Publication2.pub
[2011/01/29 20:51:18 | 000,011,588 | —- | C] () – C:\Users\gails machine\Documents\Rainbow Nursery.docx
[2011/01/29 20:50:28 | 024,493,056 | —- | C] () – C:\Users\gails machine\Documents\euan picture.pub
[2010/04/26 11:25:50 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/12/16 23:18:42 | 000,110,592 | —- | C] () – C:\Windows\System32\FsUsbExDevice.Dll
[2009/12/16 23:18:42 | 000,036,608 | —- | C] () – C:\Windows\System32\FsUsbExDisk.Sys
[2009/07/08 12:11:43 | 000,000,230 | —- | C] () – C:\Windows\reimage.ini
[2009/06/21 09:35:29 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/19 13:05:14 | 001,380,403 | —- | C] () – C:\Windows\System32\avgsdk.dll
[2008/10/07 08:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2008/09/08 07:15:11 | 000,000,031 | -H– | C] () – C:\Windows\UKCpInfo.sys
[2008/09/05 16:06:33 | 000,006,601 | —- | C] () – C:\ProgramData\lxdi
[2008/07/19 07:42:47 | 000,000,002 | —- | C] () – C:\Windows\msoffice.ini
[2008/05/04 17:39:34 | 000,002,560 | —- | C] () – C:\Windows\System32\ViaClassCoInstaller.dll
[2007/12/22 17:02:53 | 000,344,064 | —- | C] () – C:\Windows\System32\lxdicoin.dll
[2007/12/22 17:00:20 | 000,045,056 | —- | C] () – C:\Windows\System32\LXF3PMON.DLL
[2007/12/22 17:00:20 | 000,032,768 | —- | C] () – C:\Windows\System32\LXF3FXPU.DLL
[2007/12/22 17:00:00 | 000,036,864 | —- | C] () – C:\Windows\System32\lxf3oem.dll
[2007/12/22 17:00:00 | 000,012,288 | —- | C] () – C:\Windows\System32\LXF3PMRC.DLL
[2007/12/22 16:58:15 | 000,000,060 | -H– | C] () – C:\Windows\System32\lxdirwrd.ini
[2007/12/22 16:58:00 | 000,294,912 | —- | C] () – C:\Windows\System32\lxdiinst.dll
[2007/12/22 16:57:55 | 000,208,896 | —- | C] () – C:\Windows\System32\lxdigrd.dll
[2007/10/25 17:26:10 | 000,005,632 | —- | C] () – C:\Windows\System32\drivers\StarOpen.sys
[2007/10/11 16:38:43 | 000,001,356 | —- | C] () – C:\Users\gails machine\AppData\Local\d3d9caps.dat
[2007/06/29 09:25:12 | 000,033,664 | —- | C] () – C:\Windows\System32\drivers\TsWlan.sys
[2007/06/16 09:05:58 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2007/06/11 20:55:57 | 000,651,264 | —- | C] () – C:\Windows\System32\libeay32.dll
[2007/06/11 20:55:57 | 000,147,456 | —- | C] () – C:\Windows\System32\ssleay32.dll
[2007/05/10 21:38:16 | 000,036,197 | —- | C] () – C:\ProgramData\LUUnInstall.LiveUpdate
[2007/04/18 16:38:22 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2007/04/18 16:24:35 | 000,000,720 | —- | C] () – C:\Windows\Lexstat.ini
[2007/04/10 16:19:07 | 000,021,504 | —- | C] () – C:\Users\gails machine\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/04/10 16:17:21 | 000,000,101 | —- | C] () – C:\Users\gails machine\AppData\Local\fusioncache.dat
[2007/03/27 09:45:22 | 000,004,096 | —- | C] () – C:\Windows\System32\sysres.dll
[2007/03/23 19:44:45 | 000,692,224 | —- | C] () – C:\Windows\System32\lxdidrs.dll
[2007/02/09 18:07:06 | 000,069,632 | —- | C] () – C:\Windows\System32\lxdicnv4.dll
[2007/02/07 18:57:50 | 000,039,899 | —- | C] () – C:\Windows\System32\rtsicis.ini
[2007/01/23 23:40:16 | 000,065,536 | —- | C] () – C:\Windows\System32\lxdicaps.dll
[2007/01/22 07:49:34 | 000,344,064 | —- | C] () – C:\Windows\System32\lxbkcoin.dll
[2006/12/21 10:06:12 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/30 12:34:24 | 000,413,696 | —- | C] () – C:\Windows\System32\lxbkutil.dll
[2006/11/02 12:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 07:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/08/01 05:53:18 | 000,040,960 | —- | C] () – C:\Windows\System32\lxdivs.dll
[2005/10/05 11:19:32 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbkvs.dll
[2005/09/13 15:27:10 | 000,061,440 | —- | C] () – C:\Windows\System32\lxbkcnv5.dll
[2004/07/10 17:55:38 | 000,252,416 | —- | C] () – C:\Windows\System32\wsiShared.dll
[2004/01/15 06:01:26 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2003/10/21 11:58:28 | 000,040,448 | —- | C] () – C:\Windows\System32\REGOBJ.DLL
[1999/01/22 18:46:58 | 000,065,536 | —- | C] () – C:\Windows\System32\MSRTEDIT.DLL

========== Alternate Data Streams ==========

@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >
I didnt get a second report from OTL … We are on a cable connection with 4 cabled connections, and my son accesses the net with his phone, ipod, and laptop. I take it we need to run on all our machines? I ran ESET on my sons and nothing comes up at all, says its okay. The BHO are for a couple of games ie Zynga and Runescape. The IMM is for a spy program for keeping an eye on messenger conversations. Thanks for your help
Hi there,

The BHO are for a couple of games ie Zynga and Runescape.



I have to disagree with you at this point. Those BHO aren't for the games themselves, but for their respective Internet Explorer Toolbars. These toolbars, that are part of the Conduit Community Toolbars, are known to have a certain trackware functionality. As they are just browser helper objects, they are not part of the games themselves, so there wont be a problem removing them.


We are on a cable connection with 4 cabled connections, and my son accesses the net with his phone, ipod, and laptop. I take it we need to run on all our machines? I ran ESET on my sons and nothing comes up at all, says its okay.


WelI, these attacks are coming from 2 of the computers: 192.168.1.7 and 192.168.1.4. We need to focus just on these two machines to get rid of the DoS infection, if present. Can you tell to which machine does each IP correspond? If not, then please follow these simple procedure in each machine to determine their respective IP adresses, and isolate the two computers we need to work on:


Launch Notepad (not wordpad), and copy and paste the contents of the code box below into a new text file.

  • Save it as file name: "IP.bat" (not including the quotes). Save as file type: All files (*.*) and save it on your Desktop.


    @echo off
    ipconfig > ipconfig.txt
    del %0
    exit
  • Once done, double click IP.bat to run it. A command window will open briefly, then close. This is quite normal.
  • Go to your desktop, open the file ipconfig.txt and copy-paste it´s content here.
this is the report from the computer that is .7

OTL logfile created on: 26/02/2011 10:45:42 - Run 2
OTL by OldTimer - Version 3.2.21.0 Folder = C:\Users\neil\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.79 Gb Total Space | 134.41 Gb Free Space | 57.74% Space Free | Partition Type: NTFS
Drive D: | 99.99 Mb Total Space | 86.20 Mb Free Space | 86.21% Space Free | Partition Type: NTFS
Drive E: | 148.95 Gb Total Space | 45.57 Gb Free Space | 30.59% Space Free | Partition Type: NTFS
Drive H: | 6.32 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive I: | 245.48 Mb Total Space | 224.67 Mb Free Space | 91.52% Space Free | Partition Type: FAT

Computer Name: NEIL-PC | User Name: neil | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\neil\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe ()
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
PRC - C:\Windows\System32\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\neil\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\StructuredQuery.dll (Microsoft Corporation)
MOD - C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msvcr100_clr0400.dll (Microsoft Corporation)
MOD - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)
MOD - C:\Windows\System32\thumbcache.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\srvcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\slc.dll (Microsoft Corporation)
MOD - C:\Windows\System32\SearchFolder.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\RpcRtRemote.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\networkexplorer.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\EhStorShell.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptsp.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cscapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\actxprxy.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (gdrv) – C:\Windows\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (ha20x2k) – C:\Windows\System32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\Windows\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\Windows\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\Windows\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\Windows\System32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – C:\Windows\System32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\Windows\System32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\Windows\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTEXFIFX.SYS) – C:\Windows\System32\drivers\CTEXFIFX.SYS (Creative Technology Ltd.)
DRV - (CTEXFIFX) – C:\Windows\System32\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV - (CTHWIUT.SYS) – C:\Windows\System32\drivers\CTHWIUT.SYS (Creative Technology Ltd.)
DRV - (CTHWIUT) – C:\Windows\System32\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV - (CT20XUT.SYS) – C:\Windows\System32\drivers\CT20XUT.SYS (Creative Technology Ltd.)
DRV - (CT20XUT) – C:\Windows\System32\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (SaiKA50A) – C:\Windows\System32\drivers\SaiKA50A.sys (Saitek)
DRV - (SaiUA50A) – C:\Windows\System32\drivers\SaiUA50A.sys (Saitek)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek Corporation )
DRV - (Alpham1) – C:\Windows\System32\drivers\Alpham1.sys (Ideazon Corporation)
DRV - (Alpham2) – C:\Windows\System32\drivers\Alpham2.sys (Ideazon Corporation)
DRV - (RecFltr) – C:\Windows\System32\drivers\RecFltr.sys ()
DRV - (OmniUsb) – C:\Windows\System32\drivers\OmniUsb.sys (Ideazon)
DRV - (OmniUsbl) – C:\Windows\System32\drivers\OmniUsbl.sys (Ideazon)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 96 25 44 A9 51 D4 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2009/06/10 21:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (@C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.)
O4 - HKCU..\Run: [Comrade.exe] C:\Program Files\GameSpy\Comrade\Comrade.exe (IGN Entertainment Inc.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15114/CTPID.cab (Creative Software AutoUpdate Support Package 1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | —- | M] () - E:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/06/12 02:27:33 | 000,000,140 | R— | M] () - H:\autorun.inf – [ UDF ]
O33 - MountPoints2\{439ef54e-2b9f-11e0-9559-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{439ef54e-2b9f-11e0-9559-806e6f6e6963}\Shell\AutoRun\command - "" = G:\setup\rsrc\Autorun.exe
O33 - MountPoints2\{439ef54e-2b9f-11e0-9559-806e6f6e6963}\Shell\dinstall\command - "" = G:\Directx\dxsetup.exe
O33 - MountPoints2\{b9972bb7-2b8a-11e0-82bb-001fd0017c99}\Shell - "" = AutoRun
O33 - MountPoints2\{b9972bb7-2b8a-11e0-82bb-001fd0017c99}\Shell\AutoRun\command - "" = F:\LaunchU3.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)


SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MsMpSvc - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Power - C:\Windows\System32\umpo.dll (Microsoft Corporation)
SafeBootMin: Primary disk - Driver Group
SafeBootMin: RpcEptMapper - C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: Dhcp - C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MsMpSvc - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: ndiscap - C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Power - C:\Windows\System32\umpo.dll (Microsoft Corporation)
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: RpcEptMapper - C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

========== Files/Folders - Created Within 30 Days ==========

[2011/02/26 09:17:20 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/02/26 08:58:29 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{002669F2-52DF-41AF-92EA-1CDDBBF85778}
[2011/02/25 22:20:49 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Roaming\PCFix
[2011/02/25 22:10:35 | 000,577,024 | —- | C] (OldTimer Tools) – C:\Users\neil\Desktop\OTL.exe
[2011/02/25 22:09:24 | 000,000,000 | —D | C] – C:\Windows\System32\RTCOM
[2011/02/25 22:08:51 | 001,783,056 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\WavesLib.dll
[2011/02/25 22:08:51 | 001,723,536 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\WavesGUILib.dll
[2011/02/25 22:08:51 | 000,345,328 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSTSXT.dll
[2011/02/25 22:08:51 | 000,185,584 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSTSHD.dll
[2011/02/25 22:08:51 | 000,173,296 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSHP360.dll
[2011/02/25 22:08:51 | 000,140,528 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSWOW.dll
[2011/02/25 22:08:49 | 001,084,008 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RTSndMgr.cpl
[2011/02/25 22:08:49 | 000,214,352 | —- | C] (Virage Logic Corporation / Sonic Focus) – C:\Windows\System32\SFNHK.dll
[2011/02/25 22:08:49 | 000,074,064 | —- | C] (Virage Logic Corporation / Sonic Focus) – C:\Windows\System32\SFCOM.dll
[2011/02/25 22:08:49 | 000,068,944 | —- | C] (Virage Logic Corporation / Sonic Focus) – C:\Windows\System32\SFAPO.dll
[2011/02/25 22:08:48 | 003,386,792 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\drivers\RTKVHDA.sys
[2011/02/25 22:08:48 | 002,137,704 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkPgExt.dll
[2011/02/25 22:08:47 | 003,804,264 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkAPO.dll
[2011/02/25 22:08:47 | 000,477,800 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkApoApi.dll
[2011/02/25 22:08:47 | 000,069,224 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkCoInst.dll
[2011/02/25 22:08:44 | 000,359,768 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RTEEP32A.dll
[2011/02/25 22:08:44 | 000,170,840 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RTEED32A.dll
[2011/02/25 22:08:44 | 000,078,680 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RTEEL32A.dll
[2011/02/25 22:08:44 | 000,064,856 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RTEEG32A.dll
[2011/02/25 22:08:43 | 001,705,816 | —- | C] (Dolby Laboratories) – C:\Windows\System32\R4EEP32A.dll
[2011/02/25 22:08:43 | 000,783,360 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RCoRes.dat
[2011/02/25 22:08:43 | 000,341,848 | —- | C] (Dolby Laboratories) – C:\Windows\System32\R4EED32A.dll
[2011/02/25 22:08:43 | 000,295,768 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RP3DHT32.dll
[2011/02/25 22:08:43 | 000,295,768 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RP3DAA32.dll
[2011/02/25 22:08:43 | 000,252,760 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxVolumeSDAPO.dll
[2011/02/25 22:08:43 | 000,096,600 | —- | C] (Dolby Laboratories) – C:\Windows\System32\R4EEL32A.dll
[2011/02/25 22:08:43 | 000,081,240 | —- | C] (Dolby Laboratories) – C:\Windows\System32\R4EEA32A.dll
[2011/02/25 22:08:43 | 000,061,784 | —- | C] (Dolby Laboratories) – C:\Windows\System32\R4EEG32A.dll
[2011/02/25 22:08:42 | 001,938,704 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxAudioEQ.dll
[2011/02/25 22:08:42 | 001,439,064 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxAudioRealtek.dll
[2011/02/25 22:08:41 | 000,259,928 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxAudioAPO30.dll
[2011/02/25 22:08:40 | 000,232,792 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxAudioAPO20.dll
[2011/02/25 22:08:40 | 000,132,368 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxAudioAPO.dll
[2011/02/25 22:08:26 | 001,564,736 | —- | C] (Fortemedia Corporation) – C:\Windows\System32\FMAPO.dll
[2011/02/25 22:08:26 | 001,132,648 | —- | C] (DTS) – C:\Windows\System32\DTSS2SpeakerDLL.dll
[2011/02/25 22:08:26 | 000,962,664 | —- | C] (DTS) – C:\Windows\System32\DTSS2HeadphoneDLL.dll
[2011/02/25 22:08:26 | 000,429,160 | —- | C] (DTS) – C:\Windows\System32\DTSSymmetryDLL.dll
[2011/02/25 22:08:26 | 000,406,120 | —- | C] (DTS) – C:\Windows\System32\DTSVoiceClarityDLL.dll
[2011/02/25 22:08:26 | 000,291,432 | —- | C] (DTS) – C:\Windows\System32\DTSNeoPCDLL.dll
[2011/02/25 22:08:26 | 000,224,360 | —- | C] (DTS) – C:\Windows\System32\DTSLimiterDLL.dll
[2011/02/25 22:08:25 | 000,901,224 | —- | C] (DTS) – C:\Windows\System32\DTSBoostDLL.dll
[2011/02/25 22:08:25 | 000,448,616 | —- | C] (DTS) – C:\Windows\System32\DTSBassEnhancementDLL.dll
[2011/02/25 22:08:25 | 000,236,648 | —- | C] (DTS) – C:\Windows\System32\DTSGainCompensatorDLL.dll
[2011/02/25 22:08:25 | 000,175,200 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\AERTACap.dll
[2011/02/25 22:08:25 | 000,107,112 | —- | C] (DTS) – C:\Windows\System32\DTSLFXAPO.dll
[2011/02/25 22:08:25 | 000,107,112 | —- | C] (DTS) – C:\Windows\System32\DTSGFXAPO.dll
[2011/02/25 22:08:25 | 000,106,600 | —- | C] (DTS) – C:\Windows\System32\DTSGFXAPONS.dll
[2011/02/25 22:08:25 | 000,096,160 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\AERTARen.dll
[2011/02/25 21:54:41 | 000,000,000 | —D | C] – C:\Swsetup
[2011/02/25 21:53:35 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A4Tech Hardware
[2011/02/25 21:53:33 | 000,000,000 | —D | C] – C:\Program Files\A4Tech
[2011/02/25 21:49:58 | 000,057,960 | —- | C] (Khronos Group) – C:\Windows\System32\OpenCL.dll
[2011/02/25 21:49:57 | 015,047,272 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvoglv32.dll
[2011/02/25 21:49:57 | 013,011,560 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcompiler.dll
[2011/02/25 21:49:57 | 010,467,656 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvlddmkm.sys
[2011/02/25 21:49:57 | 010,078,312 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvd3dum.dll
[2011/02/25 21:49:57 | 004,941,928 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuda.dll
[2011/02/25 21:49:57 | 002,895,976 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuvid.dll
[2011/02/25 21:49:57 | 002,251,368 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuvenc.dll
[2011/02/25 21:49:57 | 000,941,160 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvdispco322090.dll
[2011/02/25 21:49:57 | 000,837,736 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvgenco322040.dll
[2011/02/25 21:49:57 | 000,010,920 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvBridge.kmd
[2011/02/25 17:22:04 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{CB67E52B-876D-442D-9FA0-D2EDDFDB6009}
[2011/02/24 14:49:53 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{9C9F49DB-D062-4D5D-9D2C-2317DFA3C744}
[2011/02/23 16:18:09 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/02/23 16:18:09 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/02/23 16:14:37 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{956B0E52-1AFD-426D-8E91-9239EA042CB4}
[2011/02/22 14:35:27 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{84E9F283-DE9E-4551-9519-3680E624231F}
[2011/02/21 14:18:56 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{B8039718-16DA-4AE4-A775-D25E162FBD75}
[2011/02/20 21:54:25 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{838E0FDD-14AA-4753-8CE4-9F28563464AF}
[2011/02/20 16:51:32 | 000,000,000 | —D | C] – C:\Windows\System32\Adobe
[2011/02/20 10:46:58 | 000,000,000 | —D | C] – C:\Users\neil\Documents\My Received Files
[2011/02/20 09:53:58 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{FE15B7E3-73A5-4742-B872-97977A25B764}
[2011/02/19 14:29:53 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{B9D1D328-EA2C-4329-8961-B3E15C759F9F}
[2011/02/18 18:24:23 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{169CBC1E-33FC-4A7B-87AC-B1AAD312387A}
[2011/02/17 15:18:45 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{8F610ADB-D27C-4B99-93E1-336BFBA829BF}
[2011/02/16 13:59:19 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{9A737D31-F02B-4224-B45C-107076DCE392}
[2011/02/15 15:03:27 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{E5D317CD-8F3B-4C4B-B745-B06DAF8C5EA7}
[2011/02/14 18:46:13 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{1E58F721-C452-4A36-A99F-CE242E763881}
[2011/02/13 22:02:26 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{68B1AEF6-24BE-41C8-9BFB-5932D7D5E721}
[2011/02/13 10:02:14 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{6E33697A-D6A6-4B4E-B0BB-0A1C1DE4C4D0}
[2011/02/12 21:41:54 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{FFEB9C8F-F1F2-485D-83D1-BA9903B11C15}
[2011/02/12 09:41:27 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{5AFE2B5A-83C1-4D78-AE2A-E85449D4F5C0}
[2011/02/11 16:04:44 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{7A5AA1A8-9BC8-4128-B44A-2572ABF0CB6A}
[2011/02/10 16:11:04 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{65C95FBF-3B1C-4A2F-8DA8-A9FD5FE63B6B}
[2011/02/09 16:03:51 | 002,329,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/02/09 16:03:48 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/02/09 16:03:48 | 000,428,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/02/09 16:03:44 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/02/09 16:03:44 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/02/09 16:03:44 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/02/09 16:03:44 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/02/09 16:03:44 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/02/09 16:03:44 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/02/09 16:03:43 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/02/09 16:03:43 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/02/09 16:03:43 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/02/09 16:02:53 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/02/09 16:02:53 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/02/09 16:02:50 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/02/09 16:02:50 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/02/09 16:02:42 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\upnp.dll
[2011/02/09 16:02:41 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\davclnt.dll
[2011/02/09 16:02:41 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscapi.dll
[2011/02/09 16:02:41 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwga.dll
[2011/02/09 16:02:40 | 000,219,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2011/02/09 15:58:08 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{CA344B5C-706D-4CD4-AFDA-6D372D7D52F2}
[2011/02/08 18:09:20 | 000,000,000 | —D | C] – C:\Users\neil\Desktop\New folder (4)
[2011/02/08 16:39:12 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{144E3A5F-1D31-4AB0-8055-FED49C76AB0A}
[2011/02/07 15:31:20 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{99A6B983-DE4D-4221-8FB3-1E627365F6AB}
[2011/02/06 22:09:03 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{9E105CF9-2C94-452B-9B15-25329B181305}
[2011/02/06 10:08:51 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{7CD312B2-52DE-4085-B00B-57128AF8587A}
[2011/02/05 22:08:26 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{1409C62E-B2CF-4A7A-8FC8-B0D2F561F252}
[2011/02/05 13:53:54 | 010,653,973 | —- | C] (Electronic Arts, Inc ) – C:\Users\neil\Desktop\battlefield_vietnam_incremental_patch_v1.2_to_v1.21.exe
[2011/02/05 13:04:12 | 000,000,000 | —D | C] – C:\Users\neil\Desktop\BF2CC_Client_1.4.2446
[2011/02/05 11:53:57 | 000,000,000 | —D | C] – C:\Program Files\URLGameStarter
[2011/02/05 10:08:01 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{035DD773-4FC1-4B0F-A76F-D00B61A010EA}
[2011/02/04 14:59:59 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{2AB5C30A-12AF-4CC7-ACBB-6D3F17EC5413}
[2011/02/03 15:10:12 | 000,000,000 | —D | C] – C:\.jagex_cache_32
[2011/02/03 15:06:40 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneScape
[2011/02/03 15:06:39 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\jagexlauncher
[2011/02/03 14:48:08 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{55D320E6-D58B-4134-80F7-CD7AF659D828}
[2011/02/02 17:15:29 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{CA109A29-2132-4FE4-B464-894A39F0F6E2}
[2011/02/01 15:54:57 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{7DC11B6D-C1F0-4425-B2D6-A9DEEFF32BFA}
[2011/01/31 14:02:41 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{DA10126C-DAE9-4635-967A-12DA9E42ACE9}
[2011/01/30 22:38:12 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{636433B7-94AF-4168-A0A7-BFEF8FE7CC8B}
[2011/01/30 10:37:47 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{9FEDAC7F-12FD-42D5-B361-BFA3F58AA0F6}
[2011/01/29 21:34:08 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{1BDC9D9D-8AD1-4F56-80D3-628B39E0F30C}
[2011/01/29 13:37:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/01/29 13:21:07 | 000,000,000 | —D | C] – C:\Program Files\Activision
[2011/01/29 12:18:44 | 007,246,688 | —- | C] (Activision Blizzard, Inc.) – C:\Users\neil\Desktop\CoDWaW.exe
[2011/01/29 10:54:15 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Roaming\U3
[2011/01/29 09:33:42 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{F4AA6F99-8DBA-4257-9B32-05B9F5E0CE51}
[2011/01/28 18:01:06 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{E35BBD1F-D1D0-4E4A-A4D5-D61971F9ADCB}
[2011/01/27 18:07:42 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Roaming\BFBC2CC
[2011/01/27 18:07:38 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\i3D.net
[2011/01/27 18:07:25 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\Deployment
[2011/01/27 18:07:25 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\Apps
[2011/01/27 17:20:23 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2011/01/27 17:17:03 | 000,729,088 | —- | C] (Indigo Rose Corporation) – C:\Windows\iun6002.exe
[2011/01/27 17:17:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DesertCombat
[2011/01/27 17:10:12 | 000,000,000 | —D | C] – C:\Users\neil\Documents\My Downloads
[2011/01/27 17:00:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
[2011/01/27 16:58:59 | 000,000,000 | —D | C] – C:\Program Files\EA GAMES
[2011/01/27 14:56:09 | 000,000,000 | —D | C] – C:\Users\neil\AppData\Local\{AD41DD22-E186-4A2D-BFAE-22C4E01DA16B}
[2010/05/05 19:59:10 | 000,060,928 | —- | C] ( ) – C:\Windows\System32\a3d.dll

========== Files - Modified Within 30 Days ==========

[2011/02/26 09:04:57 | 000,023,760 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/26 09:04:57 | 000,023,760 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/26 08:57:37 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/02/26 08:57:28 | 2414,731,264 | -HS- | M] () – C:\hiberfil.sys
[2011/02/25 22:41:23 | 000,054,400 | —- | M] () – C:\Windows\System32\BMXStateBkp-{00000004-00000000-00000001-00001102-00000005-00311102}.rfx
[2011/02/25 22:41:23 | 000,054,400 | —- | M] () – C:\Windows\System32\BMXState-{00000004-00000000-00000001-00001102-00000005-00311102}.rfx
[2011/02/25 22:41:23 | 000,000,788 | —- | M] () – C:\Windows\System32\DVCState-{00000004-00000000-00000001-00001102-00000005-00311102}.rfx
[2011/02/25 22:23:33 | 000,577,024 | —- | M] (OldTimer Tools) – C:\Users\neil\Desktop\OTL.exe
[2011/02/25 22:19:40 | 000,661,622 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/02/25 22:19:40 | 000,123,456 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/02/25 21:46:01 | 000,445,016 | —- | M] (Creative Labs) – C:\Windows\System32\wrap_oal.dll
[2011/02/25 21:46:00 | 000,109,144 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\System32\OpenAL32.dll
[2011/02/25 21:46:00 | 000,000,087 | RH– | M] () – C:\Windows\ctfile.rfc
[2011/02/25 21:41:40 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_SaiKA50A_01005.Wdf
[2011/02/24 17:38:21 | 000,138,416 | —- | M] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2011/02/24 17:38:11 | 000,270,904 | —- | M] () – C:\Windows\System32\PnkBstrB.xtr
[2011/02/24 17:37:17 | 000,215,128 | —- | M] () – C:\Windows\System32\PnkBstrB.ex0
[2011/02/23 21:34:54 | 000,000,117 | —- | M] () – C:\Users\neil\jagex_runescape_preferences2.dat
[2011/02/23 21:33:58 | 000,000,024 | —- | M] () – C:\Users\neil\jagexappletviewer.preferences
[2011/02/23 21:30:44 | 000,000,034 | —- | M] () – C:\Users\neil\jagex_runescape_preferences.dat
[2011/02/23 17:19:46 | 000,000,215 | —- | M] () – C:\Users\neil\Desktop\Operation Flashpoint Dragon Rising.url
[2011/02/20 10:20:57 | 000,000,972 | —- | M] () – C:\Users\Public\Desktop\Mumble.lnk
[2011/02/10 16:10:29 | 000,266,808 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/02/07 22:58:42 | 000,000,215 | —- | M] () – C:\Users\neil\Desktop\Battlefield Bad Company 2.url
[2011/02/05 14:51:46 | 003,476,023 | —- | M] () – C:\Users\neil\Desktop\BF2CC_Client_1.4.2446.zip
[2011/02/05 13:54:11 | 010,653,973 | —- | M] (Electronic Arts, Inc ) – C:\Users\neil\Desktop\battlefield_vietnam_incremental_patch_v1.2_to_v1.21.exe
[2011/02/05 13:43:23 | 000,001,165 | —- | M] () – C:\Users\neil\Desktop\FileZilla.lnk
[2011/02/05 13:16:09 | 000,001,165 | —- | M] () – C:\Users\neil\Desktop\FileZilla (2).lnk
[2011/02/03 15:10:01 | 000,002,126 | —- | M] () – C:\Users\neil\Desktop\RuneScape.lnk
[2011/02/03 05:45:07 | 000,219,008 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2011/01/29 15:11:03 | 000,001,956 | —- | M] () – C:\Users\Public\Desktop\Call of Duty® 4 - Modern Warfare™ Multiplayer.lnk
[2011/01/29 13:38:08 | 000,022,328 | —- | M] () – C:\Users\neil\AppData\Roaming\PnkBstrK.sys
[2011/01/29 13:37:39 | 000,000,319 | —- | M] () – C:\Windows\game.ini
[2011/01/29 12:18:17 | 000,000,458 | —- | M] () – C:\Users\neil\Desktop\Local Disk (E) - Shortcut.lnk
[2011/01/29 12:17:58 | 000,001,635 | —- | M] () – C:\Users\neil\Desktop\Notepad.lnk
[2011/01/29 10:52:57 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/01/27 18:07:38 | 000,000,320 | —- | M] () – C:\Users\neil\Desktop\BC2CC.appref-ms
[2011/01/27 17:17:06 | 000,002,094 | —- | M] () – C:\Users\neil\Desktop\DesertCombat.lnk
[2011/01/27 17:14:42 | 000,729,088 | —- | M] (Indigo Rose Corporation) – C:\Windows\iun6002.exe
[2011/01/27 17:08:18 | 000,000,561 | —- | M] () – C:\Windows\eReg.dat
[2011/01/27 17:07:53 | 000,002,036 | —- | M] () – C:\Users\Public\Desktop\Battlefield 1942.lnk

========== Files Created - No Company Name ==========

[2011/02/25 21:41:40 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_SaiKA50A_01005.Wdf
[2011/02/23 17:19:46 | 000,000,215 | —- | C] () – C:\Users\neil\Desktop\Operation Flashpoint Dragon Rising.url
[2011/02/07 22:58:42 | 000,000,215 | —- | C] () – C:\Users\neil\Desktop\Battlefield Bad Company 2.url
[2011/02/05 13:43:23 | 000,001,165 | —- | C] () – C:\Users\neil\Desktop\FileZilla.lnk
[2011/02/05 13:04:00 | 003,476,023 | —- | C] () – C:\Users\neil\Desktop\BF2CC_Client_1.4.2446.zip
[2011/02/03 15:10:45 | 000,000,117 | —- | C] () – C:\Users\neil\jagex_runescape_preferences2.dat
[2011/02/03 15:10:15 | 000,000,034 | —- | C] () – C:\Users\neil\jagex_runescape_preferences.dat
[2011/02/03 15:10:09 | 000,000,024 | —- | C] () – C:\Users\neil\jagexappletviewer.preferences
[2011/02/03 15:06:40 | 000,002,134 | —- | C] () – C:\Users\neil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneScape
[2011/02/03 15:06:40 | 000,002,126 | —- | C] () – C:\Users\neil\Desktop\RuneScape.lnk
[2011/01/29 15:11:03 | 000,001,956 | —- | C] () – C:\Users\Public\Desktop\Call of Duty® 4 - Modern Warfare™ Multiplayer.lnk
[2011/01/29 13:37:39 | 000,000,319 | —- | C] () – C:\Windows\game.ini
[2011/01/29 13:17:45 | 000,001,907 | —- | C] () – C:\Users\neil\Desktop\Call of Duty Modern Warfare 2 - Multiplayer.lnk
[2011/01/29 12:18:17 | 000,000,458 | —- | C] () – C:\Users\neil\Desktop\Local Disk (E) - Shortcut.lnk
[2011/01/29 12:17:37 | 000,011,502 | —- | C] () – C:\Users\neil\Desktop\CoDWaW.ico
[2011/01/29 10:52:57 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/01/27 18:07:38 | 000,000,320 | —- | C] () – C:\Users\neil\Desktop\BC2CC.appref-ms
[2011/01/27 17:17:06 | 000,002,094 | —- | C] () – C:\Users\neil\Desktop\DesertCombat.lnk
[2011/01/27 17:08:18 | 000,000,561 | —- | C] () – C:\Windows\eReg.dat
[2011/01/27 17:07:53 | 000,002,036 | —- | C] () – C:\Users\Public\Desktop\Battlefield 1942.lnk
[2010/12/15 18:13:54 | 000,000,262 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/12/14 17:24:09 | 000,148,480 | —- | C] () – C:\Windows\System32\APOMngr.DLL
[2010/12/14 17:24:09 | 000,073,728 | —- | C] () – C:\Windows\System32\CmdRtr.DLL
[2010/12/14 15:19:19 | 000,138,416 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2010/12/14 15:19:19 | 000,022,328 | —- | C] () – C:\Users\neil\AppData\Roaming\PnkBstrK.sys
[2010/12/14 00:55:42 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini
[2010/05/05 20:37:52 | 000,021,204 | —- | C] () – C:\Windows\System32\instwdm.ini
[2010/05/05 20:37:50 | 000,000,054 | —- | C] () – C:\Windows\System32\ctzapxx.ini
[2010/05/05 19:56:46 | 000,002,560 | —- | C] () – C:\Windows\System32\CtxfiRes.dll
[2010/05/05 19:56:46 | 000,002,560 | —- | C] () – C:\Windows\CTXFIRES.DLL
[2009/07/13 23:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/06 13:47:08 | 000,000,285 | —- | C] () – C:\Windows\System32\kill.ini
[2007/01/18 09:21:38 | 000,041,984 | —- | C] () – C:\Windows\System32\drivers\RecFltr.sys

< End of report >
also from .7 C:\Program Files\PCFix\PCFix.exe probably a variant of Win32/Adware.PCFixCleaner application C:\Users\neil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4JGH1OHD\pcfix-v206-eng[1].exe probably a variant of Win32/Adware.PCFixCleaner application
Thanks for the logs.

Please go here: http://virusscan.jotti.org

  • When the jotti page has finished loading, click the "Browse" button and navigate to the following files and click Submit:

    • C:\Program Files\PCFix\PCFix.exe
      C:\Windows\System32\drivers\RecFltr.sys
  • Copy the results and paste them here
  • Note: You will not be able to upload and scan all files at once. You will have to submit and scan each file separately.
Due to the lack of feedback, this Topic is closed. If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI