This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer running slowly am I infected?

50 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Andrew The Malwarebytes log shows the entry found wasn't fixed, only detected. Did you run the program again and remove it? If not, run Malwarebytes again and choose tro fix it.
Ok I've run mbam again and this time asked it to remove the offending item here's the log…………… Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6283 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19019 08/04/2011 08:44:50 mbam-log-2011-04-08 (08-44-50).txt Scan type: Quick scan Objects scanned: 189926 Time elapsed: 4 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe (Security.Hijack) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Apart from the deletion everything is the same as in my previous post.
Andrew
  • right-click on your taskbar at the bottom and choose Task Manager.
  • click File- New Task (Run).
  • type explorer.exe and click OK.
Andrew

Let's run a quick scan and have a look at some folders.

Run OTL
  • Double click on the icon to run it
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following
/md5start
explorer.exe
winlogon.exe
/md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt

Please post this log.

Thanks

Satchfan
Hi here it is……..

OTL logfile created on: 08/04/2011 14:50:50 - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Administrator
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 238.16 Gb Free Space | 51.13% Space Free | Partition Type: NTFS
Drive E: | 581.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: ANDREW-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Administrator\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Users\Administrator\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcr80.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcp80.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (vsmon) – C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Media Toolbox 6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (Vsdatant) – C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (t3) – C:\Windows\System32\drivers\t3.sys (Creative Technology Ltd.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (MRV6X32P) – C:\Windows\System32\drivers\MRVW13B.sys (Marvell Semiconductor, Inc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/
IE - HKLM\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yahoo!"
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:[removed]
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/02/07 14:47:43 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/02 23:00:33 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/07 12:57:39 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/01/31 23:20:12 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2011/01/31 23:20:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Extensions
[2011/01/31 23:20:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/03/27 13:53:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\bhwd8ppd.default\extensions
[2011/02/06 09:59:22 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) – C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\bhwd8ppd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/04/07 12:57:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/07 12:57:41 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2011/02/07 14:47:43 | 000,000,000 | -H-D | M] (ZoneAlarm Security Engine) – C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
[2011/04/07 12:56:05 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/03 18:47:02 | 000,001,538 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/03 18:47:02 | 000,000,947 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/03 18:47:02 | 000,000,769 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2009/04/07 14:59:38 | 000,000,872 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\Yahooober4735472.gif
[2011/02/16 19:31:31 | 000,000,199 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\Yahooober4735472.src

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | -H– | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [SPIRunE] C:\Windows\System32\SpiRunE.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…NPUplden-gb.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15112/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | -H– | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/06/14 11:44:42 | 000,000,085 | R— | M] () - E:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/08 14:48:14 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{DD0BF8A3-9786-41F9-8924-DD66217F3C2E}
[2011/04/08 14:47:49 | 000,000,000 | —D | C] – C:\Windows\LastGood
[2011/04/07 12:57:39 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/04/07 12:57:39 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/04/07 12:57:39 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/07 12:47:21 | 016,525,088 | —- | C] (Sun Microsystems, Inc.) – C:\Users\Administrator\jre-6u24-windows-i586.exe
[2011/04/07 12:33:39 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{4B14A281-11EB-40D1-B456-A11EECEA2049}
[2011/04/06 20:38:58 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{248239B4-518D-40FD-91A1-9C6B51331548}
[2011/04/06 12:01:06 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/04/06 08:48:17 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/06 08:48:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/06 08:48:14 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/04/06 08:47:46 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\Administrator\mbam-setup-1.50.1.1100.exe
[2011/04/06 08:38:21 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{46150EDD-ADFE-4191-83FB-268566A5C543}
[2011/04/05 20:46:58 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/05 08:54:19 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{F4FCF50E-D051-4604-957E-8C22B1AB346E}
[2011/04/05 08:46:29 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{91ED111D-CD38-4AB4-A4B9-FB05689B2E41}
[2011/04/04 15:34:16 | 000,000,000 | —D | C] – C:\_OTL
[2011/04/04 10:05:23 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Administrator\OTL.exe
[2011/04/04 10:03:10 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{A34D152F-16D7-436E-B4E7-0CE11E0F1EBF}
[2011/04/03 23:21:57 | 000,000,000 | —D | C] – C:\Users\Administrator\tdsskiller
[2011/04/03 18:31:13 | 000,000,000 | R–D | C] – C:\32788R22FWJFW
[2011/04/03 15:35:56 | 001,090,912 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Users\Administrator\avg_remover_stf_x86_2011_1184.exe
[2011/04/03 09:41:06 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{78EB8057-2B37-4E81-A487-74F19944D270}
[2011/04/02 09:39:20 | 000,000,000 | -H-D | C] – C:\Users\Administrator\RK_Quarantine
[2011/04/02 09:29:26 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{805C14E6-AA7B-4D3C-BE40-6F40DCA36B11}
[2011/04/01 11:06:06 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{7A0F5FB6-8BEC-4F9F-944D-DEB0FD832895}
[2011/04/01 10:57:39 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{73813386-9006-4EB5-BD8C-A921C07E10B6}
[2011/03/31 22:15:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{9A1CCCB4-25D3-4CAF-8C6F-30CAB69455C7}
[2011/03/30 21:21:03 | 000,000,000 | -H-D | C] – C:\Program Files\Trend Micro
[2011/03/30 21:21:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/03/23 14:51:05 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/23 14:51:05 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll

========== Files - Modified Within 30 Days ==========

[2011/04/08 14:49:11 | 000,000,900 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/08 14:47:34 | 000,000,896 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/08 14:47:32 | 000,037,685 | —- | M] () – C:\ProgramData\nvModes.001
[2011/04/08 14:47:31 | 000,004,192 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/08 14:47:31 | 000,004,192 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/08 14:47:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/08 14:47:26 | 3220,545,536 | -HS- | M] () – C:\hiberfil.sys
[2011/04/08 12:19:00 | 000,000,938 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3164612162-256102785-1375235700-500UA.job
[2011/04/07 20:31:03 | 000,029,184 | —- | M] () – C:\Users\Administrator\Performance Tests Conclusion
[2011/04/07 17:19:00 | 000,000,886 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3164612162-256102785-1375235700-500Core.job
[2011/04/07 16:48:51 | 000,294,400 | —- | M] () – C:\Users\Administrator\exeHelper.com
[2011/04/07 12:56:03 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/04/07 12:56:03 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/04/07 12:56:03 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/04/07 12:56:03 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/07 12:47:35 | 016,525,088 | —- | M] (Sun Microsystems, Inc.) – C:\Users\Administrator\jre-6u24-windows-i586.exe
[2011/04/07 12:42:07 | 000,001,892 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/04/06 08:48:17 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/06 08:47:53 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Administrator\mbam-setup-1.50.1.1100.exe
[2011/04/04 10:05:25 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Administrator\OTL.exe
[2011/04/03 23:20:11 | 001,263,721 | —- | M] () – C:\Users\Administrator\tdsskiller.zip
[2011/04/03 16:03:40 | 004,310,402 | —- | M] () – C:\Users\Administrator\mytool.exe
[2011/04/03 15:51:19 | 000,037,685 | —- | M] () – C:\ProgramData\nvModes.dat
[2011/04/03 15:35:57 | 001,090,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Users\Administrator\avg_remover_stf_x86_2011_1184.exe
[2011/04/03 09:48:57 | 000,879,081 | —- | M] () – C:\Users\Administrator\SecurityCheck.exe
[2011/04/02 17:14:02 | 001,058,816 | —- | M] () – C:\Users\Administrator\RogueKiller.exe
[2011/04/01 18:26:55 | 341,400,810 | -H– | M] () – C:\Windows\MEMORY.DMP
[2011/03/31 22:21:55 | 001,006,778 | -H– | M] () – C:\Users\Administrator\rkill.com
[2011/03/31 22:20:16 | 001,006,778 | -H– | M] () – C:\Users\Administrator\rkill.exe
[2011/03/31 07:00:17 | 000,070,656 | -H– | M] () – C:\Users\Administrator\English c-w essay 2011 childhood
[2011/03/31 06:59:55 | 000,611,664 | -H– | M] () – C:\Windows\System32\perfh009.dat
[2011/03/31 06:59:55 | 000,109,112 | -H– | M] () – C:\Windows\System32\perfc009.dat
[2011/03/30 21:22:05 | 000,002,539 | -H– | M] () – C:\Users\Administrator\Desktop\HiJackThis.lnk
[2011/03/29 07:04:24 | 000,002,281 | -H– | M] () – C:\Users\Public\Desktop\Safari.lnk
[2011/03/28 16:55:39 | 000,002,231 | -H– | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/03/26 01:20:13 | 000,002,082 | -H– | M] () – C:\Users\Administrator\Desktop\Google Chrome.lnk
[2011/03/26 01:20:13 | 000,002,044 | -H– | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

========== Files Created - No Company Name ==========

[2011/04/07 20:31:03 | 000,029,184 | —- | C] () – C:\Users\Administrator\Performance Tests Conclusion
[2011/04/07 16:48:50 | 000,294,400 | —- | C] () – C:\Users\Administrator\exeHelper.com
[2011/04/07 12:42:07 | 000,001,892 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/04/07 12:42:06 | 000,001,804 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/04/06 08:48:17 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/03 23:20:09 | 001,263,721 | —- | C] () – C:\Users\Administrator\tdsskiller.zip
[2011/04/03 15:58:43 | 004,310,402 | —- | C] () – C:\Users\Administrator\mytool.exe
[2011/04/03 15:30:04 | 000,037,685 | —- | C] () – C:\ProgramData\nvModes.dat
[2011/04/03 15:30:04 | 000,037,685 | —- | C] () – C:\ProgramData\nvModes.001
[2011/04/02 09:38:31 | 001,058,816 | —- | C] () – C:\Users\Administrator\RogueKiller.exe
[2011/04/01 21:21:15 | 3220,545,536 | -HS- | C] () – C:\hiberfil.sys
[2011/03/31 22:21:53 | 001,006,778 | -H– | C] () – C:\Users\Administrator\rkill.com
[2011/03/31 22:17:18 | 001,006,778 | -H– | C] () – C:\Users\Administrator\rkill.exe
[2011/03/31 12:26:10 | 000,879,081 | —- | C] () – C:\Users\Administrator\SecurityCheck.exe
[2011/03/31 07:00:47 | 000,070,656 | -H– | C] () – C:\Users\Administrator\English c-w essay 2011 childhood
[2011/03/30 21:21:03 | 000,002,539 | -H– | C] () – C:\Users\Administrator\Desktop\HiJackThis.lnk
[2010/12/21 13:40:50 | 000,000,527 | -H– | C] () – C:\Windows\eReg.dat
[2010/07/25 18:40:19 | 000,003,584 | -H– | C] () – C:\Users\Administrator\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/14 10:48:32 | 000,000,210 | -H– | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/07/10 11:46:25 | 000,134,044 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2010/05/04 16:00:13 | 000,004,626 | -H– | C] () – C:\Windows\System32\AudioDrv.ini
[2010/05/04 16:00:01 | 000,000,049 | RH– | C] () – C:\Windows\System32\ctzapxx.ini
[2010/05/03 17:01:54 | 000,073,728 | -H– | C] () – C:\Windows\System32\CmdRtr.DLL
[2010/05/03 17:01:53 | 000,148,480 | -H– | C] () – C:\Windows\System32\APOMngr.DLL
[2010/05/03 17:00:04 | 000,004,984 | -H– | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/04/26 11:49:48 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/04/26 11:49:47 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/04/24 16:49:11 | 000,000,376 | -H– | C] () – C:\Windows\ODBC.INI
[2010/04/24 08:38:08 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/04/22 17:23:00 | 000,000,680 | -H– | C] () – C:\Users\Administrator\AppData\Local\d3d9caps.dat
[2009/08/26 05:29:28 | 000,150,016 | -H– | C] () – C:\Windows\System32\OemSpiE.dll
[2009/08/03 15:07:42 | 000,403,816 | -H– | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | -H– | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/15 08:22:48 | 000,032,914 | -H– | C] () – C:\Windows\System32\t3.ini
[2009/01/14 02:47:24 | 000,001,436 | -H– | C] () – C:\Windows\CfgHPSp.ini
[2009/01/14 02:47:24 | 000,001,434 | -H– | C] () – C:\Windows\Cfg05Sp.ini
[2009/01/14 02:47:24 | 000,001,434 | -H– | C] () – C:\Windows\Cfg04Sp.ini
[2009/01/14 02:47:24 | 000,001,091 | -H– | C] () – C:\Windows\Cfg03Sp.ini
[2009/01/14 02:47:24 | 000,001,091 | -H– | C] () – C:\Windows\Cfg02Sp.ini
[2009/01/14 02:47:24 | 000,001,000 | -H– | C] () – C:\Windows\Cfg01Sp.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\CfgHPHp.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\CfgHPDO.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\Cfg05DO.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\Cfg04DO.ini
[2009/01/14 02:47:24 | 000,000,930 | -H– | C] () – C:\Windows\Cfg05Hp.ini
[2009/01/14 02:47:24 | 000,000,930 | -H– | C] () – C:\Windows\Cfg04Hp.ini
[2009/01/14 02:47:24 | 000,000,818 | -H– | C] () – C:\Windows\Cfg01APR.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg03Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg03DO.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg02Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg02DO.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg01Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg01DO.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03DI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02DI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01Mic.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01LI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01DI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPRMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPRLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPFMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPDI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05DI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04DI.ini
[2006/11/02 13:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 000,305,584 | -H– | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 000,611,664 | -H– | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | -H– | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,109,112 | -H– | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | -H– | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:23:21 | 000,215,943 | -H– | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | -H– | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | -H– | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | -H– | C] () – C:\Windows\System32\mlang.dat
[2003/01/07 15:05:08 | 000,002,695 | -H– | C] () – C:\Windows\System32\OUTLPERF.INI
[1997/06/14 01:56:08 | 000,056,832 | -H– | C] () – C:\Windows\System32\iyvu9_32.dll

========== Custom Scans ==========



< MD5 for: EXPLORER.EXE >
[2008/10/29 07:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 07:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/30 04:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/28 03:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/21 03:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 07:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 07:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/21 03:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< End of report >


Thanks
Andrew

I’d like you to check your system files:
• Click on Start, Run and type in, (or copy and paste),:
• Type in sfc /scannow in the command window and press Enter.
• Note the space between the c and the /
• If any files require replacing SFC will replace them. You may be asked to insert your Windows Vista Disk for this process to continue. This can be done with a borrowed Windows Vista disk if you don't have one.
• Be patient because the scan may take some time.
• Allow the scan to run and when completed, reboot the system.
Satchfan
Ok did as you asked - it did not ask for the vista disk and finished without producing a report I rebooted bu t my docs folder still reads empty - ho hum.
Hi Andrew

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :filefind
    *explorer*

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Satchfan
Ok here it is SystemLook 04.09.10 by jpshortstuff Log created at 08:33 on 09/04/2011 by Administrator Administrator - Elevation successful ========== filefind ========== Searching for "*explorer*" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk –ah— 226 bytes [12:55 02/11/2006] [02:42 21/01/2008] 1549862E20C3C97A223A3536BAAA482F C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp –ah— 391734 bytes [20:51 19/07/2010] [20:51 19/07/2010] 38E94CA283FFB93352529596CFC31584 C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk –ah— 943 bytes [16:23 22/04/2010] [10:51 03/05/2010] 99E03F426A70F9A047CAE578AD754D09 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk –ah— 949 bytes [16:23 22/04/2010] [10:51 03/05/2010] 75EAE03FC68688A6DDA5A213DD999F98 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk –ah— 1537 bytes [16:22 22/04/2010] [02:42 21/01/2008] F682BB49AFF0CE008D8F8DF62067AB37 C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk –ah— 979 bytes [16:23 22/04/2010] [10:51 03/05/2010] F5F6285D73AE64E407AC4E7EC51B24EA C:\Users\Administrator\Documents\Documents\My Documents\Rebecca\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp –ah— 68066 bytes [13:26 23/04/2010] [20:06 04/11/2005] 8B1E526FE066AE37556E41FF9F1D23A0 C:\Users\Administrator\Documents\Documents\My Documents\Rebecca\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk –ah— 786 bytes [13:26 23/04/2010] [18:58 02/02/2005] A8733E0972339988E3D5F4DD67EEE39C C:\Users\Administrator\Documents\Documents\My Documents\Rebecca\Start Menu\Programs\Internet Explorer.lnk –ah— 774 bytes [13:27 23/04/2010] [18:58 02/02/2005] 28A160DF7F59566622D00B24245517DD C:\Users\Administrator\Documents\Documents\My Documents\Rebecca\Start Menu\Programs\Accessories\Windows Explorer.lnk –ah— 1494 bytes [13:27 23/04/2010] [18:44 25/01/2007] 41691A5C25060EF598A6C10B1A641A67 C:\Users\Administrator\Documents\Documents\Rebecca\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp –ah— 68066 bytes [13:31 23/04/2010] [20:06 04/11/2005] 8B1E526FE066AE37556E41FF9F1D23A0 C:\Users\Administrator\Documents\Documents\Rebecca\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk –ah— 786 bytes [13:31 23/04/2010] [18:58 02/02/2005] A8733E0972339988E3D5F4DD67EEE39C C:\Users\Administrator\Documents\Documents\Rebecca\Start Menu\Programs\Internet Explorer.lnk –ah— 774 bytes [13:32 23/04/2010] [18:58 02/02/2005] 28A160DF7F59566622D00B24245517DD C:\Users\Administrator\Documents\Documents\Rebecca\Start Menu\Programs\Accessories\Windows Explorer.lnk –ah— 1494 bytes [13:32 23/04/2010] [18:44 25/01/2007] 41691A5C25060EF598A6C10B1A641A67 C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk –ah— 226 bytes [12:55 02/11/2006] [02:42 21/01/2008] 1549862E20C3C97A223A3536BAAA482F C:\Users\Andrew\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk –ah— 943 bytes [18:51 23/04/2010] [19:04 03/05/2010] 05564C9AE9841F4F5A765C37A3A3344A C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk –ah— 949 bytes [18:45 23/04/2010] [19:04 03/05/2010] 2C58BFE3F003A783BA992AC12A02B267 C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk –ah— 1537 bytes [18:45 23/04/2010] [02:42 21/01/2008] F682BB49AFF0CE008D8F8DF62067AB37 C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk –ah— 979 bytes [18:45 23/04/2010] [19:04 03/05/2010] 7D2817F442D73938C2523E41D395D266 C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk –ah— 1537 bytes [12:50 02/11/2006] [02:42 21/01/2008] F682BB49AFF0CE008D8F8DF62067AB37 C:\Users\Public\Desktop\Setup for Microsoft Internet Explorer 4.0.lnk –ah— 505 bytes [16:26 22/05/2010] [16:26 22/05/2010] FBBF461CEA8589CCFCFD92ACE7BED429 C:\Users\Rebecca\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk –ah— 949 bytes [17:44 06/04/2011] [17:44 06/04/2011] 75EAE03FC68688A6DDA5A213DD999F98 C:\Users\Rebecca\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk –ah— 943 bytes [17:59 28/04/2010] [10:51 03/05/2010] 99E03F426A70F9A047CAE578AD754D09 C:\Users\Rebecca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk –ah— 949 bytes [17:59 28/04/2010] [10:51 03/05/2010] 75EAE03FC68688A6DDA5A213DD999F98 C:\Users\Rebecca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk –ah— 1537 bytes [17:58 28/04/2010] [02:42 21/01/2008] F682BB49AFF0CE008D8F8DF62067AB37 C:\Users\Rebecca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk –ah— 979 bytes [17:59 28/04/2010] [10:51 03/05/2010] F5F6285D73AE64E407AC4E7EC51B24EA C:\Users\Rebecca\Desktop\Internet Explorer.lnk –ah— 949 bytes [17:45 31/03/2011] [17:45 31/03/2011] 75EAE03FC68688A6DDA5A213DD999F98 C:\Users\Ruth\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk –ah— 943 bytes [17:30 30/04/2010] [13:56 03/05/2010] 99E03F426A70F9A047CAE578AD754D09 C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk –ah— 949 bytes [17:29 30/04/2010] [13:56 03/05/2010] 75EAE03FC68688A6DDA5A213DD999F98 C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk –ah— 1537 bytes [17:29 30/04/2010] [02:42 21/01/2008] F682BB49AFF0CE008D8F8DF62067AB37 C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk –ah— 979 bytes [17:29 30/04/2010] [13:56 03/05/2010] F5F6285D73AE64E407AC4E7EC51B24EA C:\Windows\explorer.exe –a—- 2926592 bytes [10:49 26/04/2010] [06:27 11/04/2009] D07D4C3038F3578FFCE1C0237F2A1253 C:\Windows\en-US\explorer.exe.mui –a—- 36864 bytes [12:41 02/11/2006] [12:41 02/11/2006] 192DD053B43250E264383CDC3D564A18 C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf –a—- 34614 bytes [10:45 08/04/2011] [10:45 08/04/2011] B9AAE514A93B3576E9BD16EE5F2BB13F C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-Package-MiniLP~31bf3856ad364e35~x86~en-US~8.0.6001.18702.cat –a—- 7591 bytes [08:14 03/05/2010] [21:30 08/03/2009] 4A21A159614B2B44D4C30A900A2A2CC3 C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-Package-MiniLP~31bf3856ad364e35~x86~en-US~8.0.6001.18702.mum –a—- 1638 bytes [08:14 03/05/2010] [21:28 08/03/2009] 6E75BF3C20328D7DA73E76C6FC0AD486 C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-Package-TopLevel~31bf3856ad364e35~x86~~8.0.6001.18702.cat –a—- 7591 bytes [08:14 03/05/2010] [21:30 08/03/2009] 70F19D313EFCC7C164D803B44869EB93 C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-Package-TopLevel~31bf3856ad364e35~x86~~8.0.6001.18702.mum –a—- 2019 bytes [08:14 03/05/2010] [21:28 08/03/2009] FDB03FEF8C2F02DA7EAE7B340EAA4743 C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-Package~31bf3856ad364e35~x86~en-US~8.0.6001.18702.cat –a—- 7591 bytes [08:14 03/05/2010] [21:30 08/03/2009] 2300626EF2D80B0F18CB134CF78528FD C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-Package~31bf3856ad364e35~x86~en-US~8.0.6001.18702.mum –a—- 1377 bytes [08:14 03/05/2010] [21:28 08/03/2009] 3E5F357837BD042B277C9FA1210441EA C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-Package~31bf3856ad364e35~x86~~8.0.6001.18702.cat –a—- 7576 bytes [08:14 03/05/2010] [21:30 08/03/2009] 4FFB939E3D86868CB2EE452868115226 C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-Package~31bf3856ad364e35~x86~~8.0.6001.18702.mum –a—- 1821 bytes [08:14 03/05/2010] [21:25 08/03/2009] EA4CEB8D83EB249DA1748B9BFEB4A307 C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-RTM-Update~31bf3856ad364e35~x86~en-US~8.0.6001.18702.cat –a—- 33737 bytes [08:14 03/05/2010] [21:30 08/03/2009] 64444C0A3E204DA46ECA45AC5646CAF5 C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-RTM-Update~31bf3856ad364e35~x86~en-US~8.0.6001.18702.mum –a—- 14390 bytes [08:14 03/05/2010] [21:28 08/03/2009] 457DC20C14B2F327D19706CD130F5F05 C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-RTM-Update~31bf3856ad364e35~x86~~8.0.6001.18702.cat –a—- 182005 bytes [08:14 03/05/2010] [21:30 08/03/2009] 724DFFD25DEF507202F9AA8F1CBC7040 C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-RTM-Update~31bf3856ad364e35~x86~~8.0.6001.18702.mum –a—- 20416 bytes [08:14 03/05/2010] [21:25 08/03/2009] A60375C12363F712933CD698B65A8FCA C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-SP1-Update~31bf3856ad364e35~x86~~8.0.6001.18702.cat –a—- 8454 bytes [08:14 03/05/2010] [21:30 08/03/2009] 6D8F45B2438833DE6015148A3D5BF8A2 C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-8-SP1-Update~31bf3856ad364e35~x86~~8.0.6001.18702.mum –a—- 2136 bytes [08:14 03/05/2010] [21:25 08/03/2009] F025E9FA9912276034C07CB16880E9E5 C:\Windows\System32\ExplorerFrame.dll –a—- 20992 bytes [10:49 26/04/2010] [06:28 11/04/2009] 61216539E55DDF2F78E421E7EF140650 C:\Windows\System32\networkexplorer.dll –a—- 2226688 bytes [10:49 26/04/2010] [06:28 11/04/2009] 04044BF8E6989BE45FA718C24407CA28 C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-8-Package-MiniLP~31bf3856ad364e35~x86~en-US~8.0.6001.18702.cat —-s– 7591 bytes [08:14 03/05/2010] [21:30 08/03/2009] 4A21A159614B2B44D4C30A900A2A2CC3 C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-8-Package-TopLevel~31bf3856ad364e35~x86~~8.0.6001.18702.cat —-s– 7591 bytes [08:14 03/05/2010] [21:30 08/03/2009] 70F19D313EFCC7C164D803B44869EB93 C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-8-Package~31bf3856ad364e35~x86~en-US~8.0.6001.18702.cat —-s– 7591 bytes [08:14 03/05/2010] [21:30 08/03/2009] 2300626EF2D80B0F18CB134CF78528FD C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-8-Package~31bf3856ad364e35~x86~~8.0.6001.18702.cat —-s– 7576 bytes [08:14 03/05/2010] [21:30 08/03/2009] 4FFB939E3D86868CB2EE452868115226 C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-8-RTM-Update~31bf3856ad364e35~x86~en-US~8.0.6001.18702.cat —-s– 33737 bytes [08:14 03/05/2010] [21:30 08/03/2009] 64444C0A3E204DA46ECA45AC5646CAF5 C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-8-RTM-Update~31bf3856ad364e35~x86~~8.0.6001.18702.cat —-s– 182005 bytes [08:14 03/05/2010] [21:30 08/03/2009] 724DFFD25DEF507202F9AA8F1CBC7040 C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-8-SP1-Update~31bf3856ad364e35~x86~~8.0.6001.18702.cat —-s– 8454 bytes [08:14 03/05/2010] [21:30 08/03/2009] 6D8F45B2438833DE6015148A3D5BF8A2 C:\Windows\System32\en-US\NetworkExplorer.dll.mui –a—- 16384 bytes [12:40 02/11/2006] [12:40 02/11/2006] 0D3C95B3633EC94078981AE8ED3DB95D C:\Windows\System32\licensing\ppdlic\explorer-ppdlic.xrm-ms –a—- 3034 bytes [02:24 21/01/2008] [02:24 21/01/2008] EEEF7B6C4CE548E031D7FCA8A06CC697 C:\Windows\System32\migwiz\dlmanifests\explorer-DL.man –a—- 3219 bytes [12:35 02/11/2006] [12:35 02/11/2006] B9F1FC934E51B456456620B44ECFB661 C:\Windows\System32\migwiz\dlmanifests\Microsoft-Windows-IE-InternetExplorer-DL.man –a—- 12754 bytes [02:23 21/01/2008] [02:23 21/01/2008] B9358283944BD34C6E7FCA3E2595683F C:\Windows\System32\winevt\Logs\Internet Explorer.evtx –ah— 69632 bytes [16:16 22/04/2010] [16:18 22/04/2010] A55FE49683C29388694AF6AC8D49B480 C:\Windows\winsxs\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms –a—- 4920 bytes [10:43 02/11/2006] [08:01 10/02/2011] ACC409415D103A9445FB50DDC4E18ED3 C:\Windows\winsxs\FileMaps\program_files_internet_explorer_en-us_2650c83f8a48b821.cdf-ms –a—- 3180 bytes [12:42 02/11/2006] [08:14 03/05/2010] 817E2632B157B4205351551CAAAEAE34 C:\Windows\winsxs\Manifests\x86_microsoft-windows-e..orkexplorersettings_31bf3856ad364e35_6.0.6000.16386_none_aefe26dcd9f7cec1.man ifest –a—- 3454 bytes [12:33 02/11/2006] [12:33 02/11/2006] 487E899F26A72EDCB5E9BA890C228895 C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20.manifest –a—- 2482 bytes [12:39 02/11/2006] [12:39 02/11/2006] E0EFA8E1D76A52F6D244178AE434994B C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorerframe_31bf3856ad364e35_6.0.6000.16386_none_c046476776e5d606.manifest –a—- 16819 bytes [10:21 02/11/2006] [10:13 02/11/2006] D58B98ED8464C4CFEE3F0E92C558577B C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorerframe_31bf3856ad364e35_6.0.6001.18000_none_c27d096373d0e6da.manifest –a—- 19040 bytes [02:19 21/01/2008] [02:19 21/01/2008] E4B7326DAA1514962E06EA0FC62EEAB0 C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorerframe_31bf3856ad364e35_6.0.6002.18005_none_c468826f70f2b226.manifest ——- 19040 bytes [10:39 26/04/2010] [23:17 10/04/2009] 3946550820CEB75FCB2FC6B83CD4109C C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb.manifest –a—- 129106 bytes [10:21 02/11/2006] [10:05 02/11/2006] D3F0A434F1DE1A5E00C877AD01D9DD74 C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3.manifest ——- 129106 bytes [17:10 22/04/2010] [06:35 29/10/2008] AD31C95424A4D6B137528BB0497080EB C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b.manifest ——- 129106 bytes [17:10 22/04/2010] [04:37 28/10/2008] 8E14832A125753610E088F0E75FE3745 C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf.manifest –a—- 127220 bytes [02:19 21/01/2008] [02:19 21/01/2008] 1CF9DABE51DBED4A31709AB4BCD70083 C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8.manifest ——- 127220 bytes [17:10 22/04/2010] [07:00 29/10/2008] 06C8AECA79994D2E8BBF2E827C93E737 C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1.manifest ——- 127220 bytes [17:10 22/04/2010] [04:16 30/10/2008] 9AB70D9187402BCA8F46C5B1BB104A4B C:\Windows\winsxs\Manifests\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b.manifest ——- 127175 bytes [10:39 26/04/2010] [23:37 10/04/2009] 56B37CBC438267BD2DFC1E5F828CACCB C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_0c6e92a0721fadf0.manifest –a—- 2386 bytes [12:39 02/11/2006] [12:39 02/11/2006] 6D8CAE2413F938613C1701EC156A0010 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.16386_none_3fc98d12c451f0a7.manifest –a—- 87465 bytes [12:33 02/11/2006] [12:33 02/11/2006] AF0C3DF056F15971F4BB815F2FA70F67 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.16772_none_3fd0636ec44d63f6.manifest ——- 87465 bytes [16:26 22/04/2010] [08:37 01/11/2008] EFAED6609F9A9E108BDA1EC2972B3DAA C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.16917_none_40164834c4183551.manifest ——- 87465 bytes [16:53 22/04/2010] [05:20 29/08/2009] FB41B6A811E81F47F0DE76DAFDE352B6 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.20949_none_408173e9dd4c5e75.manifest ——- 87465 bytes [16:26 22/04/2010] [08:37 01/11/2008] CD503D54D7FCF4DE2946B87ACBC76C6D C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6000.21117_none_409fbd21dd36085d.manifest ——- 87465 bytes [16:53 22/04/2010] [05:13 29/08/2009] F8EB79510F1E6BFE45D6B92A8AB51187 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18000_none_42004f0ec13d017b.manifest –a—- 87465 bytes [02:18 21/01/2008] [02:18 21/01/2008] 369450C7488176A496308B5BF2E86689 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18165_none_41c472dec16924fb.manifest ——- 94489 bytes [16:26 22/04/2010] [02:32 04/11/2008] 8076F79CDC1498C42E78FD2AAC8FFBDA C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18320_none_41eab4e8c14d30d2.manifest ——- 94489 bytes [16:53 22/04/2010] [14:17 29/08/2009] C6CEC658D7DD9F53D6CB88FB03267137 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18461_none_41c07768c16cb714.manifest ——- 94489 bytes [17:51 22/06/2010] [08:57 19/04/2010] FF261DB74A09964E4461C50083D4BFAC C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18520_none_41eab8b4c14d2b20.manifest ——- 94489 bytes [09:31 27/10/2010] [17:26 27/08/2010] 0471DDD5CE603FCBF64114226BF3CAD9 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.22299_none_4231a10dda9b7df4.manifest ——- 87465 bytes [16:26 22/04/2010] [03:58 31/10/2008] 3467E7DD19917ADC736031B4419D277B C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.22509_none_4292f60bda5279f0.manifest ——- 87465 bytes [16:53 22/04/2010] [14:11 28/08/2009] E2C349023571BA23C86959B9CA809B42 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.22672_none_42404677da91894d.manifest ——- 87465 bytes [17:51 22/06/2010] [18:01 16/04/2010] BC1ED1D1428BD6E4C3A63CE0B134F7D9 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.22750_none_4253e7a1da831be4.manifest ——- 87465 bytes [09:31 27/10/2010] [16:04 26/08/2010] 4E34F215E6A061B8D2BAC3EEEDBB0F6E C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18005_none_43ebc81abe5eccc7.manifest ——- 87420 bytes [10:39 26/04/2010] [23:36 10/04/2009] 21E58EEE9A65B83C1356E8283FA2AC2E C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18101_none_43e7c8d8be626492.manifest ——- 94489 bytes [16:53 22/04/2010] [14:17 29/08/2009] BE77121A3EB060DE576DA611A3C6E81B C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18179_none_43a41bb4be93f2e1.manifest ——- 87465 bytes [07:30 06/06/2010] [18:59 06/01/2010] 16E5F074AEC89EA3B9E8B092DC1894CF C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18244_none_43bf8becbe801d82.manifest ——- 94489 bytes [17:51 22/06/2010] [08:57 19/04/2010] BFBEFD77F48985DD2CE3F905E56350E3 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18301_none_43e7cca4be625ee0.manifest ——- 87465 bytes [09:31 27/10/2010] [17:01 26/08/2010] 0B5862F027497532AA7EAD6888F0F420 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.22213_none_4468964bd78652fb.manifest ——- 87465 bytes [16:53 22/04/2010] [08:50 29/08/2009] 7833C97208AA3E1C1DADFA24DAE170AF C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.22303_none_4473681dd77e3431.manifest ——- 87465 bytes [07:30 06/06/2010] [19:12 06/01/2010] F929F3F8BE515702A16045AB9A322789 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.22384_none_441de907d7be2d10.manifest ——- 87465 bytes [17:51 22/06/2010] [19:22 16/04/2010] 9BC45613FC2B914D2076139313FA1B08 C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.22475_none_4429bb23d7b5279d.manifest ——- 87465 bytes [09:31 27/10/2010] [17:32 26/08/2010] 6F8E222F4A8E2BFBF3668F440D5FEAD9 C:\Windows\winsxs\Manifests\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590.manifest –a—- 3474 bytes [12:39 02/11/2006] [12:39 02/11/2006] 72ABA2F4CCAC9A5CF92CBD269BFAE3CA C:\Windows\winsxs\Manifests\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1.manifest ——- 3625 bytes [08:13 03/05/2010] [21:28 08/03/2009] 32CFB217AA597DD9BD335BEDD4C1E34F C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16386_none_2d2b3e0d1d136ff5.manifest –a—- 119172 bytes [10:21 02/11/2006] [10:13 02/11/2006] 0AF1436F5F105034F55973007058F554 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.17037_none_2d6231791cea1fc3.manifest ——- 119136 bytes [17:11 22/04/2010] [18:32 09/03/2010] E034D02D0BB729784B7AD22DA7666F31 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21242_none_2ddbfecc361459f2.manifest ——- 119136 bytes [17:11 22/04/2010] [18:14 09/03/2010] 7DC0D6079956849300B022C28C256FA2 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9.manifest –a—- 119246 bytes [02:18 21/01/2008] [02:18 21/01/2008] 87BE47E8419FE26BF3ED9E55D72FA854 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18444_none_2f3ac9191a1b4a85.manifest ——- 119272 bytes [17:11 22/04/2010] [18:32 09/03/2010] F0B8DDE6DFC37EDB5021CEB9398AF97C C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22653_none_2fb897943341ea10.manifest ——- 119272 bytes [17:11 22/04/2010] [18:42 11/03/2010] 7743F8AB371989927C0B3160113B6807 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15.manifest ——- 119230 bytes [10:39 26/04/2010] [23:36 10/04/2009] 9939CF9A7C8CA884F1F5D2EA5BF4EA18 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126.manifest ——- 131505 bytes [08:13 03/05/2010] [21:26 08/03/2009] 4478FD81816737653045C753B7102430 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18904_none_124f26c32fc81e22.manifest ——- 134730 bytes [08:15 03/05/2010] [07:03 23/02/2010] 8FB7DD26EEA78C8ACDD8AFA0979AE307 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60.manifest ——- 134730 bytes [13:41 10/06/2010] [06:25 04/05/2010] 1E0345025A8B8520E2FBC18503AC303D C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f.manifest ——- 134730 bytes [11:40 12/08/2010] [06:36 26/06/2010] FC0A186FFB59101C3FCF45C6585A46A4 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18975_none_120477992ffffb10.manifest ——- 134730 bytes [06:38 13/10/2010] [06:26 08/09/2010] 192D067D9FBAC107BF9C6F667844F512 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18999_none_11f2d8e9300c984e.manifest ——- 134730 bytes [09:44 15/12/2010] [06:26 02/11/2010] 4A384B462EF22C39B551383DEB3BD8DE C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08.manifest ——- 134730 bytes [12:57 09/02/2011] [06:55 18/12/2010] 7688C18D86BE818A09DBED097B670DE8 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22995_none_127872a6492dd595.manifest ——- 134730 bytes [08:15 03/05/2010] [15:29 23/02/2010] 43CCBFA005DBFB53EA1EB673BEBA1201 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab.manifest ——- 134730 bytes [13:41 10/06/2010] [07:07 04/05/2010] 82812CAA13CB0C724E9D5DFACC181730 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f.manifest ——- 134730 bytes [11:40 12/08/2010] [07:22 26/06/2010] C05A90C687C2A378B2BE7D6CCBD0D4A8 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23067_none_129abb204913e7b2.manifest ——- 134730 bytes [06:38 13/10/2010] [06:58 08/09/2010] 1B8F94502D708CB80E2050E17EF3936B C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23091_none_127449a04931a37b.manifest ——- 134730 bytes [09:44 15/12/2010] [07:46 02/11/2010] 3C2AAF0A900D358A49DE5A418B97E657 C:\Windows\winsxs\Manifests\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a.manifest ——- 134730 bytes [12:57 09/02/2011] [07:41 18/12/2010] C9C756C9595A4EEBADB86755776C5A82 C:\Windows\winsxs\Manifests\x86_microsoft-windows-interface-explorer_31bf3856ad364e35_6.0.6000.16386_none_9353562d8ea992d1.manifest –a—- 1218 bytes [10:21 02/11/2006] [10:03 02/11/2006] 2FBFA70F1918231946306AAF59DE4845 C:\Windows\winsxs\Manifests\x86_microsoft-windows-n..kexplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_859c40b32ad08ecc.manifest –a—- 4289 bytes [12:39 02/11/2006] [12:39 02/11/2006] D99F781B6A15AB1630329C4517BBD88F C:\Windows\winsxs\Manifests\x86_microsoft-windows-networkexplorer_31bf3856ad364e35_6.0.6000.16386_none_3e1b9f1648f54ac5.manifest –a—- 28103 bytes [10:20 02/11/2006] [10:18 02/11/2006] A56500CD09C8FC545B7457117557E30E C:\Windows\winsxs\Manifests\x86_microsoft-windows-networkexplorer_31bf3856ad364e35_6.0.6001.18000_none_4052611245e05b99.manifest –a—- 27760 bytes [02:19 21/01/2008] [02:19 21/01/2008] B1A39B316EBCA62B62898DE0DD9E6939 C:\Windows\winsxs\Manifests\x86_microsoft-windows-networkexplorer_31bf3856ad364e35_6.0.6002.18005_none_423dda1e430226e5.manifest ——- 27760 bytes [10:39 26/04/2010] [23:19 10/04/2009] 0BEBAB451421B2016C40A4E954CD0549 C:\Windows\winsxs\Manifests\x86_microsoft-windows-shell-internetexplorer_31bf3856ad364e35_6.0.6000.16386_none_821a29a454ed2dc9.manifest –a—- 1373 bytes [10:21 02/11/2006] [10:03 02/11/2006] E3A4E86501962B42C994BED1D27000F2 C:\Windows\winsxs\Temp\PendingRenames\7a092c460af6cb018f0f0000e80c180b.program_files_internet_explorer_a421d1bfaf 856e2b.cdf-ms –a—- 4920 bytes [16:30 08/04/2011] [16:30 08/04/2011] D492C849126D4F404BA7B3F423DCC4CA C:\Windows\winsxs\Temp\PendingRenames\da6a2e460af6cb01900f0000e80c180b.program_files_internet_explorer_en-us_2650c83f8a48b821.cdf-ms –a—- 3180 bytes [16:30 08/04/2011] [16:30 08/04/2011] 2CC44FA719136A78D5227787280775FA C:\Windows\winsxs\Temp\PendingRenames\fa38d24a0af6cb0110100000e80c180b.program_files_internet_explorer_a421d1bfaf 856e2b.cdf-ms –a—- 4920 bytes [16:30 08/04/2011] [16:30 08/04/2011] 24A904D37CD671483A44C00030AD9AE8 C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui –a—- 36864 bytes [12:41 02/11/2006] [12:41 02/11/2006] 192DD053B43250E264383CDC3D564A18 C:\Windows\winsxs\x86_microsoft-windows-explorerframe_31bf3856ad364e35_6.0.6001.18000_none_c27d096373d0e6da\ExplorerFrame.dll –a—- 20992 bytes [02:24 21/01/2008] [02:24 21/01/2008] B43DC259D9D66075D0E1BCB8A235CBBD C:\Windows\winsxs\x86_microsoft-windows-explorerframe_31bf3856ad364e35_6.0.6002.18005_none_c468826f70f2b226\ExplorerFrame.dll –a—- 20992 bytes [10:49 26/04/2010] [06:28 11/04/2009] 61216539E55DDF2F78E421E7EF140650 C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer-ppdlic.xrm-ms –a—- 3005 bytes [17:42 22/04/2010] [05:54 29/10/2008] DB298113997EEA568E4FDF0708BE0A37 C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe –a—- 2923520 bytes [17:42 22/04/2010] [06:20 29/10/2008] 37440D09DEAE0B672A04DCCF7ABF06BE C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer-ppdlic.xrm-ms –a—- 3005 bytes [17:42 22/04/2010] [04:02 28/10/2008] E14B8E99FEA98895CB719D2EAA78C03B C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe –a—- 2923520 bytes [17:42 22/04/2010] [02:15 28/10/2008] E7156B0B74762D9DE0E66BDCDE06E5FB C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer-ppdlic.xrm-ms –a—- 3034 bytes [02:24 21/01/2008] [02:24 21/01/2008] EEEF7B6C4CE548E031D7FCA8A06CC697 C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe –a—- 2927104 bytes [02:24 21/01/2008] [02:24 21/01/2008] FFA764631CB70A30065C12EF8E174F9F C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer-ppdlic.xrm-ms –a—- 3034 bytes [17:42 22/04/2010] [06:00 29/10/2008] 60030670E554B1B0819541540757C7F0 C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe –a—- 2927104 bytes [17:42 22/04/2010] [06:29 29/10/2008] 4F554999D7D5F05DAAEBBA7B5BA1089D C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer-ppdlic.xrm-ms –a—- 3034 bytes [17:42 22/04/2010] [03:38 30/10/2008] 767DBD68E5CEDC0E7A40C8947559D0E8 C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe –a—- 2927616 bytes [17:42 22/04/2010] [03:59 30/10/2008] 50BA5850147410CDE89C523AD3BC606E C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer-ppdlic.xrm-ms –a—- 3034 bytes [02:24 21/01/2008] [02:24 21/01/2008] EEEF7B6C4CE548E031D7FCA8A06CC697 C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe –a—- 2926592 bytes [10:49 26/04/2010] [06:27 11/04/2009] D07D4C3038F3578FFCE1C0237F2A1253 C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.0.6001.18000_none_0278b57e8399bfdb\explorer-DL.man –a—- 3219 bytes [12:35 02/11/2006] [12:35 02/11/2006] B9F1FC934E51B456456620B44ECFB661 C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.0.6001.18000_none_0278b57e8399bfdb\Microsoft-Windows-IE-InternetExplorer-DL.man –a—- 12754 bytes [02:23 21/01/2008] [02:23 21/01/2008] B9358283944BD34C6E7FCA3E2595683F C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.0.6002.18005_none_04642e8a80bb8b27\explorer-DL.man –a—- 3219 bytes [12:35 02/11/2006] [12:35 02/11/2006] B9F1FC934E51B456456620B44ECFB661 C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.0.6002.18005_none_04642e8a80bb8b27\Microsoft-Windows-IE-InternetExplorer-DL.man –a—- 12754 bytes [02:23 21/01/2008] [02:23 21/01/2008] B9358283944BD34C6E7FCA3E2595683F C:\Windows\winsxs\x86_microsoft-windows-n..kexplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_859c40b32ad08ecc\NetworkExplorer.dll.mui –a—- 16384 bytes [12:40 02/11/2006] [12:40 02/11/2006] 0D3C95B3633EC94078981AE8ED3DB95D C:\Windows\winsxs\x86_microsoft-windows-networkexplorer_31bf3856ad364e35_6.0.6001.18000_none_4052611245e05b99\networkexplorer.dll –a—- 2226688 bytes [02:24 21/01/2008] [02:24 21/01/2008] E3C52CD56F4CB2D9736C75EFAA62A07F C:\Windows\winsxs\x86_microsoft-windows-networkexplorer_31bf3856ad364e35_6.0.6002.18005_none_423dda1e430226e5\networkexplorer.dll –a—- 2226688 bytes [10:49 26/04/2010] [06:28 11/04/2009] 04044BF8E6989BE45FA718C24407CA28 -= EOF =-
Andrew

If you have re-installed AVG, you will have to follow the previous steps to uninstall and remove remnants. The antivirus may affect the running of the tool we will be using.

If you have not re-installed it, do the following:

Run OTL
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    
    :Files
    c:\program files\avg
    C:\Users\Administrator\avg_remover_stf_x86_2011_1184.exe
    
    :Commands
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)

Run ComboFix

Delete the version of ComboFix you have on your desktop and download a new one from one of the following locations:

Link1
Link2
Link3

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Close any open browser windows
  • Double click on combofix.exe and follow the prompts.
When finished, it will produce a report for you.

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall

Satchfan
Whose the Daddy of restoring computers then!!!!!!

I have no idea what it did but running combo fix returned all the missing desktop short cuts all my files one happy bunny here good job man!
OTL LOg to follow


ComboFix 11-04-10.01 - Administrator 10/04/2011 20:39:16.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3070.1820 [GMT 1:00]
Running from: c:\users\[removed]\Documents\ComboFix.exe
FW: ZoneAlarm Firewall *Enabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\GamesBar\oberontb.dll
c:\users\Administrator\exeHelper.com
c:\users\Administrator\mytool.exe
c:\users\Administrator\rkill.com
c:\users\Administrator\rkill.exe
c:\users\Administrator\SecurityCheck.exe
c:\users\Administrator\SystemLook.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-03-10 to 2011-04-10 )))))))))))))))))))))))))))))))
.
.
2011-04-10 19:44 . 2011-04-10 19:44 ——– d—–w- c:\users\Ruth\AppData\Local\temp
2011-04-10 19:44 . 2011-04-10 19:44 ——– d—–w- c:\users\Rebecca\AppData\Local\temp
2011-04-10 19:44 . 2011-04-10 19:44 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-04-10 19:44 . 2011-04-10 19:44 ——– d—–w- c:\users\Andrew\AppData\Local\temp
2011-04-10 19:30 . 2011-04-10 19:30 ——– d—–w- c:\windows\LastGood
2011-04-10 08:09 . 2011-03-23 09:11 6792528 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2AAF1842-2FAB-4C2A-B02C-94F1E72328B7}\mpengine.dll
2011-04-10 07:49 . 2011-04-10 07:49 ——– d—–w- c:\users\Administrator\AppData\Local\{4E94AB89-0516-407B-A0E5-2C7A280E0C17}
2011-04-09 16:14 . 2011-04-09 16:14 ——– d—–w- c:\users\Andrew\AppData\Local\Mozilla
2011-04-09 07:30 . 2011-04-09 07:30 ——– d—–w- c:\users\Administrator\AppData\Local\{C734C090-F712-49CF-A452-6527B296B2B4}
2011-04-08 13:48 . 2011-04-08 13:48 ——– d—–w- c:\users\Administrator\AppData\Local\{DD0BF8A3-9786-41F9-8924-DD66217F3C2E}
2011-04-07 11:57 . 2011-04-07 11:56 472808 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-04-07 11:47 . 2011-04-07 11:47 16525088 —-a-w- c:\users\Administrator\jre-6u24-windows-i586.exe
2011-04-07 11:36 . 2011-03-01 08:57 32592 —-a-w- c:\program files\Mozilla Firefox\plugins\np_gp.dll
2011-04-07 11:33 . 2011-04-07 11:33 ——– d—–w- c:\users\Administrator\AppData\Local\{4B14A281-11EB-40D1-B456-A11EECEA2049}
2011-04-06 19:38 . 2011-04-06 19:38 ——– d—–w- c:\users\Administrator\AppData\Local\{248239B4-518D-40FD-91A1-9C6B51331548}
2011-04-06 11:01 . 2011-04-06 11:01 ——– d—–w- c:\program files\ESET
2011-04-06 07:48 . 2010-12-20 17:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-06 07:48 . 2010-12-20 17:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-04-06 07:47 . 2011-04-06 07:47 7734208 —-a-w- c:\users\Administrator\mbam-setup-1.50.1.1100.exe
2011-04-06 07:38 . 2011-04-06 07:38 ——– d—–w- c:\users\Administrator\AppData\Local\{46150EDD-ADFE-4191-83FB-268566A5C543}
2011-04-05 19:46 . 2011-04-07 15:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-04-05 07:54 . 2011-04-05 07:54 ——– d—–w- c:\users\Administrator\AppData\Local\{F4FCF50E-D051-4604-957E-8C22B1AB346E}
2011-04-05 07:46 . 2011-04-05 07:46 ——– d—–w- c:\users\Administrator\AppData\Local\{91ED111D-CD38-4AB4-A4B9-FB05689B2E41}
2011-04-04 14:34 . 2011-04-04 14:34 ——– d—–w- C:\_OTL
2011-04-04 09:05 . 2011-04-04 09:05 580608 —-a-w- c:\users\Administrator\OTL.exe
2011-04-04 09:03 . 2011-04-04 09:03 ——– d—–w- c:\users\Administrator\AppData\Local\{A34D152F-16D7-436E-B4E7-0CE11E0F1EBF}
2011-04-03 22:21 . 2011-04-03 22:21 ——– d—–w- c:\users\Administrator\tdsskiller
2011-04-03 14:35 . 2011-04-03 14:35 1090912 —-a-w- c:\users\Administrator\avg_remover_stf_x86_2011_1184.exe
2011-04-03 08:41 . 2011-04-03 08:41 ——– d—–w- c:\users\Administrator\AppData\Local\{78EB8057-2B37-4E81-A487-74F19944D270}
2011-04-02 08:39 . 2011-04-02 08:39 ——– d–h–w- c:\users\Administrator\RK_Quarantine
2011-04-02 08:38 . 2011-04-02 16:14 1058816 —-a-w- c:\users\Administrator\RogueKiller.exe
2011-04-02 08:29 . 2011-04-02 08:29 ——– d–h–w- c:\users\Administrator\AppData\Local\{805C14E6-AA7B-4D3C-BE40-6F40DCA36B11}
2011-04-01 10:06 . 2011-04-01 10:06 ——– d–h–w- c:\users\Administrator\AppData\Local\{7A0F5FB6-8BEC-4F9F-944D-DEB0FD832895}
2011-04-01 09:57 . 2011-04-01 09:57 ——– d–h–w- c:\users\Administrator\AppData\Local\{73813386-9006-4EB5-BD8C-A921C07E10B6}
2011-03-31 21:15 . 2011-03-31 21:15 ——– d–h–w- c:\users\Administrator\AppData\Local\{9A1CCCB4-25D3-4CAF-8C6F-30CAB69455C7}
2011-03-30 20:21 . 2011-03-30 20:21 388096 —ha-r- c:\users\Administrator\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-30 20:21 . 2011-03-30 20:21 ——– d–h–w- c:\program files\Trend Micro
2011-03-23 13:51 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-23 13:51 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-03-23 13:51 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-07 11:56 . 2010-05-03 16:55 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-03-09 16:10 . 2010-06-24 10:33 18328 —ha-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-02-23 07:27 . 2011-02-23 07:27 941160 —-a-w- c:\windows\system32\nvdispco322090.dll
2011-02-23 07:27 . 2011-02-23 07:27 837736 —-a-w- c:\windows\system32\nvgenco322040.dll
2011-02-23 07:27 . 2011-02-23 07:27 57960 —-a-w- c:\windows\system32\OpenCL.dll
2011-02-23 07:27 . 2011-02-23 07:27 4942952 —-a-w- c:\windows\system32\nvcuda.dll
2011-02-23 07:27 . 2011-02-23 07:27 2895976 —-a-w- c:\windows\system32\nvcuvid.dll
2011-02-23 07:27 . 2011-02-23 07:27 2251368 —-a-w- c:\windows\system32\nvcuvenc.dll
2011-02-23 07:27 . 2011-02-23 07:27 15047272 —-a-w- c:\windows\system32\nvoglv32.dll
2011-02-23 07:27 . 2011-02-23 07:27 13011560 —-a-w- c:\windows\system32\nvcompiler.dll
2011-02-23 07:27 . 2011-02-23 07:27 10920 —-a-w- c:\windows\system32\drivers\nvBridge.kmd
2011-02-23 07:27 . 2011-02-23 07:27 10468360 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-02-23 07:27 . 2010-07-10 04:37 5654120 —-a-w- c:\windows\system32\nvwgf2um.dll
2011-02-23 07:27 . 2010-04-03 21:55 1965672 —-a-w- c:\windows\system32\nvapi.dll
2011-02-23 07:27 . 2010-04-03 21:55 10079336 —-a-w- c:\windows\system32\nvd3dum.dll
2011-02-02 17:11 . 2010-04-22 16:52 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:37 . 2011-02-09 13:03 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:08 . 2011-02-09 13:03 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08 . 2011-02-09 13:03 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08 . 2011-02-09 13:03 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08 . 2011-02-09 13:03 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08 . 2011-02-09 13:03 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07 . 2011-02-09 13:02 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07 . 2011-02-09 13:02 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07 . 2011-02-09 13:03 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06 . 2011-02-09 13:03 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06 . 2011-02-09 13:02 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04 . 2011-02-09 13:03 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04 . 2011-02-09 13:02 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 14:28 . 2011-02-09 13:03 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27 . 2011-02-09 13:03 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26 . 2011-02-09 13:03 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25 . 2011-02-09 13:03 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24 . 2011-02-09 13:03 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15 . 2011-02-09 13:03 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14 . 2011-02-09 13:03 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14 . 2011-02-09 13:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14 . 2011-02-09 13:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12 . 2011-02-09 13:03 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11 . 2011-02-09 13:03 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47 . 2011-02-09 13:03 683008 —-a-w- c:\windows\system32\d2d1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
.
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
2010-05-09 10:50 2517088 —ha-w- c:\program files\ZoneAlarm\tbZone.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
.
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
.
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Google Update"="c:\users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-11-07 136176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2010-09-02 1638400]
"SPIRunE"="SPIRunE.dll" [2009-03-05 18432]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-02-28 180224]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 136176]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-05-03 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-05-03 79360]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2010-05-03 79360]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe [2008-01-21 21504]
R3 vsdatant7;vsdatant7;c:\windows\system32\drivers\vsdatant.win7.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2010-05-26 26352]
S2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2010-05-26 493032]
S3 t3;Sound Blaster X-Fi Xtreme Audio;c:\windows\system32\drivers\t3.sys [2009-05-06 413208]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 12:44]
.
2011-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 12:44]
.
2011-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3164612162-256102785-1375235700-500Core.job
- c:\users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-07 17:14]
.
2011-04-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3164612162-256102785-1375235700-500UA.job
- c:\users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-07 17:14]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\bhwd8ppd.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo!
FF - prefs.js: network.proxy.type - 0
FF - Ext: ZoneAlarm Security Engine: {FFB96CC1-7EB3-449D-B827-DB661701C6BB} - c:\program files\CheckPoint\ZAForceField\TrustChecker
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-10 20:45
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,1b,97,05,e7,27,f2,44,40,8f,c6,9c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,bd,d2,cd,6d,88,63,c1,40,b7,32,a5,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,1b,97,05,e7,27,f2,44,40,8f,c6,9c,\
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.avi"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.CDA"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M3U"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAV"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAX"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdseml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMA"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMD"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMS"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMV"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMZ"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WPL"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WVX"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3164612162-256102785-1375235700-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(652)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'Explorer.exe'(4708)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2011-04-10 20:47:27
ComboFix-quarantined-files.txt 2011-04-10 19:47
.
Pre-Run: 252,654,063,616 bytes free
Post-Run: 255,247,933,440 bytes free
.
- - End Of File - - D838283EFF3FBEB0A8F38FB2084DE61B
otl log ========== SERVICES/DRIVERS ========== ========== OTL ========== ========== FILES ========== File\Folder c:\program files\avg not found. File\Folder C:\Users\Administrator\avg_remover_stf_x86_2011_1184.exe not found. ========== COMMANDS ========== OTL by OldTimer - Version 3.2.22.3 log created on 04102011_210257 The only thing is now the pages are enormous! lol Also will you let me know when I can reinstall AVg or should i go for another? Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI