This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus?

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I am constantly requested to install updates through Windows, even after updating the system on log-off - this is very strange. There is also an inordinate length of time booting-up; 2 or 3 times longer than normal. Another issue is that there seems to be something running in the background, but Task Manager says otherwise. One last slight problem is that maybe 3 times a day the system will say that there is no Internet Connection, and will only connect after I've disconnected the modem and router and re-connected. My question today is, "Is there a virus/worm/script that can fool the system to such an extent as above?" Any help would be greatly appreciated. Thank you. Declan.
:welcome:

Lets run some scans and if nothing bad is detected than i can link you to our windows forum

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.




Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please




Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6448 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 26/04/2011 19:12:07 mbam-log-2011-04-26 (19-12-07).txt Scan type: Quick scan Objects scanned: 147583 Time elapsed: 7 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 19:14:45.53 on 26/04/2011 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_21 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.452 [GMT 1:00] . AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: COMODO Firewall *Enabled* . ============== Running Processes =============== . C:\PROGRA~1\AVG\AVG10\avgchsvx.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe C:\Program Files\AVG\AVG10\avgwdsvc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\Creative\Shared Files\CTDevSrv.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Microsoft LifeCam\MSCamS32.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\fxssvc.exe C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files\AVG\AVG10\avgnsx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\AVG\AVG10\avgrsx.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\Documents and Settings\chic\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.co.uk/ uInternet Settings,ProxyOverride = BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [AdobeBridge] uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe" dRunOnce: [RunNarrator] Narrator.exe uPolicies-explorer: NoResolveTrack = 1 (0x1) mPolicies-explorer: NoResolveTrack = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000 IE: MediaManager tool grab multimedia file - c:\program files\mp3 player utilities 4.00\mediamanager\grab.html IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/E/1/F/E1F6B9B3-49AA-42BB-9115-D9FB57768CC2/wmavax.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL AppInit_DLLs: c:\windows\system32\guard32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\chic\applic~1\mozilla\firefox\profiles\a8kz582u.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=747542&p= FF - plugin: c:\documents and settings\chic\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\mozilla firefox\plugins\npBBCPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll . —- FIREFOX POLICIES —- FF - user.js: browser.cache.memory.capacity - 16000 FF - user.js: browser.chrome.favicons - false FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 4095 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 1000000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 1000000 FF - user.js: dom.disable_window_status_change - true FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 1000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 32464] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 296400] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-6-4 239368] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-6-1 27576] R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-4-22 352144] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-2-15 7421280] R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520] R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2010-6-1 1803224] R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-8-10 55152] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-3-30 134480] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216] R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [2009-9-29 12160] R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [2009-9-29 10496] R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [2009-9-29 12928] R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [2005-6-17 17664] S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\drivers\ntcdrdrv.sys –> c:\windows\system32\drivers\ntcdrdrv.sys [?] S2 Ca536av;5.0M MPEG4 DV Video Capture;c:\windows\system32\drivers\Ca536av.sys [2005-12-19 514155] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-18 136176] S3 ambitucm;Ambit USB Cable Modem NDIS Driver;c:\windows\system32\drivers\ambitucm.sys [2005-11-24 14974] S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [2010-12-7 14336] S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2010-12-7 20736] S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2010-12-7 20096] S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [2010-12-7 25088] S3 AndNetDiag;LG AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys –> c:\windows\system32\drivers\lgandnetdiag.sys [?] S3 AndNetGps;LG AndroidNet USB GPS NMEA Port;c:\windows\system32\drivers\lgandnetgps.sys –> c:\windows\system32\drivers\lgandnetgps.sys [?] S3 ANDNetModem;LG AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys –> c:\windows\system32\drivers\lgandnetmodem.sys [?] S3 andnetndis;LG AndroidNet NDIS Ethernet Adapter;c:\windows\system32\drivers\lgandnetndis.sys –> c:\windows\system32\drivers\lgandnetndis.sys [?] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2007-12-30 16512] S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000] S3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\drivers\DTV_Capture_2X0.sys [2005-12-25 18432] S3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\drivers\DTV_Loader_2X1.sys [2005-12-25 19328] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-4-3 36608] S3 k600bus;Sony Ericsson 600i driver (WDM);c:\windows\system32\drivers\k600bus.sys [2005-5-11 52384] S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;c:\windows\system32\drivers\k600mdfl.sys [2005-5-11 6096] S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;c:\windows\system32\drivers\k600mdm.sys [2005-5-11 87456] S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;c:\windows\system32\drivers\k600mgmt.sys [2005-5-11 79248] S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\k600obex.sys [2005-5-11 77072] S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\manycam.sys –> c:\windows\system32\drivers\ManyCam.sys [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-6-25 35088] S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-4-3 233472] . =============== Created Last 30 ================ . 2011-04-23 17:37:32 ——– d–h–w- C:\$AVG 2011-04-23 16:52:31 ——– d—–w- c:\docume~1\chic\applic~1\AVG10 2011-04-23 16:50:12 ——– d–h–w- c:\docume~1\alluse~1\applic~1\Common Files 2011-04-23 16:47:53 ——– d—–w- c:\windows\system32\drivers\AVG 2011-04-23 16:47:53 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVG10 2011-04-23 16:43:25 ——– d—–w- c:\docume~1\alluse~1\applic~1\MFAData 2011-04-23 05:58:39 ——– d—–w- c:\program files\AVAST Software 2011-04-23 05:58:39 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVAST Software 2011-04-22 15:31:38 ——– d—–w- c:\docume~1\alluse~1\applic~1\Skype Extras 2011-04-13 18:46:54 ——– d—–w- c:\program files\SopCast 2011-04-04 19:13:32 ——– d—–w- c:\program files\SlySoft 2011-03-30 16:17:22 134480 —-a-w- c:\windows\system32\drivers\AVGIDSDriver.sys . ==================== Find3M ==================== . 2011-04-23 05:56:36 285480 —-a-w- c:\windows\system32\guard32.dll 2011-03-07 05:33:50 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:45:07 434176 —-a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:21:11 1857920 —-a-w- c:\windows\system32\win32k.sys 2011-02-17 19:00:29 832512 —-a-w- c:\windows\system32\wininet.dll 2011-02-17 19:00:28 78336 —-a-w- c:\windows\system32\ieencode.dll 2011-02-17 19:00:28 1830912 —-a-w- c:\windows\system32\inetcpl.cpl 2011-02-17 19:00:27 17408 —-a-w- c:\windows\system32\corpol.dll 2011-02-17 12:32:12 5120 —-a-w- c:\windows\system32\xpsp4res.dll 2011-02-17 11:44:16 389120 —-a-w- c:\windows\system32\html.iec 2011-02-15 12:56:39 290432 —-a-w- c:\windows\system32\atmfd.dll 2011-02-11 13:25:52 229888 —-a-w- c:\windows\system32\fxscover.exe 2011-02-09 13:53:52 270848 —-a-w- c:\windows\system32\sbe.dll 2011-02-09 13:53:52 186880 —-a-w- c:\windows\system32\encdec.dll 2011-02-08 13:33:55 978944 —-a-w- c:\windows\system32\mfc42.dll 2011-02-08 13:33:55 974848 —-a-w- c:\windows\system32\mfc42u.dll 2011-02-02 07:58:35 2067456 —-a-w- c:\windows\system32\mstscax.dll 2011-01-27 11:57:06 677888 —-a-w- c:\windows\system32\mstsc.exe . ============= FINISH: 19:17:36.20 ===============

Attachments:

Hi,

I am seeing markers in your log for AVG Antivirus and also comodo internet security, you cant have both, one needs to go, having both of these will suck up system resources and cause all kinds of havoc. Your call but remove one and then run this program

OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTL logfile created on: 27/04/2011 05:38:54 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 448.00 Mb Available Physical Memory | 44.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 113.46 Gb Free Space | 78.12% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 837.60 Gb Free Space | 89.92% Space Free | Partition Type: NTFS

Computer Name: AMANCHIC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (IDriverT) – File not found
SRV - (HidServ) – File not found
SRV - (cmdAgent) – File not found
SRV - (AppMgmt) – File not found
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ANDModem) – C:\WINDOWS\system32\drivers\lgandmodem.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (Andbus) – C:\WINDOWS\system32\drivers\lgandbus.sys (LG Electronics Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (VX1000) – C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (LgBttPort) – C:\WINDOWS\system32\drivers\lgbtport.sys (LG Electronics Inc.)
DRV - (LGVMODEM) – C:\WINDOWS\system32\drivers\lgvmodem.sys (LG Electronics Inc.)
DRV - (lgbusenum) – C:\WINDOWS\system32\drivers\lgbtbus.sys (LG Electronics Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (s716unic) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM) – C:\WINDOWS\system32\drivers\s716unic.sys (MCCI Corporation)
DRV - (s716obex) – C:\WINDOWS\system32\drivers\s716obex.sys (MCCI Corporation)
DRV - (s716nd5) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS) – C:\WINDOWS\system32\drivers\s716nd5.sys (MCCI Corporation)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mgmt) Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s716mgmt.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) Sony Ericsson Device 716 driver (WDM) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (ElbyCDFL) – C:\WINDOWS\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DTV_Loader_2X1) – C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys (WideView Technology Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (k600obex) – C:\WINDOWS\system32\drivers\k600obex.sys (MCCI)
DRV - (k600mgmt) – C:\WINDOWS\system32\drivers\k600mgmt.sys (MCCI)
DRV - (k600mdm) – C:\WINDOWS\system32\drivers\k600mdm.sys (MCCI)
DRV - (k600mdfl) – C:\WINDOWS\system32\drivers\k600mdfl.sys (MCCI)
DRV - (k600bus) Sony Ericsson 600i driver (WDM) – C:\WINDOWS\system32\drivers\k600bus.sys (MCCI)
DRV - (DTV_Capture_2X0) – C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys (Computer & Entertainment, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ca536av) – C:\WINDOWS\system32\drivers\Ca536av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk536.sys (USB BULK)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (usbcm) – C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (ambitucm) – C:\WINDOWS\system32\drivers\ambitucm.sys (Ambit Microsystems Corp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.co.uk/myway
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.co.uk/myway
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/ig"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=747542&p="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"


FF - HKLM\software\mozilla\Firefox\Extensions\\{82081B3D-393D-4389-85A9-8DBBF6AB896B}: C:\Documents and Settings\chic\Local Settings\Application Data\{82081B3D-393D-4389-85A9-8DBBF6AB896B}
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/04/23 17:49:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/27 14:07:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/27 14:07:03 | 000,000,000 | —D | M]

[2008/12/20 16:53:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Extensions
[2011/04/15 20:36:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Nagra3 Community Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{04666517-d7b9-43c9-b329-cd7a30ff0079}(2)
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
[2011/03/12 09:11:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/01/22 21:07:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions
[2007/07/01 12:49:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2007/01/11 07:37:51 | 000,000,000 | —D | M] (TV Guide UK Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{98cb2cc5-46e6-4622-aa41-ce2f64fbfcff}
[2007/04/03 20:21:22 | 000,000,000 | —D | M] (StumbleUpon) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions
[2011/01/22 21:07:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2009/04/11 15:17:33 | 000,000,681 | —- | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\ask.xml
[2011/03/27 14:07:07 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/23 19:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/08/13 00:45:50 | 000,000,000 | —D | M] (Search Settings Plugin) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
[2011/04/23 17:49:46 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2010/07/23 19:19:21 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/18 18:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/02/27 17:57:38 | 000,106,496 | —- | M] (British Broadcasting Corporation) – C:\Program Files\Mozilla Firefox\plugins\npBBCPlugin.dll
[2010/07/23 19:19:21 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/24 20:10:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2010/07/22 21:33:13 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\..\Toolbar\ShellBrowser: (Stumble&Upon) - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1927.dll (StumbleUpon.com)
O4 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006..\Run: [AdobeBridge] File not found
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/E/1…8CC2/wmavax.CAB (Reg Error: Value error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/02/04 18:05:36 | 000,000,000 | RH-D | M] - G:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 13:56:50 | 000,000,036 | RH– | M] () - G:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{47ec6900-36ae-11e0-a921-00123fb247c6}\Shell\AutoRun\command - "" = G:\RunClubSanDisk.exe
O33 - MountPoints2\{612bcee4-2990-11dc-acc8-000e9bea7207}\Shell\AutoRun\command - "" = J:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/27 05:37:31 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/04/26 22:14:01 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Local Settings\Application Data\uTorrent
[2011/04/26 19:00:06 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\chic\Desktop\ATF-Cleaner.exe
[2011/04/23 18:37:32 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/04/23 17:52:31 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/23 17:50:12 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/23 17:49:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011
[2011/04/23 17:47:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/04/23 17:47:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/04/23 17:43:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/23 06:58:39 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/04/23 06:58:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/22 16:31:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype Extras
[2011/04/22 16:31:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/04/22 16:31:13 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/04/22 12:02:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare 4
[2011/04/13 19:46:54 | 000,000,000 | —D | C] – C:\Program Files\SopCast
[2011/04/04 20:48:57 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\My Documents\karaoke
[2011/04/04 20:13:32 | 000,000,000 | —D | C] – C:\Program Files\SlySoft
[2011/04/04 20:13:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SlySoft
[2011/03/30 17:17:22 | 000,134,480 | —- | C] (AVG Technologies CZ, s.r.o. ) – C:\WINDOWS\System32\drivers\AVGIDSDriver.sys
[2008/07/24 20:38:14 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\chic\Application Data\pcouffin.sys
[2005/11/17 20:46:48 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll

========== Files - Modified Within 30 Days ==========

[2011/04/27 05:37:22 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/04/27 05:29:01 | 000,000,972 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
[2011/04/27 05:17:42 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/27 05:17:14 | 000,000,310 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/04/27 05:17:08 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/27 05:16:41 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/27 05:16:38 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2011/04/27 05:16:13 | 000,000,272 | —- | M] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/27 05:12:01 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/26 22:14:40 | 000,000,630 | —- | M] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2011/04/26 18:59:40 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\chic\Desktop\ATF-Cleaner.exe
[2011/04/26 18:15:19 | 113,434,779 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/04/25 08:29:02 | 000,000,920 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
[2011/04/25 02:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
[2011/04/24 07:31:20 | 000,000,741 | —- | M] () – C:\Documents and Settings\chic\Desktop\Glary Utilities.lnk
[2011/04/23 22:20:09 | 000,002,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Celtic Football Coach.lnk
[2011/04/23 17:49:51 | 000,000,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/04/23 17:34:33 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/04/23 06:56:36 | 000,285,480 | —- | M] (COMODO) – C:\WINDOWS\System32\guard32.dll
[2011/04/23 06:56:35 | 000,239,368 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmdGuard.sys
[2011/04/23 06:56:35 | 000,027,576 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmdhlp.sys
[2011/04/23 06:56:35 | 000,015,592 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmderd.sys
[2011/04/22 16:54:21 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/22 12:02:23 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4 Beta.lnk
[2011/04/20 08:21:02 | 000,120,832 | —- | M] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/16 15:29:13 | 000,006,705 | —- | M] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/04/14 06:44:23 | 003,775,584 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/05 20:42:56 | 000,340,404 | —- | M] () – C:\Documents and Settings\chic\Desktop\bmx stuff (pinkbike).xcf
[2011/04/04 20:46:47 | 000,000,041 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/04/04 20:13:38 | 000,000,766 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CloneCD.lnk
[2011/03/30 17:17:22 | 000,134,480 | —- | M] (AVG Technologies CZ, s.r.o. ) – C:\WINDOWS\System32\drivers\AVGIDSDriver.sys

========== Files Created - No Company Name ==========

[2011/04/27 05:16:13 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/26 22:14:40 | 000,000,630 | —- | C] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2011/04/26 18:15:19 | 113,434,779 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/04/23 17:49:51 | 000,000,690 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/04/22 16:31:15 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/22 12:02:23 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4 Beta.lnk
[2011/04/16 15:29:13 | 000,006,705 | —- | C] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/04/05 20:42:56 | 000,340,404 | —- | C] () – C:\Documents and Settings\chic\Desktop\bmx stuff (pinkbike).xcf
[2011/04/04 20:46:47 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/04/04 20:13:38 | 000,000,766 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CloneCD.lnk
[2011/02/13 00:19:50 | 002,018,408 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/12 23:17:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2011/01/12 23:17:12 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2010/10/29 20:49:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2010/10/05 00:59:32 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\StarOpen.sys
[2010/06/25 18:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/18 20:02:41 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/04/03 10:41:50 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/04/03 10:41:50 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/04/03 10:41:37 | 000,002,528 | —- | C] () – C:\Documents and Settings\chic\Application Data\$_hpcst$.hpc
[2010/03/26 21:46:21 | 000,000,108 | —- | C] () – C:\Documents and Settings\chic\Application Data\default.pls
[2010/02/12 18:01:25 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/31 22:59:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2010/01/31 22:59:11 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2009/11/19 21:29:03 | 000,015,498 | —- | C] () – C:\WINDOWS\VX1000.ini
[2009/09/27 21:58:46 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/09/26 22:30:54 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/09/09 07:17:00 | 000,017,510 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/06/19 20:18:06 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/05/13 08:05:19 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/03/24 20:49:18 | 000,000,007 | —- | C] () – C:\WINDOWS\sbacknt.bin
[2008/11/14 12:31:34 | 000,000,168 | —- | C] () – C:\WINDOWS\netg.ini
[2008/11/14 12:31:34 | 000,000,093 | —- | C] () – C:\WINDOWS\skillv.ini
[2008/10/25 21:37:33 | 000,048,396 | —- | C] () – C:\WINDOWS\UninstVeetleTVPlayer.exe
[2008/07/24 20:39:10 | 000,081,920 | —- | C] () – C:\Documents and Settings\chic\Application Data\ezpinst.exe
[2008/07/24 20:38:14 | 000,007,176 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.cat
[2008/07/24 20:38:10 | 000,001,144 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.inf
[2008/06/23 19:12:12 | 000,000,065 | —- | C] () – C:\WINDOWS\FISHUI.INI
[2008/03/05 21:23:28 | 000,002,104 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/05 21:23:26 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/02/03 10:38:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/12/08 20:23:23 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNWISE.EXE
[2007/07/11 22:06:05 | 000,000,127 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\fusioncache.dat
[2007/06/14 19:54:54 | 000,044,440 | —- | C] () – C:\WINDOWS\System32\MtpAccess.dll
[2007/06/14 18:59:33 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\LAME_MP3.dll
[2007/06/14 18:59:19 | 000,065,024 | —- | C] () – C:\WINDOWS\IFinst26.exe
[2007/05/12 00:19:17 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/03/01 00:39:47 | 000,000,120 | —- | C] () – C:\WINDOWS\PbkUser.INI
[2007/02/05 15:24:28 | 000,018,271 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2007/02/05 15:24:26 | 000,099,999 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/01/24 23:12:53 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/01/24 23:12:40 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/01/03 12:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 23:59:04 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/10/26 21:09:34 | 000,036,864 | —- | C] () – C:\WINDOWS\uneng.exe
[2006/10/08 20:09:58 | 000,000,072 | —- | C] () – C:\WINDOWS\MediaManager.INI
[2006/07/19 20:26:15 | 000,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2006/05/22 10:26:06 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2006/04/16 20:23:19 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/03/05 14:21:03 | 000,099,840 | —- | C] () – C:\WINDOWS\System32\UnCasino5.exe
[2006/01/15 20:30:10 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/12/19 19:14:11 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2005/12/04 00:14:05 | 000,001,771 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/25 07:14:32 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/24 23:45:56 | 000,120,832 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/11/24 23:04:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/11/24 22:44:58 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2005/11/17 21:23:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/17 21:17:33 | 000,099,965 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2005/11/17 21:17:32 | 000,005,485 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/11/17 21:16:40 | 000,000,777 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/17 21:13:29 | 000,000,484 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/17 21:10:11 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/11/17 21:09:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2005/11/17 21:09:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2005/11/17 21:09:30 | 000,000,072 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2005/11/17 20:47:14 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlcdserv.dll
[2005/11/17 20:47:14 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlcdusb1.dll
[2005/11/17 20:47:14 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlcdpmui.dll
[2005/11/17 20:47:14 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcdlmpm.dll
[2005/11/17 20:47:14 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlcdutil.dll
[2005/11/17 20:47:14 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdprox.dll
[2005/11/17 20:47:14 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlcdjswr.dll
[2005/11/17 20:47:14 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlcdpplc.dll
[2005/11/17 20:47:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlcdinsr.dll
[2005/11/17 20:47:14 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlcdvs.dll
[2005/11/17 20:47:14 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcdcur.dll
[2005/11/17 20:47:12 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcdhbn3.dll
[2005/11/17 20:47:12 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcdcomc.dll
[2005/11/17 20:47:12 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcdcoms.exe
[2005/11/17 20:47:12 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcdcomm.dll
[2005/11/17 20:47:12 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlcdih.exe
[2005/11/17 20:47:12 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.exe
[2005/11/17 20:47:12 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlcdinsb.dll
[2005/11/17 20:47:12 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdins.dll
[2005/11/17 20:47:12 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcdcub.dll
[2005/11/17 20:47:12 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcdcu.dll
[2005/11/17 20:47:12 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.dll
[2005/11/17 20:46:48 | 000,060,928 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2005/11/17 20:46:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2005/11/17 20:46:38 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/11/17 20:46:34 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/11/17 20:46:16 | 000,000,402 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/02 18:05:54 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlcdplc.ini
[2004/09/22 20:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 003,775,584 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,486,540 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,088,424 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/05/12 14:01:12 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\qhtm.dll
[2004/02/21 04:31:10 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\ccvidcl.dll
[2003/06/11 19:39:44 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2002/03/05 19:30:00 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll

========== LOP Check ==========

[2010/09/17 09:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aiseesoft Studio
[2007/02/25 10:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2011/04/23 17:34:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/23 17:51:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2007/05/27 21:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/04/23 17:50:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/31 09:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/02/01 19:59:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/01/18 07:18:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2008/01/21 07:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2011/04/23 17:52:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2008/07/26 09:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2006/12/30 23:53:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/03/19 12:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2007/06/10 11:04:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\starters orders 3
[2011/04/17 19:07:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/28 21:48:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2007/07/01 20:55:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/12/25 23:57:47 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{615DB4DC-B7C1-4125-9858-78EF460B76D2}
[2009/04/22 22:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/12/25 23:56:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{9BA38AC8-8A1E-463A-97ED-AE291D3E1A06}
[2006/09/16 20:11:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Acoustica
[2010/12/09 12:21:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo
[2007/06/07 22:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo Photo Commander 4
[2009/05/27 14:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Astro Gemini Software
[2011/04/23 17:52:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/22 13:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Azureus
[2011/04/22 13:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\BitTorrent
[2010/05/04 13:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Bump Technologies, Inc
[2009/08/28 23:13:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CBS Interactive
[2007/12/06 19:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CheckPoint
[2009/06/09 13:42:50 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Chessmaster Challenge
[2007/02/02 22:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ConvertTemp
[2009/12/31 09:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DAEMON Tools Pro
[2007/06/14 19:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DataCast
[2009/11/25 19:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\eMusic
[2010/07/25 20:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Foxit Software
[2009/12/06 12:50:41 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\FreeVideoConverter
[2007/09/23 21:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\funkitron
[2009/06/09 13:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\GlarySoft
[2011/04/16 15:29:13 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\gtk-2.0
[2009/05/14 12:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Hrsim
[2011/04/22 12:02:09 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\IObit
[2007/07/15 12:35:44 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\iWin
[2005/11/30 21:19:26 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Leadertech
[2008/08/09 15:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\LimeWire
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ManyCam
[2009/09/02 21:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Moyea
[2009/08/16 22:53:06 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\MP3Rocket
[2010/12/02 20:19:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\NCH Swift Sound
[2008/01/18 22:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Opera
[2010/04/03 13:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PC Suite
[2011/02/26 15:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Philipp Winterberg
[2007/07/15 14:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PPMate
[2010/06/26 07:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Recordpad
[2010/05/27 22:33:34 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Samsung
[2010/02/07 19:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Search Settings
[2011/02/13 00:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Sports Interactive
[2010/12/31 21:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Spotify
[2007/07/06 05:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\StumbleUpon
[2009/09/02 21:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Teleca
[2009/10/24 00:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Temporary
[2007/07/19 20:12:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\TransRender
[2011/04/26 22:40:56 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\uTorrent
[2009/03/24 21:02:57 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\vghd
[2009/07/27 19:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Vso
[2008/01/26 11:55:03 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Windows Desktop Search
[2009/12/06 12:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Xilisoft Corporation
[2010/08/02 20:24:56 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressripDowngrade.job
[2010/08/02 20:24:57 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressripShakeIcon.job
[2011/04/27 05:17:14 | 000,000,310 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Top 60 albums - November 2005.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\itunes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Cyberlink:Roxio EMC Stream
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:453B2FDD421AAE3E

< End of report >
OTL Extras logfile created on: 27/04/2011 05:38:55 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 448.00 Mb Available Physical Memory | 44.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 113.46 Gb Free Space | 78.12% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 837.60 Gb Free Space | 89.92% Space Free | Partition Type: NTFS

Computer Name: AMANCHIC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – Reg Error: Value error.
Directory [Winamp.Enqueue] – Reg Error: Value error.
Directory [Winamp.Play] – Reg Error: Value error.
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"135:TCP" = 135:TCP:*:Enabled:TCP Port 135
"5000:TCP" = 5000:TCP:*:Enabled:TCP Port 5000
"5001:TCP" = 5001:TCP:*:Enabled:TCP Port 5001
"5002:TCP" = 5002:TCP:*:Enabled:TCP Port 5002
"5003:TCP" = 5003:TCP:*:Enabled:TCP Port 5003
"5004:TCP" = 5004:TCP:*:Enabled:TCP Port 5004
"5005:TCP" = 5005:TCP:*:Enabled:TCP Port 5005
"5006:TCP" = 5006:TCP:*:Enabled:TCP Port 5006
"5007:TCP" = 5007:TCP:*:Enabled:TCP Port 5007
"5008:TCP" = 5008:TCP:*:Enabled:TCP Port 5008
"5009:TCP" = 5009:TCP:*:Enabled:TCP Port 5009
"5010:TCP" = 5010:TCP:*:Enabled:TCP Port 5010
"5011:TCP" = 5011:TCP:*:Enabled:TCP Port 5011
"5012:TCP" = 5012:TCP:*:Enabled:TCP Port 5012
"5013:TCP" = 5013:TCP:*:Enabled:TCP Port 5013
"5014:TCP" = 5014:TCP:*:Enabled:TCP Port 5014
"5015:TCP" = 5015:TCP:*:Enabled:TCP Port 5015
"5016:TCP" = 5016:TCP:*:Enabled:TCP Port 5016
"5017:TCP" = 5017:TCP:*:Enabled:TCP Port 5017
"5018:TCP" = 5018:TCP:*:Enabled:TCP Port 5018
"5019:TCP" = 5019:TCP:*:Enabled:TCP Port 5019
"5020:TCP" = 5020:TCP:*:Enabled:TCP Port 5020

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kontiki\KService.exe" = C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service – (Kontiki Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe" = C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeTray.exe" = C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe – (Microsoft Corporation)
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\WINDOWS\system32\dlcdcoms.exe" = C:\WINDOWS\system32\dlcdcoms.exe:*:Enabled:Dell 944 Server – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcdPSWX.EXE" = C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcdPSWX.EXE:*:Enabled:Dell 944 Printer Status – ()
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\BitTorrent\BitTorrent.exe" = C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Documents and Settings\chic\My Documents\Downloads\BitTorrent-7.2.exe" = C:\Documents and Settings\chic\My Documents\Downloads\BitTorrent-7.2.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{0354C0B5-AA35-49D8-B7B7-1CF3412465DD}" = DataCastComponent
"{055A0044-64A6-4248-A026-9745C1E9E159}" = Microsoft Encarta Encyclopedia Standard 2005
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}" = Search Settings 1.2.1
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F549047-2FC2-4D35-A165-8F58268CC73A}" = Celtic Football Coach
"{0F6D55D8-89AA-4C1D-BC4C-ACBBDE8BE57A}" = Serif PhotoPlus 8.0
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1D3C662A-F6C6-4767-A788-7AA43A9A1317}" = ARTEuro
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{39CEE1F2-12B6-4C50-9131-04BFCA110578}" = PowerCinema NE for Everio
"{3F262ADC-5AD2-48E5-A586-44315E04A9E2}" = Microsoft Picture It! Library 10
"{42756145-9997-4D28-809B-8756BFD00106}" = Microsoft Photo Premium 10
"{4442AB48-DEC4-4B39-B067-1F75BF8017E7}" = Creative Centrale
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{461B11E8-BF34-4ACB-962A-1CBE905BD9EB}" = LG United Mobile Drivers
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50AF9AC4-6E62-405A-A269-C02B70A21E64}" = 944plc32
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5FC7AB5C-61FC-42DF-A923-5139BCF10D42}" = Microsoft LifeCam
"{6003F12D-6DAF-4C3F-9FFA-F4A721DC6BBF}" = AVG 2011
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.9
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75AE638F-750A-11DF-96D5-005056806466}" = Google Earth Plug-in
"{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}" = Windows Live Family Safety
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel® PROSet for Wired Connections
"{86604C06-DA30-425E-AECE-47304FE81C45}" = Creative Software Update
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90240409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Resource Kit
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95468B00-C081-4B27-AC96-0A2A31359E60}" = Adobe Flash Player 10 ActiveX
"{95774351-6087-3A3B-8CA8-70BEE49D2BD5}" = Google Gears
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{A7894110-9C15-43EF-89E9-060363290188}" = Samsung PC Studio
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}" = Dell Media Experience
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AC7EE5F1-0DE4-4256-8E43-92B73C8E6019}" = LG Bluetooth Drivers
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}" = Dell Picture Studio v3.0
"{AFC00CDF-E197-41EE-90BE-3E467C0C5527}" = Wireless Camera Setup Utility
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C19BE821-89B1-4A96-AC7C-873810C0CB5F}" = ContentSAFER for Wizmax
"{C3208FCF-EAF5-43EE-972B-812DEA54FC72}_is1" = 1AVCenter version 2.2.7.21
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB54ABA8-D67F-47AD-A76C-2631BADA9FE5}" = Microsoft Works Suite Add-in for Microsoft Word
"{CC6B1BB4-4E06-4A5B-A166-B371B551324B}" = COMODO Internet Security
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB481CC-F57C-4397-81A0-DADD22257047}" = Sound Blaster Live! 24-bit
"{CF9CD37C-E29A-11D5-AE3D-005004B8E30C}" = Digital Photo Navigator 1.5
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D466F3D9-510C-4729-B7D4-2E70490E4CDF}" = BBC iPlayer Download Manager
"{D4E53304-1F6C-4111-9872-1BCD2CF5B642}" = AVG 2011
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E72019B8-1287-4093-BE9B-1CFA7BA1A8D2}" = Windows Desktop Search 3.01
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EDE721EC-870A-11D8-9D75-000129760D75}" = PowerDirector Express
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8650CB3-89F1-4AE0-81AC-917423C58DB8}" = Serif PhotoPlus Association File Formats
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)
"3D Billiard_is1" = 3D Billiards 1.36
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"Advanced SystemCare 4_is1" = Advanced SystemCare 4 Beta 3.0
"Ashampoo Burning Studio 10_is1" = Ashampoo Burning Studio 10.0.7
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE
"ATI Display Driver" = ATI Display Driver
"AVG" = AVG 2011
"BBC iPlayer Download Manager" = BBC iPlayer Download Manager
"BitTorrent" = BitTorrent
"CC Network Video Client" = CC Network Video Client
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"CloneCD" = CloneCD
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Creative Centrale" = Creative Centrale
"Defraggler" = Defraggler (remove only)
"Dell Photo AIO Printer 944" = Dell Photo AIO Printer 944
"DellSupport" = Dell Support 5.0.0 (630)
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"Foxit Reader" = Foxit Reader
"Glary Utilities_is1" = Glary Utilities Pro 2.33.0.1158
"HMV Digital Downloads" = HMV Digital Downloads
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"IEAK5" = Microsoft Internet Explorer Administration Kit 5
"Indeo® software" = Indeo® software
"InstallShield_{0F549047-2FC2-4D35-A165-8F58268CC73A}" = Celtic Football Coach
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"LG PC Suite IV" = LG PC Suite IV
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2005b" = Microsoft Money
"Mozilla Firefox 4.0 (x86 en-US)" = Mozilla Firefox 4.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nikon FotoShare" = Nikon FotoShare
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"PictureItPrem_v10" = Microsoft Photo Premium 10
"PROSet" = Intel® PRO Network Connections Drivers
"RarZilla Free Unrar" = RarZilla Free Unrar
"RealPlayer 6.0" = RealPlayer
"Smart Defrag_is1" = Smart Defrag
"Spotify" = Spotify
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SpywareBlaster_is1" = SpywareBlaster 4.4
"SpywareGuard_is1" = SpywareGuard v2.2
"uTorrent" = µTorrent
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.2
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZENMXUG" = Creative ZEN MX Documentation

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CNET TechTracker" = CNET TechTracker
"f031ef6ac137efc5" = Dell Driver Download Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 21/04/2011 15:21:29 | Computer Name = AMANCHIC | Source = Application Error | ID = 1000
Description = Faulting application football.exe, version 1.0.1.1, faulting module
librarysw.dll, version 0.0.0.0, fault address 0x00002440.

Error - 23/04/2011 17:19:54 | Computer Name = AMANCHIC | Source = Application Error | ID = 1000
Description = Faulting application football.exe, version 1.0.1.1, faulting module
unknown, version 0.0.0.0, fault address 0x245c8a53.

Error - 24/04/2011 02:43:56 | Computer Name = AMANCHIC | Source = Application Error | ID = 1000
Description = Faulting application divx plus player.exe, version 10.2.1.20, faulting
module divx plus player.exe, version 10.2.1.20, fault address 0x0000bac1.

Error - 24/04/2011 03:39:53 | Computer Name = AMANCHIC | Source = MsiInstaller | ID = 11706
Description = Product: HiJackThis – Error 1706. An installation package for the
product HiJackThis cannot be found. Try the installation again using a valid copy
of the installation package 'HiJackThis.msi'.

Error - 25/04/2011 12:49:37 | Computer Name = AMANCHIC | Source = Application Error | ID = 1000
Description = Faulting application divx plus player.exe, version 10.2.1.20, faulting
module qtcore4.dll, version 4.5.0.0, fault address 0x000e1b16.

Error - 27/04/2011 00:12:47 | Computer Name = AMANCHIC | Source = MsiInstaller | ID = 11316
Description = Product: COMODO Internet Security – Error 1316. A network error occurred
while attempting to read from the file: C:\WINDOWS\Installer\CFP_Setup.msi

Error - 27/04/2011 00:13:32 | Computer Name = AMANCHIC | Source = MsiInstaller | ID = 10005
Description = Product: COMODO Internet Security Premium – You must restart your
computer before continuing installation.

Error - 27/04/2011 00:14:37 | Computer Name = AMANCHIC | Source = MsiInstaller | ID = 10005
Description = Product: COMODO Internet Security – You must restart your computer
before continuing installation.

Error - 27/04/2011 00:14:46 | Computer Name = AMANCHIC | Source = MsiInstaller | ID = 10005
Description = Product: COMODO Internet Security – You must restart your computer
before continuing installation.

Error - 27/04/2011 00:18:50 | Computer Name = AMANCHIC | Source = MsiInstaller | ID = 11316
Description = Product: COMODO Internet Security – Error 1316. A network error occurred
while attempting to read from the file: C:\WINDOWS\Installer\CFP_Setup.msi

[ OSession Events ]
Error - 17/11/2008 19:32:11 | Computer Name = AMANCHIC | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 10/04/2009 11:57:43 | Computer Name = AMANCHIC | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 02/05/2009 15:11:19 | Computer Name = AMANCHIC | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 19/06/2009 17:58:10 | Computer Name = AMANCHIC | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

[ System Events ]
Error - 27/04/2011 00:13:06 | Computer Name = AMANCHIC | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/04/2011 00:13:06 | Computer Name = AMANCHIC | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/04/2011 00:13:06 | Computer Name = AMANCHIC | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/04/2011 00:13:06 | Computer Name = AMANCHIC | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/04/2011 00:13:06 | Computer Name = AMANCHIC | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/04/2011 00:13:06 | Computer Name = AMANCHIC | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/04/2011 00:16:59 | Computer Name = AMANCHIC | Source = Service Control Manager | ID = 7000
Description = The COMODO Internet Security Helper Service service failed to start
due to the following error: %%2

Error - 27/04/2011 00:16:59 | Computer Name = AMANCHIC | Source = Service Control Manager | ID = 7000
Description = The 5.0M MPEG4 DV Video Capture service failed to start due to the
following error: %%1058

Error - 27/04/2011 00:16:59 | Computer Name = AMANCHIC | Source = Service Control Manager | ID = 7000
Description = The Cdralw2k service failed to start due to the following error: %%1058

Error - 27/04/2011 00:16:59 | Computer Name = AMANCHIC | Source = Service Control Manager | ID = 7023
Description = The Human Interface Device Access service terminated with the following
error: %%126


< End of report >
Hi,

Fast Browser Search <–We can remove this if you wish, brings you ads

This need to go also, your downloading that file from an unknown source and most contain malware of some sort, doing what I do and knowing what I know about the latest threats I would never allow this on any of my systems. These can be uninstalled via Add Remove Programs in the Control Panel.
µTorrent.
BitTorrent



I am still looking at markers in your log for Avast, AVG and Comodo, I can only advise you but two need to go, if you want to continue, uninstall two and also the File Sharing Programs
I tried to remove Comodo yesterday, both with the Add/Remove Programs and with Glary's Utilities. Both times I received the same error message," A network error occurred while attempting to read from the file C:\windows\Installer\CFP_Setup.msi". How can I go about removing Comodo? I have googled this problem but there is no resolution available, that I can see anyway? I wasn't aware I had Avast on the system; I try various programs to contrast and compare and sometimes traces are left after removal, I think. If you can help with the Comodo I would appreciate it. Declan.
Sorry for the delay, but experienced numerous problems in the Comodo Forum - so uninstalled AVG instead!

I have also uninstalled the torrent files, but not sure how to uninstall the browser you mentioned.

The OTL has been re-run as instructed but only resulted in 1 outcome, which I have posted below.

Thanks for your time.

OTL logfile created on: 29/04/2011 16:47:17 - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 614.00 Mb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 115.55 Gb Free Space | 79.56% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 835.45 Gb Free Space | 89.69% Space Free | Partition Type: NTFS

Computer Name: AMANCHIC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.53\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (IDriverT) – File not found
SRV - (HidServ) – File not found
SRV - (cmdAgent) – File not found
SRV - (AppMgmt) – File not found
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (ANDModem) – C:\WINDOWS\system32\drivers\lgandmodem.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (Andbus) – C:\WINDOWS\system32\drivers\lgandbus.sys (LG Electronics Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (VX1000) – C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (LgBttPort) – C:\WINDOWS\system32\drivers\lgbtport.sys (LG Electronics Inc.)
DRV - (LGVMODEM) – C:\WINDOWS\system32\drivers\lgvmodem.sys (LG Electronics Inc.)
DRV - (lgbusenum) – C:\WINDOWS\system32\drivers\lgbtbus.sys (LG Electronics Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (s716unic) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM) – C:\WINDOWS\system32\drivers\s716unic.sys (MCCI Corporation)
DRV - (s716obex) – C:\WINDOWS\system32\drivers\s716obex.sys (MCCI Corporation)
DRV - (s716nd5) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS) – C:\WINDOWS\system32\drivers\s716nd5.sys (MCCI Corporation)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mgmt) Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s716mgmt.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) Sony Ericsson Device 716 driver (WDM) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (ElbyCDFL) – C:\WINDOWS\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DTV_Loader_2X1) – C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys (WideView Technology Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (k600obex) – C:\WINDOWS\system32\drivers\k600obex.sys (MCCI)
DRV - (k600mgmt) – C:\WINDOWS\system32\drivers\k600mgmt.sys (MCCI)
DRV - (k600mdm) – C:\WINDOWS\system32\drivers\k600mdm.sys (MCCI)
DRV - (k600mdfl) – C:\WINDOWS\system32\drivers\k600mdfl.sys (MCCI)
DRV - (k600bus) Sony Ericsson 600i driver (WDM) – C:\WINDOWS\system32\drivers\k600bus.sys (MCCI)
DRV - (DTV_Capture_2X0) – C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys (Computer & Entertainment, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ca536av) – C:\WINDOWS\system32\drivers\Ca536av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk536.sys (USB BULK)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (usbcm) – C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (ambitucm) – C:\WINDOWS\system32\drivers\ambitucm.sys (Ambit Microsystems Corp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.co.uk/myway
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.co.uk/myway
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/ig"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=747542&p="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"


FF - HKLM\software\mozilla\Firefox\Extensions\\{82081B3D-393D-4389-85A9-8DBBF6AB896B}: C:\Documents and Settings\chic\Local Settings\Application Data\{82081B3D-393D-4389-85A9-8DBBF6AB896B}
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/27 14:07:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/27 14:07:03 | 000,000,000 | —D | M]

[2008/12/20 16:53:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Extensions
[2011/04/15 20:36:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Nagra3 Community Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{04666517-d7b9-43c9-b329-cd7a30ff0079}(2)
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
[2011/03/12 09:11:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/01/22 21:07:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions
[2007/07/01 12:49:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2007/01/11 07:37:51 | 000,000,000 | —D | M] (TV Guide UK Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{98cb2cc5-46e6-4622-aa41-ce2f64fbfcff}
[2007/04/03 20:21:22 | 000,000,000 | —D | M] (StumbleUpon) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions
[2011/01/22 21:07:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2009/04/11 15:17:33 | 000,000,681 | —- | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\ask.xml
[2011/03/27 14:07:07 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/23 19:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/08/13 00:45:50 | 000,000,000 | —D | M] (Search Settings Plugin) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
[2010/07/23 19:19:21 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/18 18:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/02/27 17:57:38 | 000,106,496 | —- | M] (British Broadcasting Corporation) – C:\Program Files\Mozilla Firefox\plugins\npBBCPlugin.dll
[2010/07/23 19:19:21 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/24 20:10:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2010/07/22 21:33:13 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\..\Toolbar\ShellBrowser: (Stumble&Upon) - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1927.dll (StumbleUpon.com)
O4 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006..\Run: [AdobeBridge] File not found
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/E/1…8CC2/wmavax.CAB (Reg Error: Value error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/02/04 18:05:36 | 000,000,000 | RH-D | M] - G:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 13:56:50 | 000,000,036 | RH– | M] () - G:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{47ec6900-36ae-11e0-a921-00123fb247c6}\Shell\AutoRun\command - "" = G:\RunClubSanDisk.exe
O33 - MountPoints2\{612bcee4-2990-11dc-acc8-000e9bea7207}\Shell\AutoRun\command - "" = J:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/29 16:38:46 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/04/23 18:37:32 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/04/23 17:52:31 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/23 17:50:12 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/23 17:47:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/04/23 17:47:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/04/23 17:43:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/23 06:58:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/22 16:31:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype Extras
[2011/04/22 16:31:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/04/22 16:31:13 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/04/22 12:02:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare 4
[2011/04/13 19:46:54 | 000,000,000 | —D | C] – C:\Program Files\SopCast
[2011/04/04 20:48:57 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\My Documents\karaoke
[2011/04/04 20:13:32 | 000,000,000 | —D | C] – C:\Program Files\SlySoft
[2011/04/04 20:13:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SlySoft
[2008/07/24 20:38:14 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\chic\Application Data\pcouffin.sys
[2005/11/17 20:46:48 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll

========== Files - Modified Within 30 Days ==========

[2011/04/29 16:38:37 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/04/29 16:36:22 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/29 16:35:52 | 000,000,310 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/04/29 16:35:46 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/29 16:35:28 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/29 16:35:23 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2011/04/29 16:30:29 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
[2011/04/29 16:30:28 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
[2011/04/29 16:29:42 | 113,706,359 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm.prepare
[2011/04/29 06:12:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/27 05:16:13 | 000,000,272 | —- | M] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/25 02:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
[2011/04/24 07:31:20 | 000,000,741 | —- | M] () – C:\Documents and Settings\chic\Desktop\Glary Utilities.lnk
[2011/04/23 22:20:09 | 000,002,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Celtic Football Coach.lnk
[2011/04/23 17:34:33 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/04/23 06:56:36 | 000,285,480 | —- | M] (COMODO) – C:\WINDOWS\System32\guard32.dll
[2011/04/23 06:56:35 | 000,239,368 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmdGuard.sys
[2011/04/23 06:56:35 | 000,027,576 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmdhlp.sys
[2011/04/23 06:56:35 | 000,015,592 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmderd.sys
[2011/04/22 16:54:21 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/22 12:02:23 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4 Beta.lnk
[2011/04/20 08:21:02 | 000,120,832 | —- | M] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/16 15:29:13 | 000,006,705 | —- | M] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/04/14 06:44:23 | 003,775,584 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/05 20:42:56 | 000,340,404 | —- | M] () – C:\Documents and Settings\chic\Desktop\bmx stuff (pinkbike).xcf
[2011/04/04 20:46:47 | 000,000,041 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/04/04 20:13:38 | 000,000,766 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CloneCD.lnk

========== Files Created - No Company Name ==========

[2011/04/29 16:28:23 | 113,706,359 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm.prepare
[2011/04/27 05:16:13 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/22 16:31:15 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/22 12:02:23 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4 Beta.lnk
[2011/04/16 15:29:13 | 000,006,705 | —- | C] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/04/05 20:42:56 | 000,340,404 | —- | C] () – C:\Documents and Settings\chic\Desktop\bmx stuff (pinkbike).xcf
[2011/04/04 20:46:47 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/04/04 20:13:38 | 000,000,766 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CloneCD.lnk
[2011/02/13 00:19:50 | 002,018,408 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/12 23:17:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2011/01/12 23:17:12 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2010/10/29 20:49:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2010/10/05 00:59:32 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\StarOpen.sys
[2010/06/25 18:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/18 20:02:41 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/04/03 10:41:50 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/04/03 10:41:50 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/04/03 10:41:37 | 000,002,528 | —- | C] () – C:\Documents and Settings\chic\Application Data\$_hpcst$.hpc
[2010/03/26 21:46:21 | 000,000,108 | —- | C] () – C:\Documents and Settings\chic\Application Data\default.pls
[2010/02/12 18:01:25 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/31 22:59:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2010/01/31 22:59:11 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2009/11/19 21:29:03 | 000,015,498 | —- | C] () – C:\WINDOWS\VX1000.ini
[2009/09/27 21:58:46 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/09/26 22:30:54 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/09/09 07:17:00 | 000,017,510 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/06/19 20:18:06 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/05/13 08:05:19 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/03/24 20:49:18 | 000,000,007 | —- | C] () – C:\WINDOWS\sbacknt.bin
[2008/11/14 12:31:34 | 000,000,168 | —- | C] () – C:\WINDOWS\netg.ini
[2008/11/14 12:31:34 | 000,000,093 | —- | C] () – C:\WINDOWS\skillv.ini
[2008/10/25 21:37:33 | 000,048,396 | —- | C] () – C:\WINDOWS\UninstVeetleTVPlayer.exe
[2008/07/24 20:39:10 | 000,081,920 | —- | C] () – C:\Documents and Settings\chic\Application Data\ezpinst.exe
[2008/07/24 20:38:14 | 000,007,176 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.cat
[2008/07/24 20:38:10 | 000,001,144 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.inf
[2008/06/23 19:12:12 | 000,000,065 | —- | C] () – C:\WINDOWS\FISHUI.INI
[2008/03/05 21:23:28 | 000,002,104 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/05 21:23:26 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/02/03 10:38:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/12/08 20:23:23 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNWISE.EXE
[2007/07/11 22:06:05 | 000,000,127 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\fusioncache.dat
[2007/06/14 19:54:54 | 000,044,440 | —- | C] () – C:\WINDOWS\System32\MtpAccess.dll
[2007/06/14 18:59:33 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\LAME_MP3.dll
[2007/06/14 18:59:19 | 000,065,024 | —- | C] () – C:\WINDOWS\IFinst26.exe
[2007/05/12 00:19:17 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/03/01 00:39:47 | 000,000,120 | —- | C] () – C:\WINDOWS\PbkUser.INI
[2007/02/05 15:24:28 | 000,018,271 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2007/02/05 15:24:26 | 000,099,999 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/01/24 23:12:53 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/01/24 23:12:40 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/01/03 12:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 23:59:04 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/10/26 21:09:34 | 000,036,864 | —- | C] () – C:\WINDOWS\uneng.exe
[2006/10/08 20:09:58 | 000,000,072 | —- | C] () – C:\WINDOWS\MediaManager.INI
[2006/07/19 20:26:15 | 000,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2006/05/22 10:26:06 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2006/04/16 20:23:19 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/03/05 14:21:03 | 000,099,840 | —- | C] () – C:\WINDOWS\System32\UnCasino5.exe
[2006/01/15 20:30:10 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/12/19 19:14:11 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2005/12/04 00:14:05 | 000,001,771 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/25 07:14:32 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/24 23:45:56 | 000,120,832 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/11/24 23:04:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/11/24 22:44:58 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2005/11/17 21:23:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/17 21:17:33 | 000,099,965 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2005/11/17 21:17:32 | 000,005,485 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/11/17 21:16:40 | 000,000,777 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/17 21:13:29 | 000,000,484 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/17 21:10:11 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/11/17 21:09:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2005/11/17 21:09:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2005/11/17 21:09:30 | 000,000,072 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2005/11/17 20:47:14 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlcdserv.dll
[2005/11/17 20:47:14 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlcdusb1.dll
[2005/11/17 20:47:14 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlcdpmui.dll
[2005/11/17 20:47:14 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcdlmpm.dll
[2005/11/17 20:47:14 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlcdutil.dll
[2005/11/17 20:47:14 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdprox.dll
[2005/11/17 20:47:14 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlcdjswr.dll
[2005/11/17 20:47:14 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlcdpplc.dll
[2005/11/17 20:47:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlcdinsr.dll
[2005/11/17 20:47:14 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlcdvs.dll
[2005/11/17 20:47:14 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcdcur.dll
[2005/11/17 20:47:12 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcdhbn3.dll
[2005/11/17 20:47:12 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcdcomc.dll
[2005/11/17 20:47:12 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcdcoms.exe
[2005/11/17 20:47:12 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcdcomm.dll
[2005/11/17 20:47:12 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlcdih.exe
[2005/11/17 20:47:12 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.exe
[2005/11/17 20:47:12 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlcdinsb.dll
[2005/11/17 20:47:12 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdins.dll
[2005/11/17 20:47:12 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcdcub.dll
[2005/11/17 20:47:12 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcdcu.dll
[2005/11/17 20:47:12 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.dll
[2005/11/17 20:46:48 | 000,060,928 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2005/11/17 20:46:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2005/11/17 20:46:38 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/11/17 20:46:34 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/11/17 20:46:16 | 000,000,402 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/02 18:05:54 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlcdplc.ini
[2004/09/22 20:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 003,775,584 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,486,540 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,088,424 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/05/12 14:01:12 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\qhtm.dll
[2004/02/21 04:31:10 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\ccvidcl.dll
[2003/06/11 19:39:44 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2002/03/05 19:30:00 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll

========== LOP Check ==========

[2010/09/17 09:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aiseesoft Studio
[2007/02/25 10:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2011/04/23 17:34:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/29 16:35:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2007/05/27 21:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/04/23 17:50:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/31 09:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/02/01 19:59:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/01/18 07:18:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2008/01/21 07:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2011/04/29 16:34:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2008/07/26 09:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2006/12/30 23:53:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/03/19 12:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2007/06/10 11:04:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\starters orders 3
[2011/04/27 06:13:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/28 21:48:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2007/07/01 20:55:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/12/25 23:57:47 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{615DB4DC-B7C1-4125-9858-78EF460B76D2}
[2009/04/22 22:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/12/25 23:56:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{9BA38AC8-8A1E-463A-97ED-AE291D3E1A06}
[2006/09/16 20:11:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Acoustica
[2010/12/09 12:21:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo
[2007/06/07 22:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo Photo Commander 4
[2009/05/27 14:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Astro Gemini Software
[2011/04/23 17:52:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/22 13:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Azureus
[2010/05/04 13:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Bump Technologies, Inc
[2009/08/28 23:13:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CBS Interactive
[2007/12/06 19:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CheckPoint
[2009/06/09 13:42:50 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Chessmaster Challenge
[2007/02/02 22:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ConvertTemp
[2009/12/31 09:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DAEMON Tools Pro
[2007/06/14 19:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DataCast
[2009/11/25 19:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\eMusic
[2010/07/25 20:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Foxit Software
[2009/12/06 12:50:41 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\FreeVideoConverter
[2007/09/23 21:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\funkitron
[2009/06/09 13:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\GlarySoft
[2011/04/16 15:29:13 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\gtk-2.0
[2009/05/14 12:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Hrsim
[2011/04/22 12:02:09 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\IObit
[2007/07/15 12:35:44 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\iWin
[2005/11/30 21:19:26 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Leadertech
[2008/08/09 15:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\LimeWire
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ManyCam
[2009/09/02 21:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Moyea
[2009/08/16 22:53:06 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\MP3Rocket
[2010/12/02 20:19:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\NCH Swift Sound
[2008/01/18 22:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Opera
[2010/04/03 13:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PC Suite
[2011/02/26 15:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Philipp Winterberg
[2007/07/15 14:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PPMate
[2010/06/26 07:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Recordpad
[2010/05/27 22:33:34 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Samsung
[2010/02/07 19:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Search Settings
[2011/02/13 00:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Sports Interactive
[2010/12/31 21:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Spotify
[2007/07/06 05:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\StumbleUpon
[2009/09/02 21:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Teleca
[2009/10/24 00:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Temporary
[2007/07/19 20:12:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\TransRender
[2009/03/24 21:02:57 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\vghd
[2009/07/27 19:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Vso
[2008/01/26 11:55:03 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Windows Desktop Search
[2009/12/06 12:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Xilisoft Corporation
[2010/08/02 20:24:56 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressripDowngrade.job
[2010/08/02 20:24:57 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressripShakeIcon.job
[2011/04/29 16:35:52 | 000,000,310 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Top 60 albums - November 2005.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\itunes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Cyberlink:Roxio EMC Stream
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:453B2FDD421AAE3E

< End of report >
Still looking at markers in your log for AVG, try running there removal tool
http://www.avg.com/us-en/download-tools


Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
    FF - prefs.js..browser.search.order.1: "Fast Browser Search"
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /release /c
    ipconfig /renew /c
    ipconfig /flushdns /c
    
    
    
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
both outcomes posted below … thank you.

All processes killed
========== PROCESSES ==========
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /release /c >
Windows IP Configuration
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
IP Address. . . . . . . . . . . . : 0.0.0.0
Subnet Mask . . . . . . . . . . . : 0.0.0.0
Default Gateway . . . . . . . . . :
C:\Documents and Settings\chic\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\chic\Desktop\cmd.txt deleted successfully.
< ipconfig /renew /c >
Windows IP Configuration
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . : cable.virginmedia.net
IP Address. . . . . . . . . . . . : 192.168.1.102
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
C:\Documents and Settings\chic\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\chic\Desktop\cmd.txt deleted successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\chic\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\chic\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: chic
->Temp folder emptied: 685090 bytes
->Temporary Internet Files folder emptied: 16381112 bytes
->Java cache emptied: 245692 bytes
->FireFox cache emptied: 58732932 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 24687 bytes

User: Default User
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 41620 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 143776 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 321378344 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 379.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 04292011_195813

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

———————————————————————–

OTL logfile created on: 29/04/2011 20:15:32 - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 484.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 115.83 Gb Free Space | 79.75% Space Free | Partition Type: NTFS
Drive D: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 931.51 Gb Total Space | 835.45 Gb Free Space | 89.69% Space Free | Partition Type: NTFS

Computer Name: AMANCHIC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.53\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (IDriverT) – File not found
SRV - (HidServ) – File not found
SRV - (cmdAgent) – File not found
SRV - (AppMgmt) – File not found
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (ANDModem) – C:\WINDOWS\system32\drivers\lgandmodem.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (Andbus) – C:\WINDOWS\system32\drivers\lgandbus.sys (LG Electronics Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (VX1000) – C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (LgBttPort) – C:\WINDOWS\system32\drivers\lgbtport.sys (LG Electronics Inc.)
DRV - (LGVMODEM) – C:\WINDOWS\system32\drivers\lgvmodem.sys (LG Electronics Inc.)
DRV - (lgbusenum) – C:\WINDOWS\system32\drivers\lgbtbus.sys (LG Electronics Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (s716unic) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM) – C:\WINDOWS\system32\drivers\s716unic.sys (MCCI Corporation)
DRV - (s716obex) – C:\WINDOWS\system32\drivers\s716obex.sys (MCCI Corporation)
DRV - (s716nd5) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS) – C:\WINDOWS\system32\drivers\s716nd5.sys (MCCI Corporation)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mgmt) Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s716mgmt.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) Sony Ericsson Device 716 driver (WDM) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (ElbyCDFL) – C:\WINDOWS\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DTV_Loader_2X1) – C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys (WideView Technology Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (k600obex) – C:\WINDOWS\system32\drivers\k600obex.sys (MCCI)
DRV - (k600mgmt) – C:\WINDOWS\system32\drivers\k600mgmt.sys (MCCI)
DRV - (k600mdm) – C:\WINDOWS\system32\drivers\k600mdm.sys (MCCI)
DRV - (k600mdfl) – C:\WINDOWS\system32\drivers\k600mdfl.sys (MCCI)
DRV - (k600bus) Sony Ericsson 600i driver (WDM) – C:\WINDOWS\system32\drivers\k600bus.sys (MCCI)
DRV - (DTV_Capture_2X0) – C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys (Computer & Entertainment, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ca536av) – C:\WINDOWS\system32\drivers\Ca536av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk536.sys (USB BULK)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (usbcm) – C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (ambitucm) – C:\WINDOWS\system32\drivers\ambitucm.sys (Ambit Microsystems Corp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.co.uk/myway
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.co.uk/myway
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/ig"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=747542&p="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"


FF - HKLM\software\mozilla\Firefox\Extensions\\{82081B3D-393D-4389-85A9-8DBBF6AB896B}: C:\Documents and Settings\chic\Local Settings\Application Data\{82081B3D-393D-4389-85A9-8DBBF6AB896B}
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/29 19:52:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/27 14:07:03 | 000,000,000 | —D | M]

[2008/12/20 16:53:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Extensions
[2011/04/15 20:36:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Nagra3 Community Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{04666517-d7b9-43c9-b329-cd7a30ff0079}(2)
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
[2011/03/12 09:11:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/01/22 21:07:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions
[2007/07/01 12:49:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2007/01/11 07:37:51 | 000,000,000 | —D | M] (TV Guide UK Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{98cb2cc5-46e6-4622-aa41-ce2f64fbfcff}
[2007/04/03 20:21:22 | 000,000,000 | —D | M] (StumbleUpon) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions
[2011/01/22 21:07:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2009/04/11 15:17:33 | 000,000,681 | —- | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\ask.xml
[2011/03/27 14:07:07 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/23 19:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/08/13 00:45:50 | 000,000,000 | —D | M] (Search Settings Plugin) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
[2010/07/23 19:19:21 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/04/29 19:52:32 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/02/27 17:57:38 | 000,106,496 | —- | M] (British Broadcasting Corporation) – C:\Program Files\Mozilla Firefox\plugins\npBBCPlugin.dll
[2010/07/23 19:19:21 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/24 20:10:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/04/29 19:58:19 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\..\Toolbar\ShellBrowser: (Stumble&Upon) - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1927.dll (StumbleUpon.com)
O4 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006..\Run: [AdobeBridge] File not found
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-3405850505-2850181533-2126382385-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/E/1…8CC2/wmavax.CAB (Reg Error: Value error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/02/22 16:15:44 | 000,000,027 | R— | M] () - D:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2011/02/04 18:05:36 | 000,000,000 | RH-D | M] - G:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 13:56:50 | 000,000,036 | RH– | M] () - G:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{47ec6900-36ae-11e0-a921-00123fb247c6}\Shell\AutoRun\command - "" = G:\RunClubSanDisk.exe
O33 - MountPoints2\{612bcee4-2990-11dc-acc8-000e9bea7207}\Shell\AutoRun\command - "" = J:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/29 19:58:13 | 000,000,000 | —D | C] – C:\_OTL
[2011/04/29 19:56:42 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/04/23 18:37:32 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/04/23 17:52:31 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/23 17:50:12 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/23 17:47:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/04/23 17:47:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/04/23 17:43:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/23 06:58:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/22 16:31:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype Extras
[2011/04/22 16:31:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/04/22 16:31:13 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/04/22 12:02:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare 4
[2011/04/13 19:46:54 | 000,000,000 | —D | C] – C:\Program Files\SopCast
[2011/04/04 20:48:57 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\My Documents\karaoke
[2011/04/04 20:13:32 | 000,000,000 | —D | C] – C:\Program Files\SlySoft
[2011/04/04 20:13:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SlySoft
[2008/07/24 20:38:14 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\chic\Application Data\pcouffin.sys
[2005/11/17 20:46:48 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll

========== Files - Modified Within 30 Days ==========

[2011/04/29 20:12:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/29 20:10:03 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/29 20:10:03 | 000,000,310 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/04/29 20:10:00 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/29 19:59:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/29 19:59:52 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2011/04/29 19:58:19 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2011/04/29 19:56:38 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/04/29 19:35:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
[2011/04/29 18:40:34 | 000,002,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Celtic Football Coach.lnk
[2011/04/29 16:30:28 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
[2011/04/29 16:29:42 | 113,706,359 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm.prepare
[2011/04/27 05:16:13 | 000,000,272 | —- | M] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/25 02:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
[2011/04/24 07:31:20 | 000,000,741 | —- | M] () – C:\Documents and Settings\chic\Desktop\Glary Utilities.lnk
[2011/04/23 17:34:33 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/04/23 06:56:36 | 000,285,480 | —- | M] (COMODO) – C:\WINDOWS\System32\guard32.dll
[2011/04/23 06:56:35 | 000,239,368 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmdGuard.sys
[2011/04/23 06:56:35 | 000,027,576 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmdhlp.sys
[2011/04/23 06:56:35 | 000,015,592 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmderd.sys
[2011/04/22 16:54:21 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/22 12:02:23 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4 Beta.lnk
[2011/04/20 08:21:02 | 000,120,832 | —- | M] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/16 15:29:13 | 000,006,705 | —- | M] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/04/14 06:44:23 | 003,775,584 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/05 20:42:56 | 000,340,404 | —- | M] () – C:\Documents and Settings\chic\Desktop\bmx stuff (pinkbike).xcf
[2011/04/04 20:46:47 | 000,000,041 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/04/04 20:13:38 | 000,000,766 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CloneCD.lnk

========== Files Created - No Company Name ==========

[2011/04/29 16:28:23 | 113,706,359 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm.prepare
[2011/04/27 05:16:13 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/22 16:31:15 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/22 12:02:23 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4 Beta.lnk
[2011/04/16 15:29:13 | 000,006,705 | —- | C] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/04/05 20:42:56 | 000,340,404 | —- | C] () – C:\Documents and Settings\chic\Desktop\bmx stuff (pinkbike).xcf
[2011/04/04 20:46:47 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/04/04 20:13:38 | 000,000,766 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CloneCD.lnk
[2011/02/13 00:19:50 | 002,018,408 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/12 23:17:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2011/01/12 23:17:12 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2010/10/29 20:49:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2010/10/05 00:59:32 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\StarOpen.sys
[2010/06/25 18:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/18 20:02:41 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/04/03 10:41:50 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/04/03 10:41:50 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/04/03 10:41:37 | 000,002,528 | —- | C] () – C:\Documents and Settings\chic\Application Data\$_hpcst$.hpc
[2010/03/26 21:46:21 | 000,000,108 | —- | C] () – C:\Documents and Settings\chic\Application Data\default.pls
[2010/02/12 18:01:25 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/31 22:59:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2010/01/31 22:59:11 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2009/11/19 21:29:03 | 000,015,498 | —- | C] () – C:\WINDOWS\VX1000.ini
[2009/09/27 21:58:46 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/09/26 22:30:54 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/09/09 07:17:00 | 000,017,510 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/06/19 20:18:06 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/05/13 08:05:19 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/03/24 20:49:18 | 000,000,007 | —- | C] () – C:\WINDOWS\sbacknt.bin
[2008/11/14 12:31:34 | 000,000,168 | —- | C] () – C:\WINDOWS\netg.ini
[2008/11/14 12:31:34 | 000,000,093 | —- | C] () – C:\WINDOWS\skillv.ini
[2008/10/25 21:37:33 | 000,048,396 | —- | C] () – C:\WINDOWS\UninstVeetleTVPlayer.exe
[2008/07/24 20:39:10 | 000,081,920 | —- | C] () – C:\Documents and Settings\chic\Application Data\ezpinst.exe
[2008/07/24 20:38:14 | 000,007,176 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.cat
[2008/07/24 20:38:10 | 000,001,144 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.inf
[2008/06/23 19:12:12 | 000,000,065 | —- | C] () – C:\WINDOWS\FISHUI.INI
[2008/03/05 21:23:28 | 000,002,104 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/05 21:23:26 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/02/03 10:38:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/12/08 20:23:23 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNWISE.EXE
[2007/07/11 22:06:05 | 000,000,127 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\fusioncache.dat
[2007/06/14 19:54:54 | 000,044,440 | —- | C] () – C:\WINDOWS\System32\MtpAccess.dll
[2007/06/14 18:59:33 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\LAME_MP3.dll
[2007/06/14 18:59:19 | 000,065,024 | —- | C] () – C:\WINDOWS\IFinst26.exe
[2007/05/12 00:19:17 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/03/01 00:39:47 | 000,000,120 | —- | C] () – C:\WINDOWS\PbkUser.INI
[2007/02/05 15:24:28 | 000,018,271 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2007/02/05 15:24:26 | 000,099,999 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/01/24 23:12:53 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/01/24 23:12:40 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/01/03 12:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 23:59:04 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/10/26 21:09:34 | 000,036,864 | —- | C] () – C:\WINDOWS\uneng.exe
[2006/10/08 20:09:58 | 000,000,072 | —- | C] () – C:\WINDOWS\MediaManager.INI
[2006/07/19 20:26:15 | 000,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2006/05/22 10:26:06 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2006/04/16 20:23:19 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/03/05 14:21:03 | 000,099,840 | —- | C] () – C:\WINDOWS\System32\UnCasino5.exe
[2006/01/15 20:30:10 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/12/19 19:14:11 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2005/12/04 00:14:05 | 000,001,771 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/25 07:14:32 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/24 23:45:56 | 000,120,832 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/11/24 23:04:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/11/24 22:44:58 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2005/11/17 21:23:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/17 21:17:33 | 000,099,965 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2005/11/17 21:17:32 | 000,005,485 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/11/17 21:16:40 | 000,000,777 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/17 21:13:29 | 000,000,484 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/17 21:10:11 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/11/17 21:09:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2005/11/17 21:09:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2005/11/17 21:09:30 | 000,000,072 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2005/11/17 20:47:14 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlcdserv.dll
[2005/11/17 20:47:14 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlcdusb1.dll
[2005/11/17 20:47:14 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlcdpmui.dll
[2005/11/17 20:47:14 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcdlmpm.dll
[2005/11/17 20:47:14 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlcdutil.dll
[2005/11/17 20:47:14 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdprox.dll
[2005/11/17 20:47:14 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlcdjswr.dll
[2005/11/17 20:47:14 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlcdpplc.dll
[2005/11/17 20:47:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlcdinsr.dll
[2005/11/17 20:47:14 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlcdvs.dll
[2005/11/17 20:47:14 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcdcur.dll
[2005/11/17 20:47:12 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcdhbn3.dll
[2005/11/17 20:47:12 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcdcomc.dll
[2005/11/17 20:47:12 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcdcoms.exe
[2005/11/17 20:47:12 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcdcomm.dll
[2005/11/17 20:47:12 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlcdih.exe
[2005/11/17 20:47:12 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.exe
[2005/11/17 20:47:12 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlcdinsb.dll
[2005/11/17 20:47:12 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdins.dll
[2005/11/17 20:47:12 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcdcub.dll
[2005/11/17 20:47:12 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcdcu.dll
[2005/11/17 20:47:12 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.dll
[2005/11/17 20:46:48 | 000,060,928 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2005/11/17 20:46:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2005/11/17 20:46:38 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/11/17 20:46:34 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/11/17 20:46:16 | 000,000,402 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/02 18:05:54 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlcdplc.ini
[2004/09/22 20:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 003,775,584 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,486,540 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,088,424 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/05/12 14:01:12 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\qhtm.dll
[2004/02/21 04:31:10 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\ccvidcl.dll
[2003/06/11 19:39:44 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2002/03/05 19:30:00 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Top 60 albums - November 2005.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\itunes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Cyberlink:Roxio EMC Stream
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:453B2FDD421AAE3E

< End of report >
Sorry for the late reply but it appears the site was down for a time.

The last fix for Fast Browser Search did not take so let run it again in Safemode


To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode



Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
    FF - prefs.js..browser.search.order.1: "Fast Browser Search"
    
    
    :Services
    
    :Reg
    
    :Files
    
    
    
    
    
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Results posted below …

All processes killed
========== PROCESSES ==========
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: chic
->Temp folder emptied: 29881957 bytes
->Temporary Internet Files folder emptied: 169212 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 44597413 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 5083 bytes

User: Default User
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 140896 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 18459252 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 89.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 04302011_180807

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…


______________________________________________________



OTL logfile created on: 30/04/2011 18:11:15 - Run 5
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 660.00 Mb Available Physical Memory | 65.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 115.74 Gb Free Space | 79.69% Space Free | Partition Type: NTFS
Drive D: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 931.51 Gb Total Space | 835.45 Gb Free Space | 89.69% Space Free | Partition Type: NTFS

Computer Name: AMANCHIC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.53\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (IDriverT) – File not found
SRV - (HidServ) – File not found
SRV - (cmdAgent) – File not found
SRV - (AppMgmt) – File not found
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (ANDModem) – C:\WINDOWS\system32\drivers\lgandmodem.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (Andbus) – C:\WINDOWS\system32\drivers\lgandbus.sys (LG Electronics Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (VX1000) – C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (LgBttPort) – C:\WINDOWS\system32\drivers\lgbtport.sys (LG Electronics Inc.)
DRV - (LGVMODEM) – C:\WINDOWS\system32\drivers\lgvmodem.sys (LG Electronics Inc.)
DRV - (lgbusenum) – C:\WINDOWS\system32\drivers\lgbtbus.sys (LG Electronics Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (s716unic) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM) – C:\WINDOWS\system32\drivers\s716unic.sys (MCCI Corporation)
DRV - (s716obex) – C:\WINDOWS\system32\drivers\s716obex.sys (MCCI Corporation)
DRV - (s716nd5) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS) – C:\WINDOWS\system32\drivers\s716nd5.sys (MCCI Corporation)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mgmt) Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s716mgmt.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) Sony Ericsson Device 716 driver (WDM) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (ElbyCDFL) – C:\WINDOWS\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DTV_Loader_2X1) – C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys (WideView Technology Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (k600obex) – C:\WINDOWS\system32\drivers\k600obex.sys (MCCI)
DRV - (k600mgmt) – C:\WINDOWS\system32\drivers\k600mgmt.sys (MCCI)
DRV - (k600mdm) – C:\WINDOWS\system32\drivers\k600mdm.sys (MCCI)
DRV - (k600mdfl) – C:\WINDOWS\system32\drivers\k600mdfl.sys (MCCI)
DRV - (k600bus) Sony Ericsson 600i driver (WDM) – C:\WINDOWS\system32\drivers\k600bus.sys (MCCI)
DRV - (DTV_Capture_2X0) – C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys (Computer & Entertainment, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ca536av) – C:\WINDOWS\system32\drivers\Ca536av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk536.sys (USB BULK)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (usbcm) – C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (ambitucm) – C:\WINDOWS\system32\drivers\ambitucm.sys (Ambit Microsystems Corp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/ig"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=747542&p="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"


FF - HKLM\software\mozilla\Firefox\Extensions\\{82081B3D-393D-4389-85A9-8DBBF6AB896B}: C:\Documents and Settings\chic\Local Settings\Application Data\{82081B3D-393D-4389-85A9-8DBBF6AB896B}
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/29 19:52:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/27 14:07:03 | 000,000,000 | —D | M]

[2008/12/20 16:53:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Extensions
[2011/04/30 17:40:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Nagra3 Community Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{04666517-d7b9-43c9-b329-cd7a30ff0079}(2)
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
[2011/03/12 09:11:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/01/22 21:07:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions
[2007/07/01 12:49:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2007/01/11 07:37:51 | 000,000,000 | —D | M] (TV Guide UK Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{98cb2cc5-46e6-4622-aa41-ce2f64fbfcff}
[2007/04/03 20:21:22 | 000,000,000 | —D | M] (StumbleUpon) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions
[2011/01/22 21:07:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2009/04/11 15:17:33 | 000,000,681 | —- | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\ask.xml
[2011/03/27 14:07:07 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/23 19:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/08/13 00:45:50 | 000,000,000 | —D | M] (Search Settings Plugin) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
[2010/07/23 19:19:21 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/04/29 19:52:32 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/02/27 17:57:38 | 000,106,496 | —- | M] (British Broadcasting Corporation) – C:\Program Files\Mozilla Firefox\plugins\npBBCPlugin.dll
[2010/07/23 19:19:21 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/24 20:10:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/04/29 19:58:19 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Stumble&Upon) - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1927.dll (StumbleUpon.com)
O4 - HKCU..\Run: [AdobeBridge] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/E/1…8CC2/wmavax.CAB (Reg Error: Value error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/02/22 16:15:44 | 000,000,027 | R— | M] () - D:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2011/02/04 18:05:36 | 000,000,000 | RH-D | M] - G:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 13:56:50 | 000,000,036 | RH– | M] () - G:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{47ec6900-36ae-11e0-a921-00123fb247c6}\Shell\AutoRun\command - "" = G:\RunClubSanDisk.exe
O33 - MountPoints2\{612bcee4-2990-11dc-acc8-000e9bea7207}\Shell\AutoRun\command - "" = J:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/29 19:58:13 | 000,000,000 | —D | C] – C:\_OTL
[2011/04/29 19:56:42 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/04/23 18:37:32 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/04/23 17:52:31 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/23 17:50:12 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/23 17:47:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/04/23 17:47:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/04/23 17:43:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/23 06:58:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/22 16:31:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype Extras
[2011/04/22 16:31:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/04/22 16:31:13 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/04/22 12:02:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare 4
[2011/04/13 19:46:54 | 000,000,000 | —D | C] – C:\Program Files\SopCast
[2011/04/04 20:48:57 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\My Documents\karaoke
[2011/04/04 20:13:32 | 000,000,000 | —D | C] – C:\Program Files\SlySoft
[2011/04/04 20:13:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SlySoft
[2008/07/24 20:38:14 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\chic\Application Data\pcouffin.sys
[2005/11/17 20:46:48 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll

========== Files - Modified Within 30 Days ==========

[2011/04/30 18:12:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/30 18:10:13 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/30 18:10:12 | 000,000,310 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/04/30 18:10:11 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/30 18:09:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/30 18:09:32 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2011/04/30 17:35:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
[2011/04/30 16:35:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
[2011/04/29 19:58:19 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2011/04/29 19:56:38 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/04/29 18:40:34 | 000,002,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Celtic Football Coach.lnk
[2011/04/29 16:29:42 | 113,706,359 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm.prepare
[2011/04/27 05:16:13 | 000,000,272 | —- | M] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/25 02:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
[2011/04/24 07:31:20 | 000,000,741 | —- | M] () – C:\Documents and Settings\chic\Desktop\Glary Utilities.lnk
[2011/04/23 17:34:33 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/04/23 06:56:36 | 000,285,480 | —- | M] (COMODO) – C:\WINDOWS\System32\guard32.dll
[2011/04/23 06:56:35 | 000,239,368 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmdGuard.sys
[2011/04/23 06:56:35 | 000,027,576 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmdhlp.sys
[2011/04/23 06:56:35 | 000,015,592 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmderd.sys
[2011/04/22 16:54:21 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/22 12:02:23 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4 Beta.lnk
[2011/04/20 08:21:02 | 000,120,832 | —- | M] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/16 15:29:13 | 000,006,705 | —- | M] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/04/14 06:44:23 | 003,775,584 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/05 20:42:56 | 000,340,404 | —- | M] () – C:\Documents and Settings\chic\Desktop\bmx stuff (pinkbike).xcf
[2011/04/04 20:46:47 | 000,000,041 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/04/04 20:13:38 | 000,000,766 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CloneCD.lnk

========== Files Created - No Company Name ==========

[2011/04/30 18:09:31 | 1071,796,224 | -HS- | C] () – C:\hiberfil.sys
[2011/04/29 16:28:23 | 113,706,359 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm.prepare
[2011/04/27 05:16:13 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/22 16:31:15 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/04/22 12:02:23 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4 Beta.lnk
[2011/04/16 15:29:13 | 000,006,705 | —- | C] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/04/05 20:42:56 | 000,340,404 | —- | C] () – C:\Documents and Settings\chic\Desktop\bmx stuff (pinkbike).xcf
[2011/04/04 20:46:47 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/04/04 20:13:38 | 000,000,766 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CloneCD.lnk
[2011/02/13 00:19:50 | 002,018,408 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/12 23:17:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2011/01/12 23:17:12 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2010/10/29 20:49:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2010/10/05 00:59:32 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\StarOpen.sys
[2010/06/25 18:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/18 20:02:41 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/04/03 10:41:50 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/04/03 10:41:50 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/04/03 10:41:37 | 000,002,528 | —- | C] () – C:\Documents and Settings\chic\Application Data\$_hpcst$.hpc
[2010/03/26 21:46:21 | 000,000,108 | —- | C] () – C:\Documents and Settings\chic\Application Data\default.pls
[2010/02/12 18:01:25 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/31 22:59:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2010/01/31 22:59:11 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2009/11/19 21:29:03 | 000,015,498 | —- | C] () – C:\WINDOWS\VX1000.ini
[2009/09/27 21:58:46 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/09/26 22:30:54 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/09/09 07:17:00 | 000,017,510 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/06/19 20:18:06 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/05/13 08:05:19 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/03/24 20:49:18 | 000,000,007 | —- | C] () – C:\WINDOWS\sbacknt.bin
[2008/11/14 12:31:34 | 000,000,168 | —- | C] () – C:\WINDOWS\netg.ini
[2008/11/14 12:31:34 | 000,000,093 | —- | C] () – C:\WINDOWS\skillv.ini
[2008/10/25 21:37:33 | 000,048,396 | —- | C] () – C:\WINDOWS\UninstVeetleTVPlayer.exe
[2008/07/24 20:39:10 | 000,081,920 | —- | C] () – C:\Documents and Settings\chic\Application Data\ezpinst.exe
[2008/07/24 20:38:14 | 000,007,176 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.cat
[2008/07/24 20:38:10 | 000,001,144 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.inf
[2008/06/23 19:12:12 | 000,000,065 | —- | C] () – C:\WINDOWS\FISHUI.INI
[2008/03/05 21:23:28 | 000,002,104 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/05 21:23:26 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/02/03 10:38:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/12/08 20:23:23 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNWISE.EXE
[2007/07/11 22:06:05 | 000,000,127 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\fusioncache.dat
[2007/06/14 19:54:54 | 000,044,440 | —- | C] () – C:\WINDOWS\System32\MtpAccess.dll
[2007/06/14 18:59:33 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\LAME_MP3.dll
[2007/06/14 18:59:19 | 000,065,024 | —- | C] () – C:\WINDOWS\IFinst26.exe
[2007/05/12 00:19:17 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/03/01 00:39:47 | 000,000,120 | —- | C] () – C:\WINDOWS\PbkUser.INI
[2007/02/05 15:24:28 | 000,018,271 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2007/02/05 15:24:26 | 000,099,999 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/01/24 23:12:53 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/01/24 23:12:40 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/01/03 12:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 23:59:04 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/10/26 21:09:34 | 000,036,864 | —- | C] () – C:\WINDOWS\uneng.exe
[2006/10/08 20:09:58 | 000,000,072 | —- | C] () – C:\WINDOWS\MediaManager.INI
[2006/07/19 20:26:15 | 000,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2006/05/22 10:26:06 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2006/04/16 20:23:19 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/03/05 14:21:03 | 000,099,840 | —- | C] () – C:\WINDOWS\System32\UnCasino5.exe
[2006/01/15 20:30:10 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/12/19 19:14:11 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2005/12/04 00:14:05 | 000,001,771 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/25 07:14:32 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/24 23:45:56 | 000,120,832 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/11/24 23:04:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/11/24 22:44:58 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2005/11/17 21:23:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/17 21:17:33 | 000,099,965 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2005/11/17 21:17:32 | 000,005,485 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/11/17 21:16:40 | 000,000,777 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/17 21:13:29 | 000,000,484 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/17 21:10:11 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/11/17 21:09:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2005/11/17 21:09:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2005/11/17 21:09:30 | 000,000,072 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2005/11/17 20:47:14 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlcdserv.dll
[2005/11/17 20:47:14 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlcdusb1.dll
[2005/11/17 20:47:14 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlcdpmui.dll
[2005/11/17 20:47:14 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcdlmpm.dll
[2005/11/17 20:47:14 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlcdutil.dll
[2005/11/17 20:47:14 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdprox.dll
[2005/11/17 20:47:14 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlcdjswr.dll
[2005/11/17 20:47:14 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlcdpplc.dll
[2005/11/17 20:47:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlcdinsr.dll
[2005/11/17 20:47:14 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlcdvs.dll
[2005/11/17 20:47:14 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcdcur.dll
[2005/11/17 20:47:12 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcdhbn3.dll
[2005/11/17 20:47:12 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcdcomc.dll
[2005/11/17 20:47:12 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcdcoms.exe
[2005/11/17 20:47:12 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcdcomm.dll
[2005/11/17 20:47:12 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlcdih.exe
[2005/11/17 20:47:12 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.exe
[2005/11/17 20:47:12 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlcdinsb.dll
[2005/11/17 20:47:12 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdins.dll
[2005/11/17 20:47:12 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcdcub.dll
[2005/11/17 20:47:12 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcdcu.dll
[2005/11/17 20:47:12 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.dll
[2005/11/17 20:46:48 | 000,060,928 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2005/11/17 20:46:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2005/11/17 20:46:38 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/11/17 20:46:34 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/11/17 20:46:16 | 000,000,402 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/02 18:05:54 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlcdplc.ini
[2004/09/22 20:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 003,775,584 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,486,540 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,088,424 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/05/12 14:01:12 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\qhtm.dll
[2004/02/21 04:31:10 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\ccvidcl.dll
[2003/06/11 19:39:44 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2002/03/05 19:30:00 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Top 60 albums - November 2005.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\itunes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Cyberlink:Roxio EMC Stream
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:453B2FDD421AAE3E

< End of report >
Still there.

FYI <–You got this from a a facebook application "My Tattoos"


Open Firefox, go under "Tools", and then "Add Ons". look for it and Click "Uninstall".

Let me know how it went

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI