Declan
Topic Starter
Hi, this morning I received a number of "fake alerts" re application errors and notification that I had experienced hard disk errors.
After running Malwarebytes Anti-Malware certain viruses were highlighted that hid the desktop, the task manager and certain drive properties.
The desktop and task manager are now visible but the fake alerts persist and various parts of programs don't run.
I have followed your advice re OTL, HiJack This and DDS.
While running OTL I received an Access Violation alert and the program stalled on "creating restore point - DO NOT INTERRUPT", therefore I do not have the requested log files for this program. (I have re-run OTL and it completed the run - providing an OTL.txt file which I have loaded before the HiJack This file.)
The others are listed below.
Any help would be appreciated. Thank you.
OTL logfile created on: 03/06/2011 12:21:49 - Run 8
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1022.07 Mb Total Physical Memory | 632.00 Mb Available Physical Memory | 61.83% Memory free
2.40 Gb Paging File | 2.18 Gb Available in Paging File | 90.66% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 109.40 Gb Free Space | 75.33% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 825.10 Gb Free Space | 88.58% Space Free | Partition Type: NTFS
Computer Name: AMANCHIC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.57\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (IDriverT) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (VX1000) – C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (LgBttPort) – C:\WINDOWS\system32\drivers\lgbtport.sys (LG Electronics Inc.)
DRV - (LGVMODEM) – C:\WINDOWS\system32\drivers\lgvmodem.sys (LG Electronics Inc.)
DRV - (lgbusenum) – C:\WINDOWS\system32\drivers\lgbtbus.sys (LG Electronics Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (s716unic) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM) – C:\WINDOWS\system32\drivers\s716unic.sys (MCCI Corporation)
DRV - (s716obex) – C:\WINDOWS\system32\drivers\s716obex.sys (MCCI Corporation)
DRV - (s716nd5) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS) – C:\WINDOWS\system32\drivers\s716nd5.sys (MCCI Corporation)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mgmt) Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s716mgmt.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) Sony Ericsson Device 716 driver (WDM) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (ElbyCDFL) – C:\WINDOWS\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DTV_Loader_2X1) – C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys (WideView Technology Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (k600obex) – C:\WINDOWS\system32\drivers\k600obex.sys (MCCI)
DRV - (k600mgmt) – C:\WINDOWS\system32\drivers\k600mgmt.sys (MCCI)
DRV - (k600mdm) – C:\WINDOWS\system32\drivers\k600mdm.sys (MCCI)
DRV - (k600mdfl) – C:\WINDOWS\system32\drivers\k600mdfl.sys (MCCI)
DRV - (k600bus) Sony Ericsson 600i driver (WDM) – C:\WINDOWS\system32\drivers\k600bus.sys (MCCI)
DRV - (DTV_Capture_2X0) – C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys (Computer & Entertainment, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ca536av) – C:\WINDOWS\system32\drivers\Ca536av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk536.sys (USB BULK)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (usbcm) – C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (ambitucm) – C:\WINDOWS\system32\drivers\ambitucm.sys (Ambit Microsystems Corp)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/ig"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..keyword.URL: "http://www.questscan.com/?tmp=nemo_results_removelink&prt=QstscanPB&keywords="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - HKLM\software\mozilla\Firefox\Extensions\\{82081B3D-393D-4389-85A9-8DBBF6AB896B}: C:\Documents and Settings\chic\Local Settings\Application Data\{82081B3D-393D-4389-85A9-8DBBF6AB896B}
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/31 17:15:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/31 17:15:28 | 000,000,000 | —D | M]
[2008/12/20 16:53:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Extensions
[2011/06/02 08:00:59 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Nagra3 Community Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{04666517-d7b9-43c9-b329-cd7a30ff0079}(2)
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
[2011/03/12 09:11:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/01/22 21:07:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions
[2007/07/01 12:49:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2007/01/11 07:37:51 | 000,000,000 | —D | M] (TV Guide UK Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{98cb2cc5-46e6-4622-aa41-ce2f64fbfcff}
[2007/04/03 20:21:22 | 000,000,000 | —D | M] (StumbleUpon) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions
[2011/01/22 21:07:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2009/04/11 15:17:33 | 000,000,681 | -H– | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\ask.xml
[2011/05/28 04:34:33 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/23 19:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/08/13 00:45:50 | 000,000,000 | —D | M] (Search Settings Plugin) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
[2010/07/23 19:19:21 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/04/14 17:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/02/27 17:57:38 | 000,106,496 | —- | M] (British Broadcasting Corporation) – C:\Program Files\Mozilla Firefox\plugins\npBBCPlugin.dll
[2009/11/06 16:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/07/23 19:19:21 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/24 20:10:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2009/11/06 16:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/04/29 19:58:19 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HistoryTriggerBHO Class) - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Stumble&Upon) - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1927.dll (StumbleUpon.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/E/1…8CC2/wmavax.CAB (Reg Error: Value error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/02/04 18:05:36 | 000,000,000 | RH-D | M] - G:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 13:56:50 | 000,000,036 | RH– | M] () - G:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{612bcee4-2990-11dc-acc8-000e9bea7207}\Shell\AutoRun\command - "" = J:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Intel Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave8 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)
========== Files/Folders - Created Within 30 Days ==========
[2011/06/03 08:16:19 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/06/03 05:58:51 | 000,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\beep.sys
[2011/06/03 05:55:56 | 000,000,000 | RH-D | C] – C:\Documents and Settings\chic\Recent
[2011/06/01 21:18:40 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\EverioBackup
[2011/05/31 17:15:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Coupons
[2011/05/31 17:15:28 | 000,000,000 | —D | C] – C:\WINDOWS\Cache
[2011/05/31 17:15:27 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2011/05/31 17:15:16 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\HpUpdate
[2011/05/31 17:14:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\HP
[2011/05/31 17:14:21 | 001,761,128 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\HPScanMiniDrv_DJ1050_J410.dll
[2011/05/31 17:14:17 | 000,539,496 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinksts8911.dll
[2011/05/31 17:14:17 | 000,272,744 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinksts8911LM.dll
[2011/05/31 17:14:17 | 000,201,728 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinkcoi8911.dll
[2011/05/31 17:12:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP
[2011/05/31 17:12:18 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/05/31 17:11:53 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Local Settings\Application Data\HP
[2011/05/31 11:13:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2011/05/31 05:19:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Free YouTube Downloader
[2011/05/26 05:06:16 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/15 20:51:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ODBC
[2011/05/15 20:24:36 | 000,000,000 | —D | C] – C:\Program Files\QuestScan
[2011/05/15 20:24:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\QuestScan
[2011/05/10 07:25:52 | 000,020,736 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lganddiag.sys
[2011/05/10 07:25:52 | 000,020,096 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lgandgps.sys
[2011/05/10 06:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\LG PC Suite IV
[2011/05/08 15:55:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\My Music
[2011/05/08 15:52:22 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\iTunes
[2011/05/08 15:51:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/05/08 15:50:29 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/05/08 15:50:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/05/08 15:49:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/05/08 15:49:05 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/05/08 15:47:52 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/05/08 15:47:02 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/07 18:22:54 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2011/05/07 18:22:48 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\uTorrent
[2011/05/07 18:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Local Settings\Application Data\uTorrent
[2011/05/07 13:05:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\WindowsPowerShell
[2011/05/07 13:05:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\winrm
[2011/05/07 13:05:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\GroupPolicy
[2011/05/07 13:04:54 | 000,000,000 | -H-D | C] – C:\WINDOWS\$968930Uinstall_KB968930$
[2011/05/05 21:42:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\IObit
[2008/07/24 20:38:14 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\chic\Application Data\pcouffin.sys
[2005/11/17 20:46:48 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
========== Files - Modified Within 30 Days ==========
[2011/06/03 12:17:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/03 11:40:12 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
[2011/06/03 11:40:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
[2011/06/03 10:10:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/06/03 09:55:11 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\6824.sys
[2011/06/03 09:55:04 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/03 09:54:35 | 000,000,310 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/06/03 09:54:34 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/03 09:54:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/03 09:54:16 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2011/06/03 08:36:31 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\1484.sys
[2011/06/03 08:22:24 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\chic\Desktop\HiJackThis.exe
[2011/06/03 08:17:09 | 000,625,664 | —- | M] () – C:\Documents and Settings\chic\Desktop\dds.scr
[2011/06/03 08:16:13 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/06/03 08:12:04 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\148D.sys
[2011/06/03 08:08:00 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\2993.sys
[2011/06/03 07:57:12 | 000,107,232 | —- | M] () – C:\Documents and Settings\chic\Application Data\25327-utorrent.1509.dmp
[2011/06/03 07:56:08 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\2004.sys
[2011/06/03 07:48:44 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\1844.sys
[2011/06/03 05:28:35 | 000,000,152 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~20045604r
[2011/06/03 05:28:35 | 000,000,136 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~20045604
[2011/06/03 05:28:22 | 000,000,336 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\20045604
[2011/06/02 20:40:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/06/02 17:15:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/06/02 14:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/05/31 17:14:23 | 000,001,981 | —- | M] () – C:\Documents and Settings\All Users\Desktop\printer.lnk
[2011/05/31 14:16:29 | 000,000,625 | —- | M] () – C:\Documents and Settings\chic\Desktop\Glary Utilities.lnk
[2011/05/31 05:19:56 | 000,000,730 | —- | M] () – C:\Documents and Settings\All Users\Desktop\yt.lnk
[2011/05/30 14:09:15 | 000,001,578 | -H– | M] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/05/30 14:08:48 | 000,000,079 | -H– | M] () – C:\Documents and Settings\chic\.gtk-bookmarks
[2011/05/29 08:29:31 | 000,843,136 | -H– | M] () – C:\Documents and Settings\chic\My Documents\Coastal-Trail.pdf
[2011/05/29 02:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
[2011/05/28 08:55:55 | 000,112,952 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/27 18:10:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/26 05:06:16 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/10 10:59:49 | 000,002,413 | —- | M] () – C:\WINDOWS\System32\lgAxconfig.ini
[2011/05/09 23:09:37 | 000,000,742 | —- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/09 23:09:37 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/05/08 15:51:13 | 000,001,452 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/07 13:05:56 | 000,486,540 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/05/07 13:05:56 | 000,088,424 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/05/05 21:34:23 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk
========== Files Created - No Company Name ==========
[2011/06/03 09:55:11 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\6824.sys
[2011/06/03 08:36:31 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\1484.sys
[2011/06/03 08:17:10 | 000,625,664 | —- | C] () – C:\Documents and Settings\chic\Desktop\dds.scr
[2011/06/03 08:12:04 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\148D.sys
[2011/06/03 08:08:00 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\2993.sys
[2011/06/03 07:57:11 | 000,107,232 | —- | C] () – C:\Documents and Settings\chic\Application Data\25327-utorrent.1509.dmp
[2011/06/03 07:56:08 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\2004.sys
[2011/06/03 07:48:44 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\1844.sys
[2011/06/03 05:57:10 | 1071,796,224 | -HS- | C] () – C:\hiberfil.sys
[2011/06/03 05:28:35 | 000,000,152 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~20045604r
[2011/06/03 05:28:35 | 000,000,136 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~20045604
[2011/06/03 05:28:22 | 000,000,336 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\20045604
[2011/05/31 17:15:13 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At4.job
[2011/05/31 17:15:12 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At3.job
[2011/05/31 17:15:12 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At2.job
[2011/05/31 17:15:12 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2011/05/31 17:14:23 | 000,001,981 | —- | C] () – C:\Documents and Settings\All Users\Desktop\printer.lnk
[2011/05/31 05:19:56 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Desktop\yt.lnk
[2011/05/30 14:09:15 | 000,001,578 | -H– | C] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/05/30 14:08:48 | 000,000,079 | -H– | C] () – C:\Documents and Settings\chic\.gtk-bookmarks
[2011/05/29 08:32:03 | 000,843,136 | -H– | C] () – C:\Documents and Settings\chic\My Documents\Coastal-Trail.pdf
[2011/05/28 08:55:55 | 000,112,952 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/08 15:51:13 | 000,001,452 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/08 15:47:55 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/05 21:34:23 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk
[2011/04/27 05:16:13 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/04 20:46:47 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/01/12 23:17:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2011/01/12 23:17:12 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2010/10/29 20:49:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2010/10/05 00:59:32 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\StarOpen.sys
[2010/06/25 18:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/18 20:02:41 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/04/03 10:41:50 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/04/03 10:41:50 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/04/03 10:41:37 | 000,002,528 | -H– | C] () – C:\Documents and Settings\chic\Application Data\$_hpcst$.hpc
[2010/03/26 21:46:21 | 000,000,108 | -H– | C] () – C:\Documents and Settings\chic\Application Data\default.pls
[2010/02/12 18:01:25 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/31 22:59:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2010/01/31 22:59:11 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2009/11/19 21:29:03 | 000,015,498 | —- | C] () – C:\WINDOWS\VX1000.ini
[2009/09/27 21:58:46 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/09/26 22:30:54 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/09/09 07:17:00 | 000,017,510 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/06/19 20:18:06 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/05/13 08:05:19 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/03/24 20:49:18 | 000,000,007 | —- | C] () – C:\WINDOWS\sbacknt.bin
[2008/11/14 12:31:34 | 000,000,168 | —- | C] () – C:\WINDOWS\netg.ini
[2008/11/14 12:31:34 | 000,000,093 | —- | C] () – C:\WINDOWS\skillv.ini
[2008/10/25 21:37:33 | 000,048,396 | —- | C] () – C:\WINDOWS\UninstVeetleTVPlayer.exe
[2008/07/24 20:39:10 | 000,081,920 | —- | C] () – C:\Documents and Settings\chic\Application Data\ezpinst.exe
[2008/07/24 20:38:14 | 000,007,176 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.cat
[2008/07/24 20:38:10 | 000,001,144 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.inf
[2008/06/23 19:12:12 | 000,000,065 | —- | C] () – C:\WINDOWS\FISHUI.INI
[2008/03/05 21:23:28 | 000,002,104 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/05 21:23:26 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/02/03 10:38:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/12/08 20:23:23 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNWISE.EXE
[2007/07/11 22:06:05 | 000,000,127 | -H– | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\fusioncache.dat
[2007/06/14 19:54:54 | 000,044,440 | —- | C] () – C:\WINDOWS\System32\MtpAccess.dll
[2007/06/14 18:59:33 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\LAME_MP3.dll
[2007/06/14 18:59:19 | 000,065,024 | —- | C] () – C:\WINDOWS\IFinst26.exe
[2007/05/12 00:19:17 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/03/01 00:39:47 | 000,000,120 | —- | C] () – C:\WINDOWS\PbkUser.INI
[2007/02/05 15:24:28 | 000,018,271 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2007/02/05 15:24:26 | 000,099,999 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/01/24 23:12:53 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/01/24 23:12:40 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/01/03 12:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 23:59:04 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/10/26 21:09:34 | 000,036,864 | —- | C] () – C:\WINDOWS\uneng.exe
[2006/10/08 20:09:58 | 000,000,072 | —- | C] () – C:\WINDOWS\MediaManager.INI
[2006/07/19 20:26:15 | 000,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2006/05/22 10:26:06 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2006/04/16 20:23:19 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/03/05 14:21:03 | 000,099,840 | —- | C] () – C:\WINDOWS\System32\UnCasino5.exe
[2006/01/15 20:30:10 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/12/19 19:14:11 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2005/12/04 00:14:05 | 000,001,771 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/25 07:14:32 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/24 23:45:56 | 000,120,832 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/11/24 23:04:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/11/24 22:44:58 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2005/11/17 21:23:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/17 21:17:33 | 000,099,965 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2005/11/17 21:17:32 | 000,005,485 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/11/17 21:16:40 | 000,000,777 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/17 21:13:29 | 000,000,484 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/17 21:10:11 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/11/17 21:09:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2005/11/17 21:09:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2005/11/17 21:09:30 | 000,000,072 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2005/11/17 20:47:14 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlcdserv.dll
[2005/11/17 20:47:14 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlcdusb1.dll
[2005/11/17 20:47:14 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlcdpmui.dll
[2005/11/17 20:47:14 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcdlmpm.dll
[2005/11/17 20:47:14 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlcdutil.dll
[2005/11/17 20:47:14 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdprox.dll
[2005/11/17 20:47:14 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlcdjswr.dll
[2005/11/17 20:47:14 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlcdpplc.dll
[2005/11/17 20:47:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlcdinsr.dll
[2005/11/17 20:47:14 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlcdvs.dll
[2005/11/17 20:47:14 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcdcur.dll
[2005/11/17 20:47:12 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcdhbn3.dll
[2005/11/17 20:47:12 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcdcomc.dll
[2005/11/17 20:47:12 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcdcoms.exe
[2005/11/17 20:47:12 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcdcomm.dll
[2005/11/17 20:47:12 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlcdih.exe
[2005/11/17 20:47:12 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.exe
[2005/11/17 20:47:12 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlcdinsb.dll
[2005/11/17 20:47:12 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdins.dll
[2005/11/17 20:47:12 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcdcub.dll
[2005/11/17 20:47:12 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcdcu.dll
[2005/11/17 20:47:12 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.dll
[2005/11/17 20:46:48 | 000,060,928 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2005/11/17 20:46:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2005/11/17 20:46:38 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/11/17 20:46:34 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/11/17 20:46:16 | 000,000,402 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/02 18:05:54 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlcdplc.ini
[2005/05/17 18:17:52 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dlcdcnv4.dll
[2004/09/22 20:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 003,775,584 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,486,540 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,088,424 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/05/12 14:01:12 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\qhtm.dll
[2004/02/21 04:31:10 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\ccvidcl.dll
[2003/06/11 19:39:44 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2002/03/05 19:30:00 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll
========== LOP Check ==========
[2010/09/17 09:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aiseesoft Studio
[2007/02/25 10:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2011/04/23 17:34:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/29 16:35:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2007/05/27 21:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/04/23 17:50:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/31 09:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/02/01 19:59:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2011/05/05 21:42:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/05/10 07:24:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2008/01/21 07:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2011/04/29 16:34:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2008/07/26 09:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2006/12/30 23:53:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/05/30 06:35:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuestScan
[2011/03/19 12:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2007/06/10 11:04:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\starters orders 3
[2011/06/03 06:02:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/28 21:48:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2007/07/01 20:55:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2011/05/08 15:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/25 23:57:47 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{615DB4DC-B7C1-4125-9858-78EF460B76D2}
[2009/04/22 22:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/12/25 23:56:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{9BA38AC8-8A1E-463A-97ED-AE291D3E1A06}
[2006/09/16 20:11:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Acoustica
[2010/12/09 12:21:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo
[2007/06/07 22:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo Photo Commander 4
[2009/05/27 14:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Astro Gemini Software
[2011/04/23 17:52:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/22 13:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Azureus
[2010/05/04 13:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Bump Technologies, Inc
[2009/08/28 23:13:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CBS Interactive
[2007/12/06 19:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CheckPoint
[2009/06/09 13:42:50 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Chessmaster Challenge
[2007/02/02 22:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ConvertTemp
[2009/12/31 09:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DAEMON Tools Pro
[2007/06/14 19:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DataCast
[2009/11/25 19:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\eMusic
[2010/07/25 20:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Foxit Software
[2009/12/06 12:50:41 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\FreeVideoConverter
[2007/09/23 21:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\funkitron
[2009/06/09 13:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\GlarySoft
[2011/05/30 14:09:15 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\gtk-2.0
[2009/05/14 12:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Hrsim
[2011/04/22 12:02:09 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\IObit
[2007/07/15 12:35:44 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\iWin
[2005/11/30 21:19:26 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Leadertech
[2008/08/09 15:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\LimeWire
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ManyCam
[2009/09/02 21:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Moyea
[2009/08/16 22:53:06 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\MP3Rocket
[2010/12/02 20:19:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\NCH Swift Sound
[2008/01/18 22:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Opera
[2010/04/03 13:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PC Suite
[2011/02/26 15:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Philipp Winterberg
[2007/07/15 14:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PPMate
[2010/06/26 07:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Recordpad
[2010/05/27 22:33:34 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Samsung
[2010/02/07 19:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Search Settings
[2011/02/13 00:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Sports Interactive
[2010/12/31 21:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Spotify
[2007/07/06 05:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\StumbleUpon
[2009/09/02 21:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Teleca
[2009/10/24 00:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Temporary
[2007/07/19 20:12:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\TransRender
[2011/06/03 07:57:10 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\uTorrent
[2009/03/24 21:02:57 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\vghd
[2009/07/27 19:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Vso
[2008/01/26 11:55:03 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Windows Desktop Search
[2009/12/06 12:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Xilisoft Corporation
[2011/06/03 10:10:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/06/02 20:40:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/06/02 17:15:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/06/02 14:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2010/08/02 20:24:56 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressripDowngrade.job
[2010/08/02 20:24:57 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressripShakeIcon.job
[2011/06/03 09:54:35 | 000,000,310 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/11/24 22:47:54 | 000,000,735 | —- | M] () – C:\892.cin
[2010/06/02 21:33:44 | 000,000,216 | —- | M] () – C:\ASLog.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/08/11 11:18:33 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/11/03 03:45:47 | 000,003,291 | —- | M] () – C:\data
[2006/01/17 11:43:34 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2005/11/17 20:51:24 | 000,005,148 | RH– | M] () – C:\dell.sdr
[2011/06/03 08:08:53 | 000,058,503 | —- | M] () – C:\dlcd.log
[2010/10/25 20:43:22 | 000,009,432 | —- | M] () – C:\dlcdscan.log
[2009/02/18 22:37:03 | 000,003,532 | —- | M] () – C:\drmHeader.bin
[2006/01/29 14:07:03 | 000,013,312 | —- | M] () – C:\dvb.GRF
[2006/01/28 20:59:03 | 000,008,192 | —- | M] () – C:\dvb4.GRF
[2010/02/21 13:11:54 | 000,000,157 | —- | M] () – C:\error.txt
[2011/06/03 09:54:16 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2010/11/22 22:11:18 | 000,230,424 | —- | M] () – C:\img2-001.raw
[2005/11/24 22:18:42 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2005/11/17 21:11:23 | 000,000,897 | -H– | M] () – C:\IPH.PH
[2010/05/07 19:49:49 | 000,029,887 | —- | M] () – C:\log.txt
[2006/10/08 20:03:52 | 000,000,036 | —- | M] () – C:\mediamp3.dat
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/27 22:24:22 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/06/03 09:54:03 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2006/02/25 15:44:24 | 000,184,320 | —- | M] () – C:\PlayerHost.dll
[2008/06/24 18:14:29 | 000,003,021 | —- | M] () – C:\rollback.ini
[2007/11/08 20:03:17 | 000,000,512 | —- | M] () – C:\ScanSectorLog.dat
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/10 14:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/06/21 04:46:26 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlcdPP5C.DLL
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/04/25 08:58:07 | 000,001,746 | -H– | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 13:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 13:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/27 22:36:59 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2008/06/23 18:36:24 | 000,773,120 | —- | M] () – C:\WINDOWS\system32\NEROINSTAEC43759.DB
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/24 21:16:36 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/06/03 08:22:24 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\chic\desktop\HiJackThis.exe
[2011/06/03 08:16:13 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\desktop\OTL.exe
[2009/05/03 09:04:25 | 003,550,592 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Documents and Settings\chic\desktop\procexp.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2010/05/20 15:27:26 | 000,013,023 | —- | M] () – C:\WINDOWS\VX1000.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-28 03:34:35
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Top 60 albums - November 2005.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Cyberlink:Roxio EMC Stream
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:453B2FDD421AAE3E
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B1CD2545
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:38:30, on 03/06/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17096)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\chic\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~4\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
–
End of file - 8033 bytes
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 8:39:40.50 on 03/06/2011
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.611 [GMT 1:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\chic\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = ;*.local
BHO: HistoryTriggerBHO Class: {21a88cb9-84d2-4020-a2d1-b25a21034884} - c:\program files\lg electronics\lg pc suite iv\linkair\LinkAirBrowserHelper.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\i386\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoInstrumentation = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\mp3 player utilities 4.00\mediamanager\grab.html
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD}
DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/E/1/F/E1F6B9B3-49AA-42BB-9115-D9FB57768CC2/wmavax.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\chic\applic~1\mozilla\firefox\profiles\a8kz582u.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig
FF - prefs.js: keyword.URL - hxxp://www.questscan.com/?tmp=nemo_results_removelink&prt=QstscanPB&keywords=
FF - plugin: c:\documents and settings\chic\local settings\application data\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npBBCPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: g:\program files\itunes\mozilla plugins\npitunes.dll
.
—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-6-4 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-6-1 27576]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-4-22 352656]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-8-10 55152]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [2009-9-29 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [2009-9-29 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [2009-9-29 12928]
R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [2005-6-17 17664]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\drivers\ntcdrdrv.sys –> c:\windows\system32\drivers\ntcdrdrv.sys [?]
S2 Ca536av;5.0M MPEG4 DV Video Capture;c:\windows\system32\drivers\Ca536av.sys [2005-12-19 514155]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-18 136176]
S3 ambitucm;Ambit USB Cable Modem NDIS Driver;c:\windows\system32\drivers\ambitucm.sys [2005-11-24 14974]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys –> c:\windows\system32\drivers\lgandbus.sys [?]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2011-5-10 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2011-5-10 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys –> c:\windows\system32\drivers\lgandmodem.sys [?]
S3 AndNetDiag;LG AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys –> c:\windows\system32\drivers\lgandnetdiag.sys [?]
S3 AndNetGps;LG AndroidNet USB GPS NMEA Port;c:\windows\system32\drivers\lgandnetgps.sys –> c:\windows\system32\drivers\lgandnetgps.sys [?]
S3 ANDNetModem;LG AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys –> c:\windows\system32\drivers\lgandnetmodem.sys [?]
S3 andnetndis;LG AndroidNet NDIS Ethernet Adapter;c:\windows\system32\drivers\lgandnetndis.sys –> c:\windows\system32\drivers\lgandnetndis.sys [?]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2007-12-30 16512]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]
S3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\drivers\DTV_Capture_2X0.sys [2005-12-25 18432]
S3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\drivers\DTV_Loader_2X1.sys [2005-12-25 19328]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-4-3 36608]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-6-18 136176]
S3 k600bus;Sony Ericsson 600i driver (WDM);c:\windows\system32\drivers\k600bus.sys [2005-5-11 52384]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;c:\windows\system32\drivers\k600mdfl.sys [2005-5-11 6096]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;c:\windows\system32\drivers\k600mdm.sys [2005-5-11 87456]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;c:\windows\system32\drivers\k600mgmt.sys [2005-5-11 79248]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\k600obex.sys [2005-5-11 77072]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\manycam.sys –> c:\windows\system32\drivers\ManyCam.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-6-25 35088]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-10 14336]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-4-3 233472]
.
=============== Created Last 30 ================
.
2011-06-03 07:36:31 116224 —-a-w- c:\windows\system32\drivers\1484.sys
2011-06-03 07:12:04 116224 —-a-w- c:\windows\system32\drivers\148D.sys
2011-06-03 07:08:00 116224 —-a-w- c:\windows\system32\drivers\2993.sys
2011-06-03 06:56:08 116224 —-a-w- c:\windows\system32\drivers\2004.sys
2011-06-03 06:48:44 116224 —-a-w- c:\windows\system32\drivers\1844.sys
2011-06-03 04:58:51 4224 —-a-w- c:\windows\system32\beep.sys
2011-05-31 16:15:28 ——– d—–w- c:\windows\Cache
2011-05-31 16:15:27 ——– d—–w- c:\program files\Coupons
2011-05-31 16:15:16 ——– d—–w- c:\docume~1\chic\applic~1\HpUpdate
2011-05-31 16:14:21 1761128 —-a-w- c:\windows\system32\HPScanMiniDrv_DJ1050_J410.dll
2011-05-31 16:14:17 539496 —-a-w- c:\windows\system32\hpinksts8911.dll
2011-05-31 16:14:17 272744 —-a-w- c:\windows\system32\hpinksts8911LM.dll
2011-05-31 16:14:17 201728 —-a-w- c:\windows\system32\hpinkcoi8911.dll
2011-05-31 16:12:18 ——– d—–w- c:\program files\HP
2011-05-31 16:11:53 ——– d—–w- c:\docume~1\chic\locals~1\applic~1\HP
2011-05-26 04:06:16 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-15 19:51:40 ——– d—–w- c:\program files\common files\ODBC
2011-05-15 19:24:36 ——– d—–w- c:\program files\QuestScan
2011-05-15 19:24:36 ——– d—–w- c:\docume~1\alluse~1\applic~1\QuestScan
2011-05-10 06:25:52 20736 —-a-w- c:\windows\system32\drivers\lganddiag.sys
2011-05-10 06:25:52 20096 —-a-w- c:\windows\system32\drivers\lgandgps.sys
2011-05-08 14:50:29 ——– d—–w- c:\program files\iPod
2011-05-08 14:50:24 ——– d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-05-08 14:47:02 ——– d—–w- c:\program files\Bonjour
2011-05-07 17:22:54 ——– d—–w- c:\program files\uTorrent
2011-05-07 17:22:48 ——– d—–w- c:\docume~1\chic\applic~1\uTorrent
2011-05-07 17:22:28 ——– d—–w- c:\docume~1\chic\locals~1\applic~1\uTorrent
2011-05-07 12:05:04 ——– d—–w- c:\windows\system32\winrm
2011-05-07 12:05:04 ——– d—–w- c:\windows\system32\GroupPolicy
2011-05-07 12:04:54 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2011-05-05 20:42:27 ——– d—–w- c:\docume~1\alluse~1\applic~1\IObit
.
==================== Find3M ====================
.
2011-04-23 05:56:36 285480 —-a-w- c:\windows\system32\guard32.dll
2011-04-06 15:20:16 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20:16 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 15:20:16 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 15:20:16 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-03-11 14:10:38 471552 —-a-w- c:\windows\apppatch\aclayers.dll
2011-03-07 05:33:50 692736 —-a-w- c:\windows\system32\inetcomm.dll
.
============= FINISH: 8:41:07.59 ===============
After running Malwarebytes Anti-Malware certain viruses were highlighted that hid the desktop, the task manager and certain drive properties.
The desktop and task manager are now visible but the fake alerts persist and various parts of programs don't run.
I have followed your advice re OTL, HiJack This and DDS.
While running OTL I received an Access Violation alert and the program stalled on "creating restore point - DO NOT INTERRUPT", therefore I do not have the requested log files for this program. (I have re-run OTL and it completed the run - providing an OTL.txt file which I have loaded before the HiJack This file.)
The others are listed below.
Any help would be appreciated. Thank you.
OTL logfile created on: 03/06/2011 12:21:49 - Run 8
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\chic\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1022.07 Mb Total Physical Memory | 632.00 Mb Available Physical Memory | 61.83% Memory free
2.40 Gb Paging File | 2.18 Gb Available in Paging File | 90.66% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.24 Gb Total Space | 109.40 Gb Free Space | 75.33% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 825.10 Gb Free Space | 88.58% Space Free | Partition Type: NTFS
Computer Name: AMANCHIC | User Name: chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.57\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\chic\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (IDriverT) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (CTUPnPSv) – C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe (Creative Technology Ltd)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (VX1000) – C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (LgBttPort) – C:\WINDOWS\system32\drivers\lgbtport.sys (LG Electronics Inc.)
DRV - (LGVMODEM) – C:\WINDOWS\system32\drivers\lgvmodem.sys (LG Electronics Inc.)
DRV - (lgbusenum) – C:\WINDOWS\system32\drivers\lgbtbus.sys (LG Electronics Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (s716unic) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM) – C:\WINDOWS\system32\drivers\s716unic.sys (MCCI Corporation)
DRV - (s716obex) – C:\WINDOWS\system32\drivers\s716obex.sys (MCCI Corporation)
DRV - (s716nd5) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS) – C:\WINDOWS\system32\drivers\s716nd5.sys (MCCI Corporation)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mgmt) Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s716mgmt.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) Sony Ericsson Device 716 driver (WDM) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (ElbyCDFL) – C:\WINDOWS\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (DTV_Loader_2X1) – C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys (WideView Technology Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (k600obex) – C:\WINDOWS\system32\drivers\k600obex.sys (MCCI)
DRV - (k600mgmt) – C:\WINDOWS\system32\drivers\k600mgmt.sys (MCCI)
DRV - (k600mdm) – C:\WINDOWS\system32\drivers\k600mdm.sys (MCCI)
DRV - (k600mdfl) – C:\WINDOWS\system32\drivers\k600mdfl.sys (MCCI)
DRV - (k600bus) Sony Ericsson 600i driver (WDM) – C:\WINDOWS\system32\drivers\k600bus.sys (MCCI)
DRV - (DTV_Capture_2X0) – C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys (Computer & Entertainment, Inc.)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ca536av) – C:\WINDOWS\system32\drivers\Ca536av.sys (Digital Camera)
DRV - (USBCamera) – C:\WINDOWS\system32\drivers\Bulk536.sys (USB BULK)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (usbcm) – C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (ambitucm) – C:\WINDOWS\system32\drivers\ambitucm.sys (Ambit Microsystems Corp)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.search.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/ig"
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..keyword.URL: "http://www.questscan.com/?tmp=nemo_results_removelink&prt=QstscanPB&keywords="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - HKLM\software\mozilla\Firefox\Extensions\\{82081B3D-393D-4389-85A9-8DBBF6AB896B}: C:\Documents and Settings\chic\Local Settings\Application Data\{82081B3D-393D-4389-85A9-8DBBF6AB896B}
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/31 17:15:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/31 17:15:28 | 000,000,000 | —D | M]
[2008/12/20 16:53:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Extensions
[2011/06/02 08:00:59 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Nagra3 Community Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\{04666517-d7b9-43c9-b329-cd7a30ff0079}(2)
[2011/03/14 19:42:39 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\engine@conduit(2).com
[2011/03/12 09:11:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\extensions\[removed]
[2011/01/22 21:07:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions
[2007/07/01 12:49:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2007/01/11 07:37:51 | 000,000,000 | —D | M] (TV Guide UK Toolbar) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{98cb2cc5-46e6-4622-aa41-ce2f64fbfcff}
[2007/04/03 20:21:22 | 000,000,000 | —D | M] (StumbleUpon) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\kcfxidsl.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/01/22 21:07:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions
[2011/01/22 21:07:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\zbtwfzxo.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2009/04/11 15:17:33 | 000,000,681 | -H– | M] () – C:\Documents and Settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\searchplugins\ask.xml
[2011/05/28 04:34:33 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/23 19:19:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/08/13 00:45:50 | 000,000,000 | —D | M] (Search Settings Plugin) – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\CHIC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\A8KZ582U.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
[2010/07/23 19:19:21 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/04/14 17:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/02/27 17:57:38 | 000,106,496 | —- | M] (British Broadcasting Corporation) – C:\Program Files\Mozilla Firefox\plugins\npBBCPlugin.dll
[2009/11/06 16:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/07/23 19:19:21 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/24 20:10:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2009/11/06 16:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/04/29 19:58:19 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HistoryTriggerBHO Class) - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Stumble&Upon) - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1927.dll (StumbleUpon.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/E/1…8CC2/wmavax.CAB (Reg Error: Value error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/02/04 18:05:36 | 000,000,000 | RH-D | M] - G:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 13:56:50 | 000,000,036 | RH– | M] () - G:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{612bcee4-2990-11dc-acc8-000e9bea7207}\Shell\AutoRun\command - "" = J:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Intel Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave8 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)
========== Files/Folders - Created Within 30 Days ==========
[2011/06/03 08:16:19 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/06/03 05:58:51 | 000,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\beep.sys
[2011/06/03 05:55:56 | 000,000,000 | RH-D | C] – C:\Documents and Settings\chic\Recent
[2011/06/01 21:18:40 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\EverioBackup
[2011/05/31 17:15:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Coupons
[2011/05/31 17:15:28 | 000,000,000 | —D | C] – C:\WINDOWS\Cache
[2011/05/31 17:15:27 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2011/05/31 17:15:16 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\HpUpdate
[2011/05/31 17:14:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\HP
[2011/05/31 17:14:21 | 001,761,128 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\HPScanMiniDrv_DJ1050_J410.dll
[2011/05/31 17:14:17 | 000,539,496 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinksts8911.dll
[2011/05/31 17:14:17 | 000,272,744 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinksts8911LM.dll
[2011/05/31 17:14:17 | 000,201,728 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinkcoi8911.dll
[2011/05/31 17:12:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP
[2011/05/31 17:12:18 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/05/31 17:11:53 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Local Settings\Application Data\HP
[2011/05/31 11:13:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2011/05/31 05:19:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Free YouTube Downloader
[2011/05/26 05:06:16 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/15 20:51:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ODBC
[2011/05/15 20:24:36 | 000,000,000 | —D | C] – C:\Program Files\QuestScan
[2011/05/15 20:24:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\QuestScan
[2011/05/10 07:25:52 | 000,020,736 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lganddiag.sys
[2011/05/10 07:25:52 | 000,020,096 | —- | C] (LG Electronics Inc.) – C:\WINDOWS\System32\drivers\lgandgps.sys
[2011/05/10 06:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\LG PC Suite IV
[2011/05/08 15:55:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\My Music
[2011/05/08 15:52:22 | 000,000,000 | -H-D | C] – C:\Documents and Settings\chic\My Documents\iTunes
[2011/05/08 15:51:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/05/08 15:50:29 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/05/08 15:50:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/05/08 15:49:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/05/08 15:49:05 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/05/08 15:47:52 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/05/08 15:47:02 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/07 18:22:54 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2011/05/07 18:22:48 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Application Data\uTorrent
[2011/05/07 18:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\chic\Local Settings\Application Data\uTorrent
[2011/05/07 13:05:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\WindowsPowerShell
[2011/05/07 13:05:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\winrm
[2011/05/07 13:05:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\GroupPolicy
[2011/05/07 13:04:54 | 000,000,000 | -H-D | C] – C:\WINDOWS\$968930Uinstall_KB968930$
[2011/05/05 21:42:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\IObit
[2008/07/24 20:38:14 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\chic\Application Data\pcouffin.sys
[2005/11/17 20:46:48 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
========== Files - Modified Within 30 Days ==========
[2011/06/03 12:17:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/03 11:40:12 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
[2011/06/03 11:40:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
[2011/06/03 10:10:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/06/03 09:55:11 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\6824.sys
[2011/06/03 09:55:04 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/03 09:54:35 | 000,000,310 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/06/03 09:54:34 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/03 09:54:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/03 09:54:16 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2011/06/03 08:36:31 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\1484.sys
[2011/06/03 08:22:24 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\chic\Desktop\HiJackThis.exe
[2011/06/03 08:17:09 | 000,625,664 | —- | M] () – C:\Documents and Settings\chic\Desktop\dds.scr
[2011/06/03 08:16:13 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\Desktop\OTL.exe
[2011/06/03 08:12:04 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\148D.sys
[2011/06/03 08:08:00 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\2993.sys
[2011/06/03 07:57:12 | 000,107,232 | —- | M] () – C:\Documents and Settings\chic\Application Data\25327-utorrent.1509.dmp
[2011/06/03 07:56:08 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\2004.sys
[2011/06/03 07:48:44 | 000,116,224 | —- | M] () – C:\WINDOWS\System32\drivers\1844.sys
[2011/06/03 05:28:35 | 000,000,152 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~20045604r
[2011/06/03 05:28:35 | 000,000,136 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~20045604
[2011/06/03 05:28:22 | 000,000,336 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\20045604
[2011/06/02 20:40:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/06/02 17:15:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/06/02 14:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/05/31 17:14:23 | 000,001,981 | —- | M] () – C:\Documents and Settings\All Users\Desktop\printer.lnk
[2011/05/31 14:16:29 | 000,000,625 | —- | M] () – C:\Documents and Settings\chic\Desktop\Glary Utilities.lnk
[2011/05/31 05:19:56 | 000,000,730 | —- | M] () – C:\Documents and Settings\All Users\Desktop\yt.lnk
[2011/05/30 14:09:15 | 000,001,578 | -H– | M] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/05/30 14:08:48 | 000,000,079 | -H– | M] () – C:\Documents and Settings\chic\.gtk-bookmarks
[2011/05/29 08:29:31 | 000,843,136 | -H– | M] () – C:\Documents and Settings\chic\My Documents\Coastal-Trail.pdf
[2011/05/29 02:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
[2011/05/28 08:55:55 | 000,112,952 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/27 18:10:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/26 05:06:16 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/10 10:59:49 | 000,002,413 | —- | M] () – C:\WINDOWS\System32\lgAxconfig.ini
[2011/05/09 23:09:37 | 000,000,742 | —- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/09 23:09:37 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/05/08 15:51:13 | 000,001,452 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/07 13:05:56 | 000,486,540 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/05/07 13:05:56 | 000,088,424 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/05/05 21:34:23 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk
========== Files Created - No Company Name ==========
[2011/06/03 09:55:11 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\6824.sys
[2011/06/03 08:36:31 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\1484.sys
[2011/06/03 08:17:10 | 000,625,664 | —- | C] () – C:\Documents and Settings\chic\Desktop\dds.scr
[2011/06/03 08:12:04 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\148D.sys
[2011/06/03 08:08:00 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\2993.sys
[2011/06/03 07:57:11 | 000,107,232 | —- | C] () – C:\Documents and Settings\chic\Application Data\25327-utorrent.1509.dmp
[2011/06/03 07:56:08 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\2004.sys
[2011/06/03 07:48:44 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\drivers\1844.sys
[2011/06/03 05:57:10 | 1071,796,224 | -HS- | C] () – C:\hiberfil.sys
[2011/06/03 05:28:35 | 000,000,152 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~20045604r
[2011/06/03 05:28:35 | 000,000,136 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~20045604
[2011/06/03 05:28:22 | 000,000,336 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\20045604
[2011/05/31 17:15:13 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At4.job
[2011/05/31 17:15:12 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At3.job
[2011/05/31 17:15:12 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At2.job
[2011/05/31 17:15:12 | 000,000,464 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2011/05/31 17:14:23 | 000,001,981 | —- | C] () – C:\Documents and Settings\All Users\Desktop\printer.lnk
[2011/05/31 05:19:56 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Desktop\yt.lnk
[2011/05/30 14:09:15 | 000,001,578 | -H– | C] () – C:\Documents and Settings\chic\.recently-used.xbel
[2011/05/30 14:08:48 | 000,000,079 | -H– | C] () – C:\Documents and Settings\chic\.gtk-bookmarks
[2011/05/29 08:32:03 | 000,843,136 | -H– | C] () – C:\Documents and Settings\chic\My Documents\Coastal-Trail.pdf
[2011/05/28 08:55:55 | 000,112,952 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/08 15:51:13 | 000,001,452 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/08 15:47:55 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/05 21:34:23 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk
[2011/04/27 05:16:13 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/04/04 20:46:47 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/01/12 23:17:12 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2011/01/12 23:17:12 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2010/10/29 20:49:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2010/10/05 00:59:32 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\StarOpen.sys
[2010/06/25 18:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/18 20:02:41 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/04/03 10:41:50 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/04/03 10:41:50 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/04/03 10:41:37 | 000,002,528 | -H– | C] () – C:\Documents and Settings\chic\Application Data\$_hpcst$.hpc
[2010/03/26 21:46:21 | 000,000,108 | -H– | C] () – C:\Documents and Settings\chic\Application Data\default.pls
[2010/02/12 18:01:25 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/31 22:59:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2010/01/31 22:59:11 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2009/11/19 21:29:03 | 000,015,498 | —- | C] () – C:\WINDOWS\VX1000.ini
[2009/09/27 21:58:46 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/09/26 22:30:54 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/09/09 07:17:00 | 000,017,510 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/06/19 20:18:06 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2009/05/13 08:05:19 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/03/24 20:49:18 | 000,000,007 | —- | C] () – C:\WINDOWS\sbacknt.bin
[2008/11/14 12:31:34 | 000,000,168 | —- | C] () – C:\WINDOWS\netg.ini
[2008/11/14 12:31:34 | 000,000,093 | —- | C] () – C:\WINDOWS\skillv.ini
[2008/10/25 21:37:33 | 000,048,396 | —- | C] () – C:\WINDOWS\UninstVeetleTVPlayer.exe
[2008/07/24 20:39:10 | 000,081,920 | —- | C] () – C:\Documents and Settings\chic\Application Data\ezpinst.exe
[2008/07/24 20:38:14 | 000,007,176 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.cat
[2008/07/24 20:38:10 | 000,001,144 | —- | C] () – C:\Documents and Settings\chic\Application Data\pcouffin.inf
[2008/06/23 19:12:12 | 000,000,065 | —- | C] () – C:\WINDOWS\FISHUI.INI
[2008/03/05 21:23:28 | 000,002,104 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/05 21:23:26 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/02/03 10:38:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/12/08 20:23:23 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNWISE.EXE
[2007/07/11 22:06:05 | 000,000,127 | -H– | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\fusioncache.dat
[2007/06/14 19:54:54 | 000,044,440 | —- | C] () – C:\WINDOWS\System32\MtpAccess.dll
[2007/06/14 18:59:33 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\LAME_MP3.dll
[2007/06/14 18:59:19 | 000,065,024 | —- | C] () – C:\WINDOWS\IFinst26.exe
[2007/05/12 00:19:17 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/03/01 00:39:47 | 000,000,120 | —- | C] () – C:\WINDOWS\PbkUser.INI
[2007/02/05 15:24:28 | 000,018,271 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2007/02/05 15:24:26 | 000,099,999 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/01/24 23:12:53 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/01/24 23:12:40 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/01/03 12:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 23:59:04 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/10/26 21:09:34 | 000,036,864 | —- | C] () – C:\WINDOWS\uneng.exe
[2006/10/08 20:09:58 | 000,000,072 | —- | C] () – C:\WINDOWS\MediaManager.INI
[2006/07/19 20:26:15 | 000,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2006/05/22 10:26:06 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2006/04/16 20:23:19 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/03/05 14:21:03 | 000,099,840 | —- | C] () – C:\WINDOWS\System32\UnCasino5.exe
[2006/01/15 20:30:10 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/12/19 19:14:11 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2005/12/04 00:14:05 | 000,001,771 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/25 07:14:32 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/24 23:45:56 | 000,120,832 | —- | C] () – C:\Documents and Settings\chic\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/11/24 23:04:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/11/24 22:44:58 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2005/11/17 21:23:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/17 21:17:33 | 000,099,965 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2005/11/17 21:17:32 | 000,005,485 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/11/17 21:16:40 | 000,000,777 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/17 21:13:29 | 000,000,484 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/17 21:10:11 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/11/17 21:09:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2005/11/17 21:09:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2005/11/17 21:09:30 | 000,000,072 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2005/11/17 20:47:14 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlcdserv.dll
[2005/11/17 20:47:14 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlcdusb1.dll
[2005/11/17 20:47:14 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlcdpmui.dll
[2005/11/17 20:47:14 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcdlmpm.dll
[2005/11/17 20:47:14 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlcdutil.dll
[2005/11/17 20:47:14 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdprox.dll
[2005/11/17 20:47:14 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlcdjswr.dll
[2005/11/17 20:47:14 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlcdpplc.dll
[2005/11/17 20:47:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlcdinsr.dll
[2005/11/17 20:47:14 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlcdvs.dll
[2005/11/17 20:47:14 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcdcur.dll
[2005/11/17 20:47:12 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcdhbn3.dll
[2005/11/17 20:47:12 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcdcomc.dll
[2005/11/17 20:47:12 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcdcoms.exe
[2005/11/17 20:47:12 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcdcomm.dll
[2005/11/17 20:47:12 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlcdih.exe
[2005/11/17 20:47:12 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.exe
[2005/11/17 20:47:12 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlcdinsb.dll
[2005/11/17 20:47:12 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdins.dll
[2005/11/17 20:47:12 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcdcub.dll
[2005/11/17 20:47:12 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcdcu.dll
[2005/11/17 20:47:12 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.dll
[2005/11/17 20:46:48 | 000,060,928 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2005/11/17 20:46:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2005/11/17 20:46:38 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/11/17 20:46:34 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/11/17 20:46:16 | 000,000,402 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/02 18:05:54 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlcdplc.ini
[2005/05/17 18:17:52 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dlcdcnv4.dll
[2004/09/22 20:17:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 14:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:57:15 | 003,775,584 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 13:51:20 | 000,486,540 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 13:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 13:51:20 | 000,088,424 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 13:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 13:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 13:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 13:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 13:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 13:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 13:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 13:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/05/12 14:01:12 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\qhtm.dll
[2004/02/21 04:31:10 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\ccvidcl.dll
[2003/06/11 19:39:44 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2002/03/05 19:30:00 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll
========== LOP Check ==========
[2010/09/17 09:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aiseesoft Studio
[2007/02/25 10:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2011/04/23 17:34:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/29 16:35:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2007/05/27 21:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/04/23 17:50:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/31 09:32:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/02/01 19:59:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2011/05/05 21:42:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/05/10 07:24:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2008/01/21 07:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2011/04/29 16:34:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2008/07/26 09:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2010/12/27 17:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2006/12/30 23:53:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/05/30 06:35:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuestScan
[2011/03/19 12:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2007/06/10 11:04:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/12/27 17:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\starters orders 3
[2011/06/03 06:02:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/28 21:48:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2007/07/01 20:55:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/12/30 23:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2011/05/08 15:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/25 23:57:47 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{615DB4DC-B7C1-4125-9858-78EF460B76D2}
[2009/04/22 22:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/12/25 23:56:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{9BA38AC8-8A1E-463A-97ED-AE291D3E1A06}
[2006/09/16 20:11:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Acoustica
[2010/12/09 12:21:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo
[2007/06/07 22:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Ashampoo Photo Commander 4
[2009/05/27 14:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Astro Gemini Software
[2011/04/23 17:52:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\AVG10
[2011/04/22 13:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Azureus
[2010/05/04 13:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Bump Technologies, Inc
[2009/08/28 23:13:31 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CBS Interactive
[2007/12/06 19:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\CheckPoint
[2009/06/09 13:42:50 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Chessmaster Challenge
[2007/02/02 22:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ConvertTemp
[2009/12/31 09:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DAEMON Tools Pro
[2007/06/14 19:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\DataCast
[2009/11/25 19:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\eMusic
[2010/07/25 20:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Foxit Software
[2009/12/06 12:50:41 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\FreeVideoConverter
[2007/09/23 21:25:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\funkitron
[2009/06/09 13:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\GlarySoft
[2011/05/30 14:09:15 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\gtk-2.0
[2009/05/14 12:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Hrsim
[2011/04/22 12:02:09 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\IObit
[2007/07/15 12:35:44 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\iWin
[2005/11/30 21:19:26 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Leadertech
[2008/08/09 15:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\LimeWire
[2010/09/14 21:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\ManyCam
[2009/09/02 21:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Moyea
[2009/08/16 22:53:06 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\MP3Rocket
[2010/12/02 20:19:43 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\NCH Swift Sound
[2008/01/18 22:16:56 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Opera
[2010/04/03 13:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PC Suite
[2011/02/26 15:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Philipp Winterberg
[2007/07/15 14:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\PPMate
[2010/06/26 07:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Recordpad
[2010/05/27 22:33:34 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Samsung
[2010/02/07 19:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Search Settings
[2011/02/13 00:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Sports Interactive
[2010/12/31 21:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Spotify
[2007/07/06 05:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\StumbleUpon
[2009/09/02 21:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Teleca
[2009/10/24 00:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Temporary
[2007/07/19 20:12:51 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\TransRender
[2011/06/03 07:57:10 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\uTorrent
[2009/03/24 21:02:57 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\vghd
[2009/07/27 19:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Vso
[2008/01/26 11:55:03 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Windows Desktop Search
[2009/12/06 12:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\chic\Application Data\Xilisoft Corporation
[2011/06/03 10:10:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/06/02 20:40:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/06/02 17:15:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/06/02 14:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2010/08/02 20:24:56 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressripDowngrade.job
[2010/08/02 20:24:57 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressripShakeIcon.job
[2011/06/03 09:54:35 | 000,000,310 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/11/24 22:47:54 | 000,000,735 | —- | M] () – C:\892.cin
[2010/06/02 21:33:44 | 000,000,216 | —- | M] () – C:\ASLog.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/08/11 11:18:33 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/11/03 03:45:47 | 000,003,291 | —- | M] () – C:\data
[2006/01/17 11:43:34 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2005/11/17 20:51:24 | 000,005,148 | RH– | M] () – C:\dell.sdr
[2011/06/03 08:08:53 | 000,058,503 | —- | M] () – C:\dlcd.log
[2010/10/25 20:43:22 | 000,009,432 | —- | M] () – C:\dlcdscan.log
[2009/02/18 22:37:03 | 000,003,532 | —- | M] () – C:\drmHeader.bin
[2006/01/29 14:07:03 | 000,013,312 | —- | M] () – C:\dvb.GRF
[2006/01/28 20:59:03 | 000,008,192 | —- | M] () – C:\dvb4.GRF
[2010/02/21 13:11:54 | 000,000,157 | —- | M] () – C:\error.txt
[2011/06/03 09:54:16 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2010/11/22 22:11:18 | 000,230,424 | —- | M] () – C:\img2-001.raw
[2005/11/24 22:18:42 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2005/11/17 21:11:23 | 000,000,897 | -H– | M] () – C:\IPH.PH
[2010/05/07 19:49:49 | 000,029,887 | —- | M] () – C:\log.txt
[2006/10/08 20:03:52 | 000,000,036 | —- | M] () – C:\mediamp3.dat
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/27 22:24:22 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/06/03 09:54:03 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2006/02/25 15:44:24 | 000,184,320 | —- | M] () – C:\PlayerHost.dll
[2008/06/24 18:14:29 | 000,003,021 | —- | M] () – C:\rollback.ini
[2007/11/08 20:03:17 | 000,000,512 | —- | M] () – C:\ScanSectorLog.dat
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/10 14:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/06/21 04:46:26 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlcdPP5C.DLL
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/04/25 08:58:07 | 000,001,746 | -H– | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 13:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 13:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/27 22:36:59 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2008/06/23 18:36:24 | 000,773,120 | —- | M] () – C:\WINDOWS\system32\NEROINSTAEC43759.DB
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/24 21:16:36 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\chic\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/06/03 08:22:24 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\chic\desktop\HiJackThis.exe
[2011/06/03 08:16:13 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\chic\desktop\OTL.exe
[2009/05/03 09:04:25 | 003,550,592 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Documents and Settings\chic\desktop\procexp.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2010/05/20 15:27:26 | 000,013,023 | —- | M] () – C:\WINDOWS\VX1000.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-28 03:34:35
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Top 60 albums - November 2005.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\chic\My Documents\Cyberlink:Roxio EMC Stream
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:453B2FDD421AAE3E
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B1CD2545
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:38:30, on 03/06/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17096)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\chic\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~4\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
–
End of file - 8033 bytes
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 8:39:40.50 on 03/06/2011
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.611 [GMT 1:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\chic\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = ;*.local
BHO: HistoryTriggerBHO Class: {21a88cb9-84d2-4020-a2d1-b25a21034884} - c:\program files\lg electronics\lg pc suite iv\linkair\LinkAirBrowserHelper.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\i386\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoInstrumentation = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\mp3 player utilities 4.00\mediamanager\grab.html
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD}
DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/E/1/F/E1F6B9B3-49AA-42BB-9115-D9FB57768CC2/wmavax.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\chic\applic~1\mozilla\firefox\profiles\a8kz582u.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig
FF - prefs.js: keyword.URL - hxxp://www.questscan.com/?tmp=nemo_results_removelink&prt=QstscanPB&keywords=
FF - plugin: c:\documents and settings\chic\local settings\application data\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npBBCPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: g:\program files\itunes\mozilla plugins\npitunes.dll
.
—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-6-4 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-6-1 27576]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-4-22 352656]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-8-10 55152]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [2009-9-29 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [2009-9-29 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [2009-9-29 12928]
R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [2005-6-17 17664]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\drivers\ntcdrdrv.sys –> c:\windows\system32\drivers\ntcdrdrv.sys [?]
S2 Ca536av;5.0M MPEG4 DV Video Capture;c:\windows\system32\drivers\Ca536av.sys [2005-12-19 514155]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-18 136176]
S3 ambitucm;Ambit USB Cable Modem NDIS Driver;c:\windows\system32\drivers\ambitucm.sys [2005-11-24 14974]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys –> c:\windows\system32\drivers\lgandbus.sys [?]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2011-5-10 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2011-5-10 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys –> c:\windows\system32\drivers\lgandmodem.sys [?]
S3 AndNetDiag;LG AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys –> c:\windows\system32\drivers\lgandnetdiag.sys [?]
S3 AndNetGps;LG AndroidNet USB GPS NMEA Port;c:\windows\system32\drivers\lgandnetgps.sys –> c:\windows\system32\drivers\lgandnetgps.sys [?]
S3 ANDNetModem;LG AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys –> c:\windows\system32\drivers\lgandnetmodem.sys [?]
S3 andnetndis;LG AndroidNet NDIS Ethernet Adapter;c:\windows\system32\drivers\lgandnetndis.sys –> c:\windows\system32\drivers\lgandnetndis.sys [?]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2007-12-30 16512]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]
S3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\drivers\DTV_Capture_2X0.sys [2005-12-25 18432]
S3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\drivers\DTV_Loader_2X1.sys [2005-12-25 19328]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-4-3 36608]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-6-18 136176]
S3 k600bus;Sony Ericsson 600i driver (WDM);c:\windows\system32\drivers\k600bus.sys [2005-5-11 52384]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;c:\windows\system32\drivers\k600mdfl.sys [2005-5-11 6096]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;c:\windows\system32\drivers\k600mdm.sys [2005-5-11 87456]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;c:\windows\system32\drivers\k600mgmt.sys [2005-5-11 79248]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\k600obex.sys [2005-5-11 77072]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\manycam.sys –> c:\windows\system32\drivers\ManyCam.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-6-25 35088]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-10 14336]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-4-3 233472]
.
=============== Created Last 30 ================
.
2011-06-03 07:36:31 116224 —-a-w- c:\windows\system32\drivers\1484.sys
2011-06-03 07:12:04 116224 —-a-w- c:\windows\system32\drivers\148D.sys
2011-06-03 07:08:00 116224 —-a-w- c:\windows\system32\drivers\2993.sys
2011-06-03 06:56:08 116224 —-a-w- c:\windows\system32\drivers\2004.sys
2011-06-03 06:48:44 116224 —-a-w- c:\windows\system32\drivers\1844.sys
2011-06-03 04:58:51 4224 —-a-w- c:\windows\system32\beep.sys
2011-05-31 16:15:28 ——– d—–w- c:\windows\Cache
2011-05-31 16:15:27 ——– d—–w- c:\program files\Coupons
2011-05-31 16:15:16 ——– d—–w- c:\docume~1\chic\applic~1\HpUpdate
2011-05-31 16:14:21 1761128 —-a-w- c:\windows\system32\HPScanMiniDrv_DJ1050_J410.dll
2011-05-31 16:14:17 539496 —-a-w- c:\windows\system32\hpinksts8911.dll
2011-05-31 16:14:17 272744 —-a-w- c:\windows\system32\hpinksts8911LM.dll
2011-05-31 16:14:17 201728 —-a-w- c:\windows\system32\hpinkcoi8911.dll
2011-05-31 16:12:18 ——– d—–w- c:\program files\HP
2011-05-31 16:11:53 ——– d—–w- c:\docume~1\chic\locals~1\applic~1\HP
2011-05-26 04:06:16 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-15 19:51:40 ——– d—–w- c:\program files\common files\ODBC
2011-05-15 19:24:36 ——– d—–w- c:\program files\QuestScan
2011-05-15 19:24:36 ——– d—–w- c:\docume~1\alluse~1\applic~1\QuestScan
2011-05-10 06:25:52 20736 —-a-w- c:\windows\system32\drivers\lganddiag.sys
2011-05-10 06:25:52 20096 —-a-w- c:\windows\system32\drivers\lgandgps.sys
2011-05-08 14:50:29 ——– d—–w- c:\program files\iPod
2011-05-08 14:50:24 ——– d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-05-08 14:47:02 ——– d—–w- c:\program files\Bonjour
2011-05-07 17:22:54 ——– d—–w- c:\program files\uTorrent
2011-05-07 17:22:48 ——– d—–w- c:\docume~1\chic\applic~1\uTorrent
2011-05-07 17:22:28 ——– d—–w- c:\docume~1\chic\locals~1\applic~1\uTorrent
2011-05-07 12:05:04 ——– d—–w- c:\windows\system32\winrm
2011-05-07 12:05:04 ——– d—–w- c:\windows\system32\GroupPolicy
2011-05-07 12:04:54 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2011-05-05 20:42:27 ——– d—–w- c:\docume~1\alluse~1\applic~1\IObit
.
==================== Find3M ====================
.
2011-04-23 05:56:36 285480 —-a-w- c:\windows\system32\guard32.dll
2011-04-06 15:20:16 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20:16 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 15:20:16 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 15:20:16 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-03-11 14:10:38 471552 —-a-w- c:\windows\apppatch\aclayers.dll
2011-03-07 05:33:50 692736 —-a-w- c:\windows\system32\inetcomm.dll
.
============= FINISH: 8:41:07.59 ===============