hana
Topic Starter
Hello
A month ago, I have the internet redirect virus. I tried many ways to correct this problem including combofix, malwarebytes, restore windows to an earlier date, restore windows with original CD, Fronline Registry Cleaner, CCleaner and etc. Finally the redirect virus problem solved. But after that I have other problems. The computer always runs updating once it is turn off and on, but it fails when updating the files in windows update. I also have problems opening documents in words which was downloaded from the email attached file. Words said that the files are disable due to documents caused serious error last time when they were opened. I also run the Active Recovery software but it can only run once and I can`t use it anymore. Problem with Mozilla and I have to uninstall and re-install. The Malwarebytes also showed a message that it is 20 days not updated but when I press the update button, it showed the "Program_Error_Updating(5,0,create file)".
Please help me on this matter. Below is the OTL.txt and Extras.txt details as requested.
Thank you…..
OTL logfile created on: 6/9/2011 11:42:55 AM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\liynapearl\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd
1.99 Gb Total Physical Memory | 0.92 Gb Available Physical Memory | 46.30% Memory free
3.98 Gb Paging File | 2.82 Gb Available in Paging File | 70.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.91 Gb Total Space | 125.93 Gb Free Space | 58.32% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.78 Gb Free Space | 57.82% Space Free | Partition Type: NTFS
Computer Name: LIYNAPEARL-PC | User Name: Liyna_ADMIN | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\liynapearl\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
PRC - C:\Program Files\Max PC Booster\PCBVistaService.exe (Max Secure Software)
PRC - C:\Program Files\Max PC Booster\PCBSysTray.exe (Max Secure Software.)
PRC - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
PRC - C:\Windows\System32\ChgService.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (SafeList) ==========
MOD - C:\Users\liynapearl\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\IME\IMEJP10\IMJPTIP.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IMJP10K.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\shared\IMETIP.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\IMEJP10\IMJPAPI.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\shared\IMJKAPI.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\shared\imecfm.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (nosGetPlusHelper) getPlus® – File not found
SRV - (PCBVistaSvc) – C:\Program Files\Max PC Booster\PCBVistaService.exe (Max Secure Software)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (SBAMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
SRV - (SBPIMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (TMachInfo) – C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Thpsrv) – C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation)
SRV - (Change Modem Device Service) – C:\Windows\System32\ChgService.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (SbFw) – C:\Windows\System32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (sbhips) – C:\Windows\System32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SbTis) – C:\Windows\System32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (nmwcdnsu) – C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (sbapifs) – C:\Windows\System32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (SBRE) – C:\Windows\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (SBFWIMCLMP) – C:\Windows\System32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) – C:\Windows\System32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (ewusbnet) – C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbdev) – C:\Windows\System32\drivers\ewusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (RSUSBSTOR) – C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV - (Thpevm) – C:\Windows\system32\DRIVERS\Thpevm.SYS (TOSHIBA Corporation)
DRV - (Thpdrv) – C:\Windows\system32\DRIVERS\thpdrv.sys (TOSHIBA Corporation)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (TVALZFL) – C:\Windows\System32\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV - (CLBUDF) – C:\Windows\System32\drivers\CLBUDF.sys (CyberLink Corporation.)
DRV - (CLBStor) – C:\Windows\System32\drivers\CLBStor.sys (Cyberlink Co.,Ltd.)
DRV - (cmnsusbser) – C:\Windows\System32\drivers\cmnsusbser.sys (Mobile Connector)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ja
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 73 07 C0 EE E6 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.jp/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {749474f5-3972-0174-45ff-a63c3dce6339}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.736
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.3.5.20110120033202
FF - prefs.js..extensions.enabledItems: {fe0258ab-4f74-43a1-8781-bcdf340f9ee9}:2.6.4
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.25
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=405&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2011/01/31 10:46:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/03/07 09:16:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/03 23:44:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/03 23:44:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/03/07 09:16:06 | 000,000,000 | —D | M]
[2011/05/04 23:13:06 | 000,000,000 | -H-D | M] (No name found) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Extensions
[2011/06/08 15:23:30 | 000,000,000 | —D | M] (No name found) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions
[2011/05/17 22:00:34 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/05/17 22:00:35 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/06/04 12:25:24 | 000,000,000 | —D | M] (BitComet Video Downloader) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2011/05/18 16:51:15 | 000,000,000 | —D | M] (Redirect Remover) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{fe0258ab-4f74-43a1-8781-bcdf340f9ee9}
[2011/05/17 22:00:34 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\[removed]
[2011/06/05 20:36:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/08 00:11:01 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{749474f5-3972-0174-45ff-a63c3dce6339}
[2011/06/05 20:36:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/03/07 09:16:05 | 000,000,000 | —D | M] (Firefox Synchronisation Extension) – C:\PROGRAM FILES\NOKIA\NOKIA OVI SUITE\CONNECTORS\BOOKMARKS CONNECTOR\FIREFOXEXTENSION
[2011/01/31 10:46:29 | 000,000,000 | —D | M] (PC Sync 2 Synchronisation Extension) – C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC
[2009/10/31 23:16:20 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
File not found (No name found) – C:\PROGRAM FILES\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2010/08/24 18:31:30 | 000,773,120 | —- | M] (BitComet) – C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2011/04/04 14:03:00 | 000,002,046 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml
[2010/10/13 08:38:58 | 000,001,175 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\FLVTube.xml.bak
O1 HOSTS File: ([2011/05/19 19:03:50 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (i-フィルター 5.0 ブラウザヘルパー) - {0FAF6F52-1AD4-4282-9EA1-3EC884DA7AA3} - C:\Program Files\Digital Arts\IFP5\app\bin\ifp5toolbar.dll (デジタルアーツ株式会社)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.12.6.dll (BitComet)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [InstantBurn] C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
O4 - HKLM..\Run: [PCBSystemTray] C:\Program Files\Max PC Booster\PCBSysTray.exe (Max Secure Software.)
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
O4 - HKLM..\Run: [ThpSrv] C:\Windows\System32\thpsrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\RunOnce: [*WerKernelReporting] C:\Windows\System32\WerFault.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all links using BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Download link using &BitComet; - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.12.6.dll (BitComet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll (Installation Support)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 06:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
========== Files/Folders - Created Within 30 Days ==========
[2011/06/05 20:26:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2011/06/05 20:26:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/06/05 20:25:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2011/06/05 20:23:13 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2011/06/05 20:21:56 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2011/06/05 20:19:22 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2011/06/05 20:17:26 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Analysis Services
[2011/06/05 20:14:45 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/06/03 23:44:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/06/03 23:33:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011/06/03 23:33:41 | 000,000,000 | —D | C] – C:\Program Files\7-Zip
[2011/06/03 01:02:54 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\poqexec.exe
[2011/06/03 01:02:52 | 000,026,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2011/06/02 11:42:22 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Roaming\CyberLink
[2011/06/02 11:39:59 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Local\Power2Go
[2011/06/02 11:27:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
[2011/06/02 11:27:54 | 000,161,704 | —- | C] (CyberLink Corporation.) – C:\Windows\System32\drivers\CLBUDF.sys
[2011/06/02 11:27:54 | 000,015,784 | —- | C] (Cyberlink Co.,Ltd.) – C:\Windows\System32\drivers\CLBStor.sys
[2011/06/02 11:27:27 | 000,000,000 | —D | C] – C:\Program Files\CyberLink
[2011/06/02 11:27:13 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2011/06/01 22:42:24 | 000,000,000 | —D | C] – C:\Program Files\LSoft Technologies
[2011/06/01 22:42:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ File Recovery
[2011/05/29 11:38:21 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2011/05/20 13:04:19 | 000,000,000 | -H-D | C] – C:\Windows\PIF
[2011/05/20 09:59:00 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/20 09:59:00 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/20 09:58:59 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/20 09:58:59 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/20 09:58:59 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/20 09:58:59 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/20 09:58:59 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/20 09:58:59 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/20 09:58:59 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/20 09:58:59 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/20 09:58:59 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/20 09:58:59 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/20 09:58:59 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/20 09:58:59 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/20 09:58:59 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/20 09:58:59 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/20 09:58:59 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/20 09:58:59 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/20 09:58:59 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/20 09:58:56 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/20 09:58:56 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/20 09:58:56 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/20 09:58:56 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/20 09:58:56 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/20 09:58:56 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/20 09:58:56 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/20 09:58:56 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/20 09:58:56 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/20 09:58:56 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/20 09:58:56 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/20 09:58:56 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/20 09:58:56 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/20 09:58:56 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/20 09:58:56 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/20 09:58:56 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/20 09:58:56 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/20 09:58:56 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/20 09:58:56 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/20 09:58:56 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/20 09:48:34 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Roaming\yahoo!
[2011/05/19 23:18:42 | 000,000,000 | —D | C] – C:\FORMS
[2011/05/19 19:08:24 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/05/19 19:08:17 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Local\temp
[2011/05/19 19:05:04 | 000,000,000 | —D | C] – C:\Microsoft
[2011/05/19 18:46:37 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2011/05/19 13:28:36 | 000,000,000 | —D | C] – C:\ProgramData\FrontLine Registry Cleaner
[2011/05/19 13:25:55 | 000,000,000 | —D | C] – C:\temp
[2011/05/19 13:25:13 | 000,000,000 | —D | C] – C:\Program Files\Frontline Registry Cleaner 2010 v1.25
[2011/05/19 12:48:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Frontline Registry Cleaner
[2011/05/19 12:48:37 | 000,000,000 | —D | C] – C:\Program Files\Frontline Registry Cleaner
[2011/05/19 12:13:03 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/05/19 12:13:03 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/05/19 12:13:03 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/05/19 12:12:46 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/05/19 12:10:00 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/19 10:30:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/05/18 23:41:33 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Roaming\Malwarebytes
[2011/05/18 23:41:09 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/18 23:41:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/18 23:41:08 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/18 23:41:05 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/18 10:15:51 | 000,000,000 | —D | C] – C:\w
[2011/05/18 10:15:50 | 000,000,000 | —D | C] – C:\Cache
[2011/05/18 10:15:45 | 000,000,000 | —D | C] – C:\e
[2011/05/17 17:10:12 | 000,000,000 | —D | C] – C:\Data
[2010/09/24 01:53:00 | 000,850,200 | —- | C] (DivX, Inc. ) – C:\Users\liynapearl\AppData\Roaming\DivXInstaller.exe
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/09 11:17:30 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/09 11:17:30 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/09 11:08:23 | 000,000,674 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/09 11:08:06 | 000,000,437 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2011/06/09 11:07:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/09 11:07:40 | 1603,084,288 | -HS- | M] () – C:\hiberfil.sys
[2011/06/08 15:55:05 | 000,000,678 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/05 21:09:56 | 000,413,512 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/06/05 21:08:25 | 000,001,110 | —- | M] () – C:\Windows\System32\ServiceConfig.xml
[2011/06/05 21:08:25 | 000,000,810 | —- | M] () – C:\Windows\System32\RegistrationConfig.xml
[2011/06/04 12:25:14 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\BitComet.lnk
[2011/06/04 12:17:32 | 000,000,312 | —- | M] () – C:\Windows\System32\SBRC.dat
[2011/06/04 11:55:04 | 000,001,990 | —- | M] () – C:\Users\Liyna_ADMIN\Desktop\CyberLink Power2Go.lnk
[2011/06/04 10:49:43 | 002,677,546 | —- | M] () – C:\Windows\System32\perfh011.dat
[2011/06/04 10:49:43 | 002,078,056 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/06/04 10:49:43 | 001,549,488 | —- | M] () – C:\Windows\System32\perfc011.dat
[2011/06/04 10:49:43 | 001,509,358 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/06/03 23:44:19 | 000,001,896 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/29 23:04:02 | 000,002,503 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/05/20 09:59:00 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/20 09:59:00 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/20 09:58:59 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/20 09:58:59 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/20 09:58:59 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/20 09:58:59 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/20 09:58:59 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/20 09:58:59 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/20 09:58:59 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/20 09:58:59 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/20 09:58:59 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/20 09:58:59 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/20 09:58:59 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/20 09:58:59 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/20 09:58:59 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/20 09:58:59 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/20 09:58:59 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/20 09:58:59 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/20 09:58:59 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/20 09:58:58 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/05/20 09:58:56 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/20 09:58:56 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/20 09:58:56 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/20 09:58:56 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/20 09:58:56 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/20 09:58:56 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/20 09:58:56 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/20 09:58:56 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/20 09:58:56 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/20 09:58:56 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/20 09:58:56 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/20 09:58:56 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/20 09:58:56 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/20 09:58:56 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/20 09:58:56 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/20 09:58:56 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/20 09:58:56 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/20 09:58:56 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/20 09:58:56 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/20 09:58:56 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/19 19:03:50 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/05/19 14:38:05 | 000,000,420 | —- | M] () – C:\Windows\tasks\FrontLine Registry Cleaner Scheduled Scan - Liyna_ADMIN.job
[2011/05/19 12:48:38 | 000,002,018 | —- | M] () – C:\Users\Public\Desktop\FrontLine Registry Cleaner.lnk
[2011/05/19 10:30:01 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/05/18 23:41:09 | 000,001,078 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/17 15:29:59 | 000,000,136 | -H– | M] () – C:\ProgramData\~33545976r
[2011/05/17 15:29:59 | 000,000,112 | -H– | M] () – C:\ProgramData\~33545976
[2011/05/17 15:29:41 | 000,000,336 | -H– | M] () – C:\ProgramData\33545976
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/04 12:25:14 | 000,000,976 | —- | C] () – C:\Users\Public\Desktop\BitComet.lnk
[2011/06/03 23:44:19 | 000,001,896 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/02 11:33:12 | 000,001,990 | —- | C] () – C:\Users\Liyna_ADMIN\Desktop\CyberLink Power2Go.lnk
[2011/06/02 11:27:48 | 000,486,766 | —- | C] () – C:\Windows\CLBUDF.tbl
[2011/05/20 13:03:13 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/05/20 13:03:13 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/05/20 09:58:58 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/05/19 13:28:42 | 000,000,420 | —- | C] () – C:\Windows\tasks\FrontLine Registry Cleaner Scheduled Scan - Liyna_ADMIN.job
[2011/05/19 12:48:38 | 000,002,018 | —- | C] () – C:\Users\Public\Desktop\FrontLine Registry Cleaner.lnk
[2011/05/19 12:13:03 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/05/19 12:13:03 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/05/19 12:13:03 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/05/19 12:13:03 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/05/19 12:13:03 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/05/19 10:30:01 | 000,000,976 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/05/18 23:41:09 | 000,001,078 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/17 15:29:59 | 000,000,136 | -H– | C] () – C:\ProgramData\~33545976r
[2011/05/17 15:29:58 | 000,000,112 | -H– | C] () – C:\ProgramData\~33545976
[2011/05/17 15:29:41 | 000,000,336 | -H– | C] () – C:\ProgramData\33545976
[2011/04/24 15:00:34 | 000,000,312 | —- | C] () – C:\Windows\System32\SBRC.dat
[2010/05/22 15:23:26 | 000,000,008 | —- | C] () – C:\Windows\WININIT.INI
[2010/02/15 14:45:38 | 000,007,600 | -H– | C] () – C:\Users\liynapearl\AppData\Local\Resmon.ResmonCfg
[2010/02/02 01:35:51 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/11/07 07:59:58 | 000,006,656 | —- | C] () – C:\Users\liynapearl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/02 01:22:17 | 000,045,056 | —- | C] () – C:\Windows\System32\HWS_Ctrl.dll
[2009/11/02 00:48:43 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/10/29 17:03:55 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/10/29 15:11:35 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll.old
[2009/10/29 14:46:05 | 000,135,168 | —- | C] () – C:\Windows\System32\ChgService.exe
[2009/07/15 00:19:25 | 002,677,546 | —- | C] () – C:\Windows\System32\perfh011.dat
[2009/07/15 00:19:25 | 001,549,488 | —- | C] () – C:\Windows\System32\perfc011.dat
[2009/07/15 00:19:25 | 000,141,988 | —- | C] () – C:\Windows\System32\perfi011.dat
[2009/07/15 00:19:25 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd011.dat
[2009/07/14 13:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 13:33:53 | 000,413,512 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 11:05:48 | 002,078,056 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 11:05:48 | 001,509,358 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 11:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 11:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 11:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 11:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 09:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 08:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 08:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 08:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 06:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/28 04:37:00 | 000,028,672 | —- | C] () – C:\Windows\System32\SPCtl.dll
[2008/10/21 13:59:32 | 000,046,456 | R— | C] () – C:\Windows\System32\exitwx.exe
[2002/11/16 15:37:48 | 000,053,248 | —- | C] () – C:\Windows\System32\ahook.dll
========== LOP Check ==========
[2011/03/10 14:00:14 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\Aura4You
[2011/06/09 11:51:33 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\BitComet
[2010/07/09 00:13:22 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1
[2010/05/12 12:34:56 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\Ectaco
[2011/05/17 22:00:27 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\GetRightToGo
[2011/05/17 22:00:27 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\Juniper Networks
[2009/12/11 22:47:45 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\Nokia
[2009/12/11 21:23:11 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\PC Suite
[2010/07/06 19:40:31 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\RLM Software
[2011/05/17 22:00:50 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\solid-mp4-video-converter
[2011/05/17 21:54:25 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\Thinstall
[2011/05/17 21:54:25 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\Toshiba
[2009/11/01 23:42:29 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\WinBatch
[2011/05/19 14:38:05 | 000,000,420 | —- | M] () – C:\Windows\Tasks\FrontLine Registry Cleaner Scheduled Scan - Liyna_ADMIN.job
[2011/05/27 22:13:30 | 000,032,662 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/11 06:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/14 10:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2009/09/05 10:16:40 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/05/19 19:08:15 | 000,021,031 | —- | M] () – C:\ComboFix.txt
[2009/06/11 06:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/06/09 11:07:40 | 1603,084,288 | -HS- | M] () – C:\hiberfil.sys
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/06/09 11:07:39 | 2137,448,448 | -HS- | M] () – C:\pagefile.sys
[2010/02/23 19:28:32 | 000,001,413 | —- | M] () – C:\[23]TCPLibrary.log
[2009/11/25 21:29:51 | 000,000,542 | —- | M] () – C:\[25]TCPLibrary.log
[2010/03/04 16:33:42 | 000,000,542 | —- | M] () – C:\[4]TCPLibrary.log
< %systemroot%\Fonts\*.com >
[2009/07/14 13:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 13:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 13:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 13:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 06:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 10:15:05 | 000,071,168 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNBPP4.DLL
[2009/07/14 10:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/14 10:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
Invalid Environment Variable: APPDATA
< %ALLUSERSPROFILE%\Favorites\*.* >
Invalid Environment Variable: APPDATA
< %PROGRAMFILES%\*.* >
[2009/07/14 13:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
Invalid Environment Variable: APPDATA
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
Invalid Environment Variable: APPDATA
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-08 06:59:25
========== Alternate Data Streams ==========
@Alternate Data Stream - 170 bytes -> C:\ProgramData\TEMP:96D0C06F
@Alternate Data Stream - 157 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >
A month ago, I have the internet redirect virus. I tried many ways to correct this problem including combofix, malwarebytes, restore windows to an earlier date, restore windows with original CD, Fronline Registry Cleaner, CCleaner and etc. Finally the redirect virus problem solved. But after that I have other problems. The computer always runs updating once it is turn off and on, but it fails when updating the files in windows update. I also have problems opening documents in words which was downloaded from the email attached file. Words said that the files are disable due to documents caused serious error last time when they were opened. I also run the Active Recovery software but it can only run once and I can`t use it anymore. Problem with Mozilla and I have to uninstall and re-install. The Malwarebytes also showed a message that it is 20 days not updated but when I press the update button, it showed the "Program_Error_Updating(5,0,create file)".
Please help me on this matter. Below is the OTL.txt and Extras.txt details as requested.
Thank you…..
OTL logfile created on: 6/9/2011 11:42:55 AM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\liynapearl\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd
1.99 Gb Total Physical Memory | 0.92 Gb Available Physical Memory | 46.30% Memory free
3.98 Gb Paging File | 2.82 Gb Available in Paging File | 70.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.91 Gb Total Space | 125.93 Gb Free Space | 58.32% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.78 Gb Free Space | 57.82% Space Free | Partition Type: NTFS
Computer Name: LIYNAPEARL-PC | User Name: Liyna_ADMIN | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\liynapearl\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
PRC - C:\Program Files\Max PC Booster\PCBVistaService.exe (Max Secure Software)
PRC - C:\Program Files\Max PC Booster\PCBSysTray.exe (Max Secure Software.)
PRC - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
PRC - C:\Windows\System32\ChgService.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (SafeList) ==========
MOD - C:\Users\liynapearl\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\IME\IMEJP10\IMJPTIP.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IMJP10K.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\shared\IMETIP.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\IMEJP10\IMJPAPI.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\shared\IMJKAPI.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\IME\shared\imecfm.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (nosGetPlusHelper) getPlus® – File not found
SRV - (PCBVistaSvc) – C:\Program Files\Max PC Booster\PCBVistaService.exe (Max Secure Software)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (SBAMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
SRV - (SBPIMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (TMachInfo) – C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Thpsrv) – C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation)
SRV - (Change Modem Device Service) – C:\Windows\System32\ChgService.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (SbFw) – C:\Windows\System32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (sbhips) – C:\Windows\System32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SbTis) – C:\Windows\System32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (nmwcdnsu) – C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (sbapifs) – C:\Windows\System32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (SBRE) – C:\Windows\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (SBFWIMCLMP) – C:\Windows\System32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) – C:\Windows\System32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (ewusbnet) – C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbdev) – C:\Windows\System32\drivers\ewusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (RSUSBSTOR) – C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV - (Thpevm) – C:\Windows\system32\DRIVERS\Thpevm.SYS (TOSHIBA Corporation)
DRV - (Thpdrv) – C:\Windows\system32\DRIVERS\thpdrv.sys (TOSHIBA Corporation)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (TVALZFL) – C:\Windows\System32\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV - (CLBUDF) – C:\Windows\System32\drivers\CLBUDF.sys (CyberLink Corporation.)
DRV - (CLBStor) – C:\Windows\System32\drivers\CLBStor.sys (Cyberlink Co.,Ltd.)
DRV - (cmnsusbser) – C:\Windows\System32\drivers\cmnsusbser.sys (Mobile Connector)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ja
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 73 07 C0 EE E6 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.jp/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {749474f5-3972-0174-45ff-a63c3dce6339}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.736
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.3.5.20110120033202
FF - prefs.js..extensions.enabledItems: {fe0258ab-4f74-43a1-8781-bcdf340f9ee9}:2.6.4
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.25
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=405&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2011/01/31 10:46:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/03/07 09:16:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/03 23:44:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/03 23:44:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/03/07 09:16:06 | 000,000,000 | —D | M]
[2011/05/04 23:13:06 | 000,000,000 | -H-D | M] (No name found) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Extensions
[2011/06/08 15:23:30 | 000,000,000 | —D | M] (No name found) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions
[2011/05/17 22:00:34 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/05/17 22:00:35 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/06/04 12:25:24 | 000,000,000 | —D | M] (BitComet Video Downloader) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2011/05/18 16:51:15 | 000,000,000 | —D | M] (Redirect Remover) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\{fe0258ab-4f74-43a1-8781-bcdf340f9ee9}
[2011/05/17 22:00:34 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\liynapearl\AppData\Roaming\Mozilla\Firefox\Profiles\hqsg4kvj.default\extensions\[removed]
[2011/06/05 20:36:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/08 00:11:01 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{749474f5-3972-0174-45ff-a63c3dce6339}
[2011/06/05 20:36:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/03/07 09:16:05 | 000,000,000 | —D | M] (Firefox Synchronisation Extension) – C:\PROGRAM FILES\NOKIA\NOKIA OVI SUITE\CONNECTORS\BOOKMARKS CONNECTOR\FIREFOXEXTENSION
[2011/01/31 10:46:29 | 000,000,000 | —D | M] (PC Sync 2 Synchronisation Extension) – C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC
[2009/10/31 23:16:20 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
File not found (No name found) – C:\PROGRAM FILES\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2010/08/24 18:31:30 | 000,773,120 | —- | M] (BitComet) – C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2011/04/04 14:03:00 | 000,002,046 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml
[2010/10/13 08:38:58 | 000,001,175 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\FLVTube.xml.bak
O1 HOSTS File: ([2011/05/19 19:03:50 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (i-フィルター 5.0 ブラウザヘルパー) - {0FAF6F52-1AD4-4282-9EA1-3EC884DA7AA3} - C:\Program Files\Digital Arts\IFP5\app\bin\ifp5toolbar.dll (デジタルアーツ株式会社)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.12.6.dll (BitComet)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [InstantBurn] C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.)
O4 - HKLM..\Run: [PCBSystemTray] C:\Program Files\Max PC Booster\PCBSysTray.exe (Max Secure Software.)
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
O4 - HKLM..\Run: [ThpSrv] C:\Windows\System32\thpsrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\RunOnce: [*WerKernelReporting] C:\Windows\System32\WerFault.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all links using BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Download link using &BitComet; - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.12.6.dll (BitComet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll (Installation Support)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 06:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
========== Files/Folders - Created Within 30 Days ==========
[2011/06/05 20:26:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2011/06/05 20:26:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/06/05 20:25:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2011/06/05 20:23:13 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2011/06/05 20:21:56 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2011/06/05 20:19:22 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2011/06/05 20:17:26 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Analysis Services
[2011/06/05 20:14:45 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/06/03 23:44:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/06/03 23:33:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011/06/03 23:33:41 | 000,000,000 | —D | C] – C:\Program Files\7-Zip
[2011/06/03 01:02:54 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\poqexec.exe
[2011/06/03 01:02:52 | 000,026,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2011/06/02 11:42:22 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Roaming\CyberLink
[2011/06/02 11:39:59 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Local\Power2Go
[2011/06/02 11:27:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
[2011/06/02 11:27:54 | 000,161,704 | —- | C] (CyberLink Corporation.) – C:\Windows\System32\drivers\CLBUDF.sys
[2011/06/02 11:27:54 | 000,015,784 | —- | C] (Cyberlink Co.,Ltd.) – C:\Windows\System32\drivers\CLBStor.sys
[2011/06/02 11:27:27 | 000,000,000 | —D | C] – C:\Program Files\CyberLink
[2011/06/02 11:27:13 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2011/06/01 22:42:24 | 000,000,000 | —D | C] – C:\Program Files\LSoft Technologies
[2011/06/01 22:42:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ File Recovery
[2011/05/29 11:38:21 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2011/05/20 13:04:19 | 000,000,000 | -H-D | C] – C:\Windows\PIF
[2011/05/20 09:59:00 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/20 09:59:00 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/20 09:58:59 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/20 09:58:59 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/20 09:58:59 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/20 09:58:59 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/20 09:58:59 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/20 09:58:59 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/20 09:58:59 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/20 09:58:59 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/20 09:58:59 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/20 09:58:59 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/20 09:58:59 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/20 09:58:59 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/20 09:58:59 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/20 09:58:59 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/20 09:58:59 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/20 09:58:59 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/20 09:58:59 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/20 09:58:56 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/20 09:58:56 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/20 09:58:56 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/20 09:58:56 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/20 09:58:56 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/20 09:58:56 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/20 09:58:56 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/20 09:58:56 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/20 09:58:56 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/20 09:58:56 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/20 09:58:56 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/20 09:58:56 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/20 09:58:56 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/20 09:58:56 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/20 09:58:56 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/20 09:58:56 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/20 09:58:56 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/20 09:58:56 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/20 09:58:56 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/20 09:58:56 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/20 09:48:34 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Roaming\yahoo!
[2011/05/19 23:18:42 | 000,000,000 | —D | C] – C:\FORMS
[2011/05/19 19:08:24 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/05/19 19:08:17 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Local\temp
[2011/05/19 19:05:04 | 000,000,000 | —D | C] – C:\Microsoft
[2011/05/19 18:46:37 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2011/05/19 13:28:36 | 000,000,000 | —D | C] – C:\ProgramData\FrontLine Registry Cleaner
[2011/05/19 13:25:55 | 000,000,000 | —D | C] – C:\temp
[2011/05/19 13:25:13 | 000,000,000 | —D | C] – C:\Program Files\Frontline Registry Cleaner 2010 v1.25
[2011/05/19 12:48:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Frontline Registry Cleaner
[2011/05/19 12:48:37 | 000,000,000 | —D | C] – C:\Program Files\Frontline Registry Cleaner
[2011/05/19 12:13:03 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/05/19 12:13:03 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/05/19 12:13:03 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/05/19 12:12:46 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/05/19 12:10:00 | 000,000,000 | —D | C] – C:\Qoobox
[2011/05/19 10:30:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/05/18 23:41:33 | 000,000,000 | —D | C] – C:\Users\liynapearl\AppData\Roaming\Malwarebytes
[2011/05/18 23:41:09 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/18 23:41:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/18 23:41:08 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/18 23:41:05 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/18 10:15:51 | 000,000,000 | —D | C] – C:\w
[2011/05/18 10:15:50 | 000,000,000 | —D | C] – C:\Cache
[2011/05/18 10:15:45 | 000,000,000 | —D | C] – C:\e
[2011/05/17 17:10:12 | 000,000,000 | —D | C] – C:\Data
[2010/09/24 01:53:00 | 000,850,200 | —- | C] (DivX, Inc. ) – C:\Users\liynapearl\AppData\Roaming\DivXInstaller.exe
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/09 11:17:30 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/09 11:17:30 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/09 11:08:23 | 000,000,674 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/09 11:08:06 | 000,000,437 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2011/06/09 11:07:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/09 11:07:40 | 1603,084,288 | -HS- | M] () – C:\hiberfil.sys
[2011/06/08 15:55:05 | 000,000,678 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/05 21:09:56 | 000,413,512 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/06/05 21:08:25 | 000,001,110 | —- | M] () – C:\Windows\System32\ServiceConfig.xml
[2011/06/05 21:08:25 | 000,000,810 | —- | M] () – C:\Windows\System32\RegistrationConfig.xml
[2011/06/04 12:25:14 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\BitComet.lnk
[2011/06/04 12:17:32 | 000,000,312 | —- | M] () – C:\Windows\System32\SBRC.dat
[2011/06/04 11:55:04 | 000,001,990 | —- | M] () – C:\Users\Liyna_ADMIN\Desktop\CyberLink Power2Go.lnk
[2011/06/04 10:49:43 | 002,677,546 | —- | M] () – C:\Windows\System32\perfh011.dat
[2011/06/04 10:49:43 | 002,078,056 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/06/04 10:49:43 | 001,549,488 | —- | M] () – C:\Windows\System32\perfc011.dat
[2011/06/04 10:49:43 | 001,509,358 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/06/03 23:44:19 | 000,001,896 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/29 23:04:02 | 000,002,503 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/05/20 09:59:00 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/20 09:59:00 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/20 09:58:59 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/20 09:58:59 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/20 09:58:59 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/20 09:58:59 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/20 09:58:59 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/20 09:58:59 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/20 09:58:59 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/20 09:58:59 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/20 09:58:59 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/20 09:58:59 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/20 09:58:59 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/20 09:58:59 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/20 09:58:59 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/20 09:58:59 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/20 09:58:59 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/20 09:58:59 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/20 09:58:59 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/20 09:58:58 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/05/20 09:58:56 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/20 09:58:56 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/20 09:58:56 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/20 09:58:56 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/20 09:58:56 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/20 09:58:56 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/20 09:58:56 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/20 09:58:56 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/20 09:58:56 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/20 09:58:56 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/20 09:58:56 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/20 09:58:56 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/20 09:58:56 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/20 09:58:56 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/20 09:58:56 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/20 09:58:56 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/20 09:58:56 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/20 09:58:56 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/20 09:58:56 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/20 09:58:56 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/19 19:03:50 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/05/19 14:38:05 | 000,000,420 | —- | M] () – C:\Windows\tasks\FrontLine Registry Cleaner Scheduled Scan - Liyna_ADMIN.job
[2011/05/19 12:48:38 | 000,002,018 | —- | M] () – C:\Users\Public\Desktop\FrontLine Registry Cleaner.lnk
[2011/05/19 10:30:01 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/05/18 23:41:09 | 000,001,078 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/17 15:29:59 | 000,000,136 | -H– | M] () – C:\ProgramData\~33545976r
[2011/05/17 15:29:59 | 000,000,112 | -H– | M] () – C:\ProgramData\~33545976
[2011/05/17 15:29:41 | 000,000,336 | -H– | M] () – C:\ProgramData\33545976
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/04 12:25:14 | 000,000,976 | —- | C] () – C:\Users\Public\Desktop\BitComet.lnk
[2011/06/03 23:44:19 | 000,001,896 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/02 11:33:12 | 000,001,990 | —- | C] () – C:\Users\Liyna_ADMIN\Desktop\CyberLink Power2Go.lnk
[2011/06/02 11:27:48 | 000,486,766 | —- | C] () – C:\Windows\CLBUDF.tbl
[2011/05/20 13:03:13 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/05/20 13:03:13 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/05/20 09:58:58 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/05/19 13:28:42 | 000,000,420 | —- | C] () – C:\Windows\tasks\FrontLine Registry Cleaner Scheduled Scan - Liyna_ADMIN.job
[2011/05/19 12:48:38 | 000,002,018 | —- | C] () – C:\Users\Public\Desktop\FrontLine Registry Cleaner.lnk
[2011/05/19 12:13:03 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/05/19 12:13:03 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/05/19 12:13:03 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/05/19 12:13:03 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/05/19 12:13:03 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/05/19 10:30:01 | 000,000,976 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011/05/18 23:41:09 | 000,001,078 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/17 15:29:59 | 000,000,136 | -H– | C] () – C:\ProgramData\~33545976r
[2011/05/17 15:29:58 | 000,000,112 | -H– | C] () – C:\ProgramData\~33545976
[2011/05/17 15:29:41 | 000,000,336 | -H– | C] () – C:\ProgramData\33545976
[2011/04/24 15:00:34 | 000,000,312 | —- | C] () – C:\Windows\System32\SBRC.dat
[2010/05/22 15:23:26 | 000,000,008 | —- | C] () – C:\Windows\WININIT.INI
[2010/02/15 14:45:38 | 000,007,600 | -H– | C] () – C:\Users\liynapearl\AppData\Local\Resmon.ResmonCfg
[2010/02/02 01:35:51 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/11/07 07:59:58 | 000,006,656 | —- | C] () – C:\Users\liynapearl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/02 01:22:17 | 000,045,056 | —- | C] () – C:\Windows\System32\HWS_Ctrl.dll
[2009/11/02 00:48:43 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/10/29 17:03:55 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/10/29 15:11:35 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll.old
[2009/10/29 14:46:05 | 000,135,168 | —- | C] () – C:\Windows\System32\ChgService.exe
[2009/07/15 00:19:25 | 002,677,546 | —- | C] () – C:\Windows\System32\perfh011.dat
[2009/07/15 00:19:25 | 001,549,488 | —- | C] () – C:\Windows\System32\perfc011.dat
[2009/07/15 00:19:25 | 000,141,988 | —- | C] () – C:\Windows\System32\perfi011.dat
[2009/07/15 00:19:25 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd011.dat
[2009/07/14 13:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 13:33:53 | 000,413,512 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 11:05:48 | 002,078,056 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 11:05:48 | 001,509,358 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 11:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 11:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 11:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 11:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 09:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 08:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 08:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 08:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 06:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/28 04:37:00 | 000,028,672 | —- | C] () – C:\Windows\System32\SPCtl.dll
[2008/10/21 13:59:32 | 000,046,456 | R— | C] () – C:\Windows\System32\exitwx.exe
[2002/11/16 15:37:48 | 000,053,248 | —- | C] () – C:\Windows\System32\ahook.dll
========== LOP Check ==========
[2011/03/10 14:00:14 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\Aura4You
[2011/06/09 11:51:33 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\BitComet
[2010/07/09 00:13:22 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1
[2010/05/12 12:34:56 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\Ectaco
[2011/05/17 22:00:27 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\GetRightToGo
[2011/05/17 22:00:27 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\Juniper Networks
[2009/12/11 22:47:45 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\Nokia
[2009/12/11 21:23:11 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\PC Suite
[2010/07/06 19:40:31 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\RLM Software
[2011/05/17 22:00:50 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\solid-mp4-video-converter
[2011/05/17 21:54:25 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\Thinstall
[2011/05/17 21:54:25 | 000,000,000 | —D | M] – C:\Users\liynapearl\AppData\Roaming\Toshiba
[2009/11/01 23:42:29 | 000,000,000 | -H-D | M] – C:\Users\liynapearl\AppData\Roaming\WinBatch
[2011/05/19 14:38:05 | 000,000,420 | —- | M] () – C:\Windows\Tasks\FrontLine Registry Cleaner Scheduled Scan - Liyna_ADMIN.job
[2011/05/27 22:13:30 | 000,032,662 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/11 06:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/14 10:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2009/09/05 10:16:40 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/05/19 19:08:15 | 000,021,031 | —- | M] () – C:\ComboFix.txt
[2009/06/11 06:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/06/09 11:07:40 | 1603,084,288 | -HS- | M] () – C:\hiberfil.sys
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/05/20 13:03:13 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/06/09 11:07:39 | 2137,448,448 | -HS- | M] () – C:\pagefile.sys
[2010/02/23 19:28:32 | 000,001,413 | —- | M] () – C:\[23]TCPLibrary.log
[2009/11/25 21:29:51 | 000,000,542 | —- | M] () – C:\[25]TCPLibrary.log
[2010/03/04 16:33:42 | 000,000,542 | —- | M] () – C:\[4]TCPLibrary.log
< %systemroot%\Fonts\*.com >
[2009/07/14 13:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 13:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 13:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 13:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 06:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 10:15:05 | 000,071,168 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNBPP4.DLL
[2009/07/14 10:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/14 10:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
Invalid Environment Variable: APPDATA
< %ALLUSERSPROFILE%\Favorites\*.* >
Invalid Environment Variable: APPDATA
< %PROGRAMFILES%\*.* >
[2009/07/14 13:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
Invalid Environment Variable: APPDATA
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
Invalid Environment Variable: APPDATA
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-08 06:59:25
========== Alternate Data Streams ==========
@Alternate Data Stream - 170 bytes -> C:\ProgramData\TEMP:96D0C06F
@Alternate Data Stream - 157 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >