This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Chrome (or Google) being redirected, ran HijackThis

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here are the log results:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:10:41 AM, on 8/12/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
D:\Program Files\Advanced SystemCare 4\PMonitor.exe
D:\Program Files\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
D:\Program Files\Advanced SystemCare 4\ASCTray.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Documents and Settings\Russgies\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.msn.co
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110811123352.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [UVS11 Preload] D:\Program Files\ulead\uvPL.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Advanced SystemCare 4] D:\Program Files\Advanced SystemCare 4\ASCTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\Russgies\Application Data\Dropbox\bin\Dropbox.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1311190553373
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - D:\Program Files\Advanced SystemCare 4\ASCService.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Freemake Service (FreemakeUtilsService) - Freemake - C:\Documents and Settings\All Users\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Windows Presentation Foundation Font Cache 4.0.0.0 (WPFFontCache_v0400) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (file missing)

–
End of file - 8945 bytes

Much obliged!
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)














  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
2011/08/16 14:34:07.0375 0540 TDSS rootkit removing tool 2.5.15.0 Aug 11 2011 16:32:13
2011/08/16 14:34:09.0375 0540 ================================================================================
2011/08/16 14:34:09.0375 0540 SystemInfo:
2011/08/16 14:34:09.0375 0540
2011/08/16 14:34:09.0375 0540 OS Version: 5.1.2600 ServicePack: 3.0
2011/08/16 14:34:09.0375 0540 Product type: Workstation
2011/08/16 14:34:09.0375 0540 ComputerName: VAIO
2011/08/16 14:34:09.0375 0540 UserName: Russgies
2011/08/16 14:34:09.0375 0540 Windows directory: C:\WINDOWS
2011/08/16 14:34:09.0375 0540 System windows directory: C:\WINDOWS
2011/08/16 14:34:09.0375 0540 Processor architecture: Intel x86
2011/08/16 14:34:09.0375 0540 Number of processors: 1
2011/08/16 14:34:09.0375 0540 Page size: 0x1000
2011/08/16 14:34:09.0375 0540 Boot type: Normal boot
2011/08/16 14:34:09.0375 0540 ================================================================================
2011/08/16 14:34:12.0781 0540 Initialize success
2011/08/16 14:34:17.0078 1632 ================================================================================
2011/08/16 14:34:17.0078 1632 Scan started
2011/08/16 14:34:17.0078 1632 Mode: Manual;
2011/08/16 14:34:17.0078 1632 ================================================================================
2011/08/16 14:34:18.0250 1632 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/08/16 14:34:18.0359 1632 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/08/16 14:34:18.0640 1632 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/08/16 14:34:18.0750 1632 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/08/16 14:34:18.0890 1632 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/08/16 14:34:19.0640 1632 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/08/16 14:34:20.0171 1632 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/08/16 14:34:20.0250 1632 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/08/16 14:34:20.0578 1632 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/08/16 14:34:20.0718 1632 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/08/16 14:34:20.0843 1632 BCM42XX (5ff4a1e41df9f1e328c955caa12cd3b0) C:\WINDOWS\system32\DRIVERS\bcm42xx5.sys
2011/08/16 14:34:21.0031 1632 BCMModem (2d39d498108c4810ef8cc1103a2a5b73) C:\WINDOWS\system32\DRIVERS\BCMDM.sys
2011/08/16 14:34:21.0156 1632 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/08/16 14:34:21.0296 1632 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/08/16 14:34:21.0500 1632 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/08/16 14:34:21.0562 1632 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/08/16 14:34:21.0656 1632 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/08/16 14:34:21.0828 1632 cfwids (ecaf4a51580244fef1aa32cb984f13bf) C:\WINDOWS\system32\drivers\cfwids.sys
2011/08/16 14:34:22.0718 1632 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/08/16 14:34:22.0953 1632 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/08/16 14:34:23.0218 1632 DMICall (526192bf7696f72e29777bf4a180513a) C:\WINDOWS\system32\DRIVERS\DMICall.sys
2011/08/16 14:34:23.0359 1632 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/08/16 14:34:23.0453 1632 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/08/16 14:34:23.0593 1632 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/08/16 14:34:23.0875 1632 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/08/16 14:34:24.0046 1632 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/08/16 14:34:24.0140 1632 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/08/16 14:34:24.0250 1632 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/08/16 14:34:24.0343 1632 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/08/16 14:34:24.0484 1632 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/08/16 14:34:24.0609 1632 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/08/16 14:34:24.0687 1632 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/08/16 14:34:24.0796 1632 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/08/16 14:34:24.0937 1632 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/08/16 14:34:25.0375 1632 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/08/16 14:34:25.0796 1632 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/08/16 14:34:25.0906 1632 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\drivers\Imapi.sys
2011/08/16 14:34:26.0578 1632 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/08/16 14:34:26.0703 1632 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/08/16 14:34:26.0828 1632 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/08/16 14:34:26.0921 1632 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/08/16 14:34:27.0015 1632 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/08/16 14:34:27.0140 1632 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/08/16 14:34:27.0281 1632 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/08/16 14:34:27.0390 1632 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/08/16 14:34:27.0531 1632 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/08/16 14:34:27.0687 1632 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/08/16 14:34:27.0796 1632 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/08/16 14:34:27.0875 1632 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/08/16 14:34:28.0156 1632 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/08/16 14:34:28.0343 1632 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
2011/08/16 14:34:28.0531 1632 Lbd (336abe8721cbc3110f1c6426da633417) C:\WINDOWS\system32\DRIVERS\Lbd.sys
2011/08/16 14:34:28.0875 1632 ltmodem5 (9ee18a5a45552673a67532ea37370377) C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys
2011/08/16 14:34:29.0453 1632 mfeapfk (688b626fca708ee9eb161cad1f7363a9) C:\WINDOWS\system32\drivers\mfeapfk.sys
2011/08/16 14:34:29.0609 1632 mfeavfk (693a8d924b640223974e0a88f2baf0f4) C:\WINDOWS\system32\drivers\mfeavfk.sys
2011/08/16 14:34:29.0906 1632 mfebopk (52c40d19873528bd15823c969d3ad227) C:\WINDOWS\system32\drivers\mfebopk.sys
2011/08/16 14:34:30.0125 1632 mfefirek (e37b98d49df546f4059483d49e349a53) C:\WINDOWS\system32\drivers\mfefirek.sys
2011/08/16 14:34:30.0281 1632 mfehidk (44184f32392fa2e94d08d056ce750d56) C:\WINDOWS\system32\drivers\mfehidk.sys
2011/08/16 14:34:30.0500 1632 mfendisk (8c434d77c7a8cd97f8f4c2b0be19d541) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
2011/08/16 14:34:30.0546 1632 mfendiskmp (8c434d77c7a8cd97f8f4c2b0be19d541) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
2011/08/16 14:34:30.0750 1632 mferkdet (5f5313bfd1e73233885a26ab77488f6f) C:\WINDOWS\system32\drivers\mferkdet.sys
2011/08/16 14:34:30.0921 1632 mfetdi2k (8d1a44e1f46bcf4acfe9c701edd340e3) C:\WINDOWS\system32\drivers\mfetdi2k.sys
2011/08/16 14:34:31.0046 1632 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/08/16 14:34:31.0125 1632 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/08/16 14:34:31.0250 1632 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
2011/08/16 14:34:31.0328 1632 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/08/16 14:34:31.0468 1632 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/08/16 14:34:31.0546 1632 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/08/16 14:34:31.0781 1632 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/08/16 14:34:31.0984 1632 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/08/16 14:34:32.0203 1632 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/08/16 14:34:32.0328 1632 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/08/16 14:34:32.0406 1632 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/08/16 14:34:32.0453 1632 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/08/16 14:34:32.0578 1632 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/08/16 14:34:32.0656 1632 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/08/16 14:34:32.0812 1632 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/08/16 14:34:33.0031 1632 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/08/16 14:34:33.0203 1632 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/08/16 14:34:33.0296 1632 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/08/16 14:34:33.0453 1632 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/08/16 14:34:33.0562 1632 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/08/16 14:34:33.0656 1632 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/08/16 14:34:33.0812 1632 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/08/16 14:34:33.0937 1632 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/08/16 14:34:34.0093 1632 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/08/16 14:34:34.0250 1632 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/08/16 14:34:34.0609 1632 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/08/16 14:34:35.0000 1632 nv4 (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/08/16 14:34:35.0125 1632 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/08/16 14:34:35.0203 1632 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/08/16 14:34:35.0312 1632 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/08/16 14:34:35.0609 1632 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/08/16 14:34:35.0781 1632 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/08/16 14:34:36.0140 1632 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/08/16 14:34:36.0234 1632 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/08/16 14:34:36.0656 1632 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/08/16 14:34:38.0062 1632 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/08/16 14:34:38.0140 1632 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
2011/08/16 14:34:38.0437 1632 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/08/16 14:34:38.0546 1632 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/08/16 14:34:39.0093 1632 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
2011/08/16 14:34:39.0875 1632 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/08/16 14:34:40.0515 1632 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/08/16 14:34:40.0703 1632 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/08/16 14:34:40.0765 1632 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/08/16 14:34:40.0906 1632 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/08/16 14:34:40.0984 1632 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/08/16 14:34:41.0109 1632 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/08/16 14:34:41.0265 1632 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/08/16 14:34:41.0453 1632 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
2011/08/16 14:34:41.0593 1632 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/08/16 14:34:41.0718 1632 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/08/16 14:34:41.0796 1632 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/08/16 14:34:41.0968 1632 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/08/16 14:34:42.0375 1632 smwdm (bd3e236281547c681dfc7c947531b726) C:\WINDOWS\system32\drivers\smwdm.sys
2011/08/16 14:34:42.0531 1632 SonyFanC (c000104b9807146382359d17b68b2a8b) C:\WINDOWS\system32\Drivers\SonyFanC.sys
2011/08/16 14:34:42.0781 1632 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/08/16 14:34:42.0937 1632 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/08/16 14:34:43.0171 1632 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/08/16 14:34:43.0343 1632 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/08/16 14:34:43.0468 1632 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/08/16 14:34:44.0093 1632 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/08/16 14:34:44.0281 1632 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/08/16 14:34:44.0390 1632 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/08/16 14:34:44.0484 1632 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/08/16 14:34:44.0578 1632 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/08/16 14:34:44.0890 1632 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/08/16 14:34:45.0203 1632 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/08/16 14:34:45.0375 1632 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/08/16 14:34:45.0484 1632 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/08/16 14:34:45.0578 1632 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/08/16 14:34:45.0656 1632 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/08/16 14:34:45.0812 1632 V7 (ea8def76a1be5c770fb12d0382be632c) C:\WINDOWS\system32\drivers\V7.sys
2011/08/16 14:34:45.0906 1632 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/08/16 14:34:46.0140 1632 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/08/16 14:34:46.0312 1632 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/08/16 14:34:46.0578 1632 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/08/16 14:34:47.0000 1632 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/08/16 14:34:47.0234 1632 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/08/16 14:34:47.0375 1632 MBR (0x1B8) (671b81004fdd1588fa9ed1331c9ceca9) \Device\Harddisk0\DR0
2011/08/16 14:34:47.0515 1632 MBR (0x1B8) (35c6b2fcde68facbefe0a4a7200bae58) \Device\Harddisk1\DR1
2011/08/16 14:34:47.0625 1632 Boot (0x1200) (2fd21f9019de7eadbe322d15ff2ca379) \Device\Harddisk0\DR0\Partition0
2011/08/16 14:34:47.0671 1632 Boot (0x1200) (f405dfad4d6c33f680c208dea73ea1fb) \Device\Harddisk0\DR0\Partition1
2011/08/16 14:34:47.0703 1632 Boot (0x1200) (18cbc7d4e41b0ab48b7fe51cb96272e3) \Device\Harddisk1\DR1\Partition0
2011/08/16 14:34:47.0750 1632 ================================================================================
2011/08/16 14:34:47.0750 1632 Scan finished
2011/08/16 14:34:47.0750 1632 ================================================================================
2011/08/16 14:34:47.0796 1428 Detected object count: 0
2011/08/16 14:34:47.0796 1428 Actual detected object count: 0
2011/08/16 14:39:46.0625 0756 Deinitialize success



OTL logfile created on: 8/16/2011 2:45:37 PM - Run 1
OTL by OldTimer - Version 3.2.26.4 Folder = C:\Documents and Settings\Russgies\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.53 Mb Total Physical Memory | 298.27 Mb Available Physical Memory | 58.31% Memory free
1.39 Gb Paging File | 0.90 Gb Available in Paging File | 64.59% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15.60 Gb Total Space | 1.88 Gb Free Space | 12.02% Space Free | Partition Type: FAT32
Drive D: | 37.26 Gb Total Space | 2.35 Gb Free Space | 6.30% Space Free | Partition Type: FAT32
Drive E: | 40.27 Gb Total Space | 10.36 Gb Free Space | 25.73% Space Free | Partition Type: NTFS

Computer Name: VAIO | User Name: Russgies | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Russgies\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - c:\Program Files\McAfee\MSC\mcupdmgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - D:\Program Files\Advanced SystemCare 4\ASCTray.exe (IObit)
PRC - D:\Program Files\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Documents and Settings\Russgies\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Sony\VAIO Action Setup\VAServ.exe (Sony Corporation)


========== Modules (No Company Name) ==========

MOD - D:\Program Files\Advanced SystemCare 4\madexcept_.bpl ()
MOD - D:\Program Files\Advanced SystemCare 4\madbasic_.bpl ()
MOD - D:\Program Files\Advanced SystemCare 4\maddisAsm_.bpl ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\qdvd.dll ()
MOD - C:\WINDOWS\system32\qcap.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()


========== Win32 Services (SafeList) ==========

SRV - (WPFFontCache_v0400) – File not found
SRV - (McAfee SiteAdvisor Service) – File not found
SRV - (AppMgmt) – File not found
SRV - (FreemakeUtilsService) – C:\Documents and Settings\All Users\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (AdvancedSystemCareService) – D:\Program Files\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (PSI_SVC_2) – c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (Capture Device Service) – C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)


========== Driver Services (SafeList) ==========

DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (SonyFanC) – C:\WINDOWS\system32\drivers\SonyFanC.sys (Sony Corporation)
DRV - (BCMModem) – C:\WINDOWS\system32\drivers\BCMDM.sys (BCM)
DRV - (BCM42XX) Broadcom iLine10™ – C:\WINDOWS\system32\drivers\bcm42xx5.sys (Broadcom Corporation)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (V7) – C:\WINDOWS\System32\drivers\V7.SYS (IBM Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.msn.co
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/20 13:34:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/07/20 13:34:54 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Russgies\Application Data\Mozilla\Extensions
[2011/07/20 13:34:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/08/02 16:50:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) –
[2011/08/02 16:50:14 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/07/28 00:23:18 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/07/08 01:16:28 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/01/01 02:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2001/08/18 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20110811123352.dll (McAfee, Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [UVS11 Preload] D:\Program Files\ulead\uvPL.exe (InterVideo Digital Technology Corporation)
O4 - HKLM..\Run: [ZTgServerSwitch] c:\Program Files\support.com\client\lserver\Server.vbs ()
O4 - HKCU..\Run: [Advanced SystemCare 4] D:\Program Files\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VAIO Action Setup (Server).lnk = C:\Program Files\Sony\VAIO Action Setup\VAServ.exe (Sony Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Russgies\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Russgies\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1311190553373 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/09/08 11:07:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.atrac3 - C:\WINDOWS\System32\atrac3.acm (Sony Corporation)
Drivers32: msacm.dvacm - c:\Program Files\Common Files\Ulead Systems\VIO\DVACM.acm (InterVideo Digital Technology Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.MPEGacm - C:\Program Files\Common Files\Ulead Systems\MPEG\MPEGACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.ulmp3acm - C:\Program Files\Common Files\Ulead Systems\MPEG\ulmp3acm.acm (Ulead systems)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.dvsd - C:\Program Files\Common Files\Sony Shared\DVLib\sonydv.dll (Sony Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.MJPG - C:\WINDOWS\System32\sonymjpg.dll (Sony Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/08/15 19:53:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/08/12 11:09:27 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/08/12 11:09:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Start Menu\Programs\HiJackThis
[2011/08/11 16:33:10 | 001,404,720 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Russgies\Desktop\TDSSKiller.exe
[2011/08/11 12:33:49 | 000,009,344 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeclnk.sys
[2011/08/11 12:33:15 | 000,337,912 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfefirek.sys
[2011/08/11 12:33:15 | 000,179,248 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeavfk.sys
[2011/08/11 12:33:15 | 000,089,368 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfetdi2k.sys
[2011/08/11 12:33:15 | 000,085,984 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mferkdet.sys
[2011/08/11 12:33:15 | 000,083,688 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfendisk.sys
[2011/08/11 12:33:15 | 000,059,288 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfebopk.sys
[2011/08/11 12:33:15 | 000,057,432 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\cfwids.sys
[2011/08/11 12:32:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2011/08/11 12:32:01 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2011/08/11 12:31:17 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2011/08/11 12:24:46 | 000,148,520 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\mfevtps.exe
[2011/08/10 19:09:09 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/08/10 19:08:44 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/08/10 00:30:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\McAfee Anti-Theft
[2011/08/10 00:13:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2011/08/09 23:09:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\Freemake
[2011/08/09 23:08:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Freemake
[2011/08/09 23:08:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Freemake
[2011/08/09 23:08:41 | 000,000,000 | —D | C] – C:\Program Files\Freemake
[2011/08/09 14:34:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Google
[2011/08/09 14:32:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2011/08/09 14:29:41 | 000,000,000 | —D | C] – C:\Program Files\Google
[2011/08/08 20:32:22 | 000,000,000 | -HSD | C] – C:\FOUND.001
[2011/08/08 19:17:14 | 000,101,720 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/08/08 19:10:20 | 000,064,512 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2011/08/08 19:10:20 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2011/08/08 19:09:46 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2011/08/08 19:09:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Lavasoft
[2011/08/08 19:09:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2011/08/08 18:03:28 | 000,000,000 | —D | C] – C:\WINDOWS\System32\WindowsPowerShell
[2011/08/08 18:03:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\winrm
[2011/08/08 18:03:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\GroupPolicy
[2011/08/08 18:03:07 | 000,000,000 | -H-D | C] – C:\WINDOWS\$968930Uinstall_KB968930$
[2011/08/08 17:36:15 | 000,068,608 | RHS- | C] (Znkzhqowz Edvhskpcpth) – C:\WINDOWS\System32\ds32gtt.dll
[2011/08/08 11:33:45 | 000,000,000 | —D | C] – C:\Program Files\Vstplugins
[2011/08/08 11:33:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Publish Providers
[2011/08/08 11:33:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\Vegas Movie Studio HD 9.0 Projects
[2011/08/08 11:31:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\Sony
[2011/08/08 11:27:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Sony
[2011/08/08 11:27:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sony
[2011/08/08 10:39:55 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russgies\IECompatCache
[2011/08/02 16:52:58 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2011/08/02 16:51:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/08/02 16:51:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/08/02 16:50:31 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/08/02 16:50:31 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/08/02 16:50:31 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/08/02 16:50:31 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/08/02 16:50:30 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/08/02 16:50:03 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/08/02 00:24:00 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2011/08/01 23:03:55 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/08/01 15:38:53 | 000,000,000 | —D | C] – C:\Program Files\Lame For Audacity
[2011/08/01 14:09:52 | 000,000,000 | —D | C] – C:\Program Files\Audacity
[2011/08/01 10:28:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russgies\My Documents\Dropbox
[2011/08/01 10:26:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Start Menu\Programs\Dropbox
[2011/08/01 10:26:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Dropbox
[2011/07/31 23:18:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\My Palettes
[2011/07/31 23:11:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\Corel
[2011/07/31 23:10:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\Visual Studio 2008
[2011/07/31 23:07:17 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SDKs
[2011/07/31 23:07:15 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2011/07/31 23:07:14 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 9.0
[2011/07/31 22:54:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CorelDRAW Graphics Suite X5
[2011/07/31 21:18:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Start Menu\Programs\Soulseek
[2011/07/31 21:18:22 | 000,000,000 | —D | C] – C:\Program Files\Soulseek
[2011/07/31 21:03:08 | 000,000,000 | -HSD | C] – C:\FOUND.000
[2011/07/28 00:22:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2011/07/28 00:22:09 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2011/07/28 00:21:38 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2011/07/28 00:21:38 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2011/07/28 00:21:38 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2011/07/28 00:21:38 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2011/07/28 00:21:38 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2011/07/28 00:21:38 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2011/07/26 19:46:50 | 000,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2011/07/26 19:45:59 | 000,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2011/07/26 19:32:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Sun
[2011/07/26 09:03:23 | 000,017,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/07/26 01:02:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CorelDRAW Graphics Suite X5
[2011/07/25 21:17:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\Corel VideoStudio Pro
[2011/07/25 21:16:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Protexis
[2011/07/25 21:16:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Corel
[2011/07/25 21:10:09 | 000,000,000 | —D | C] – C:\Program Files\SmartSound Software
[2011/07/25 21:10:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2011/07/25 21:08:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2011/07/25 21:08:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2011/07/25 21:07:55 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windows media
[2011/07/25 21:07:25 | 000,000,000 | —D | C] – C:\WINDOWS\RegisteredPackages
[2011/07/25 21:07:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Media
[2011/07/25 21:05:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Corel
[2011/07/25 21:04:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Corel VideoStudio Pro X4
[2011/07/25 20:58:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Protexis
[2011/07/25 20:58:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Corel
[2011/07/25 20:57:00 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_36.dll
[2011/07/25 20:57:00 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_10.dll
[2011/07/25 20:56:59 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_36.dll
[2011/07/25 20:56:59 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_36.dll
[2011/07/25 20:56:58 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_35.dll
[2011/07/25 20:56:58 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_9.dll
[2011/07/25 20:56:57 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_35.dll
[2011/07/25 20:56:57 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_35.dll
[2011/07/25 20:56:56 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_34.dll
[2011/07/25 20:56:56 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_8.dll
[2011/07/25 20:56:56 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_2.dll
[2011/07/25 20:56:55 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_34.dll
[2011/07/25 20:56:55 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_34.dll
[2011/07/25 20:56:54 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_3.dll
[2011/07/25 20:56:50 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_7.dll
[2011/07/25 20:56:45 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_33.dll
[2011/07/25 20:56:45 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_33.dll
[2011/07/25 20:56:40 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_33.dll
[2011/07/25 20:56:40 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_6.dll
[2011/07/25 20:56:39 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2011/07/25 20:56:39 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_5.dll
[2011/07/25 20:56:38 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_31.dll
[2011/07/25 20:56:38 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_4.dll
[2011/07/25 20:56:38 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_1.dll
[2011/07/25 20:56:37 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_3.dll
[2011/07/25 20:56:37 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_2.dll
[2011/07/25 20:56:37 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_2.dll
[2011/07/25 20:56:36 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_1.dll
[2011/07/25 20:56:36 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_1.dll
[2011/07/25 20:56:35 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2011/07/25 20:56:35 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_0.dll
[2011/07/25 20:56:35 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_0.dll
[2011/07/25 20:56:34 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_29.dll
[2011/07/25 20:56:34 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2011/07/25 20:56:33 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_27.dll
[2011/07/25 20:56:33 | 000,061,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput9_1_0.dll
[2011/07/25 20:56:32 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_25.dll
[2011/07/25 20:56:32 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_26.dll
[2011/07/25 20:56:30 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_24.dll
[2011/07/25 17:34:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\InterVideo
[2011/07/25 17:33:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Ulead VideoStudio 11
[2011/07/25 17:33:24 | 000,000,000 | —D | C] – C:\Program Files\Windows Media Components
[2011/07/25 17:32:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/07/25 17:32:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Ulead Systems
[2011/07/25 17:26:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\WMTools Downloaded Files
[2011/07/25 17:23:42 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russgies\My Documents\My Videos
[2011/07/25 17:23:42 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2011/07/25 17:15:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Philipp Winterberg
[2011/07/25 17:15:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Free RAR Extract Frog
[2011/07/25 17:15:53 | 000,000,000 | —D | C] – C:\Program Files\Free RAR Extract Frog
[2011/07/25 15:12:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Sony
[2011/07/25 13:44:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\Ulead VideoStudio
[2011/07/25 13:44:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Ulead Systems
[2011/07/25 13:43:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\InterVideo
[2011/07/25 13:34:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\NeroVision
[2011/07/21 23:33:01 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russgies\PrivacIE
[2011/07/21 23:32:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Real
[2011/07/21 23:22:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\vlc
[2011/07/21 18:07:38 | 002,095,600 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxsfs.dll
[2011/07/21 18:07:38 | 000,571,888 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxdrv.dll
[2011/07/21 18:07:38 | 000,133,616 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxafs.dll
[2011/07/21 18:07:38 | 000,126,448 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxinsi64.exe
[2011/07/21 18:07:38 | 000,123,888 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxcpyi64.exe
[2011/07/21 18:07:38 | 000,068,592 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxinsa64.exe
[2011/07/21 18:07:38 | 000,068,080 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxcpya64.exe
[2011/07/21 18:07:38 | 000,059,888 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxwma.dll
[2011/07/21 18:07:38 | 000,009,200 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys
[2011/07/21 18:07:38 | 000,009,072 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys
[2011/07/21 18:07:35 | 000,000,000 | —D | C] – C:\Program Files\Winamp
[2011/07/21 18:07:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Winamp
[2011/07/21 10:43:40 | 000,954,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40.dll
[2011/07/21 10:43:40 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011/07/21 10:40:38 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2011/07/21 10:39:36 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/07/21 10:37:50 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2011/07/21 10:31:04 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2011/07/21 10:30:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare 4
[2011/07/21 10:30:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\IObit
[2011/07/20 23:50:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
[2011/07/20 23:50:38 | 000,032,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msonpmon.dll
[2011/07/20 23:48:01 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2011/07/20 23:47:27 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2011/07/20 23:40:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\Microsoft Help
[2011/07/20 23:40:17 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/07/20 23:40:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2011/07/20 23:39:40 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/07/20 23:20:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\Ahead
[2011/07/20 23:18:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition
[2011/07/20 23:16:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Ahead
[2011/07/20 23:14:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Ahead
[2011/07/20 22:39:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/07/20 22:39:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2011/07/20 22:20:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\Solid State Networks
[2011/07/20 18:57:06 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/07/20 18:43:35 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/07/20 18:43:34 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2011/07/20 18:43:33 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2011/07/20 18:40:18 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2011/07/20 18:26:16 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2011/07/20 18:25:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\uTorrent
[2011/07/20 18:25:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\uTorrent
[2011/07/20 18:02:39 | 000,000,000 | —D | C] – C:\Program Files\BitTorrent
[2011/07/20 18:01:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\BitTorrent
[2011/07/20 17:23:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Macromedia
[2011/07/20 16:51:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/07/20 16:50:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\Apple
[2011/07/20 16:50:40 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/07/20 16:50:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2011/07/20 16:50:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\Apple Computer
[2011/07/20 16:48:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\Downloads
[2011/07/20 16:29:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Start Menu\Programs\Google Chrome
[2011/07/20 16:22:30 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russgies\IETldCache
[2011/07/20 16:16:40 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2011/07/20 16:16:27 | 001,991,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2011/07/20 16:16:27 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011/07/20 16:16:27 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2011/07/20 16:16:27 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2011/07/20 16:16:25 | 011,081,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2011/07/20 16:16:02 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2011/07/20 16:14:56 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/07/20 16:14:56 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2011/07/20 14:53:37 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2011/07/20 14:53:15 | 000,346,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecsext.dll
[2011/07/20 14:53:14 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2011/07/20 14:53:10 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2011/07/20 14:53:10 | 000,276,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmphoto.dll
[2011/07/20 14:53:08 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2011/07/20 14:53:06 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2011/07/20 14:53:05 | 000,412,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\photometadatahandler.dll
[2011/07/20 14:53:05 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2011/07/20 14:53:04 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2011/07/20 14:53:04 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2011/07/20 14:53:03 | 000,542,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\blackbox.dll
[2011/07/20 14:53:03 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2011/07/20 14:53:03 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2011/07/20 14:53:02 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2011/07/20 14:53:02 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2011/07/20 14:53:01 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2011/07/20 14:52:58 | 000,991,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\drmv2clt.dll
[2011/07/20 14:52:58 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2011/07/20 14:52:58 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2011/07/20 14:52:57 | 000,222,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmasf.dll
[2011/07/20 14:52:57 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2011/07/20 14:52:56 | 001,329,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\WMSPDMOE.dll
[2011/07/20 14:52:56 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2011/07/20 14:52:56 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2011/07/20 14:52:55 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2011/07/20 14:52:55 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2011/07/20 14:52:54 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2011/07/20 14:52:48 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2011/07/20 14:52:48 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2011/07/20 14:52:47 | 000,299,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\drmclien.dll
[2011/07/20 14:52:45 | 000,364,544 | —- | C] (Microsoft Corporation (written by Digital Renaissance Inc.)) – C:\WINDOWS\System32\dllcache\npdsplay.dll
[2011/07/20 14:52:44 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2011/07/20 14:52:44 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2011/07/20 14:52:41 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\verclsid.exe
[2011/07/20 14:52:40 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2011/07/20 14:52:40 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2011/07/20 14:52:40 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2011/07/20 14:52:40 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2011/07/20 14:52:40 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2011/07/20 14:52:39 | 000,414,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msscp.dll
[2011/07/20 14:52:38 | 000,102,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmpshell.dll
[2011/07/20 14:52:37 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmpband.dll
[2011/07/20 14:52:37 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2011/07/20 14:52:36 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmpns.dll
[2011/07/20 14:52:35 | 000,786,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\migrate.exe
[2011/07/20 14:52:33 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shmedia.dll
[2011/07/20 14:52:32 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmidx.dll
[2011/07/20 14:52:31 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\custsat.dll
[2011/07/20 14:52:27 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2011/07/20 14:52:27 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2011/07/20 14:52:26 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msnetobj.dll
[2011/07/20 14:52:26 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2011/07/20 14:52:26 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2011/07/20 14:52:26 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2011/07/20 14:52:25 | 000,774,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\setup_wm.exe
[2011/07/20 14:52:25 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\npdrmv2.dll
[2011/07/20 14:52:23 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mplay32.exe
[2011/07/20 14:52:19 | 000,368,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mpvis.dll
[2011/07/20 14:52:18 | 000,208,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\unregmp2.exe
[2011/07/20 14:52:17 | 000,294,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dlimport.exe
[2011/07/20 14:52:17 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ieencode.dll
[2011/07/20 14:52:16 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmsdmoe2.dll
[2011/07/20 14:52:15 | 000,303,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmstream.dll
[2011/07/20 14:52:15 | 000,114,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmpasf.dll
[2011/07/20 14:52:15 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmvdmoe2.dll
[2011/07/20 14:52:14 | 001,117,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\WMADMOE.dll
[2011/07/20 14:52:14 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmvdmod.dll
[2011/07/20 14:52:14 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmsdmod.dll
[2011/07/20 14:52:13 | 000,175,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mspmsp.dll
[2011/07/20 14:52:12 | 000,087,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\drmstor.dll
[2011/07/20 14:52:11 | 000,757,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\WMADMOD.dll
[2011/07/20 14:52:11 | 000,321,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswmdm.dll
[2011/07/20 14:52:10 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\MP4SDMOD.dll
[2011/07/20 14:52:10 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\MP43DMOD.dll
[2011/07/20 14:52:09 | 002,940,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmploc.dll
[2011/07/20 14:52:09 | 000,229,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cewmdm.dll
[2011/07/20 14:52:08 | 000,115,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmsdmoe.dll
[2011/07/20 14:52:08 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmplayer.exe
[2011/07/20 14:52:08 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mspmsnsv.dll
[2011/07/20 14:52:07 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\MPG4DMOD.dll
[2011/07/20 14:52:06 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadds32.ax
[2011/07/20 14:52:06 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmdmlog.dll
[2011/07/20 14:52:05 | 000,278,559 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmv8ds32.ax
[2011/07/20 14:52:04 | 000,262,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mpg4ds32.ax
[2011/07/20 14:52:04 | 000,258,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmvds32.ax
[2011/07/20 14:52:04 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msscds32.ax
[2011/07/20 14:52:03 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\npwmsdrm.dll
[2011/07/20 14:52:01 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\LAPRXY.dll
[2011/07/20 14:52:00 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmdmps.dll
[2011/07/20 14:52:00 | 000,004,639 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mplayer2.exe
[2011/07/20 14:51:58 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmpcore.dll
[2011/07/20 14:51:57 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmpui.dll
[2011/07/20 14:51:57 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmpcd.dll
[2011/07/20 14:51:56 | 000,168,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmerror.dll
[2011/07/20 14:51:54 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmp.ocx
[2011/07/20 14:51:53 | 000,294,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msaud32.acm
[2011/07/20 14:51:53 | 000,290,816 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\WINDOWS\System32\dllcache\l3codeca.acm
[2011/07/20 14:51:52 | 000,086,016 | —- | C] (Sipro Lab Telecom Inc.) – C:\WINDOWS\System32\dllcache\sl_anet.acm
[2011/07/20 14:31:27 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2011/07/20 14:31:11 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srv.sys
[2011/07/20 14:30:58 | 000,456,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2011/07/20 14:30:52 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2011/07/20 14:30:42 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2011/07/20 14:30:19 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\t2embed.dll
[2011/07/20 14:30:19 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fontsub.dll
[2011/07/20 14:30:10 | 002,192,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2011/07/20 14:30:10 | 002,148,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2011/07/20 14:30:09 | 002,027,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2011/07/20 14:29:54 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2011/07/20 14:28:57 | 000,203,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rmcast.sys
[2011/07/20 14:28:50 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2011/07/20 14:27:16 | 002,066,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstscax.dll
[2011/07/20 14:27:01 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2011/07/20 14:27:00 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml3.dll
[2011/07/20 14:22:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2011/07/20 14:22:11 | 000,000,000 | -H-D | C] – C:\WINDOWS\$hf_mig$
[2011/07/20 14:21:56 | 000,000,000 | -H-D | C] – C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2011/07/20 14:11:02 | 000,000,000 | —D | C] – C:\WINDOWS\peernet
[2011/07/20 14:11:01 | 000,000,000 | —D | C] – C:\WINDOWS\provisioning
[2011/07/20 14:07:48 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2011/07/20 14:01:23 | 000,026,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spupdsvc.exe
[2011/07/20 13:58:12 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2011/07/20 13:58:06 | 000,000,000 | —D | C] – C:\WINDOWS\EHome
[2011/07/20 13:47:39 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spnpinst.exe
[2011/07/20 13:41:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2011/07/20 13:37:35 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/07/20 13:37:20 | 000,438,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpob2res.dll
[2011/07/20 13:37:20 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx3.dll
[2011/07/20 13:37:19 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qmgrprxy.dll
[2011/07/20 13:37:19 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx2.dll
[2011/07/20 13:36:27 | 000,575,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll
[2011/07/20 13:36:27 | 000,327,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll
[2011/07/20 13:36:27 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wups2.dll
[2011/07/20 13:36:27 | 000,035,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wups.dll
[2011/07/20 13:36:27 | 000,021,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll.mui
[2011/07/20 13:36:27 | 000,015,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll.mui
[2011/07/20 13:36:01 | 000,000,000 | —D | C] – C:\WINDOWS\SoftwareDistribution
[2011/07/20 13:34:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\Mozilla
[2011/07/20 13:34:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Mozilla
[2011/07/20 13:34:33 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/07/20 13:31:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\Google
[2011/07/20 13:31:07 | 000,000,000 | –SD | C] – C:\Documents and Settings\Russgies\UserData
[2011/07/20 13:26:47 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2011/07/20 13:22:15 | 000,111,616 | —- | C] (Lernout & Hauspie) – C:\WINDOWS\System32\Ltih30tb.dll
[2011/07/20 13:22:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\WexTech Shared
[2011/07/20 13:22:15 | 000,000,000 | —D | C] – C:\Program Files\WexTech
[2011/07/20 13:22:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\LHSPF
[2011/07/20 13:21:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\Corel User Files
[2011/07/20 13:20:42 | 000,000,000 | —D | C] – C:\WINDOWS\ShellNew
[2011/07/20 13:18:24 | 000,000,000 | —D | C] – C:\Program Files\Borland
[2011/07/20 13:18:13 | 000,401,462 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\31413
[2011/07/20 13:18:11 | 000,133,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MFCANS32.DLL
[2011/07/20 13:18:11 | 000,093,184 | —- | C] (Novell Inc.) – C:\WINDOWS\System32\LTIH21TB.DLL
[2011/07/20 13:18:11 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mfcuia32.dll
[2011/07/20 13:16:12 | 000,000,000 | —D | C] – C:\WINDOWS\Corel
[2011/07/20 13:14:49 | 000,643,072 | —- | C] (Lake Technology Limited, http://www.lake.com.au) – C:\WINDOWS\System32\DolbyHph.dll
[2011/07/20 13:14:49 | 000,208,896 | —- | C] (Mediamatics, Inc.) – C:\WINDOWS\System32\DVDRGCTL.dll
[2011/07/20 13:14:49 | 000,193,536 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\AllNode.DLL
[2011/07/20 13:14:49 | 000,040,960 | —- | C] (Lake Technology Limited http://www.lake.com) – C:\WINDOWS\System32\DolbyHphMM.dll
[2011/07/20 13:14:49 | 000,007,196 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\drivers\V7.SYS
[2011/07/20 13:14:48 | 000,146,432 | —- | C] (Mediamatics Inc) – C:\WINDOWS\System32\Mmac3.dll
[2011/07/20 13:14:48 | 000,000,000 | —D | C] – C:\Program Files\Mediamatics
[2011/07/20 13:13:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Media Bar
[2011/07/20 13:13:00 | 000,000,000 | —D | C] – C:\ucd
[2011/07/20 13:11:31 | 000,000,000 | –SD | C] – C:\Documents and Settings\Russgies\Application Data\Microsoft
[2011/07/20 13:11:31 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russgies\SendTo
[2011/07/20 13:11:31 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russgies\Recent
[2011/07/20 13:11:31 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russgies\Application Data
[2011/07/20 13:11:31 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russgies\Start Menu\Programs\Startup
[2011/07/20 13:11:31 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russgies\Start Menu
[2011/07/20 13:11:31 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russgies\My Documents\My Pictures
[2011/07/20 13:11:31 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russgies\My Documents\My Music
[2011/07/20 13:11:31 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russgies\My Documents
[2011/07/20 13:11:31 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russgies\Favorites
[2011/07/20 13:11:31 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russgies\Start Menu\Programs\Accessories
[2011/07/20 13:11:31 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russgies\Cookies
[2011/07/20 13:11:31 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russgies\Templates
[2011/07/20 13:11:31 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russgies\PrintHood
[2011/07/20 13:11:31 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russgies\NetHood
[2011/07/20 13:11:31 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russgies\Local Settings
[2011/07/20 13:11:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\WINDOWS
[2011/07/20 13:11:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Sony Corporation
[2011/07/20 13:11:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\My Documents\My eBooks
[2011/07/20 13:11:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Local Settings\Application Data\Microsoft
[2011/07/20 13:11:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\InterTrust
[2011/07/20 13:11:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Identities
[2011/07/20 13:11:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Desktop
[2011/07/20 13:11:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Russgies\Application Data\Adobe
[2011/07/20 13:11:18 | 000,000,000 | –SD | C] – C:\WINDOWS\System32\Microsoft
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Russgies\My Documents\*.tmp files -> C:\Documents and Settings\Russgies\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/16 14:35:02 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/16 14:35:02 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/16 14:07:02 | 000,000,294 | -H– | M] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2011/08/16 13:56:02 | 000,000,294 | -H– | M] () – C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2011/08/16 12:57:46 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/08/15 19:53:22 | 000,001,499 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2011/08/15 19:19:30 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/08/15 19:19:16 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\rp_stats.dat
[2011/08/15 19:19:16 | 000,000,044 | —- | M] () – C:\WINDOWS\System32\rp_rules.dat
[2011/08/15 00:49:08 | 000,000,264 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/08/12 11:09:30 | 000,001,990 | —- | M] () – C:\Documents and Settings\Russgies\Desktop\HiJackThis.lnk
[2011/08/12 10:39:00 | 000,002,052 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/08/12 10:38:40 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/12 01:18:06 | 000,000,938 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-329068152-926492609-725345543-1004Core1cc4e883b97b5be.job
[2011/08/12 00:58:32 | 000,000,306 | -HS- | M] () – C:\WINDOWS\tasks\vzuhvje.job
[2011/08/12 00:58:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/12 00:58:10 | 536,449,024 | -HS- | M] () – C:\hiberfil.sys
[2011/08/12 00:54:48 | 000,435,260 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/12 00:54:48 | 000,068,156 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/11 16:33:10 | 001,404,720 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Russgies\Desktop\TDSSKiller.exe
[2011/08/11 13:44:08 | 000,027,136 | —- | M] () – C:\Documents and Settings\Russgies\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/11 11:17:28 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/08/09 23:40:42 | 006,922,240 | —- | M] () – C:\Documents and Settings\All Users\Documents\Atom to universe.mpg
[2011/08/08 19:17:14 | 000,101,720 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/08/08 19:17:14 | 000,016,432 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2011/08/08 19:10:34 | 000,000,701 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2011/08/08 17:36:16 | 000,068,608 | RHS- | M] (Znkzhqowz Edvhskpcpth) – C:\WINDOWS\System32\ds32gtt.dll
[2011/08/05 10:31:18 | 000,093,872 | —- | M] () – C:\Documents and Settings\Russgies\My Documents\Shouldice map.jpg
[2011/08/02 16:50:12 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/08/02 16:50:12 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/08/02 16:50:12 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/08/02 16:50:12 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/08/02 16:50:12 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/08/02 01:22:18 | 000,373,672 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/08/01 23:03:56 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/08/01 14:46:34 | 000,479,697 | —- | M] () – C:\Documents and Settings\Russgies\My Documents\iris pics.cdr
[2011/08/01 10:28:06 | 000,000,911 | —- | M] () – C:\Documents and Settings\Russgies\Desktop\Dropbox.lnk
[2011/08/01 10:26:42 | 000,000,911 | —- | M] () – C:\Documents and Settings\Russgies\Start Menu\Programs\Startup\Dropbox.lnk
[2011/07/26 19:51:00 | 000,000,134 | —- | M] () – C:\Documents and Settings\Russgies\Desktop\Microsoft Fix it.url
[2011/07/26 09:22:04 | 000,000,052 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
[2011/07/26 00:49:14 | 000,000,952 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/07/25 23:44:38 | 000,002,828 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2011/07/25 23:18:00 | 000,000,008 | RHS- | M] () – C:\Documents and Settings\All Users\Application Data\F3AA723DE9.sys
[2011/07/25 21:09:44 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/07/25 21:08:56 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2011/07/25 21:04:40 | 000,000,541 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Corel VideoStudio Pro X4.lnk
[2011/07/25 17:33:44 | 000,000,538 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ulead VideoStudio 11.lnk
[2011/07/25 16:04:10 | 000,000,582 | —- | M] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/07/25 16:00:32 | 000,043,062 | —- | M] () – C:\Documents and Settings\Russgies\My Documents\UserImages.bmp
[2011/07/25 14:31:52 | 000,000,042 | —- | M] () – C:\Documents and Settings\Russgies\default.pls
[2011/07/25 09:17:44 | 005,969,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2011/07/21 23:38:20 | 000,000,997 | —- | M] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to vlc.lnk
[2011/07/21 14:59:08 | 000,064,512 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2011/07/20 23:18:14 | 000,001,305 | —- | M] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk
[2011/07/20 23:18:14 | 000,001,237 | —- | M] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home.lnk
[2011/07/20 18:40:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/20 16:50:46 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/07/20 16:46:06 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/07/20 16:46:06 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2011/07/20 16:43:24 | 000,000,599 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2011/07/20 16:41:42 | 000,000,053 | —- | M] () – C:\WINDOWS\photoprn.ini
[2011/07/20 16:29:30 | 000,002,191 | —- | M] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/07/20 16:22:34 | 000,000,719 | —- | M] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/20 14:13:08 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2011/07/20 14:03:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/07/20 13:34:50 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2011/07/20 13:34:36 | 000,000,646 | —- | M] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/07/20 13:14:52 | 000,000,000 | —- | M] () – C:\WINDOWS\MPLAYER.INI
[2011/07/20 13:11:24 | 000,000,524 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Russgies\My Documents\*.tmp files -> C:\Documents and Settings\Russgies\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/12 11:09:29 | 000,001,990 | —- | C] () – C:\Documents and Settings\Russgies\Desktop\HiJackThis.lnk
[2011/08/12 10:38:58 | 000,002,052 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/08/11 20:07:28 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/08/11 20:07:28 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/08/11 12:36:31 | 000,001,499 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2011/08/11 10:35:39 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/08/09 23:40:21 | 006,922,240 | —- | C] () – C:\Documents and Settings\All Users\Documents\Atom to universe.mpg
[2011/08/09 14:30:03 | 000,000,890 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/09 14:30:01 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/08 20:22:38 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2011/08/08 19:11:08 | 000,000,486 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/08/08 19:10:32 | 000,000,701 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2011/08/08 18:05:59 | 000,225,262 | —- | C] () – C:\WINDOWS\System32\dllcache\msimain.sdb
[2011/08/08 17:36:16 | 000,000,306 | -HS- | C] () – C:\WINDOWS\tasks\vzuhvje.job
[2011/08/08 17:35:26 | 000,000,294 | -H– | C] () – C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2011/08/08 17:35:21 | 000,000,294 | -H– | C] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2011/08/05 10:31:13 | 000,093,872 | —- | C] () – C:\Documents and Settings\Russgies\My Documents\Shouldice map.jpg
[2011/08/02 00:24:10 | 000,216,424 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/08/01 14:46:22 | 000,479,697 | —- | C] () – C:\Documents and Settings\Russgies\My Documents\iris pics.cdr
[2011/08/01 14:09:55 | 000,000,540 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Audacity.lnk
[2011/08/01 10:28:04 | 000,000,911 | —- | C] () – C:\Documents and Settings\Russgies\Desktop\Dropbox.lnk
[2011/08/01 10:26:40 | 000,000,911 | —- | C] () – C:\Documents and Settings\Russgies\Start Menu\Programs\Startup\Dropbox.lnk
[2011/07/30 01:13:50 | 000,000,938 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-329068152-926492609-725345543-1004Core1cc4e883b97b5be.job
[2011/07/26 19:50:59 | 000,000,134 | —- | C] () – C:\Documents and Settings\Russgies\Desktop\Microsoft Fix it.url
[2011/07/26 00:46:48 | 000,000,952 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/07/25 23:17:59 | 000,002,828 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2011/07/25 23:17:59 | 000,000,008 | RHS- | C] () – C:\Documents and Settings\All Users\Application Data\F3AA723DE9.sys
[2011/07/25 21:08:54 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2011/07/25 21:04:38 | 000,000,541 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Corel VideoStudio Pro X4.lnk
[2011/07/25 17:33:59 | 000,210,456 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2011/07/25 17:33:59 | 000,206,360 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2011/07/25 17:33:59 | 000,198,168 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2011/07/25 17:33:59 | 000,198,168 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2011/07/25 17:33:59 | 000,194,072 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2011/07/25 17:33:59 | 000,026,136 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2011/07/25 17:33:43 | 000,000,538 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ulead VideoStudio 11.lnk
[2011/07/25 16:00:31 | 000,043,062 | —- | C] () – C:\Documents and Settings\Russgies\My Documents\UserImages.bmp
[2011/07/21 23:38:19 | 000,000,997 | —- | C] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to vlc.lnk
[2011/07/21 10:33:19 | 000,000,264 | —- | C] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/07/21 10:30:49 | 000,000,582 | —- | C] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/07/20 23:24:24 | 000,000,042 | —- | C] () – C:\Documents and Settings\Russgies\default.pls
[2011/07/20 23:22:13 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2011/07/20 23:18:13 | 000,001,305 | —- | C] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk
[2011/07/20 23:18:13 | 000,001,237 | —- | C] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home.lnk
[2011/07/20 17:25:31 | 000,027,136 | —- | C] () – C:\Documents and Settings\Russgies\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/20 16:50:44 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/07/20 16:50:41 | 000,001,830 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/07/20 16:46:05 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2011/07/20 16:46:05 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2011/07/20 16:29:29 | 000,002,191 | —- | C] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/07/20 16:22:19 | 536,449,024 | -HS- | C] () – C:\hiberfil.sys
[2011/07/20 14:52:46 | 000,498,742 | —- | C] () – C:\WINDOWS\System32\dllcache\dxmasf.dll
[2011/07/20 14:52:42 | 000,023,195 | —- | C] () – C:\WINDOWS\System32\dllcache\wmplay.chm
[2011/07/20 14:52:32 | 000,067,374 | —- | C] () – C:\WINDOWS\System32\dllcache\wmplayer.adm
[2011/07/20 14:52:21 | 000,184,959 | —- | C] () – C:\WINDOWS\System32\dllcache\compact.wmz
[2011/07/20 14:52:12 | 000,066,725 | —- | C] () – C:\WINDOWS\System32\dllcache\revert.wmz
[2011/07/20 14:51:59 | 000,844,314 | —- | C] () – C:\WINDOWS\System32\dllcache\msdxm.ocx
[2011/07/20 14:51:53 | 000,029,070 | —- | C] () – C:\WINDOWS\System32\dllcache\wmp.inf
[2011/07/20 14:51:50 | 000,004,126 | —- | C] () – C:\WINDOWS\System32\dllcache\msdxmlc.dll
[2011/07/20 14:51:45 | 000,009,585 | —- | C] () – C:\WINDOWS\System32\dllcache\controls.css
[2011/07/20 14:51:45 | 000,008,298 | —- | C] () – C:\WINDOWS\System32\dllcache\contents.htm
[2011/07/20 14:51:45 | 000,006,878 | —- | C] () – C:\WINDOWS\System32\dllcache\controls.js
[2011/07/20 14:51:45 | 000,000,999 | —- | C] () – C:\WINDOWS\System32\dllcache\bktrh.gif
[2011/07/20 14:51:45 | 000,000,773 | —- | C] () – C:\WINDOWS\System32\dllcache\cnth.gif
[2011/07/20 14:51:45 | 000,000,773 | —- | C] () – C:\WINDOWS\System32\dllcache\cnt.gif
[2011/07/20 14:51:45 | 000,000,772 | —- | C] () – C:\WINDOWS\System32\dllcache\cntd.gif
[2011/07/20 14:51:45 | 000,000,760 | —- | C] () – C:\WINDOWS\System32\dllcache\cloapph.gif
[2011/07/20 14:51:45 | 000,000,717 | —- | C] () – C:\WINDOWS\System32\dllcache\cloapp.gif
[2011/07/20 14:51:44 | 000,381,425 | —- | C] () – C:\WINDOWS\System32\dllcache\copycd.wmv
[2011/07/20 14:51:44 | 000,005,971 | —- | C] () – C:\WINDOWS\System32\dllcache\events.js
[2011/07/20 14:51:42 | 000,001,261 | —- | C] () – C:\WINDOWS\System32\pid.inf
[2011/07/20 14:51:41 | 000,457,607 | —- | C] () – C:\WINDOWS\System32\dllcache\mdlib.wmv
[2011/07/20 14:51:40 | 000,375,519 | —- | C] () – C:\WINDOWS\System32\dllcache\nuskin.wmv
[2011/07/20 14:51:40 | 000,077,307 | —- | C] () – C:\WINDOWS\System32\dllcache\plyr_err.chm
[2011/07/20 14:51:40 | 000,022,060 | —- | C] () – C:\WINDOWS\System32\dllcache\npds.zip
[2011/07/20 14:51:40 | 000,018,286 | —- | C] () – C:\WINDOWS\System32\dllcache\mplayer2.inf
[2011/07/20 14:51:40 | 000,002,778 | —- | C] () – C:\WINDOWS\System32\dllcache\mplogoh.gif
[2011/07/20 14:51:40 | 000,002,545 | —- | C] () – C:\WINDOWS\System32\dllcache\mplogo.gif
[2011/07/20 14:51:40 | 000,001,477 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst6.wpl
[2011/07/20 14:51:40 | 000,001,477 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst5.wpl
[2011/07/20 14:51:40 | 000,001,474 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst3.wpl
[2011/07/20 14:51:40 | 000,001,451 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst12.wpl
[2011/07/20 14:51:40 | 000,001,448 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst4.wpl
[2011/07/20 14:51:40 | 000,001,250 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst1.wpl
[2011/07/20 14:51:40 | 000,001,049 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst2.wpl
[2011/07/20 14:51:40 | 000,001,046 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst7.wpl
[2011/07/20 14:51:40 | 000,001,036 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst8.wpl
[2011/07/20 14:51:40 | 000,000,789 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst11.wpl
[2011/07/20 14:51:40 | 000,000,787 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst10.wpl
[2011/07/20 14:51:40 | 000,000,784 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst9.wpl
[2011/07/20 14:51:40 | 000,000,783 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst13.wpl
[2011/07/20 14:51:40 | 000,000,775 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst14.wpl
[2011/07/20 14:51:40 | 000,000,733 | —- | C] () – C:\WINDOWS\System32\dllcache\plylst15.wpl
[2011/07/20 14:51:40 | 000,000,403 | —- | C] () – C:\WINDOWS\System32\dllcache\npdrmv2.zip
[2011/07/20 14:51:39 | 000,572,557 | —- | C] () – C:\WINDOWS\System32\dllcache\rtuner.wmv
[2011/07/20 14:51:39 | 000,300,969 | —- | C] () – C:\WINDOWS\System32\dllcache\viz.wmv
[2011/07/20 14:51:39 | 000,023,829 | —- | C] () – C:\WINDOWS\System32\dllcache\tourbg.gif
[2011/07/20 14:51:39 | 000,017,489 | —- | C] () – C:\WINDOWS\System32\dllcache\videobg.gif
[2011/07/20 14:51:39 | 000,005,290 | —- | C] () – C:\WINDOWS\System32\dllcache\vidsamp.gif
[2011/07/20 14:51:39 | 000,003,187 | —- | C] () – C:\WINDOWS\System32\dllcache\tour.js
[2011/07/20 14:51:39 | 000,002,469 | —- | C] () – C:\WINDOWS\System32\dllcache\tplay.gif
[2011/07/20 14:51:39 | 000,002,450 | —- | C] () – C:\WINDOWS\System32\dllcache\tpause.gif
[2011/07/20 14:51:39 | 000,002,375 | —- | C] () – C:\WINDOWS\System32\dllcache\tplayh.gif
[2011/07/20 14:51:39 | 000,002,371 | —- | C] () – C:\WINDOWS\System32\dllcache\tpauseh.gif
[2011/07/20 14:51:39 | 000,001,398 | —- | C] () – C:\WINDOWS\System32\dllcache\taon.gif
[2011/07/20 14:51:39 | 000,001,380 | —- | C] () – C:\WINDOWS\System32\dllcache\taonh.gif
[2011/07/20 14:51:39 | 000,001,380 | —- | C] () – C:\WINDOWS\System32\dllcache\taoff.gif
[2011/07/20 14:51:39 | 000,001,367 | —- | C] () – C:\WINDOWS\System32\dllcache\taoffh.gif
[2011/07/20 14:51:39 | 000,001,148 | —- | C] () – C:\WINDOWS\System32\dllcache\snd.htm
[2011/07/20 14:51:39 | 000,000,908 | —- | C] () – C:\WINDOWS\System32\dllcache\skins.inf
[2011/07/20 14:51:38 | 000,613,334 | —- | C] () – C:\WINDOWS\System32\dllcache\wmplayer.chm
[2011/07/20 14:51:38 | 000,354,468 | —- | C] () – C:\WINDOWS\System32\dllcache\wmpaud1.wav
[2011/07/20 14:51:38 | 000,343,204 | —- | C] () – C:\WINDOWS\System32\dllcache\wmpaud7.wav
[2011/07/20 14:51:38 | 000,343,204 | —- | C] () – C:\WINDOWS\System32\dllcache\wmpaud6.wav
[2011/07/20 14:51:38 | 000,172,196 | —- | C] () – C:\WINDOWS\System32\dllcache\wmpaud9.wav
[2011/07/20 14:51:38 | 000,172,196 | —- | C] () – C:\WINDOWS\System32\dllcache\wmpaud8.wav
[2011/07/20 14:51:38 | 000,172,196 | —- | C] () – C:\WINDOWS\System32\dllcache\wmpaud3.wav
[2011/07/20 14:51:38 | 000,086,196 | —- | C] () – C:\WINDOWS\System32\dllcache\wmpaud5.wav
[2011/07/20 14:51:38 | 000,086,180 | —- | C] () – C:\WINDOWS\System32\dllcache\wmpaud4.wav
[2011/07/20 14:51:38 | 000,086,180 | —- | C] () – C:\WINDOWS\System32\dllcache\wmpaud2.wav
[2011/07/20 14:51:38 | 000,017,272 | —- | C] () – C:\WINDOWS\System32\dllcache\wmdm.inf
[2011/07/20 14:51:38 | 000,010,457 | —- | C] () – C:\WINDOWS\System32\dllcache\wmptour.hta
[2011/07/20 14:51:38 | 000,008,677 | —- | C] () – C:\WINDOWS\System32\dllcache\wm7.gif
[2011/07/20 14:51:38 | 000,007,892 | —- | C] () – C:\WINDOWS\System32\dllcache\wm9.gif
[2011/07/20 14:51:38 | 000,007,636 | —- | C] () – C:\WINDOWS\System32\dllcache\wm2.gif
[2011/07/20 14:51:38 | 000,007,369 | —- | C] () – C:\WINDOWS\System32\dllcache\wm4.gif
[2011/07/20 14:51:38 | 000,006,769 | —- | C] () – C:\WINDOWS\System32\dllcache\wmfsdk.inf
[2011/07/20 14:51:38 | 000,006,241 | —- | C] () – C:\WINDOWS\System32\dllcache\wm3.gif
[2011/07/20 14:51:38 | 000,006,060 | —- | C] () – C:\WINDOWS\System32\dllcache\wm6.gif
[2011/07/20 14:51:38 | 000,005,789 | —- | C] () – C:\WINDOWS\System32\dllcache\wm1.gif
[2011/07/20 14:51:38 | 000,004,193 | —- | C] () – C:\WINDOWS\System32\dllcache\wm8.gif
[2011/07/20 14:51:38 | 000,002,477 | —- | C] () – C:\WINDOWS\System32\dllcache\wm5.gif
[2011/07/20 14:51:38 | 000,001,771 | —- | C] () – C:\WINDOWS\System32\dllcache\wmptour.css
[2011/07/20 14:51:38 | 000,000,855 | —- | C] () – C:\WINDOWS\System32\dllcache\wmpocm.inf
[2011/07/20 14:51:38 | 000,000,420 | —- | C] () – C:\WINDOWS\System32\dllcache\wmploc.js
[2011/07/20 14:12:44 | 000,316,640 | —- | C] () – C:\WINDOWS\WMSysPr9.prx
[2011/07/20 13:47:39 | 000,007,208 | —- | C] () – C:\WINDOWS\System32\secupd.sig
[2011/07/20 13:47:39 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2011/07/20 13:34:49 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/20 13:34:35 | 000,000,646 | —- | C] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/07/20 13:34:35 | 000,000,634 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/07/20 13:21:43 | 000,000,052 | —- | C] () – C:\WINDOWS\System32\mapisvc.inf
[2011/07/20 13:17:42 | 001,213,440 | —- | C] () – C:\WINDOWS\System32\opengl.dll
[2011/07/20 13:17:41 | 000,154,624 | —- | C] () – C:\WINDOWS\System32\glut.dll
[2011/07/20 13:17:40 | 000,315,904 | —- | C] () – C:\WINDOWS\System32\glu.dll
[2011/07/20 13:14:50 | 000,000,000 | —- | C] () – C:\WINDOWS\MPLAYER.INI
[2011/07/20 13:14:49 | 000,157,696 | —- | C] () – C:\WINDOWS\System32\LakeSwitch.exe
[2011/07/20 13:14:49 | 000,067,584 | —- | C] () – C:\WINDOWS\System32\macrovsn.dll
[2011/07/20 13:14:49 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\MMDVDROM.dll
[2011/07/20 13:14:49 | 000,004,900 | -H– | C] () – C:\WINDOWS\System32\DolbyHph.ll
[2011/07/20 13:14:49 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\getregn.exe
[2011/07/20 13:11:32 | 000,001,503 | —- | C] () – C:\Documents and Settings\Russgies\Start Menu\Programs\Remote Assistance.lnk
[2011/07/20 13:11:32 | 000,000,719 | —- | C] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/20 13:11:32 | 000,000,707 | —- | C] () – C:\Documents and Settings\Russgies\Start Menu\Programs\Internet Explorer.lnk
[2011/07/20 13:11:32 | 000,000,696 | —- | C] () – C:\Documents and Settings\Russgies\Start Menu\Programs\Windows Media Player.lnk
[2011/07/20 13:11:32 | 000,000,642 | —- | C] () – C:\Documents and Settings\Russgies\Start Menu\Programs\Outlook Express.lnk
[2011/07/20 13:11:32 | 000,000,079 | —- | C] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2001/09/08 13:06:47 | 000,000,051 | —- | C] () – C:\WINDOWS\intuprof.ini
[2001/09/08 13:06:46 | 000,007,406 | —- | C] () – C:\WINDOWS\ICOADB32.DAT
[2001/09/08 13:06:46 | 000,000,599 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2001/09/08 13:03:28 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\TDI-SonyOMG.dll
[2001/09/08 13:03:27 | 000,262,416 | —- | C] () – C:\WINDOWS\System32\Asfv2.dll
[2001/09/08 12:58:38 | 000,343,040 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
[2001/09/08 12:58:38 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\lfkodak.dll
[2001/09/08 12:58:16 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2001/09/08 12:53:08 | 000,000,053 | —- | C] () – C:\WINDOWS\photoprn.ini
[2001/09/08 11:55:30 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2001/09/08 11:14:34 | 000,000,782 | —- | C] () – C:\WINDOWS\orun32.ini
[2001/09/08 11:13:00 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2001/09/08 11:10:07 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2001/09/08 11:04:28 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2001/09/08 10:59:08 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2001/09/08 10:58:22 | 000,373,672 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2001/09/08 10:53:54 | 000,000,672 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/09/08 10:53:23 | 000,435,260 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/09/08 10:53:23 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/09/08 10:53:23 | 000,068,156 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/09/08 10:53:23 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/09/08 10:53:22 | 000,004,530 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/09/08 10:53:19 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/09/08 10:53:18 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2001/09/08 10:53:11 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/09/08 10:53:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/09/08 10:53:03 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/09/08 10:52:53 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin

========== LOP Check ==========

[2011/07/25 17:32:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/07/25 17:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InterVideo
[2011/07/25 21:10:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2011/08/08 11:27:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2011/08/09 23:08:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Freemake
[2001/09/08 13:02:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Russgies\Application Data\InterTrust
[2011/07/20 18:01:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Russgies\Application Data\BitTorrent
[2011/07/20 18:25:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Russgies\Application Data\uTorrent
[2011/07/21 10:30:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Russgies\Application Data\IObit
[2011/07/25 13:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Russgies\Application Data\Ulead Systems
[2011/07/25 15:12:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Russgies\Application Data\Sony
[2011/07/25 17:16:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Russgies\Application Data\Philipp Winterberg
[2011/08/01 10:26:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Russgies\Application Data\Dropbox
[2011/08/08 11:33:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Russgies\Application Data\Publish Providers
[2011/08/16 13:56:02 | 000,000,294 | -H– | M] () – C:\WINDOWS\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2011/08/16 14:07:02 | 000,000,294 | -H– | M] () – C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2011/08/15 19:19:30 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/08/15 00:49:08 | 000,000,264 | —- | M] () – C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/08/12 00:58:32 | 000,000,306 | -HS- | M] () – C:\WINDOWS\Tasks\vzuhvje.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/07/20 18:40:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/20 14:03:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/07/20 14:13:08 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2001/09/08 11:07:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2001/09/08 11:07:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2001/09/08 11:07:08 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2001/09/08 11:07:08 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/08/12 00:58:08 | 991,952,896 | -HS- | M] () – C:\pagefile.sys
[2011/08/12 00:58:06 | 000,002,879 | —- | M] () – C:\aaw7boot.log
[2011/08/16 14:39:48 | 000,038,598 | —- | M] () – C:\TDSSKiller.2.5.15.0_16.08.2011_14.34.07_log.txt
[2011/08/12 00:58:10 | 536,449,024 | -HS- | M] () – C:\hiberfil.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2001/09/08 11:06:38 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 04:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2001/09/08 10:57:48 | 000,385,024 | —- | M] () – C:\WINDOWS\System32\config\system.sav
[2001/09/08 10:57:48 | 000,610,304 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2001/09/08 10:57:48 | 000,090,112 | —- | M] () – C:\WINDOWS\System32\config\default.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/07/20 18:44:30 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2001/09/08 11:16:26 | 000,000,148 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\winbom.log

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2001/09/08 11:14:20 | 000,000,079 | —- | M] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/07/20 14:19:00 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Russgies\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/08/11 16:33:10 | 001,404,720 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Russgies\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2011/07/20 14:19:00 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Russgies\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/08/16 10:34:26 | 000,081,920 | —- | M] () – C:\Documents and Settings\Russgies\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-11 17:22:28

< End of report >



OTL Extras logfile created on: 8/16/2011 2:45:37 PM - Run 1
OTL by OldTimer - Version 3.2.26.4 Folder = C:\Documents and Settings\Russgies\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.53 Mb Total Physical Memory | 298.27 Mb Available Physical Memory | 58.31% Memory free
1.39 Gb Paging File | 0.90 Gb Available in Paging File | 64.59% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15.60 Gb Total Space | 1.88 Gb Free Space | 12.02% Space Free | Partition Type: FAT32
Drive D: | 37.26 Gb Total Space | 2.35 Gb Free Space | 6.30% Space Free | Partition Type: FAT32
Drive E: | 40.27 Gb Total Space | 10.36 Gb Free Space | 25.73% Space Free | Partition Type: NTFS

Computer Name: VAIO | User Name: Russgies | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:TCP" = 1900:TCP:LocalSubNet:Enabled:UDP 1900
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\support.com\client\bin\tgcmd.exe" = C:\Program Files\support.com\client\bin\tgcmd.exe:*:Enabled:tgcmd Module – (Support.com, Inc.)
"C:\Program Files\BitTorrent\BitTorrent.exe" = C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Soulseek\slsk.exe" = C:\Program Files\Soulseek\slsk.exe:*:Enabled:SoulSeek – ()
"C:\Documents and Settings\Russgies\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Russgies\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{AA902C31-B49D-4608-BCCF-2519EB77722D}" = Corel VideoStudio Pro X4
"_{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}" = Corel Graphics - Windows Shell Extension
"_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW® Graphics Suite X5
"{052B4734-CD9B-468F-B25D-D1E136B2C95A}" = Ad-Aware
"{21CF3E6E-1659-433E-B6CE-165D793560DA}" = VAIO Grid Wallpaper
"{24D9A3E0-D086-4B62-AF93-63CF6B05CB48}" = CorelDRAW Graphics Suite X5 - Custom Data
"{260ED378-2B8C-4831-ADAE-D0712D119AC5}" = CorelDRAW Graphics Suite X5 - VSTA
"{26945917-E053-45F6-AF98-309730CFC318}" = Visual Basic for Applications ® Core
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 26
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{29F61465-428A-11D4-B646-00C04F790F76}" = DVgate
"{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"{2FAF5A9F-7EDE-4F1A-B082-C95A9F420630}" = Media Bar 3.2.11
"{3472C84E-2FD0-439F-B27F-C290C1E4CD8B}" = CorelDRAW Graphics Suite X5 - Filters
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3990E632-42C3-4A25-ADFF-1101E3D6DD47}" = VSClassic
"{3B24B725-D81F-442D-8CE5-2AF05A4A4CC9}" = Music Visualizer Library 1.1
"{3C67D8C0-F0EC-11D3-99D3-00C04FCCB775}" = VAIO Action Setup
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{48BE827A-2D06-4804-90C3-4F2F8460F9D4}" = Support Actions Win2K,WinXP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B6F4C00-E935-11D3-A98A-0080986030D9}" = Smart Capture
"{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}" = InterVideo DeviceService
"{54B8F4A1-02B0-4D32-8F37-925526C0EEC6}" = CorelDRAW Graphics Suite X5 - Connect
"{57400C1E-BC51-4ECE-AD2A-A6096204DDEC}" = CorelDRAW Graphics Suite X5 - VBA
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{59123CCF-FED2-46FF-9293-D1DC80042219}" = CorelDRAW Graphics Suite X5 - Redist
"{5FF58521-5E44-11D4-A433-00105A8547C6}" = PictureGear 5.1
"{6060E6A1-5342-4D2B-8F66-B6D6E20BBD03}" = VAIO Help & Support
"{62978C1C-FE2E-4A4E-851D-3EB406C9EBC2}" = CorelDRAW Graphics Suite X5 - Draw
"{655CD886-3B90-4E4D-B314-92BDA9B08C86}" = Vegas Movie Studio HD 9.0
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6990A2BF-D1D2-11D3-81BC-00609789C908}" = Sony DV Shared Library
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8139011A-4039-46C7-8614-A3F8948121AD}" = PicoPlayer
"{84B2CF01-194D-2284-B313-F2E0D78D1033}" = Nero 7 Demo
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9244E956-5939-4B88-930C-0699D4AB2B95}" = CorelDRAW Graphics Suite X5 - WT
"{983F7145-CABF-4EDD-9F3D-E06B2F024BD3}" = CorelDRAW Graphics Suite X5 - FontNav
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1B04B6B-25BB-48AD-8BD9-D31A86E89F3E}" = CorelDRAW Graphics Suite X5 - PHOTO-PAINT
"{A228A09C-4826-42E0-A3D8-95B2BAAB5049}" = OpenMG Secure Module
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A567895C-1D23-48ED-BE83-FB3ED7D30442}" = IPM_VS_Pro
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AA902C31-B49D-4608-BCCF-2519EB77722D}" = ICA
"{B0125BEB-6731-43FA-88DA-B64D7BD3AD2D}" = VSPro
"{B399C91E-96F2-4265-9884-1C9A10E9FCF4}" = CorelDRAW Graphics Suite X5
"{B5B0ABC0-3177-11D3-AC45-0000F879D920}" = VisualFlow 2.1
"{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}" = Corel Graphics - Windows Shell Extension
"{B84ECBE1-6ED5-4E86-B4AB-DF46D342411F}" = Share
"{B87FAC24-973D-4A4F-AFC4-555FB95B32DB}" = PureHD
"{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4778408-3268-45CE-AE15-772D1739A1F1}" = VIO
"{C6017EEA-9E51-4129-84BA-EFA9520E69D8}" = Common
"{CA3861BA-1D96-4D66-B577-318E1602C4F3}" = CorelDRAW Graphics Suite X5 - Common
"{CC4C7E9B-4B26-4D8D-8076-40CF708A9FA4}" = Contents
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW Graphics Suite X5 - Setup Files
"{D0448678-1203-4158-A58F-B3D0B616BF9E}" = Sony Certificate PCH
"{D07F85DE-22F1-4FB4-B3D1-402FD22C4870}" = DeviceIO
"{D4A49B00-02F8-11D5-B64D-00C04F790F76}" = MovieShaker 3.2
"{D596EEA2-C6C8-45D3-89DF-FA2DBE99F829}" = Visual Basic for Applications ® Core - English
"{D642FF8D-438D-4545-A1D5-2EDB4BCAE3BA}" = CorelDRAW Graphics Suite X5 - Photozoom Plugin
"{D68897FC-7E8D-4849-819A-726B2489713C}" = ISCOM
"{D8D9BCF5-0F5F-4D3F-8427-64B7632F93BE}" = Setup
"{DE6CBC04-8673-4DBA-BA81-07F1639CEB5F}" = CorelDRAW Graphics Suite X5 - IPM
"{E2069DE3-5924-4766-A385-CDA273885A31}" = DigitalPrint 1.0
"{E34C6AA4-AE8E-4677-912A-92FC2E039DD9}" = CorelDRAW Graphics Suite X5 - EN
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E535DC62-56D6-11D5-8AE3-00105A7276CD}" = SonicStage
"{EDB98D5A-A6FB-425C-BFB7-51A0924B762D}" = CorelDRAW Graphics Suite X5 - Capture
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F3CB4DC0-4FC0-11D5-9254-0000F460E7A9}" = SonicStage CD-R Writing Module
"{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}" = VideoStudio
"{FE4B83DE-85CF-4DE5-90CE-A2735A0E1F21}" = CorelDRAW Graphics Suite X5 - VideoBrowser
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop Elements 1.0" = Adobe Photoshop Elements
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"AnswerWorks" = AnswerWorks Runtime
"Audacity_is1" = Audacity 1.2.6
"BitTorrent" = BitTorrent
"DVD Express A/V Pak" = DVDExpress
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Free RAR Extract Frog" = Free RAR Extract Frog
"Freemake Video Converter_is1" = Freemake Video Converter version 2.3.3
"ie8" = Windows Internet Explorer 8
"InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"InstallShield_{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}" = Ulead VideoStudio 11
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Motion JPEG Software Decoder" = Motion JPEG Software Decoder
"Mozilla Firefox 5.0.1 (x86 en-US)" = Mozilla Firefox 5.0.1 (x86 en-US)
"MSC" = McAfee AntiVirus Plus
"Soulseek" = SoulSeek Client 156c
"uTorrent" = µTorrent
"VAIO Support" = VAIO Support
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YIP2_SONY" = Sony on Yahoo!

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/10/2011 3:31:24 AM | Computer Name = VAIO | Source = McLogEvent | ID = 5004
Description = Could not contact Filter Driver. Error = 0x7e : The specified module
could not be found.

Error - 8/10/2011 3:31:24 AM | Computer Name = VAIO | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 1

Error - 8/10/2011 3:31:31 AM | Computer Name = VAIO | Source = McLogEvent | ID = 5004
Description = Could not contact Filter Driver. Error = 0x7e : The specified module
could not be found.

Error - 8/10/2011 3:31:31 AM | Computer Name = VAIO | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 1

Error - 8/11/2011 1:27:37 PM | Computer Name = VAIO | Source = .NET Runtime Optimization Service | ID = 1103
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Tried to start a service that wasn't the latest version of CLR Optimization service.
Will shutdown

Error - 8/11/2011 10:07:33 PM | Computer Name = VAIO | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 8/12/2011 12:39:02 PM | Computer Name = VAIO | Source = Microsoft Security Client | ID = 5000
Description =

Error - 8/12/2011 1:25:50 PM | Computer Name = VAIO | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Failed to compile: PresentationUI, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
. Error code = 0x80070002

Error - 8/13/2011 9:20:44 AM | Computer Name = VAIO | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
gcswf32.dll, version 10.3.183.5, fault address 0x003aaf20.

Error - 8/15/2011 9:19:17 PM | Computer Name = VAIO | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

[ System Events ]
Error - 8/2/2011 10:19:53 AM | Computer Name = VAIO | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 8/2/2011 10:19:53 AM | Computer Name = VAIO | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 8/2/2011 10:19:53 AM | Computer Name = VAIO | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 8/2/2011 10:19:53 AM | Computer Name = VAIO | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 8/2/2011 10:20:04 AM | Computer Name = VAIO | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
MACBOOKPRO-17BA that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{11A92C55-FF2. The master browser is stopping or an election is being
forced.

Error - 8/2/2011 11:51:35 AM | Computer Name = VAIO | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
MACBOOKPRO-17BA that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{11A92C55-FF2. The master browser is stopping or an election is being
forced.

Error - 8/2/2011 2:03:12 PM | Computer Name = VAIO | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
MACBOOKPRO-17BA that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{11A92C55-FF2. The master browser is stopping or an election is being
forced.

Error - 8/2/2011 4:10:45 PM | Computer Name = VAIO | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
MACBOOKPRO-17BA that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{11A92C55-FF2. The master browser is stopping or an election is being
forced.

Error - 8/6/2011 3:50:03 AM | Computer Name = VAIO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Netman service.

Error - 8/7/2011 12:47:19 PM | Computer Name = VAIO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Netman service.


< End of report >
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 11-08-16.05 - Russgies 08/16/2011 15:48:52.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.91 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Owner\WINDOWS
c:\documents and settings\Russgies\My Documents\~WRL3247.tmp
c:\documents and settings\Russgies\WINDOWS
c:\windows\desktop
c:\windows\desktop\ImageStation.lnk
c:\windows\system32\config\systemprofile\WINDOWS
.
.
((((((((((((((((((((((((( Files Created from 2011-07-16 to 2011-08-16 )))))))))))))))))))))))))))))))
.
.
2011-08-12 17:09 . 2011-08-12 17:09 ——– d—–w- c:\program files\Trend Micro
2011-08-11 18:33 . 2011-03-13 17:20 9344 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-08-11 18:33 . 2011-03-13 17:20 89368 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2011-08-11 18:33 . 2011-03-13 17:20 85984 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2011-08-11 18:33 . 2011-03-13 17:20 83688 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2011-08-11 18:33 . 2011-03-13 17:20 59288 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2011-08-11 18:33 . 2011-03-13 17:20 57432 —-a-w- c:\windows\system32\drivers\cfwids.sys
2011-08-11 18:33 . 2011-03-13 17:20 337912 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2011-08-11 18:33 . 2011-03-13 17:20 179248 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-08-11 18:32 . 2011-08-11 18:32 ——– d—–w- c:\program files\Common Files\Mcafee
2011-08-11 18:31 . 2011-08-11 18:31 ——– d—–w- c:\program files\McAfee
2011-08-11 18:24 . 2011-03-13 17:45 148520 —-a-w- c:\windows\system32\mfevtps.exe
2011-08-11 01:09 . 2011-06-24 14:10 139656 ——w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-11 01:08 . 2011-07-08 14:02 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-10 06:13 . 2011-08-10 06:13 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2011-08-10 05:08 . 2011-08-10 05:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Freemake
2011-08-10 05:08 . 2011-08-10 05:08 ——– d—–w- c:\program files\Freemake
2011-08-09 20:29 . 2011-08-09 20:29 ——– d—–w- c:\program files\Google
2011-08-09 02:32 . 2011-08-09 02:32 ——– d—–w- C:\FOUND.001
2011-08-09 02:22 . 2011-08-09 01:17 16432 —-a-w- c:\windows\system32\lsdelete.exe
2011-08-09 01:17 . 2011-08-09 01:17 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-08-09 01:10 . 2011-08-09 01:10 ——– d—–w- c:\windows\system32\DRVSTORE
2011-08-09 01:10 . 2011-07-21 20:59 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-08-09 01:09 . 2011-08-09 01:09 ——– d—–w- c:\program files\Lavasoft
2011-08-09 01:09 . 2011-08-09 01:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-08-09 00:05 . 2010-10-18 11:10 7680 ——w- c:\windows\system32\dllcache\iecompat.dll
2011-08-09 00:03 . 2011-08-09 00:03 ——– d—–w- c:\windows\system32\winrm
2011-08-09 00:03 . 2011-08-09 00:03 ——– d—–w- c:\windows\system32\GroupPolicy
2011-08-09 00:03 . 2011-08-09 00:03 ——– d–h–w- c:\windows\$968930Uinstall_KB968930$
2011-08-08 23:36 . 2011-08-08 23:36 68608 –sha-r- c:\windows\system32\ds32gtt.dll
2011-08-08 17:33 . 2011-08-08 17:33 ——– d—–w- c:\program files\Vstplugins
2011-08-08 17:27 . 2011-08-08 17:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Sony
2011-08-02 22:52 . 2011-08-02 22:53 ——– d—–w- c:\windows\Sun
2011-08-02 22:51 . 2011-08-02 22:51 ——– d—–w- c:\program files\Common Files\Java
2011-08-02 22:50 . 2011-08-02 22:50 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-08-02 22:50 . 2011-08-02 22:50 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-08-02 22:50 . 2011-08-02 22:50 ——– d—–w- c:\program files\Java
2011-08-02 06:24 . 2011-08-02 06:24 ——– d—–w- c:\program files\MSXML 4.0
2011-08-02 05:03 . 2011-08-02 05:03 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-01 21:38 . 2011-08-01 21:38 ——– d—–w- c:\program files\Lame For Audacity
2011-08-01 20:09 . 2011-08-01 20:09 ——– d—–w- c:\program files\Audacity
2011-08-01 05:13 . 2011-08-01 05:13 348256 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\VSTAHost\CorelPHOTOPAINT\9.0\1033\ResourceCache.dll
2011-08-01 05:12 . 2011-08-01 05:12 348256 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\VSTAHost\CorelDRAW\9.0\1033\ResourceCache.dll
2011-08-01 05:10 . 2011-08-01 05:10 416 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2011-08-01 05:07 . 2011-08-01 05:07 ——– d—–w- c:\program files\Microsoft SDKs
2011-08-01 05:07 . 2011-08-01 05:07 ——– d—–w- c:\program files\Microsoft.NET
2011-08-01 05:07 . 2011-08-01 05:07 ——– d—–w- c:\program files\Microsoft Visual Studio 9.0
2011-08-01 03:18 . 2011-08-01 03:18 ——– d—–w- c:\program files\Soulseek
2011-08-01 03:03 . 2011-08-01 03:03 ——– d—–w- C:\FOUND.000
2011-07-28 06:22 . 2011-07-28 06:22 ——– d—–w- c:\windows\system32\XPSViewer
2011-07-28 06:22 . 2011-07-28 06:22 ——– d—–w- c:\program files\Reference Assemblies
2011-07-28 06:21 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-07-28 06:21 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-07-28 06:21 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2011-07-28 06:21 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-07-28 06:21 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2011-07-28 06:21 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2011-07-28 06:21 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2011-07-28 06:21 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-07-28 06:21 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-07-26 06:46 . 2011-07-26 06:49 952 –sha-w- c:\windows\system32\KGyGaAvL.sys
2011-07-26 05:17 . 2011-07-26 05:44 2828 –sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2011-07-26 05:17 . 2011-07-26 05:18 8 –sh–r- c:\documents and settings\All Users\Application Data\F3AA723DE9.sys
2011-07-26 03:16 . 2011-07-26 03:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Protexis
2011-07-26 03:10 . 2011-07-26 03:10 ——– d—–w- c:\program files\SmartSound Software
2011-07-26 03:10 . 2011-07-26 03:10 ——– d—–w- c:\documents and settings\All Users\Application Data\SmartSound Software Inc
2011-07-26 03:08 . 2011-07-26 03:08 ——– d—–w- c:\windows\system32\LogFiles
2011-07-26 03:08 . 2011-07-26 03:08 ——– d—–w- c:\windows\system32\drivers\UMDF
2011-07-26 03:07 . 2011-07-26 03:07 ——– d—–w- c:\windows\system32\windows media
2011-07-26 03:07 . 2011-07-26 03:07 ——– d–h–w- c:\windows\msdownld.tmp
2011-07-26 03:05 . 2011-07-26 03:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Corel
2011-07-26 02:58 . 2011-07-26 02:58 ——– d—–w- c:\program files\Common Files\Protexis
2011-07-26 02:58 . 2011-07-26 02:58 ——– d—–w- c:\program files\Common Files\Corel
2011-07-26 02:57 . 2007-10-22 09:39 267272 —-a-w- c:\windows\system32\xactengine2_10.dll
2011-07-26 02:57 . 2007-10-02 15:56 444776 —-a-w- c:\windows\system32\d3dx10_36.dll
2011-07-25 23:34 . 2011-07-25 23:34 ——– d—–w- c:\documents and settings\All Users\Application Data\InterVideo
2011-07-25 23:33 . 2007-03-06 17:58 210456 —-a-w- c:\windows\system32\IVIresizeW7.dll
2011-07-25 23:33 . 2007-03-06 17:58 194072 —-a-w- c:\windows\system32\IVIresizePX.dll
2011-07-25 23:33 . 2007-03-06 17:58 198168 —-a-w- c:\windows\system32\IVIresizeP6.dll
2011-07-25 23:33 . 2007-03-06 17:58 198168 —-a-w- c:\windows\system32\IVIresizeM6.dll
2011-07-25 23:33 . 2007-03-06 17:58 206360 —-a-w- c:\windows\system32\IVIresizeA6.dll
2011-07-25 23:33 . 2007-03-06 17:58 26136 —-a-w- c:\windows\system32\IVIresize.dll
2011-07-25 23:33 . 2011-07-25 23:33 ——– d—–w- c:\program files\Windows Media Components
2011-07-25 23:32 . 2011-07-25 23:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Ulead Systems
2011-07-25 23:32 . 2011-07-25 23:32 ——– d—–w- c:\program files\Common Files\Ulead Systems
2011-07-25 23:15 . 2011-07-25 23:15 ——– d—–w- c:\program files\Free RAR Extract Frog
2011-07-25 21:47 . 2011-07-25 21:47 ——– d—–w- c:\windows\system32\wbem\Repository
2011-07-25 19:43 . 2011-07-25 19:43 ——– d—–w- c:\program files\Common Files\InterVideo
2011-07-22 00:07 . 2011-03-04 19:44 59888 ——w- c:\windows\system32\pxwma.dll
2011-07-22 00:07 . 2011-03-04 19:44 133616 ——w- c:\windows\system32\pxafs.dll
2011-07-22 00:07 . 2011-03-04 19:44 9200 ——w- c:\windows\system32\drivers\cdralw2k.sys
2011-07-22 00:07 . 2011-03-04 19:44 9072 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2011-07-22 00:07 . 2011-03-04 19:44 126448 ——w- c:\windows\system32\pxinsi64.exe
2011-07-22 00:07 . 2011-03-04 19:44 123888 ——w- c:\windows\system32\pxcpyi64.exe
2011-07-22 00:07 . 2011-07-22 00:07 ——– d—–w- c:\program files\Winamp
2011-07-21 16:43 . 2010-09-18 06:53 954368 ——w- c:\windows\system32\dllcache\mfc40.dll
2011-07-21 16:43 . 2010-09-18 06:53 953856 ——w- c:\windows\system32\dllcache\mfc40u.dll
2011-07-21 16:40 . 2010-08-23 16:12 617472 ——w- c:\windows\system32\dllcache\comctl32.dll
2011-07-21 16:39 . 2010-11-02 15:17 40960 ——w- c:\windows\system32\dllcache\ndproxy.sys
2011-07-21 16:37 . 2011-04-21 13:37 105472 ——w- c:\windows\system32\dllcache\mup.sys
2011-07-21 16:31 . 2010-10-11 14:59 45568 ——w- c:\windows\system32\dllcache\wab.exe
2011-07-21 05:50 . 2006-10-27 01:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-07-21 05:50 . 2006-10-27 01:56 32592 —-a-w- c:\windows\system32\msonpmon.dll
2011-07-21 05:48 . 2011-07-21 05:48 ——– d—–w- c:\program files\MSBuild
2011-07-21 05:40 . 2011-07-21 05:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2011-07-21 05:39 . 2011-07-21 05:39 ——– d—–r- C:\MSOCache
2011-07-21 05:14 . 2011-07-21 05:14 ——– d—–w- c:\program files\Common Files\Ahead
2011-07-21 04:39 . 2011-07-21 04:39 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-07-21 04:39 . 2011-07-21 04:39 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-07-21 04:39 . 2011-07-21 04:39 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-07-21 04:39 . 2011-07-21 04:39 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-07-21 04:39 . 2011-07-21 04:39 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-07-21 04:39 . 2011-07-21 04:39 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-07-21 04:39 . 2011-07-21 04:39 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-07-21 04:39 . 2011-07-21 04:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2011-07-21 00:57 . 2011-07-21 00:57 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2011-07-21 00:43 . 2011-07-21 00:43 ——– d—–w- c:\windows\system32\scripting
2011-07-21 00:43 . 2011-07-21 00:43 ——– d—–w- c:\windows\l2schemas
2011-07-21 00:43 . 2011-07-21 00:43 ——– d—–w- c:\windows\system32\en
2011-07-21 00:26 . 2011-07-21 00:26 ——– d—–w- c:\program files\uTorrent
2011-07-21 00:02 . 2011-07-21 00:02 ——– d—–w- c:\program files\BitTorrent
2011-07-20 22:51 . 2011-07-20 22:51 ——– d—–w- c:\program files\Common Files\Apple
2011-07-20 22:50 . 2011-07-20 22:50 ——– d—–w- c:\program files\Apple Software Update
2011-07-20 22:50 . 2011-07-20 22:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2011-07-20 22:46 . 2011-07-20 22:46 1409 —-a-w- c:\windows\QTFont.for
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-15 13:29 . 2001-09-08 16:53 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2001-09-08 16:53 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2001-09-08 17:03 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2001-09-08 16:53 916480 —-a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2001-09-08 16:53 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2001-09-08 16:53 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2001-09-08 16:53 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-06-02 14:02 . 2001-09-08 16:53 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-07-08 07:16 . 2011-07-20 19:34 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Russgies\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Russgies\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Russgies\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Russgies\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 4"="d:\program files\Advanced SystemCare 4\ASCTray.exe" [2011-05-28 412560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" [2001-09-11 2339]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"UVS11 Preload"="d:\program files\ulead\uvPL.exe" [2007-03-03 341488]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-06-23 1306728]
.
c:\documents and settings\Russgies\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Russgies\Application Data\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
VAIO Action Setup (Server).lnk - c:\program files\Sony\VAIO Action Setup\VAServ.exe [2001-9-8 40960]
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2001-9-8 113664]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\support.com\\client\\bin\\tgcmd.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Documents and Settings\\Russgies\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/8/2011 7:10 PM 64512]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [8/11/2011 12:33 PM 89368]
R1 SonyFanC;FAN Control Device Service;c:\windows\system32\drivers\SonyFanC.sys [9/9/2001 1:57 PM 68116]
R2 AdvancedSystemCareService;Advanced SystemCare Service;d:\program files\Advanced SystemCare 4\ASCService.exe [7/21/2011 10:30 AM 353168]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [8/11/2011 12:32 PM 214904]
R2 V7;V7;c:\windows\system32\drivers\V7.SYS [7/20/2011 1:14 PM 7196]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [7/21/2011 2:59 PM 15232]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [8/11/2011 12:33 PM 337912]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [8/11/2011 12:33 PM 83688]
S2 FreemakeUtilsService;Freemake Service;c:\documents and settings\All Users\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [8/9/2011 11:08 PM 74240]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/9/2011 2:29 PM 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/21/2011 2:59 PM 2151640]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe –> c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [?]
S3 BCM42XX;Broadcom iLine10™ Network Adapter Driver;c:\windows\system32\drivers\bcm42xx5.sys [9/8/2001 2:22 PM 54271]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [8/11/2011 12:33 PM 57432]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/9/2011 2:29 PM 136176]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [8/11/2011 12:33 PM 83688]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [8/11/2011 12:33 PM 85984]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-09 20:29]
.
2011-08-16 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-07-21 20:59]
.
2011-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-09 20:29]
.
2011-07-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
2011-08-16 c:\windows\Tasks\ASC4_PerformanceMonitor.job
- d:\program files\Advanced SystemCare 4\PMonitor.exe [2011-07-21 20:46]
.
2011-08-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-329068152-926492609-725345543-1004Core1cc4e883b97b5be.job
- c:\documents and settings\Russgies\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-20 22:28]
.
2011-08-16 c:\windows\Tasks\vzuhvje.job
- c:\windows\system32\ds32gtt.dll [2011-08-08 23:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.sony.com/vaiopeople
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254 192.168.1.254
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Russgies\Application Data\Mozilla\Firefox\Profiles\wtf5l9fc.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-16 15:59
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-08-16 16:03:14
ComboFix-quarantined-files.txt 2011-08-16 22:03
.
Pre-Run: 2,035,335,168 bytes free
Post-Run: 2,557,431,808 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - EAFED672BD477CE965269C131E32765D
Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please












Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7483 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 8/16/2011 7:01:31 PM mbam-log-2011-08-16 (19-01-31).txt Scan type: Quick scan Objects scanned: 175953 Time elapsed: 13 minute(s), 10 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\ZU6RKI1ONY (Trojan.FakeAlert.SA) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=8fd9029a059fb34a8ea15b60be43cd63 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-08-17 02:33:45 # local_time=2011-08-16 08:33:45 (-0700, Mountain Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5121 16777189 100 75 370001 13920385 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=100789 # found=3 # cleaned=3 # scan_time=4311 C:\Documents and Settings\Russgies\My Documents\Downloads\registrybooster.exe Win32/RegistryBooster application (deleted - quarantined) 00000000000000000000000000000000 C E:\Izotope.iDrum.VSTi.RTAS.v1.7.1.Incl.Keygen-AiR\Izotope.iDrum.VSTi.RTAS.v1.7.1.Incl.Keygen-AiR\keygen.exe a variant of Win32/Keygen.AD application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C E:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP11\A0002171.exe a variant of Win32/Keygen.AD application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

You have 2 antivirus installed you should only have one.


Please post a new OTL log and tell me how the computer is running now.
I've tried a number of Google searches and so far none of the results have been hijacked. I tried to run the custom OTL scan again but the process stopped and the .exe file disappeared. Is that normal? Is it possible the problem is solved? Thanks so much for your assistance!

I tried to run the custom OTL scan again but the process stopped and the .exe file disappeared. Is that normal?

No that is not normal,did you hit the Clean up button by mistake as that is what happens when you do.

Download a new copy of OTL from the link below and click Run scan,post the new log.

OTL
Tried it every which way and OTL still disappears during the scan. But I have a quirky computer, so it does that sort of thing. Unless you can suggest why it does that and suggest any possible fixes, I will thank you very much for your help and cross my fingers that this computer is clean. Cheers!
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.




Please scan the following files


  • Please visit Virus Total by clicking here.
  • Click the Browse button and search for the following file: c:\windows\system32\ds32gtt.dll
  • Click Open.
  • Then click Send File.
  • Please be patient while the file is scanned.
  • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

  • Once the scan results appear, copy and paste them into Notepad













Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
You didn't ask for it, but I've included the results from Virus Total as well: Antivirus Version Last Update Result AhnLab-V3 2011.08.20.00 2011.08.19 - AntiVir 7.11.13.154 2011.08.19 TR/Crypt.XPACK.Gen Antiy-AVL 2.0.3.7 2011.08.19 - Avast 4.8.1351.0 2011.08.19 - Avast5 5.0.677.0 2011.08.19 - AVG 10.0.0.1190 2011.08.19 - BitDefender 7.2 2011.08.20 - ByteHero 1.0.0.1 2011.08.20 - CAT-QuickHeal 11.00 2011.08.19 - ClamAV 0.97.0.0 2011.08.20 - Commtouch 5.3.2.6 2011.08.20 - DrWeb 5.0.2.03300 2011.08.20 - Emsisoft 5.1.0.10 2011.08.19 - eSafe 7.0.17.0 2011.08.18 - eTrust-Vet 36.1.8511 2011.08.19 - F-Prot 4.6.2.117 2011.08.20 - F-Secure 9.0.16440.0 2011.08.20 - Fortinet 4.2.257.0 2011.08.20 - GData 22 2011.08.20 - Ikarus T3.1.1.107.0 2011.08.19 - Jiangmin 13.0.900 2011.08.19 Adware/SuperJuan.aeu K7AntiVirus 9.109.5030 2011.08.18 - Kaspersky 9.0.0.837 2011.08.20 - McAfee 5.400.0.1158 2011.08.19 - McAfee-GW-Edition 2010.1D 2011.08.20 - Microsoft 1.7604 2011.08.19 - NOD32 6394 2011.08.20 - Norman 6.07.10 2011.08.19 - nProtect 2011-08-19.01 2011.08.19 - Panda 10.0.3.5 2011.08.19 - PCTools 8.0.0.5 2011.08.20 - Prevx 3.0 2011.08.20 - Rising 23.71.03.03 2011.08.18 - Sophos 4.68.0 2011.08.19 - SUPERAntiSpyware 4.40.0.1006 2011.08.20 - Symantec 20111.2.0.82 2011.08.20 - TheHacker 6.7.0.1.282 2011.08.20 - TrendMicro 9.500.0.1008 2011.08.17 - TrendMicro-HouseCall 9.500.0.1008 2011.08.20 - VBA32 3.12.16.4 2011.08.19 - VIPRE 10215 2011.08.20 - ViRobot 2011.8.20.4630 2011.08.20 - VirusBuster 14.0.177.0 2011.08.19 - Additional informationShow all MD5 : 38b874383eeba3b3ae71e969d5e55673 SHA1 : 0e71db9efb00b705d09537765ef3bfdf6b8d7c48 SHA256: f4859eab50af75641d226698fedfa742fbc2e64ba4ebbab866082fc72e396281 . DDS (Ver_2011-06-23.01) - FAT32x86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26 Run by [removed] at 21:26:50 on 2011-08-19 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.58 [GMT -6:00] . AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch SVCHOST.EXE C:\WINDOWS\System32\svchost.exe -k netsvcs SVCHOST.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\rundll32.exe D:\Program Files\Advanced SystemCare 4\PMonitor.exe D:\Program Files\Advanced SystemCare 4\ASCService.exe C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe C:\WINDOWS\system32\mfevtps.exe c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe SVCHOST.EXE C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe D:\Program Files\Advanced SystemCare 4\ASCTray.exe C:\Program Files\Sony\VAIO Action Setup\VAServ.exe C:\Documents and Settings\Russgies\Application Data\Dropbox\bin\Dropbox.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft Office\Office12\WINWORD.EXE C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Russgies\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\notepad.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.sony.com/vaiopeople BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110811123352.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [Advanced SystemCare 4] d:\program files\advanced systemcare 4\ASCTray.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10u_ActiveX.exe -update activex mRun: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [UVS11 Preload] d:\program files\ulead\uvPL.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray StartupFolder: c:\docume~1\russgies\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\russgies\application data\dropbox\bin\Dropbox.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vaioac~1.lnk - c:\program files\sony\vaio action setup\VAServ.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1311190553373 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab TCP: DhcpNameServer = 192.168.1.254 192.168.1.254 TCP: Interfaces\{11A92C55-FF2A-466E-B2A4-66138B5FFBBD} : DhcpNameServer = 192.168.1.254 192.168.1.254 Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\McSnIePl.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\russgies\application data\mozilla\firefox\profiles\wtf5l9fc.default\ FF - plugin: c:\documents and settings\russgies\local settings\application data\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\progra~1\mcafee\msc\npMcSnFFPl.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-8-8 64512] R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-3-13 459728] R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2011-8-11 89368] R1 SonyFanC;FAN Control Device Service;c:\windows\system32\drivers\SonyFanC.sys [2001-9-9 68116] R2 AdvancedSystemCareService;Advanced SystemCare Service;d:\program files\advanced systemcare 4\ASCService.exe [2011-7-21 353168] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-8-16 366640] R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-8-11 214904] R2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-8-11 214904] R2 McShield;McAfee McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-8-11 165000] R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2011-8-11 159832] R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-8-11 148520] R2 V7;V7;c:\windows\system32\drivers\V7.SYS [2011-7-20 7196] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-8-16 22712] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-8-11 179248] R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-8-11 337912] R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2011-8-11 83688] S2 FreemakeUtilsService;Freemake Service;c:\documents and settings\all users\application data\freemake\freemakeutilsservice\FreemakeUtilsService.exe [2011-8-9 74240] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-9 136176] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-7-21 2151640] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\sitead~1\mcsacore.exe –> c:\progra~1\mcafee\sitead~1\mcsacore.exe [?] S3 BCM42XX;Broadcom iLine10™ Network Adapter Driver;c:\windows\system32\drivers\bcm42xx5.sys [2001-9-8 54271] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-8-11 57432] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-9 136176] S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-7-21 15232] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-8-16 41272] S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-8-11 59288] S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2011-8-11 83688] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-8-11 85984] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2001-9-8 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpffontcache_v0400.exe –> c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [?] . =============== Created Last 30 ================ . 2011-08-17 01:06:53 ——– d—–w- c:\program files\ESET 2011-08-17 00:45:30 ——– d—–w- c:\documents and settings\russgies\application data\Malwarebytes 2011-08-17 00:44:43 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-17 00:44:40 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-08-17 00:44:17 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-17 00:44:16 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-08-16 21:47:19 ——– d-sha-r- C:\cmdcons 2011-08-16 21:45:19 98816 —-a-w- c:\windows\sed.exe 2011-08-16 21:45:19 518144 —-a-w- c:\windows\SWREG.exe 2011-08-16 21:45:19 256000 —-a-w- c:\windows\PEV.exe 2011-08-16 21:45:19 208896 —-a-w- c:\windows\MBR.exe 2011-08-16 21:44:57 ——– d—–w- C:\ComboFix 2011-08-12 17:09:34 388096 —-a-r- c:\documents and settings\russgies\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-08-12 17:09:27 ——– d—–w- c:\program files\Trend Micro 2011-08-11 18:33:52 24376 —-a-w- c:\program files\mozilla firefox\distribution\bundles\{d19ca586-dd6c-4a0a-96f8-14644f340d60}\components\scriptff.dll 2011-08-11 18:33:49 9344 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2011-08-11 18:33:15 89368 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys 2011-08-11 18:33:15 85984 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2011-08-11 18:33:15 83688 —-a-w- c:\windows\system32\drivers\mfendisk.sys 2011-08-11 18:33:15 59288 —-a-w- c:\windows\system32\drivers\mfebopk.sys 2011-08-11 18:33:15 57432 —-a-w- c:\windows\system32\drivers\cfwids.sys 2011-08-11 18:33:15 337912 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2011-08-11 18:33:15 179248 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2011-08-11 18:32:21 ——– d—–w- c:\program files\common files\Mcafee 2011-08-11 18:32:01 ——– d—–w- c:\program files\McAfee.com 2011-08-11 18:31:17 ——– d—–w- c:\program files\McAfee 2011-08-11 18:24:46 148520 —-a-w- c:\windows\system32\mfevtps.exe 2011-08-11 01:09:09 139656 ——w- c:\windows\system32\dllcache\rdpwd.sys 2011-08-11 01:08:44 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys 2011-08-10 06:30:41 ——– d—–w- c:\documents and settings\russgies\local settings\application data\McAfee Anti-Theft 2011-08-10 05:08:56 ——– d—–w- c:\documents and settings\all users\application data\Freemake 2011-08-10 05:08:41 ——– d—–w- c:\program files\Freemake 2011-08-09 02:32:22 ——– d—–w- C:\FOUND.001 2011-08-09 02:22:38 16432 —-a-w- c:\windows\system32\lsdelete.exe 2011-08-09 01:17:14 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-08-09 01:10:20 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys 2011-08-09 01:09:46 ——– d—–w- c:\program files\Lavasoft 2011-08-09 00:05:32 7680 ——w- c:\windows\system32\dllcache\iecompat.dll 2011-08-09 00:03:25 ——– d—–w- c:\windows\system32\winrm 2011-08-09 00:03:25 ——– d—–w- c:\windows\system32\GroupPolicy 2011-08-09 00:03:07 ——– d–h–w- c:\windows\$968930Uinstall_KB968930$ 2011-08-08 23:36:15 68608 –sha-r- c:\windows\system32\ds32gtt.dll 2011-08-08 17:33:45 ——– d—–w- c:\program files\Vstplugins 2011-08-08 17:31:44 ——– d—–w- c:\documents and settings\russgies\local settings\application data\Sony 2011-08-08 16:39:55 ——– d-sh–w- c:\documents and settings\russgies\IECompatCache 2011-08-02 22:50:31 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-08-02 22:50:31 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-08-02 06:24:00 ——– d—–w- c:\program files\MSXML 4.0 2011-08-02 05:03:55 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-08-01 21:38:53 ——– d—–w- c:\program files\Lame For Audacity 2011-08-01 20:09:52 ——– d—–w- c:\program files\Audacity 2011-08-01 16:26:05 ——– d—–w- c:\documents and settings\russgies\application data\Dropbox 2011-08-01 05:13:49 348256 —-a-w- c:\documents and settings\all users\application data\microsoft\vstahost\corelphotopaint\9.0\1033\ResourceCache.dll 2011-08-01 05:12:36 348256 —-a-w- c:\documents and settings\all users\application data\microsoft\vstahost\coreldraw\9.0\1033\ResourceCache.dll 2011-08-01 05:10:48 416 —-a-w- c:\documents and settings\all users\application data\microsoft\msdn\9.0\1033\ResourceCache.dll 2011-08-01 03:18:22 ——– d—–w- c:\program files\Soulseek 2011-08-01 03:03:08 ——– d—–w- C:\FOUND.000 2011-07-28 06:22:25 ——– d—–w- c:\windows\system32\XPSViewer 2011-07-28 06:21:50 89088 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll 2011-07-28 06:21:38 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2011-07-28 06:21:38 597504 ——w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2011-07-28 06:21:38 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2011-07-28 06:21:38 575488 ——w- c:\windows\system32\xpsshhdr.dll 2011-07-28 06:21:38 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll 2011-07-28 06:21:38 1676288 ——w- c:\windows\system32\xpssvcs.dll 2011-07-28 06:21:38 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll 2011-07-28 06:21:38 117760 ——w- c:\windows\system32\prntvpt.dll 2011-07-26 07:02:51 ——– d—–w- c:\documents and settings\all users\application data\CorelDRAW Graphics Suite X5 2011-07-26 06:46:48 952 –sha-w- c:\windows\system32\KGyGaAvL.sys 2011-07-26 05:17:59 8 –sh–r- c:\documents and settings\all users\application data\F3AA723DE9.sys 2011-07-26 05:17:59 2828 –sha-w- c:\documents and settings\all users\application data\KGyGaAvL.sys 2011-07-26 03:16:53 ——– d—–w- c:\documents and settings\all users\application data\Protexis 2011-07-26 03:10:09 ——– d—–w- c:\program files\SmartSound Software 2011-07-26 03:10:06 ——– d—–w- c:\documents and settings\all users\application data\SmartSound Software Inc 2011-07-26 03:08:52 ——– d—–w- c:\windows\system32\LogFiles 2011-07-26 03:07:55 ——– d—–w- c:\windows\system32\windows media 2011-07-26 03:07:25 ——– d—–w- c:\windows\RegisteredPackages 2011-07-26 03:07:23 ——– d–h–w- c:\windows\msdownld.tmp 2011-07-26 03:05:22 ——– d—–w- c:\documents and settings\all users\application data\Corel 2011-07-26 02:58:57 ——– d—–w- c:\program files\common files\Protexis 2011-07-26 02:58:36 ——– d—–w- c:\program files\common files\Corel 2011-07-26 02:57:00 444776 —-a-w- c:\windows\system32\d3dx10_36.dll 2011-07-26 02:57:00 267272 —-a-w- c:\windows\system32\xactengine2_10.dll 2011-07-25 23:34:02 ——– d—–w- c:\documents and settings\all users\application data\InterVideo 2011-07-25 23:33:59 26136 —-a-w- c:\windows\system32\IVIresize.dll 2011-07-25 23:33:59 210456 —-a-w- c:\windows\system32\IVIresizeW7.dll 2011-07-25 23:33:59 206360 —-a-w- c:\windows\system32\IVIresizeA6.dll 2011-07-25 23:33:59 198168 —-a-w- c:\windows\system32\IVIresizeP6.dll 2011-07-25 23:33:59 198168 —-a-w- c:\windows\system32\IVIresizeM6.dll 2011-07-25 23:33:59 194072 —-a-w- c:\windows\system32\IVIresizePX.dll 2011-07-25 23:33:24 ——– d—–w- c:\program files\Windows Media Components 2011-07-25 23:32:32 ——– d—–w- c:\program files\common files\Ulead Systems 2011-07-25 23:26:05 ——– d—–w- c:\documents and settings\russgies\local settings\application data\WMTools Downloaded Files 2011-07-25 23:15:58 ——– d—–w- c:\documents and settings\russgies\application data\Philipp Winterberg 2011-07-25 23:15:53 ——– d—–w- c:\program files\Free RAR Extract Frog 2011-07-25 21:47:04 ——– d—–w- c:\windows\system32\wbem\repository\FS 2011-07-25 21:47:04 ——– d—–w- c:\windows\system32\wbem\Repository 2011-07-25 19:43:52 ——– d—–w- c:\program files\common files\InterVideo 2011-07-22 05:33:01 ——– d-sh–w- c:\documents and settings\russgies\PrivacIE 2011-07-22 00:07:38 9200 ——w- c:\windows\system32\drivers\cdralw2k.sys 2011-07-22 00:07:38 9072 ——w- c:\windows\system32\drivers\cdr4_xp.sys 2011-07-22 00:07:38 59888 ——w- c:\windows\system32\pxwma.dll 2011-07-22 00:07:38 133616 ——w- c:\windows\system32\pxafs.dll 2011-07-22 00:07:38 126448 ——w- c:\windows\system32\pxinsi64.exe 2011-07-22 00:07:38 123888 ——w- c:\windows\system32\pxcpyi64.exe 2011-07-21 16:43:40 954368 ——w- c:\windows\system32\dllcache\mfc40.dll 2011-07-21 16:43:40 953856 ——w- c:\windows\system32\dllcache\mfc40u.dll 2011-07-21 16:40:38 617472 ——w- c:\windows\system32\dllcache\comctl32.dll 2011-07-21 16:39:36 40960 ——w- c:\windows\system32\dllcache\ndproxy.sys 2011-07-21 16:37:50 105472 ——w- c:\windows\system32\dllcache\mup.sys 2011-07-21 16:31:04 45568 ——w- c:\windows\system32\dllcache\wab.exe 2011-07-21 16:30:40 ——– d—–w- c:\documents and settings\russgies\application data\IObit 2011-07-21 05:50:38 33104 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll 2011-07-21 05:50:38 32592 —-a-w- c:\windows\system32\msonpmon.dll 2011-07-21 05:40:47 ——– d—–w- c:\documents and settings\russgies\local settings\application data\Microsoft Help 2011-07-21 05:20:28 ——– d—–w- c:\documents and settings\russgies\local settings\application data\Ahead 2011-07-21 04:39:38 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll 2011-07-21 04:39:38 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll 2011-07-21 04:39:38 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll 2011-07-21 04:39:38 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll 2011-07-21 04:39:38 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll 2011-07-21 04:39:38 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll 2011-07-21 04:39:38 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll 2011-07-21 04:20:26 ——– d—–w- c:\documents and settings\russgies\local settings\application data\Solid State Networks . ==================== Find3M ==================== . 2011-07-20 22:46:06 1409 —-a-w- c:\windows\QTFont.for 2011-07-15 13:29:32 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-07-08 14:02:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys 2011-06-24 14:10:36 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2011-06-23 18:36:30 916480 —-a-w- c:\windows\system32\wininet.dll 2011-06-23 18:36:30 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-06-23 18:36:30 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-06-23 12:05:14 385024 —-a-w- c:\windows\system32\html.iec 2011-06-20 17:44:52 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-06-02 14:02:06 1858944 —-a-w- c:\windows\system32\win32k.sys . ============= FINISH: 21:28:26.95 ===============

Attachments:

You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)













Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.









Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI