This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu/406 infection - scan results

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, my machine is infected with the searchqu virus. I've run MalwareBytes as well as StopZilla, and it still shows up as my Home Page. I changed the settings in "tools" to eliminate any mention of Searchqu, deleted the Boo-something and iLivid. So, I researched solutions and found your site. HELP, PLEASE!

Have run the HijackThis software, and here is the log report:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:38:04 AM, on 12/6/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Lynx Studio Technology\Mixer.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Derek\My Documents\Downloads\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
O2 - BHO: PE_IE_Helper Class - {0941C58F-E461-4E03-BD7D-44C27392ADE1} - C:\Program Files\IBM\Lotus Forms\Viewer\3.5\PEhelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~1\WI371A~1\Datamngr\BROWSE~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LynxONE TaskBar Icon.lnk = C:\Program Files\Lynx Studio Technology\Mixer.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1238886182500
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - https://wimpro.cce.hp.com/ChatEntry/downloads/msxml4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://3dlifeplayer.dl.3dvia.com/player/in…r_installer.exe
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://splicesoftware.webex.com/client/T27…ort/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O20 - AppInit_DLLs: C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll
O20 - Winlogon Notify: TPSvc - TPSvc.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Amazon Unbox Video Service (ADVService) - Unknown owner - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe (file missing)
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Unknown owner - C:\Program Files\Canon\CAL\CALMAIN.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MSCamSvc - Unknown owner - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\pctsAuxs.exe (file missing)
O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - C:\Program Files\Spyware Doctor\pctsSvc.exe (file missing)
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: ThreatFire - Unknown owner - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe (file missing)
O23 - Service: Windows Search (WSearch) - Unknown owner - C:\WINDOWS\system32\SearchIndexer.exe (file missing)
O23 - Service: Zune Bus Enumerator (ZuneBusEnum) - Unknown owner - c:\Program Files\Zune\ZuneBusEnum.exe (file missing)

–
End of file - 13460 bytes
Hello and Welcome to WhatTheTech Forums

My name is BlackPegasus.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for
    further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to
    get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out
    the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
  • I will reply back shortly with instructions.
Hello dshetterly, :wavey:
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check Scan all users
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
=================
NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

Summary of the logs I need from you in your next post:
OTL.Txt and Extras.Txt.
aswMBR log
Hi,
Below are the OTL results. Running MBR now.



OTL logfile created on: 12/6/2011 8:27:52 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Derek\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 72.66% Memory free
4.84 Gb Paging File | 4.17 Gb Available in Paging File | 86.19% Paging File free
Paging file location(s): C:\pagefile.sys 2048 2048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 763.11 Gb Free Space | 81.92% Space Free | Partition Type: NTFS
Drive E: | 11.17 Gb Total Space | 10.27 Gb Free Space | 91.94% Space Free | Partition Type: FAT32
Drive X: | 931.51 Gb Total Space | 420.21 Gb Free Space | 45.11% Space Free | Partition Type: NTFS

Computer Name: DEREK | User Name: Derek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Derek\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lynx Studio Technology\Mixer.exe (Lynx Studio Technology, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()


========== Win32 Services (SafeList) ==========

SRV - (ZuneBusEnum) – File not found
SRV - (WSearch) – File not found
SRV - (ThreatFire) – File not found
SRV - (srv3844) – File not found
SRV - (sdCoreService) – File not found
SRV - (sdAuxService) – File not found
SRV - (Pml Driver HPZ12) – File not found
SRV - (MSCamSvc) – File not found
SRV - (JavaQuickStarterService) – File not found
SRV - (CCALib8) – File not found
SRV - (AsSysCtrlService) – File not found
SRV - (AppMgmt) – File not found
SRV - (ADVService) – File not found
SRV - (szserver) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) – C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirMailService) – C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (WMZuneComm) – c:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – c:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)


========== Driver Services (SafeList) ==========

DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avkmgr) – C:\WINDOWS\system32\drivers\avkmgr.sys (Avira GmbH)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (DrvAgent32) – C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (szkg5) – C:\WINDOWS\system32\drivers\szkg.sys (iS3 Inc.)
DRV - (is3srv) – C:\WINDOWS\system32\drivers\is3srv.sys (iS3 Inc.)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (szkgfs) – C:\WINDOWS\system32\drivers\szkgfs.sys (iS3, Inc.)
DRV - (mv91cons) – C:\WINDOWS\system32\DRIVERS\mv91cons.sys (Marvell Semiconductor Inc.)
DRV - (mv91xx) – C:\WINDOWS\system32\DRIVERS\mv91xx.sys (Marvell Semiconductor, Inc.)
DRV - (nusb3xhc) – C:\WINDOWS\system32\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV - (nusb3hub) – C:\WINDOWS\system32\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (MSHUSBVideo) – C:\WINDOWS\system32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (mv61xx) – C:\WINDOWS\system32\DRIVERS\mv61xx.sys (Marvell Semiconductor, Inc.)
DRV - (AlesisFirewire) – C:\WINDOWS\system32\drivers\AlesisFirewire.sys (Alesis)
DRV - (AlesisFirewireAudio) – C:\WINDOWS\system32\drivers\AlesisFirewireAudio.sys (Alesis)
DRV - (AlesisFirewireMidi) – C:\WINDOWS\system32\drivers\AlesisFirewireMidi.sys (Alesis)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (SUSTUCAU) – C:\WINDOWS\system32\drivers\sustucau.sys (Susteen, Inc.)
DRV - (SUSTUCAP) – C:\WINDOWS\system32\drivers\sustucap.sys (Susteen, Inc.)
DRV - (SUSTUCAM) – C:\WINDOWS\system32\drivers\sustucam.sys (Susteen, Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (DiceAudioStrm) – C:\WINDOWS\system32\drivers\DiceAudioStrm.sys (TC Tech Inc.)
DRV - (Dice1394) – C:\WINDOWS\system32\drivers\Dice1394.sys (TC Tech Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (Lynx) – C:\WINDOWS\SYSTEM32\DRIVERS\Lynx.SYS (Lynx Studio Technology, Inc.)
DRV - (banshee) – C:\WINDOWS\system32\drivers\banshee.sys (3Dfx Interactive, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: "free-downloads.net Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {ecdee021-0d17-467f-a1ff-c7a115230949}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..keyword.URL: "http://search.search-go.net/?sid=10101052100&s;="
FF - prefs.js..network.proxy.type: 0

FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..keyword.URL: "http://search.search-go.net/?sid=10101052100&s;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/05/11 05:15:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2009/12/26 05:18:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/02 10:35:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/02 10:35:40 | 000,000,000 | —D | M]

[2011/11/30 07:51:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Derek\Application Data\Mozilla\Extensions
[2011/12/06 06:25:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions
[2011/03/29 07:45:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/09/14 07:35:32 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/09/14 11:54:44 | 000,000,000 | —D | M] (NCH) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{c2db4fe6-8409-45ce-8010-189a7b5cce86}
[2011/12/02 12:41:21 | 000,000,000 | —D | M] (Microsoft Choice Guard) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\ChoiceGuard@Microsoft
[2010/01/20 12:16:28 | 000,000,939 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\searchplugins\conduit.xml
[2011/11/29 06:56:12 | 000,002,519 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\searchplugins\Search_Results.xml
[2011/12/02 10:35:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/23 07:26:01 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/12/02 10:35:38 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/29 18:01:26 | 000,302,904 | —- | M] (Cisco WebEx LLC) – C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
[2003/03/18 21:20:00 | 001,060,864 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\mfc71.dll
[2003/02/21 04:42:22 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\msvcr71.dll
[2011/11/29 18:01:23 | 000,176,952 | —- | M] (Cisco WebEx LLC) – C:\Program Files\mozilla firefox\plugins\npatgpc.dll
[2010/05/21 11:16:22 | 000,155,648 | —- | M] (IBM Corporation) – C:\Program Files\mozilla firefox\plugins\npmfv.dll
[2011/12/02 10:35:33 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2009/09/25 11:39:22 | 000,003,700 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fast.png
[2009/09/25 11:39:22 | 000,001,963 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fast.xml
[2011/11/29 06:56:12 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011/12/02 10:35:33 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PE_IE_Helper Class) - {0941C58F-E461-4E03-BD7D-44C27392ADE1} - C:\Program Files\IBM\Lotus Forms\Viewer\3.5\PEhelper.dll (IBM Corporation)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..\Toolbar\WebBrowser: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - No CLSID value found.
O3 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKU\.DEFAULT..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-18..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-21-299502267-1682526488-839522115-1004..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LynxONE TaskBar Icon.lnk = C:\Program Files\Lynx Studio Technology\Mixer.exe (Lynx Studio Technology, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O15 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..Trusted Domains: microsoft.com ([www.update] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1238886182500 (WUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} https://wimpro.cce.hp.com/ChatEntry/downloads/msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in…r_installer.exe (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://splicesoftware.webex.com/client/T27…ort/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B0D9737B-FE70-4AAF-8488-91E2AB77D517}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7CBB56E-AA01-4B35-8F5B-FD8CB4A59325}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSTEM32\Userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - (TPSvc.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Derek\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Derek\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/04 14:16:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{35b89d1f-ef10-11de-834f-00248c5e6886}\Shell\AutoRun\command - "" = F:\MI.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: srv3844 - File not found
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

File not found – C:\WINDOWS\System32\
[2011/12/06 06:09:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1206
[2011/12/05 20:13:32 | 000,000,000 | —D | C] – C:\VS2010-VPC
[2011/12/05 19:41:52 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/12/05 17:20:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Picasa 3
[2011/12/05 17:17:51 | 000,000,000 | —D | C] – C:\Program Files\Picasa3
[2011/12/05 12:52:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\My Documents\Flagstar Statements
[2011/12/05 08:17:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1205
[2011/12/02 12:41:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Tracing
[2011/12/02 12:39:59 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/12/02 12:37:52 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2011/12/02 12:37:34 | 000,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2011/12/02 12:37:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live
[2011/12/02 12:37:08 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/12/02 12:33:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/12/02 06:40:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1202
[2011/12/01 08:41:25 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2011/12/01 08:41:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\STOPzilla
[2011/12/01 08:41:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2011/12/01 07:46:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/12/01 06:59:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1201
[2011/11/30 19:45:38 | 000,547,880 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/11/30 19:45:38 | 000,134,184 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/11/30 19:45:38 | 000,024,616 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/11/30 19:45:36 | 000,482,344 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/11/30 19:45:36 | 000,457,768 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/11/30 19:45:36 | 000,392,232 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/11/30 19:45:36 | 000,232,488 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/11/30 19:45:36 | 000,105,512 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/11/30 19:45:36 | 000,101,416 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/11/30 19:45:36 | 000,068,648 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/11/30 19:45:36 | 000,030,248 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/11/30 19:45:34 | 000,740,392 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/11/30 07:14:40 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/11/30 07:14:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/11/29 18:34:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\New Folder
[2011/11/29 18:01:38 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Derek\My Documents\cache
[2011/11/29 18:01:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\webex
[2011/11/29 09:45:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\CONTACTS
[2011/11/29 06:57:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\Ilivid Player
[2011/11/29 06:57:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\searchquband
[2011/11/29 06:57:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\AppData
[2011/11/29 06:56:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\searchqutoolbar
[2011/11/29 06:56:12 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/11/29 06:56:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/11/29 06:55:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\PackageAware
[2011/11/24 11:07:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Digiarty
[2011/11/24 11:04:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Digiarty
[2011/11/24 11:04:49 | 000,000,000 | —D | C] – C:\Program Files\Digiarty
[2011/11/24 11:04:25 | 008,249,312 | —- | C] (Digiarty Software,Inc. ) – C:\Program Files\winx-mov-to-wmv.exe
[2011/11/23 22:36:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\NCH Software Suite
[2011/11/23 22:32:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\My Documents\HP Photosmart Projects
[2011/11/23 22:31:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\HP
[2011/11/23 22:25:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Visan
[2011/11/23 22:25:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Visan
[2011/11/23 22:24:31 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2011/11/23 22:24:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP Photo Creations
[2011/11/23 07:25:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/11/21 11:45:56 | 005,073,240 | —- | C] (Microsoft Corporation) – C:\Program Files\vcredist_x86.exe
[2011/11/21 08:38:35 | 000,000,000 | —D | C] – C:\CTCTOutlook
[2011/11/21 08:32:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Constant Contact
[2011/11/18 09:27:30 | 000,000,000 | —D | C] – C:\Program Files\Constant Contact
[2011/11/17 08:11:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Avira
[2011/11/17 08:09:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/11/17 08:09:16 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/11/17 08:09:10 | 000,134,344 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/11/17 08:09:10 | 000,074,640 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/11/17 08:09:10 | 000,036,000 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avkmgr.sys
[2011/11/15 07:33:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\SCANS for Derek
[2011/11/15 03:00:40 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/11/14 17:11:41 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/11/14 17:10:58 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/11/14 14:43:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Desktop\Allison's Music
[2011/11/14 12:07:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2011/11/14 12:06:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
[2011/11/14 12:05:09 | 000,600,680 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\easyupdatusapiu.dll
[2011/11/14 12:03:28 | 017,186,816 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcompiler.dll
[2011/11/14 12:03:28 | 002,387,560 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvid.dll
[2011/11/14 12:03:28 | 002,090,088 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvenc.dll
[2011/11/14 12:03:28 | 000,914,024 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvdispco32.dll
[2011/11/14 12:03:28 | 000,875,112 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvgenco32.dll
[2011/11/14 12:03:28 | 000,061,440 | —- | C] (Khronos Group) – C:\WINDOWS\System32\OpenCL.dll
[2011/11/14 12:02:46 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2011/11/14 12:01:51 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/11/14 12:00:23 | 001,691,480 | —- | C] (Creative) – C:\WINDOWS\System32\drivers\Ambfilt.sys
[2011/11/14 11:59:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Renesas Electronics
[2011/11/14 11:59:15 | 000,000,000 | —D | C] – C:\Program Files\Renesas Electronics
[2011/11/14 11:44:53 | 000,023,456 | —- | C] (Phoenix Technologies) – C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2011/11/14 11:44:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\eSupport.com
[2011/11/11 15:48:16 | 001,564,976 | —- | C] (Kaspersky Lab ZAO) – C:\Program Files\TDSSKiller.exe
[2011/11/11 13:22:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Desktop\Virus-Spyware
[2011/11/10 14:08:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\CONCEPTUAL ARTS
[2011/11/10 05:21:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/09 11:48:25 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/09 09:40:53 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2011/08/09 09:40:30 | 004,500,784 | —- | C] (Amazon.com ) – C:\Program Files\AmazonUnboxVideo.exe
[2011/01/29 17:24:59 | 038,147,376 | —- | C] (Apple Inc.) – C:\Program Files\QuickTimeInstaller.exe
[2011/01/28 07:47:42 | 004,770,043 | —- | C] (Canneverbe Limited ) – C:\Program Files\cdbxp_setup_4.3.8.2474.exe
[2010/05/18 12:59:40 | 002,942,176 | —- | C] (Siber Systems) – C:\Program Files\AiRoboForm.exe
[2010/03/02 11:14:39 | 169,720,592 | —- | C] (IMSIDesign ) – C:\Program Files\TurboCAD-Deluxe-16-2.exe
[2009/05/29 05:27:46 | 000,301,384 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\All Users\Application Data\dxwebsetup.exe
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found – C:\WINDOWS\System32\
[2011/12/06 08:32:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{D07FB967-02EC-4F68-A7FA-D05A55F7A08C}.job
[2011/12/06 07:50:00 | 000,000,476 | —- | M] () – C:\WINDOWS\tasks\HP Photo Creations Communicator.job
[2011/12/06 06:47:41 | 000,482,856 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/06 06:47:41 | 000,085,286 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/06 06:45:24 | 000,000,744 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/12/06 06:43:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/06 06:06:33 | 000,000,433 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Shared Folder.lnk
[2011/12/05 20:17:11 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/05 19:49:42 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/12/05 19:48:38 | 000,000,815 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/05 19:26:31 | 000,280,276 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/12/05 19:26:31 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/12/05 19:21:43 | 000,280,276 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/12/05 18:00:00 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\File Backup.job
[2011/12/05 17:45:00 | 000,000,334 | —- | M] () – C:\WINDOWS\tasks\Update Tasks.job
[2011/12/05 17:20:17 | 000,000,684 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/12/05 17:20:17 | 000,000,666 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2011/12/05 17:04:11 | 000,039,424 | —- | M] () – C:\Documents and Settings\Derek\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/05 12:51:51 | 000,394,108 | —- | M] () – C:\Documents and Settings\Derek\My Documents\StatementViewer.pdf
[2011/12/05 07:21:00 | 000,234,813 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Portland-20111203-00069.jpg
[2011/12/05 06:22:48 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/02 15:05:15 | 000,002,231 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Shortcut to VMRecorder.exe.lnk
[2011/12/01 07:44:02 | 000,000,071 | —- | M] () – C:\WINDOWS\Pex.INI
[2011/11/30 19:45:38 | 000,547,880 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/11/30 19:45:38 | 000,134,184 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/11/30 19:45:38 | 000,024,616 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/11/30 19:45:36 | 000,482,344 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/11/30 19:45:36 | 000,457,768 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/11/30 19:45:36 | 000,392,232 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/11/30 19:45:36 | 000,232,488 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/11/30 19:45:36 | 000,105,512 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/11/30 19:45:36 | 000,101,416 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/11/30 19:45:36 | 000,068,648 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/11/30 19:45:36 | 000,030,248 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/11/30 19:45:34 | 000,740,392 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/11/29 09:55:54 | 000,043,976 | —- | M] () – C:\Documents and Settings\All Users\Documents\US Silver.pk
[2011/11/29 09:55:53 | 002,809,162 | —- | M] () – C:\Documents and Settings\All Users\Documents\US Silver.WAV
[2011/11/26 22:37:01 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\photopadShakeIcon.job
[2011/11/26 00:00:00 | 000,000,320 | —- | M] () – C:\WINDOWS\tasks\Clone Backup.job
[2011/11/24 11:04:32 | 008,249,312 | —- | M] (Digiarty Software,Inc. ) – C:\Program Files\winx-mov-to-wmv.exe
[2011/11/23 22:30:54 | 000,019,497 | —- | M] () – C:\WINDOWS\hpqins13.dat
[2011/11/21 11:55:48 | 005,073,240 | —- | M] (Microsoft Corporation) – C:\Program Files\vcredist_x86.exe
[2011/11/17 08:07:43 | 000,028,520 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/11/17 08:07:42 | 000,036,000 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avkmgr.sys
[2011/11/17 08:07:41 | 000,134,344 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/11/17 08:07:40 | 000,074,640 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/11/15 03:39:09 | 000,275,760 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/14 13:29:22 | 000,000,014 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2011/11/14 12:25:23 | 000,000,298 | RHS- | M] () – C:\boot.ini
[2011/11/14 12:04:55 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/11/14 11:44:53 | 000,023,456 | —- | M] (Phoenix Technologies) – C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2011/11/14 11:36:19 | 000,177,751 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/11/14 11:31:54 | 000,210,085 | —- | M] () – C:\MGlogs.zip
[2011/11/11 15:48:16 | 001,564,976 | —- | M] (Kaspersky Lab ZAO) – C:\Program Files\TDSSKiller.exe
[2011/11/11 14:07:16 | 000,001,037 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/11/11 09:17:52 | 000,000,000 | —- | M] () – C:\WINDOWS\2771026874
[2011/11/10 22:44:02 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/06 06:45:17 | 000,000,744 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/12/05 17:20:17 | 000,000,684 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/12/05 17:20:17 | 000,000,666 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2011/12/05 12:51:51 | 000,394,108 | —- | C] () – C:\Documents and Settings\Derek\My Documents\StatementViewer.pdf
[2011/12/05 07:21:00 | 000,234,813 | —- | C] () – C:\Documents and Settings\Derek\Desktop\Portland-20111203-00069.jpg
[2011/12/02 10:35:42 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/29 09:55:53 | 002,809,162 | —- | C] () – C:\Documents and Settings\All Users\Documents\US Silver.WAV
[2011/11/29 09:55:53 | 000,043,976 | —- | C] () – C:\Documents and Settings\All Users\Documents\US Silver.pk
[2011/11/23 22:37:57 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\photopadShakeIcon.job
[2011/11/23 22:36:40 | 000,000,805 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\PhotoPad Image Editor.lnk
[2011/11/23 22:29:08 | 000,019,497 | —- | C] () – C:\WINDOWS\hpqins13.dat
[2011/11/23 22:24:51 | 000,000,476 | —- | C] () – C:\WINDOWS\tasks\HP Photo Creations Communicator.job
[2011/11/15 03:00:43 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/11/14 12:04:55 | 000,280,276 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/11/14 12:04:55 | 000,280,276 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/11/14 12:04:55 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/11/14 12:04:55 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/11/14 12:03:28 | 002,128,778 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/11/14 12:03:28 | 000,003,249 | —- | C] () – C:\WINDOWS\System32\nvinfo.pb
[2011/11/09 11:48:32 | 000,001,037 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/11/09 08:31:28 | 000,000,000 | —- | C] () – C:\WINDOWS\2771026874
[2011/09/06 11:00:03 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2011/09/03 08:17:59 | 000,080,416 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/09/03 08:08:27 | 000,207,400 | R— | C] () – C:\WINDOWS\GSetup.exe
[2011/09/03 08:08:27 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2011/09/02 17:52:48 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/08/09 09:41:01 | 001,894,912 | —- | C] () – C:\Program Files\Amazon Unbox Video.msi
[2011/08/09 09:41:01 | 000,006,129 | —- | C] () – C:\Program Files\0x0409.ini
[2011/05/20 11:27:40 | 000,000,071 | —- | C] () – C:\WINDOWS\Pex.INI
[2011/05/19 03:36:13 | 000,413,024 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/28 07:48:11 | 000,005,504 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/12/15 11:11:36 | 000,278,398 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/11/19 06:25:02 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/11/19 06:22:09 | 000,000,006 | —- | C] () – C:\Documents and Settings\Derek\Application Data\start
[2010/11/19 05:25:05 | 000,000,006 | —- | C] () – C:\Documents and Settings\Derek\Application Data\completescan
[2010/11/19 05:11:16 | 000,000,010 | —- | C] () – C:\Documents and Settings\Derek\Application Data\install
[2010/10/05 04:24:10 | 000,038,469 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (Windows).ADR
[2010/09/15 16:36:38 | 000,000,185 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/06/16 11:06:00 | 003,535,754 | —- | C] () – C:\Program Files\VoiceMergeRecorder.zip
[2010/04/22 07:09:11 | 000,000,088 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2010/04/09 04:53:39 | 000,122,880 | —- | C] () – C:\WINDOWS\UnGins.exe
[2009/11/10 06:51:59 | 000,057,236 | —- | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/09/28 13:53:31 | 000,020,992 | —- | C] () – C:\WINDOWS\jestertb.dll
[2009/08/21 09:46:45 | 000,000,014 | —- | C] () – C:\WINDOWS\System32\nvModes.dat
[2009/08/20 07:44:43 | 000,000,056 | —- | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/07/01 06:38:25 | 000,105,290 | —- | C] () – C:\WINDOWS\HPFins09.dat.temp
[2009/07/01 06:38:25 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat.temp
[2009/05/18 05:18:31 | 000,039,424 | —- | C] () – C:\Documents and Settings\Derek\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/27 06:15:23 | 000,013,000 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (DOS).CAL
[2009/04/26 07:28:30 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2009/04/17 12:15:45 | 000,038,472 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (DOS).ADR
[2009/04/10 09:03:17 | 013,190,496 | —- | C] () – C:\Program Files\winzip120.exe
[2009/04/07 11:44:45 | 000,389,344 | —- | C] () – C:\Program Files\Setup024m.exe
[2009/04/07 08:44:10 | 000,002,451 | —- | C] () – C:\Program Files\Alesis Firewire Control Panel.lnk
[2009/04/07 07:38:20 | 000,413,183 | —- | C] () – C:\Program Files\ASIO4ALL_2_9_English.exe
[2009/04/07 05:40:50 | 000,001,747 | —- | C] () – C:\Program Files\Start Download Manager.lnk
[2009/04/06 12:18:42 | 000,000,984 | —- | C] () – C:\Program Files\HP Solution Center.lnk
[2009/04/06 11:53:39 | 000,102,833 | —- | C] () – C:\WINDOWS\HPFins09.dat
[2009/04/06 11:53:39 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat
[2009/04/06 11:53:27 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2009/04/05 16:09:11 | 000,446,464 | —- | C] () – C:\WINDOWS\System32\DspfxCro.dll
[2009/04/05 16:09:11 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\DspfxDll.dll
[2009/04/05 16:09:11 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\DspfxCom.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS9.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS8.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS6.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS5.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS4.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS3.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS2.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS15.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS14.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS13.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS12.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS1.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxDw.dll
[2009/04/05 16:09:11 | 000,015,040 | —- | C] () – C:\WINDOWS\System32\Mxmidi16.dll
[2009/04/05 12:44:01 | 000,000,772 | —- | C] () – C:\Program Files\DriveImage XML.lnk
[2009/04/04 17:44:52 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/04/04 17:37:05 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\AvgLdx86.sys
[2009/04/04 14:59:29 | 000,000,000 | —- | C] () – C:\WINDOWS\msicpl.ini
[2009/04/04 14:50:18 | 000,131,072 | R— | C] () – C:\WINDOWS\System32\smdll.dll
[2009/04/04 14:50:14 | 000,258,048 | R— | C] () – C:\WINDOWS\System32\HookMAp.dll
[2009/04/04 14:50:14 | 000,032,768 | R— | C] () – C:\WINDOWS\System32\Auxiliary.dll
[2009/04/04 14:50:13 | 000,262,144 | R— | C] () – C:\WINDOWS\System32\HookShield.dll
[2009/04/04 14:38:48 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\AsIO.dll
[2009/04/04 14:22:50 | 000,036,537 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2009/04/04 14:22:23 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/04/04 14:22:17 | 000,035,944 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/04/04 14:22:17 | 000,010,296 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/04/04 14:17:50 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/04/04 14:14:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/04/04 06:07:10 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/04/04 06:06:07 | 000,275,760 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 20:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/02 19:16:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2004/08/04 04:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 04:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 04:00:00 | 000,482,856 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 04:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 04:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 04:00:00 | 000,085,286 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 04:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 04:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 04:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 04:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 04:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 04:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/01/30 08:37:50 | 000,000,092 | R— | C] () – C:\WINDOWS\System32\FTDIUN2K.INI
[2002/03/01 13:43:34 | 000,028,008 | —- | C] () – C:\WINDOWS\System32\SUSUSB.SYS
[2001/07/06 15:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2011/08/09 09:41:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Amazon
[2011/11/29 06:56:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/01/28 07:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/09/23 13:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/06/05 09:39:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2009/05/12 14:00:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2011/09/23 13:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/04/05 09:53:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2011/01/05 11:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PureEdge
[2009/12/26 05:19:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2011/12/06 08:15:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/12/06 06:43:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/20 09:32:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/11/23 22:25:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visan
[2010/01/22 07:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/17 14:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\ArcVP
[2011/01/28 07:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Canneverbe Limited
[2009/10/26 05:50:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\CoffeeCup Software
[2009/05/19 09:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\CoreFTP
[2011/09/24 07:14:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\DD83E66D5FAF4DC27D3466A7C9D66E4F
[2011/11/24 12:04:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Digiarty
[2011/09/13 12:22:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Dropbox
[2009/12/08 07:07:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\FileZilla
[2010/12/10 12:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\GARMIN
[2009/11/10 09:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\GetRightToGo
[2011/12/05 17:11:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Image Zone Express
[2010/03/02 11:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\IMSIDesign
[2011/09/20 12:42:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\ImTOO
[2010/11/07 06:48:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\JAM Software
[2010/04/22 07:09:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Leadertech
[2009/09/28 14:28:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Memeo
[2009/11/12 11:23:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Motion Technologies
[2009/08/24 18:39:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Pamela
[2011/01/05 11:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\PureEdge
[2011/11/29 06:57:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\searchquband
[2011/11/29 06:57:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\searchqutoolbar
[2011/09/23 06:54:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\TeamViewer
[2011/11/14 11:56:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\TMP
[2011/05/20 09:36:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Ulead Systems
[2011/11/23 22:50:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Visan
[2011/11/29 18:01:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\webex
[2009/05/11 08:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Windows Desktop Search
[2009/05/12 19:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Windows Search
[2011/11/26 00:00:00 | 000,000,320 | —- | M] () – C:\WINDOWS\Tasks\Clone Backup.job
[2010/12/31 06:40:01 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\disketchShakeIcon.job
[2011/12/05 18:00:00 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\File Backup.job
[2011/11/26 22:37:01 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\photopadShakeIcon.job
[2011/12/05 17:45:00 | 000,000,334 | —- | M] () – C:\WINDOWS\Tasks\Update Tasks.job
[2011/12/06 08:32:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{D07FB967-02EC-4F68-A7FA-D05A55F7A08C}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 04:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 04:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\MGtools\temp\SPF\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 04:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 04:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2007/07/12 13:35:02 | 000,305,176 | R— | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 – C:\cmdcons\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 04:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NVATA.SYS >
[2006/10/18 14:31:38 | 000,105,472 | R— | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A – C:\cmdcons\nvata.sys

< MD5 for: NVATABUS.SYS >
[2006/10/18 13:31:38 | 000,105,472 | R— | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A – C:\cmdcons\NvAtaBus.sys

< MD5 for: SCECLI.DLL >
[2004/08/04 04:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< MD5 for: SYMMPI.SYS >
[2007/02/09 19:06:00 | 000,100,096 | R— | M] (LSI Logic) MD5=A42F863305943869BA00A613C8EE8C7E – C:\cmdcons\symmpi.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/04/04 06:04:49 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/04/04 06:04:48 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/04/04 06:04:48 | 000,937,984 | —- | M] () – C:\WINDOWS\System32\config\system.sav

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB28633$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
OTL logfile created on: 12/6/2011 8:27:52 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Derek\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 72.66% Memory free
4.84 Gb Paging File | 4.17 Gb Available in Paging File | 86.19% Paging File free
Paging file location(s): C:\pagefile.sys 2048 2048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 763.11 Gb Free Space | 81.92% Space Free | Partition Type: NTFS
Drive E: | 11.17 Gb Total Space | 10.27 Gb Free Space | 91.94% Space Free | Partition Type: FAT32
Drive X: | 931.51 Gb Total Space | 420.21 Gb Free Space | 45.11% Space Free | Partition Type: NTFS

Computer Name: DEREK | User Name: Derek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Derek\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lynx Studio Technology\Mixer.exe (Lynx Studio Technology, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()


========== Win32 Services (SafeList) ==========

SRV - (ZuneBusEnum) – File not found
SRV - (WSearch) – File not found
SRV - (ThreatFire) – File not found
SRV - (srv3844) – File not found
SRV - (sdCoreService) – File not found
SRV - (sdAuxService) – File not found
SRV - (Pml Driver HPZ12) – File not found
SRV - (MSCamSvc) – File not found
SRV - (JavaQuickStarterService) – File not found
SRV - (CCALib8) – File not found
SRV - (AsSysCtrlService) – File not found
SRV - (AppMgmt) – File not found
SRV - (ADVService) – File not found
SRV - (szserver) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) – C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirMailService) – C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (WMZuneComm) – c:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – c:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)


========== Driver Services (SafeList) ==========

DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avkmgr) – C:\WINDOWS\system32\drivers\avkmgr.sys (Avira GmbH)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (DrvAgent32) – C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (szkg5) – C:\WINDOWS\system32\drivers\szkg.sys (iS3 Inc.)
DRV - (is3srv) – C:\WINDOWS\system32\drivers\is3srv.sys (iS3 Inc.)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (szkgfs) – C:\WINDOWS\system32\drivers\szkgfs.sys (iS3, Inc.)
DRV - (mv91cons) – C:\WINDOWS\system32\DRIVERS\mv91cons.sys (Marvell Semiconductor Inc.)
DRV - (mv91xx) – C:\WINDOWS\system32\DRIVERS\mv91xx.sys (Marvell Semiconductor, Inc.)
DRV - (nusb3xhc) – C:\WINDOWS\system32\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV - (nusb3hub) – C:\WINDOWS\system32\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (MSHUSBVideo) – C:\WINDOWS\system32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (mv61xx) – C:\WINDOWS\system32\DRIVERS\mv61xx.sys (Marvell Semiconductor, Inc.)
DRV - (AlesisFirewire) – C:\WINDOWS\system32\drivers\AlesisFirewire.sys (Alesis)
DRV - (AlesisFirewireAudio) – C:\WINDOWS\system32\drivers\AlesisFirewireAudio.sys (Alesis)
DRV - (AlesisFirewireMidi) – C:\WINDOWS\system32\drivers\AlesisFirewireMidi.sys (Alesis)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (SUSTUCAU) – C:\WINDOWS\system32\drivers\sustucau.sys (Susteen, Inc.)
DRV - (SUSTUCAP) – C:\WINDOWS\system32\drivers\sustucap.sys (Susteen, Inc.)
DRV - (SUSTUCAM) – C:\WINDOWS\system32\drivers\sustucam.sys (Susteen, Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (DiceAudioStrm) – C:\WINDOWS\system32\drivers\DiceAudioStrm.sys (TC Tech Inc.)
DRV - (Dice1394) – C:\WINDOWS\system32\drivers\Dice1394.sys (TC Tech Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (Lynx) – C:\WINDOWS\SYSTEM32\DRIVERS\Lynx.SYS (Lynx Studio Technology, Inc.)
DRV - (banshee) – C:\WINDOWS\system32\drivers\banshee.sys (3Dfx Interactive, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: "free-downloads.net Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {ecdee021-0d17-467f-a1ff-c7a115230949}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..keyword.URL: "http://search.search-go.net/?sid=10101052100&s;="
FF - prefs.js..network.proxy.type: 0

FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..keyword.URL: "http://search.search-go.net/?sid=10101052100&s;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/05/11 05:15:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2009/12/26 05:18:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/02 10:35:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/02 10:35:40 | 000,000,000 | —D | M]

[2011/11/30 07:51:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Derek\Application Data\Mozilla\Extensions
[2011/12/06 06:25:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions
[2011/03/29 07:45:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/09/14 07:35:32 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/09/14 11:54:44 | 000,000,000 | —D | M] (NCH) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{c2db4fe6-8409-45ce-8010-189a7b5cce86}
[2011/12/02 12:41:21 | 000,000,000 | —D | M] (Microsoft Choice Guard) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\ChoiceGuard@Microsoft
[2010/01/20 12:16:28 | 000,000,939 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\searchplugins\conduit.xml
[2011/11/29 06:56:12 | 000,002,519 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\searchplugins\Search_Results.xml
[2011/12/02 10:35:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/23 07:26:01 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/12/02 10:35:38 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/29 18:01:26 | 000,302,904 | —- | M] (Cisco WebEx LLC) – C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
[2003/03/18 21:20:00 | 001,060,864 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\mfc71.dll
[2003/02/21 04:42:22 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\msvcr71.dll
[2011/11/29 18:01:23 | 000,176,952 | —- | M] (Cisco WebEx LLC) – C:\Program Files\mozilla firefox\plugins\npatgpc.dll
[2010/05/21 11:16:22 | 000,155,648 | —- | M] (IBM Corporation) – C:\Program Files\mozilla firefox\plugins\npmfv.dll
[2011/12/02 10:35:33 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2009/09/25 11:39:22 | 000,003,700 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fast.png
[2009/09/25 11:39:22 | 000,001,963 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fast.xml
[2011/11/29 06:56:12 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011/12/02 10:35:33 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PE_IE_Helper Class) - {0941C58F-E461-4E03-BD7D-44C27392ADE1} - C:\Program Files\IBM\Lotus Forms\Viewer\3.5\PEhelper.dll (IBM Corporation)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..\Toolbar\WebBrowser: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - No CLSID value found.
O3 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKU\.DEFAULT..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-18..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-21-299502267-1682526488-839522115-1004..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LynxONE TaskBar Icon.lnk = C:\Program Files\Lynx Studio Technology\Mixer.exe (Lynx Studio Technology, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O15 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..Trusted Domains: microsoft.com ([www.update] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1238886182500 (WUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} https://wimpro.cce.hp.com/ChatEntry/downloads/msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in…r_installer.exe (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://splicesoftware.webex.com/client/T27…ort/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B0D9737B-FE70-4AAF-8488-91E2AB77D517}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7CBB56E-AA01-4B35-8F5B-FD8CB4A59325}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSTEM32\Userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - (TPSvc.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Derek\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Derek\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/04 14:16:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{35b89d1f-ef10-11de-834f-00248c5e6886}\Shell\AutoRun\command - "" = F:\MI.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: srv3844 - File not found
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

File not found – C:\WINDOWS\System32\
[2011/12/06 06:09:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1206
[2011/12/05 20:13:32 | 000,000,000 | —D | C] – C:\VS2010-VPC
[2011/12/05 19:41:52 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/12/05 17:20:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Picasa 3
[2011/12/05 17:17:51 | 000,000,000 | —D | C] – C:\Program Files\Picasa3
[2011/12/05 12:52:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\My Documents\Flagstar Statements
[2011/12/05 08:17:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1205
[2011/12/02 12:41:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Tracing
[2011/12/02 12:39:59 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/12/02 12:37:52 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2011/12/02 12:37:34 | 000,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2011/12/02 12:37:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live
[2011/12/02 12:37:08 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/12/02 12:33:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/12/02 06:40:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1202
[2011/12/01 08:41:25 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2011/12/01 08:41:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\STOPzilla
[2011/12/01 08:41:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2011/12/01 07:46:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/12/01 06:59:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1201
[2011/11/30 19:45:38 | 000,547,880 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/11/30 19:45:38 | 000,134,184 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/11/30 19:45:38 | 000,024,616 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/11/30 19:45:36 | 000,482,344 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/11/30 19:45:36 | 000,457,768 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/11/30 19:45:36 | 000,392,232 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/11/30 19:45:36 | 000,232,488 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/11/30 19:45:36 | 000,105,512 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/11/30 19:45:36 | 000,101,416 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/11/30 19:45:36 | 000,068,648 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/11/30 19:45:36 | 000,030,248 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/11/30 19:45:34 | 000,740,392 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/11/30 07:14:40 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/11/30 07:14:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/11/29 18:34:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\New Folder
[2011/11/29 18:01:38 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Derek\My Documents\cache
[2011/11/29 18:01:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\webex
[2011/11/29 09:45:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\CONTACTS
[2011/11/29 06:57:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\Ilivid Player
[2011/11/29 06:57:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\searchquband
[2011/11/29 06:57:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\AppData
[2011/11/29 06:56:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\searchqutoolbar
[2011/11/29 06:56:12 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/11/29 06:56:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/11/29 06:55:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\PackageAware
[2011/11/24 11:07:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Digiarty
[2011/11/24 11:04:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Digiarty
[2011/11/24 11:04:49 | 000,000,000 | —D | C] – C:\Program Files\Digiarty
[2011/11/24 11:04:25 | 008,249,312 | —- | C] (Digiarty Software,Inc. ) – C:\Program Files\winx-mov-to-wmv.exe
[2011/11/23 22:36:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\NCH Software Suite
[2011/11/23 22:32:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\My Documents\HP Photosmart Projects
[2011/11/23 22:31:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\HP
[2011/11/23 22:25:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Visan
[2011/11/23 22:25:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Visan
[2011/11/23 22:24:31 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2011/11/23 22:24:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP Photo Creations
[2011/11/23 07:25:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/11/21 11:45:56 | 005,073,240 | —- | C] (Microsoft Corporation) – C:\Program Files\vcredist_x86.exe
[2011/11/21 08:38:35 | 000,000,000 | —D | C] – C:\CTCTOutlook
[2011/11/21 08:32:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Constant Contact
[2011/11/18 09:27:30 | 000,000,000 | —D | C] – C:\Program Files\Constant Contact
[2011/11/17 08:11:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Avira
[2011/11/17 08:09:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/11/17 08:09:16 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/11/17 08:09:10 | 000,134,344 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/11/17 08:09:10 | 000,074,640 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/11/17 08:09:10 | 000,036,000 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avkmgr.sys
[2011/11/15 07:33:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\SCANS for Derek
[2011/11/15 03:00:40 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/11/14 17:11:41 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/11/14 17:10:58 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/11/14 14:43:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Desktop\Allison's Music
[2011/11/14 12:07:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2011/11/14 12:06:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
[2011/11/14 12:05:09 | 000,600,680 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\easyupdatusapiu.dll
[2011/11/14 12:03:28 | 017,186,816 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcompiler.dll
[2011/11/14 12:03:28 | 002,387,560 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvid.dll
[2011/11/14 12:03:28 | 002,090,088 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvenc.dll
[2011/11/14 12:03:28 | 000,914,024 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvdispco32.dll
[2011/11/14 12:03:28 | 000,875,112 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvgenco32.dll
[2011/11/14 12:03:28 | 000,061,440 | —- | C] (Khronos Group) – C:\WINDOWS\System32\OpenCL.dll
[2011/11/14 12:02:46 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2011/11/14 12:01:51 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/11/14 12:00:23 | 001,691,480 | —- | C] (Creative) – C:\WINDOWS\System32\drivers\Ambfilt.sys
[2011/11/14 11:59:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Renesas Electronics
[2011/11/14 11:59:15 | 000,000,000 | —D | C] – C:\Program Files\Renesas Electronics
[2011/11/14 11:44:53 | 000,023,456 | —- | C] (Phoenix Technologies) – C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2011/11/14 11:44:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\eSupport.com
[2011/11/11 15:48:16 | 001,564,976 | —- | C] (Kaspersky Lab ZAO) – C:\Program Files\TDSSKiller.exe
[2011/11/11 13:22:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Desktop\Virus-Spyware
[2011/11/10 14:08:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\CONCEPTUAL ARTS
[2011/11/10 05:21:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/09 11:48:25 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/09 09:40:53 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2011/08/09 09:40:30 | 004,500,784 | —- | C] (Amazon.com ) – C:\Program Files\AmazonUnboxVideo.exe
[2011/01/29 17:24:59 | 038,147,376 | —- | C] (Apple Inc.) – C:\Program Files\QuickTimeInstaller.exe
[2011/01/28 07:47:42 | 004,770,043 | —- | C] (Canneverbe Limited ) – C:\Program Files\cdbxp_setup_4.3.8.2474.exe
[2010/05/18 12:59:40 | 002,942,176 | —- | C] (Siber Systems) – C:\Program Files\AiRoboForm.exe
[2010/03/02 11:14:39 | 169,720,592 | —- | C] (IMSIDesign ) – C:\Program Files\TurboCAD-Deluxe-16-2.exe
[2009/05/29 05:27:46 | 000,301,384 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\All Users\Application Data\dxwebsetup.exe
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found – C:\WINDOWS\System32\
[2011/12/06 08:32:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{D07FB967-02EC-4F68-A7FA-D05A55F7A08C}.job
[2011/12/06 07:50:00 | 000,000,476 | —- | M] () – C:\WINDOWS\tasks\HP Photo Creations Communicator.job
[2011/12/06 06:47:41 | 000,482,856 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/06 06:47:41 | 000,085,286 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/06 06:45:24 | 000,000,744 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/12/06 06:43:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/06 06:06:33 | 000,000,433 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Shared Folder.lnk
[2011/12/05 20:17:11 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/05 19:49:42 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/12/05 19:48:38 | 000,000,815 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/05 19:26:31 | 000,280,276 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/12/05 19:26:31 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/12/05 19:21:43 | 000,280,276 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/12/05 18:00:00 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\File Backup.job
[2011/12/05 17:45:00 | 000,000,334 | —- | M] () – C:\WINDOWS\tasks\Update Tasks.job
[2011/12/05 17:20:17 | 000,000,684 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/12/05 17:20:17 | 000,000,666 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2011/12/05 17:04:11 | 000,039,424 | —- | M] () – C:\Documents and Settings\Derek\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/05 12:51:51 | 000,394,108 | —- | M] () – C:\Documents and Settings\Derek\My Documents\StatementViewer.pdf
[2011/12/05 07:21:00 | 000,234,813 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Portland-20111203-00069.jpg
[2011/12/05 06:22:48 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/02 15:05:15 | 000,002,231 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Shortcut to VMRecorder.exe.lnk
[2011/12/01 07:44:02 | 000,000,071 | —- | M] () – C:\WINDOWS\Pex.INI
[2011/11/30 19:45:38 | 000,547,880 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/11/30 19:45:38 | 000,134,184 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/11/30 19:45:38 | 000,024,616 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/11/30 19:45:36 | 000,482,344 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/11/30 19:45:36 | 000,457,768 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/11/30 19:45:36 | 000,392,232 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/11/30 19:45:36 | 000,232,488 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/11/30 19:45:36 | 000,105,512 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/11/30 19:45:36 | 000,101,416 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/11/30 19:45:36 | 000,068,648 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/11/30 19:45:36 | 000,030,248 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/11/30 19:45:34 | 000,740,392 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/11/29 09:55:54 | 000,043,976 | —- | M] () – C:\Documents and Settings\All Users\Documents\US Silver.pk
[2011/11/29 09:55:53 | 002,809,162 | —- | M] () – C:\Documents and Settings\All Users\Documents\US Silver.WAV
[2011/11/26 22:37:01 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\photopadShakeIcon.job
[2011/11/26 00:00:00 | 000,000,320 | —- | M] () – C:\WINDOWS\tasks\Clone Backup.job
[2011/11/24 11:04:32 | 008,249,312 | —- | M] (Digiarty Software,Inc. ) – C:\Program Files\winx-mov-to-wmv.exe
[2011/11/23 22:30:54 | 000,019,497 | —- | M] () – C:\WINDOWS\hpqins13.dat
[2011/11/21 11:55:48 | 005,073,240 | —- | M] (Microsoft Corporation) – C:\Program Files\vcredist_x86.exe
[2011/11/17 08:07:43 | 000,028,520 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/11/17 08:07:42 | 000,036,000 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avkmgr.sys
[2011/11/17 08:07:41 | 000,134,344 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/11/17 08:07:40 | 000,074,640 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/11/15 03:39:09 | 000,275,760 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/14 13:29:22 | 000,000,014 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2011/11/14 12:25:23 | 000,000,298 | RHS- | M] () – C:\boot.ini
[2011/11/14 12:04:55 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/11/14 11:44:53 | 000,023,456 | —- | M] (Phoenix Technologies) – C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2011/11/14 11:36:19 | 000,177,751 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/11/14 11:31:54 | 000,210,085 | —- | M] () – C:\MGlogs.zip
[2011/11/11 15:48:16 | 001,564,976 | —- | M] (Kaspersky Lab ZAO) – C:\Program Files\TDSSKiller.exe
[2011/11/11 14:07:16 | 000,001,037 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/11/11 09:17:52 | 000,000,000 | —- | M] () – C:\WINDOWS\2771026874
[2011/11/10 22:44:02 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/06 06:45:17 | 000,000,744 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/12/05 17:20:17 | 000,000,684 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/12/05 17:20:17 | 000,000,666 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2011/12/05 12:51:51 | 000,394,108 | —- | C] () – C:\Documents and Settings\Derek\My Documents\StatementViewer.pdf
[2011/12/05 07:21:00 | 000,234,813 | —- | C] () – C:\Documents and Settings\Derek\Desktop\Portland-20111203-00069.jpg
[2011/12/02 10:35:42 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/29 09:55:53 | 002,809,162 | —- | C] () – C:\Documents and Settings\All Users\Documents\US Silver.WAV
[2011/11/29 09:55:53 | 000,043,976 | —- | C] () – C:\Documents and Settings\All Users\Documents\US Silver.pk
[2011/11/23 22:37:57 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\photopadShakeIcon.job
[2011/11/23 22:36:40 | 000,000,805 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\PhotoPad Image Editor.lnk
[2011/11/23 22:29:08 | 000,019,497 | —- | C] () – C:\WINDOWS\hpqins13.dat
[2011/11/23 22:24:51 | 000,000,476 | —- | C] () – C:\WINDOWS\tasks\HP Photo Creations Communicator.job
[2011/11/15 03:00:43 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/11/14 12:04:55 | 000,280,276 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/11/14 12:04:55 | 000,280,276 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/11/14 12:04:55 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/11/14 12:04:55 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/11/14 12:03:28 | 002,128,778 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/11/14 12:03:28 | 000,003,249 | —- | C] () – C:\WINDOWS\System32\nvinfo.pb
[2011/11/09 11:48:32 | 000,001,037 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/11/09 08:31:28 | 000,000,000 | —- | C] () – C:\WINDOWS\2771026874
[2011/09/06 11:00:03 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2011/09/03 08:17:59 | 000,080,416 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/09/03 08:08:27 | 000,207,400 | R— | C] () – C:\WINDOWS\GSetup.exe
[2011/09/03 08:08:27 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2011/09/02 17:52:48 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/08/09 09:41:01 | 001,894,912 | —- | C] () – C:\Program Files\Amazon Unbox Video.msi
[2011/08/09 09:41:01 | 000,006,129 | —- | C] () – C:\Program Files\0x0409.ini
[2011/05/20 11:27:40 | 000,000,071 | —- | C] () – C:\WINDOWS\Pex.INI
[2011/05/19 03:36:13 | 000,413,024 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/28 07:48:11 | 000,005,504 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/12/15 11:11:36 | 000,278,398 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/11/19 06:25:02 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/11/19 06:22:09 | 000,000,006 | —- | C] () – C:\Documents and Settings\Derek\Application Data\start
[2010/11/19 05:25:05 | 000,000,006 | —- | C] () – C:\Documents and Settings\Derek\Application Data\completescan
[2010/11/19 05:11:16 | 000,000,010 | —- | C] () – C:\Documents and Settings\Derek\Application Data\install
[2010/10/05 04:24:10 | 000,038,469 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (Windows).ADR
[2010/09/15 16:36:38 | 000,000,185 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/06/16 11:06:00 | 003,535,754 | —- | C] () – C:\Program Files\VoiceMergeRecorder.zip
[2010/04/22 07:09:11 | 000,000,088 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2010/04/09 04:53:39 | 000,122,880 | —- | C] () – C:\WINDOWS\UnGins.exe
[2009/11/10 06:51:59 | 000,057,236 | —- | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/09/28 13:53:31 | 000,020,992 | —- | C] () – C:\WINDOWS\jestertb.dll
[2009/08/21 09:46:45 | 000,000,014 | —- | C] () – C:\WINDOWS\System32\nvModes.dat
[2009/08/20 07:44:43 | 000,000,056 | —- | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/07/01 06:38:25 | 000,105,290 | —- | C] () – C:\WINDOWS\HPFins09.dat.temp
[2009/07/01 06:38:25 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat.temp
[2009/05/18 05:18:31 | 000,039,424 | —- | C] () – C:\Documents and Settings\Derek\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/27 06:15:23 | 000,013,000 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (DOS).CAL
[2009/04/26 07:28:30 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2009/04/17 12:15:45 | 000,038,472 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (DOS).ADR
[2009/04/10 09:03:17 | 013,190,496 | —- | C] () – C:\Program Files\winzip120.exe
[2009/04/07 11:44:45 | 000,389,344 | —- | C] () – C:\Program Files\Setup024m.exe
[2009/04/07 08:44:10 | 000,002,451 | —- | C] () – C:\Program Files\Alesis Firewire Control Panel.lnk
[2009/04/07 07:38:20 | 000,413,183 | —- | C] () – C:\Program Files\ASIO4ALL_2_9_English.exe
[2009/04/07 05:40:50 | 000,001,747 | —- | C] () – C:\Program Files\Start Download Manager.lnk
[2009/04/06 12:18:42 | 000,000,984 | —- | C] () – C:\Program Files\HP Solution Center.lnk
[2009/04/06 11:53:39 | 000,102,833 | —- | C] () – C:\WINDOWS\HPFins09.dat
[2009/04/06 11:53:39 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat
[2009/04/06 11:53:27 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2009/04/05 16:09:11 | 000,446,464 | —- | C] () – C:\WINDOWS\System32\DspfxCro.dll
[2009/04/05 16:09:11 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\DspfxDll.dll
[2009/04/05 16:09:11 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\DspfxCom.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS9.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS8.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS6.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS5.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS4.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS3.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS2.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS15.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS14.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS13.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS12.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS1.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxDw.dll
[2009/04/05 16:09:11 | 000,015,040 | —- | C] () – C:\WINDOWS\System32\Mxmidi16.dll
[2009/04/05 12:44:01 | 000,000,772 | —- | C] () – C:\Program Files\DriveImage XML.lnk
[2009/04/04 17:44:52 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/04/04 17:37:05 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\AvgLdx86.sys
[2009/04/04 14:59:29 | 000,000,000 | —- | C] () – C:\WINDOWS\msicpl.ini
[2009/04/04 14:50:18 | 000,131,072 | R— | C] () – C:\WINDOWS\System32\smdll.dll
[2009/04/04 14:50:14 | 000,258,048 | R— | C] () – C:\WINDOWS\System32\HookMAp.dll
[2009/04/04 14:50:14 | 000,032,768 | R— | C] () – C:\WINDOWS\System32\Auxiliary.dll
[2009/04/04 14:50:13 | 000,262,144 | R— | C] () – C:\WINDOWS\System32\HookShield.dll
[2009/04/04 14:38:48 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\AsIO.dll
[2009/04/04 14:22:50 | 000,036,537 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2009/04/04 14:22:23 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/04/04 14:22:17 | 000,035,944 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/04/04 14:22:17 | 000,010,296 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/04/04 14:17:50 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/04/04 14:14:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/04/04 06:07:10 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/04/04 06:06:07 | 000,275,760 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 20:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/02 19:16:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2004/08/04 04:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 04:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 04:00:00 | 000,482,856 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 04:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 04:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 04:00:00 | 000,085,286 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 04:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 04:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 04:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 04:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 04:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 04:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/01/30 08:37:50 | 000,000,092 | R— | C] () – C:\WINDOWS\System32\FTDIUN2K.INI
[2002/03/01 13:43:34 | 000,028,008 | —- | C] () – C:\WINDOWS\System32\SUSUSB.SYS
[2001/07/06 15:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2011/08/09 09:41:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Amazon
[2011/11/29 06:56:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/01/28 07:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/09/23 13:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/06/05 09:39:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2009/05/12 14:00:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2011/09/23 13:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/04/05 09:53:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2011/01/05 11:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PureEdge
[2009/12/26 05:19:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2011/12/06 08:15:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/12/06 06:43:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/20 09:32:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/11/23 22:25:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visan
[2010/01/22 07:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/17 14:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\ArcVP
[2011/01/28 07:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Canneverbe Limited
[2009/10/26 05:50:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\CoffeeCup Software
[2009/05/19 09:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\CoreFTP
[2011/09/24 07:14:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\DD83E66D5FAF4DC27D3466A7C9D66E4F
[2011/11/24 12:04:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Digiarty
[2011/09/13 12:22:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Dropbox
[2009/12/08 07:07:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\FileZilla
[2010/12/10 12:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\GARMIN
[2009/11/10 09:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\GetRightToGo
[2011/12/05 17:11:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Image Zone Express
[2010/03/02 11:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\IMSIDesign
[2011/09/20 12:42:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\ImTOO
[2010/11/07 06:48:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\JAM Software
[2010/04/22 07:09:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Leadertech
[2009/09/28 14:28:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Memeo
[2009/11/12 11:23:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Motion Technologies
[2009/08/24 18:39:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Pamela
[2011/01/05 11:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\PureEdge
[2011/11/29 06:57:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\searchquband
[2011/11/29 06:57:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\searchqutoolbar
[2011/09/23 06:54:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\TeamViewer
[2011/11/14 11:56:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\TMP
[2011/05/20 09:36:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Ulead Systems
[2011/11/23 22:50:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Visan
[2011/11/29 18:01:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\webex
[2009/05/11 08:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Windows Desktop Search
[2009/05/12 19:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Windows Search
[2011/11/26 00:00:00 | 000,000,320 | —- | M] () – C:\WINDOWS\Tasks\Clone Backup.job
[2010/12/31 06:40:01 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\disketchShakeIcon.job
[2011/12/05 18:00:00 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\File Backup.job
[2011/11/26 22:37:01 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\photopadShakeIcon.job
[2011/12/05 17:45:00 | 000,000,334 | —- | M] () – C:\WINDOWS\Tasks\Update Tasks.job
[2011/12/06 08:32:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{D07FB967-02EC-4F68-A7FA-D05A55F7A08C}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 04:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 04:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\MGtools\temp\SPF\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 04:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 04:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2007/07/12 13:35:02 | 000,305,176 | R— | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 – C:\cmdcons\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 04:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NVATA.SYS >
[2006/10/18 14:31:38 | 000,105,472 | R— | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A – C:\cmdcons\nvata.sys

< MD5 for: NVATABUS.SYS >
[2006/10/18 13:31:38 | 000,105,472 | R— | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A – C:\cmdcons\NvAtaBus.sys

< MD5 for: SCECLI.DLL >
[2004/08/04 04:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< MD5 for: SYMMPI.SYS >
[2007/02/09 19:06:00 | 000,100,096 | R— | M] (LSI Logic) MD5=A42F863305943869BA00A613C8EE8C7E – C:\cmdcons\symmpi.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/04/04 06:04:49 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/04/04 06:04:48 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/04/04 06:04:48 | 000,937,984 | —- | M] () – C:\WINDOWS\System32\config\system.sav

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB28633$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
aswMBR results:

OTL logfile created on: 12/6/2011 8:27:52 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Derek\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 72.66% Memory free
4.84 Gb Paging File | 4.17 Gb Available in Paging File | 86.19% Paging File free
Paging file location(s): C:\pagefile.sys 2048 2048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 763.11 Gb Free Space | 81.92% Space Free | Partition Type: NTFS
Drive E: | 11.17 Gb Total Space | 10.27 Gb Free Space | 91.94% Space Free | Partition Type: FAT32
Drive X: | 931.51 Gb Total Space | 420.21 Gb Free Space | 45.11% Space Free | Partition Type: NTFS

Computer Name: DEREK | User Name: Derek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Derek\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lynx Studio Technology\Mixer.exe (Lynx Studio Technology, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()


========== Win32 Services (SafeList) ==========

SRV - (ZuneBusEnum) – File not found
SRV - (WSearch) – File not found
SRV - (ThreatFire) – File not found
SRV - (srv3844) – File not found
SRV - (sdCoreService) – File not found
SRV - (sdAuxService) – File not found
SRV - (Pml Driver HPZ12) – File not found
SRV - (MSCamSvc) – File not found
SRV - (JavaQuickStarterService) – File not found
SRV - (CCALib8) – File not found
SRV - (AsSysCtrlService) – File not found
SRV - (AppMgmt) – File not found
SRV - (ADVService) – File not found
SRV - (szserver) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) – C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirMailService) – C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (WMZuneComm) – c:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – c:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)


========== Driver Services (SafeList) ==========

DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avkmgr) – C:\WINDOWS\system32\drivers\avkmgr.sys (Avira GmbH)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (DrvAgent32) – C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (szkg5) – C:\WINDOWS\system32\drivers\szkg.sys (iS3 Inc.)
DRV - (is3srv) – C:\WINDOWS\system32\drivers\is3srv.sys (iS3 Inc.)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (szkgfs) – C:\WINDOWS\system32\drivers\szkgfs.sys (iS3, Inc.)
DRV - (mv91cons) – C:\WINDOWS\system32\DRIVERS\mv91cons.sys (Marvell Semiconductor Inc.)
DRV - (mv91xx) – C:\WINDOWS\system32\DRIVERS\mv91xx.sys (Marvell Semiconductor, Inc.)
DRV - (nusb3xhc) – C:\WINDOWS\system32\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV - (nusb3hub) – C:\WINDOWS\system32\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (MSHUSBVideo) – C:\WINDOWS\system32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (mv61xx) – C:\WINDOWS\system32\DRIVERS\mv61xx.sys (Marvell Semiconductor, Inc.)
DRV - (AlesisFirewire) – C:\WINDOWS\system32\drivers\AlesisFirewire.sys (Alesis)
DRV - (AlesisFirewireAudio) – C:\WINDOWS\system32\drivers\AlesisFirewireAudio.sys (Alesis)
DRV - (AlesisFirewireMidi) – C:\WINDOWS\system32\drivers\AlesisFirewireMidi.sys (Alesis)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (SUSTUCAU) – C:\WINDOWS\system32\drivers\sustucau.sys (Susteen, Inc.)
DRV - (SUSTUCAP) – C:\WINDOWS\system32\drivers\sustucap.sys (Susteen, Inc.)
DRV - (SUSTUCAM) – C:\WINDOWS\system32\drivers\sustucam.sys (Susteen, Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (DiceAudioStrm) – C:\WINDOWS\system32\drivers\DiceAudioStrm.sys (TC Tech Inc.)
DRV - (Dice1394) – C:\WINDOWS\system32\drivers\Dice1394.sys (TC Tech Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (Lynx) – C:\WINDOWS\SYSTEM32\DRIVERS\Lynx.SYS (Lynx Studio Technology, Inc.)
DRV - (banshee) – C:\WINDOWS\system32\drivers\banshee.sys (3Dfx Interactive, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: "free-downloads.net Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {ecdee021-0d17-467f-a1ff-c7a115230949}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..keyword.URL: "http://search.search-go.net/?sid=10101052100&s;="
FF - prefs.js..network.proxy.type: 0

FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..keyword.URL: "http://search.search-go.net/?sid=10101052100&s;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/05/11 05:15:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2009/12/26 05:18:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/02 10:35:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/02 10:35:40 | 000,000,000 | —D | M]

[2011/11/30 07:51:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Derek\Application Data\Mozilla\Extensions
[2011/12/06 06:25:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions
[2011/03/29 07:45:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/09/14 07:35:32 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/09/14 11:54:44 | 000,000,000 | —D | M] (NCH) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{c2db4fe6-8409-45ce-8010-189a7b5cce86}
[2011/12/02 12:41:21 | 000,000,000 | —D | M] (Microsoft Choice Guard) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\ChoiceGuard@Microsoft
[2010/01/20 12:16:28 | 000,000,939 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\searchplugins\conduit.xml
[2011/11/29 06:56:12 | 000,002,519 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\searchplugins\Search_Results.xml
[2011/12/02 10:35:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/23 07:26:01 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/12/02 10:35:38 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/29 18:01:26 | 000,302,904 | —- | M] (Cisco WebEx LLC) – C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
[2003/03/18 21:20:00 | 001,060,864 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\mfc71.dll
[2003/02/21 04:42:22 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\msvcr71.dll
[2011/11/29 18:01:23 | 000,176,952 | —- | M] (Cisco WebEx LLC) – C:\Program Files\mozilla firefox\plugins\npatgpc.dll
[2010/05/21 11:16:22 | 000,155,648 | —- | M] (IBM Corporation) – C:\Program Files\mozilla firefox\plugins\npmfv.dll
[2011/12/02 10:35:33 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2009/09/25 11:39:22 | 000,003,700 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fast.png
[2009/09/25 11:39:22 | 000,001,963 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fast.xml
[2011/11/29 06:56:12 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011/12/02 10:35:33 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PE_IE_Helper Class) - {0941C58F-E461-4E03-BD7D-44C27392ADE1} - C:\Program Files\IBM\Lotus Forms\Viewer\3.5\PEhelper.dll (IBM Corporation)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..\Toolbar\WebBrowser: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - No CLSID value found.
O3 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKU\.DEFAULT..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-18..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-21-299502267-1682526488-839522115-1004..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LynxONE TaskBar Icon.lnk = C:\Program Files\Lynx Studio Technology\Mixer.exe (Lynx Studio Technology, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O15 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..Trusted Domains: microsoft.com ([www.update] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1238886182500 (WUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} https://wimpro.cce.hp.com/ChatEntry/downloads/msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in…r_installer.exe (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://splicesoftware.webex.com/client/T27…ort/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B0D9737B-FE70-4AAF-8488-91E2AB77D517}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7CBB56E-AA01-4B35-8F5B-FD8CB4A59325}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSTEM32\Userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - (TPSvc.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Derek\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Derek\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/04 14:16:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{35b89d1f-ef10-11de-834f-00248c5e6886}\Shell\AutoRun\command - "" = F:\MI.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: srv3844 - File not found
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

File not found – C:\WINDOWS\System32\
[2011/12/06 06:09:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1206
[2011/12/05 20:13:32 | 000,000,000 | —D | C] – C:\VS2010-VPC
[2011/12/05 19:41:52 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/12/05 17:20:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Picasa 3
[2011/12/05 17:17:51 | 000,000,000 | —D | C] – C:\Program Files\Picasa3
[2011/12/05 12:52:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\My Documents\Flagstar Statements
[2011/12/05 08:17:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1205
[2011/12/02 12:41:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Tracing
[2011/12/02 12:39:59 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/12/02 12:37:52 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2011/12/02 12:37:34 | 000,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2011/12/02 12:37:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live
[2011/12/02 12:37:08 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/12/02 12:33:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/12/02 06:40:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1202
[2011/12/01 08:41:25 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2011/12/01 08:41:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\STOPzilla
[2011/12/01 08:41:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2011/12/01 07:46:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/12/01 06:59:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1201
[2011/11/30 19:45:38 | 000,547,880 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/11/30 19:45:38 | 000,134,184 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/11/30 19:45:38 | 000,024,616 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/11/30 19:45:36 | 000,482,344 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/11/30 19:45:36 | 000,457,768 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/11/30 19:45:36 | 000,392,232 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/11/30 19:45:36 | 000,232,488 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/11/30 19:45:36 | 000,105,512 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/11/30 19:45:36 | 000,101,416 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/11/30 19:45:36 | 000,068,648 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/11/30 19:45:36 | 000,030,248 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/11/30 19:45:34 | 000,740,392 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/11/30 07:14:40 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/11/30 07:14:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/11/29 18:34:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\New Folder
[2011/11/29 18:01:38 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Derek\My Documents\cache
[2011/11/29 18:01:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\webex
[2011/11/29 09:45:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\CONTACTS
[2011/11/29 06:57:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\Ilivid Player
[2011/11/29 06:57:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\searchquband
[2011/11/29 06:57:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\AppData
[2011/11/29 06:56:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\searchqutoolbar
[2011/11/29 06:56:12 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/11/29 06:56:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/11/29 06:55:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\PackageAware
[2011/11/24 11:07:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Digiarty
[2011/11/24 11:04:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Digiarty
[2011/11/24 11:04:49 | 000,000,000 | —D | C] – C:\Program Files\Digiarty
[2011/11/24 11:04:25 | 008,249,312 | —- | C] (Digiarty Software,Inc. ) – C:\Program Files\winx-mov-to-wmv.exe
[2011/11/23 22:36:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\NCH Software Suite
[2011/11/23 22:32:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\My Documents\HP Photosmart Projects
[2011/11/23 22:31:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\HP
[2011/11/23 22:25:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Visan
[2011/11/23 22:25:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Visan
[2011/11/23 22:24:31 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2011/11/23 22:24:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP Photo Creations
[2011/11/23 07:25:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/11/21 11:45:56 | 005,073,240 | —- | C] (Microsoft Corporation) – C:\Program Files\vcredist_x86.exe
[2011/11/21 08:38:35 | 000,000,000 | —D | C] – C:\CTCTOutlook
[2011/11/21 08:32:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Constant Contact
[2011/11/18 09:27:30 | 000,000,000 | —D | C] – C:\Program Files\Constant Contact
[2011/11/17 08:11:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Avira
[2011/11/17 08:09:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/11/17 08:09:16 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/11/17 08:09:10 | 000,134,344 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/11/17 08:09:10 | 000,074,640 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/11/17 08:09:10 | 000,036,000 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avkmgr.sys
[2011/11/15 07:33:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\SCANS for Derek
[2011/11/15 03:00:40 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/11/14 17:11:41 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/11/14 17:10:58 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/11/14 14:43:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Desktop\Allison's Music
[2011/11/14 12:07:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2011/11/14 12:06:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
[2011/11/14 12:05:09 | 000,600,680 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\easyupdatusapiu.dll
[2011/11/14 12:03:28 | 017,186,816 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcompiler.dll
[2011/11/14 12:03:28 | 002,387,560 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvid.dll
[2011/11/14 12:03:28 | 002,090,088 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvenc.dll
[2011/11/14 12:03:28 | 000,914,024 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvdispco32.dll
[2011/11/14 12:03:28 | 000,875,112 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvgenco32.dll
[2011/11/14 12:03:28 | 000,061,440 | —- | C] (Khronos Group) – C:\WINDOWS\System32\OpenCL.dll
[2011/11/14 12:02:46 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2011/11/14 12:01:51 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/11/14 12:00:23 | 001,691,480 | —- | C] (Creative) – C:\WINDOWS\System32\drivers\Ambfilt.sys
[2011/11/14 11:59:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Renesas Electronics
[2011/11/14 11:59:15 | 000,000,000 | —D | C] – C:\Program Files\Renesas Electronics
[2011/11/14 11:44:53 | 000,023,456 | —- | C] (Phoenix Technologies) – C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2011/11/14 11:44:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\eSupport.com
[2011/11/11 15:48:16 | 001,564,976 | —- | C] (Kaspersky Lab ZAO) – C:\Program Files\TDSSKiller.exe
[2011/11/11 13:22:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Desktop\Virus-Spyware
[2011/11/10 14:08:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\CONCEPTUAL ARTS
[2011/11/10 05:21:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/09 11:48:25 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/09 09:40:53 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2011/08/09 09:40:30 | 004,500,784 | —- | C] (Amazon.com ) – C:\Program Files\AmazonUnboxVideo.exe
[2011/01/29 17:24:59 | 038,147,376 | —- | C] (Apple Inc.) – C:\Program Files\QuickTimeInstaller.exe
[2011/01/28 07:47:42 | 004,770,043 | —- | C] (Canneverbe Limited ) – C:\Program Files\cdbxp_setup_4.3.8.2474.exe
[2010/05/18 12:59:40 | 002,942,176 | —- | C] (Siber Systems) – C:\Program Files\AiRoboForm.exe
[2010/03/02 11:14:39 | 169,720,592 | —- | C] (IMSIDesign ) – C:\Program Files\TurboCAD-Deluxe-16-2.exe
[2009/05/29 05:27:46 | 000,301,384 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\All Users\Application Data\dxwebsetup.exe
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found – C:\WINDOWS\System32\
[2011/12/06 08:32:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{D07FB967-02EC-4F68-A7FA-D05A55F7A08C}.job
[2011/12/06 07:50:00 | 000,000,476 | —- | M] () – C:\WINDOWS\tasks\HP Photo Creations Communicator.job
[2011/12/06 06:47:41 | 000,482,856 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/06 06:47:41 | 000,085,286 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/06 06:45:24 | 000,000,744 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/12/06 06:43:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/06 06:06:33 | 000,000,433 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Shared Folder.lnk
[2011/12/05 20:17:11 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/05 19:49:42 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/12/05 19:48:38 | 000,000,815 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/05 19:26:31 | 000,280,276 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/12/05 19:26:31 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/12/05 19:21:43 | 000,280,276 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/12/05 18:00:00 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\File Backup.job
[2011/12/05 17:45:00 | 000,000,334 | —- | M] () – C:\WINDOWS\tasks\Update Tasks.job
[2011/12/05 17:20:17 | 000,000,684 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/12/05 17:20:17 | 000,000,666 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2011/12/05 17:04:11 | 000,039,424 | —- | M] () – C:\Documents and Settings\Derek\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/05 12:51:51 | 000,394,108 | —- | M] () – C:\Documents and Settings\Derek\My Documents\StatementViewer.pdf
[2011/12/05 07:21:00 | 000,234,813 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Portland-20111203-00069.jpg
[2011/12/05 06:22:48 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/02 15:05:15 | 000,002,231 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Shortcut to VMRecorder.exe.lnk
[2011/12/01 07:44:02 | 000,000,071 | —- | M] () – C:\WINDOWS\Pex.INI
[2011/11/30 19:45:38 | 000,547,880 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/11/30 19:45:38 | 000,134,184 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/11/30 19:45:38 | 000,024,616 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/11/30 19:45:36 | 000,482,344 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/11/30 19:45:36 | 000,457,768 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/11/30 19:45:36 | 000,392,232 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/11/30 19:45:36 | 000,232,488 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/11/30 19:45:36 | 000,105,512 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/11/30 19:45:36 | 000,101,416 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/11/30 19:45:36 | 000,068,648 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/11/30 19:45:36 | 000,030,248 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/11/30 19:45:34 | 000,740,392 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/11/29 09:55:54 | 000,043,976 | —- | M] () – C:\Documents and Settings\All Users\Documents\US Silver.pk
[2011/11/29 09:55:53 | 002,809,162 | —- | M] () – C:\Documents and Settings\All Users\Documents\US Silver.WAV
[2011/11/26 22:37:01 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\photopadShakeIcon.job
[2011/11/26 00:00:00 | 000,000,320 | —- | M] () – C:\WINDOWS\tasks\Clone Backup.job
[2011/11/24 11:04:32 | 008,249,312 | —- | M] (Digiarty Software,Inc. ) – C:\Program Files\winx-mov-to-wmv.exe
[2011/11/23 22:30:54 | 000,019,497 | —- | M] () – C:\WINDOWS\hpqins13.dat
[2011/11/21 11:55:48 | 005,073,240 | —- | M] (Microsoft Corporation) – C:\Program Files\vcredist_x86.exe
[2011/11/17 08:07:43 | 000,028,520 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/11/17 08:07:42 | 000,036,000 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avkmgr.sys
[2011/11/17 08:07:41 | 000,134,344 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/11/17 08:07:40 | 000,074,640 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/11/15 03:39:09 | 000,275,760 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/14 13:29:22 | 000,000,014 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2011/11/14 12:25:23 | 000,000,298 | RHS- | M] () – C:\boot.ini
[2011/11/14 12:04:55 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/11/14 11:44:53 | 000,023,456 | —- | M] (Phoenix Technologies) – C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2011/11/14 11:36:19 | 000,177,751 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/11/14 11:31:54 | 000,210,085 | —- | M] () – C:\MGlogs.zip
[2011/11/11 15:48:16 | 001,564,976 | —- | M] (Kaspersky Lab ZAO) – C:\Program Files\TDSSKiller.exe
[2011/11/11 14:07:16 | 000,001,037 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/11/11 09:17:52 | 000,000,000 | —- | M] () – C:\WINDOWS\2771026874
[2011/11/10 22:44:02 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/06 06:45:17 | 000,000,744 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/12/05 17:20:17 | 000,000,684 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/12/05 17:20:17 | 000,000,666 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2011/12/05 12:51:51 | 000,394,108 | —- | C] () – C:\Documents and Settings\Derek\My Documents\StatementViewer.pdf
[2011/12/05 07:21:00 | 000,234,813 | —- | C] () – C:\Documents and Settings\Derek\Desktop\Portland-20111203-00069.jpg
[2011/12/02 10:35:42 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/29 09:55:53 | 002,809,162 | —- | C] () – C:\Documents and Settings\All Users\Documents\US Silver.WAV
[2011/11/29 09:55:53 | 000,043,976 | —- | C] () – C:\Documents and Settings\All Users\Documents\US Silver.pk
[2011/11/23 22:37:57 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\photopadShakeIcon.job
[2011/11/23 22:36:40 | 000,000,805 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\PhotoPad Image Editor.lnk
[2011/11/23 22:29:08 | 000,019,497 | —- | C] () – C:\WINDOWS\hpqins13.dat
[2011/11/23 22:24:51 | 000,000,476 | —- | C] () – C:\WINDOWS\tasks\HP Photo Creations Communicator.job
[2011/11/15 03:00:43 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/11/14 12:04:55 | 000,280,276 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/11/14 12:04:55 | 000,280,276 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/11/14 12:04:55 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/11/14 12:04:55 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/11/14 12:03:28 | 002,128,778 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/11/14 12:03:28 | 000,003,249 | —- | C] () – C:\WINDOWS\System32\nvinfo.pb
[2011/11/09 11:48:32 | 000,001,037 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/11/09 08:31:28 | 000,000,000 | —- | C] () – C:\WINDOWS\2771026874
[2011/09/06 11:00:03 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2011/09/03 08:17:59 | 000,080,416 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/09/03 08:08:27 | 000,207,400 | R— | C] () – C:\WINDOWS\GSetup.exe
[2011/09/03 08:08:27 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2011/09/02 17:52:48 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/08/09 09:41:01 | 001,894,912 | —- | C] () – C:\Program Files\Amazon Unbox Video.msi
[2011/08/09 09:41:01 | 000,006,129 | —- | C] () – C:\Program Files\0x0409.ini
[2011/05/20 11:27:40 | 000,000,071 | —- | C] () – C:\WINDOWS\Pex.INI
[2011/05/19 03:36:13 | 000,413,024 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/28 07:48:11 | 000,005,504 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/12/15 11:11:36 | 000,278,398 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/11/19 06:25:02 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/11/19 06:22:09 | 000,000,006 | —- | C] () – C:\Documents and Settings\Derek\Application Data\start
[2010/11/19 05:25:05 | 000,000,006 | —- | C] () – C:\Documents and Settings\Derek\Application Data\completescan
[2010/11/19 05:11:16 | 000,000,010 | —- | C] () – C:\Documents and Settings\Derek\Application Data\install
[2010/10/05 04:24:10 | 000,038,469 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (Windows).ADR
[2010/09/15 16:36:38 | 000,000,185 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/06/16 11:06:00 | 003,535,754 | —- | C] () – C:\Program Files\VoiceMergeRecorder.zip
[2010/04/22 07:09:11 | 000,000,088 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2010/04/09 04:53:39 | 000,122,880 | —- | C] () – C:\WINDOWS\UnGins.exe
[2009/11/10 06:51:59 | 000,057,236 | —- | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/09/28 13:53:31 | 000,020,992 | —- | C] () – C:\WINDOWS\jestertb.dll
[2009/08/21 09:46:45 | 000,000,014 | —- | C] () – C:\WINDOWS\System32\nvModes.dat
[2009/08/20 07:44:43 | 000,000,056 | —- | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/07/01 06:38:25 | 000,105,290 | —- | C] () – C:\WINDOWS\HPFins09.dat.temp
[2009/07/01 06:38:25 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat.temp
[2009/05/18 05:18:31 | 000,039,424 | —- | C] () – C:\Documents and Settings\Derek\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/27 06:15:23 | 000,013,000 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (DOS).CAL
[2009/04/26 07:28:30 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2009/04/17 12:15:45 | 000,038,472 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (DOS).ADR
[2009/04/10 09:03:17 | 013,190,496 | —- | C] () – C:\Program Files\winzip120.exe
[2009/04/07 11:44:45 | 000,389,344 | —- | C] () – C:\Program Files\Setup024m.exe
[2009/04/07 08:44:10 | 000,002,451 | —- | C] () – C:\Program Files\Alesis Firewire Control Panel.lnk
[2009/04/07 07:38:20 | 000,413,183 | —- | C] () – C:\Program Files\ASIO4ALL_2_9_English.exe
[2009/04/07 05:40:50 | 000,001,747 | —- | C] () – C:\Program Files\Start Download Manager.lnk
[2009/04/06 12:18:42 | 000,000,984 | —- | C] () – C:\Program Files\HP Solution Center.lnk
[2009/04/06 11:53:39 | 000,102,833 | —- | C] () – C:\WINDOWS\HPFins09.dat
[2009/04/06 11:53:39 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat
[2009/04/06 11:53:27 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2009/04/05 16:09:11 | 000,446,464 | —- | C] () – C:\WINDOWS\System32\DspfxCro.dll
[2009/04/05 16:09:11 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\DspfxDll.dll
[2009/04/05 16:09:11 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\DspfxCom.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS9.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS8.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS6.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS5.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS4.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS3.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS2.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS15.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS14.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS13.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS12.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS1.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxDw.dll
[2009/04/05 16:09:11 | 000,015,040 | —- | C] () – C:\WINDOWS\System32\Mxmidi16.dll
[2009/04/05 12:44:01 | 000,000,772 | —- | C] () – C:\Program Files\DriveImage XML.lnk
[2009/04/04 17:44:52 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/04/04 17:37:05 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\AvgLdx86.sys
[2009/04/04 14:59:29 | 000,000,000 | —- | C] () – C:\WINDOWS\msicpl.ini
[2009/04/04 14:50:18 | 000,131,072 | R— | C] () – C:\WINDOWS\System32\smdll.dll
[2009/04/04 14:50:14 | 000,258,048 | R— | C] () – C:\WINDOWS\System32\HookMAp.dll
[2009/04/04 14:50:14 | 000,032,768 | R— | C] () – C:\WINDOWS\System32\Auxiliary.dll
[2009/04/04 14:50:13 | 000,262,144 | R— | C] () – C:\WINDOWS\System32\HookShield.dll
[2009/04/04 14:38:48 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\AsIO.dll
[2009/04/04 14:22:50 | 000,036,537 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2009/04/04 14:22:23 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/04/04 14:22:17 | 000,035,944 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/04/04 14:22:17 | 000,010,296 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/04/04 14:17:50 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/04/04 14:14:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/04/04 06:07:10 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/04/04 06:06:07 | 000,275,760 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 20:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/02 19:16:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2004/08/04 04:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 04:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 04:00:00 | 000,482,856 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 04:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 04:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 04:00:00 | 000,085,286 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 04:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 04:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 04:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 04:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 04:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 04:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/01/30 08:37:50 | 000,000,092 | R— | C] () – C:\WINDOWS\System32\FTDIUN2K.INI
[2002/03/01 13:43:34 | 000,028,008 | —- | C] () – C:\WINDOWS\System32\SUSUSB.SYS
[2001/07/06 15:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2011/08/09 09:41:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Amazon
[2011/11/29 06:56:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/01/28 07:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/09/23 13:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/06/05 09:39:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2009/05/12 14:00:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2011/09/23 13:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/04/05 09:53:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2011/01/05 11:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PureEdge
[2009/12/26 05:19:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2011/12/06 08:15:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/12/06 06:43:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/20 09:32:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/11/23 22:25:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visan
[2010/01/22 07:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/17 14:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\ArcVP
[2011/01/28 07:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Canneverbe Limited
[2009/10/26 05:50:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\CoffeeCup Software
[2009/05/19 09:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\CoreFTP
[2011/09/24 07:14:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\DD83E66D5FAF4DC27D3466A7C9D66E4F
[2011/11/24 12:04:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Digiarty
[2011/09/13 12:22:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Dropbox
[2009/12/08 07:07:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\FileZilla
[2010/12/10 12:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\GARMIN
[2009/11/10 09:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\GetRightToGo
[2011/12/05 17:11:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Image Zone Express
[2010/03/02 11:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\IMSIDesign
[2011/09/20 12:42:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\ImTOO
[2010/11/07 06:48:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\JAM Software
[2010/04/22 07:09:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Leadertech
[2009/09/28 14:28:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Memeo
[2009/11/12 11:23:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Motion Technologies
[2009/08/24 18:39:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Pamela
[2011/01/05 11:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\PureEdge
[2011/11/29 06:57:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\searchquband
[2011/11/29 06:57:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\searchqutoolbar
[2011/09/23 06:54:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\TeamViewer
[2011/11/14 11:56:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\TMP
[2011/05/20 09:36:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Ulead Systems
[2011/11/23 22:50:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Visan
[2011/11/29 18:01:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\webex
[2009/05/11 08:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Windows Desktop Search
[2009/05/12 19:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Windows Search
[2011/11/26 00:00:00 | 000,000,320 | —- | M] () – C:\WINDOWS\Tasks\Clone Backup.job
[2010/12/31 06:40:01 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\disketchShakeIcon.job
[2011/12/05 18:00:00 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\File Backup.job
[2011/11/26 22:37:01 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\photopadShakeIcon.job
[2011/12/05 17:45:00 | 000,000,334 | —- | M] () – C:\WINDOWS\Tasks\Update Tasks.job
[2011/12/06 08:32:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{D07FB967-02EC-4F68-A7FA-D05A55F7A08C}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 04:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 04:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\MGtools\temp\SPF\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 04:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 04:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2007/07/12 13:35:02 | 000,305,176 | R— | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 – C:\cmdcons\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 04:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NVATA.SYS >
[2006/10/18 14:31:38 | 000,105,472 | R— | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A – C:\cmdcons\nvata.sys

< MD5 for: NVATABUS.SYS >
[2006/10/18 13:31:38 | 000,105,472 | R— | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A – C:\cmdcons\NvAtaBus.sys

< MD5 for: SCECLI.DLL >
[2004/08/04 04:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< MD5 for: SYMMPI.SYS >
[2007/02/09 19:06:00 | 000,100,096 | R— | M] (LSI Logic) MD5=A42F863305943869BA00A613C8EE8C7E – C:\cmdcons\symmpi.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/04/04 06:04:49 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/04/04 06:04:48 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/04/04 06:04:48 | 000,937,984 | —- | M] () – C:\WINDOWS\System32\config\system.sav

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB28633$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
Hello dshetterly,

Thanks for the OTL log :thumbup: but I need the Extras.Txt too.
When the scan completed, it opened two notepad windows. OTL.Txt and Extras.Txt.
Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.

You posted the OTL log instead of the aswMBR results: You can find the aswMBR log on your desktop. :)
these are the ansMBR results: aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-06 08:50:33 —————————– 08:50:33.171 OS Version: Windows 5.1.2600 Service Pack 3 08:50:33.171 Number of processors: 8 586 0x1A04 08:50:33.171 ComputerName: DEREK UserName: Derek 08:50:39.375 Initialize success 08:51:05.328 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-1a 08:51:05.328 Disk 0 Vendor: WDC_WD1001FALS-00J7B1 05.00K05 Size: 953869MB BusType: 3 08:51:07.343 Disk 0 MBR read successfully 08:51:07.343 Disk 0 MBR scan 08:51:07.343 Disk 0 Windows XP default MBR code 08:51:07.343 Disk 0 scanning sectors +1953504000 08:51:07.421 Disk 0 scanning C:\WINDOWS\system32\drivers 08:51:12.828 Service scanning 08:51:13.687 Modules scanning 08:51:16.671 Disk 0 trace - called modules: 08:51:16.687 ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 08:51:16.687 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8af24030] 08:51:16.687 3 CLASSPNP.SYS[b8148fd7] -> nt!IofCallDriver -> [0x8af1f548] 08:51:16.687 5 PCTCore.sys[b7df6891] -> nt!IofCallDriver -> \Device\00000082[0x8aef4030] 08:51:16.687 7 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-1a[0x8add9d98] 08:51:16.687 Scan finished successfully 08:51:38.562 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Derek\Desktop\MBR.dat" 08:51:38.562 The log file has been saved successfully to "C:\Documents and Settings\Derek\Desktop\aswMBR.txt"
Hello dshetterly,

OTL only gives you the Extras.Txt on the first run, it will not produce another after that.

go to your C:\ drive. and find the OTL folder,open it up and you should find the Extras.Txt there. :thumbup:
Hello dshetterly,


**WARNING** Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

What you have onboard your computer is what seems to be the ZeroAccess Rootkit. To be completely honest it may be better to format and reinstall the operating system.

However…If you would like to continue with the cleaning your system please follow the instructions below and I will be more than happy to help.
================
Make sure SPYBOT TEATIMER is disabled

  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done and reboot your computer.
(When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.
================
NEXT

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
OK - well, your warning at the top has me quite concerned and I've sent a note to my IT guy to get involved with this. I can't disable the Spybot Teatimer, because I don't have Spybot S&D on my computer that I know of.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI