This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I fear Outlook has been compromised [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Something has obviously taken over my Outlook on my PC…everyone in my address book gets spam every few days or so sent without my consent…they are not found in my sent folder in Outlook or in my att email account online…we've never sent out a blanket email for someone to harvest the entire address book to spoof an email sent by me…so I'm thinking we have a virus or malware…
I'll post the logs as required, but I can't run the programs as Administrator because even though I've never created a password for Administrator it wont allow me to…run as administrator without it…
Any help given is appreciated…
================================================================================
===
OTL logfile created on: 12/22/2011 10:28:19 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Paul & Mimi\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

1022.98 Mb Total Physical Memory | 595.47 Mb Available Physical Memory | 58.21% Memory free
1.66 Gb Paging File | 1.36 Gb Available in Paging File | 82.18% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 11.86 Gb Free Space | 15.93% Space Free | Partition Type: NTFS
Drive F: | 149.05 Gb Total Space | 65.27 Gb Free Space | 43.79% Space Free | Partition Type: NTFS

Computer Name: PMBONO | User Name: Paul & Mimi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Paul & Mimi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files\Lexmark 3600-4600 Series\lxdxmsdmon.exe ()
PRC - C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
PRC - C:\Program Files\NETGEAR\WG111v3\WG111v3.exe ()
PRC - C:\WINDOWS\SYSTEM32\lxdxcoms.exe ( )
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe ()
PRC - C:\WINDOWS\SYSTEM32\WFXSNT40.EXE (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxmsdmon.exe ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxcaps.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxscw.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxdrs.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxcnv4.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\app4r.monitor.core.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\app4r.monitor.common.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\app4r.devmons.mcmdevmon.dll ()
MOD - C:\Program Files\NETGEAR\WG111v3\WG111v3.exe ()
MOD - C:\Program Files\NETGEAR\WG111v3\WlanDll.dll ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\lxdxdrpp.dll ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\lxdxdatr.dll ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\lxdxcats.dll ()
MOD - C:\Program Files\NETGEAR\WG111v3\WG111v3.dll ()
MOD - C:\WINDOWS\SYSTEM32\msdmo.dll ()
MOD - C:\Program Files\NETGEAR\WG111v3\acAuth.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll ()
MOD - C:\Program Files\NETGEAR\WG111v3\CheckSessions.dll ()
MOD - C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe ()
MOD - C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoures.dll ()
MOD - C:\WINDOWS\SYSTEM32\Amhooker.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\WFXPNT40.DLL ()


========== Win32 Services (SafeList) ==========

SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (PMBDeviceInfoProvider) – C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (lxdx_device) – C:\WINDOWS\System32\lxdxcoms.exe ( )
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (CA_LIC_CLNT) – C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe (Computer Associates International Inc.)
SRV - (LogWatch) – C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe (Computer Associates)
SRV - (InCDsrv) – C:\Program Files\Ahead\InCD\incdsrv.exe (AHEAD Software)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (wfxsvc) – C:\WINDOWS\SYSTEM32\WFXSVC.EXE (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (MpKsl713ee2f9) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CE0727A2-B840-4329-B952-CF93CD1097ED}\MpKsl713ee2f9.sys (Microsoft Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys (Malwarebytes Corporation)
DRV - (RTL8187B) – C:\WINDOWS\SYSTEM32\DRIVERS\wg111v3.sys (Realtek Semiconductor Corporation )
DRV - (ssmdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ssmdrv.sys (Avira GmbH)
DRV - (WinDriver6) – C:\WINDOWS\SYSTEM32\DRIVERS\windrvr6.sys (Jungo)
DRV - (USBModem) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (DLPORTIO) – C:\WINDOWS\Dlportio.sys ()
DRV - (motccgpfl) – C:\WINDOWS\SYSTEM32\DRIVERS\motccgpfl.sys (Motorola)
DRV - (motccgp) – C:\WINDOWS\SYSTEM32\DRIVERS\motccgp.sys (Motorola)
DRV - (USB_RNDIS_XP) – C:\WINDOWS\SYSTEM32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (NwlnkIpx) – C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (MotDev) – C:\WINDOWS\SYSTEM32\DRIVERS\motodrv.sys (Motorola Inc)
DRV - (motmodem) – C:\WINDOWS\SYSTEM32\DRIVERS\motmodem.sys (Motorola)
DRV - (Amusbprt) – C:\WINDOWS\SYSTEM32\DRIVERS\Amusbprt.sys (A4Tech Co.,Ltd.)
DRV - (tmcomm) – C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys (Trend Micro Inc.)
DRV - (JL2005C) – C:\WINDOWS\SYSTEM32\DRIVERS\jl2005c.sys (Windows ® 2000 DDK provider)
DRV - (Amfilter) – C:\WINDOWS\SYSTEM32\DRIVERS\Amfilter.sys (A4Tech Co.,Ltd.)
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (AnyDVD) – C:\WINDOWS\SYSTEM32\DRIVERS\AnyDVD.sys (SlySoft, Inc.)
DRV - (symlcbrd) – C:\WINDOWS\SYSTEM32\DRIVERS\symlcbrd.sys (Symantec Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWCD2) – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWCD2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Afc) – C:\WINDOWS\SYSTEM32\DRIVERS\afc.sys (Arcsoft, Inc.)
DRV - (giveio) – C:\WINDOWS\SYSTEM32\giveio.sys ()
DRV - (gameenum) – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (LHidUsb) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidUsb.sys (Logitech, Inc.)
DRV - (LCcfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\LCcfltr.sys (Logitech, Inc.)
DRV - (InCDPass) – C:\WINDOWS\SYSTEM32\DRIVERS\incdpass.sys (Ahead Software)
DRV - (InCDfs) – C:\WINDOWS\System32\drivers\incdfs.sys (Ahead Software)
DRV - (P16X) Creative SB Live! Series (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\P16X.sys (Creative Technology Ltd.)
DRV - (Ser2pl) – C:\WINDOWS\SYSTEM32\DRIVERS\ser2pl.sys (Prolific Technology Inc.)
DRV - (NwlnkNb) – C:\WINDOWS\SYSTEM32\DRIVERS\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkspx.sys (Microsoft Corporation)
DRV - (b57w2k) – C:\WINDOWS\SYSTEM32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (sonypvs1) – C:\WINDOWS\SYSTEM32\DRIVERS\sonypvs1.sys (Sony Corporation)
DRV - (WmHidLo) – C:\WINDOWS\SYSTEM32\DRIVERS\WmHidLo.sys (Logitech Inc.)
DRV - (WmFilter) – C:\WINDOWS\SYSTEM32\DRIVERS\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – C:\WINDOWS\SYSTEM32\DRIVERS\WmBEnum.sys (Logitech Inc.)
DRV - (WmVirHid) – C:\WINDOWS\SYSTEM32\DRIVERS\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore) – C:\WINDOWS\SYSTEM32\DRIVERS\WmXlCore.sys (Logitech Inc.)
DRV - (WmAdiHid) – C:\WINDOWS\SYSTEM32\DRIVERS\WmAdiHid.sys (Logitech Inc.)
DRV - (WIBUKEY) – C:\WINDOWS\SYSTEM32\DRIVERS\Wibukey.sys (WIBU-SYSTEMS AG)
DRV - (sonyhcs) – C:\WINDOWS\SYSTEM32\DRIVERS\sonyhcs.sys (Sony Corporation)
DRV - (sonyhcb) – C:\WINDOWS\system32\DRIVERS\sonyhcb.sys (Sony Corporation)
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\PFMODNT.SYS (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsoft.com/search/lobby/search.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 06 16 73 15 0A BF CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://nternet.com/search.html
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://nternet.com/search.html"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll File not found
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/10 07:57:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/10 07:56:58 | 000,000,000 | —D | M]

[2009/05/26 11:33:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Paul & Mimi\Application Data\Mozilla\Extensions
[2011/12/19 02:33:34 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Paul & Mimi\Application Data\Mozilla\Firefox\Profiles\xz5r5tbu.default\extensions
[2011/12/19 02:33:34 | 000,000,000 | —D | M] (FoxyProxy Standard) – C:\Documents and Settings\Paul & Mimi\Application Data\Mozilla\Firefox\Profiles\xz5r5tbu.default\extensions\[removed]
[2010/07/15 07:48:10 | 000,000,000 | —D | M] (Keep Tube Downloader) – C:\Documents and Settings\Paul & Mimi\Application Data\Mozilla\Firefox\Profiles\xz5r5tbu.default\extensions\[removed]
[2011/11/10 07:57:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/22 07:09:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\PAUL & MIMI\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\XZ5R5TBU.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\PAUL & MIMI\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\XZ5R5TBU.DEFAULT\EXTENSIONS\[removed]
[2009/07/23 09:21:26 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/12/20 12:33:20 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/11/05 00:53:18 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 15:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 04:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 15:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/11/04 21:21:03 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/04 21:21:03 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2010/01/14 23:23:39 | 000,373,811 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 12905 more lines…
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems)
O4 - HKLM..\Run: [lxdxamon] C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe ()
O4 - HKLM..\Run: [lxdxmon.exe] C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [WheelMouse] C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe ()
O4 - HKLM..\Run: [WinFaxAppPortStarter] C:\WINDOWS\System32\WFXSNT40.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [EPSON Stylus Photo R280 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICKA.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe ()
O4 - Startup: C:\Documents and Settings\Paul & Mimi\Start Menu\Programs\Startup\Jobulator.lnk = File not found
O4 - Startup: C:\Documents and Settings\Paul & Mimi\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk.disabled ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe File not found
O9 - Extra 'Tools' menuitem : FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 84696577773877.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: southwest.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: vistaprint.com ([www] http in Trusted sites)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/oas/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://download.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1190415989671 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1190437991359 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab (ZoneIntro Class)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} https://www-secure.symantec.com/techsupp/asa/SymAData.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab (Reg Error: Key error.)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx (Persits Software XUpload)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{29556B73-621F-4CE3-9ABA-32670EF1A6B3}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\Netscape Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Netscape Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {A213B520-C6C2-11d0-AF9D-008029E1027E} - C:\Program Files\WinFax\WFXSEH32.DLL (Symantec Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 13:36:02 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/10/09 11:15:18 | 000,000,766 | —- | M] () - C:\AUTORUN.ico – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (SsiEfr.e)
O34 - HKLM BootExecute: (OODBS)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ctmp3 - C:\WINDOWS\SYSTEM32\ctmp3.acm (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.JDCT - C:\WINDOWS\System32\jl_jdct.drv (JEILIN Tech.)
Drivers32: vidc.XVID - xvidvfw.dll File not found
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/22 09:45:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Paul & Mimi\Desktop\HiJackThis.exe
[2011/12/22 09:43:46 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Paul & Mimi\Desktop\OTL.exe
[2011/07/10 11:50:38 | 000,438,272 | —- | C] ( ) – C:\WINDOWS\System32\LXDXhcp.dll
[2011/05/31 11:38:24 | 001,105,920 | —- | C] ( ) – C:\WINDOWS\System32\lxdxserv.dll
[2011/05/31 11:38:24 | 000,843,776 | —- | C] ( ) – C:\WINDOWS\System32\lxdxusb1.dll
[2011/05/31 11:38:24 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdxprox.dll
[2011/05/31 11:38:23 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\lxdxpmui.dll
[2011/05/31 11:38:23 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdxinpa.dll
[2011/05/31 11:38:23 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdxiesc.dll
[2011/05/31 11:38:23 | 000,315,392 | —- | C] ( ) – C:\WINDOWS\System32\lxdxih.exe
[2011/05/31 11:38:22 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdxhbn3.dll
[2011/05/31 11:38:21 | 000,589,824 | —- | C] ( ) – C:\WINDOWS\System32\lxdxcoms.exe
[2011/05/31 11:38:21 | 000,376,832 | —- | C] ( ) – C:\WINDOWS\System32\lxdxcomm.dll
[2011/05/31 11:38:19 | 000,851,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdxcomc.dll
[2011/05/31 11:38:19 | 000,409,600 | R— | C] ( ) – C:\WINDOWS\System32\lxdxcoin.dll
[2011/05/31 11:38:17 | 000,360,448 | —- | C] ( ) – C:\WINDOWS\System32\lxdxcfg.exe
[2011/05/31 11:38:15 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\lxdxlmpm.dll
[2010/01/15 09:04:51 | 000,084,816 | —- | C] (Malwarebytes Corporation) – C:\Program Files\mbamext.dll
[2009/07/12 19:40:40 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/22 10:26:15 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/12/22 10:20:42 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/12/22 09:46:14 | 000,625,664 | —- | M] () – C:\Documents and Settings\Paul & Mimi\Desktop\dds.scr
[2011/12/22 09:45:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Paul & Mimi\Desktop\HiJackThis.exe
[2011/12/22 09:44:05 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Paul & Mimi\Desktop\OTL.exe
[2011/12/21 04:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2011/12/20 17:36:19 | 000,001,038 | —- | M] () – C:\Documents and Settings\Paul & Mimi\Desktop\magicJack.lnk
[2011/12/20 17:18:45 | 000,444,200 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/20 17:10:57 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/20 16:36:29 | 000,164,081 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/12/09 17:53:57 | 000,002,473 | —- | M] () – C:\Documents and Settings\Paul & Mimi\Desktop\Microsoft Word.lnk
[2011/12/08 13:54:46 | 000,002,419 | —- | M] () – C:\Documents and Settings\Paul & Mimi\Desktop\Microsoft Publisher.lnk
[2011/12/01 11:31:17 | 000,399,311 | —- | M] () – C:\Documents and Settings\Paul & Mimi\Desktop\partsElectricalStartersAlternators.pdf
[2011/12/01 11:26:18 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/23 07:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\win32k.sys
[2011/11/23 07:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\win32k.sys
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/22 09:46:08 | 000,625,664 | —- | C] () – C:\Documents and Settings\Paul & Mimi\Desktop\dds.scr
[2011/12/01 11:31:17 | 000,399,311 | —- | C] () – C:\Documents and Settings\Paul & Mimi\Desktop\partsElectricalStartersAlternators.pdf
[2011/07/10 11:50:41 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\lxdxrwrd.ini
[2011/07/10 11:50:39 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\LXDXinst.dll
[2011/05/31 11:38:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdxvs.dll
[2011/05/31 11:38:22 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdxgrd.dll
[2011/05/31 11:37:01 | 000,782,336 | —- | C] () – C:\WINDOWS\System32\lxdxdrs.dll
[2011/05/31 11:37:01 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\lxdxcaps.dll
[2011/05/31 11:37:01 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdxcnv4.dll
[2010/10/13 11:46:28 | 000,000,043 | —- | C] () – C:\WINDOWS\INSTALL.INI
[2009/11/06 11:01:27 | 000,110,085 | R— | C] () – C:\WINDOWS\System32\cdimage.exe
[2009/07/29 13:57:50 | 000,000,025 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2009/07/28 16:21:25 | 000,000,025 | —- | C] () – C:\Program Files\popcinfot.dat
[2009/06/27 10:07:19 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\uuddc32.dll
[2009/04/19 22:10:07 | 000,000,047 | —- | C] () – C:\WINDOWS\marscam.ini
[2009/01/06 14:42:36 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/11/25 15:56:22 | 000,012,499 | —- | C] () – C:\WINDOWS\System32\Seagate.bin
[2008/09/17 09:39:45 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/09/15 18:14:24 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/09/15 18:11:10 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/09/05 20:20:17 | 000,027,460 | —- | C] () – C:\WINDOWS\System32\loaddrv.exe
[2008/09/05 20:20:17 | 000,003,584 | —- | C] () – C:\WINDOWS\Dlportio.sys
[2008/03/15 20:07:19 | 000,000,026 | —- | C] () – C:\WINDOWS\dvdSanta.INI
[2008/03/15 16:43:28 | 000,022,782 | —- | C] () – C:\WINDOWS\System32\UninstXviDDec.exe
[2008/01/31 15:34:09 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2008/01/25 09:32:24 | 006,436,896 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2008/01/25 09:32:24 | 000,160,800 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox2.dat
[2007/12/05 16:39:06 | 000,000,071 | —- | C] () – C:\WINDOWS\EPSONCD.INI
[2007/12/05 16:21:31 | 000,073,220 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2007/12/05 16:21:31 | 000,001,137 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2007/12/05 16:21:31 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2007/12/05 16:21:30 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2007/12/05 16:21:30 | 000,029,114 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2007/12/05 16:21:30 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2007/12/05 16:21:30 | 000,021,021 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2007/12/05 16:21:30 | 000,015,670 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2007/12/05 16:21:30 | 000,013,280 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2007/12/05 16:21:30 | 000,010,673 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2007/12/05 16:21:30 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2007/12/05 16:21:30 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2007/12/05 16:21:30 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2007/12/05 16:21:30 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2007/12/05 16:21:30 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2007/12/05 16:21:30 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2007/12/05 01:41:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/12/05 01:41:00 | 001,626,112 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2007/12/05 01:41:00 | 001,474,560 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/12/05 01:41:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2007/12/05 01:41:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/12/05 01:41:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/12/05 01:41:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2007/12/05 01:41:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2007/12/05 01:41:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/11/28 11:02:10 | 000,000,305 | —- | C] () – C:\Documents and Settings\All Users\Application Data\addr_file.html
[2007/11/20 20:13:31 | 000,000,107 | —- | C] () – C:\WINDOWS\winzipme.ini
[2007/11/18 20:10:01 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007/11/17 16:18:55 | 000,000,044 | —- | C] () – C:\WINDOWS\EPSPR280.ini
[2007/10/04 17:56:36 | 000,044,491 | —- | C] () – C:\WINDOWS\System32\MiiIniFile13.ini
[2007/09/08 08:37:44 | 000,057,552 | —- | C] () – C:\WINDOWS\System32\WKDOS.EXE
[2007/09/08 08:36:09 | 000,077,895 | —- | C] () – C:\WINDOWS\System32\unibus_tcutil.dll
[2007/07/27 15:38:50 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\a1009isp.dll
[2007/07/26 15:13:45 | 000,000,988 | R— | C] () – C:\WINDOWS\cdPlayer.ini
[2007/05/17 10:04:43 | 000,000,000 | R— | C] () – C:\WINDOWS\oodcnt.INI
[2007/05/16 22:03:33 | 000,010,752 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2007/04/28 11:50:10 | 000,012,028 | —- | C] () – C:\Documents and Settings\All Users\Application Data\B4.gif
[2007/04/28 11:50:08 | 000,037,491 | —- | C] () – C:\Documents and Settings\All Users\Application Data\B3.gif
[2007/04/28 11:40:10 | 000,000,002 | —- | C] () – C:\WINDOWS\System32\TLS1.DLL
[2007/02/27 09:56:24 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\Amhooker.dll
[2007/01/11 13:39:07 | 000,000,000 | R— | C] () – C:\WINDOWS\WTNSETUP.INI
[2007/01/11 13:32:36 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\DCCWFP32.DLL
[2007/01/11 13:32:34 | 000,000,250 | —- | C] () – C:\WINDOWS\WINFAX.INI
[2007/01/11 13:32:31 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\IMPLODE.DLL
[2007/01/03 12:48:24 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\dec_jl6.dll
[2006/12/27 15:40:06 | 000,002,127 | R— | C] () – C:\WINDOWS\EReg515.dat
[2006/11/28 09:03:22 | 000,684,032 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2006/11/28 09:03:22 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2006/11/04 18:55:10 | 000,000,825 | R— | C] () – C:\WINDOWS\E-REGTLC.INI
[2006/11/04 18:53:18 | 000,000,136 | R— | C] () – C:\WINDOWS\TLCAPPS.INI
[2006/11/04 17:41:33 | 000,063,488 | R— | C] () – C:\WINDOWS\xobglu16.dll
[2006/11/04 17:41:33 | 000,023,552 | R— | C] () – C:\WINDOWS\xobglu32.dll
[2006/10/21 10:05:36 | 000,000,071 | —- | C] () – C:\WINDOWS\System32\xvid.ini
[2006/07/21 11:18:58 | 000,002,154 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2006/05/25 16:30:36 | 000,000,134 | —- | C] () – C:\Documents and Settings\Paul & Mimi\Local Settings\Application Data\fusioncache.dat
[2006/02/07 21:00:57 | 000,000,475 | R— | C] () – C:\WINDOWS\MP3trt.ini
[2006/02/07 20:52:10 | 000,278,528 | —- | C] () – C:\WINDOWS\System32\ammpp.dll
[2006/02/07 20:52:10 | 000,193,536 | —- | C] () – C:\WINDOWS\System32\atomid.exe
[2006/02/07 20:52:10 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\a1.dll
[2006/01/14 12:20:10 | 000,000,000 | R— | C] () – C:\WINDOWS\Pool.INI
[2006/01/11 18:15:11 | 000,046,345 | R— | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2005/12/20 23:05:28 | 000,000,040 | R— | C] () – C:\WINDOWS\RSoftInfo.dat
[2005/11/23 16:57:56 | 000,684,032 | R— | C] () – C:\WINDOWS\libeay32.dll
[2005/11/23 16:57:56 | 000,155,648 | R— | C] () – C:\WINDOWS\ssleay32.dll
[2005/10/15 11:57:32 | 000,005,542 | R— | C] () – C:\WINDOWS\mozver.dat
[2005/08/16 19:26:31 | 000,004,096 | R— | C] () – C:\WINDOWS\d3dx.dat
[2005/07/29 12:55:23 | 000,000,351 | R— | C] () – C:\WINDOWS\popcinfo.dat
[2005/07/28 19:42:37 | 000,000,004 | R— | C] () – C:\WINDOWS\RM_RESULT.DAT
[2005/05/03 15:54:20 | 000,006,550 | R— | C] () – C:\WINDOWS\jautoexp.dat
[2005/05/02 15:55:23 | 000,071,749 | R— | C] () – C:\WINDOWS\hcextoutput.dll
[2005/05/02 15:54:47 | 000,000,170 | R— | C] () – C:\WINDOWS\GetServer.ini
[2005/04/13 19:38:04 | 000,004,212 | —- | C] () – C:\WINDOWS\System32\zllictbl.dat
[2005/02/08 11:10:31 | 000,000,206 | R— | C] () – C:\WINDOWS\ITRACE32.INI
[2005/01/21 20:49:40 | 000,143,360 | R— | C] () – C:\WINDOWS\bbuninst.exe
[2004/12/10 10:43:03 | 000,000,067 | R— | C] () – C:\WINDOWS\COBX.BIN
[2004/11/24 12:38:56 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
[2004/10/01 16:33:46 | 000,000,680 | R— | C] () – C:\WINDOWS\TSC.ini
[2004/09/03 18:52:50 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\GCCollection.dll
[2004/08/02 13:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/07/22 17:46:24 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
[2004/07/22 17:34:21 | 000,000,334 | R— | C] () – C:\WINDOWS\SIERRA.INI
[2004/06/30 16:04:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\SDelete.dll
[2004/05/11 17:26:11 | 000,000,120 | R— | C] () – C:\WINDOWS\WINRESAZ.INI
[2004/03/07 14:51:00 | 000,024,924 | —- | C] () – C:\WINDOWS\System32\openports.dll
[2004/02/09 20:41:51 | 000,000,035 | R— | C] () – C:\WINDOWS\Ulead32.INI
[2004/02/09 20:35:27 | 000,285,216 | —- | C] () – C:\WINDOWS\System32\drivers\Onsio.sys
[2004/02/09 20:35:27 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\drivers\Onsreged.sys
[2004/01/28 11:20:48 | 000,000,000 | R— | C] () – C:\WINDOWS\SETUP32.INI
[2004/01/21 22:00:34 | 000,001,768 | R— | C] () – C:\WINDOWS\EntPack.dat
[2003/12/18 20:48:19 | 000,000,121 | R— | C] () – C:\WINDOWS\Winamp.ini
[2003/12/05 17:13:54 | 000,001,352 | R— | C] () – C:\WINDOWS\ka.ini
[2003/12/04 18:38:34 | 000,000,654 | R— | C] () – C:\WINDOWS\eReg.dat
[2003/12/01 17:15:50 | 000,031,232 | —- | C] () – C:\Documents and Settings\Paul & Mimi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/12/01 13:16:28 | 000,061,678 | —- | C] () – C:\Documents and Settings\Paul & Mimi\Application Data\PFP110JPR.{PB
[2003/12/01 13:16:28 | 000,012,358 | —- | C] () – C:\Documents and Settings\Paul & Mimi\Application Data\PFP110JCM.{PB
[2003/11/30 11:46:12 | 000,000,000 | R— | C] () – C:\WINDOWS\iPlayer.INI
[2003/11/28 21:35:23 | 000,000,984 | R— | C] () – C:\WINDOWS\ssconf2.bin
[2003/11/28 09:10:16 | 000,001,064 | R— | C] () – C:\WINDOWS\EReg206.dat
[2003/11/28 06:57:09 | 000,000,518 | R— | C] () – C:\WINDOWS\SCRABOUT.INI
[2003/11/28 06:54:50 | 000,001,032 | R— | C] () – C:\WINDOWS\entpack.ini
[2003/11/28 06:52:02 | 000,271,264 | R— | C] () – C:\WINDOWS\VBRUN100.DLL
[2003/11/28 06:52:02 | 000,019,200 | R— | C] () – C:\WINDOWS\WEPUTIL.DLL
[2003/11/27 08:05:27 | 000,004,636 | R— | C] () – C:\WINDOWS\Disney.ini
[2003/11/27 03:23:23 | 000,000,376 | R— | C] () – C:\WINDOWS\mozregistry.dat
[2003/11/27 03:01:50 | 000,000,376 | R— | C] () – C:\WINDOWS\ODBC.INI
[2003/11/27 02:15:11 | 000,000,275 | R— | C] () – C:\WINDOWS\netscape.INI
[2003/11/27 02:06:06 | 000,040,661 | R— | C] () – C:\WINDOWS\nsreg.dat
[2003/11/27 02:05:49 | 000,634,087 | R— | C] () – C:\WINDOWS\cd32.exe
[2003/11/27 00:45:11 | 000,002,408 | R— | C] () – C:\WINDOWS\unins000.dat
[2003/11/21 17:17:41 | 000,000,061 | R— | C] () – C:\WINDOWS\smscfg.ini
[2003/11/21 17:13:05 | 000,000,258 | —- | C] () – C:\WINDOWS\System32\BDEMERGE.INI
[2003/11/21 17:09:39 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2003/11/21 17:09:39 | 000,000,231 | R— | C] () – C:\WINDOWS\AC3API.INI
[2003/11/21 17:09:20 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2003/11/21 17:09:20 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2003/11/21 17:09:20 | 000,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2003/11/21 17:09:19 | 000,002,572 | R— | C] () – C:\WINDOWS\MIXDEF.INI
[2003/11/21 17:09:19 | 000,000,064 | R— | C] () – C:\WINDOWS\P16x.ini
[2003/11/21 17:08:45 | 000,000,245 | R— | C] () – C:\WINDOWS\SBWIN.INI
[2003/11/21 17:05:06 | 000,002,419 | R— | C] () – C:\WINDOWS\wininit.ini
[2003/11/21 17:00:17 | 000,000,791 | R— | C] () – C:\WINDOWS\orun32.ini
[2003/11/21 16:47:02 | 000,002,048 | R-S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2003/11/21 16:44:37 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/11/21 16:44:22 | 000,527,222 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2003/11/21 16:44:22 | 000,106,698 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2003/11/21 16:29:56 | 000,000,480 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/07/16 10:48:28 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2003/07/16 10:48:27 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2003/07/16 10:35:07 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2003/07/16 10:35:05 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2003/07/16 10:28:25 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2003/07/16 10:28:14 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2003/07/16 10:21:49 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2003/07/16 10:20:48 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/03/13 16:50:18 | 000,151,040 | —- | C] () – C:\WINDOWS\System32\wimadll.dll
[2002/11/01 15:17:50 | 000,000,256 | R— | C] () – C:\WINDOWS\aucfg.ini
[2002/09/03 13:42:36 | 000,444,200 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2002/09/03 13:35:18 | 000,004,161 | R— | C] () – C:\WINDOWS\ODBCINST.INI
[2002/09/03 13:31:48 | 000,023,348 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/08/29 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2002/07/04 14:05:34 | 000,000,269 | R— | C] () – C:\WINDOWS\tmupdate.ini
[2002/03/02 19:26:18 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\cypher.dll
[2001/12/14 12:34:46 | 000,164,864 | R— | C] () – C:\WINDOWS\patchw32.dll
[2001/08/29 19:57:40 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\addurl41.DLL
[2001/07/10 14:43:16 | 000,018,432 | —- | C] () – C:\WINDOWS\System32\winwatch.DLL
[2000/04/11 19:44:56 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[1999/07/23 12:46:48 | 000,000,116 | R— | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 09:53:20 | 000,129,536 | R— | C] () – C:\WINDOWS\AuHCcup1.dll
[1999/01/22 12:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 02:00:00 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\REGOBJ.DLL
[1997/11/17 16:13:16 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2006/07/06 21:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1.0.0.0
[2008/03/10 15:11:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2009/09/18 20:42:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ashtons. Family Resort
[2008/02/12 17:03:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2007/11/28 10:39:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg7(2)
[2011/06/26 10:10:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2011/04/19 16:37:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/06/28 16:26:05 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CellServia
[2011/11/25 10:10:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\cupcakecafe
[2008/12/20 11:22:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2009/10/31 20:45:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
[2009/07/28 15:51:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Far Mills
[2010/11/08 03:34:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Farm Fishes
[2009/07/28 16:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Farm Frenzy
[2009/11/07 11:02:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy3
[2010/01/08 18:04:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy3_America
[2010/08/24 20:33:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy3_Madagascar
[2010/05/30 20:33:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy3_Russia
[2010/10/10 14:38:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fenomen Games
[2009/06/01 08:28:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Freedom
[2010/05/14 15:52:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreshGames
[2009/12/02 20:57:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2009/07/27 21:47:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2010/09/14 03:38:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gamers Digital
[2009/10/04 17:17:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Go Go Gourmet
[2009/07/28 15:49:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoBit Games
[2009/08/08 12:11:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gogii
[2007/11/28 10:08:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/03/10 14:47:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HipSoft
[2010/05/30 20:12:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\incredible express
[2009/07/28 16:19:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin
[2010/09/26 17:13:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWinG
[2009/10/27 16:11:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin_generic
[2009/11/11 17:08:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2010/01/14 19:48:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kristanix Games
[2009/11/10 21:58:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ludia
[2011/04/07 14:37:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2009/09/27 10:13:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Merscom
[2009/12/25 18:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MightyPlay
[2008/03/04 15:16:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Mixesoft
[2009/11/19 21:19:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/11/27 09:29:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\N2Edit
[2008/03/10 10:24:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2008/03/10 15:29:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NannyMania
[2008/03/10 15:53:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NeptunesAdve
[2009/09/11 09:58:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Games
[2005/12/20 23:27:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Media
[2010/09/15 15:08:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/11/03 00:43:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PoBros
[2005/07/29 14:49:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2009/07/28 16:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2009/07/28 15:39:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickClick
[2008/01/31 15:41:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Radialpoint
[2009/12/30 10:13:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\rionix
[2005/04/15 21:17:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/10/13 14:12:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2003/11/27 03:04:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBT
[2004/01/30 18:15:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\shockwave.com
[2009/12/28 19:36:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SOS
[2009/02/28 15:08:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2009/09/03 15:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SugarGames
[2010/09/14 00:46:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SulusGames
[2011/11/25 11:17:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/08/01 17:27:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ThumbnailCache4R
[2009/08/02 09:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UClick
[2009/10/13 05:10:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Valusoft
[2008/01/25 11:21:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/04/20 08:35:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2008/03/10 16:31:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[2010/09/10 07:25:24 | 000,000,000 | -HSD | M] – C:\Documents and Settings\Paul & Mimi\Application Data\.#
[2009/07/28 18:38:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\3 Days Zoo Mystery
[2009/09/16 21:36:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Alawar
[2010/02/12 18:29:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Alien Skin
[2009/09/18 20:42:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Ashtons. Family Resort
[2008/02/12 17:03:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\AT&T;
[2009/12/02 18:03:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Awem
[2009/08/23 09:58:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\BeachPartyCraze
[2009/10/11 13:13:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Bloom
[2010/10/13 12:40:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Boolat Games
[2010/03/14 12:45:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Boomzap
[2009/11/19 21:33:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\casanova
[2010/01/15 23:07:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Cat's Eye Games
[2007/06/01 11:16:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Disney Interactive
[2007/07/12 18:49:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\EBookSys
[2010/01/14 18:53:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\ElementalsTheMagicKey
[2009/09/15 20:13:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Enchanted Katya
[2007/12/05 21:46:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Eyeblaster
[2010/05/14 15:52:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\freshgames
[2010/01/08 12:31:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Friday's games
[2009/10/18 12:07:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\funkitron
[2009/09/08 19:30:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Gaijin Ent
[2009/07/27 15:02:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\GameHouse
[2009/09/20 10:34:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\GameInvest
[2008/03/10 15:18:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Gamelab
[2010/09/14 03:38:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Gamers Digital
[2010/08/23 11:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\GamesCafe
[2009/09/24 20:01:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Go-Go Gourmet Chef of the Year
[2009/07/28 16:27:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\HSA
[2009/12/02 07:21:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\ImgBurn
[2009/07/28 16:19:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\iWin
[2010/09/26 17:13:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\iWinG
[2009/10/27 16:11:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\iWin_generic
[2009/08/23 13:08:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Jane s Hotel
[2009/09/16 21:22:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Jane s Hotel Family Hero
[2011/08/26 16:10:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Jobulator
[2003/11/29 16:54:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Leadertech
[2011/07/10 11:53:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Lexmark Productivity Studio
[2010/01/09 22:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Little Worlds Online
[2009/11/10 21:58:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Ludia
[2010/01/26 21:54:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Meridian93
[2009/09/27 10:13:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Merscom
[2009/12/25 18:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\MightyPlay
[2011/12/20 17:36:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\mjusbsp
[2004/06/04 21:12:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\MX
[2009/07/27 16:14:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\My Games
[2009/09/18 19:20:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\MysteryStudio
[2010/08/24 20:34:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Namco
[2006/10/23 21:47:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Netscape
[2009/09/11 09:58:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Oberon Games
[2005/07/03 18:42:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Opera
[2010/08/31 18:54:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\PeaceCraft2
[2009/07/28 16:13:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Pi Eye Games
[2010/09/15 15:08:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\PlayFirst
[2009/10/17 19:35:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Playrix Entertainment
[2009/11/03 00:43:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\PoBros
[2009/10/07 16:21:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Pogo Games
[2008/03/10 14:48:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Sandlot Games
[2009/07/28 07:09:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Shape games
[2004/01/30 18:11:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\shockwave.com
[2005/11/30 18:52:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\SlySoft
[2009/12/28 13:05:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Smith & Tinker, Inc
[2006/06/30 09:59:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Snapfish
[2008/03/10 16:17:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Super-Cow
[2009/12/29 13:14:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Tandem Games
[2010/01/28 18:58:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\TheFixerUpper
[2008/03/10 14:56:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Total Eclipse
[2009/08/02 09:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\UClick
[2009/10/13 05:10:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Valusoft
[2009/09/25 08:39:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\ViquaSoft
[2005/11/27 09:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Wildfire
[2009/09/16 17:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Wildgames_DressUpRush
[2009/09/16 21:34:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\Wildgames_JanesRealty
[2010/02/22 05:55:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\World-LooM
[2009/07/27 16:54:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul & Mimi\Application Data\YoudaGames
[2011/12/22 10:26:15 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/01/22 11:47:33 | 000,012,666 | —- | M] () – C:\15_1.jpe
[2005/10/15 11:12:21 | 000,000,017 | —- | M] () – C:\2g.bin
[2006/02/07 21:37:25 | 000,068,441 | —- | M] () – C:\2nddown.mp3
[2006/07/05 19:04:31 | 000,000,721 | —- | M] () – C:\addendumResponse.txt
[2005/04/15 21:49:05 | 000,004,838 | —- | M] () – C:\adp_inst.log
[2009/05/29 17:36:13 | 000,254,480 | —- | M] () – C:\amt1
[2002/09/03 13:36:02 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2001/10/09 11:15:18 | 000,000,766 | —- | M] () – C:\AUTORUN.ico
[2008/01/31 15:34:35 | 062,204,460 | —- | M] () – C:\BellSouthIW.re~
[2008/12/16 20:53:04 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2002/09/03 13:13:28 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2008/01/25 12:51:03 | 000,010,848 | —- | M] () – C:\ComboFix.txt
[2008/08/31 15:35:19 | 000,181,735 | —- | M] () – C:\config.dat
[2002/09/03 13:36:02 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/06/10 10:38:18 | 001,068,544 | —- | M] (Coupons.com Incorporated) – C:\couponprinter.exe
[2006/02/02 13:08:18 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2003/11/21 16:36:30 | 000,005,747 | RH– | M] () – C:\DELL.SDR
[2011/05/14 21:56:29 | 000,007,483 | —- | M] () – C:\devicetable.log
[2008/07/30 10:01:16 | 000,018,432 | —- | M] () – C:\dtemp.bn102
[2008/03/15 16:59:53 | 000,002,021 | —- | M] () – C:\dvdlog.txt
[2011/11/18 13:54:26 | 000,228,893 | —- | M] () – C:\formatter.log
[2006/02/07 21:36:41 | 000,048,901 | —- | M] () – C:\GeauxTigers.mp3
[2008/03/15 16:47:13 | 000,000,960 | —- | M] () – C:\graph.txt
[2002/09/03 13:36:02 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2007/03/09 22:49:23 | 000,000,000 | —- | M] () – C:\itouch_config_crash_info.txt
[2007/03/09 22:37:02 | 000,000,000 | —- | M] () – C:\itouch_crash_info.txt
[2011/05/27 22:33:05 | 000,225,060 | —- | M] () – C:\log.txt
[2002/09/03 13:36:02 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2007/09/22 11:03:49 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/28 23:00:08 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/22 10:19:48 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2006/10/21 16:34:55 | 000,001,292 | -H– | M] () – C:\PANDA.RPT
[2004/05/12 17:39:22 | 000,000,245 | —- | M] () – C:\password.klc
[2009/07/13 20:15:57 | 000,319,183 | —- | M] () – C:\rapport.txt
[2007/12/14 01:41:14 | 000,055,995 | —- | M] () – C:\rebuildingtogether.htm
[2007/09/23 08:30:35 | 000,000,620 | —- | M] () – C:\reset.cmd
[2005/11/25 12:54:05 | 000,057,856 | —- | M] () – C:\self-nom.doc
[2005/11/25 12:59:36 | 000,058,880 | —- | M] () – C:\self-nom.doc # 2.doc
[2005/11/05 16:48:13 | 000,001,066 | —- | M] () – C:\smitfiles.txt
[2007/09/30 11:28:08 | 000,000,000 | —- | M] () – C:\t15s.12a
[2007/09/30 11:34:13 | 000,000,000 | —- | M] () – C:\t15s.1pa
[2007/09/30 11:37:04 | 000,000,000 | —- | M] () – C:\t15s.1st
[2007/09/30 11:58:46 | 000,000,000 | —- | M] () – C:\t15s.386
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.am
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.ar
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.as
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.at
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.b0
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.bd
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.be
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.bm
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.bt
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.cc
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.cf
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.cl
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.cr
[2007/09/30 11:17:54 | 000,000,000 | —- | M] () – C:\t15s.cs
[2007/09/30 11:24:45 | 000,000,000 | —- | M] () – C:\t15s.ds
[2007/09/30 11:24:45 | 000,000,000 | —- | M] () – C:\t15s.dt
[2007/09/30 11:24:52 | 000,000,000 | —- | M] () – C:\t15s.el
[2007/09/30 11:24:52 | 000,000,000 | —- | M] () – C:\t15s.et
[2007/09/30 11:24:57 | 000,000,000 | —- | M] () – C:\t15s.gs
[2007/09/30 11:24:57 | 000,000,000 | —- | M] () – C:\t15s.hm
[2007/09/30 11:24:57 | 000,000,000 | —- | M] () – C:\t15s.hu
[2007/09/30 11:25:00 | 000,000,000 | —- | M] () – C:\t15s.ip
[2007/09/30 11:25:00 | 000,000,000 | —- | M] () – C:\t15s.j0
[2007/09/30 11:25:00 | 000,000,000 | —- | M] () – C:\t15s.ja
[2007/09/30 11:25:01 | 000,000,000 | —- | M] () – C:\t15s.ko
[2007/09/30 11:25:01 | 000,000,000 | —- | M] () – C:\t15s.l0
[2007/09/30 11:25:01 | 000,000,000 | —- | M] () – C:\t15s.lt
[2007/09/30 11:25:01 | 000,000,000 | —- | M] () – C:\t15s.lv
[2007/09/30 11:25:01 | 000,000,000 | —- | M] () – C:\t15s.mc
[2007/09/30 11:25:01 | 000,000,000 | —- | M] () – C:\t15s.me
[2007/09/30 11:25:01 | 000,000,000 | —- | M] () – C:\t15s.mp
[2007/09/30 11:25:01 | 000,000,000 | —- | M] () – C:\t15s.n0
[2007/09/30 11:25:01 | 000,000,000 | —- | M] () – C:\t15s.nv
[2007/09/30 11:25:01 | 000,000,000 | —- | M] () – C:\t15s.op
[2007/09/30 11:27:43 | 000,000,000 | —- | M] () – C:\t15s.ph
[2007/09/30 11:27:50 | 000,000,000 | —- | M] () – C:\t15s.pt
[2007/09/30 11:27:50 | 000,000,000 | —- | M] () – C:\t15s.pv
[2007/09/30 11:27:50 | 000,000,000 | —- | M] () – C:\t15s.q0
[2007/09/30 11:27:50 | 000,000,000 | —- | M] () – C:\t15s.r0
[2007/09/30 11:27:50 | 000,000,000 | —- | M] () – C:\t15s.rh
[2007/09/30 11:27:50 | 000,000,000 | —- | M] () – C:\t15s.ri
[2007/09/30 11:27:50 | 000,000,000 | —- | M] () – C:\t15s.ro
[2007/09/30 11:27:50 | 000,000,000 | —- | M] () – C:\t15s.ru
[2007/09/30 11:28:04 | 000,000,000 | —- | M] () – C:\t15s.sg
[2007/09/30 11:28:04 | 000,000,000 | —- | M] () – C:\t15s.sk
[2007/09/30 11:28:04 | 000,000,000 | —- | M] () – C:\t15s.sr
[2007/09/30 11:28:04 | 000,000,000 | —- | M] () – C:\t15s.tb
[2007/09/30 11:28:05 | 000,000,000 | —- | M] () – C:\t15s.th
[2007/09/30 11:28:05 | 000,000,000 | —- | M] () – C:\t15s.tr
[2007/09/30 11:28:05 | 000,000,000 | —- | M] () – C:\t15s.tv
[2007/09/30 11:28:08 | 000,000,000 | —- | M] () – C:\t15s.uk
[2007/09/30 11:28:08 | 000,000,000 | —- | M] () – C:\t15s.us
[2007/09/30 11:28:08 | 000,000,000 | —- | M] () – C:\t15s.vm
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.am
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.ar
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.as
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.at
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.b0
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.bd
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.be
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.bm
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.bt
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.cc
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.cf
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.cl
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.cr
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.cs
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.ds
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.dt
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.el
[2007/09/29 20:18:17 | 000,000,000 | —- | M] () – C:\t1b0.et
[2007/09/29 20:21:12 | 000,000,000 | —- | M] () – C:\t1b0.gs
[2007/09/29 20:21:12 | 000,000,000 | —- | M] () – C:\t1b0.hm
[2007/09/29 20:21:12 | 000,000,000 | —- | M] () – C:\t1b0.hu
[2007/09/29 20:21:12 | 000,000,000 | —- | M] () – C:\t1b0.ip
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.j0
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.ja
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.ko
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.l0
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.lt
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.lv
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.mc
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.me
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.mp
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.n0
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.nv
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.op
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.ph
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.pt
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.pv
[2007/09/29 20:21:15 | 000,000,000 | —- | M] () – C:\t1b0.q0
[2007/09/29 20:33:18 | 000,000,000 | —- | M] () – C:\t1rg.12a
[2007/09/29 20:47:07 | 000,000,000 | —- | M] () – C:\t1rg.1pa
[2007/09/29 20:47:17 | 000,000,000 | —- | M] () – C:\t1rg.1st
[2007/09/29 21:21:23 | 000,000,000 | —- | M] () – C:\t1rg.386
[2007/09/29 20:25:36 | 000,000,000 | —- | M] () – C:\t1rg.am
[2007/09/29 20:25:36 | 000,000,000 | —- | M] () – C:\t1rg.ar
[2007/09/29 20:25:36 | 000,000,000 | —- | M] () – C:\t1rg.as
[2007/09/29 20:25:36 | 000,000,000 | —- | M] () – C:\t1rg.at
[2007/09/29 20:25:36 | 000,000,000 | —- | M] () – C:\t1rg.b0
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.bd
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.be
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.bm
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.bt
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.cc
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.cf
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.cl
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.cr
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.cs
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.ds
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.dt
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.el
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.et
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.gs
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.hm
[2007/09/29 20:25:39 | 000,000,000 | —- | M] () – C:\t1rg.hu
[2007/09/29 20:29:09 | 000,000,000 | —- | M] () – C:\t1rg.ip
[2007/09/29 20:29:09 | 000,000,000 | —- | M] () – C:\t1rg.j0
[2007/09/29 20:29:09 | 000,000,000 | —- | M] () – C:\t1rg.ja
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.ko
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.l0
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.lt
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.lv
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.mc
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.me
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.mp
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.n0
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.nv
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.op
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.ph
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.pt
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.pv
[2007/09/29 20:29:20 | 000,000,000 | —- | M] () – C:\t1rg.q0
[2007/09/29 20:32:37 | 000,000,000 | —- | M] () – C:\t1rg.r0
[2007/09/29 20:32:41 | 000,000,000 | —- | M] () – C:\t1rg.rh
[2007/09/29 20:32:41 | 000,000,000 | —- | M] () – C:\t1rg.ri
[2007/09/29 20:32:41 | 000,000,000 | —- | M] () – C:\t1rg.ro
[2007/09/29 20:32:41 | 000,000,000 | —- | M] () – C:\t1rg.ru
[2007/09/29 20:33:17 | 000,000,000 | —- | M] () – C:\t1rg.sg
[2007/09/29 20:33:17 | 000,000,000 | —- | M] () – C:\t1rg.sk
[2007/09/29 20:33:17 | 000,000,000 | —- | M] () – C:\t1rg.sr
[2007/09/29 20:33:17 | 000,000,000 | —- | M] () – C:\t1rg.tb
[2007/09/29 20:33:17 | 000,000,000 | —- | M] () – C:\t1rg.th
[2007/09/29 20:33:18 | 000,000,000 | —- | M] () – C:\t1rg.tr
[2007/09/29 20:33:18 | 000,000,000 | —- | M] () – C:\t1rg.tv
[2007/09/29 20:33:18 | 000,000,000 | —- | M] () – C:\t1rg.uk
[2007/09/29 20:33:18 | 000,000,000 | —- | M] () – C:\t1rg.us
[2007/09/29 20:33:18 | 000,000,000 | —- | M] () – C:\t1rg.vm
[2007/10/03 15:51:05 | 000,000,000 | —- | M] () – C:\t2b0.12a
[2007/10/03 15:55:43 | 000,000,000 | —- | M] () – C:\t2b0.1pa
[2007/10/03 15:55:43 | 000,000,000 | —- | M] () – C:\t2b0.1st
[2007/10/03 16:19:59 | 000,000,000 | —- | M] () – C:\t2b0.386
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.am
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.ar
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.as
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.at
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.b0
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.bd
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.be
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.bm
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.bt
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.cc
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.cf
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.cl
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.cr
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.cs
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.ds
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.dt
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.el
[2007/10/03 15:43:55 | 000,000,000 | —- | M] () – C:\t2b0.et
[2007/10/03 15:47:09 | 000,000,000 | —- | M] () – C:\t2b0.gs
[2007/10/03 15:47:09 | 000,000,000 | —- | M] () – C:\t2b0.hm
[2007/10/03 15:47:09 | 000,000,000 | —- | M] () – C:\t2b0.hu
[2007/10/03 15:47:09 | 000,000,000 | —- | M] () – C:\t2b0.ip
[2007/10/03 15:47:09 | 000,000,000 | —- | M] () – C:\t2b0.j0
[2007/10/03 15:47:09 | 000,000,000 | —- | M] () – C:\t2b0.ja
[2007/10/03 15:47:14 | 000,000,000 | —- | M] () – C:\t2b0.ko
[2007/10/03 15:47:14 | 000,000,000 | —- | M] () – C:\t2b0.l0
[2007/10/03 15:47:14 | 000,000,000 | —- | M] () – C:\t2b0.lt
[2007/10/03 15:47:14 | 000,000,000 | —- | M] () – C:\t2b0.lv
[2007/10/03 15:47:15 | 000,000,000 | —- | M] () – C:\t2b0.mc
[2007/10/03 15:47:15 | 000,000,000 | —- | M] () – C:\t2b0.me
[2007/10/03 15:47:15 | 000,000,000 | —- | M] () – C:\t2b0.mp
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.n0
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.nv
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.op
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.ph
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.pt
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.pv
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.q0
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.r0
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.rh
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.ri
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.ro
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.ru
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.sg
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.sk
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.sr
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.tb
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.th
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.tr
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.tv
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.uk
[2007/10/03 15:47:19 | 000,000,000 | —- | M] () – C:\t2b0.us
[2007/10/03 15:51:05 | 000,000,000 | —- | M] () – C:\t2b0.vm
[2007/10/04 15:45:50 | 000,000,000 | —- | M] () – C:\t2sk.12a
[2007/10/04 15:54:15 | 000,000,000 | —- | M] () – C:\t2sk.1pa
[2007/10/04 15:54:15 | 000,000,000 | —- | M] () – C:\t2sk.1st
[2007/10/04 15:41:23 | 000,000,000 | —- | M] () – C:\t2sk.am
[2007/10/04 15:41:23 | 000,000,000 | —- | M] () – C:\t2sk.ar
[2007/10/04 15:41:23 | 000,000,000 | —- | M] () – C:\t2sk.as
[2007/10/04 15:41:23 | 000,000,000 | —- | M] () – C:\t2sk.at
[2007/10/04 15:41:23 | 000,000,000 | —- | M] () – C:\t2sk.b0
[2007/10/04 15:41:23 | 000,000,000 | —- | M] () – C:\t2sk.bd
[2007/10/04 15:41:23 | 000,000,000 | —- | M] () – C:\t2sk.be
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.bm
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.bt
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.cc
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.cf
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.cl
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.cr
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.cs
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.ds
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.dt
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.el
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.et
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.gs
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.hm
[2007/10/04 15:41:24 | 000,000,000 | —- | M] () – C:\t2sk.hu
[2007/10/04 15:45:41 | 000,000,000 | —- | M] () – C:\t2sk.ip
[2007/10/04 15:45:41 | 000,000,000 | —- | M] () – C:\t2sk.j0
[2007/10/04 15:45:41 | 000,000,000 | —- | M] () – C:\t2sk.ja
[2007/10/04 15:45:41 | 000,000,000 | —- | M] () – C:\t2sk.ko
[2007/10/04 15:45:41 | 000,000,000 | —- | M] () – C:\t2sk.l0
[2007/10/04 15:45:41 | 000,000,000 | —- | M] () – C:\t2sk.lt
[2007/10/04 15:45:41 | 000,000,000 | —- | M] () – C:\t2sk.lv
[2007/10/04 15:45:41 | 000,000,000 | —- | M] () – C:\t2sk.mc
[2007/10/04 15:45:41 | 000,000,000 | —- | M] () – C:\t2sk.me
[2007/10/04 15:45:45 | 000,000,000 | —- | M] () – C:\t2sk.mp
[2007/10/04 15:45:45 | 000,000,000 | —- | M] () – C:\t2sk.n0
[2007/10/04 15:45:45 | 000,000,000 | —- | M] () – C:\t2sk.nv
[2007/10/04 15:45:45 | 000,000,000 | —- | M] () – C:\t2sk.op
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.ph
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.pt
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.pv
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.q0
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.r0
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.rh
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.ri
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.ro
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.ru
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.sg
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.sk
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.sr
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.tb
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.th
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.tr
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.tv
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.uk
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.us
[2007/10/04 15:45:49 | 000,000,000 | —- | M] () – C:\t2sk.vm
[2008/08/23 19:32:55 | 000,000,032 | —- | M] () – C:\Temp.dat
[2008/08/23 19:32:43 | 000,002,411 | —- | M] () – C:\TempDat.dat
[2008/10/31 18:26:31 | 000,000,388 | —- | M] () – C:\TEMPEP.dat
[2009/08/15 17:42:54 | 000,003,300 | —- | M] () – C:\Tempkey.chk
[2007/10/02 04:08:13 | 000,000,000 | —- | M] () – C:\tgs.12a
[2007/10/02 04:12:25 | 000,000,000 | —- | M] () – C:\tgs.1pa
[2007/10/02 04:17:04 | 000,000,000 | —- | M] () – C:\tgs.1st
[2007/10/02 04:24:33 | 000,000,000 | —- | M] () – C:\tgs.386
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.am
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.ar
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.as
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.at
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.b0
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.bd
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.be
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.bm
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.bt
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.cc
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.cf
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.cl
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.cr
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.cs
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.ds
[2007/10/02 04:00:47 | 000,000,000 | —- | M] () – C:\tgs.dt
[2007/10/02 04:00:48 | 000,000,000 | —- | M] () – C:\tgs.el
[2007/10/02 04:00:48 | 000,000,000 | —- | M] () – C:\tgs.et
[2007/10/02 04:04:12 | 000,000,000 | —- | M] () – C:\tgs.gs
[2007/10/02 04:04:12 | 000,000,000 | —- | M] () – C:\tgs.hm
[2007/10/02 04:04:12 | 000,000,000 | —- | M] () – C:\tgs.hu
[2007/10/02 04:04:12 | 000,000,000 | —- | M] () – C:\tgs.ip
[2007/10/02 04:04:12 | 000,000,000 | —- | M] () – C:\tgs.j0
[2007/10/02 04:04:12 | 000,000,000 | —- | M] () – C:\tgs.ja
[2007/10/02 04:04:21 | 000,000,000 | —- | M] () – C:\tgs.ko
[2007/10/02 04:04:21 | 000,000,000 | —- | M] () – C:\tgs.l0
[2007/10/02 04:04:21 | 000,000,000 | —- | M] () – C:\tgs.lt
[2007/10/02 04:04:21 | 000,000,000 | —- | M] () – C:\tgs.lv
[2007/10/02 04:04:21 | 000,000,000 | —- | M] () – C:\tgs.mc
[2007/10/02 04:04:25 | 000,000,000 | —- | M] () – C:\tgs.me
[2007/10/02 04:04:25 | 000,000,000 | —- | M] () – C:\tgs.mp
[2007/10/02 04:04:25 | 000,000,000 | —- | M] () – C:\tgs.n0
[2007/10/02 04:04:25 | 000,000,000 | —- | M] () – C:\tgs.nv
[2007/10/02 04:04:25 | 000,000,000 | —- | M] () – C:\tgs.op
[2007/10/02 04:04:25 | 000,000,000 | —- | M] () – C:\tgs.ph
[2007/10/02 04:04:25 | 000,000,000 | —- | M] () – C:\tgs.pt
[2007/10/02 04:04:25 | 000,000,000 | —- | M] () – C:\tgs.pv
[2007/10/02 04:04:25 | 000,000,000 | —- | M] () – C:\tgs.q0
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.r0
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.rh
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.ri
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.ro
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.ru
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.sg
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.sk
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.sr
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.tb
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.th
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.tr
[2007/10/02 04:04:26 | 000,000,000 | —- | M] () – C:\tgs.tv
[2007/10/02 04:08:13 | 000,000,000 | —- | M] () – C:\tgs.uk
[2007/10/02 04:08:13 | 000,000,000 | —- | M] () – C:\tgs.us
[2007/10/02 04:08:13 | 000,000,000 | —- | M] () – C:\tgs.vm
[2006/02/18 12:09:34 | 000,007,168 | -HS- | M] () – C:\Thumbs.db
[2007/04/28 11:45:54 | 000,000,001 | —- | M] () – C:\TLS1234.txt
[2007/07/26 14:05:08 | 004,207,914 | —- | M] () – C:\track24.mp3

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2007/09/21 20:43:18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/08/14 20:49:20 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/10/16 08:12:44 | 000,147,968 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdxdrpp.dll
[2009/08/14 17:02:46 | 000,594,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2000/09/28 23:58:38 | 000,012,800 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\WFXPNT40.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2004/08/20 18:00:00 | 000,811,008 | R— | M] (Sprout Games, LLC) – C:\WINDOWS\FeedingFrenzy.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >
[2010/11/27 09:29:21 | 000,001,268 | —- | M] () – C:\Documents and Settings\All Users\Favorites\WildTangent Games.lnk

< %APPDATA%\Microsoft\*.* >
[2008/02/19 17:15:44 | 000,001,530 | -H– | M] () – C:\Documents and Settings\Paul & Mimi\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2008/02/12 17:03:24 | 000,053,934 | —- | M] () – C:\Program Files\INSTALL.LOG
[2010/01/07 16:07:06 | 000,084,816 | —- | M] (Malwarebytes Corporation) – C:\Program Files\mbamext.dll
[2009/07/28 16:21:25 | 000,000,025 | —- | M] () – C:\Program Files\popcinfot.dat
[2009/07/12 19:40:32 | 000,774,144 | —- | M] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2007/09/21 13:59:35 | 001,310,720 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2007/09/21 19:52:23 | 000,065,536 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2007/09/21 13:59:35 | 028,049,408 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2007/09/21 13:59:37 | 009,961,472 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/11/05 23:25:09 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/11/05 23:51:47 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Paul & Mimi\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2003/11/26 23:59:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\Paul & Mimi\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/01/23 08:28:03 | 000,157,696 | —- | M] (CrystalIDEA Software) – C:\Documents and Settings\Paul & Mimi\Desktop\anytoiso.exe
[2004/05/08 11:47:42 | 000,128,000 | —- | M] (DVDDuplication.ws) – C:\Documents and Settings\Paul & Mimi\Desktop\dvdduplication.exe
[2011/12/22 09:45:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Paul & Mimi\Desktop\HiJackThis.exe
[2011/12/22 09:44:05 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Paul & Mimi\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-20 23:16:47

========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:33384BC0
@Alternate Data Stream - 97 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C928F3BE
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A1CD17F9
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:91486201
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ECCE99EF
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:45F3AD49
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ED9B661E
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B5038B1
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3A6BC948
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F1F85068
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2F0007D6

< End of report >

================================================================================
======
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:44 AM, on 12/22/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe
C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files\Lexmark 3600-4600 Series\lxdxMsdMon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxdxcoms.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\Paul & Mimi\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://nternet.com/search.html
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Program Files\Netscape\Users\pmbono\prefs.js)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm; - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe
O4 - HKLM\..\Run: [lxdxmon.exe] "C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe"
O4 - HKLM\..\Run: [lxdxamon] "C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R280 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICKA.EXE /FU "C:\WINDOWS\TEMP\E_SAFC.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Paul & Mimi\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'Default user')
O4 - Startup: Jobulator.lnk = C:\Program Files\Jobulator\Jobulator.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk.disabled
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://www.vistaprint.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/oas/ActiveX/MSDcode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1190415989671
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1190437991359
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx
O20 - Winlogon Notify: !SASWinLogon - Invalid registry found
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxdx_device - - C:\WINDOWS\system32\lxdxcoms.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe

–
End of file - 8202 bytes
================================================================================
===================
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 10:45:28.40 on 12/22/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.551 [GMT -6:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe
C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files\Lexmark 3600-4600 Series\lxdxMsdMon.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxdxcoms.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\Paul & Mimi\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uCustomizeSearch = hxxp://nternet.com/search.html
BHO: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboForm.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &RoboForm;: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboForm.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {E6AE90A4-1B01-47F0-AA78-E6B122E145E9} - No File
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus Photo R280 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticka.exe /fu "c:\windows\temp\E_SAFC.tmp" /EF "HKCU"
uRun: [cdloader] "c:\documents and settings\paul & mimi\application data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [WinFaxAppPortStarter] wfxsnt40.exe
mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [WheelMouse] c:\program files\ge\97769 dual scroll optical mouse\Amoumain.exe
mRun: [lxdxmon.exe] "c:\program files\lexmark 3600-4600 series\lxdxmon.exe"
mRun: [lxdxamon] "c:\program files\lexmark 3600-4600 series\lxdxamon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
StartupFolder: c:\docume~1\paul&m;~1\startm~1\programs\startup\jobula~1.lnk - c:\program files\jobulator\Jobulator.exe
StartupFolder: c:\documents and settings\paul & mimi\start menu\programs\startup\Picture Motion Browser Media Check Tool.lnk.disabled
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v3\WG111v3.exe
uPolicies-explorer: NoThemesTab = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
uPolicies-system: NoColorChoice = 0 (0x0)
uPolicies-system: NoSizeChoice = 0 (0x0)
uPolicies-system: NoVisualStyleChoice = 0 (0x0)
uPolicies-system: NoDispSettingsPage = 0 (0x0)
mPolicies-explorer: =
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: 84696577773877.com
Trusted Zone: southwest.com\www
Trusted Zone: vistaprint.com\www
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/oas/ActiveX/MSDcode.cab
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://download.ewido.net/ewidoOnlineScan.cab
DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - hxxp://a1540.g.akamai.net/7/1540/52/20040427/qtinstall.info.apple.com/saba/us/win/QuickTimeInstaller.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1190415989671
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190437991359
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxps://www-secure.symantec.com/techsupp/asa/SymAData.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - hxxps://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} - hxxp://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: WinFax PRO IShellExecuteHook: {a213b520-c6c2-11d0-af9d-008029e1027e} - c:\program files\winfax\WfxSeh32.Dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\paul&m;~1\applic~1\mozilla\firefox\profiles\xz5r5tbu.default\
FF - prefs.js: browser.startup.homepage - hxxp://nternet.com/search.html
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
.
—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
.
============= SERVICES / DRIVERS ===============
.
R0 sonyhcb;Sony Digital Imaging Base;c:\windows\system32\drivers\sonyhcb.sys [2007-11-18 6097]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648]
R1 MpKsl713ee2f9;MpKsl713ee2f9;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ce0727a2-b840-4329-b952-cf93cd1097ed}\MpKsl713ee2f9.sys [2011-12-22 29904]
R2 DLPORTIO;DLPORTIO;c:\windows\Dlportio.sys [2008-9-5 3584]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2007-10-9 38144]
R2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe -service –> c:\windows\system32\lxdxcoms.exe -service [?]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-4 366152]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2010-6-1 367456]
R3 HSFHWCD2;HSFHWCD2;c:\windows\system32\drivers\HSFHWCD2.sys [2010-7-16 216064]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-1-15 22216]
S1 MpKsl14c718be;MpKsl14c718be;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3facc8f8-30ec-45b8-abec-2d54caedd877}\mpksl14c718be.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3facc8f8-30ec-45b8-abec-2d54caedd877}\MpKsl14c718be.sys [?]
S1 MpKsl2b00d034;MpKsl2b00d034;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bea5aee5-825b-4e0d-9a69-e01939ddc64d}\mpksl2b00d034.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bea5aee5-825b-4e0d-9a69-e01939ddc64d}\MpKsl2b00d034.sys [?]
S1 MpKsl8fad3e2f;MpKsl8fad3e2f;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{489730e3-4961-4d5d-940d-e9df72d80d20}\mpksl8fad3e2f.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{489730e3-4961-4d5d-940d-e9df72d80d20}\MpKsl8fad3e2f.sys [?]
S1 MpKsl9654e89c;MpKsl9654e89c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{56dbd8f3-f312-4165-a9d5-33d3df8ad876}\mpksl9654e89c.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{56dbd8f3-f312-4165-a9d5-33d3df8ad876}\MpKsl9654e89c.sys [?]
S1 MpKslb69db345;MpKslb69db345;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fa6d8362-4f18-4410-988b-06cbf5d699ee}\mpkslb69db345.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fa6d8362-4f18-4410-988b-06cbf5d699ee}\MpKslb69db345.sys [?]
S1 MpKslee2fc57a;MpKslee2fc57a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fdcad0b7-d374-4852-9d4c-b8bef060f27e}\mpkslee2fc57a.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fdcad0b7-d374-4852-9d4c-b8bef060f27e}\MpKslee2fc57a.sys [?]
S1 MpKslf5d08c0b;MpKslf5d08c0b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c89a1e05-f7ba-4dcc-a060-1964187955fa}\mpkslf5d08c0b.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c89a1e05-f7ba-4dcc-a060-1964187955fa}\MpKslf5d08c0b.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\superantispyware\sasdifsv.sys –> c:\program files\superantispyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\superantispyware\saskutil.sys –> c:\program files\superantispyware\SASKUTIL.sys [?]
S3 GamesAppService;GamesAppService;c:\program files\wildtangent games\app\GamesAppService.exe [2010-10-12 206072]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2009-7-14 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-7-14 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2009-7-14 42112]
S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [2009-7-31 341504]
S3 SASENUM;SASENUM;\??\c:\program files\superantispyware\sasenum.sys –> c:\program files\superantispyware\SASENUM.SYS [?]
S3 sonyhcs;Sony Digital Imaging Video;c:\windows\system32\drivers\sonyhcs.sys [2007-11-18 299923]
S3 WmAdiHid;Logitech WingMan Digital Devices Driver;c:\windows\system32\drivers\WmAdiHid.sys [2002-6-20 20320]
S4 CA_LIC_CLNT;CA License Client;c:\program files\ca\sharedcomponents\ca_lic\lic98rmt.exe [2004-8-31 143360]
S4 LogWatch;Event Log Watch;c:\program files\ca\sharedcomponents\ca_lic\LogWatNT.exe [2004-7-23 53248]
S4 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-7-5 1174664]
.
=============== File Associations ===============
.
inffile=
.
=============== Created Last 30 ================
.
2011-12-22 16:21:13 29904 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{ce0727a2-b840-4329-b952-cf93cd1097ed}\MpKsl713ee2f9.sys
2011-12-22 16:21:07 56200 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{ce0727a2-b840-4329-b952-cf93cd1097ed}\offreg.dll
2011-12-21 23:27:43 6823496 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{ce0727a2-b840-4329-b952-cf93cd1097ed}\mpengine.dll
.
==================== Find3M ====================
.
2011-12-01 17:26:18 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20:51 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:51 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:51 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23:59 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-25 12:15:46 1752683 —-a-w- c:\documents and settings\all users\SPL786.tmp
2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-03 10:06:03 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 07:37:52 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2010-01-07 22:07:06 84816 —-a-w- c:\program files\mbamext.dll
2009-07-13 01:40:32 774144 —-a-w- c:\program files\RngInterstitial.dll
.
============= FINISH: 10:46:11.35 ===============

Attachments:

  • [attachment removed: Attach.zip]
Hi,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

It looks like you're already logged in as administrator so you're OK.

===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
Hell NoodleTech, And Thanks for your help on this issue…Please accept my apologies for posting this help topic around the Christmas Holidays…I understand people get busy with shopping and Family so please don't feel the need to rush to get this done and I will completely understand if you cannot answer until after Christmas… I wish you a Merry Christmas to you and your loved ones…Thank you for your help…it is appreciated Pepperidge ================================================================================ =============== aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software Run date: 2011-12-23 09:23:39 —————————– 09:23:39.687 OS Version: Windows 5.1.2600 Service Pack 3 09:23:39.687 Number of processors: 1 586 0x209 09:23:39.687 ComputerName: PMBONO UserName: 09:23:40.828 Initialize success 09:24:16.875 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 09:24:16.875 Disk 0 Vendor: Maxtor_6Y080L0 YAR41BW0 Size: 76293MB BusType: 3 09:24:16.875 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c 09:24:16.875 Disk 1 Vendor: WDC_WD1600JB-00GVC0 08.02D08 Size: 152627MB BusType: 3 09:24:18.906 Disk 0 MBR read successfully 09:24:18.906 Disk 0 MBR scan 09:24:18.906 Disk 0 Windows XP default MBR code 09:24:18.906 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 39 MB offset 63 09:24:18.921 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76245 MB offset 80325 09:24:18.921 Disk 0 scanning sectors +156232125 09:24:19.015 Disk 0 scanning C:\WINDOWS\system32\drivers 09:24:43.406 Service scanning 09:24:44.687 Service MpKsl88d507a8 C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CE0727A2-B840-4329-B952-CF93CD1097ED}\MpKsl88d507a8.sys **LOCKED** 32 09:24:46.031 Modules scanning 09:25:02.546 Disk 0 trace - called modules: 09:25:02.578 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 09:25:02.578 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x877d0ab8] 09:25:02.578 3 CLASSPNP.SYS[f7741fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x8776eb00] 09:25:02.593 Scan finished successfully 09:25:32.281 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Paul & Mimi\Desktop\MBR.dat" 09:25:32.359 The log file has been saved successfully to "C:\Documents and Settings\Paul & Mimi\Desktop\aswMBR.txt"

Attachments:

Hi Pepperidge,

And Thanks for your help on this issue…Please accept my apologies for posting this help topic around the Christmas Holidays…I understand people get busy with shopping and Family so please don't feel the need to rush to get this done and I will completely understand if you cannot answer until after Christmas…
I wish you a Merry Christmas to you and your loved ones…Thank you for your help…it is appreciated

My pleasure and no worries :). I got the Christmas shopping done last week, so I'm just hanging around the house spending time with family and removing malware between it all :D. I wish you and yours a merry Christmas as well! Now let's try to get to the bottom of the spam issue.

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.


  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Glad to hear you are getting some family time this Christmas…
Here is the Combo fix log
Thanks again and Merry Christmas…

================================================================================
=
ComboFix 11-12-23.01 - Paul & Mimi 12/23/2011 18:38:52.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.484 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users\Application Data\L3.txt
c:\documents and settings\All Users\Application Data\L4.txt
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\SPL786.tmp
c:\windows\DOWNLO~1\EWIDoo~1.dll
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\SoftWareProtector
c:\windows\SoftWareProtector\TMMA.pr
c:\windows\SoftWareProtector\TMMApp22.pr
c:\windows\SoftWareProtector\TMMApp99.pr
c:\windows\system32\linkinfo(2).dll
c:\windows\system32\oobe\isperror
c:\windows\system32\oobe\isperror\ISPCNERR.HTM
c:\windows\system32\oobe\isperror\ISPDTONE.HTM
c:\windows\system32\oobe\isperror\ISPHDSHK.HTM
c:\windows\system32\oobe\isperror\ISPINS.HTM
c:\windows\system32\oobe\isperror\ISPNOANW.HTM
c:\windows\system32\oobe\isperror\ISPPBERR.HTM
c:\windows\system32\oobe\isperror\ISPPHBSY.HTM
c:\windows\system32\oobe\isperror\ISPSBUSY.HTM
c:\windows\system32\PowerToyReadme.htm
c:\windows\system32\tooldownloadreadme.htm
F:\install.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Legacy_USNJSVC
——-\Service_usnjsvc
.
.
((((((((((((((((((((((((( Files Created from 2011-11-24 to 2011-12-24 )))))))))))))))))))))))))))))))
.
.
2011-12-24 01:00 . 2011-12-24 01:00 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{794B45FB-4AEB-40E2-AAFE-2E827AADB3ED}\offreg.dll
2011-12-23 17:24 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{794B45FB-4AEB-40E2-AAFE-2E827AADB3ED}\mpengine.dll
2011-12-22 16:03 . 2011-12-22 16:03 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-12-22 16:01 . 2011-12-22 16:01 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-01 17:26 . 2011-08-16 07:36 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25 . 2003-07-16 16:45 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 10:47 . 2011-04-21 17:01 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-04 19:20 . 2006-06-23 17:33 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2003-07-16 16:26 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2003-07-16 16:24 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2007-09-22 17:12 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2003-07-16 16:34 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2003-07-16 16:20 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2003-07-16 16:33 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2002-08-29 01:04 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2003-07-16 16:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2007-09-22 02:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-03 10:06 . 2010-05-04 18:07 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 07:37 . 2008-01-30 15:24 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06 . 2003-03-20 22:18 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41 . 2008-07-30 01:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41 . 2003-07-16 16:34 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41 . 2003-07-16 16:34 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2010-01-07 22:07 . 2010-01-15 15:04 84816 —-a-w- c:\program files\mbamext.dll
2009-07-13 01:40 . 2009-07-13 01:40 774144 —-a-w- c:\program files\RngInterstitial.dll
2011-11-05 06:53 . 2011-11-10 13:57 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Paul & Mimi\Application Data\mjusbsp\cdloader2.exe" [2011-08-23 50592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2000-09-29 43008]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2010-06-01 600928]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"WheelMouse"="c:\program files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe" [2007-02-27 184320]
"lxdxmon.exe"="c:\program files\Lexmark 3600-4600 Series\lxdxmon.exe" [2010-02-04 672424]
"lxdxamon"="c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe" [2010-02-04 16040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-05-21 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2006-01-28 139322]
.
c:\documents and settings\Paul & Mimi\Start Menu\Programs\Startup\
Jobulator.lnk - c:\program files\Jobulator\Jobulator.exe [N/A]
Picture Motion Browser Media Check Tool.lnk.disabled [2007-11-18 1983]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2009-12-23 2330624]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= "c:\program files\WinFax\WfxSeh32.Dll" [1998-07-27 38400]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Harmony Remote.lnk]
backup=c:\windows\pss\Logitech Harmony Remote.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Paul & Mimi^Start Menu^Programs^Startup^DING!.lnk]
backup=c:\windows\pss\DING!.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Paul & Mimi^Start Menu^Programs^Startup^Resume Windows Update Installation.lnk]
path=c:\documents and settings\Paul & Mimi\Start Menu\Programs\Startup\Resume Windows Update Installation.lnk
backup=c:\windows\pss\Resume Windows Update Installation.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!ewido
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MBkLogOnHook
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MskAgentexe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MWLExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PopUpStopperProfessional
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSGuard spyware remover
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2003-08-13 16:27 28672 —-a-w- c:\windows\SYSTEM32\DSentry.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GDIPatch]
2006-01-04 20:17 362496 —-a-w- c:\progra~1\WMFPatch\inject.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2007-01-19 17:54 5674352 —-a-w- c:\program files\MSN Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 21:40 155648 —-a-w- c:\windows\SYSTEM32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2007-12-05 07:41 8523776 —-a-w- c:\windows\SYSTEM32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2007-12-05 07:41 1626112 —-a-w- c:\windows\SYSTEM32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2004-05-21 01:42 98304 —-a-w- c:\program files\QuickTime\qttask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
2006-01-28 22:04 139322 —-a-w- c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-02-22 10:25 144784 —-a-w- c:\program files\Java\jre1.6.0_05\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinFaxAppPortStarter]
2000-09-29 05:58 43008 —-a-w- c:\windows\SYSTEM32\WFXSNT40.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher]
2004-03-18 15:33 892928 —-a-w- c:\program files\Logitech\iTouch\iTouch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wfxsvc"=2 (0x2)
"WebrootSpySweeperService"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"O&O Defrag"=2 (0x2)
"NVSvc"=2 (0x2)
"NetSvc"=3 (0x3)
"McSysmon"=2 (0x2)
"McShield"=2 (0x2)
"LogWatch"=2 (0x2)
"LiveUpdate Notice Ex"=2 (0x2)
"LiveUpdate"=3 (0x3)
"InCDsrv"=3 (0x3)
"ewido anti-spyware 4.0 guard"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"CA_LIC_CLNT"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"Adobe LM Service"=3 (0x3)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" /background
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\FlashFXP\\flashfxp.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\SYSTEM32\\lxdxcoms.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxdxpswx.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxdxjswx.exe"=
"c:\\Program Files\\WinFax\\WFXCTL32.EXE"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\lxdxmon.exe"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\frun.exe"=
"c:\\Documents and Settings\\Paul & Mimi\\Application Data\\mjusbsp\\magicJack.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9281:TCP"= 9281:TCP:UPnP
.
R0 sonyhcb;Sony Digital Imaging Base;c:\windows\SYSTEM32\DRIVERS\sonyhcb.sys [11/18/2007 8:10 PM 6097]
R2 DLPORTIO;DLPORTIO;c:\windows\Dlportio.sys [09/05/2008 8:20 PM 3584]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\SYSTEM32\DRIVERS\EAPPkt.sys [10/09/2007 12:13 PM 38144]
R2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe -service –> c:\windows\system32\lxdxcoms.exe -service [?]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/04/2011 5:26 PM 366152]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [06/01/2010 3:01 AM 367456]
R3 HSFHWCD2;HSFHWCD2;c:\windows\SYSTEM32\DRIVERS\HSFHWCD2.sys [07/16/2010 4:57 PM 216064]
R3 MBAMProtector;MBAMProtector;c:\windows\SYSTEM32\DRIVERS\mbam.sys [01/15/2010 9:04 AM 22216]
R3 Pcouffin;Low level access layer for CD devices;c:\windows\SYSTEM32\DRIVERS\Pcouffin.sys [09/02/2006 2:51 AM 39488]
S1 MpKsl14c718be;MpKsl14c718be;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3FACC8F8-30EC-45B8-ABEC-2D54CAEDD877}\MpKsl14c718be.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3FACC8F8-30EC-45B8-ABEC-2D54CAEDD877}\MpKsl14c718be.sys [?]
S1 MpKsl2b00d034;MpKsl2b00d034;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BEA5AEE5-825B-4E0D-9A69-E01939DDC64D}\MpKsl2b00d034.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BEA5AEE5-825B-4E0D-9A69-E01939DDC64D}\MpKsl2b00d034.sys [?]
S1 MpKsl5cf9e698;MpKsl5cf9e698;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{794B45FB-4AEB-40E2-AAFE-2E827AADB3ED}\MpKsl5cf9e698.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{794B45FB-4AEB-40E2-AAFE-2E827AADB3ED}\MpKsl5cf9e698.sys [?]
S1 MpKsl713ee2f9;MpKsl713ee2f9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CE0727A2-B840-4329-B952-CF93CD1097ED}\MpKsl713ee2f9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CE0727A2-B840-4329-B952-CF93CD1097ED}\MpKsl713ee2f9.sys [?]
S1 MpKsl8fad3e2f;MpKsl8fad3e2f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{489730E3-4961-4D5D-940D-E9DF72D80D20}\MpKsl8fad3e2f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{489730E3-4961-4D5D-940D-E9DF72D80D20}\MpKsl8fad3e2f.sys [?]
S1 MpKsl9654e89c;MpKsl9654e89c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{56DBD8F3-F312-4165-A9D5-33D3DF8AD876}\MpKsl9654e89c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{56DBD8F3-F312-4165-A9D5-33D3DF8AD876}\MpKsl9654e89c.sys [?]
S1 MpKslb69db345;MpKslb69db345;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FA6D8362-4F18-4410-988B-06CBF5D699EE}\MpKslb69db345.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FA6D8362-4F18-4410-988B-06CBF5D699EE}\MpKslb69db345.sys [?]
S1 MpKsle6183f1c;MpKsle6183f1c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CE0727A2-B840-4329-B952-CF93CD1097ED}\MpKsle6183f1c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CE0727A2-B840-4329-B952-CF93CD1097ED}\MpKsle6183f1c.sys [?]
S1 MpKslee2fc57a;MpKslee2fc57a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FDCAD0B7-D374-4852-9D4C-B8BEF060F27E}\MpKslee2fc57a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FDCAD0B7-D374-4852-9D4C-B8BEF060F27E}\MpKslee2fc57a.sys [?]
S1 MpKslf5d08c0b;MpKslf5d08c0b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C89A1E05-F7BA-4DCC-A060-1964187955FA}\MpKslf5d08c0b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C89A1E05-F7BA-4DCC-A060-1964187955FA}\MpKslf5d08c0b.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS –> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys –> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [10/12/2010 11:59 AM 206072]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\SYSTEM32\DRIVERS\motccgp.sys [07/14/2009 6:16 PM 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\SYSTEM32\DRIVERS\motccgpfl.sys [07/14/2009 6:16 PM 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\SYSTEM32\DRIVERS\motodrv.sys [07/14/2009 6:16 PM 42112]
S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Vista Driver;c:\windows\SYSTEM32\DRIVERS\wg111v3.sys [07/31/2009 2:12 PM 341504]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS –> c:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
S3 sonyhcs;Sony Digital Imaging Video;c:\windows\SYSTEM32\DRIVERS\sonyhcs.sys [11/18/2007 8:10 PM 299923]
S3 WmAdiHid;Logitech WingMan Digital Devices Driver;c:\windows\SYSTEM32\DRIVERS\WmAdiHid.sys [06/20/2002 11:45 AM 20320]
S4 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [08/31/2004 2:21 PM 143360]
S4 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [07/23/2004 3:06 PM 53248]
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-24 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
.
.
——- Supplementary Scan ——-
.
uCustomizeSearch = hxxp://nternet.com/search.html
Trusted Zone: 84696577773877.com
Trusted Zone: southwest.com\www
Trusted Zone: vistaprint.com\www
TCP: DhcpNameServer = 192.168.1.254
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Paul & Mimi\Application Data\Mozilla\Firefox\Profiles\xz5r5tbu.default\
FF - prefs.js: browser.startup.homepage - hxxp://nternet.com/search.html
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{E6AE90A4-1B01-47F0-AA78-E6B122E145E9} - (no file)
Notify-!SASWinLogon - (no file)
MSConfigStartUp-ISW - c:\program files\AT&T\Internet Security Wizard\ISW.exe
MSConfigStartUp-OODefragTray - c:\windows\System32\oodtray.exe
MSConfigStartUp-XPRepairPro2007 - c:\program files\XP Repair Pro 2007\XPRepairPro.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-23 19:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-911889850-2695157550-976931430-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-911889850-2695157550-976931430-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A33CF07A-81A5-967F-3A22-E90BC116BA46}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"fagkbghjmeio"=hex:6f,62,6b,68,65,6e,70,6b,69,6a,70,67,62,70,69,68,6a,6a,6b,66,
6e,6a,69,68,63,70,63,70,65,6f,65,6c,6a,68,67,6e,6e,6e,62,6a,6e,66,61,64,65,\
.
[HKEY_USERS\S-1-5-21-911889850-2695157550-976931430-1006\ª*Ü]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"LastTimeUsed"=dword:42d8dc9d
DUMPHIVE0.003 (REGF)
.
[HKEY_LOCAL_MACHINE\software\Classes\.xaml\bootstrap]
@DACL=(02 0000)
@="bootstrap.xaml.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\.xbap\bootstrap]
@DACL=(02 0000)
@="bootstrap.xbap.1"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="20157F9C3C264CB3A09AACF3EE6218EC5F6A37825B6A5F9A5B452C462103EBA7769032368F3
64023BE001E17128390DE8746CA6A739F81204EE4C4E6EDC1C0EA78F94B830B82674758AA181453C8
30B20719FDEBD0CBF8068B6CD524DF9E1DFED462B9DBCBCE914F02FD94194495E241F93578AF9A937
06BD33C51BED22007ED905E5F3705A5FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFE
BC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667A6171C11EC38DE3D5D5
75E7D6A3B98089DB7CE019D40AA5C8437C20C2A6A0953701A8A533BC1A63FC513E085192130EB1E3F
B6FBAAE4E23332AEB43A77D6398B6DA4753D21C04969D4EC0DE3B380722E3ABA62673F37E3A43F23D
5614502E98EAA15BDDD74408A488F722A8938F57EF1BF327E608FB069310E0EDDFBC1056F7BE6CDDE
62CF9316FB321117F04C2DF0F987B571D4F074235C36CAD6898B1C343895132A7A40B0AAE9AA948B1
F8B75FECC1F3FF4B6A8495D6F029B9F8F3A28356ADE0F415C47B0993BA0310E1704BF6F324829957D
F41CF272EF22EB94D62F047F1E4F1D3FDBD1C8DCEAFC7C63B9A49C3BF8B337A305FB5337B168C024D
CD9C428E1C40960E7F5B30117F10712245E78385A010E287D9D04CEAFDB794EBD73B2576EC4A580C9
A2E79AE46EB2B4AC4D0340C819A48D74589C11824A46275EED19463C096564538208E4C835D860B3F
1552D57E8585A7829C91A796AA8C4195F5AF075AE12D449E34ADB6BEB252F0D759A1C4CBD5B9909AE
CB4897D2F743397EEB967A37459D68B679412A1E193EFCA092F11ECAB25819AC763E1381DDC3802A5
5BBDE876F90DB12721A943989B0C0648E52FCA9B9AB110D326455D65BE8A4E2B62AE86A5481C73128
2FEF111FA9075278A749541CA84DD87C64FE16C0D94D4BBEEA948C0D49C06F210F33D95655F122492
1992ADC6A9DC2E22F61E6B54398AF34D0137E83C3D050F7098C2F00E099AC91B0B66ED08F461C0DF5
025835D396FAEFEEC5B7F85376F9D9B3DC10427C08F3F30C9D4824BAFEDE31311DD88E404D3EDF9E4
50F005CA4340B66B6DD93DDBD19A7AC0045D112F2269B1CA0BD63BEB52F83F95DC381C541EF5F40E3
DFC1C1AC63F9D2C4522E414431AC35AEBFAB8CBCA572E18CF539FCA43DC221E1406E613BBD47FD04C
35CF5076559409FF931E8431FD3FA07AC35741ED1B22F5E0C0D8245B784770CD0D7634049A9C37AEC
93969D3C66ADB4CF5A1EEE884253C0B7E6E79A8238C65D156DC06E0A390B02FD455E1543FA25AFAD6
2F4CE5E963A209819DBFCF5FEBAAF1140C701F5B92525758C0BE71BF5D2C976D474E5F5EA55C96994
AC238C06E5E9A5C4365B82EDE58CFE84ECC5D0D2698441951CD2150D593D489DAC3AE6919E2B1D45D
157C72F64912C1DD654979C621886"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2944)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxdxcoms.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Lexmark 3600-4600 Series\lxdxMsdMon.exe
.
**************************************************************************
.
Completion time: 2011-12-23 19:14:17 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-24 01:14
ComboFix2.txt 2008-01-25 18:51
.
Pre-Run: 12,428,075,008 bytes free
Post-Run: 12,489,056,256 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 9F5271B72D6DC7A97B1FB7DD85BDF773
Hi pepperidge,

Did you change your search site to this?: nternet.com/search.html

And did you add these sites to your Internet Explorer trusted zone?:
84696577773877.com
southwest.com\www
vistaprint.com\www

I see that you have Malwarebytes Antimalware installed. Can you please open it, do an update, then run a quick scan and post the log?
yes to 84696577773877.com it was trusted at the time, but I no longer go there so if you'd like me to delete it I can… Southwest.com and Vistaprint .com is still being used… a few questions… now I'm not so sure about why the www is after those addresses you posted though..is that normal for the logs to move the www behind the address? or is that a sign of a spoof site? Will run malware bytes and post the log in a few minutes Thanks, Pepperidge
Hi pepperidge, I'll leave them alone and let you do with them as you please. I'm not sure why the www comes after the addresses either… However, they are not a sign of a spoof site, so don't worry.
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 911122309 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/23/2011 9:14:16 PM mbam-log-2011-12-23 (21-14-16).txt Scan type: Quick scan Objects scanned: 184010 Time elapsed: 11 minute(s), 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi pepperidge,

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 7 Update 2.
  • Click on jre-7u2-windows-i586.exe if you are running 32-bit Windows or jre-7u2-windows-x64.exe if you are running 64-bit Windows.
  • After the download completes, close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings

  • Click OK to leave the Java Control Panel.
===================================================

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer if required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader.
  • Make sure you uncheck Yes, install McAfee Security Scan Plus - optional if prompted.
Alternative Option: after uninstalling Adobe Reader, you could try downloading and installing SlimPDF Reader from >here<.
SlimPDF Reader comes with no bloatware and loads extremely quickly.
I updated Java per the steps you recommended… I removed Adobe(which always gave me a boot error anyway) and installed the Slim PDF tool instead Thanks for all the help… some quick questions: with all the logs posted what did you find? was it something serious? was it what was sending out the spam? or once my address book was harvested (or whatever happened) is that something that will continue to happen now that it was compromised? I'd really hate to give up my original email address…I've had it since 1995 but whatever you recommend to do… I'll follow…it is quite embarrassing for all my contacts to receive these even though it is only occasionally… Thanks again for all your help and a very Merry Christmas to you and yours… Pepp
Hi Pepperidge,

My pleasure :)! Merry Christmas to you and yours as well.

We're not quite done yet, but I'll answer your questions anyways. I didn't find much on the system, neither did the tools. ComboFix removed a small number of files and services. These may or may not have compromised your email/address book. If anything, your infection was not serious. From my experience, after the infection is removed and password to the email changed, your account should stop sending out spam. So I'd suggest changing your email account's password. No need to get rid of the email address completely.

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Merry Christmas once again…

The scan was still running at bedtime and was completed when the kids awoke us to open presents that Santa Clause left for them…


I viewed, exported and saved the log to my desktop as eset.txt and closed the eset window …This is where it gets a little disheartening… I went to the desktop only to find the log vanished…I ran a search of my PC for it and nothing turned up….

I can run the scan again if you'd like…but I can tell you it found one thing…Virtumonde

Please advise…

Thanks again and Mery Christmas :)
Hi pepperidge, Merry Christmas :) Yes, please run it again. I need to know the files it found that were infected with Virtumonde so we can ensure a complete clean. Best, NoodleTech

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI