OTL.txrt
OTL logfile created on: 31/01/2010 12:19:28 PM - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\Sharon\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1,023.00 Mb Total Physical Memory | 399.00 Mb Available Physical Memory | 39.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 4.53 Gb Free Space | 3.04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 18.55 Gb Total Space | 1.02 Gb Free Space | 5.51% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-19AD2330D9
Current User Name: Sharon
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/01/31 12:18:58 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sharon\Desktop\OTL.exe
PRC - [2010/01/06 17:19:36 | 000,307,672 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/01/05 07:56:02 | 002,002,160 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2009/12/08 23:53:01 | 000,827,392 | ---- | M] () -- C:\Documents and Settings\Sharon\Application Data\WhereSphere\wheresphere.exe
PRC - [2009/10/28 20:21:26 | 000,141,600 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/10/28 20:21:14 | 000,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/07/09 12:22:18 | 000,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/04/08 13:09:25 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/04/08 13:09:25 | 000,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/12/12 11:17:38 | 000,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/04/30 12:26:20 | 001,126,400 | ---- | M] (Last.fm) -- C:\Program Files\Last.fm\LastFM.exe
PRC - [2008/04/18 08:52:27 | 000,579,584 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgcc.exe
PRC - [2007/12/21 11:36:57 | 000,406,528 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgemc.exe
PRC - [2007/10/29 15:34:51 | 000,418,816 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgamsvr.exe
PRC - [2007/06/13 20:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/05/30 17:21:24 | 000,520,192 | ---- | M] () -- C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
PRC - [2007/01/30 12:02:00 | 000,303,104 | ---- | M] (FUJIFILM Corporation) -- C:\Program Files\FinePixViewer\QuickDCF2.exe
PRC - [2006/12/29 04:46:10 | 000,049,664 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgupsvc.exe
PRC - [2006/10/23 06:22:00 | 000,159,810 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2006/09/26 20:51:16 | 002,486,272 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 2.0\program\soffice.bin
PRC - [2006/09/26 20:51:14 | 002,334,720 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
PRC - [2006/03/14 12:06:01 | 001,397,760 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCD.exe
PRC - [2006/03/02 10:22:04 | 000,577,536 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe
PRC - [2005/07/09 10:24:46 | 000,871,424 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2005/05/31 14:29:16 | 000,577,597 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2005/05/31 14:23:08 | 000,258,103 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
PRC - [2004/11/03 14:24:46 | 000,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
PRC - [2004/03/01 13:00:00 | 000,098,304 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATI9EP.EXE
PRC - [2002/07/17 02:03:00 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
PRC - [2002/01/29 13:33:14 | 000,077,824 | ---- | M] () -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
========== Modules (SafeList) ========== MOD - [2010/01/31 12:18:58 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sharon\Desktop\OTL.exe
MOD - [2007/03/09 01:36:28 | 000,150,528 | ---- | M] () -- C:\WINDOWS\acaqoyejamiyum.dll
MOD - [2006/08/26 01:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - [2010/01/30 05:06:54 | 000,046,432 | ---- | M] () [Disabled | Stopped] -- C:\Documents and Settings\All Users\Application Data\Kwanzy\kwanzy141.exe -- (Kwanzy Service)
SRV - [2009/10/28 20:21:14 | 000,545,568 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/08/05 22:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2009/07/09 12:22:18 | 000,144,712 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009/04/08 13:09:25 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2008/12/12 11:17:38 | 000,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2007/12/21 11:36:57 | 000,406,528 | ---- | M] (GRISOFT, s.r.o.) [Auto | Running] -- C:\Program Files\Grisoft\AVG Free\avgemc.exe -- (AVGEMS)
SRV - [2007/10/29 15:34:51 | 000,418,816 | ---- | M] (GRISOFT, s.r.o.) [Auto | Running] -- C:\Program Files\Grisoft\AVG Free\avgamsvr.exe -- (Avg7Alrt)
SRV - [2007/01/01 16:47:34 | 000,072,704 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2006/12/29 04:46:10 | 000,049,664 | ---- | M] (GRISOFT, s.r.o.) [Auto | Running] -- C:\Program Files\Grisoft\AVG Free\avgupsvc.exe -- (Avg7UpdSvc)
SRV - [2006/10/23 06:22:00 | 000,159,810 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - [2005/07/09 10:24:46 | 000,871,424 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2005/05/31 14:23:08 | 000,258,103 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe -- (btwdins)
SRV - [2003/07/28 12:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2002/07/17 02:03:00 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe -- (EPSONStatusAgent2)
SRV - [2002/01/29 13:33:14 | 000,077,824 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)
========== Driver Services (SafeList) ========== DRV - [2010/01/07 16:07:14 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010/01/05 07:56:06 | 000,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Running] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010/01/05 07:56:04 | 000,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/01/05 07:56:02 | 000,074,480 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2009/08/28 19:42:52 | 000,040,448 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaapl.sys -- (USBAAPL)
DRV - [2009/08/05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009/05/18 14:17:00 | 000,026,600 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2008/04/16 14:51:56 | 000,022,784 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RimUsb.sys -- (RimUsb)
DRV - [2007/12/21 11:36:58 | 000,010,760 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgclean.sys -- (AvgClean)
DRV - [2007/11/13 20:25:53 | 000,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2007/10/29 15:34:35 | 000,821,856 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avg7core.sys -- (Avg7Core)
DRV - [2007/07/20 00:47:22 | 000,109,056 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\catchme.exe -- (catchme)
DRV - [2007/04/23 10:15:25 | 000,036,624 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)
DRV - [2007/02/24 09:22:15 | 000,027,776 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avg7rsxp.sys -- (Avg7RsXP)
DRV - [2006/12/29 04:46:19 | 000,004,960 | ---- | M] (GRISOFT, s.r.o.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\Drivers\avgtdi.sys -- (AvgTdi)
DRV - [2006/12/29 04:46:13 | 000,004,224 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avg7rsw.sys -- (Avg7RsW)
DRV - [2006/10/23 06:22:00 | 003,994,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006/06/19 17:37:34 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006/06/12 19:06:28 | 000,041,984 | ---- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\DGIVECP.SYS -- (DgiVecp)
DRV - [2006/03/21 08:45:52 | 003,960,000 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2006/03/14 12:06:01 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDrm.sys -- (incdrm)
DRV - [2006/02/27 07:46:20 | 000,081,408 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2005/07/09 10:17:54 | 000,099,584 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\system32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005/07/09 10:17:36 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2005/05/31 14:16:06 | 000,401,152 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2005/05/31 14:13:34 | 001,341,466 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2005/05/31 14:11:18 | 000,030,363 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2005/05/31 14:10:32 | 000,056,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2005/05/31 14:07:56 | 000,148,040 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2004/08/04 22:00:00 | 000,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
DRV - [2004/08/04 16:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/08/04 09:08:22 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2003/01/10 10:56:34 | 000,030,921 | ---- | M] (Service & Quality Technology.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SQCaptur.sys -- (DCamUSBSQTECH) Dual-Mode DSC(2770)
DRV - [2001/08/18 00:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default = 6B 28 B9 D0 18 8E E1 4F A2 ED C5 00 9A 2F ED 68 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:3.0.3
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {4E551550-1870-479D-BF66-DF77900E100E}:1.0
FF - prefs.js..extensions.enabledItems: {1E2687DB-3259-463F-8FC8-48BA4248ACC3}:1.9.1
FF - HKLM\software\mozilla\Firefox\extensions\\{1E2687DB-3259-463F-8FC8-48BA4248ACC3}: C:\Documents and Settings\Sharon\Local Settings\Application Data\{1E2687DB-3259-463F-8FC8-48BA4248ACC3} [2010/01/30 09:50:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/09 19:46:26 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/06 17:19:40 | 000,000,000 | ---D | M]
[2009/05/07 07:31:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sharon\Application Data\Mozilla\Extensions
[2009/03/08 10:13:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sharon\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/01/31 12:18:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sharon\Application Data\Mozilla\Firefox\Profiles\r5a8gia0.default\extensions
[2007/08/09 17:57:28 | 000,000,000 | ---D | M] (INpact Dark Orange) -- C:\Documents and Settings\Sharon\Application Data\Mozilla\Firefox\Profiles\r5a8gia0.default\extensions\{08749A2F-9877-4934-BB64-687558DBB8D0}
[2008/03/28 06:48:51 | 000,000,000 | ---D | M] (Blue Ice) -- C:\Documents and Settings\Sharon\Application Data\Mozilla\Firefox\Profiles\r5a8gia0.default\extensions\{a8dd47cf-239f-48c4-8379-e6b4cbafdcfa}
[2008/03/18 17:22:25 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Sharon\Application Data\Mozilla\Firefox\Profiles\r5a8gia0.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/01/30 21:37:55 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/01/23 10:13:49 | 000,000,000 | ---D | M] (Kwanzy) -- C:\Program Files\Mozilla Firefox\extensions\{4E551550-1870-479D-BF66-DF77900E100E}
[2009/12/08 23:53:30 | 000,212,480 | ---- | M] () -- C:\Program Files\Mozilla Firefox\components\wsff.dll
[2009/12/30 15:16:37 | 000,002,381 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\kwanzy133.xml
[2010/01/08 18:25:02 | 000,002,381 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\kwanzy135.xml
[2010/01/23 10:13:49 | 000,002,381 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\kwanzy139.xml
[2010/01/31 11:53:49 | 000,002,381 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\kwanzy141.xml
O1 HOSTS File: ([2007/09/20 00:15:03 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AVG7_CC] C:\Program Files\Grisoft\AVG Free\avgcc.exe (GRISOFT, s.r.o.)
O4 - HKLM..\Run: [EPSON Stylus CX6500 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EP.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Frofoyatu] C:\WINDOWS\acaqoyejamiyum.DLL ()
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [WhereSphere] C:\Documents and Settings\Sharon\Application Data\WhereSphere\wheresphere.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
O4 - Startup: C:\Documents and Settings\Sharon\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Sharon\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\Sharon\Start Menu\Programs\Startup\Registration .LNK = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C}
http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (Checkers Class)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B}
http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134}
http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Sharon\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Sharon\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/19 16:00:11 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{51767d24-3168-11dd-a18e-000c5519aea6}\Shell\AutoRun\command - "" = wd_windows_tools\setup.exe
O33 - MountPoints2\{5338564c-a0be-11de-a315-0017318d60cb}\Shell\AutoRun\command - "" = E:\WDSetup.exe -- File not found
O33 - MountPoints2\{ac2ae40c-6152-11dd-a1c9-000c5519aea6}\Shell\AutoRun\command - "" = dmbdkwoo.exe
O33 - MountPoints2\{ac2ae40c-6152-11dd-a1c9-000c5519aea6}\Shell\explore\Command - "" = dmbdkwoo.exe
O33 - MountPoints2\{ac2ae40c-6152-11dd-a1c9-000c5519aea6}\Shell\open\Command - "" = dmbdkwoo.exe
O33 - MountPoints2\{fdb382b7-31b9-11dd-a18f-0017318d60cb}\Shell\AutoRun\command - "" = llefgnuw.exe
O33 - MountPoints2\{fdb382b7-31b9-11dd-a18f-0017318d60cb}\Shell\explore\Command - "" = llefgnuw.exe
O33 - MountPoints2\{fdb382b7-31b9-11dd-a18f-0017318d60cb}\Shell\open\Command - "" = llefgnuw.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/01/31 12:18:58 | 000,548,864 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sharon\Desktop\OTL.exe
[2010/01/31 11:56:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sharon\Desktop\backups
[2010/01/30 18:32:15 | 000,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Sharon\Desktop\winlogon.scr
[2010/01/30 16:09:01 | 005,115,824 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Sharon\Desktop\mbam-setup.scr
[2010/01/30 15:56:39 | 000,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Sharon\Desktop\explorer.exe
[2010/01/30 13:48:29 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Sharon\Recent
[2010/01/30 13:14:07 | 001,128,296 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Sharon\Desktop\ccsetup228_slim.exe
[2010/01/30 09:50:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sharon\Local Settings\Application Data\{1E2687DB-3259-463F-8FC8-48BA4248ACC3}
[2010/01/30 09:45:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2010/01/30 09:43:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sharon\Application Data\AntiVirus Plus
[2010/01/19 17:22:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MpEngineStore
[2010/01/19 10:15:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sharon\Application Data\Malwarebytes
[2010/01/19 10:14:49 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/19 10:14:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/01/19 10:14:47 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/19 10:14:47 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/19 10:14:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/01/19 10:14:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sharon\Application Data\SUPERAntiSpyware.com
[2010/01/19 10:14:00 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/01/19 10:13:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010/01/19 10:11:57 | 010,038,728 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Sharon\Desktop\windows-kb890830-v3.3.exe
[2010/01/18 16:10:09 | 000,021,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml2a.dll
[2010/01/18 16:10:08 | 000,057,344 | ---- | C] (Samsung Electronics) -- C:\WINDOWS\System32\ssdevm.dll
[2010/01/18 16:10:08 | 000,049,152 | ---- | C] (Samsung Electronics) -- C:\WINDOWS\System32\ssusbpn.dll
[2010/01/18 16:10:08 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml4a.dll
[2010/01/18 16:09:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\Samsung
[2010/01/18 16:07:57 | 000,022,663 | ---- | C] (Samsung Electronics.) -- C:\WINDOWS\System32\SUGG1LMK.DLL
[2010/01/18 16:07:56 | 000,151,552 | ---- | C] (Samsung Electronics Co., Ltd.) -- C:\WINDOWS\System32\SUGG1CI.exe
[2010/01/18 16:07:56 | 000,057,344 | ---- | C] (SEC) -- C:\WINDOWS\System32\SUGG1CI.dll
[2010/01/18 16:07:41 | 000,704,512 | ---- | C] (Unified FB) -- C:\WINDOWS\System32\drivers\Samsung\Samsung CLP-300 Series\SUGG1UM.dll
[2010/01/18 16:07:41 | 000,224,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\Samsung\Samsung CLP-300 Series\SUGG1ui.dll
[2010/01/18 16:07:41 | 000,022,663 | ---- | C] (Samsung Electronics.) -- C:\WINDOWS\System32\drivers\Samsung\Samsung CLP-300 Series\SUGG1lmk.dll
[2010/01/18 16:07:40 | 000,837,028 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\Samsung\Samsung CLP-300 Series\SUGG1.dll
[2010/01/18 16:07:40 | 000,204,800 | ---- | C] (SEC) -- C:\WINDOWS\System32\drivers\Samsung\Samsung CLP-300 Series\SUGG1CM.dll
[2010/01/18 16:07:40 | 000,151,552 | ---- | C] (Samsung Electronics Co., Ltd.) -- C:\WINDOWS\System32\drivers\Samsung\Samsung CLP-300 Series\SUGG1CI.exe
[2010/01/18 16:07:40 | 000,057,344 | ---- | C] (SEC) -- C:\WINDOWS\System32\drivers\Samsung\Samsung CLP-300 Series\SUGG1CI.dll
[2010/01/18 16:07:40 | 000,041,984 | ---- | C] (Samsung Electronics Co., Ltd.) -- C:\WINDOWS\System32\drivers\DGIVECP.SYS
[2010/01/18 16:07:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Samsung\Samsung CLP-300 Series
[2010/01/18 16:07:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Samsung
[2010/01/18 16:07:35 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
[2009/08/28 03:02:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2007/12/29 14:24:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/10/18 08:57:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/03/04 16:04:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2006/12/29 09:27:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\AVG7
[2006/12/19 16:00:03 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/01/31 12:18:58 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sharon\Desktop\OTL.exe
[2010/01/31 12:02:12 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/01/31 12:02:10 | 000,012,718 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/01/31 12:00:10 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/01/31 12:00:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/01/31 11:58:50 | 012,582,912 | -H-- | M] () -- C:\Documents and Settings\Sharon\NTUSER.DAT
[2010/01/31 11:58:50 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Sharon\ntuser.ini
[2010/01/31 11:54:05 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\12316.exe
[2010/01/31 11:51:14 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Vravuwafonu.bin
[2010/01/31 11:51:13 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Gpavewizutero.dat
[2010/01/31 11:33:57 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\778.exe
[2010/01/31 11:13:50 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\27529.exe
[2010/01/31 10:53:43 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\9741.exe
[2010/01/31 10:33:41 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\8723.exe
[2010/01/31 10:13:33 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\12859.exe
[2010/01/31 09:53:26 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\20037.exe
[2010/01/31 09:33:19 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\32757.exe
[2010/01/31 09:13:12 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\32662.exe
[2010/01/31 08:53:05 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\27644.exe
[2010/01/31 08:32:58 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\25547.exe
[2010/01/31 08:12:50 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\6868.exe
[2010/01/31 07:52:43 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\28253.exe
[2010/01/31 07:32:36 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\7711.exe
[2010/01/31 07:12:28 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\15141.exe
[2010/01/31 06:52:21 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\4664.exe
[2010/01/31 06:32:14 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\17673.exe
[2010/01/31 06:12:06 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\30333.exe
[2010/01/31 05:51:59 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\31322.exe
[2010/01/31 05:31:52 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\23811.exe
[2010/01/31 05:11:45 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\28703.exe
[2010/01/31 04:51:37 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\9894.exe
[2010/01/31 04:31:30 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\17035.exe
[2010/01/31 04:11:23 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\26299.exe
[2010/01/31 03:51:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\25667.exe
[2010/01/31 03:31:08 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\19912.exe
[2010/01/31 03:11:01 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\1869.exe
[2010/01/31 02:50:53 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\11538.exe
[2010/01/31 02:30:46 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\14771.exe
[2010/01/31 02:10:39 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\21726.exe
[2010/01/31 01:50:31 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\5447.exe
[2010/01/31 01:30:24 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\19895.exe
[2010/01/31 01:10:17 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\19718.exe
[2010/01/31 00:50:09 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\18716.exe
[2010/01/31 00:30:02 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\17421.exe
[2010/01/31 00:10:00 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\12382.exe
[2010/01/30 23:49:53 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\292.exe
[2010/01/30 23:29:45 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\153.exe
[2010/01/30 23:09:38 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\3902.exe
[2010/01/30 22:49:36 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\14604.exe
[2010/01/30 22:29:28 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\32391.exe
[2010/01/30 22:09:21 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\5436.exe
[2010/01/30 21:49:14 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\4827.exe
[2010/01/30 21:29:06 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\11942.exe
[2010/01/30 21:08:59 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\2995.exe
[2010/01/30 20:48:57 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\491.exe
[2010/01/30 20:28:50 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\9961.exe
[2010/01/30 20:08:42 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\16827.exe
[2010/01/30 19:48:35 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\23281.exe
[2010/01/30 19:28:28 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\28145.exe
[2010/01/30 19:08:25 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\5705.exe
[2010/01/30 18:48:18 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\24464.exe
[2010/01/30 18:32:18 | 000,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Sharon\Desktop\winlogon.scr
[2010/01/30 18:28:10 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\26962.exe
[2010/01/30 18:08:03 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\29358.exe
[2010/01/30 17:48:01 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\11478.exe
[2010/01/30 17:27:53 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\15724.exe
[2010/01/30 17:07:46 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\19169.exe
[2010/01/30 16:47:44 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\26500.exe
[2010/01/30 16:27:36 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\6334.exe
[2010/01/30 16:09:23 | 005,115,824 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Sharon\Desktop\mbam-setup.scr
[2010/01/30 16:07:29 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\18467.exe
[2010/01/30 16:02:45 | 001,872,472 | ---- | M] () -- C:\Documents and Settings\Sharon\Desktop\SmitfraudFix.exe
[2010/01/30 15:56:40 | 000,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Sharon\Desktop\explorer.exe
[2010/01/30 15:47:27 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\41.exe
[2010/01/30 15:47:19 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\IS15.exe
[2010/01/30 15:47:09 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\helper32.dll
[2010/01/30 13:38:22 | 002,387,269 | ---- | M] () -- C:\MGtools.exe
[2010/01/30 13:36:46 | 003,840,413 | ---- | M] () -- C:\Documents and Settings\Sharon\Desktop\ComboFix.exe
[2010/01/30 13:33:34 | 000,000,738 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/01/30 13:33:34 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/01/30 13:33:34 | 000,000,223 | RHS- | M] () -- C:\boot.ini
[2010/01/30 13:14:44 | 000,001,548 | ---- | M] () -- C:\Documents and Settings\Sharon\Desktop\CCleaner.lnk
[2010/01/30 13:14:19 | 001,128,296 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Sharon\Desktop\ccsetup228_slim.exe
[2010/01/30 09:44:01 | 000,000,001 | ---- | M] () -- C:\s
[2010/01/30 09:43:49 | 000,016,896 | ---- | M] () -- C:\duehpow.exe
[2010/01/30 09:43:45 | 000,030,720 | ---- | M] () -- C:\dqccpnq.exe
[2010/01/30 09:43:45 | 000,020,480 | ---- | M] () -- C:\WINDOWS\System32\winlogon32.exe
[2010/01/30 09:43:45 | 000,020,480 | ---- | M] () -- C:\WINDOWS\System32\smss32.exe
[2010/01/30 09:43:45 | 000,020,480 | ---- | M] () -- C:\kkalf.exe
[2010/01/30 09:43:43 | 000,023,040 | ---- | M] () -- C:\wtork.exe
[2010/01/30 09:00:31 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/01/29 19:04:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/01/19 10:14:52 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/19 10:14:04 | 000,000,780 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/01/19 10:13:04 | 010,038,728 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Sharon\Desktop\windows-kb890830-v3.3.exe
[2010/01/19 10:12:07 | 007,520,288 | ---- | M] () -- C:\Documents and Settings\Sharon\Desktop\SUPERAntiSpyware.exe
[2010/01/18 23:30:22 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\Sharon\My Documents\Roseanne_Mills_Resume.doc
[2010/01/18 17:44:40 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\Sharon\Desktop\Microsoft Office Word 2003.lnk
[2010/01/18 16:10:20 | 000,000,138 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SAMSUNG Dr.Printer.url
[2010/01/07 16:07:14 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 000,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/05 20:00:29 | 000,832,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
[2010/01/05 20:00:28 | 001,168,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll
[2010/01/05 20:00:28 | 000,671,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mstime.dll
[2010/01/05 20:00:28 | 000,671,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
[2010/01/05 20:00:28 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\webcheck.dll
[2010/01/05 20:00:28 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll
[2010/01/05 20:00:28 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll
[2010/01/05 20:00:28 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll
[2010/01/05 20:00:28 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\pngfilt.dll
[2010/01/05 20:00:28 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pngfilt.dll
[2010/01/05 20:00:27 | 000,477,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll
[2010/01/05 20:00:27 | 000,193,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msrating.dll
[2010/01/05 20:00:27 | 000,193,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msrating.dll
[2010/01/05 20:00:26 | 003,599,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2010/01/05 20:00:25 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedsbs.dll
[2010/01/05 20:00:25 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2010/01/05 20:00:24 | 001,830,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl
[2010/01/05 20:00:24 | 001,830,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2010/01/05 20:00:24 | 000,459,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll
[2010/01/05 20:00:24 | 000,459,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2010/01/05 20:00:24 | 000,268,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2010/01/05 20:00:24 | 000,192,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iepeers.dll
[2010/01/05 20:00:24 | 000,192,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll
[2010/01/05 20:00:24 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iernonce.dll
[2010/01/05 20:00:24 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iernonce.dll
[2010/01/05 20:00:24 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll
[2010/01/05 20:00:24 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll
[2010/01/05 20:00:23 | 006,067,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2010/01/05 20:00:21 | 000,385,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll
[2010/01/05 20:00:21 | 000,385,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2010/01/05 20:00:21 | 000,380,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieapfltr.dll
[2010/01/05 20:00:21 | 000,380,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2010/01/05 20:00:21 | 000,230,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieaksie.dll
[2010/01/05 20:00:21 | 000,230,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieaksie.dll
[2010/01/05 20:00:21 | 000,214,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dxtrans.dll
[2010/01/05 20:00:21 | 000,214,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dxtrans.dll
[2010/01/05 20:00:21 | 000,153,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieakeng.dll
[2010/01/05 20:00:21 | 000,153,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieakeng.dll