OTL logfile created on: 4/15/2010 1:29:06 PM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\paul\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 189.92 Gb Total Space | 164.55 Gb Free Space | 86.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 7.43 Gb Total Space | 5.93 Gb Free Space | 79.80% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive N: | 18.68 Gb Total Space | 5.68 Gb Free Space | 30.42% Space Free | Partition Type: NTFS
Computer Name: CVB
Current User Name: paul
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/04/15 13:28:27 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\paul\My Documents\Downloads\OTL.exe
PRC - [2010/04/04 15:51:13 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/04/01 09:39:44 | 002,064,224 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/04/01 09:39:15 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/03/14 09:57:03 | 000,617,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/03/14 09:57:03 | 000,508,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/03/14 09:57:00 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/03/14 09:56:33 | 000,916,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2010/03/14 09:56:32 | 000,710,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/03/01 23:04:16 | 001,029,456 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010/03/01 23:04:16 | 000,524,632 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010/02/25 19:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.1.0.32\ccsvchst.exe
PRC - [2010/02/18 11:43:20 | 000,490,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2010/02/04 14:00:00 | 000,495,432 | R--- | M] (WinZip Computing, S.L.) -- C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2009/08/07 15:36:26 | 003,993,368 | ---- | M] (ParetoLogic) -- C:\Program Files\ParetoLogic\DriverCure\DriverCure.exe
PRC - [2009/06/24 15:03:34 | 002,876,216 | ---- | M] (Mozy, Inc.) -- C:\Program Files\MozyHome\mozystat.exe
PRC - [2009/01/20 16:22:12 | 000,069,632 | ---- | M] (S3 Graphics Co., Inc.) -- C:\WINDOWS\system32\s3loadsv.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/07/27 21:12:49 | 002,178,832 | ---- | M] () -- C:\Program Files\Logitech\QuickCam\Quickcam.exe
PRC - [2008/07/27 21:11:45 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/07/27 21:09:28 | 000,141,848 | ---- | M] (Logitech Inc.) -- c:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/07/27 21:09:25 | 000,563,984 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
PRC - [2008/07/27 21:09:25 | 000,407,824 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2008/07/23 13:16:50 | 001,927,448 | ---- | M] (Uniblue Software) -- C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
PRC - [2008/07/08 18:48:16 | 000,204,800 | ---- | M] (S3 Graphics Co., Ltd.) -- C:\WINDOWS\system32\S3Trayp.exe
PRC - [2008/05/26 22:19:14 | 000,123,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/07/09 12:54:08 | 000,177,416 | R--- | M] (Authentium, Inc.) -- C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
PRC - [2007/04/23 05:00:00 | 000,692,224 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2007/04/11 16:32:22 | 000,056,080 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
PRC - [2007/02/16 18:57:24 | 001,945,960 | ---- | M] (Acronis) -- C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
PRC - [2007/02/16 18:49:58 | 000,149,024 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2007/02/16 18:49:50 | 000,411,168 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2007/02/16 18:45:30 | 001,169,776 | ---- | M] (Acronis) -- C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
PRC - [2007/01/20 03:09:41 | 000,200,704 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2006/12/22 16:30:08 | 000,016,384 | ---- | M] () -- C:\Program Files\Spotmau WinCares 2007\FolderProtectService.exe
PRC - [2006/12/22 16:29:58 | 000,024,576 | ---- | M] () -- C:\Program Files\Spotmau WinCares 2007\FolderProtect.exe
PRC - [2006/06/18 14:56:10 | 000,712,704 | ---- | M] (UltraVNC) -- C:\Program Files\UltraVNC\winvnc.exe
PRC - [2003/04/01 11:33:00 | 000,053,248 | ---- | M] (ali) -- C:\USBStorage\USBDetector.exe
========== Modules (SafeList) ========== MOD - [2010/04/15 13:28:27 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\paul\My Documents\Downloads\OTL.exe
MOD - [2010/03/26 19:52:36 | 000,415,088 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.1.0.32\asoehook.dll
MOD - [2009/07/12 04:02:02 | 000,653,120 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.1.0.32\microsoft.vc90.crt\msvcr90.dll
MOD - [2009/07/12 04:02:00 | 000,569,664 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.1.0.32\microsoft.vc90.crt\msvcp90.dll
MOD - [2009/07/12 02:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2009/07/12 02:09:20 | 000,554,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
MOD - [2007/10/19 14:19:10 | 000,109,080 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcInj.dll
MOD - [2007/04/23 05:00:00 | 000,045,568 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\SetPoint\lgscroll.dll
========== Win32 Services (SafeList) ========== SRV - [2010/03/14 09:57:00 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/03/14 09:56:33 | 000,916,760 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/03/01 23:04:16 | 001,029,456 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/02/25 19:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton Security Suite\Engine\4.1.0.32\ccSvcHst.exe -- (N360)
SRV - [2009/09/29 06:41:04 | 000,335,872 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\SoundTaxi Media Suite\STSService.exe -- (STSService)
SRV - [2009/09/28 16:13:04 | 000,335,872 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\RadioGet\RGService.exe -- (RGService)
SRV - [2009/08/05 22:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2009/01/20 16:22:12 | 000,069,632 | ---- | M] (S3 Graphics Co., Inc.) [Auto | Running] -- C:\WINDOWS\system32\s3loadsv.exe -- (S3LoadSv)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/07/27 21:09:28 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\logishrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2008/07/27 21:09:28 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- c:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2007/07/09 12:54:08 | 000,177,416 | R--- | M] (Authentium, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe -- (dvpapi)
SRV - [2007/05/16 09:41:18 | 000,029,704 | ---- | M] (TuneUp Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2007/02/16 18:49:50 | 000,411,168 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2006/12/22 16:30:08 | 000,016,384 | ---- | M] () [Auto | Running] -- C:\Program Files\Spotmau WinCares 2007\FolderProtectService.exe -- (FolderProtectService)
SRV - [2006/06/18 14:56:10 | 000,712,704 | ---- | M] (UltraVNC) [Auto | Running] -- C:\Program Files\UltraVNC\WinVNC.exe -- (winvnc)
========== Driver Services (SafeList) ========== DRV - [2010/04/04 18:11:07 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010/04/04 01:00:00 | 001,324,720 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100415.003\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/04/04 01:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/04/04 01:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/04/04 01:00:00 | 000,084,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100415.003\NAVENG.SYS -- (NAVENG)
DRV - [2010/03/24 16:38:08 | 000,536,112 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100324.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2010/03/14 09:57:04 | 000,242,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/03/14 09:57:03 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2010/03/14 09:56:32 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/02/26 22:23:54 | 000,116,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0401000.020\Ironx86.SYS -- (SymIRON)
DRV - [2010/02/26 22:23:21 | 000,325,680 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0401000.020\SRTSP.SYS -- (SRTSP)
DRV - [2010/02/26 22:23:21 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0401000.020\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 19:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0401000.020\ccHPx86.sys -- (ccHP)
DRV - [2010/02/22 23:13:55 | 000,064,160 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2010/02/21 08:54:31 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010/02/21 08:54:30 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/21 08:54:30 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2009/11/26 02:41:48 | 000,172,592 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0401000.020\SYMEFA.SYS -- (SymEFA)
DRV - [2009/11/21 20:43:48 | 000,362,032 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0401000.020\SYMTDI.SYS -- (SYMTDI)
DRV - [2009/11/16 20:51:14 | 000,329,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100409.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2009/10/14 23:50:05 | 000,328,752 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0401000.020\SYMDS.SYS -- (SymDS)
DRV - [2009/08/05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009/04/30 23:01:36 | 000,265,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
DRV - [2009/04/30 22:55:34 | 000,013,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2009/03/17 09:34:10 | 000,561,152 | ---- | M] (S3 Graphics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\S3gIGPm.sys -- (S3GIGP)
DRV - [2009/02/18 19:31:04 | 005,028,352 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/12/13 14:47:38 | 000,040,496 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\hotcore3.sys -- (hotcore3)
DRV - [2008/12/13 14:47:38 | 000,032,056 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\UimBus.sys -- (UimBus)
DRV - [2008/08/05 21:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/07/27 19:56:34 | 000,392,320 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\timntr.sys -- (timounter)
DRV - [2008/07/27 19:56:34 | 000,032,768 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2008/07/27 19:56:32 | 000,114,048 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\snapman.sys -- (snapman)
DRV - [2008/04/14 00:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 22:06:08 | 000,084,480 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ac97via.sys -- (VIAudio) VIA AC'97 Audio Controller (WDM)
DRV - [2008/04/13 22:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/11/20 17:56:28 | 000,017,920 | ---- | M] (VIA Technologies,Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\xfilt.sys -- (xfilt)
DRV - [2007/11/07 10:18:54 | 000,007,936 | R--- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\inidvd.sys -- (INIDVD)
DRV - [2007/10/19 14:16:30 | 002,109,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007/10/18 06:28:52 | 000,052,224 | R--- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ViPrt.sys -- (ViPrt)
DRV - [2007/10/18 06:28:30 | 000,016,896 | R--- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ViBus.sys -- (ViBus)
DRV - [2007/10/11 22:00:42 | 000,041,752 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007/10/11 21:55:58 | 001,279,000 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2007/10/11 19:59:24 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2007/10/11 19:59:02 | 002,142,488 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/09/21 05:49:10 | 000,009,216 | R--- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\videX32.sys -- (videX32)
DRV - [2007/08/16 10:09:38 | 000,003,604 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Tseries BIOS Update\Award\BS_Flash.sys -- (BS_Flash)
DRV - [2007/07/09 12:01:04 | 000,834,448 | ---- | M] (Authentium, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Css-Dvp.sys -- (CSS DVP)
DRV - [2007/04/11 16:33:14 | 000,028,688 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2007/04/11 16:32:58 | 000,036,112 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2007/04/11 16:32:52 | 000,034,832 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007/04/11 16:32:30 | 000,020,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2007/01/20 03:11:07 | 000,031,644 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2006/12/12 15:25:30 | 000,011,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\Spotmau WinCares 2007\FolderProtectDriver.sys -- (FolderProtectDriver)
DRV - [2006/12/11 21:02:24 | 000,016,768 | ---- | M] (BIOSTAR Group) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BS_I2cIo.sys -- (BS_I2cIo)
DRV - [2006/11/02 17:31:20 | 000,003,584 | R--- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\shwMirror.sys -- (shwMirror)
DRV - [2006/01/04 16:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2005/03/16 02:23:54 | 000,013,696 | R--- | M] (BIOSTAR Group) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BIOS.sys -- (BIOS)
DRV - [2004/06/26 13:22:00 | 000,006,016 | ---- | M] (RDV Soft) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\vnccom.SYS -- (vnccom)
DRV - [2004/06/26 13:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vncdrv.sys -- (vncdrv)
DRV - [2004/04/10 09:42:36 | 000,002,944 | ---- | M] (cansoft@livewiredev.com) [Kernel | System | Running] -- C:\WINDOWS\system32\mbmiodrvr.sys -- (mbmiodrvr)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.msn.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
www.live.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
www.live.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.comIE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=667323"
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.783
FF - prefs.js..extensions.enabledItems: avg@igeared:4.002.023.004
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/14 11:41:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/26 22:11:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/04/04 18:11:41 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/04/04 18:11:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/04 16:16:41 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/15 08:52:54 | 000,000,000 | ---D | M]
[2010/04/04 16:16:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Mozilla\Extensions
[2010/04/14 21:26:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\wf4fo45m.default\extensions
[2010/04/04 17:31:14 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\wf4fo45m.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/14 21:26:56 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/07/26 21:53:32 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\google-cjk@partners.mozilla.com
[2008/06/18 02:43:04 | 000,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2008/07/27 21:13:26 | 000,024,576 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npgcplug.dll
[2008/07/27 21:13:26 | 000,200,704 | ---- | M] (Ancestry.com) -- C:\Program Files\Mozilla Firefox\plugins\npImgCtl.dll
[2008/07/27 21:13:26 | 000,114,688 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2008/07/27 21:13:26 | 000,102,400 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
[2010/01/24 22:59:22 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/03/11 16:56:34 | 000,002,191 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/01/24 22:59:22 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/24 22:59:22 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/01/24 22:59:22 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2009/11/13 05:50:44 | 000,614,790 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1
www.accuserveadsystem.comO1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1
www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 ads.active.com
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1
www.activemeter.com #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 data2.activshopper.com #[Trackware.ActivShopper]
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ad2games.com
O1 - Hosts: 127.0.0.1 cms.ad2click.nl
O1 - Hosts: 127.0.0.1 ads.ad2games.com
O1 - Hosts: 127.0.0.1 content.ad20.net
O1 - Hosts: 16153 more lines...
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.1.0.32\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.1.0.32\ipsbho.dll (Symantec Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.1.0.32\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.1.0.32\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [S3Trayp] C:\WINDOWS\System32\S3Trayp.exe (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [USBDetector] C:\USBStorage\USBDetector.exe (ali)
O4 - HKLM..\Run: [WinVNC] C:\Program Files\UltraVNC\WinVNC.exe (UltraVNC)
O4 - HKCU..\Run: [DriverCure] C:\Program Files\ParetoLogic\DriverCure\DriverCure.exe (ParetoLogic)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe (Uniblue Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe (Mozy, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\iavlsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\iavlsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\iavlsp.dll ()
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8}
http://www.worldwinner.com/games/v47/solitairerush/solitairerush.cab (SolitaireRush Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1217253207046 (MUWebControl Class)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB}
http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F}
http://www.worldwinner.com/games/v53/h2hpool/h2hpool.cab (H2hPool Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.73.246 68.87.71.230
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2008/07/27 19:45:01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/08/09 03:10:22 | 000,001,868 | ---- | M] () - N:\Autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/04/13 22:06:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/04/13 22:06:04 | 000,000,000 | ---D | C] -- C:\Program Files\Sun
[2010/04/13 22:05:55 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/04/13 22:05:54 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/04/13 22:05:54 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/04/13 22:05:54 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/04/13 21:51:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\My Documents\Downloads
[2010/04/12 19:18:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Malwarebytes
[2010/04/12 19:18:27 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/12 19:18:25 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/12 19:18:25 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/12 19:18:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/12 18:35:03 | 000,362,032 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0401000.020\symtdi.sys
[2010/04/12 18:35:03 | 000,340,016 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0401000.020\symtdiv.sys
[2010/04/12 18:35:03 | 000,328,752 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0401000.020\symds.sys
[2010/04/12 18:35:03 | 000,172,592 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0401000.020\symefa.sys
[2010/04/12 18:35:03 | 000,043,696 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.sys
[2010/04/12 18:35:02 | 000,501,888 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0401000.020\cchpx86.sys
[2010/04/12 18:35:02 | 000,325,680 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.sys
[2010/04/12 18:35:02 | 000,116,784 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0401000.020\ironx86.sys
[2010/04/12 18:34:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360\0401000.020
[2010/04/11 21:55:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Tracing
[2010/04/11 21:10:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Local Settings\Application Data\Adobe
[2010/04/11 20:37:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Local Settings\Application Data\Temp
[2010/04/05 16:00:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\SUPERAntiSpyware.com
[2010/04/05 15:53:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\DriverCure
[2010/04/05 15:37:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Tific
[2010/04/04 18:11:17 | 000,107,368 | R--- | C] (GEAR Software Inc.) -- C:\WINDOWS\System32\GEARAspi.dll
[2010/04/04 18:11:07 | 000,124,976 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/04 18:11:07 | 000,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/04 18:11:07 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2010/04/04 18:10:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
[2010/04/04 18:10:36 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2010/04/04 18:10:36 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Security Suite
[2010/04/04 18:10:05 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2010/04/04 18:10:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/04/04 18:10:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\My Documents\Symantec
[2010/04/04 17:48:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\MyFamily.com
[2010/04/04 17:46:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Norton
[2010/04/04 17:46:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2010/04/04 17:19:03 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\paul\PrivacIE
[2010/04/04 17:18:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Local Settings\Application Data\Google
[2010/04/04 17:18:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Google
[2010/04/04 17:18:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Sun
[2010/04/04 17:05:58 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\paul\IECompatCache
[2010/04/04 16:47:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Windows Search
[2010/04/04 16:25:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Uniblue
[2010/04/04 16:17:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Local Settings\Application Data\AVG Security Toolbar
[2010/04/04 16:16:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Local Settings\Application Data\Mozilla
[2010/04/04 16:16:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Mozilla
[2010/04/04 16:14:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Adobe
[2010/04/04 16:14:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\HP
[2010/04/04 16:13:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Local Settings\Application Data\Identities
[2010/04/04 16:13:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Logitech
[2010/04/04 16:13:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Windows Desktop Search
[2010/04/04 16:13:05 | 000,000,000 | R--D | C] -- C:\Documents and Settings\paul\My Documents\My Videos
[2010/04/04 16:12:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Identities
[2010/04/04 16:12:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\paul\My Documents\My Pictures
[2010/04/04 16:12:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\paul\My Documents\My Music
[2010/04/04 16:12:27 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\paul\IETldCache
[2010/04/04 16:12:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Local Settings\Application Data\Microsoft
[2010/04/04 16:12:21 | 000,000,000 | --SD | C] -- C:\Documents and Settings\paul\Application Data\Microsoft
[2010/04/04 16:12:21 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\paul\SendTo
[2010/04/04 16:12:21 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\paul\Recent
[2010/04/04 16:12:21 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\paul\Application Data
[2010/04/04 16:12:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\paul\Start Menu
[2010/04/04 16:12:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\paul\My Documents
[2010/04/04 16:12:21 | 000,000,000 | R--D | C] -- C:\Documents and Settings\paul\Favorites
[2010/04/04 16:12:21 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\paul\Cookies
[2010/04/04 16:12:21 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\paul\PrintHood
[2010/04/04 16:12:21 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\paul\NetHood
[2010/04/04 16:12:21 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\paul\Local Settings
[2010/04/04 16:12:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Macromedia
[2010/04/04 16:12:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Desktop
[2010/04/04 16:12:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\paul\Templates
[2010/04/01 00:44:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/30 23:33:46 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2010/03/20 08:37:21 | 000,067,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\SYSINFO.OCX
[2010/03/20 08:37:21 | 000,000,000 | ---D | C] -- C:\Program Files\Easy Macro Recorder
[2010/03/17 21:48:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ParetoLogic
[2010/03/17 21:48:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/03/17 21:48:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DriverCure
[2010/03/17 21:48:51 | 000,000,000 | ---D | C] -- C:\Program Files\ParetoLogic
[2010/02/12 22:10:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\freeonlinetvbar
[2009/12/15 13:02:15 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/12/15 13:02:15 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/12/15 13:02:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/09/30 16:07:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/06/17 15:41:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/06/05 21:10:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2009/04/01 12:54:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2009/02/12 04:09:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2008/07/28 11:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\iolo
[2008/07/28 11:13:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\iolo
[2008/07/26 22:03:02 | 000,857,088 | ---- | C] (SRO Software) -- C:\Program Files\abc-cal.exe
[2008/07/26 21:39:14 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2008/07/26 21:39:14 | 000,062,464 | ---- | C] (Prof Abimbola A. Olowofoyeku (the African Chief)) -- C:\Program Files\bcuninst.exe
[2008/07/26 21:39:14 | 000,015,872 | ---- | C] (SRO Software) -- C:\Program Files\WIPEDATA.exe
[2008/07/26 21:39:14 | 000,014,848 | ---- | C] (SRO Software) -- C:\Program Files\bcregclr.exe
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/04/15 13:33:00 | 000,000,426 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{83FCA04C-F890-4EBB-9504-0BCE04B3875A}.job
[2010/04/15 13:32:00 | 000,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-2025429265-725345543-1003UA.job
[2010/04/15 12:44:01 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2010/04/15 12:37:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/15 11:44:01 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At12.job
[2010/04/15 11:43:10 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2010/04/15 10:44:01 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At11.job
[2010/04/15 09:44:01 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2010/04/15 09:08:39 | 058,926,845 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/04/15 08:52:55 | 000,001,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/04/15 08:48:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/04/15 08:48:15 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/15 08:44:01 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At9.job
[2010/04/15 07:44:01 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At8.job
[2010/04/15 06:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At7.job
[2010/04/15 05:44:01 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At6.job
[2010/04/15 05:32:00 | 000,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-2025429265-725345543-1003Core.job
[2010/04/15 04:54:00 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Update Version2.job
[2010/04/15 04:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At5.job
[2010/04/15 03:44:03 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2010/04/15 03:21:46 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2010/04/15 03:21:46 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/04/15 03:21:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/04/15 03:19:50 | 003,145,728 | -H-- | M] () -- C:\Documents and Settings\paul\NTUSER.DAT
[2010/04/15 03:19:24 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\paul\ntuser.ini
[2010/04/15 03:19:19 | 006,291,456 | -H-- | M] () -- C:\Documents and Settings\paul\Local Settings\Application Data\IconCache.db
[2010/04/15 03:04:17 | 000,675,616 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\Cat.DB
[2010/04/15 03:03:56 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/04/15 02:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2010/04/15 01:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2010/04/15 00:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2010/04/14 23:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At24.job
[2010/04/14 22:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At23.job
[2010/04/14 22:04:19 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/04/14 21:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2010/04/14 21:35:56 | 000,000,655 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/04/14 21:35:56 | 000,000,082 | ---- | M] () -- C:\WINDOWS\MPLAYER.INI
[2010/04/14 20:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At21.job
[2010/04/14 19:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2010/04/14 18:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At19.job
[2010/04/14 18:00:00 | 000,000,446 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Registration.job
[2010/04/14 17:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2010/04/14 16:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2010/04/14 14:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2010/04/14 13:44:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2010/04/13 22:05:40 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/04/13 22:05:40 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/04/13 22:05:40 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/04/13 22:05:40 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/04/13 22:05:39 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2010/04/13 21:39:07 | 000,001,922 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/04/12 20:13:11 | 000,002,028 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton Security Suite.LNK
[2010/04/12 20:00:41 | 000,000,384 | ---- | M] () -- C:\WINDOWS\tasks\DriverCure.job
[2010/04/12 19:18:31 | 000,000,703 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/09 21:10:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/04/09 00:15:00 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/04/06 16:27:27 | 004,415,471 | ---- | M] () -- C:\Documents and Settings\paul\Desktop\swiss.pmac
[2010/04/04 18:11:07 | 000,124,976 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/04 18:11:07 | 000,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/04 18:11:07 | 000,007,443 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/04 18:11:07 | 000,000,805 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/04/04 17:54:21 | 000,000,832 | ---- | M] () -- C:\Documents and Settings\paul\Desktop\Norton Installation Files.lnk
[2010/04/04 17:29:22 | 000,000,000 | ---- | M] () -- C:\WINDOWS\lgfwup.ini
[2010/04/04 16:46:23 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\paul\Ÿ9Ÿ9
[2010/04/04 16:40:43 | 000,000,760 | ---- | M] () -- C:\Documents and Settings\paul\Application Data\setup_ldm.iss
[2010/04/04 16:38:26 | 000,001,788 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Logitech QuickCam.lnk
[2010/04/04 16:12:27 | 000,017,864 | ---- | M] () -- C:\Documents and Settings\paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/31 11:21:22 | 000,002,844 | ---- | M] () -- C:\WINDOWS\WINCMD.INI
[2010/03/30 21:52:42 | 000,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\isolate.ini
[2010/03/30 00:46:30 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/28 19:31:56 | 000,018,546 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\cJAKX65roVxQl
[2010/03/20 08:34:14 | 000,001,739 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2010/03/20 08:34:14 | 000,001,667 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2010/03/17 21:48:52 | 000,000,871 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ParetoLogic DriverCure.lnk
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/04/13 21:39:07 | 000,001,922 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/04/12 20:11:26 | 000,675,616 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\Cat.DB
[2010/04/12 19:18:31 | 000,000,703 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/12 18:35:03 | 000,007,787 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\symnetv.cat
[2010/04/12 18:35:03 | 000,007,444 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\symefa.cat
[2010/04/12 18:35:03 | 000,007,425 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\symds.cat
[2010/04/12 18:35:03 | 000,007,368 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\symnet.cat
[2010/04/12 18:35:03 | 000,003,374 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\symefa.inf
[2010/04/12 18:35:03 | 000,002,793 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\symds.inf
[2010/04/12 18:35:03 | 000,001,473 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\symnetv.inf
[2010/04/12 18:35:03 | 000,001,445 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\symnet.inf
[2010/04/12 18:35:02 | 000,007,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.cat
[2010/04/12 18:35:02 | 000,007,438 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.cat
[2010/04/12 18:35:02 | 000,007,438 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\iron.cat
[2010/04/12 18:35:02 | 000,007,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\cchpx86.cat
[2010/04/12 18:35:02 | 000,001,754 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\cchpx86.inf
[2010/04/12 18:35:02 | 000,001,388 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.inf
[2010/04/12 18:35:02 | 000,001,382 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.inf
[2010/04/12 18:35:02 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\iron.inf
[2010/04/12 18:34:37 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\isolate.ini
[2010/04/06 16:27:25 | 004,415,471 | ---- | C] () -- C:\Documents and Settings\paul\Desktop\swiss.pmac
[2010/04/04 18:11:07 | 000,007,443 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/04 18:11:07 | 000,000,805 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/04/04 18:10:56 | 000,002,028 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton Security Suite.LNK
[2010/04/04 17:46:57 | 000,000,832 | ---- | C] () -- C:\Documents and Settings\paul\Desktop\Norton Installation Files.lnk
[2010/04/04 16:46:23 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\paul\Ÿ9Ÿ9
[2010/04/04 16:40:43 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\paul\Application Data\setup_ldm.iss
[2010/04/04 16:38:26 | 000,001,788 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Logitech QuickCam.lnk
[2010/04/04 16:12:23 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\paul\ntuser.ini
[2010/04/04 16:12:20 | 003,145,728 | -H-- | C] () -- C:\Documents and Settings\paul\NTUSER.DAT
[2010/04/04 16:12:20 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\paul\NTUSER.DAT.LOG
[2010/03/28 18:28:46 | 000,018,546 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\cJAKX65roVxQl
[2010/03/20 08:34:14 | 000,001,739 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2010/03/20 08:34:14 | 000,001,667 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2010/03/17 21:49:02 | 000,000,446 | ---- | C] () -- C:\WINDOWS\tasks\ParetoLogic Registration.job
[2010/03/17 21:48:56 | 000,000,384 | ---- | C] () -- C:\WINDOWS\tasks\DriverCure.job
[2010/03/17 21:48:55 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\ParetoLogic Update Version2.job
[2010/03/17 21:48:52 | 000,000,871 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ParetoLogic DriverCure.lnk
[2010/01/12 14:18:12 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2010/01/06 22:33:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
[2009/11/15 15:32:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\lgfwup.ini
[2008/12/11 16:17:29 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A5W.INI
[2008/10/30 13:35:12 | 000,000,147 | ---- | C] () -- C:\WINDOWS\System32\09wutili.sys
[2008/08/07 22:54:58 | 000,021,504 | ---- | C] () -- C:\WINDOWS\System32\WBCustomizer.dll
[2008/08/02 23:27:05 | 000,001,683 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/07/28 19:21:42 | 000,002,844 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2008/07/28 19:01:17 | 000,000,082 | ---- | C] () -- C:\WINDOWS\MPLAYER.INI
[2008/07/28 11:37:21 | 000,000,432 | ---- | C] () -- C:\WINDOWS\System32\iolo.ini
[2008/07/28 11:13:44 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\iavlsp.dll
[2008/07/28 11:13:34 | 002,115,496 | ---- | C] () -- C:\WINDOWS\System32\Incinerator.dll
[2008/07/28 11:12:04 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[2008/07/28 09:38:36 | 000,003,604 | ---- | C] () -- C:\WINDOWS\System32\drivers\BS_Flash.sys
[2008/07/28 09:28:10 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2008/07/28 07:47:44 | 000,000,094 | ---- | C] () -- C:\WINDOWS\System32\system_.ini
[2008/07/26 22:03:02 | 000,298,408 | ---- | C] () -- C:\Program Files\abccal.hlp
[2008/07/26 22:03:02 | 000,001,598 | ---- | C] () -- C:\Program Files\abcreg.txt
[2008/07/26 22:03:02 | 000,000,929 | ---- | C] () -- C:\Program Files\BC2007.DAT
[2008/07/26 22:03:02 | 000,000,848 | ---- | C] () -- C:\Program Files\abccal.cnt
[2008/07/26 21:39:14 | 000,059,477 | ---- | C] () -- C:\Program Files\bkg_sky.jpg
[2008/07/26 21:39:14 | 000,028,768 | ---- | C] () -- C:\Program Files\history.txt
[2008/07/26 21:39:14 | 000,004,201 | ---- | C] () -- C:\Program Files\holidays.bch
[2008/07/26 21:39:14 | 000,002,885 | ---- | C] () -- C:\Program Files\UNINSTAL.LOG
[2008/07/26 21:39:14 | 000,000,855 | ---- | C] () -- C:\Program Files\BCBack.z
[2008/07/26 21:39:14 | 000,000,828 | ---- | C] () -- C:\Program Files\BCBack.z.2
[2008/07/26 21:39:14 | 000,000,828 | ---- | C] () -- C:\Program Files\BCBack.z.1
[2008/07/26 21:39:14 | 000,000,246 | ---- | C] () -- C:\Program Files\bc_spkr.gif
[2008/07/26 21:39:14 | 000,000,194 | ---- | C] () -- C:\Program Files\bc_sched.gif
[2008/07/26 21:39:14 | 000,000,135 | ---- | C] () -- C:\Program Files\bc_nf-g.gif
[2008/07/26 21:39:14 | 000,000,133 | ---- | C] () -- C:\Program Files\bc_nb-g.gif
[2008/07/26 21:39:14 | 000,000,127 | ---- | C] () -- C:\Program Files\bc_nf.gif
[2008/07/26 21:39:14 | 000,000,085 | ---- | C] () -- C:\Program Files\bc_spac.gif
[2008/07/26 21:39:14 | 000,000,082 | ---- | C] () -- C:\Program Files\BuyNow.html
[2008/07/26 21:39:13 | 000,001,317 | ---- | C] () -- C:\Program Files\BC2008.DAT
[2008/07/26 21:39:13 | 000,000,188 | ---- | C] () -- C:\Program Files\bc_back.gif
[2008/07/26 21:39:13 | 000,000,155 | ---- | C] () -- C:\Program Files\bc_mf.gif
[2008/07/26 21:39:13 | 000,000,152 | ---- | C] () -- C:\Program Files\bc_mb.gif
[2008/07/26 21:39:13 | 000,000,132 | ---- | C] () -- C:\Program Files\bc_nb.gif
[2007/10/12 01:11:58 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007/10/11 19:59:24 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
========== Alternate Data Streams ========== @Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:350B3912
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FC420CE6
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E29ACA54
< End of report >