thanks for helping me with this.
Here is OTL.txt
OTL logfile created on: 4/15/2010 8:06:37 PM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\SOA
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: | Country: | Language: | Date Format:
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 16.93 Gb Free Space | 44.25% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DHCVK541
Current User Name: mimi
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/04/15 11:03:04 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\SOA\memechose.exe
PRC - [2010/04/14 22:36:52 | 001,201,640 | ---- | M] (Webroot Software, Inc. ) -- C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
PRC - [2010/04/14 22:36:16 | 004,048,240 | ---- | M] (Webroot Software, Inc. (
www.webroot.com)) -- C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
PRC - [2010/02/25 19:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\4.1.0.32\ccsvchst.exe
PRC - [2009/08/31 10:16:14 | 006,515,784 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/09/25 01:25:00 | 000,161,024 | ---- | M] (Avanquest North America, Inc.) -- C:\Program Files\Avanquest\Fix-It\mxtask.exe
PRC - [2008/08/05 14:04:02 | 000,849,192 | ---- | M] (Sunbelt Software) -- C:\Program Files\Common Files\AntiVirus\SBAMSvc.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/01/11 19:54:31 | 000,623,992 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
PRC - [2007/09/22 19:37:37 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2007/03/09 11:09:58 | 000,063,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
PRC - [2007/02/08 01:12:48 | 000,488,984 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2007/02/06 17:45:26 | 000,109,344 | ---- | M] (Logitech Inc.) -- c:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2005/03/11 17:17:08 | 000,114,688 | ---- | M] (OLYMPUS IMAGING CORP.) -- C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
========== Modules (SafeList) ========== MOD - [2010/04/15 11:03:04 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\SOA\memechose.exe
MOD - [2010/03/26 19:52:36 | 000,415,088 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\4.1.0.32\asoehook.dll
MOD - [2009/07/12 01:02:02 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
MOD - [2009/07/12 01:02:00 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
MOD - [2007/02/06 17:45:14 | 000,092,960 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcInj.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- -- (MpfService)
SRV - File not found [Auto | Stopped] -- -- (MCVSRte)
SRV - File not found [On_Demand | Stopped] -- -- (mcupdmgr.exe)
SRV - File not found [On_Demand | Stopped] -- -- (McShield)
SRV - [2010/04/14 22:36:52 | 001,201,640 | ---- | M] (Webroot Software, Inc. ) [Auto | Running] -- C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe -- (WRConsumerService)
SRV - [2010/04/14 22:36:16 | 004,048,240 | ---- | M] (Webroot Software, Inc. (
www.webroot.com)) [Auto | Running] -- C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe -- (WebrootSpySweeperService)
SRV - [2010/02/25 19:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe -- (N360)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/09/25 01:25:00 | 000,161,024 | ---- | M] (Avanquest North America, Inc.) [Auto | Running] -- C:\Program Files\Avanquest\Fix-It\mxtask.exe -- (Fix-It Task Manager)
SRV - [2008/08/05 14:04:02 | 000,849,192 | ---- | M] (Sunbelt Software) [Auto | Running] -- C:\Program Files\Common Files\AntiVirus\SBAMSvc.exe -- (SBAMSvc)
SRV - [2007/09/22 19:37:37 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Running] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2007/02/06 17:47:12 | 000,105,248 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2007/02/06 17:45:26 | 000,109,344 | ---- | M] (Logitech Inc.) [Auto | Running] -- c:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2007/01/19 12:54:14 | 000,097,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc)
========== Driver Services (SafeList) ========== DRV - [2010/04/14 22:36:19 | 000,176,752 | ---- | M] (Webroot Software, Inc. (
www.webroot.com)) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ssidrv.sys -- (ssidrv)
DRV - [2010/04/14 22:36:19 | 000,029,808 | ---- | M] (Webroot Software, Inc. (
www.webroot.com)) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys -- (ssfs0bbc)
DRV - [2010/04/14 22:36:19 | 000,023,152 | ---- | M] (Webroot Software, Inc. (
www.webroot.com)) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sshrmd.sys -- (sshrmd)
DRV - [2010/04/13 22:30:00 | 000,054,016 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\qilophoe.sys -- (edef)
DRV - [2010/04/13 22:25:03 | 000,054,016 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\cchihlns.sys -- (dmaw)
DRV - [2010/04/06 23:11:36 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS -- (SymEvent)
DRV - [2010/04/06 01:00:00 | 001,324,720 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100410.020\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/04/06 01:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/04/06 01:00:00 | 000,084,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100410.020\NAVENG.SYS -- (NAVENG)
DRV - [2010/03/24 16:38:08 | 000,536,112 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100324.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2010/02/26 22:23:54 | 000,116,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0401000.020\Ironx86.SYS -- (SymIRON)
DRV - [2010/02/26 22:23:21 | 000,325,680 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0401000.020\SRTSP.SYS -- (SRTSP)
DRV - [2010/02/26 22:23:21 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0401000.020\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 19:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\N360\0401000.020\ccHPx86.sys -- (ccHP)
DRV - [2009/11/21 20:43:48 | 000,362,032 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0401000.020\SYMTDI.SYS -- (SYMTDI)
DRV - [2009/11/16 20:51:14 | 000,329,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100402.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2009/08/26 04:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2008/07/18 01:26:32 | 000,068,912 | ---- | M] (Sunbelt Software) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\sbapifs.sys -- (sbapifs)
DRV - [2008/07/18 01:26:32 | 000,013,360 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\sbaphd.sys -- (sbaphd)
DRV - [2008/04/13 14:45:32 | 000,059,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\gckernel.sys -- (GcKernel)
DRV - [2008/04/13 14:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys -- (gameenum)
DRV - [2008/04/13 14:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 14:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 14:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2007/11/06 10:00:58 | 000,087,848 | ---- | M] (Sunbelt Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\SBREDrv.sys -- (SBRE)
DRV - [2007/02/06 17:45:04 | 000,025,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2007/02/06 17:44:36 | 001,964,064 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/02/06 17:42:40 | 001,691,808 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\Lvckap.sys -- (LVcKap)
DRV - [2007/02/03 14:32:34 | 000,041,504 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007/02/03 14:27:27 | 000,938,272 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2007/02/03 14:27:15 | 000,014,240 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\lv302af.sys -- (pepifilter)
DRV - [2005/02/23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\afc.sys -- (Afc)
DRV - [2004/08/04 01:29:54 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys -- (nv)
DRV - [2004/08/04 01:29:49 | 000,019,455 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys -- (iAimFP4)
DRV - [2004/08/04 01:29:47 | 000,012,063 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys -- (iAimFP3)
DRV - [2004/08/04 01:29:45 | 000,023,615 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys -- (iAimTV4)
DRV - [2004/08/04 01:29:43 | 000,033,599 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys -- (iAimTV3)
DRV - [2004/08/04 01:29:42 | 000,019,551 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys -- (iAimTV1)
DRV - [2004/08/04 01:29:41 | 000,029,311 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys -- (iAimTV0)
DRV - [2004/08/04 01:29:37 | 000,012,415 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys -- (iAimFP0)
DRV - [2004/08/04 01:29:37 | 000,012,127 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys -- (iAimFP1)
DRV - [2004/08/04 01:29:37 | 000,011,775 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys -- (iAimFP2)
DRV - [2004/08/04 01:29:36 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys -- (i81x)
DRV - [2004/01/20 23:48:07 | 000,669,696 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2003/12/15 18:22:00 | 000,038,448 | ---- | M] (OLYMPUS OPTICAL CO.,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\VNUSB.sys -- (VNUSB)
DRV - [2003/08/29 04:59:24 | 001,101,696 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys -- (BCMModem)
DRV - [2003/08/14 12:58:12 | 001,296,384 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\P16X.sys -- (P16X) Creative SB Live! Series (WDM)
DRV - [2003/07/16 12:42:39 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\ultra.sys -- (ultra)
DRV - [2003/07/16 12:41:17 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2003/07/16 12:41:16 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2003/07/16 12:41:16 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2003/07/16 12:41:16 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\symc810.sys -- (symc810)
DRV - [2003/07/16 12:40:06 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2003/07/16 12:36:08 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2003/07/16 12:36:07 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2003/07/16 12:36:06 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2003/07/16 12:29:06 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2003/07/16 12:21:40 | 000,008,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\hidgame.sys -- (hidgame)
DRV - [2003/07/16 12:20:43 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2003/07/16 12:19:41 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\cmdide.sys -- (CmdIde)
DRV - [2003/07/16 12:18:27 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\asc.sys -- (asc)
DRV - [2003/07/16 12:18:27 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2003/07/16 12:18:13 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2003/05/27 13:25:50 | 000,072,461 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\MpFirewall.sys -- (MPFIREWL)
DRV - [2003/05/23 14:58:30 | 000,043,136 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2002/11/08 15:45:06 | 000,017,217 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
DRV - [2002/03/13 10:50:36 | 000,023,296 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\NaiFiltr.sys -- (NaiFiltr)
DRV - [2001/08/17 15:57:38 | 000,016,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys -- (MODEMCSA)
DRV - [2001/08/17 14:02:50 | 000,002,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\HIDSwvd.sys -- (HIDSwvd)
DRV - [2001/08/17 14:02:40 | 000,035,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\msgame.sys -- (msgame)
DRV - [2000/07/24 01:01:00 | 000,019,537 | ---- | M] (Brother Industries Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\BrPar.sys -- (BrPar)
DRV - [1999/12/17 03:00:00 | 000,006,752 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\PFMODNT.SYS -- (PfModNT)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://red.clientapps.yahoo.com/customize/ie/defaults/cs/ymsgr/*http://www.yahoo.com/ext/search/search.htmlIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/04/06 23:22:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/04/06 23:22:35 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2010/04/14 22:47:06 | 000,001,270 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 viruslist.com
O1 - Hosts: 127.0.0.1 housecall.trendmicro.com
O1 - Hosts: 127.0.0.1 v4.windowsupdate.microsoft.com
O1 - Hosts: 127.0.0.1 v5.windowsupdate.microsoft.com
O1 - Hosts: 127.0.0.1 v5windowsupdate.microsoft.nsatc.net
O1 - Hosts: 127.0.0.1 viruslist.com
O1 - Hosts: 127.0.0.1 windowsupdate.microsoft.com
O1 - Hosts: 127.0.0.1
www.bitdefender.comO1 - Hosts: 127.0.0.1
www.pandasoftware.comO1 - Hosts: 127.0.0.1
www.ravantivirus.comO1 - Hosts: 127.0.0.1
www.windowsupdate.comO1 - Hosts: 127.0.0.1 www3.ca.com
O1 - Hosts: 127.0.0.1 downloads-eu1.kaspersky-labs.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.1.0.32\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.1.0.32\ipsbho.dll (Symantec Corporation)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (no name) - {a298ed31-d405-40e2-880f-b7511948e582} - No CLSID value found.
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {a298ed31-d405-40e2-880f-b7511948e582} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe (OLYMPUS IMAGING CORP.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4}
http://download.microsoft.com/download/0/f/b/0fb0fab9-7f09-4bb6-86d8-8e791ba99ac5/VirtualEarth3D.cab (Reg Error: Key error.)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E}
http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71}
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345}
https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429}
http://www.sibelius.com/download/software/win/ActiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B}
http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java
file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O21 - SSODL: FawsGCph - {48A61E7F-E20C-B4D5-F9EC-022E6DE91211} - CLSID or File not found.
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O30 - LSA: Authentication Packages - (OWS\S) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 15:36:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: ('autocheck autochk *') - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/04/14 22:36:07 | 000,000,000 | ---D | C] -- C:\Program Files\Webroot
[2010/04/14 22:32:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Local Settings\Application Data\Help
[2010/04/14 22:32:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Help
[2010/04/14 22:25:05 | 000,000,000 | ---D | C] -- C:\connerie
[2010/04/14 20:24:32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/13 22:54:20 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/13 22:54:17 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/13 22:54:17 | 000,000,000 | ---D | C] -- C:\Program Files\mmmmmm
[2010/04/13 20:10:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Avanquest
[2010/04/13 19:03:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Malwarebytes
[2010/04/13 19:03:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/13 19:02:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Avanquest
[2010/04/13 07:09:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\mimi\PrivacIE
[2010/04/13 07:08:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Local Settings\Application Data\Adobe
[2010/04/13 07:08:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Webroot
[2010/04/13 07:08:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Tific
[2010/04/13 07:08:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Adobe
[2010/04/13 07:08:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Local Settings\Application Data\Symantec
[2010/04/13 07:08:01 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\mimi\IETldCache
[2010/04/13 07:07:27 | 000,000,000 | --SD | C] -- C:\Documents and Settings\mimi\Application Data\Microsoft
[2010/04/13 07:07:27 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\mimi\SendTo
[2010/04/13 07:07:27 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\mimi\Recent
[2010/04/13 07:07:27 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\mimi\Application Data
[2010/04/13 07:07:27 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mimi\Start Menu
[2010/04/13 07:07:27 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mimi\My Documents\My Pictures
[2010/04/13 07:07:27 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mimi\My Documents\My Music
[2010/04/13 07:07:27 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mimi\My Documents
[2010/04/13 07:07:27 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mimi\Favorites
[2010/04/13 07:07:27 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\mimi\Cookies
[2010/04/13 07:07:27 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\mimi\Templates
[2010/04/13 07:07:27 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\mimi\PrintHood
[2010/04/13 07:07:27 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\mimi\NetHood
[2010/04/13 07:07:27 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\mimi\Local Settings
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Sun
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Sonic
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Real
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\My Documents\My Videos
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\My Documents\My PSP8 Files
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Local Settings\Application Data\Microsoft
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Macromedia
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Jasc Software Inc
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Identities
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Application Data\Gtek
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Desktop
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Local Settings\Application Data\ApplicationHistory
[2010/04/13 07:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mimi\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/11 17:30:07 | 000,000,000 | ---D | C] -- C:\crap
[2010/04/11 15:51:53 | 000,068,912 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\sbapifs.sys
[2010/04/11 15:51:53 | 000,013,360 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\sbaphd.sys
[2010/04/11 15:38:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010/04/10 07:04:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\PRAGMAxgeraphpft
[2010/04/06 22:56:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Norton
[2009/11/02 23:35:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/09/08 20:50:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Downloaded Installations
[2009/07/03 20:32:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/10/28 11:25:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008/07/19 11:01:37 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/12/09 22:14:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Yahoo!
[2007/12/09 22:13:59 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2007/12/09 22:11:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Google
[2007/12/09 22:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Viewpoint
[2007/08/18 23:20:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2004/02/02 17:49:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
[2004/01/20 05:13:11 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[2004/01/20 04:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/04/15 20:22:00 | 000,000,498 | ---- | M] () -- C:\WINDOWS\tasks\McAfee.com Update Check (DHCVK541-Youssef).job
[2010/04/15 20:22:00 | 000,000,494 | ---- | M] () -- C:\WINDOWS\tasks\McAfee.com Update Check (DHCVK541-Imane).job
[2010/04/15 20:20:00 | 000,000,410 | ---- | M] () -- C:\WINDOWS\tasks\Symantec NetDetect.job
[2010/04/15 20:18:00 | 000,000,492 | ---- | M] () -- C:\WINDOWS\tasks\McAfee.com Update Check (DHCVK541-Riaz).job
[2010/04/15 20:11:00 | 000,000,252 | ---- | M] () -- C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/04/15 20:04:44 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2010/04/15 20:00:44 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2010/04/15 20:00:27 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/15 19:46:06 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/15 19:11:04 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/04/15 19:10:53 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2010/04/15 19:10:49 | 2145,456,128 | -HS- | M] () -- C:\hiberfil.sys
[2010/04/14 22:47:06 | 000,001,270 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\HOSTS
[2010/04/14 22:46:28 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/04/14 22:46:27 | 000,000,974 | ---- | M] () -- C:\WINDOWS\WIN.INI
[2010/04/14 22:46:27 | 000,000,253 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI
[2010/04/14 22:37:39 | 001,048,576 | ---- | M] () -- C:\Documents and Settings\mimi\ntuser.dat
[2010/04/14 22:36:52 | 000,775,168 | ---- | M] () -- C:\WINDOWS\is-SGKDV.exe
[2010/04/14 22:36:52 | 000,010,194 | ---- | M] () -- C:\WINDOWS\is-SGKDV.msg
[2010/04/14 22:36:52 | 000,001,669 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Spy Sweeper.lnk
[2010/04/14 22:36:52 | 000,000,229 | ---- | M] () -- C:\WINDOWS\is-SGKDV.lst
[2010/04/14 22:36:19 | 000,176,752 | ---- | M] (Webroot Software, Inc. (
www.webroot.com)) -- C:\WINDOWS\System32\drivers\ssidrv.sys
[2010/04/14 22:36:19 | 000,029,808 | ---- | M] (Webroot Software, Inc. (
www.webroot.com)) -- C:\WINDOWS\System32\drivers\ssfs0bbc.sys
[2010/04/14 22:36:19 | 000,023,152 | ---- | M] (Webroot Software, Inc. (
www.webroot.com)) -- C:\WINDOWS\System32\drivers\sshrmd.sys
[2010/04/14 22:36:18 | 000,031,088 | ---- | M] () -- C:\WINDOWS\System32\wrLZMA.dll
[2010/04/14 22:36:18 | 000,016,240 | ---- | M] () -- C:\WINDOWS\System32\SsiEfr.exe
[2010/04/14 20:24:37 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/13 22:48:44 | 000,262,144 | ---- | M] () -- C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/13 22:46:01 | 003,779,476 | -H-- | M] () -- C:\Documents and Settings\mimi\Local Settings\Application Data\IconCache.db
[2010/04/13 22:30:00 | 000,054,016 | ---- | M] () -- C:\WINDOWS\System32\drivers\qilophoe.sys
[2010/04/13 22:25:03 | 000,054,016 | ---- | M] () -- C:\WINDOWS\System32\drivers\cchihlns.sys
[2010/04/13 07:13:29 | 000,000,042 | -HS- | M] () -- C:\Documents and Settings\mimi\NTUSER.INI
[2010/04/13 07:08:45 | 000,000,127 | ---- | M] () -- C:\Documents and Settings\mimi\Local Settings\Application Data\fusioncache.dat
[2010/04/13 06:51:28 | 000,015,150 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\mE20
[2010/04/11 20:48:26 | 000,015,134 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\4097701637
[2010/04/11 18:00:00 | 000,000,406 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Riaz.job
[2010/04/10 21:36:28 | 000,000,146 | ---- | M] () -- C:\WINDOWS\System32\PRAGMAwnsrsiopob.dat
[2010/04/10 09:47:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/04/09 22:00:00 | 000,001,642 | ---- | M] () -- C:\WINDOWS\tasks\wrSpySweeper_L3338A8B9E8554D19ADB40512F26E4D8B.job
[2010/04/09 21:31:18 | 000,001,165 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\pragmamfeklnmal.dll
[2010/04/09 21:31:17 | 000,049,152 | ---- | M] () -- C:\WINDOWS\System32\PRAGMAtblkwdqxns.dll
[2010/04/09 21:31:15 | 000,049,152 | ---- | M] () -- C:\WINDOWS\System32\PRAGMAxyaqpxykmr.dll
[2010/04/09 21:31:12 | 000,029,696 | ---- | M] () -- C:\WINDOWS\System32\PRAGMAmpfmqptkya.dll
[2010/04/09 20:00:00 | 000,000,596 | ---- | M] () -- C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
[2010/04/08 19:01:03 | 000,001,900 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/04/08 18:59:57 | 000,782,738 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\Cat.DB
[2010/04/06 23:11:36 | 000,124,976 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/06 23:11:36 | 000,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/06 23:11:36 | 000,007,443 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/06 23:11:36 | 000,000,805 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/03/30 00:46:30 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/26 21:39:52 | 000,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0401000.020\isolate.ini
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/04/14 22:38:31 | 2145,456,128 | -HS- | C] () -- C:\hiberfil.sys
[2010/04/14 22:36:52 | 000,775,168 | ---- | C] () -- C:\WINDOWS\is-SGKDV.exe
[2010/04/14 22:36:52 | 000,010,194 | ---- | C] () -- C:\WINDOWS\is-SGKDV.msg
[2010/04/14 22:36:52 | 000,001,669 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Spy Sweeper.lnk
[2010/04/14 22:36:52 | 000,000,229 | ---- | C] () -- C:\WINDOWS\is-SGKDV.lst
[2010/04/14 20:24:37 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/13 22:30:00 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\qilophoe.sys
[2010/04/13 22:25:03 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\cchihlns.sys
[2010/04/13 07:08:45 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\mimi\Local Settings\Application Data\fusioncache.dat
[2010/04/13 07:07:55 | 001,048,576 | ---- | C] () -- C:\Documents and Settings\mimi\ntuser.dat
[2010/04/13 07:07:55 | 000,028,672 | -H-- | C] () -- C:\Documents and Settings\mimi\ntuser.dat.LOG
[2010/04/13 07:07:27 | 000,000,042 | -HS- | C] () -- C:\Documents and Settings\mimi\NTUSER.INI
[2010/04/11 15:32:37 | 000,015,134 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\4097701637
[2010/04/10 21:44:57 | 000,015,150 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\mE20
[2010/04/09 21:31:18 | 000,001,165 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\pragmamfeklnmal.dll
[2010/04/09 21:31:17 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\PRAGMAtblkwdqxns.dll
[2010/04/09 21:31:14 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\PRAGMAxyaqpxykmr.dll
[2010/04/09 21:31:13 | 000,000,146 | ---- | C] () -- C:\WINDOWS\System32\PRAGMAwnsrsiopob.dat
[2010/04/09 21:31:12 | 000,029,696 | ---- | C] () -- C:\WINDOWS\System32\PRAGMAmpfmqptkya.dll
[2010/04/06 23:14:38 | 000,001,900 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/03/08 22:38:09 | 000,000,073 | ---- | C] () -- C:\WINDOWS\MediaManager.INI
[2009/12/09 19:43:37 | 000,000,219 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/11/15 15:03:21 | 000,000,043 | ---- | C] () -- C:\WINDOWS\gswin32.ini
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/18 20:11:12 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2009/04/21 18:26:56 | 000,031,088 | ---- | C] () -- C:\WINDOWS\System32\wrLZMA.dll
[2009/03/22 18:59:39 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
[2008/12/20 13:00:46 | 000,000,036 | ---- | C] () -- C:\WINDOWS\webica.ini
[2008/10/18 12:03:09 | 000,018,738 | ---- | C] () -- C:\Program Files\Common Files\odakeby.ban
[2008/10/18 12:03:08 | 000,014,240 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\peza._dl
[2008/10/16 23:18:34 | 000,013,549 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\qadowisov.inf
[2008/10/16 23:18:34 | 000,010,585 | ---- | C] () -- C:\WINDOWS\System32\arohahab.dll
[2008/10/16 23:18:33 | 000,018,374 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hegoki.pif
[2008/10/16 23:18:33 | 000,017,871 | ---- | C] () -- C:\Program Files\Common Files\dixyhenis.bin
[2008/10/16 23:18:33 | 000,010,664 | ---- | C] () -- C:\WINDOWS\System32\zojujoxaju.sys
[2008/10/16 23:18:32 | 000,015,402 | ---- | C] () -- C:\Program Files\Common Files\qize.scr
[2008/10/16 23:18:32 | 000,013,957 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ajoledy.dat
[2008/10/16 23:18:32 | 000,011,907 | ---- | C] () -- C:\Program Files\Common Files\abyn.bat
[2007/10/14 12:02:26 | 000,000,145 | ---- | C] () -- C:\WINDOWS\BRVIDEO.INI
[2007/10/14 12:02:26 | 000,000,040 | ---- | C] () -- C:\WINDOWS\BRDIAG.INI
[2007/10/14 12:02:26 | 000,000,023 | ---- | C] () -- C:\WINDOWS\Brownie.ini
[2007/10/14 12:02:18 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\BROSNMP.DLL
[2007/10/14 12:02:18 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\BRGSRC32.DLL
[2007/10/14 12:02:18 | 000,004,608 | ---- | C] () -- C:\WINDOWS\System32\BRGSRC16.DLL
[2007/10/14 12:02:12 | 000,008,975 | ---- | C] () -- C:\WINDOWS\HL-2040.INI
[2007/10/14 12:01:30 | 000,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2007/08/19 00:22:06 | 000,050,127 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007/05/20 20:38:16 | 000,000,004 | -H-- | C] () -- C:\WINDOWS\uccspecb.sys
[2007/03/17 16:18:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2007/02/06 17:45:04 | 000,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/06 17:42:40 | 001,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2006/10/04 19:41:09 | 000,036,911 | ---- | C] () -- C:\WINDOWS\System32\pcimsg.dll
[2006/07/09 19:22:32 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2006/07/09 19:18:12 | 000,000,044 | ---- | C] () -- C:\WINDOWS\EPCX4800.ini
[2006/04/08 10:31:40 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/04/02 11:59:51 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\OdiOlDVR.dll
[2006/04/02 11:59:51 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\OdiAPI.dll
[2006/03/06 11:41:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\AMV_DecDLL.dll
[2005/08/16 23:16:19 | 000,000,062 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2005/07/10 17:46:57 | 000,001,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\papycpu2.sys
[2005/07/10 17:46:57 | 000,001,856 | ---- | C] () -- C:\WINDOWS\System32\drivers\papyjoy.sys
[2005/07/10 17:45:53 | 000,000,132 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2005/04/24 14:58:27 | 000,000,035 | ---- | C] () -- C:\WINDOWS\WDIRECT.INI
[2005/02/05 23:59:25 | 000,000,003 | ---- | C] () -- C:\WINDOWS\sw_app.sys
[2005/01/20 18:31:31 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2004/12/26 20:32:18 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\TTSServer.dll
[2004/12/26 20:30:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Setup32.INI
[2004/11/13 21:08:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2004/11/06 21:14:49 | 000,002,122 | ---- | C] () -- C:\WINDOWS\ACROREAD.INI
[2004/11/05 22:41:57 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2004/09/16 14:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/07/21 16:28:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ATIMMC.INI
[2004/07/04 18:10:11 | 000,000,604 | ---- | C] () -- C:\WINDOWS\Spiderman.INI
[2004/02/06 21:38:10 | 000,000,021 | ---- | C] () -- C:\WINDOWS\DVDSentry.ini
[2004/02/04 00:04:03 | 000,000,174 | ---- | C] () -- C:\WINDOWS\System32\mcini.ini
[2004/02/03 18:58:42 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/02/02 18:53:05 | 000,002,865 | ---- | C] () -- C:\WINDOWS\disney.ini
[2004/02/02 17:47:24 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\MpfApi.dll
[2004/02/02 17:47:23 | 000,072,461 | ---- | C] () -- C:\WINDOWS\System32\drivers\MpFirewall.sys
[2004/02/02 17:42:00 | 000,262,144 | ---- | C] () -- C:\Documents and Settings\All Users\NTUSER.DAT
[2004/02/02 17:42:00 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2004/01/20 23:39:05 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
[2004/01/20 05:28:13 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/01/20 05:18:25 | 000,023,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\NaiFiltr.sys
[2004/01/20 05:17:38 | 000,000,258 | ---- | C] () -- C:\WINDOWS\System32\BDEMERGE.INI
[2004/01/20 05:13:38 | 000,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2004/01/20 05:13:12 | 000,002,158 | ---- | C] () -- C:\WINDOWS\System32\P16X.ini
[2004/01/20 05:13:12 | 000,000,026 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2004/01/20 05:13:11 | 000,047,616 | ---- | C] () -- C:\WINDOWS\System32\P16X.dll
[2004/01/20 05:13:11 | 000,002,572 | ---- | C] () -- C:\WINDOWS\MIXDEF.INI
[2004/01/20 05:13:11 | 000,000,064 | ---- | C] () -- C:\WINDOWS\P16x.ini
[2004/01/20 05:12:27 | 000,000,245 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2004/01/20 05:10:49 | 000,003,759 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/01/20 04:55:15 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/01/20 04:39:34 | 000,000,550 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2003/10/16 17:50:50 | 000,000,791 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2003/05/30 11:00:02 | 001,962,496 | ---- | C] () -- C:\WINDOWS\System32\quartz(2).dll
[2003/03/28 14:31:52 | 000,013,601 | ---- | C] () -- C:\WINDOWS\System32\vctest.ini
[2002/09/29 07:24:22 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2002/09/29 07:23:16 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2002/09/29 07:23:14 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2002/09/29 07:23:07 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
========== Files - Unicode (All) ==========[2004/06/04 18:01:18 | 000,002,804 | ---- | M] ()(C:\WINDOWS\System32\??E) -- C:\WINDOWS\System32\៦矵E
[2004/06/02 21:59:01 | 000,002,804 | ---- | C] ()(C:\WINDOWS\System32\??E) -- C:\WINDOWS\System32\៦矵E
========== Alternate Data Streams ========== @Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:09CD1DC6
@Alternate Data Stream - 211 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F6C0CA66
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D667795F
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7B52659E
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3BCA993F
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D431AA5F
< End of report >