This is for my gf's computer, infected about 24ish hours ago, who has lost her browser function in her windows partition, and has now lost the ability to boot into her linux partition (startup programs crashing), possibly due to her backing up files to it.
Anyhow, I'm having her go through the procedures to post here, but she can't update java or adobe, for falsely accused lack of admin rights. I've sent files to her via dropbox, which she can receive via our shared folder, but the convenience stops there. She's trying to run OTL now... We've worked a bit to try to get rid of it already, taking advice from sources saying to kill the hotfix process and exe (and some things created at the time of the infection), but it hasn't really improved the situation at all, beyond making the annoying Thinkpoint fakeware not appear. We haven't found any registry entires supposedly involved, though with a fake alert malware that supposedly spawns it, a couple reg's associated were
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnPostRedirect" = "0"
while mine were set to 1, so I had her change those. She's been able to install mbam, but it won't then immediately update/launch and can't seem to at all. Hopefully that covers the story thus far. I'll get her to post any additions tomorrow at some point.
Not sure how posting here works, but it would be convenient if she could post through her own account once she has access to another computer tomorrow. Her nick will be aphtershox.
OTL log's in, here it is, name concealed:
OTL logfile created on: 10/21/2010 7:35:40 AM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Documents and Settings\PROFILENAME\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 87.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 155.17 Gb Total Space | 49.47 Gb Free Space | 31.88% Space Free | Partition Type: NTFS
Drive E: | 54.75 Mb Total Space | 46.85 Mb Free Space | 85.56% Space Free | Partition Type: FAT
Computer Name: PROFILENAME-2008COMP | User Name: PROFILENAME | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/10/20 23:57:41 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\PROFILENAME\Desktop\O1TL.com
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/01/04 13:27:08 | 000,587,096 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
========== Modules (SafeList) ==========
MOD - [2010/10/20 23:57:41 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\PROFILENAME\Desktop\O1TL.com
MOD - [2010/08/23 09:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2008/04/13 17:12:00 | 001,384,479 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvbvm60.dll
MOD - [2008/04/13 17:11:52 | 000,158,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dinput.dll
MOD - [2008/04/13 17:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2008/04/13 10:39:24 | 002,897,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\xpsp2res.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\System32\winser.exe -- (Win PPPe)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - File not found [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - File not found [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010/08/13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/02/19 19:43:34 | 000,380,928 | ---- | M] (Spigot, Inc.) [Auto | Stopped] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2008/01/04 13:27:08 | 000,587,096 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe -- (aawservice)
SRV - [2007/09/07 11:16:18 | 001,373,480 | ---- | M] (Wacom Technology, Corp.) [Auto | Stopped] -- C:\WINDOWS\system32\Pen_Tablet.exe -- (TabletServicePen)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\DRIVERS\tclondrv.sys -- (tclondrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\point32.sys -- (Point32)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\notcable.sys -- (notecable) NoteCable Driver (WDM)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
DRV - File not found [Kernel | System | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2010/07/16 08:54:49 | 000,004,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nocashio.sys -- (nocashio)
DRV - [2010/05/21 09:11:40 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TunRAudio.sys -- (TunRAudio)
DRV - [2010/04/28 08:28:30 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DbusAudio.sys -- (DbusAudio)
DRV - [2010/03/01 10:05:24 | 000,124,784 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010/02/23 10:51:48 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)) WsAudio_DeviceS(5)
DRV - [2010/02/23 10:51:48 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)) WsAudio_DeviceS(4)
DRV - [2010/02/23 10:51:48 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV - [2010/02/23 10:51:48 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV - [2010/02/23 10:51:48 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV - [2010/02/16 14:24:01 | 000,060,936 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009/05/11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009/03/10 11:55:00 | 000,131,456 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2kfNT.sys -- (Mkd2kfNt)
DRV - [2009/02/24 18:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2009/01/08 18:00:54 | 000,016,640 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DsAudioDevice_282.sys -- (DsAudioDevice_282)
DRV - [2008/11/11 15:01:44 | 000,003,768 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CamdVideo.sys -- (CamdVideo)
DRV - [2008/11/11 15:01:42 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CamdAudio.sys -- (CamdAudio)
DRV - [2008/10/17 01:50:00 | 000,079,104 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2Nadr.sys -- (Mkd2Nadr)
DRV - [2008/07/24 02:49:52 | 000,015,872 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\cdburner.sys -- (cdburner)
DRV - [2008/04/13 11:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 11:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 11:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 09:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/07/22 19:36:42 | 000,254,872 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel(R)
DRV - [2007/07/22 14:27:12 | 004,424,704 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/06/20 17:45:24 | 000,304,920 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\iaStor.sys -- (iaStor)
DRV - [2007/05/27 21:07:48 | 006,738,304 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2007/02/16 12:12:36 | 000,011,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV - [2007/02/16 11:30:12 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacomvhid.sys -- (wacomvhid)
DRV - [2007/02/15 17:11:28 | 000,011,440 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WacomVKHid.sys -- (WacomVKHid)
DRV - [2006/08/18 12:18:08 | 000,009,400 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLADResM.SYS -- (DLADResM)
DRV - [2006/08/18 12:17:46 | 000,035,096 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLABMFSM.SYS -- (DLABMFSM)
DRV - [2006/08/18 12:17:44 | 000,097,848 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/08/18 12:17:44 | 000,094,648 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/08/18 12:17:42 | 000,026,008 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/08/18 12:17:40 | 000,032,472 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/08/18 12:17:38 | 000,104,472 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/08/18 12:17:38 | 000,014,520 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/08/11 10:05:58 | 000,051,768 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS -- (DRVNDDM)
DRV - [2006/08/11 09:35:18 | 000,012,920 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/08/11 09:35:16 | 000,028,184 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)
DRV - [2006/07/21 10:21:26 | 000,099,176 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS -- (DRVMCDB)
DRV - [2001/08/17 13:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 13:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 13:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 13:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 13:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 12:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 12:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 12:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 12:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 12:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 12:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 12:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 12:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 12:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 12:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080129
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080129
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080129
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\YouTube Downloader Toolbar\SearchSettings.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultEngine: "Yahoo"
FF - prefs.js..browser.search.defaultenginename: "Web Search..."
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-cneta&type=biennesoft_10647340"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: searchsettings@spigot.com:1.2.3
FF - prefs.js..extensions.enabledItems: youtubedownloader@mybrowserbar.com:1.0
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.86
FF - prefs.js..extensions.enabledItems: {D8798A5A-77E3-4982-8D0F-44877E525777}:1.9.1
FF - prefs.js..keyword.URL: "http://gamebox.my-quick-search.com/search.aspx?srch=ku&q="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\support@predictad.com: C:\Program Files\AutocompletePro\support@predictad.com [2010/04/19 19:19:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{D8798A5A-77E3-4982-8D0F-44877E525777}: C:\Documents and Settings\PROFILENAME\Local Settings\Application Data\{D8798A5A-77E3-4982-8D0F-44877E525777} [2010/10/19 20:19:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/21 18:29:13 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/07 07:32:42 | 000,000,000 | ---D | M]
[2008/08/27 20:16:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Extensions
[2010/10/20 05:47:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions
[2010/04/26 20:55:11 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/02 20:13:39 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/10/13 19:27:19 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2009/04/30 21:58:12 | 000,000,000 | ---D | M] (Digg This!) -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions\{6E5A7695-7C8C-42ae-9ACE-98CB5E185599}
[2010/08/22 14:15:39 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/06/13 17:42:59 | 000,004,207 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\searchplugins\aim-search.xml
[2008/02/05 19:29:58 | 000,001,877 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\searchplugins\aolsearch.xml
[2010/07/16 07:21:55 | 000,001,594 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\searchplugins\web-search.xml
[2010/10/20 05:47:22 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/02/05 12:45:06 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/04/24 15:43:32 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/24 18:34:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/12 09:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2008/02/05 18:08:08 | 000,001,948 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\AOL Search.xml
O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\YouTube Downloader Toolbar\SearchSettings.dll (Spigot, Inc.)
O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\1.0\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\1.0\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe File not found
O4 - HKLM..\Run: [ECenter] C:\dell\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [Fqapogoce] C:\WINDOWS\ukahipenoxok.DLL ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\YouTube Downloader Toolbar\SearchSettings.exe (Spigot, Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [{F239A14E-75E8-2C92-E0FF-AD246E9D0AA9}] C:\Documents and Settings\PROFILENAME\Application Data\Inoqyq\ebno.exe ()
O4 - HKCU..\Run: [Bjegagedeyo] C:\WINDOWS\wmprvcrt.DLL ()
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe File not found
O4 - HKCU..\Run: [IJKUK66HMN] C:\DOCUME~1\PROFILENAME\LOCALS~1\Temp\Ndx.exe File not found
O4 - HKCU..\Run: [NtWqIVLZEWZU] C:\DOCUME~1\PROFILENAME\LOCALS~1\Temp\Nd0.exe File not found
O4 - HKCU..\Run: [Pidgin] C:\Program Files\Pidgin\pidgin.exe (The Pidgin developer community)
O4 - Startup: C:\Documents and Settings\PROFILENAME\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab (CTAdjust Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.246,93.188.160.56
O20 - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/09/25 18:55:54 | 000,001,046 | ---- | M] () - E:\AUTOEXEC.UP -- [ FAT ]
O32 - AutoRun File - [2007/09/25 18:55:54 | 000,001,046 | ---- | M] () - E:\AUTOEXEC.BAT -- [ FAT ]
O33 - MountPoints2\{139efa5c-7b88-11dd-b86a-001d097c6895}\Shell - "" = AutoRun
O33 - MountPoints2\{139efa5c-7b88-11dd-b86a-001d097c6895}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{139efa5c-7b88-11dd-b86a-001d097c6895}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{d61abfcf-d422-11dc-ad28-001d097c6895}\Shell - "" = AutoRun
O33 - MountPoints2\{d61abfcf-d422-11dc-ad28-001d097c6895}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d61abfcf-d422-11dc-ad28-001d097c6895}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files\MSN Messenger\MsnMsgr.Exe File not found
MsConfig - StartUpReg: RoxioDragToDisc - hkey= - key= - C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
MsConfig - StartUpReg: RoxWatchTray - hkey= - key= - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
MsConfig - StartUpReg: ScreenShot.exe - hkey= - key= - C:\Program Files\ScreenShot\ScreenShot.exe File not found
MsConfig - StartUpReg: TunePat - hkey= - key= - C:\Program Files\TunePat\TunePat.exe File not found
SafeBootMin: aawservice - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: aawservice - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SafeBootNet: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2F6EFCE6-10DF-49F9-9E64-9AE3775B2588} - Microsoft .NET Framework 1.1 Security Update (KB2416447)
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {A303619C-7ACA-8F40-14F2-FE296F68D543} - DirectAnimation
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C148B7D8-F85B-6B31-2D1E-486A0F982AA5} - Microsoft Windows Media Player 6.4
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CBDDBDF2-9A90-6BAD-8AB7-63098B49D848} - Java (Sun)
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F1C786FF-02B0-920C-5E0D-9B5CFDC70B1D} - Browser Customizations
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.ffds - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Error starting restore point: The function was called in safe mode.
Error closing restore point: The sequence number is invalid.
========== Files/Folders - Created Within 30 Days ==========
[2010/10/21 07:16:40 | 027,634,824 | ---- | C] ( ) -- C:\Documents and Settings\PROFILENAME\Desktop\A1dbeRdr940_en_US.exe
[2010/10/21 07:12:36 | 016,074,528 | ---- | C] (Sun Microsystems, Inc.) -- C:\Documents and Settings\PROFILENAME\Desktop\j1re-6u22-windows-i586.exe
[2010/10/21 07:02:00 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\PROFILENAME\Desktop\O1TL.com
[2010/10/21 06:20:17 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/10/21 02:08:14 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\PROFILENAME\Recent
[2010/10/20 06:09:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Application Data\Avira
[2010/10/20 05:54:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes1
[2010/10/20 05:32:20 | 000,000,000 | ---D | C] -- C:\Program Files\avira
[2010/10/19 20:20:01 | 000,221,184 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\Nvyvea.exe
[2010/10/19 20:19:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Local Settings\Application Data\{D8798A5A-77E3-4982-8D0F-44877E525777}
[2010/10/19 20:18:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Application Data\Inoqyq
[2010/10/19 20:18:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Application Data\Coly
[2010/10/14 17:09:47 | 000,974,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/10/14 17:09:47 | 000,954,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40.dll
[2010/10/14 17:09:47 | 000,953,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010/10/14 17:09:40 | 000,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comctl32.dll
[2010/10/12 20:22:53 | 000,000,000 | ---D | C] -- C:\Program Files\Audiosurf
[2010/10/12 19:40:51 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2010/10/12 19:40:49 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2010/09/27 23:31:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Application Data\Search Settings
[2010/09/27 23:31:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Application Data\YouTube Downloader
[2010/09/27 23:11:26 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/09/27 23:11:23 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/09/27 23:08:49 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/09/27 21:34:18 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
[2010/09/27 21:34:17 | 000,000,000 | ---D | C] -- C:\Program Files\YouTube Downloader Toolbar
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/21 06:20:17 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\HijackThis.lnk
[2010/10/21 05:34:37 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/10/21 05:32:26 | 000,000,242 | -H-- | M] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/10/21 05:19:55 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Hfowipadaxuve.dat
[2010/10/21 05:19:55 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Ghilofaxacu.bin
[2010/10/21 05:19:39 | 000,000,274 | -H-- | M] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/10/21 05:19:38 | 000,000,274 | -H-- | M] () -- C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/10/21 00:13:11 | 027,634,824 | ---- | M] ( ) -- C:\Documents and Settings\PROFILENAME\Desktop\A1dbeRdr940_en_US.exe
[2010/10/21 00:09:05 | 000,205,540 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\J1avaRa.zip
[2010/10/21 00:07:30 | 016,074,528 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\PROFILENAME\Desktop\j1re-6u22-windows-i586.exe
[2010/10/20 23:57:41 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\PROFILENAME\Desktop\O1TL.com
[2010/10/20 21:12:04 | 000,364,032 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\eXplorer.exe
[2010/10/20 06:03:53 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/19 20:19:54 | 000,221,184 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\Nvyvea.exe
[2010/10/18 23:06:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/10/18 23:01:13 | 002,948,608 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\ARS 473 study guide 2.doc
[2010/10/15 18:13:15 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\GunBound.lnk
[2010/10/14 18:45:29 | 001,550,464 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/12 20:23:14 | 000,000,694 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\Audiosurf.lnk
[2010/10/12 19:37:16 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/10/09 16:37:10 | 000,073,728 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\ars 473 prelim bibliography.doc
[2010/10/06 21:15:41 | 000,442,796 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/10/06 21:15:41 | 000,071,936 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/10/06 21:10:08 | 000,082,432 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\AdvThrowingResponsePaper.doc
[2010/10/04 18:43:00 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/27 21:34:03 | 000,000,797 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\YouTube Downloader.lnk
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/21 07:13:36 | 000,205,540 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\J1avaRa.zip
[2010/10/21 07:02:00 | 000,364,032 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\eXplorer.exe
[2010/10/21 06:20:17 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\HijackThis.lnk
[2010/10/20 06:03:53 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/19 20:20:14 | 000,000,274 | -H-- | C] () -- C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/10/19 20:20:02 | 000,000,274 | -H-- | C] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/10/19 20:19:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Ghilofaxacu.bin
[2010/10/19 20:19:57 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Hfowipadaxuve.dat
[2010/10/19 20:19:56 | 000,000,242 | -H-- | C] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/10/18 22:29:50 | 002,948,608 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\ARS 473 study guide 2.doc
[2010/10/15 18:13:15 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\GunBound.lnk
[2010/10/12 20:23:14 | 000,000,694 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\Audiosurf.lnk
[2010/10/06 22:13:48 | 000,073,728 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\ars 473 prelim bibliography.doc
[2010/10/06 19:04:18 | 000,082,432 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\AdvThrowingResponsePaper.doc
[2010/09/27 23:12:12 | 000,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/09/27 21:34:03 | 000,000,797 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\YouTube Downloader.lnk
[2010/07/16 08:54:49 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\nocashio.sys
[2010/06/18 02:56:23 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2010/06/17 14:06:23 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\cdburner.sys
[2009/04/17 14:27:58 | 000,000,144 | ---- | C] () -- C:\WINDOWS\Sierra.ini
[2009/03/12 14:44:04 | 000,000,485 | ---- | C] () -- C:\WINDOWS\dle-xp.ini
[2008/12/10 02:38:45 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/10/08 21:19:06 | 000,000,023 | ---- | C] () -- C:\WINDOWS\System32\w_madriver.dll
[2008/09/03 00:42:56 | 000,000,025 | ---- | C] () -- C:\WINDOWS\System32\sysogg.dll
[2008/04/08 23:52:22 | 000,598,016 | ---- | C] () -- C:\WINDOWS\System32\viscomqtde.dll
[2008/03/19 17:31:44 | 000,000,196 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\gbufh.dll
[2008/03/16 21:29:44 | 000,001,624 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Application Data\wklnhst.dat
[2008/03/08 14:13:09 | 000,000,200 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2008/03/08 14:13:08 | 000,000,076 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2008/03/04 11:40:17 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/03/04 11:40:16 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/02/12 19:38:49 | 000,153,600 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/29 15:12:26 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/01/29 15:07:49 | 000,056,056 | ---- | C] () -- C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/01/29 15:07:49 | 000,000,120 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/01/29 14:44:19 | 000,001,124 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2007/06/18 04:19:19 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\imslevel.dll
[2007/06/16 19:40:13 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\imsispd.dll
[2007/06/16 19:40:11 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\DGRip.dll
[2007/06/02 10:46:32 | 000,153,840 | ---- | C] () -- C:\WINDOWS\System32\ARThumb.dll
[2006/11/07 03:25:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/09/16 22:36:50 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/08/10 12:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 11:51:27 | 000,186,880 | ---- | C] () -- C:\WINDOWS\ukahipenoxok.dll
[2004/08/10 11:51:27 | 000,078,848 | ---- | C] () -- C:\WINDOWS\wmprvcrt.dll
========== Custom Scans ==========
< %systemroot%*. /mp /s >
< %systemroot%system32*.dll /lockedfiles >
< %systemroot%system32*.exe /lockedfiles >
< %systemroot%Tasks*.job /lockedfiles >
< %systemroot%system32drivers*.sys /lockedfiles >
< %systemroot%System32config*.sav >
< %systemroot%system32*.sys >
< %systemroot%system32drivers*.dll >
< %systemroot%system32drivers*.ini >
< %systemroot%system32drivers*.exe >
< %SYSTEMDRIVE%*.* >
[2008/12/30 12:38:18 | 000,000,040 | ---- | M] () -- C:\.directory
[2004/08/10 12:04:08 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2008/02/05 02:51:52 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2008/05/01 21:15:02 | 000,000,274 | ---- | M] () -- C:\Bryce Lightning Uninstall.log
[2008/05/01 00:37:33 | 000,000,254 | ---- | M] () -- C:\Bryce Uninstall.log
[2004/08/10 12:04:08 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/03/13 22:00:48 | 026,068,054 | ---- | M] () -- C:\d1x-rebirth_v0.55.1-win.rar
[2008/01/29 14:47:22 | 000,006,947 | RH-- | M] () -- C:\dell.sdr
[2010/07/25 20:06:43 | 000,001,475 | ---- | M] () -- C:\deltaStartup.log
[2008/02/05 11:48:48 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2004/08/10 12:04:08 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2009/06/13 17:42:42 | 000,001,280 | -H-- | M] () -- C:\IPH.PH
[2004/08/10 12:04:08 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2009/05/04 18:43:47 | 000,003,049 | ---- | M] () -- C:\NEW.RL2
[2004/08/04 04:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/09/17 17:46:59 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/10/21 05:34:31 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2010/10/21 05:36:45 | 000,000,494 | ---- | M] () -- C:\rkill.log
[2008/03/08 14:13:47 | 000,000,168 | ---- | M] () -- C:\setupfax.log
[2008/07/22 18:54:40 | 000,000,000 | ---- | M] () -- C:\SFDebug.txt
< %PROGRAMFILES%*. >
[2009/10/21 20:15:13 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/11/17 00:13:13 | 000,000,000 | ---D | M] -- C:\Program Files\Alarm Clock
[2010/07/14 20:08:11 | 000,000,000 | ---D | M] -- C:\Program Files\Alpha Centauri
[2008/03/26 18:08:43 | 000,000,000 | ---D | M] -- C:\Program Files\Ambient Design
[2008/04/08 23:42:49 | 000,000,000 | ---D | M] -- C:\Program Files\Amond Software
[2008/06/06 15:38:26 | 000,000,000 | ---D | M] -- C:\Program Files\Anvil Studio
[2008/04/08 23:48:24 | 000,000,000 | ---D | M] -- C:\Program Files\Any Video Converter
[2008/10/22 17:17:07 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2010/09/27 21:34:19 | 000,000,000 | ---D | M] -- C:\Program Files\Application Updater
[2010/05/09 20:39:21 | 000,000,000 | ---D | M] -- C:\Program Files\ASIO4ALL v2
[2010/07/01 11:40:48 | 000,000,000 | ---D | M] -- C:\Program Files\Aspell
[2008/02/06 17:27:49 | 000,000,000 | ---D | M] -- C:\Program Files\Audacity
[2010/10/12 20:24:02 | 000,000,000 | ---D | M] -- C:\Program Files\Audiosurf
[2010/04/19 19:19:07 | 000,000,000 | ---D | M] -- C:\Program Files\AutocompletePro
[2010/10/20 05:32:20 | 000,000,000 | ---D | M] -- C:\Program Files\avira
[2010/08/20 02:26:06 | 000,000,000 | ---D | M] -- C:\Program Files\Avira1
[2010/06/18 02:56:23 | 000,000,000 | ---D | M] -- C:\Program Files\AviSynth 2.5
[2008/02/05 18:57:25 | 000,000,000 | ---D | M] -- C:\Program Files\Blender Foundation
[2010/09/27 23:08:50 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2010/09/06 12:41:28 | 000,000,000 | ---D | M] -- C:\Program Files\CCleaner
[2010/01/02 15:47:03 | 000,000,000 | ---D | M] -- C:\Program Files\CDex_150
[2010/07/23 15:08:33 | 000,000,000 | ---D | M] -- C:\Program Files\Combined Community Codec Pack
[2010/07/13 01:46:25 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2008/01/29 15:07:57 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2009/10/22 07:44:50 | 000,000,000 | ---D | M] -- C:\Program Files\DAZ
[2010/07/23 15:15:22 | 000,000,000 | ---D | M] -- C:\Program Files\Delta
[2010/07/23 15:08:29 | 000,000,000 | ---D | M] -- C:\Program Files\FastStone Image Viewer
[2009/01/22 22:36:35 | 000,000,000 | ---D | M] -- C:\Program Files\FLV Player
[2010/04/19 19:19:06 | 000,000,000 | ---D | M] -- C:\Program Files\Free Mp3 Wma Ogg Converter
[2009/12/27 20:27:35 | 000,000,000 | ---D | M] -- C:\Program Files\Game_Maker8
[2009/08/10 23:58:41 | 000,000,000 | ---D | M] -- C:\Program Files\GIMP-2.0
[2008/05/06 18:02:34 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2010/02/14 00:10:15 | 000,000,000 | ---D | M] -- C:\Program Files\Gravity
[2010/03/25 16:57:24 | 000,000,000 | ---D | M] -- C:\Program Files\Iji
[2010/06/18 03:36:59 | 000,000,000 | ---D | M] -- C:\Program Files\Image-Line
[2010/06/18 03:38:52 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2008/01/29 15:03:16 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2008/06/12 04:27:17 | 000,000,000 | ---D | M] -- C:\Program Files\intelliScore Polyphonic WAV to MIDI Converter Demo
[2010/10/14 17:14:31 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2010/09/27 23:11:26 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2010/09/27 23:12:10 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2010/08/24 18:34:05 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2008/04/08 23:52:27 | 000,000,000 | ---D | M] -- C:\Program Files\Kate's Video Converter
[2008/02/05 19:17:23 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2010/08/25 18:36:11 | 000,000,000 | ---D | M] -- C:\Program Files\MagicDisc
[2008/03/04 12:13:12 | 000,000,000 | ---D | M] -- C:\Program Files\MagicVideoMakerPro
[2010/06/20 13:25:09 | 000,000,000 | ---D | M] -- C:\Program Files\MapleStory
[2010/07/23 15:08:30 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/11/08 15:22:55 | 000,000,000 | ---D | M] -- C:\Program Files\Microprose
[2004/08/10 12:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2008/01/29 15:10:33 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2010/07/23 15:08:30 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2010/04/07 18:40:34 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft XNA
[2008/06/12 14:37:00 | 000,000,000 | ---D | M] -- C:\Program Files\MidiNotate
[2010/08/10 21:07:03 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/10/20 05:47:05 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009/08/05 12:27:31 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2004/08/10 12:01:16 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2004/08/10 12:01:24 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2009/09/19 13:48:01 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Messenger
[2008/02/05 19:09:50 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2008/01/29 14:59:26 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 6.0
[2010/06/16 22:35:15 | 000,000,000 | ---D | M] -- C:\Program Files\NCH Software
[2008/09/17 17:48:55 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2010/06/17 14:17:33 | 000,000,000 | ---D | M] -- C:\Program Files\NoteCable
[2008/09/11 09:29:56 | 000,000,000 | ---D | M] -- C:\Program Files\Ogg Converter
[2004/08/10 12:01:34 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2008/04/21 14:50:48 | 000,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 2.3
[2008/12/15 19:29:07 | 000,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 2.4
[2010/05/12 05:01:25 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010/05/09 17:52:12 | 000,000,000 | ---D | M] -- C:\Program Files\Outsim
[2010/08/07 21:22:34 | 000,000,000 | ---D | M] -- C:\Program Files\Pcsx2
[2010/08/11 17:49:39 | 000,000,000 | ---D | M] -- C:\Program Files\Pidgin
[2010/06/18 03:38:50 | 000,000,000 | ---D | M] -- C:\Program Files\Pradis
[2010/07/21 17:11:16 | 000,000,000 | ---D | M] -- C:\Program Files\Project64 1.6
[2010/09/20 23:08:48 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2010/07/23 15:08:32 | 000,000,000 | ---D | M] -- C:\Program Files\Ragnarok Battle Offline
[2010/06/17 14:01:42 | 000,000,000 | ---D | M] -- C:\Program Files\RapidSolution
[2009/08/05 12:27:23 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2008/01/29 15:07:49 | 000,000,000 | ---D | M] -- C:\Program Files\Roxio
[2008/06/06 17:09:51 | 000,000,000 | ---D | M] -- C:\Program Files\Sion Software
[2010/10/15 18:13:04 | 000,000,000 | ---D | M] -- C:\Program Files\Softnyx
[2009/11/09 13:17:35 | 000,000,000 | ---D | M] -- C:\Program Files\Software by Design
[2009/02/16 19:06:34 | 000,000,000 | ---D | M] -- C:\Program Files\Starcraft
[2010/07/30 01:11:27 | 000,000,000 | ---D | M] -- C:\Program Files\Steam
[2010/10/02 19:48:21 | 000,000,000 | ---D | M] -- C:\Program Files\StepMania
[2008/02/05 22:32:48 | 000,000,000 | ---D | M] -- C:\Program Files\SWFRIP
[2008/09/29 15:40:55 | 000,000,000 | ---D | M] -- C:\Program Files\Tablet
[2010/09/05 17:23:00 | 000,000,000 | ---D | M] -- C:\Program Files\tasofro
[2010/09/06 18:13:03 | 000,000,000 | ---D | M] -- C:\Program Files\Touhou
[2010/06/12 01:34:33 | 000,000,000 | ---D | M] -- C:\Program Files\Touhou 08 - Imperishable Night
[2010/10/21 06:20:17 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2010/06/17 14:10:48 | 000,000,000 | ---D | M] -- C:\Program Files\TuneCable
[2010/06/18 03:40:37 | 000,000,000 | ---D | M] -- C:\Program Files\TuneRaft
[2004/08/10 12:08:30 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010/01/11 21:43:37 | 000,000,000 | ---D | M] -- C:\Program Files\UnrealTournament2.2
[2010/10/19 19:14:36 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2008/07/24 20:03:24 | 000,000,000 | ---D | M] -- C:\Program Files\Veoh Networks
[2010/09/01 20:01:46 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2008/04/05 18:44:28 | 000,000,000 | ---D | M] -- C:\Program Files\VirtualDub-1.7.8
[2010/05/09 17:52:46 | 000,000,000 | ---D | M] -- C:\Program Files\VstPlugins
[2008/09/03 22:06:09 | 000,000,000 | ---D | M] -- C:\Program Files\WAV to MP3 Encoder
[2010/07/14 10:42:56 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp
[2010/07/14 10:42:48 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp Detect
[2010/07/23 15:08:34 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2008/09/17 17:48:52 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/09/17 17:48:52 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2004/08/10 12:02:52 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2008/03/03 22:57:27 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2008/10/30 09:59:44 | 000,000,000 | ---D | M] -- C:\Program Files\WMA To MP3 Converter
[2008/07/24 17:37:42 | 000,000,000 | ---D | M] -- C:\Program Files\Wolfenstein 3D
[2010/06/17 14:11:31 | 000,000,000 | ---D | M] -- C:\Program Files\Wondershare
[2004/08/10 12:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2010/09/27 21:34:03 | 000,000,000 | ---D | M] -- C:\Program Files\YouTube Downloader
[2010/09/27 21:34:19 | 000,000,000 | ---D | M] -- C:\Program Files\YouTube Downloader Toolbar
< %appdata%*.* >
[2004/08/10 11:57:42 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\PROFILENAME\Application Data\desktop.ini
[2010/04/11 01:03:36 | 000,001,624 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Application Data\wklnhst.dat
< MD5 for: AGP440.SYS >
[2004/08/04 04:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
[2004/08/04 04:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/09/17 17:45:00 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/09/17 17:45:00 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 22:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\i386\AGP440.SYS
[2004/08/03 22:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 04:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
[2004/08/04 04:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/09/17 17:45:00 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/09/17 17:45:00 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2006/08/28 01:02:10 | 000,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\i386\atapi.sys
[2006/08/27 20:02:10 | 000,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2006/08/27 20:02:10 | 000,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2006/08/27 20:02:10 | 000,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
(continued...)
Anyhow, I'm having her go through the procedures to post here, but she can't update java or adobe, for falsely accused lack of admin rights. I've sent files to her via dropbox, which she can receive via our shared folder, but the convenience stops there. She's trying to run OTL now... We've worked a bit to try to get rid of it already, taking advice from sources saying to kill the hotfix process and exe (and some things created at the time of the infection), but it hasn't really improved the situation at all, beyond making the annoying Thinkpoint fakeware not appear. We haven't found any registry entires supposedly involved, though with a fake alert malware that supposedly spawns it, a couple reg's associated were
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnPostRedirect" = "0"
while mine were set to 1, so I had her change those. She's been able to install mbam, but it won't then immediately update/launch and can't seem to at all. Hopefully that covers the story thus far. I'll get her to post any additions tomorrow at some point.
Not sure how posting here works, but it would be convenient if she could post through her own account once she has access to another computer tomorrow. Her nick will be aphtershox.
OTL log's in, here it is, name concealed:
OTL logfile created on: 10/21/2010 7:35:40 AM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Documents and Settings\PROFILENAME\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 87.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 155.17 Gb Total Space | 49.47 Gb Free Space | 31.88% Space Free | Partition Type: NTFS
Drive E: | 54.75 Mb Total Space | 46.85 Mb Free Space | 85.56% Space Free | Partition Type: FAT
Computer Name: PROFILENAME-2008COMP | User Name: PROFILENAME | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/10/20 23:57:41 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\PROFILENAME\Desktop\O1TL.com
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/01/04 13:27:08 | 000,587,096 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
========== Modules (SafeList) ==========
MOD - [2010/10/20 23:57:41 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\PROFILENAME\Desktop\O1TL.com
MOD - [2010/08/23 09:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2008/04/13 17:12:00 | 001,384,479 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvbvm60.dll
MOD - [2008/04/13 17:11:52 | 000,158,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dinput.dll
MOD - [2008/04/13 17:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2008/04/13 10:39:24 | 002,897,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\xpsp2res.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\System32\winser.exe -- (Win PPPe)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - File not found [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - File not found [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010/08/13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/02/19 19:43:34 | 000,380,928 | ---- | M] (Spigot, Inc.) [Auto | Stopped] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2008/01/04 13:27:08 | 000,587,096 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe -- (aawservice)
SRV - [2007/09/07 11:16:18 | 001,373,480 | ---- | M] (Wacom Technology, Corp.) [Auto | Stopped] -- C:\WINDOWS\system32\Pen_Tablet.exe -- (TabletServicePen)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\DRIVERS\tclondrv.sys -- (tclondrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\point32.sys -- (Point32)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\notcable.sys -- (notecable) NoteCable Driver (WDM)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
DRV - File not found [Kernel | System | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2010/07/16 08:54:49 | 000,004,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nocashio.sys -- (nocashio)
DRV - [2010/05/21 09:11:40 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TunRAudio.sys -- (TunRAudio)
DRV - [2010/04/28 08:28:30 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DbusAudio.sys -- (DbusAudio)
DRV - [2010/03/01 10:05:24 | 000,124,784 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010/02/23 10:51:48 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)) WsAudio_DeviceS(5)
DRV - [2010/02/23 10:51:48 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)) WsAudio_DeviceS(4)
DRV - [2010/02/23 10:51:48 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV - [2010/02/23 10:51:48 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV - [2010/02/23 10:51:48 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV - [2010/02/16 14:24:01 | 000,060,936 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009/05/11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009/03/10 11:55:00 | 000,131,456 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2kfNT.sys -- (Mkd2kfNt)
DRV - [2009/02/24 18:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2009/01/08 18:00:54 | 000,016,640 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DsAudioDevice_282.sys -- (DsAudioDevice_282)
DRV - [2008/11/11 15:01:44 | 000,003,768 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CamdVideo.sys -- (CamdVideo)
DRV - [2008/11/11 15:01:42 | 000,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CamdAudio.sys -- (CamdAudio)
DRV - [2008/10/17 01:50:00 | 000,079,104 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2Nadr.sys -- (Mkd2Nadr)
DRV - [2008/07/24 02:49:52 | 000,015,872 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\cdburner.sys -- (cdburner)
DRV - [2008/04/13 11:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 11:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 11:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 09:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/07/22 19:36:42 | 000,254,872 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel(R)
DRV - [2007/07/22 14:27:12 | 004,424,704 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/06/20 17:45:24 | 000,304,920 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\iaStor.sys -- (iaStor)
DRV - [2007/05/27 21:07:48 | 006,738,304 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2007/02/16 12:12:36 | 000,011,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV - [2007/02/16 11:30:12 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacomvhid.sys -- (wacomvhid)
DRV - [2007/02/15 17:11:28 | 000,011,440 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WacomVKHid.sys -- (WacomVKHid)
DRV - [2006/08/18 12:18:08 | 000,009,400 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLADResM.SYS -- (DLADResM)
DRV - [2006/08/18 12:17:46 | 000,035,096 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLABMFSM.SYS -- (DLABMFSM)
DRV - [2006/08/18 12:17:44 | 000,097,848 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/08/18 12:17:44 | 000,094,648 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/08/18 12:17:42 | 000,026,008 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/08/18 12:17:40 | 000,032,472 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/08/18 12:17:38 | 000,104,472 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/08/18 12:17:38 | 000,014,520 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/08/11 10:05:58 | 000,051,768 | ---- | M] (Roxio) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS -- (DRVNDDM)
DRV - [2006/08/11 09:35:18 | 000,012,920 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/08/11 09:35:16 | 000,028,184 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)
DRV - [2006/07/21 10:21:26 | 000,099,176 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS -- (DRVMCDB)
DRV - [2001/08/17 13:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 13:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 13:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 13:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 13:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 12:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 12:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 12:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 12:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 12:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 12:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 12:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 12:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 12:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 12:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080129
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080129
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080129
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\YouTube Downloader Toolbar\SearchSettings.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultEngine: "Yahoo"
FF - prefs.js..browser.search.defaultenginename: "Web Search..."
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-cneta&type=biennesoft_10647340"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: searchsettings@spigot.com:1.2.3
FF - prefs.js..extensions.enabledItems: youtubedownloader@mybrowserbar.com:1.0
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.86
FF - prefs.js..extensions.enabledItems: {D8798A5A-77E3-4982-8D0F-44877E525777}:1.9.1
FF - prefs.js..keyword.URL: "http://gamebox.my-quick-search.com/search.aspx?srch=ku&q="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\support@predictad.com: C:\Program Files\AutocompletePro\support@predictad.com [2010/04/19 19:19:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{D8798A5A-77E3-4982-8D0F-44877E525777}: C:\Documents and Settings\PROFILENAME\Local Settings\Application Data\{D8798A5A-77E3-4982-8D0F-44877E525777} [2010/10/19 20:19:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/21 18:29:13 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/07 07:32:42 | 000,000,000 | ---D | M]
[2008/08/27 20:16:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Extensions
[2010/10/20 05:47:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions
[2010/04/26 20:55:11 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/02 20:13:39 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/10/13 19:27:19 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2009/04/30 21:58:12 | 000,000,000 | ---D | M] (Digg This!) -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions\{6E5A7695-7C8C-42ae-9ACE-98CB5E185599}
[2010/08/22 14:15:39 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/06/13 17:42:59 | 000,004,207 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\searchplugins\aim-search.xml
[2008/02/05 19:29:58 | 000,001,877 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\searchplugins\aolsearch.xml
[2010/07/16 07:21:55 | 000,001,594 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Application Data\Mozilla\Firefox\Profiles\p9somufp.default\searchplugins\web-search.xml
[2010/10/20 05:47:22 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/02/05 12:45:06 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/04/24 15:43:32 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/24 18:34:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/12 09:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2008/02/05 18:08:08 | 000,001,948 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\AOL Search.xml
O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\YouTube Downloader Toolbar\SearchSettings.dll (Spigot, Inc.)
O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\1.0\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\1.0\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe File not found
O4 - HKLM..\Run: [ECenter] C:\dell\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [Fqapogoce] C:\WINDOWS\ukahipenoxok.DLL ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\YouTube Downloader Toolbar\SearchSettings.exe (Spigot, Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [{F239A14E-75E8-2C92-E0FF-AD246E9D0AA9}] C:\Documents and Settings\PROFILENAME\Application Data\Inoqyq\ebno.exe ()
O4 - HKCU..\Run: [Bjegagedeyo] C:\WINDOWS\wmprvcrt.DLL ()
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe File not found
O4 - HKCU..\Run: [IJKUK66HMN] C:\DOCUME~1\PROFILENAME\LOCALS~1\Temp\Ndx.exe File not found
O4 - HKCU..\Run: [NtWqIVLZEWZU] C:\DOCUME~1\PROFILENAME\LOCALS~1\Temp\Nd0.exe File not found
O4 - HKCU..\Run: [Pidgin] C:\Program Files\Pidgin\pidgin.exe (The Pidgin developer community)
O4 - Startup: C:\Documents and Settings\PROFILENAME\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab (CTAdjust Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.246,93.188.160.56
O20 - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/09/25 18:55:54 | 000,001,046 | ---- | M] () - E:\AUTOEXEC.UP -- [ FAT ]
O32 - AutoRun File - [2007/09/25 18:55:54 | 000,001,046 | ---- | M] () - E:\AUTOEXEC.BAT -- [ FAT ]
O33 - MountPoints2\{139efa5c-7b88-11dd-b86a-001d097c6895}\Shell - "" = AutoRun
O33 - MountPoints2\{139efa5c-7b88-11dd-b86a-001d097c6895}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{139efa5c-7b88-11dd-b86a-001d097c6895}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{d61abfcf-d422-11dc-ad28-001d097c6895}\Shell - "" = AutoRun
O33 - MountPoints2\{d61abfcf-d422-11dc-ad28-001d097c6895}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d61abfcf-d422-11dc-ad28-001d097c6895}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files\MSN Messenger\MsnMsgr.Exe File not found
MsConfig - StartUpReg: RoxioDragToDisc - hkey= - key= - C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
MsConfig - StartUpReg: RoxWatchTray - hkey= - key= - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
MsConfig - StartUpReg: ScreenShot.exe - hkey= - key= - C:\Program Files\ScreenShot\ScreenShot.exe File not found
MsConfig - StartUpReg: TunePat - hkey= - key= - C:\Program Files\TunePat\TunePat.exe File not found
SafeBootMin: aawservice - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: aawservice - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SafeBootNet: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2F6EFCE6-10DF-49F9-9E64-9AE3775B2588} - Microsoft .NET Framework 1.1 Security Update (KB2416447)
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {A303619C-7ACA-8F40-14F2-FE296F68D543} - DirectAnimation
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C148B7D8-F85B-6B31-2D1E-486A0F982AA5} - Microsoft Windows Media Player 6.4
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CBDDBDF2-9A90-6BAD-8AB7-63098B49D848} - Java (Sun)
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F1C786FF-02B0-920C-5E0D-9B5CFDC70B1D} - Browser Customizations
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.ffds - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Error starting restore point: The function was called in safe mode.
Error closing restore point: The sequence number is invalid.
========== Files/Folders - Created Within 30 Days ==========
[2010/10/21 07:16:40 | 027,634,824 | ---- | C] ( ) -- C:\Documents and Settings\PROFILENAME\Desktop\A1dbeRdr940_en_US.exe
[2010/10/21 07:12:36 | 016,074,528 | ---- | C] (Sun Microsystems, Inc.) -- C:\Documents and Settings\PROFILENAME\Desktop\j1re-6u22-windows-i586.exe
[2010/10/21 07:02:00 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\PROFILENAME\Desktop\O1TL.com
[2010/10/21 06:20:17 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/10/21 02:08:14 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\PROFILENAME\Recent
[2010/10/20 06:09:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Application Data\Avira
[2010/10/20 05:54:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes1
[2010/10/20 05:32:20 | 000,000,000 | ---D | C] -- C:\Program Files\avira
[2010/10/19 20:20:01 | 000,221,184 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\Nvyvea.exe
[2010/10/19 20:19:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Local Settings\Application Data\{D8798A5A-77E3-4982-8D0F-44877E525777}
[2010/10/19 20:18:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Application Data\Inoqyq
[2010/10/19 20:18:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Application Data\Coly
[2010/10/14 17:09:47 | 000,974,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/10/14 17:09:47 | 000,954,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40.dll
[2010/10/14 17:09:47 | 000,953,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010/10/14 17:09:40 | 000,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comctl32.dll
[2010/10/12 20:22:53 | 000,000,000 | ---D | C] -- C:\Program Files\Audiosurf
[2010/10/12 19:40:51 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2010/10/12 19:40:49 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2010/09/27 23:31:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Application Data\Search Settings
[2010/09/27 23:31:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PROFILENAME\Application Data\YouTube Downloader
[2010/09/27 23:11:26 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/09/27 23:11:23 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/09/27 23:08:49 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/09/27 21:34:18 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
[2010/09/27 21:34:17 | 000,000,000 | ---D | C] -- C:\Program Files\YouTube Downloader Toolbar
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/21 06:20:17 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\HijackThis.lnk
[2010/10/21 05:34:37 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/10/21 05:32:26 | 000,000,242 | -H-- | M] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/10/21 05:19:55 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Hfowipadaxuve.dat
[2010/10/21 05:19:55 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Ghilofaxacu.bin
[2010/10/21 05:19:39 | 000,000,274 | -H-- | M] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/10/21 05:19:38 | 000,000,274 | -H-- | M] () -- C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/10/21 00:13:11 | 027,634,824 | ---- | M] ( ) -- C:\Documents and Settings\PROFILENAME\Desktop\A1dbeRdr940_en_US.exe
[2010/10/21 00:09:05 | 000,205,540 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\J1avaRa.zip
[2010/10/21 00:07:30 | 016,074,528 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\PROFILENAME\Desktop\j1re-6u22-windows-i586.exe
[2010/10/20 23:57:41 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\PROFILENAME\Desktop\O1TL.com
[2010/10/20 21:12:04 | 000,364,032 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\eXplorer.exe
[2010/10/20 06:03:53 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/19 20:19:54 | 000,221,184 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\Nvyvea.exe
[2010/10/18 23:06:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/10/18 23:01:13 | 002,948,608 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\ARS 473 study guide 2.doc
[2010/10/15 18:13:15 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\GunBound.lnk
[2010/10/14 18:45:29 | 001,550,464 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/12 20:23:14 | 000,000,694 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\Audiosurf.lnk
[2010/10/12 19:37:16 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/10/09 16:37:10 | 000,073,728 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\ars 473 prelim bibliography.doc
[2010/10/06 21:15:41 | 000,442,796 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/10/06 21:15:41 | 000,071,936 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/10/06 21:10:08 | 000,082,432 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Desktop\AdvThrowingResponsePaper.doc
[2010/10/04 18:43:00 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/27 21:34:03 | 000,000,797 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\YouTube Downloader.lnk
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/21 07:13:36 | 000,205,540 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\J1avaRa.zip
[2010/10/21 07:02:00 | 000,364,032 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\eXplorer.exe
[2010/10/21 06:20:17 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\HijackThis.lnk
[2010/10/20 06:03:53 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/19 20:20:14 | 000,000,274 | -H-- | C] () -- C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/10/19 20:20:02 | 000,000,274 | -H-- | C] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/10/19 20:19:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Ghilofaxacu.bin
[2010/10/19 20:19:57 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Hfowipadaxuve.dat
[2010/10/19 20:19:56 | 000,000,242 | -H-- | C] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/10/18 22:29:50 | 002,948,608 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\ARS 473 study guide 2.doc
[2010/10/15 18:13:15 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\GunBound.lnk
[2010/10/12 20:23:14 | 000,000,694 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\Audiosurf.lnk
[2010/10/06 22:13:48 | 000,073,728 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\ars 473 prelim bibliography.doc
[2010/10/06 19:04:18 | 000,082,432 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Desktop\AdvThrowingResponsePaper.doc
[2010/09/27 23:12:12 | 000,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/09/27 21:34:03 | 000,000,797 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\YouTube Downloader.lnk
[2010/07/16 08:54:49 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\nocashio.sys
[2010/06/18 02:56:23 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2010/06/17 14:06:23 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\cdburner.sys
[2009/04/17 14:27:58 | 000,000,144 | ---- | C] () -- C:\WINDOWS\Sierra.ini
[2009/03/12 14:44:04 | 000,000,485 | ---- | C] () -- C:\WINDOWS\dle-xp.ini
[2008/12/10 02:38:45 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/10/08 21:19:06 | 000,000,023 | ---- | C] () -- C:\WINDOWS\System32\w_madriver.dll
[2008/09/03 00:42:56 | 000,000,025 | ---- | C] () -- C:\WINDOWS\System32\sysogg.dll
[2008/04/08 23:52:22 | 000,598,016 | ---- | C] () -- C:\WINDOWS\System32\viscomqtde.dll
[2008/03/19 17:31:44 | 000,000,196 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\gbufh.dll
[2008/03/16 21:29:44 | 000,001,624 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Application Data\wklnhst.dat
[2008/03/08 14:13:09 | 000,000,200 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2008/03/08 14:13:08 | 000,000,076 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2008/03/04 11:40:17 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/03/04 11:40:16 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/02/12 19:38:49 | 000,153,600 | ---- | C] () -- C:\Documents and Settings\PROFILENAME\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/29 15:12:26 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/01/29 15:07:49 | 000,056,056 | ---- | C] () -- C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/01/29 15:07:49 | 000,000,120 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/01/29 14:44:19 | 000,001,124 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2007/06/18 04:19:19 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\imslevel.dll
[2007/06/16 19:40:13 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\imsispd.dll
[2007/06/16 19:40:11 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\DGRip.dll
[2007/06/02 10:46:32 | 000,153,840 | ---- | C] () -- C:\WINDOWS\System32\ARThumb.dll
[2006/11/07 03:25:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/09/16 22:36:50 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/08/10 12:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 11:51:27 | 000,186,880 | ---- | C] () -- C:\WINDOWS\ukahipenoxok.dll
[2004/08/10 11:51:27 | 000,078,848 | ---- | C] () -- C:\WINDOWS\wmprvcrt.dll
========== Custom Scans ==========
< %systemroot%*. /mp /s >
< %systemroot%system32*.dll /lockedfiles >
< %systemroot%system32*.exe /lockedfiles >
< %systemroot%Tasks*.job /lockedfiles >
< %systemroot%system32drivers*.sys /lockedfiles >
< %systemroot%System32config*.sav >
< %systemroot%system32*.sys >
< %systemroot%system32drivers*.dll >
< %systemroot%system32drivers*.ini >
< %systemroot%system32drivers*.exe >
< %SYSTEMDRIVE%*.* >
[2008/12/30 12:38:18 | 000,000,040 | ---- | M] () -- C:\.directory
[2004/08/10 12:04:08 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2008/02/05 02:51:52 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2008/05/01 21:15:02 | 000,000,274 | ---- | M] () -- C:\Bryce Lightning Uninstall.log
[2008/05/01 00:37:33 | 000,000,254 | ---- | M] () -- C:\Bryce Uninstall.log
[2004/08/10 12:04:08 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/03/13 22:00:48 | 026,068,054 | ---- | M] () -- C:\d1x-rebirth_v0.55.1-win.rar
[2008/01/29 14:47:22 | 000,006,947 | RH-- | M] () -- C:\dell.sdr
[2010/07/25 20:06:43 | 000,001,475 | ---- | M] () -- C:\deltaStartup.log
[2008/02/05 11:48:48 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2004/08/10 12:04:08 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2009/06/13 17:42:42 | 000,001,280 | -H-- | M] () -- C:\IPH.PH
[2004/08/10 12:04:08 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2009/05/04 18:43:47 | 000,003,049 | ---- | M] () -- C:\NEW.RL2
[2004/08/04 04:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/09/17 17:46:59 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/10/21 05:34:31 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2010/10/21 05:36:45 | 000,000,494 | ---- | M] () -- C:\rkill.log
[2008/03/08 14:13:47 | 000,000,168 | ---- | M] () -- C:\setupfax.log
[2008/07/22 18:54:40 | 000,000,000 | ---- | M] () -- C:\SFDebug.txt
< %PROGRAMFILES%*. >
[2009/10/21 20:15:13 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/11/17 00:13:13 | 000,000,000 | ---D | M] -- C:\Program Files\Alarm Clock
[2010/07/14 20:08:11 | 000,000,000 | ---D | M] -- C:\Program Files\Alpha Centauri
[2008/03/26 18:08:43 | 000,000,000 | ---D | M] -- C:\Program Files\Ambient Design
[2008/04/08 23:42:49 | 000,000,000 | ---D | M] -- C:\Program Files\Amond Software
[2008/06/06 15:38:26 | 000,000,000 | ---D | M] -- C:\Program Files\Anvil Studio
[2008/04/08 23:48:24 | 000,000,000 | ---D | M] -- C:\Program Files\Any Video Converter
[2008/10/22 17:17:07 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2010/09/27 21:34:19 | 000,000,000 | ---D | M] -- C:\Program Files\Application Updater
[2010/05/09 20:39:21 | 000,000,000 | ---D | M] -- C:\Program Files\ASIO4ALL v2
[2010/07/01 11:40:48 | 000,000,000 | ---D | M] -- C:\Program Files\Aspell
[2008/02/06 17:27:49 | 000,000,000 | ---D | M] -- C:\Program Files\Audacity
[2010/10/12 20:24:02 | 000,000,000 | ---D | M] -- C:\Program Files\Audiosurf
[2010/04/19 19:19:07 | 000,000,000 | ---D | M] -- C:\Program Files\AutocompletePro
[2010/10/20 05:32:20 | 000,000,000 | ---D | M] -- C:\Program Files\avira
[2010/08/20 02:26:06 | 000,000,000 | ---D | M] -- C:\Program Files\Avira1
[2010/06/18 02:56:23 | 000,000,000 | ---D | M] -- C:\Program Files\AviSynth 2.5
[2008/02/05 18:57:25 | 000,000,000 | ---D | M] -- C:\Program Files\Blender Foundation
[2010/09/27 23:08:50 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2010/09/06 12:41:28 | 000,000,000 | ---D | M] -- C:\Program Files\CCleaner
[2010/01/02 15:47:03 | 000,000,000 | ---D | M] -- C:\Program Files\CDex_150
[2010/07/23 15:08:33 | 000,000,000 | ---D | M] -- C:\Program Files\Combined Community Codec Pack
[2010/07/13 01:46:25 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2008/01/29 15:07:57 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2009/10/22 07:44:50 | 000,000,000 | ---D | M] -- C:\Program Files\DAZ
[2010/07/23 15:15:22 | 000,000,000 | ---D | M] -- C:\Program Files\Delta
[2010/07/23 15:08:29 | 000,000,000 | ---D | M] -- C:\Program Files\FastStone Image Viewer
[2009/01/22 22:36:35 | 000,000,000 | ---D | M] -- C:\Program Files\FLV Player
[2010/04/19 19:19:06 | 000,000,000 | ---D | M] -- C:\Program Files\Free Mp3 Wma Ogg Converter
[2009/12/27 20:27:35 | 000,000,000 | ---D | M] -- C:\Program Files\Game_Maker8
[2009/08/10 23:58:41 | 000,000,000 | ---D | M] -- C:\Program Files\GIMP-2.0
[2008/05/06 18:02:34 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2010/02/14 00:10:15 | 000,000,000 | ---D | M] -- C:\Program Files\Gravity
[2010/03/25 16:57:24 | 000,000,000 | ---D | M] -- C:\Program Files\Iji
[2010/06/18 03:36:59 | 000,000,000 | ---D | M] -- C:\Program Files\Image-Line
[2010/06/18 03:38:52 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2008/01/29 15:03:16 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2008/06/12 04:27:17 | 000,000,000 | ---D | M] -- C:\Program Files\intelliScore Polyphonic WAV to MIDI Converter Demo
[2010/10/14 17:14:31 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2010/09/27 23:11:26 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2010/09/27 23:12:10 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2010/08/24 18:34:05 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2008/04/08 23:52:27 | 000,000,000 | ---D | M] -- C:\Program Files\Kate's Video Converter
[2008/02/05 19:17:23 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2010/08/25 18:36:11 | 000,000,000 | ---D | M] -- C:\Program Files\MagicDisc
[2008/03/04 12:13:12 | 000,000,000 | ---D | M] -- C:\Program Files\MagicVideoMakerPro
[2010/06/20 13:25:09 | 000,000,000 | ---D | M] -- C:\Program Files\MapleStory
[2010/07/23 15:08:30 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/11/08 15:22:55 | 000,000,000 | ---D | M] -- C:\Program Files\Microprose
[2004/08/10 12:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2008/01/29 15:10:33 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2010/07/23 15:08:30 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2010/04/07 18:40:34 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft XNA
[2008/06/12 14:37:00 | 000,000,000 | ---D | M] -- C:\Program Files\MidiNotate
[2010/08/10 21:07:03 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/10/20 05:47:05 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009/08/05 12:27:31 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2004/08/10 12:01:16 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2004/08/10 12:01:24 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2009/09/19 13:48:01 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Messenger
[2008/02/05 19:09:50 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2008/01/29 14:59:26 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 6.0
[2010/06/16 22:35:15 | 000,000,000 | ---D | M] -- C:\Program Files\NCH Software
[2008/09/17 17:48:55 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2010/06/17 14:17:33 | 000,000,000 | ---D | M] -- C:\Program Files\NoteCable
[2008/09/11 09:29:56 | 000,000,000 | ---D | M] -- C:\Program Files\Ogg Converter
[2004/08/10 12:01:34 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2008/04/21 14:50:48 | 000,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 2.3
[2008/12/15 19:29:07 | 000,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 2.4
[2010/05/12 05:01:25 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010/05/09 17:52:12 | 000,000,000 | ---D | M] -- C:\Program Files\Outsim
[2010/08/07 21:22:34 | 000,000,000 | ---D | M] -- C:\Program Files\Pcsx2
[2010/08/11 17:49:39 | 000,000,000 | ---D | M] -- C:\Program Files\Pidgin
[2010/06/18 03:38:50 | 000,000,000 | ---D | M] -- C:\Program Files\Pradis
[2010/07/21 17:11:16 | 000,000,000 | ---D | M] -- C:\Program Files\Project64 1.6
[2010/09/20 23:08:48 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2010/07/23 15:08:32 | 000,000,000 | ---D | M] -- C:\Program Files\Ragnarok Battle Offline
[2010/06/17 14:01:42 | 000,000,000 | ---D | M] -- C:\Program Files\RapidSolution
[2009/08/05 12:27:23 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2008/01/29 15:07:49 | 000,000,000 | ---D | M] -- C:\Program Files\Roxio
[2008/06/06 17:09:51 | 000,000,000 | ---D | M] -- C:\Program Files\Sion Software
[2010/10/15 18:13:04 | 000,000,000 | ---D | M] -- C:\Program Files\Softnyx
[2009/11/09 13:17:35 | 000,000,000 | ---D | M] -- C:\Program Files\Software by Design
[2009/02/16 19:06:34 | 000,000,000 | ---D | M] -- C:\Program Files\Starcraft
[2010/07/30 01:11:27 | 000,000,000 | ---D | M] -- C:\Program Files\Steam
[2010/10/02 19:48:21 | 000,000,000 | ---D | M] -- C:\Program Files\StepMania
[2008/02/05 22:32:48 | 000,000,000 | ---D | M] -- C:\Program Files\SWFRIP
[2008/09/29 15:40:55 | 000,000,000 | ---D | M] -- C:\Program Files\Tablet
[2010/09/05 17:23:00 | 000,000,000 | ---D | M] -- C:\Program Files\tasofro
[2010/09/06 18:13:03 | 000,000,000 | ---D | M] -- C:\Program Files\Touhou
[2010/06/12 01:34:33 | 000,000,000 | ---D | M] -- C:\Program Files\Touhou 08 - Imperishable Night
[2010/10/21 06:20:17 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2010/06/17 14:10:48 | 000,000,000 | ---D | M] -- C:\Program Files\TuneCable
[2010/06/18 03:40:37 | 000,000,000 | ---D | M] -- C:\Program Files\TuneRaft
[2004/08/10 12:08:30 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010/01/11 21:43:37 | 000,000,000 | ---D | M] -- C:\Program Files\UnrealTournament2.2
[2010/10/19 19:14:36 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2008/07/24 20:03:24 | 000,000,000 | ---D | M] -- C:\Program Files\Veoh Networks
[2010/09/01 20:01:46 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2008/04/05 18:44:28 | 000,000,000 | ---D | M] -- C:\Program Files\VirtualDub-1.7.8
[2010/05/09 17:52:46 | 000,000,000 | ---D | M] -- C:\Program Files\VstPlugins
[2008/09/03 22:06:09 | 000,000,000 | ---D | M] -- C:\Program Files\WAV to MP3 Encoder
[2010/07/14 10:42:56 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp
[2010/07/14 10:42:48 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp Detect
[2010/07/23 15:08:34 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2008/09/17 17:48:52 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/09/17 17:48:52 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2004/08/10 12:02:52 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2008/03/03 22:57:27 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2008/10/30 09:59:44 | 000,000,000 | ---D | M] -- C:\Program Files\WMA To MP3 Converter
[2008/07/24 17:37:42 | 000,000,000 | ---D | M] -- C:\Program Files\Wolfenstein 3D
[2010/06/17 14:11:31 | 000,000,000 | ---D | M] -- C:\Program Files\Wondershare
[2004/08/10 12:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2010/09/27 21:34:03 | 000,000,000 | ---D | M] -- C:\Program Files\YouTube Downloader
[2010/09/27 21:34:19 | 000,000,000 | ---D | M] -- C:\Program Files\YouTube Downloader Toolbar
< %appdata%*.* >
[2004/08/10 11:57:42 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\PROFILENAME\Application Data\desktop.ini
[2010/04/11 01:03:36 | 000,001,624 | ---- | M] () -- C:\Documents and Settings\PROFILENAME\Application Data\wklnhst.dat
< MD5 for: AGP440.SYS >
[2004/08/04 04:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
[2004/08/04 04:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/09/17 17:45:00 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/09/17 17:45:00 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 22:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\i386\AGP440.SYS
[2004/08/03 22:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 04:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
[2004/08/04 04:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/09/17 17:45:00 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/09/17 17:45:00 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2006/08/28 01:02:10 | 000,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\i386\atapi.sys
[2006/08/27 20:02:10 | 000,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2006/08/27 20:02:10 | 000,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2006/08/27 20:02:10 | 000,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
(continued...)