Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Google Redirect virus plus suspected rootkit [Solved]


  • This topic is locked This topic is locked

#1
Crozza

Crozza

    New Member

  • Member
  • Pip
  • 6 posts
Hi all
I seem to have contracted the dreaded google redirect malware and I think there's a possible rootkit floating around too.

This nasty little tacker basically stops me from running any anti malware programs and since running OTC and ComboFix last night I seem to have gotten rid of the google redirect however the malware that removes any downloaded files from the temp folder and doesn't let me run pretty much any downloaded exe or zip file.

Before it got really bad I was able to download combofix and OTC although I think that has been removed recently. I did get an OTC log though which I'll post below.

I have attempted to uninstall my AVG free 8.5.409 however it's not removing correctly, and I can't repair or install any other virus scanners in the interim because of the malware. I did successfully run the September Microsoft Malware program but that didn't find anything.

Thanks heaps in advance for any assistance you can provide. Very much appreciated.

Here's the OTS log from last night.

OTS logfile created on: 9/13/2009 8:08:30 PM - Run 1
OTS by OldTimer - Version 3.0.12.1	 Folder = C:\Users\brenton
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.00 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 42.33% Memory free
4.00 Gb Paging File | 2.70 Gb Available in Paging File | 67.49% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 8.67 Gb Free Space | 22.20% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1358.18 Gb Total Space | 900.51 Gb Free Space | 66.30% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 979.53 Mb Total Space | 659.64 Mb Free Space | 67.34% Space Free | Partition Type: FAT
I: Drive not present or media not loaded
 
Computer Name: FERRARI
Current User Name: brenton
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
 
[Processes - Safe List]
alg.exe -> C:\Users\brenton\alg.exe -> [2009/09/13 20:07:10 | 00,514,560 | ---- | M] (OldTimer Tools)
alg.exe -> H:\alg.exe -> [2009/09/13 19:56:38 | 00,731,136 | R--- | M] ()
avgnsx.exe -> C:\Program Files\AVG\AVG8\avgnsx.exe -> [2009/08/20 18:31:22 | 00,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgrsx.exe -> C:\Program Files\AVG\AVG8\avgrsx.exe -> [2009/08/20 18:31:24 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgtray.exe -> C:\Program Files\AVG\AVG8\avgtray.exe -> [2009/08/20 18:31:18 | 02,007,832 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> C:\Program Files\AVG\AVG8\avgwdsvc.exe -> [2009/08/20 18:31:16 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.)
bluesoleilcs.exe -> C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe -> [2009/04/20 10:13:30 | 00,840,192 | ---- | M] ()
bshelpcs.exe -> C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe -> [2009/02/27 16:42:20 | 00,098,407 | ---- | M] ()
bsmobilecs.exe -> C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe -> [2009/02/27 16:40:48 | 00,143,467 | ---- | M] ()
bttray.exe -> C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe -> [2009/02/27 16:44:34 | 00,315,478 | ---- | M] ()
daemon.exe -> C:\Program Files\DAEMON Tools Lite\daemon.exe -> [2008/08/08 20:11:12 | 00,490,952 | ---- | M] (DT Soft Ltd)
ehmsas.exe -> C:\Windows\ehome\ehmsas.exe -> [2008/01/21 10:23:22 | 00,037,376 | ---- | M] (Microsoft Corporation)
ehtray.exe -> C:\Windows\ehome\ehtray.exe -> [2008/01/21 10:23:22 | 00,125,952 | ---- | M] (Microsoft Corporation)
explorer.exe -> C:\Windows\Explorer.EXE -> [2009/04/11 14:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation)
flashutil9f.exe -> C:\Windows\System32\Macromed\Flash\FlashUtil9f.exe -> [2008/03/25 10:32:44 | 00,218,496 | R--- | M] (Adobe Systems, Inc.)
hqtray.exe -> C:\Program Files\VMware\VMware Player\hqtray.exe -> [2008/10/28 22:00:50 | 00,064,048 | ---- | M] (VMware, Inc.)
iexplore.exe -> C:\Program Files\Internet Explorer\IEXPLORE.EXE -> [2009/07/22 05:53:43 | 00,638,216 | ---- | M] (Microsoft Corporation)
iexplore.exe -> C:\Program Files\Internet Explorer\IEXPLORE.EXE -> [2009/07/22 05:53:43 | 00,638,216 | ---- | M] (Microsoft Corporation)
iexplore.exe -> C:\Program Files\Internet Explorer\IEXPLORE.EXE -> [2009/07/22 05:53:43 | 00,638,216 | ---- | M] (Microsoft Corporation)
iexplore.exe -> C:\Program Files\Internet Explorer\IEXPLORE.EXE -> [2009/07/22 05:53:43 | 00,638,216 | ---- | M] (Microsoft Corporation)
iexplore.exe -> C:\Program Files\Internet Explorer\IEXPLORE.EXE -> [2009/07/22 05:53:43 | 00,638,216 | ---- | M] (Microsoft Corporation)
ioctlsvc.exe -> C:\Windows\System32\IoctlSvc.exe -> [2006/12/19 10:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.)
jusched.exe -> C:\Program Files\Java\jre6\bin\jusched.exe -> [2009/07/25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.)
lmiguardian.exe -> C:\Program Files\LogMeIn\x86\LMIGuardian.exe -> [2008/10/16 20:35:24 | 00,087,360 | ---- | M] (LogMeIn, Inc.)
logmeinsystray.exe -> C:\Program Files\LogMeIn\x86\LogMeInSystray.exe -> [2008/07/24 18:46:10 | 00,063,048 | ---- | M] (LogMeIn, Inc.)
nbservice.exe -> C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -> [2008/06/08 09:31:04 | 00,877,864 | ---- | M] (Nero AG)
nvvsvc.exe -> C:\Windows\System32\nvvsvc.exe -> [2009/03/28 00:03:00 | 00,207,392 | ---- | M] (NVIDIA Corporation)
sidebar.exe -> C:\Program Files\Windows Sidebar\sidebar.exe -> [2009/04/11 14:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation)
sidebar.exe -> C:\Program Files\Windows Sidebar\sidebar.exe -> [2009/04/11 14:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation)
skype.exe -> C:\Program Files\Skype\Phone\Skype.exe -> [2008/05/30 15:54:14 | 21,718,312 | R--- | M] (Skype Technologies S.A.)
skypepm.exe -> C:\Program Files\Skype\Plugin Manager\skypePM.exe -> [2008/05/30 15:54:16 | 00,076,744 | R--- | M] (Skype Technologies)
vmnat.exe -> C:\Windows\System32\vmnat.exe -> [2008/10/28 22:00:08 | 00,399,920 | ---- | M] (VMware, Inc.)
vmnetdhcp.exe -> C:\Windows\System32\vmnetdhcp.exe -> [2008/10/28 22:01:22 | 00,326,192 | ---- | M] (VMware, Inc.)
vmware-authd.exe -> C:\Program Files\VMware\VMware Player\vmware-authd.exe -> [2008/10/28 22:00:40 | 00,113,200 | ---- | M] (VMware, Inc.)
wmiprvse.exe -> C:\Windows\System32\wbem\wmiprvse.exe -> [2009/04/11 14:28:15 | 00,247,296 | ---- | M] (Microsoft Corporation)
wmplayer.exe -> C:\Program Files\Windows Media Player\wmplayer.exe -> [2009/07/15 20:39:31 | 00,168,960 | ---- | M] (Microsoft Corporation)
wmpnetwk.exe -> C:\Program Files\Windows Media Player\wmpnetwk.exe -> [2008/01/21 10:23:48 | 00,896,512 | ---- | M] (Microsoft Corporation)
wmpnscfg.exe -> C:\Program Files\Windows Media Player\wmpnscfg.exe -> [2008/01/21 10:23:48 | 00,202,240 | ---- | M] (Microsoft Corporation)
wudfhost.exe -> C:\Windows\System32\WUDFHost.exe -> [2008/01/21 10:23:09 | 00,142,336 | ---- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2009/03/30 12:42:10 | 00,031,048 | ---- | M] (Microsoft Corporation)
(avg8emc) AVG Free8 E-mail Scanner [Win32_Own | Auto | Stopped] -> C:\Program Files\AVG\AVG8\avgemc.exe -> [2009/08/20 18:31:20 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.)
(avg8wd) AVG8 WatchDog [Win32_Own | Auto | Running] -> C:\Program Files\AVG\AVG8\avgwdsvc.exe -> [2009/08/20 18:31:16 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.)
(BlueSoleilCS) BlueSoleilCS [Win32_Shared | Auto | Running] -> C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe -> [2009/04/20 10:13:30 | 00,840,192 | ---- | M] ()
(BsHelpCS) BsHelpCS [Win32_Own | On_Demand | Running] -> C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe -> [2009/02/27 16:42:20 | 00,098,407 | ---- | M] ()
(BsMobileCS) BsMobileCS [Win32_Own | Auto | Running] -> C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe -> [2009/02/27 16:40:48 | 00,143,467 | ---- | M] ()
(clr_optimization_v2.0.50727_32) Microsoft .NET Framework NGEN v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2009/03/30 12:42:14 | 00,066,368 | ---- | M] (Microsoft Corporation)
(ehRecvr) Windows Media Center Receiver Service [Win32_Own | On_Demand | Stopped] -> C:\Windows\ehome\ehRecvr.exe -> [2008/01/21 10:23:20 | 00,292,352 | ---- | M] (Microsoft Corporation)
(ehSched) Windows Media Center Scheduler Service [Win32_Own | On_Demand | Stopped] -> C:\Windows\ehome\ehsched.exe -> [2006/11/02 20:34:14 | 00,131,072 | ---- | M] (Microsoft Corporation)
(ehstart) Windows Media Center Service Launcher [Win32_Shared | Auto | Stopped] -> C:\Windows\ehome\ehstart.dll -> [2006/11/02 20:34:14 | 00,013,312 | ---- | M] (Microsoft Corporation)
(Eventlog) Windows Event Log [Win32_Shared | Auto | Running] -> C:\Windows\System32\wevtsvc.dll -> [2009/04/11 14:28:25 | 01,017,856 | ---- | M] (Microsoft Corporation)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -> [2009/02/19 02:39:20 | 00,043,904 | ---- | M] (Microsoft Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2009/02/19 02:38:42 | 00,879,448 | ---- | M] (Microsoft Corporation)
(LMIMaint) LogMeIn Maintenance Service [Win32_Own | Disabled | Stopped] -> C:\Program Files\LogMeIn\x86\RaMaint.exe -> [2008/10/16 20:35:28 | 00,116,032 | ---- | M] (LogMeIn, Inc.)
(LogMeIn) LogMeIn [Win32_Own | Disabled | Stopped] -> C:\Program Files\LogMeIn\x86\LogMeIn.exe -> [2008/07/24 18:46:10 | 00,063,040 | ---- | M] (LogMeIn, Inc.)
(Nero BackItUp Scheduler 3) Nero BackItUp Scheduler 3 [Win32_Own | Auto | Running] -> C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -> [2008/06/08 09:31:04 | 00,877,864 | ---- | M] (Nero AG)
(NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2009/02/19 02:38:43 | 00,129,880 | ---- | M] (Microsoft Corporation)
(NMIndexingService) NMIndexingService [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -> [2008/06/24 16:05:56 | 00,537,896 | ---- | M] (Nero AG)
(nvsvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> C:\Windows\System32\nvvsvc.exe -> [2009/03/28 00:03:00 | 00,207,392 | ---- | M] (NVIDIA Corporation)
(OpenVPNService) OpenVPN Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\OpenVPN\bin\openvpnserv.exe -> [2008/11/20 02:22:20 | 00,015,872 | ---- | M] ()
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 11:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation)
(PLFlash DeviceIoControl Service) PLFlash DeviceIoControl Service [Win32_Own | Auto | Running] -> C:\Windows\System32\IoctlSvc.exe -> [2006/12/19 10:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.)
(ufad-ws60) VMware Agent Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\VMware\VMware Player\vmware-ufad.exe -> [2008/10/02 17:25:42 | 00,191,024 | ---- | M] (VMware, Inc.)
(usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Windows Live\Messenger\usnsvc.exe -> [2007/10/18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation)
(VMAuthdService) VMware Authorization Service [Win32_Own | Auto | Running] -> C:\Program Files\VMware\VMware Player\vmware-authd.exe -> [2008/10/28 22:00:40 | 00,113,200 | ---- | M] (VMware, Inc.)
(VMnetDHCP) VMware DHCP Service [Win32_Own | Auto | Running] -> C:\Windows\System32\vmnetdhcp.exe -> [2008/10/28 22:01:22 | 00,326,192 | ---- | M] (VMware, Inc.)
(vmserverdWin32) VMware Registration Service [Win32_Own | Auto | Stopped] ->  -> File not found
(VMware NAT Service) VMware NAT Service [Win32_Own | Auto | Running] -> C:\Windows\System32\vmnat.exe -> [2008/10/28 22:00:08 | 00,399,920 | ---- | M] (VMware, Inc.)
(WinDefend) Windows Defender [Win32_Shared | Auto | Running] -> C:\Program Files\Windows Defender\mpsvc.dll -> [2008/01/21 10:21:41 | 00,272,952 | ---- | M] (Microsoft Corporation)
(WLSetupSvc) Windows Live Setup Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Windows Live\installer\WLSetupSvc.exe -> [2007/10/25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | Auto | Running] -> C:\Program Files\Windows Media Player\wmpnetwk.exe -> [2008/01/21 10:23:48 | 00,896,512 | ---- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(adp94xx) adp94xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adp94xx.sys -> [2008/01/21 10:21:29 | 00,422,968 | ---- | M] (Adaptec, Inc.)
(adpahci) adpahci [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpahci.sys -> [2008/01/21 10:21:33 | 00,300,600 | ---- | M] (Adaptec, Inc.)
(adpu160m) adpu160m [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpu160m.sys -> [2008/01/21 10:21:34 | 00,101,432 | ---- | M] (Adaptec, Inc.)
(adpu320) adpu320 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpu320.sys -> [2008/01/21 10:21:35 | 00,149,560 | ---- | M] (Adaptec, Inc.)
(aic78xx) aic78xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\djsvs.sys -> [2006/11/02 17:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.)
(aliide) aliide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\aliide.sys -> [2008/01/21 10:21:09 | 00,017,464 | ---- | M] (Acer Laboratories Inc.)
(arc) arc [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\arc.sys -> [2008/01/21 10:21:32 | 00,079,416 | ---- | M] (Adaptec, Inc.)
(arcsas) arcsas [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\arcsas.sys -> [2008/01/21 10:21:32 | 00,079,928 | ---- | M] (Adaptec, Inc.)
(athr) Atheros Extensible Wireless LAN device driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\DRIVERS\athr.sys -> [2009/01/13 08:45:00 | 00,954,368 | ---- | M] (Atheros Communications, Inc.)
(AvgLdx86) AVG AVI Loader Driver x86 [Kernel | System | Running] -> C:\Windows\System32\Drivers\avgldx86.sys -> [2009/08/20 18:31:24 | 00,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> C:\Windows\System32\Drivers\avgmfx86.sys -> [2009/08/20 18:31:24 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgTdiX) AVG8 Network Redirector [Kernel | System | Running] -> C:\Windows\System32\Drivers\avgtdix.sys -> [2009/05/02 12:44:51 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.)
(BrFiltLo) Brother USB Mass-Storage Lower Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brfiltlo.sys -> [2006/11/02 16:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.)
(BrFiltUp) Brother USB Mass-Storage Upper Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brfiltup.sys -> [2006/11/02 16:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.)
(Brserid) Brother MFC Serial Port Interface Driver (WDM) [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brserid.sys -> [2006/11/02 16:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.)
(BrSerWdm) Brother WDM Serial driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brserwdm.sys -> [2006/11/02 16:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.)
(BrUsbMdm) Brother MFC USB Fax Only Modem [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brusbmdm.sys -> [2006/11/02 16:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.)
(BrUsbSer) Brother MFC USB Serial WDM Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brusbser.sys -> [2006/11/02 16:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.)
(BT) Bluetooth PAN Network Adapter [Kernel | On_Demand | Stopped] -> C:\Windows\System32\DRIVERS\btnetdrv.sys -> [2008/12/07 12:44:50 | 00,017,928 | ---- | M] (IVT Corporation.)
(Btcsrusb) Bluetooth USB For Bluetooth Service [Kernel | On_Demand | Stopped] -> C:\Windows\System32\Drivers\btcusb.sys -> [2009/01/03 16:40:12 | 00,039,304 | ---- | M] (IVT Corporation.)
(BtHidBus) Bluetooth HID Bus Service [Kernel | Boot | Running] -> C:\Windows\System32\Drivers\BtHidBus.sys -> [2009/01/07 23:39:36 | 00,020,744 | ---- | M] (IVT Corporation.)
(btnetBUs) Bluetooth PAN Bus Service [Kernel | On_Demand | Running] -> C:\Windows\System32\Drivers\btnetBus.sys -> [2008/12/07 12:44:54 | 00,030,088 | ---- | M] ()
(BTNetFilter) Bluetooth Network Filter [Kernel | On_Demand | Stopped] -> C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys -> [2006/11/22 13:41:18 | 00,022,416 | ---- | M] (IVT Corporation.)
(cmdide) cmdide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\cmdide.sys -> [2008/01/21 10:21:09 | 00,019,000 | ---- | M] (CMD Technology, Inc.)
(E1G60) Intel(R) PRO/1000 NDIS 6 Adapter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\DRIVERS\E1G60I32.sys -> [2008/01/21 10:21:33 | 00,118,784 | ---- | M] (Intel Corporation)
(elxstor) elxstor [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\elxstor.sys -> [2008/01/21 10:21:30 | 00,342,584 | ---- | M] (Emulex)
(gdrv) gdrv [Kernel | On_Demand | Stopped] -> C:\Windows\gdrv.sys -> [2008/07/27 21:25:39 | 00,016,608 | ---- | M] (Windows (R) 2000 DDK provider)
(hcmon) VMware hcmon [Kernel | Auto | Running] -> C:\Windows\System32\Drivers\hcmon.sys -> [2008/10/28 22:01:28 | 00,032,304 | ---- | M] (VMware, Inc.)
(HpCISSs) HpCISSs [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\hpcisss.sys -> [2008/01/21 10:21:34 | 00,040,504 | ---- | M] (Hewlett-Packard Company)
(iaStorV) Intel RAID Controller Vista [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iastorv.sys -> [2008/01/21 10:21:31 | 00,235,064 | ---- | M] (Intel Corporation)
(iirsp) iirsp [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iirsp.sys -> [2006/11/02 17:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH)
(iteatapi) ITEATAPI_Service_Install [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iteatapi.sys -> [2006/11/02 17:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.)
(iteraid) ITERAID_Service_Install [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iteraid.sys -> [2006/11/02 17:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.)
(IvtBtBUs) IVT Bluetooth Bus Service [Kernel | On_Demand | Running] -> C:\Windows\System32\Drivers\IvtBtBus.sys -> [2008/07/02 14:58:48 | 00,026,248 | ---- | M] (IVT Corporation.)
(JRAID) JRAID [Kernel | Boot | Running] -> C:\Windows\system32\drivers\jraid.sys -> [2009/08/13 16:10:36 | 00,096,368 | ---- | M] (JMicron Technology Corp.)
(LMIInfo) LogMeIn Kernel Information Provider [Kernel | Auto | Running] -> C:\Program Files\LogMeIn\x86\RaInfo.sys -> [2008/07/24 18:46:12 | 00,012,856 | ---- | M] (LogMeIn, Inc.)
(lmimirr) lmimirr [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\lmimirr.sys -> [2008/07/24 18:45:20 | 00,010,144 | ---- | M] (LogMeIn, Inc.)
(LMIRfsClientNP) LMIRfsClientNP [File_System | Disabled | Stopped] -> C:\Windows\System32\LMIRfsClientNP.dll -> [2008/10/16 20:35:58 | 00,083,288 | ---- | M] (LogMeIn, Inc.)
(LMIRfsDriver) LogMeIn Remote File System Driver [File_System | Auto | Running] -> C:\Windows\System32\drivers\LMIRfsDriver.sys -> [2008/07/24 18:46:10 | 00,047,640 | ---- | M] (LogMeIn, Inc.)
(LSI_FC) LSI_FC [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_fc.sys -> [2008/01/21 10:21:31 | 00,096,312 | ---- | M] (LSI Logic)
(LSI_SAS) LSI_SAS [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_sas.sys -> [2008/01/21 10:21:33 | 00,089,656 | ---- | M] (LSI Logic)
(LSI_SCSI) LSI_SCSI [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_scsi.sys -> [2008/01/21 10:21:31 | 00,096,312 | ---- | M] (LSI Logic)
(massfilter) ZTE Mass Storage Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\massfilter.sys -> [2008/08/12 09:11:36 | 00,007,168 | R--- | M] (ZTE Incorporated)
(megasas) megasas [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\megasas.sys -> [2008/01/21 10:21:35 | 00,031,288 | ---- | M] (LSI Corporation)
(MegaSR) MegaSR [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\megasr.sys -> [2008/01/21 10:21:35 | 00,386,616 | ---- | M] (LSI Corporation, Inc.)
(Mraid35x) Mraid35x [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\mraid35x.sys -> [2006/11/02 17:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation)
(nfrd960) nfrd960 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nfrd960.sys -> [2006/11/02 17:50:19 | 00,045,160 | ---- | M] (IBM Corporation)
(ntrigdigi) N-trig HID Tablet Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ntrigdigi.sys -> [2006/11/02 15:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies)
(nvlddmkm) nvlddmkm [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\nvlddmkm.sys -> [2009/03/28 00:03:00 | 07,738,816 | ---- | M] (NVIDIA Corporation)
(nvraid) NVIDIA nForce RAID Driver	[Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nvraid.sys -> [2008/01/21 10:21:29 | 00,102,968 | ---- | M] (NVIDIA Corporation)
(nvstor) nvstor [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nvstor.sys -> [2008/01/21 10:21:29 | 00,045,112 | ---- | M] (NVIDIA Corporation)
(pcouffin) VSO Software pcouffin [Kernel | On_Demand | Running] -> C:\Windows\System32\Drivers\pcouffin.sys -> [2008/06/11 19:35:01 | 00,047,360 | ---- | M] (VSO Software)
(ql2300) QLogic Fibre Channel Miniport Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ql2300.sys -> [2008/01/21 10:21:33 | 01,122,360 | ---- | M] (QLogic Corporation)
(ql40xx) QLogic iSCSI Miniport Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ql40xx.sys -> [2006/11/02 17:50:35 | 00,106,088 | ---- | M] (QLogic Corporation)
(R300) R300 [Kernel | On_Demand | Stopped] -> C:\Windows\System32\DRIVERS\atikmdag.sys -> [2007/01/19 00:03:24 | 02,314,752 | ---- | M] (ATI Technologies Inc.)
(ROOTMODEM) Microsoft Legacy Modem Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\Drivers\RootMdm.sys -> [2008/01/21 10:22:59 | 00,008,192 | ---- | M] (Microsoft Corporation)
(RTL8169) Realtek 8169 NT Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\Rtlh86.sys -> [2009/05/25 06:50:44 | 00,164,864 | ---- | M] (Realtek											)
(secdrv) Security Driver [Kernel | Auto | Running] -> C:\Windows\System32\drivers\secdrv.sys -> [2006/11/02 14:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(SiSRaid4) SiSRaid4 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sisraid4.sys -> [2008/01/21 10:21:34 | 00,074,808 | ---- | M] (Silicon Integrated Systems)
(sptd) sptd [Kernel | Boot | Running] -> C:\Windows\System32\Drivers\sptd.sys -> [2008/10/24 21:56:28 | 00,717,296 | ---- | M] ()
(Symc8xx) Symc8xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\symc8xx.sys -> [2006/11/02 17:50:05 | 00,035,944 | ---- | M] (LSI Logic)
(Sym_hi) Sym_hi [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sym_hi.sys -> [2006/11/02 17:49:56 | 00,031,848 | ---- | M] (LSI Logic)
(Sym_u3) Sym_u3 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sym_u3.sys -> [2006/11/02 17:50:03 | 00,034,920 | ---- | M] (LSI Logic)
(tap0901) TAP-Win32 Adapter V9 [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\tap0901.sys -> [2008/11/20 02:22:36 | 00,025,216 | ---- | M] (The OpenVPN Project)
(uliahci) uliahci [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\uliahci.sys -> [2008/01/21 10:21:28 | 00,238,648 | ---- | M] (ULi Electronics Inc.)
(UlSata) UlSata [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ulsata.sys -> [2006/11/02 17:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.)
(ulsata2) ulsata2 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ulsata2.sys -> [2008/01/21 10:21:31 | 00,115,816 | ---- | M] (Promise Technology, Inc.)
(UMPass) Microsoft UMPass Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\DRIVERS\umpass.sys -> [2008/01/21 10:21:57 | 00,007,680 | ---- | M] (Microsoft Corporation)
(usbaudio) USB Audio Driver (WDM) [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\usbaudio.sys -> [2009/04/11 12:42:54 | 00,073,216 | ---- | M] (Microsoft Corporation)
(VComm) Virtual Serial port driver [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\VComm.sys -> [2008/01/21 19:27:50 | 00,014,856 | ---- | M] (IVT Corporation.)
(VcommMgr) Bluetooth VComm Manager Service [Kernel | On_Demand | Running] -> C:\Windows\System32\Drivers\VcommMgr.sys -> [2009/01/08 02:20:04 | 00,031,880 | ---- | M] (IVT Corporation.)
(viaide) viaide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\viaide.sys -> [2008/01/21 10:21:09 | 00,020,024 | ---- | M] (VIA Technologies, Inc.)
(vmci) VMware vmci [Kernel | Auto | Running] -> C:\Windows\System32\Drivers\vmci.sys -> [2008/10/28 22:01:34 | 00,054,960 | ---- | M] (VMware, Inc.)
(vmkbd) VMware kbd [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\VMkbd.sys -> [2008/10/28 22:01:32 | 00,023,216 | ---- | M] (VMware, Inc.)
(VMnetAdapter) VMware Virtual Ethernet Adapter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\DRIVERS\vmnetadapter.sys -> [2008/10/28 16:03:28 | 00,016,560 | ---- | M] (VMware, Inc.)
(VMnetBridge) VMware Bridge Protocol [Kernel | Auto | Running] -> C:\Windows\System32\DRIVERS\vmnetbridge.sys -> [2008/10/28 16:03:28 | 00,031,280 | R--- | M] (VMware, Inc.)
(VMnetuserif) VMware Network Application Interface [Kernel | Auto | Running] -> C:\Windows\System32\drivers\vmnetuserif.sys -> [2008/10/28 22:01:32 | 00,026,288 | ---- | M] (VMware, Inc.)
(VMparport) VMware VMparport [Kernel | Auto | Running] -> C:\Windows\System32\Drivers\VMparport.sys -> [2008/10/28 22:01:20 | 00,014,896 | ---- | M] (VMware, Inc.)
(vmx86) VMware vmx86 [Kernel | Auto | Running] -> C:\Windows\System32\Drivers\vmx86.sys -> [2008/10/28 22:01:30 | 00,857,392 | ---- | M] (VMware, Inc.)
(vsmraid) vsmraid [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\vsmraid.sys -> [2008/01/21 10:21:32 | 00,130,616 | ---- | M] (VIA Technologies Inc.,Ltd)
(vstor2-ws60) Vstor2 WS60 Virtual Storage Driver [Kernel | Auto | Running] -> C:\Program Files\VMware\VMware Player\vstor2-ws60.sys -> [2008/10/02 17:24:48 | 00,022,448 | ---- | M] (VMware, Inc.)
(ZTEusbmdm6k) ZTE Proprietary USB Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\DRIVERS\ZTEusbmdm6k.sys -> [2008/04/19 05:05:22 | 00,103,936 | ---- | M] (ZTE Incorporated)
(ZTEusbnmea) ZTE NMEA Port [Kernel | On_Demand | Stopped] -> C:\Windows\System32\DRIVERS\ZTEusbnmea.sys -> [2008/04/19 05:05:22 | 00,103,936 | ---- | M] (ZTE Incorporated)
(ZTEusbser6k) ZTE Diagnostic Port [Kernel | On_Demand | Stopped] -> C:\Windows\System32\DRIVERS\ZTEusbser6k.sys -> [2008/04/19 05:05:22 | 00,103,936 | ---- | M] (ZTE Incorporated)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  [binary data] -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\Windows\System32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> 
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> 
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\] > -> -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\: Main\\"Local Page" -> C:\Windows\system32\blank.htm -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\: Main\\"Page_Transitions" -> 1 -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\: Main\\"Start Page" -> http://www.google.com.au/ -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\: Main\\"Start Page Redirect Cache" -> http://www.msn.com/ -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\: Main\\"Start Page Redirect Cache AcceptLangs" -> en-us -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\: Main\\"Start Page Redirect Cache_TIMESTAMP" -> 5C E8 15 4A 42 34 CA 01  [binary data] -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\: "ProxyEnable" -> 0 -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\: "ProxyOverride" -> <local> -> 
< FireFox Settings [Prefs.js] > -> C:\Users\brenton\AppData\Roaming\Mozilla\FireFox\Profiles\fy02zwzy.default\prefs.js -> 
browser.startup.homepage -> "http://www.facebook.com/home.php?|http://mail.google.com/mail/#inbox|http://finance.yahoo.com/|http://www.kitcometals.com/|http://www.anz.com/" ->
extensions.enabledItems -> {4DC70064-89E2-4a55-8FC6-E8CDEAE3612C}:0.6.5 ->
extensions.enabledItems -> {3f963a5b-e555-4543-90e2-c3908898db71}:8.5 ->
extensions.enabledItems -> {B9C8BE50-7105-4ec6-8FB4-4935C0671648}:0.5.99 ->
extensions.enabledItems -> {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090525 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}:6.0.06 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15 ->
extensions.enabledItems -> [email protected]:1.0.0.407 ->
extensions.enabledItems -> {20a82645-c095-46ed-80e3-08825760534b}:1.1 ->
extensions.enabledItems -> {FFA36170-80B1-4535-B0E3-A4569E497DD0}:2.0.3 ->
extensions.enabledItems -> [email protected]:2 ->
extensions.enabledItems -> 4 ->
extensions.enabledItems -> 7 ->
extensions.enabledItems -> 2 ->
extensions.enabledItems -> [email protected]:2.6.1 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions ->  -> 
HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} -> C:\PROGRAM FILES\AVG\AVG8\FIREFOX [C:\PROGRAM FILES\AVG\AVG8\FIREFOX] -> [2009/06/29 11:38:24 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/06/28 15:30:53 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions ->  -> 
HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components -> C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/09/12 01:07:49 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/09/12 01:07:49 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > -> 
 -> C:\Users\brenton\AppData\Roaming\mozilla\Extensions -> [2008/08/26 16:22:20 | 00,000,000 | ---D | M]
 -> C:\Users\brenton\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2008/08/26 16:22:20 | 00,000,000 | ---D | M]
 -> C:\Users\brenton\AppData\Roaming\mozilla\Firefox\Profiles\fy02zwzy.default\extensions -> [2009/09/12 01:08:00 | 00,097,924 | ---- | M] ()
 -> C:\Users\brenton\AppData\Roaming\mozilla\Firefox\Profiles\fy02zwzy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} -> [2009/09/12 01:08:00 | 00,097,924 | ---- | M] ()
 -> C:\Users\brenton\AppData\Roaming\mozilla\Firefox\Profiles\fy02zwzy.default\extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3612C} -> [2009/09/12 01:08:00 | 00,097,924 | ---- | M] ()
 -> C:\Users\brenton\AppData\Roaming\mozilla\Firefox\Profiles\fy02zwzy.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} -> [2009/09/12 01:08:00 | 00,097,924 | ---- | M] ()
 -> C:\Users\brenton\AppData\Roaming\mozilla\Firefox\Profiles\fy02zwzy.default\extensions\{B9C8BE50-7105-4ec6-8FB4-4935C0671648} -> [2009/09/12 01:08:00 | 00,097,924 | ---- | M] ()
 -> C:\Users\brenton\AppData\Roaming\mozilla\Firefox\Profiles\fy02zwzy.default\extensions\{FFA36170-80B1-4535-B0E3-A4569E497DD0} -> [2009/09/12 01:08:00 | 00,097,924 | ---- | M] ()
 -> C:\Users\brenton\AppData\Roaming\mozilla\Firefox\Profiles\fy02zwzy.default\extensions\[email protected] -> [2009/09/12 01:08:00 | 00,097,924 | ---- | M] ()
 -> C:\Users\brenton\AppData\Roaming\mozilla\Firefox\Profiles\fy02zwzy.default\extensions\[email protected] -> [2009/09/12 01:08:00 | 00,097,924 | ---- | M] ()
 -> C:\Users\brenton\AppData\Roaming\mozilla\Firefox\Profiles\fy02zwzy.default\extensions\[email protected] -> [2009/09/12 01:08:00 | 00,097,924 | ---- | M] ()
< FireFox Extensions [Program Folders] > -> 
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions -> [2009/09/12 01:07:49 | 09,767,928 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{231D7D17-4F1B-4933-AB61-E502DB82FD11} -> [2009/09/12 01:07:49 | 09,767,928 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/09/12 01:07:49 | 09,767,928 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} -> [2009/09/12 01:07:49 | 09,767,928 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} -> [2009/09/12 01:07:49 | 09,767,928 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} -> [2009/09/12 01:07:49 | 09,767,928 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} -> [2009/09/12 01:07:49 | 09,767,928 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} -> [2009/09/12 01:07:49 | 09,767,928 | ---- | M] (Mozilla Foundation)
< FireFox Components [Program Folders] > -> 
C:\PROGRAM FILES\MOZILLA FIREFOX\components\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\components -> [2009/09/12 01:07:49 | 00,000,000 | ---D | M]
browserdirprovider.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009/09/12 01:07:48 | 00,023,032 | ---- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009/09/12 01:07:48 | 00,134,648 | ---- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > -> 
C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins -> [2009/09/12 01:07:49 | 00,000,000 | ---D | M]
np-mswmp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\np-mswmp.dll -> [2007/04/10 17:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation)
np32dsw.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\np32dsw.dll -> [2008/08/06 16:22:02 | 00,114,688 | ---- | M] (Adobe Systems, Inc.)
npdeploytk.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npdeploytk.dll -> [2009/07/25 05:23:01 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.)
npnul32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009/09/12 01:07:48 | 00,065,528 | ---- | M] (mozilla.org)
nppdf32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\nppdf32.dll -> [2008/10/14 20:33:30 | 00,095,600 | ---- | M] (Adobe Systems Inc.)
npqtplugin.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin.dll -> [2009/07/05 18:08:30 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin2.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin2.dll -> [2009/07/05 18:08:30 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin3.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin3.dll -> [2009/07/05 18:08:30 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin4.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin4.dll -> [2009/07/05 18:08:30 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin5.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin5.dll -> [2009/07/05 18:08:30 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin6.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin6.dll -> [2009/07/05 18:08:30 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin7.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin7.dll -> [2009/07/05 18:08:30 | 00,143,360 | ---- | M] (Apple Inc.)
QuickTimePlugin.class -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\QuickTimePlugin.cla -> [2009/07/05 18:08:30 | 00,004,208 | ---- | M] ()
ShockwavePlugin.class -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\ShockwavePlugin.cla -> [2008/08/06 15:33:20 | 00,001,144 | ---- | M] ()
WMP Firefox Plugin License.rtf -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\WMP Firefox Plugin License.rtf -> [2007/03/30 10:43:58 | 00,149,569 | ---- | M] ()
WMP Firefox Plugin RelNotes.txt -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\WMP Firefox Plugin RelNotes.txt -> [2007/03/30 10:43:58 | 00,003,352 | ---- | M] ()
< FireFox SearchPlugins [Program Folders] > -> 
C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins -> [2009/07/26 14:05:10 | 00,000,000 | ---D | M]
amazon-en-GB.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\amazon-en-GB.xml -> [2009/07/26 14:05:08 | 00,001,538 | ---- | M] ()
answers.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\answers.xml -> [2009/07/26 14:05:08 | 00,002,193 | ---- | M] ()
chambers-en-GB.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\chambers-en-GB.xml -> [2009/07/26 14:05:08 | 00,000,947 | ---- | M] ()
creativecommons.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\creativecommons.xml -> [2009/07/26 14:05:08 | 00,001,534 | ---- | M] ()
eBay-en-GB.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\eBay-en-GB.xml -> [2009/07/26 14:05:08 | 00,000,759 | ---- | M] ()
google.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\google.xml -> [2009/07/26 14:05:08 | 00,001,706 | ---- | M] ()
wikipedia.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\wikipedia.xml -> [2009/07/26 14:05:08 | 00,001,178 | ---- | M] ()
yahoo-en-GB.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\yahoo-en-GB.xml -> [2009/07/26 14:05:08 | 00,000,831 | ---- | M] ()
< HOSTS File > (0 bytes and 0 lines) -> C:\Windows\System32\drivers\etc\Hosts -> 
Reset Hosts
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 22:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated)
{22BF413B-C6D2-4d91-82A9-A0F997BA588C} [HKLM] -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [Skype add-on (mastermind)] -> [2008/05/30 15:54:16 | 01,410,344 | ---- | M] (Skype Technologies S.A.)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> C:\Program Files\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2009/08/20 18:31:20 | 01,111,320 | ---- | M] (AVG Technologies CZ, s.r.o.)
{54445830-1BDA-41E6-9E4B-87305FED3DCF} [HKLM] -> C:\Windows\vanwxemggdr.dll [QXK Olive] -> File not found
{7E853D72-626A-48EC-A868-BA8D5E23E045} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2009/02/17 15:11:04 | 00,408,440 | ---- | M] (Microsoft Corporation)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2009/07/25 05:23:03 | 00,041,760 | ---- | M] (Sun Microsystems, Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{D0F811AD-FA98-436A-B4CE-B43F178537BE}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Adobe Reader Speed Launcher" -> C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/10/15 00:04:34 | 00,039,792 | ---- | M] (Adobe Systems Incorporated)
"AVG8_TRAY" -> C:\Program Files\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2009/08/20 18:31:18 | 02,007,832 | ---- | M] (AVG Technologies CZ, s.r.o.)
"BtTray" -> C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe ["C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe"] -> [2009/02/27 16:44:34 | 00,315,478 | ---- | M] ()
"EPSON Stylus CX4700 Series" -> C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIADP.EXE [C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIADP.EXE /F "C:\Windows\TEMP\E_SD0B6.tmp" /EF "HKLM"] -> [2005/02/02 04:00:00 | 00,098,304 | ---- | M] (SEIKO EPSON CORPORATION)
"JMB36X IDE Setup" -> C:\Windows\RaidTool\xInsIDE.exe [C:\Windows\RaidTool\xInsIDE.exe] -> [2007/03/20 14:36:18 | 00,036,864 | ---- | M] ()
"LogMeIn GUI" -> C:\Program Files\LogMeIn\x86\LogMeInSystray.exe ["C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"] -> [2008/07/24 18:46:10 | 00,063,048 | ---- | M] (LogMeIn, Inc.)
"NvCplDaemon" -> C:\Windows\System32\NvCpl.DLL [RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup] -> [2009/03/28 00:03:00 | 13,687,328 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" -> C:\Windows\System32\NvMcTray.DLL [RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit] -> [2009/03/28 00:03:00 | 00,092,704 | ---- | M] (NVIDIA Corporation)
"QuickTime Task" -> C:\Program Files\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> [2009/05/26 17:18:30 | 00,413,696 | ---- | M] (Apple Inc.)
"SunJavaUpdateSched" -> C:\Program Files\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2009/07/25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.)
"VMware hqtray" -> C:\Program Files\VMware\VMware Player\hqtray.exe ["C:\Program Files\VMware\VMware Player\hqtray.exe"] -> [2008/10/28 22:00:50 | 00,064,048 | ---- | M] (VMware, Inc.)
< Run [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Sidebar" -> C:\Program Files\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2009/04/11 14:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation)
"WindowsWelcomeCenter" -> C:\Windows\System32\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2009/04/11 14:28:23 | 02,153,472 | ---- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Sidebar" -> C:\Program Files\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2009/04/11 14:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation)
"WindowsWelcomeCenter" -> C:\Windows\System32\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2009/04/11 14:28:23 | 02,153,472 | ---- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\] > -> HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"DAEMON Tools Lite" -> C:\Program Files\DAEMON Tools Lite\daemon.exe ["C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun] -> [2008/08/08 20:11:12 | 00,490,952 | ---- | M] (DT Soft Ltd)
"ehTray.exe" -> C:\Windows\ehome\ehTray.exe [C:\Windows\ehome\ehTray.exe] -> [2008/01/21 10:23:22 | 00,125,952 | ---- | M] (Microsoft Corporation)
"Sidebar" -> C:\Program Files\Windows Sidebar\sidebar.exe [C:\Program Files\Windows Sidebar\sidebar.exe /autoRun] -> [2009/04/11 14:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation)
"Skype" -> C:\Program Files\Skype\Phone\Skype.exe ["C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized] -> [2008/05/30 15:54:14 | 21,718,312 | R--- | M] (Skype Technologies S.A.)
"WMPNSCFG" -> C:\Program Files\Windows Media Player\WMPNSCFG.exe [C:\Program Files\Windows Media Player\WMPNSCFG.exe] -> [2008/01/21 10:23:48 | 00,202,240 | ---- | M] (Microsoft Corporation)
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [255] -> File not found
\\"BindDirectlyToPropertySetStorage" ->  [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"ConsentPromptBehaviorAdmin" ->  [2] -> File not found
\\"ConsentPromptBehaviorUser" ->  [1] -> File not found
\\"EnableInstallerDetection" ->  [1] -> File not found
\\"EnableLUA" ->  [1] -> File not found
\\"EnableSecureUIAPaths" ->  [1] -> File not found
\\"EnableVirtualization" ->  [1] -> File not found
\\"PromptOnSecureDesktop" ->  [1] -> File not found
\\"ValidateAdminCodeSignatures" ->  [0] -> File not found
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"scforceoption" ->  [0] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"FilterAdministratorToken" ->  [0] -> File not found
\\"EnableUIADesktopToggle" ->  [0] -> File not found
\\"DisableRegistryTools" ->  [1] -> File not found
\\"DisableTaskMgr" ->  [1] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
\UIPI\Clipboard\ExceptionFormats\\"CF_TEXT" ->  [1] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_BITMAP" ->  [2] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_OEMTEXT" ->  [7] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIB" ->  [8] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_PALETTE" ->  [9] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_UNICODETEXT" ->  [13] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIBV5" ->  [17] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000] > -> HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{77BF5300-1474-4EC7-9980-D32B190E9B07}:{77BF5300-1474-4EC7-9980-D32B190E9B07} [HKLM] -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [Button: Skype] -> [2008/05/30 15:54:16 | 01,410,344 | ---- | M] (Skype Technologies S.A.)
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\] > -> HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\] > -> HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-21-2663051174-626813573-3717304182-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab [Java Plug-in 1.6.0_15] -> 
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [Reg Error: Key error.] -> 
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab [Java Plug-in 1.6.0_06] -> 
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> 
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab [Java Plug-in 1.6.0_15] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab [Java Plug-in 1.6.0_15] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> 
DhcpNameServer -> 192.168.2.1 -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{68C8324E-2162-4CA3-956A-1B5971B17194}\\DhcpNameServer -> 192.168.2.1   (Realtek PCIe GBE Family Controller) -> 
{68C8324E-2162-4CA3-956A-1B5971B17194}\\NameServer -> 203.21.20.20,203.10.1.9   (Realtek PCIe GBE Family Controller) -> 
{6A979143-28BF-44AD-8200-ECCD33D60EDA}\\DhcpNameServer -> 192.168.15.10 192.168.59.5 192.168.59.7   () -> 
{6D524227-E6D7-4B91-9549-CD0AD5C11872}\\DhcpNameServer -> 192.168.2.1   (Atheros AR5005GS Wireless Network Adapter) -> 
{6D524227-E6D7-4B91-9549-CD0AD5C11872}\\NameServer -> 203.21.20.20,203.10.1.9   (Atheros AR5005GS Wireless Network Adapter) -> 
IE Styles -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> 
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> 
avgrsstx.dll -> C:\Windows\System32\avgrsstx.dll -> [2009/08/20 18:31:24 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.)
*MultiFile Done* -> -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
Explorer.exe -> C:\Windows\explorer.exe -> [2009/04/11 14:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler -> 
"{E31004D1-A431-41B8-826F-E902F9D95C81}" [HKLM] -> C:\Windows\System32\DreamScene.dll [Windows DreamScene] -> [2007/07/20 07:55:46 | 00,233,888 | ---- | M] (Microsoft Corporation)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> 
"%windir%\system32\winav.exe" -> C:\Windows\System32\winav.exe [%windir%\system32\winav.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Program Files\TESTOUT\Cmi\Navigator.exe" -> C:\Program Files\TESTOUT\Cmi\Navigator.exe [C:\Program Files\TESTOUT\Cmi\Navigator.exe:*:Disabled:TestOut Navigator] -> [2005/10/28 23:09:16 | 01,115,776 | ---- | M] (TestOut Corporation)
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\autorun.exe" -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\autorun.exe [C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\autorun.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Users\brenton\AppData\Roaming\mcrupdate.exe" -> C:\Users\brenton\AppData\Roaming\mcrupdate.exe [C:\Users\brenton\AppData\Roaming\mcrupdate.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Users\brenton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\findfast.exe" -> C:\Users\brenton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\findfast.exe [C:\Users\brenton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\findfast.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Users\brenton\AppData\Roaming\printer.exe" -> C:\Users\brenton\AppData\Roaming\printer.exe [C:\Users\brenton\AppData\Roaming\printer.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Windows\shell.exe" -> C:\Windows\shell.exe [C:\Windows\shell.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Windows\system32\printer.exe" -> C:\Windows\System32\printer.exe [C:\Windows\system32\printer.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Windows\system32\spoolvs.exe" -> C:\Windows\System32\spoolvs.exe [C:\Windows\system32\spoolvs.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"%windir%\system32\winav.exe" -> C:\Windows\System32\winav.exe [%windir%\system32\winav.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Program Files\TESTOUT\Cmi\Navigator.exe" -> C:\Program Files\TESTOUT\Cmi\Navigator.exe [C:\Program Files\TESTOUT\Cmi\Navigator.exe:*:Disabled:TestOut Navigator] -> [2005/10/28 23:09:16 | 01,115,776 | ---- | M] (TestOut Corporation)
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\autorun.exe" -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\autorun.exe [C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\autorun.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Users\brenton\AppData\Roaming\mcrupdate.exe" -> C:\Users\brenton\AppData\Roaming\mcrupdate.exe [C:\Users\brenton\AppData\Roaming\mcrupdate.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Users\brenton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\findfast.exe" -> C:\Users\brenton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\findfast.exe [C:\Users\brenton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\findfast.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Users\brenton\AppData\Roaming\printer.exe" -> C:\Users\brenton\AppData\Roaming\printer.exe [C:\Users\brenton\AppData\Roaming\printer.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Windows\shell.exe" -> C:\Windows\shell.exe [C:\Windows\shell.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Windows\system32\printer.exe" -> C:\Windows\System32\printer.exe [C:\Windows\system32\printer.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
"C:\Windows\system32\spoolvs.exe" -> C:\Windows\System32\spoolvs.exe [C:\Windows\system32\spoolvs.exe:*:Enabled:@xpsp2res.dll,-22019] -> File not found
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" ->  [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > ->  -> 
C:\autoexec.bat [REM Dummy file for NTVDM | ] -> C:\autoexec.bat [ NTFS ] -> [2006/09/19 05:43:36 | 00,000,024 | ---- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
\{4831b296-2c9a-11dd-9c81-8460583f6139}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4831b296-2c9a-11dd-9c81-8460583f6139}\shell
\{4831b296-2c9a-11dd-9c81-8460583f6139}\shell\\"" ->  [Autorun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4831b296-2c9a-11dd-9c81-8460583f6139}\shell\Open\command
\{4831b296-2c9a-11dd-9c81-8460583f6139}\shell\Open\command\\"" ->  [Recycled.exe e] -> File not found
\{b0e91b9e-a1d3-11dd-a81a-005056c00008}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b0e91b9e-a1d3-11dd-a81a-005056c00008}\shell
\{b0e91b9e-a1d3-11dd-a81a-005056c00008}\shell\\"" ->  [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b0e91b9e-a1d3-11dd-a81a-005056c00008}\shell\AutoRun\command
\{b0e91b9e-a1d3-11dd-a81a-005056c00008}\shell\AutoRun\command\\"" -> D:\Autorun.exe [D:\Autorun.exe] -> File not found
 
[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 9/13/2009 4:43:47 AM Computer Name = ferrari | Source = vmauthd | ID = 100 -> Description = SetServiceStatus error 1722   
Application [ Error ] 9/13/2009 4:46:42 AM Computer Name = ferrari | Source = EventSystem | ID = 4609 -> Description = 
Application [ Error ] 9/13/2009 4:47:15 AM Computer Name = ferrari | Source = WinMgmt | ID = 10 -> Description = 
Application [ Error ] 9/13/2009 4:50:17 AM Computer Name = ferrari | Source = WinMgmt | ID = 10 -> Description = 
Application [ Error ] 9/13/2009 4:51:20 AM Computer Name = ferrari | Source = EventSystem | ID = 4609 -> Description = 
Application [ Error ] 9/13/2009 5:13:18 AM Computer Name = ferrari | Source = WinMgmt | ID = 10 -> Description = 
Application [ Error ] 9/13/2009 5:27:20 AM Computer Name = ferrari | Source = EventSystem | ID = 4609 -> Description = 
Application [ Error ] 9/13/2009 5:32:08 AM Computer Name = ferrari | Source = WinMgmt | ID = 10 -> Description = 
Application [ Error ] 9/13/2009 5:32:16 AM Computer Name = ferrari | Source = Application Error | ID = 1000 -> Description = Faulting application IEXPLORE.EXE, version 8.0.6001.18813, time stamp 0x4a6621ae, faulting module D49DECF2.x86.dll, version 0.0.0.0, time stamp 0x4a97f4f7, exception code 0xc0000005, fault offset 0x00004182,  process id 0xf3c, application start time 0x01ca3454fce8482a.
Application [ Error ] 9/13/2009 5:32:38 AM Computer Name = ferrari | Source = Application Error | ID = 1000 -> Description = Faulting application IEXPLORE.EXE, version 8.0.6001.18813, time stamp 0x4a6621ae, faulting module D49DECF2.x86.dll, version 0.0.0.0, time stamp 0x4a97f4f7, exception code 0xc0000005, fault offset 0x00004182,  process id 0x1224, application start time 0x01ca3455162a0a8a.
Media Center [ Error ] 12/5/2008 10:56:16 PM Computer Name = ferrari | Source = McrMgr | ID = 109 -> Description = 
Media Center [ Error ] 1/30/2009 5:00:24 AM Computer Name = ferrari | Source = Mcx2Svc | ID = 301 -> Description = 
Media Center [ Error ] 2/4/2009 9:04:42 AM Computer Name = ferrari | Source = Mcx2Svc | ID = 301 -> Description = 
Media Center [ Error ] 2/4/2009 9:14:57 AM Computer Name = ferrari | Source = Mcx2Svc | ID = 301 -> Description = 
Media Center [ Error ] 2/4/2009 9:15:20 AM Computer Name = ferrari | Source = Mcx2Svc | ID = 301 -> Description = 
Media Center [ Error ] 2/4/2009 9:15:45 AM Computer Name = ferrari | Source = Mcx2Svc | ID = 301 -> Description = 
System [ Error ] 9/13/2009 5:27:21 AM Computer Name = ferrari | Source = Service Control Manager | ID = 7001 -> Description = 
System [ Error ] 9/13/2009 5:27:21 AM Computer Name = ferrari | Source = Service Control Manager | ID = 7001 -> Description = 
System [ Error ] 9/13/2009 5:27:54 AM Computer Name = ferrari | Source = Service Control Manager | ID = 7001 -> Description = 
System [ Error ] 9/13/2009 5:27:55 AM Computer Name = ferrari | Source = DCOM | ID = 10005 -> Description = 
System [ Error ] 9/13/2009 5:27:55 AM Computer Name = ferrari | Source = Service Control Manager | ID = 7001 -> Description = 
System [ Error ] 9/13/2009 5:27:55 AM Computer Name = ferrari | Source = DCOM | ID = 10005 -> Description = 
System [ Error ] 9/13/2009 5:29:31 AM Computer Name = ferrari | Source = DCOM | ID = 10005 -> Description = 
System [ Error ] 9/13/2009 5:30:52 AM Computer Name = ferrari | Source = Microsoft-Windows-TaskScheduler | ID = 412 -> Description = 
System [ Error ] 9/13/2009 5:32:08 AM Computer Name = ferrari | Source = Service Control Manager | ID = 7000 -> Description = 
System [ Error ] 9/13/2009 5:32:08 AM Computer Name = ferrari | Source = Service Control Manager | ID = 7026 -> Description = 
 
[Files/Folders - Created Within 30 Days]
alg.exe -> C:\Users\brenton\alg.exe -> [2009/09/13 20:07:07 | 00,514,560 | ---- | C] (OldTimer Tools)
Apps -> C:\Users\brenton\AppData\Local\Apps -> [2009/09/13 19:48:39 | 00,000,000 | ---D | C]
hiberfil.sys -> C:\hiberfil.sys -> [2009/09/13 17:30:26 | 21,459,02592 | -HS- | C] ()
Test1-Malwarebytes' Anti-Malware -> C:\Program Files\Test1-Malwarebytes' Anti-Malware -> [2009/09/13 17:28:11 | 00,000,000 | ---D | C]
PIF -> C:\Windows\PIF -> [2009/09/13 16:55:01 | 00,000,000 | -H-D | C]
Test-Malwarebytes' Anti-Malware -> C:\Program Files\Test-Malwarebytes' Anti-Malware -> [2009/09/13 16:53:15 | 00,000,000 | ---D | C]
Malwarebytes -> C:\Users\brenton\AppData\Roaming\Malwarebytes -> [2009/09/13 16:39:08 | 00,000,000 | ---D | C]
Malwarebytes' Anti-Malware.lnk -> C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/09/13 16:39:07 | 00,000,818 | ---- | C] ()
mbamswissarmy.sys -> C:\Windows\System32\drivers\mbamswissarmy.sys -> [2009/09/13 16:39:04 | 00,038,224 | ---- | C] (Malwarebytes Corporation)
mbam.sys -> C:\Windows\System32\drivers\mbam.sys -> [2009/09/13 16:39:03 | 00,019,160 | ---- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2009/09/13 16:39:03 | 00,000,000 | ---D | C]
Malwarebytes -> C:\ProgramData\Malwarebytes -> [2009/09/13 16:39:03 | 00,000,000 | ---D | C]
torrents -> C:\Users\brenton\Documents\torrents -> [2009/09/12 09:37:47 | 00,000,000 | ---D | C]
tcpip.sys -> C:\Windows\System32\drivers\tcpip.sys -> [2009/09/09 04:47:23 | 00,904,776 | ---- | C] (Microsoft Corporation)
netiohlp.dll -> C:\Windows\System32\netiohlp.dll -> [2009/09/09 04:47:23 | 00,105,984 | ---- | C] (Microsoft Corporation)
tcpipreg.sys -> C:\Windows\System32\drivers\tcpipreg.sys -> [2009/09/09 04:47:22 | 00,030,720 | ---- | C] (Microsoft Corporation)
NETSTAT.EXE -> C:\Windows\System32\NETSTAT.EXE -> [2009/09/09 04:47:22 | 00,027,136 | ---- | C] (Microsoft Corporation)
ARP.EXE -> C:\Windows\System32\ARP.EXE -> [2009/09/09 04:47:22 | 00,019,968 | ---- | C] (Microsoft Corporation)
ROUTE.EXE -> C:\Windows\System32\ROUTE.EXE -> [2009/09/09 04:47:22 | 00,017,920 | ---- | C] (Microsoft Corporation)
netevent.dll -> C:\Windows\System32\netevent.dll -> [2009/09/09 04:47:22 | 00,017,920 | ---- | C] (Microsoft Corporation)
MRINFO.EXE -> C:\Windows\System32\MRINFO.EXE -> [2009/09/09 04:47:22 | 00,011,264 | ---- | C] (Microsoft Corporation)
finger.exe -> C:\Windows\System32\finger.exe -> [2009/09/09 04:47:22 | 00,010,240 | ---- | C] (Microsoft Corporation)
TCPSVCS.EXE -> C:\Windows\System32\TCPSVCS.EXE -> [2009/09/09 04:47:22 | 00,009,728 | ---- | C] (Microsoft Corporation)
HOSTNAME.EXE -> C:\Windows\System32\HOSTNAME.EXE -> [2009/09/09 04:47:22 | 00,008,704 | ---- | C] (Microsoft Corporation)
wlansec.dll -> C:\Windows\System32\wlansec.dll -> [2009/09/09 04:22:54 | 00,302,592 | ---- | C] (Microsoft Corporation)
wlanmsm.dll -> C:\Windows\System32\wlanmsm.dll -> [2009/09/09 04:22:54 | 00,293,376 | ---- | C] (Microsoft Corporation)
L2SecHC.dll -> C:\Windows\System32\L2SecHC.dll -> [2009/09/09 04:22:54 | 00,127,488 | ---- | C] (Microsoft Corporation)
wlan.tmf -> C:\Windows\System32\wlan.tmf -> [2009/09/09 04:22:53 | 02,501,921 | ---- | C] ()
wlansvc.dll -> C:\Windows\System32\wlansvc.dll -> [2009/09/09 04:22:53 | 00,513,536 | ---- | C] (Microsoft Corporation)
wlanapi.dll -> C:\Windows\System32\wlanapi.dll -> [2009/09/09 04:22:53 | 00,065,024 | ---- | C] (Microsoft Corporation)
mf.dll -> C:\Windows\System32\mf.dll -> [2009/09/09 04:22:48 | 02,868,224 | ---- | C] (Microsoft Corporation)
WMVCORE.DLL -> C:\Windows\System32\WMVCORE.DLL -> [2009/09/09 04:22:48 | 02,386,944 | ---- | C] (Microsoft Corporation)
jscript.dll -> C:\Windows\System32\jscript.dll -> [2009/09/09 04:22:31 | 00,726,528 | ---- | C] (Microsoft Corporation)
tax info 0809.ods -> C:\Users\brenton\Documents\tax info 0809.ods -> [2009/09/08 22:13:37 | 00,019,507 | ---- | C] ()
tzres.dll -> C:\Windows\System32\tzres.dll -> [2009/09/05 15:10:19 | 00,002,048 | ---- | C] (Microsoft Corporation)
JMB36X_WinDrv_R1.17.50_WHQL -> C:\JMB36X_WinDrv_R1.17.50_WHQL -> [2009/09/03 18:53:47 | 00,000,000 | ---D | C]
Microsoft Corporation -> C:\Users\brenton\AppData\Local\Microsoft Corporation -> [2009/09/03 17:32:36 | 00,000,000 | ---D | C]
Windows 7 Upgrade Advisor Beta.lnk -> C:\Users\brenton\Desktop\Windows 7 Upgrade Advisor Beta.lnk -> [2009/09/03 17:32:17 | 00,002,048 | ---- | C] ()
Microsoft Windows 7 Upgrade Advisor -> C:\Program Files\Microsoft Windows 7 Upgrade Advisor -> [2009/09/03 17:32:16 | 00,000,000 | ---D | C]
Apphlpdm.dll -> C:\Windows\System32\Apphlpdm.dll -> [2009/09/03 08:21:54 | 00,028,672 | ---- | C] (Microsoft Corporation)
GameUXLegacyGDFs.dll -> C:\Windows\System32\GameUXLegacyGDFs.dll -> [2009/09/03 08:21:53 | 04,240,384 | ---- | C] (Microsoft)
wa_residential_tenancy_kit -> C:\Users\brenton\Desktop\wa_residential_tenancy_kit -> [2009/08/16 19:12:37 | 00,000,000 | ---D | C]
lsasrv.dll -> C:\Windows\System32\lsasrv.dll -> [2009/08/16 11:06:29 | 01,259,008 | ---- | C] (Microsoft Corporation)
kerberos.dll -> C:\Windows\System32\kerberos.dll -> [2009/08/16 11:06:29 | 00,499,712 | ---- | C] (Microsoft Corporation)
ksecdd.sys -> C:\Windows\System32\drivers\ksecdd.sys -> [2009/08/16 11:06:29 | 00,439,864 | ---- | C] (Microsoft Corporation)
schannel.dll -> C:\Windows\System32\schannel.dll -> [2009/08/16 11:06:29 | 00,270,848 | ---- | C] (Microsoft Corporation)
msv1_0.dll -> C:\Windows\System32\msv1_0.dll -> [2009/08/16 11:06:29 | 00,218,624 | ---- | C] (Microsoft Corporation)
wdigest.dll -> C:\Windows\System32\wdigest.dll -> [2009/08/16 11:06:29 | 00,175,104 | ---- | C] (Microsoft Corporation)
secur32.dll -> C:\Windows\System32\secur32.dll -> [2009/08/16 11:06:29 | 00,072,704 | ---- | C] (Microsoft Corporation)
lsass.exe -> C:\Windows\System32\lsass.exe -> [2009/08/16 11:06:29 | 00,009,728 | ---- | C] (Microsoft Corporation)
xlive.dll.cat -> C:\Windows\System32\xlive.dll.cat -> [2009/08/07 19:51:34 | 00,178,430 | ---- | C] ()
OGACheckControl.dll -> C:\Windows\System32\OGACheckControl.dll -> [2009/08/03 15:07:42 | 00,403,816 | ---- | C] ()
EhStorAuthn.dll -> C:\Windows\System32\EhStorAuthn.dll -> [2009/06/28 15:53:03 | 00,117,248 | ---- | C] ()
SHORTCUT.INI -> C:\Windows\System32\SHORTCUT.INI -> [2009/06/10 21:26:44 | 00,002,235 | ---- | C] ()
REMOTEDEVICE.INI -> C:\Windows\System32\REMOTEDEVICE.INI -> [2009/06/10 21:26:22 | 00,000,132 | ---- | C] ()
LOCALSERVICE.INI -> C:\Windows\System32\LOCALSERVICE.INI -> [2009/06/10 21:25:46 | 00,006,019 | ---- | C] ()
LOCALDEVICE.INI -> C:\Windows\System32\LOCALDEVICE.INI -> [2009/06/10 21:25:39 | 00,000,099 | ---- | C] ()
BSPRINT.INI -> C:\Windows\System32\BSPRINT.INI -> [2009/06/10 21:19:51 | 00,000,000 | ---- | C] ()
avisplitter.INI -> C:\Windows\avisplitter.INI -> [2009/06/03 22:25:17 | 00,000,038 | ---- | C] ()
bscs.ini -> C:\Windows\System32\bscs.ini -> [2009/04/20 10:13:34 | 00,001,082 | ---- | C] ()
RtNicProp32.dll -> C:\Windows\System32\RtNicProp32.dll -> [2009/03/05 06:54:58 | 00,073,728 | ---- | C] ()
BsUI.dll -> C:\Windows\System32\BsUI.dll -> [2009/02/27 16:45:16 | 00,405,589 | ---- | C] ()
outlookAddin.dll -> C:\Windows\System32\outlookAddin.dll -> [2009/02/27 16:44:50 | 00,278,647 | ---- | C] ()
HtmPrintHelper.dll -> C:\Windows\System32\HtmPrintHelper.dll -> [2009/02/27 16:44:28 | 00,053,248 | ---- | C] ()
BSShell.dll -> C:\Windows\System32\BSShell.dll -> [2009/02/27 16:44:10 | 00,622,693 | ---- | C] ()
Bs2Res.dll -> C:\Windows\System32\Bs2Res.dll -> [2009/02/27 16:41:38 | 00,098,403 | ---- | C] ()
BsMobileSDK.dll -> C:\Windows\System32\BsMobileSDK.dll -> [2009/02/27 16:41:02 | 00,122,976 | ---- | C] ()
BsMobileCSps.dll -> C:\Windows\System32\BsMobileCSps.dll -> [2009/02/27 16:40:50 | 00,028,672 | ---- | C] ()
vnetinst.dll -> C:\Windows\System32\vnetinst.dll -> [2009/01/27 17:08:23 | 00,055,856 | ---- | C] ()
btnetBus.sys -> C:\Windows\System32\drivers\btnetBus.sys -> [2008/12/07 12:44:54 | 00,030,088 | ---- | C] ()
sptd.sys -> C:\Windows\System32\drivers\sptd.sys -> [2008/10/24 21:56:28 | 00,717,296 | ---- | C] ()
BsVistaCommon.dll -> C:\Windows\System32\BsVistaCommon.dll -> [2008/10/22 15:30:30 | 00,081,920 | ---- | C] ()
NeroDigital.ini -> C:\Windows\NeroDigital.ini -> [2008/09/05 18:16:06 | 00,000,069 | ---- | C] ()
GSetup.ini -> C:\Windows\GSetup.ini -> [2008/07/27 21:25:36 | 00,000,010 | ---- | C] ()
unrar.dll -> C:\Windows\System32\unrar.dll -> [2008/06/15 15:59:04 | 00,164,352 | ---- | C] ()
BsLangInDepRes.dll -> C:\Windows\System32\BsLangInDepRes.dll -> [2008/03/07 13:54:22 | 17,907,824 | ---- | C] ()
libcurl.dll -> C:\Windows\System32\libcurl.dll -> [2008/03/04 17:52:34 | 00,286,720 | ---- | C] ()
manage-bde.ini.en -> C:\Windows\System32\manage-bde.ini.en -> [2008/01/21 10:23:41 | 00,081,158 | ---- | C] ()
zlib1.dll -> C:\Windows\System32\zlib1.dll -> [2007/10/31 08:39:54 | 00,059,904 | ---- | C] ()
libexpatw.dll -> C:\Windows\System32\libexpatw.dll -> [2007/05/17 12:58:10 | 00,143,360 | ---- | C] ()
sysprepMCE.dll -> C:\Windows\System32\sysprepMCE.dll -> [2006/11/02 20:34:20 | 00,005,632 | ---- | C] ()
atitmmxx.dll -> C:\Windows\System32\atitmmxx.dll -> [2006/11/02 18:25:44 | 00,159,744 | ---- | C] ()
system.ini -> C:\Windows\system.ini -> [2006/11/02 18:23:31 | 00,000,219 | ---- | C] ()
win.ini -> C:\Windows\win.ini -> [2006/11/02 18:23:31 | 00,000,144 | ---- | C] ()
cngaudit.dll -> C:\Windows\System32\cngaudit.dll -> [2006/11/02 16:43:04 | 00,061,952 | ---- | C] ()
pacerprf.ini -> C:\Windows\System32\pacerprf.ini -> [2006/11/02 15:40:29 | 00,013,750 | ---- | C] ()
Wh2Robo.dll -> C:\Windows\System32\Wh2Robo.dll -> [2000/01/31 08:02:00 | 00,047,104 | ---- | C] ()
 
[Files/Folders - Modified Within 30 Days]
319 C:\Users\brenton\AppData\Local\Temp\*.tmp files -> C:\Users\brenton\AppData\Local\Temp\*.tmp -> 
NTUSER.DAT -> C:\Users\brenton\NTUSER.DAT -> [2009/09/13 20:11:16 | 02,359,296 | -HS- | M] ()
alg.exe -> C:\Users\brenton\alg.exe -> [2009/09/13 20:07:10 | 00,514,560 | ---- | M] (OldTimer Tools)
PerfStringBackup.INI -> C:\Windows\System32\PerfStringBackup.INI -> [2009/09/13 19:59:30 | 00,751,290 | ---- | M] ()
perfh009.dat -> C:\Windows\System32\perfh009.dat -> [2009/09/13 19:59:30 | 00,636,534 | ---- | M] ()
perfc009.dat -> C:\Windows\System32\perfc009.dat -> [2009/09/13 19:59:30 | 00,118,248 | ---- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Users\brenton\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/09/13 19:53:37 | 00,160,768 | ---- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2009/09/13 19:30:50 | 00,003,760 | -H-- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2009/09/13 19:30:50 | 00,003,760 | -H-- | M] ()
LOCALSERVICE.INI -> C:\Windows\System32\LOCALSERVICE.INI -> [2009/09/13 17:30:59 | 00,006,019 | ---- | M] ()
bscs.ini -> C:\Windows\System32\bscs.ini -> [2009/09/13 17:30:55 | 00,001,082 | ---- | M] ()
SA.DAT -> C:\Windows\tasks\SA.DAT -> [2009/09/13 17:30:52 | 00,000,006 | -H-- | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2009/09/13 17:30:33 | 00,067,584 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/09/13 17:30:26 | 21,459,02592 | -HS- | M] ()
NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\brenton\NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/13 17:29:44 | 00,524,288 | -HS- | M] ()
NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TM.blf -> C:\Users\brenton\NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TM.blf -> [2009/09/13 17:29:44 | 00,065,536 | -HS- | M] ()
MEMORY.DMP -> C:\Windows\MEMORY.DMP -> [2009/09/13 17:11:56 | 15,964,4853 | ---- | M] ()
User_Feed_Synchronization-{63B6EC25-FDA1-4089-96A5-81CA5DC576D1}.job -> C:\Windows\tasks\User_Feed_Synchronization-{63B6EC25-FDA1-4089-96A5-81CA5DC576D1}.job -> [2009/09/13 16:43:30 | 00,000,422 | -H-- | M] ()
Malwarebytes' Anti-Malware.lnk -> C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/09/13 16:39:07 | 00,000,818 | ---- | M] ()
incavi.avm -> C:\Windows\System32\drivers\Avg\incavi.avm -> [2009/09/13 15:00:12 | 41,033,455 | ---- | M] ()
microavi.avg -> C:\Windows\System32\drivers\Avg\microavi.avg -> [2009/09/13 15:00:12 | 00,095,802 | ---- | M] ()
PublishedRacMonSWITable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonSWITable.DAT -> [2009/09/13 00:07:48 | 00,186,304 | ---- | M] ()
PublishedRacMonAFLTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonAFLTable.DAT -> [2009/09/13 00:07:48 | 00,011,868 | ---- | M] ()
PublishedRacMonIndex.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonIndex.DAT -> [2009/09/13 00:07:48 | 00,008,760 | ---- | M] ()
PublishedRacMonOSFTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonOSFTable.DAT -> [2009/09/13 00:07:48 | 00,005,520 | ---- | M] ()
PublishedRacMonHFLTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonHFLTable.DAT -> [2009/09/13 00:07:48 | 00,000,000 | ---- | M] ()
PublishedRacMonCLKTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonCLKTable.DAT -> [2009/09/13 00:07:48 | 00,000,000 | ---- | M] ()
default.pls -> C:\Users\brenton\AppData\Roaming\default.pls -> [2009/09/12 09:42:44 | 00,000,095 | ---- | M] ()
qmgr1.dat -> C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat -> [2009/09/11 02:25:42 | 04,194,304 | ---- | M] ()
qmgr0.dat -> C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat -> [2009/09/11 02:25:42 | 04,194,304 | ---- | M] ()
mbamswissarmy.sys -> C:\Windows\System32\drivers\mbamswissarmy.sys -> [2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation)
mbam.sys -> C:\Windows\System32\drivers\mbam.sys -> [2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation)
a.dat -> C:\Users\brenton\AppData\Local\Temp\a.dat -> [2009/09/09 17:59:05 | 00,013,524 | ---- | M] ()
mpengine.dll -> C:\Users\brenton\AppData\Local\Temp\mpengine.dll -> [2009/09/09 07:58:29 | 05,395,280 | ---- | M] (Microsoft Corporation)
b.exe -> C:\Users\brenton\AppData\Local\Temp\b.exe -> [2009/09/09 07:30:05 | 00,158,208 | ---- | M] ()
tax info 0809.ods -> C:\Users\brenton\Documents\tax info 0809.ods -> [2009/09/08 23:38:09 | 00,019,507 | ---- | M] ()
Windows 7 Upgrade Advisor Beta.lnk -> C:\Users\brenton\Desktop\Windows 7 Upgrade Advisor Beta.lnk -> [2009/09/03 17:32:17 | 00,002,048 | ---- | M] ()
GameUXLegacyGDFs.dll -> C:\Windows\System32\GameUXLegacyGDFs.dll -> [2009/08/29 08:27:49 | 04,240,384 | ---- | M] (Microsoft)
Apphlpdm.dll -> C:\Windows\System32\Apphlpdm.dll -> [2009/08/29 08:14:38 | 00,028,672 | ---- | M] (Microsoft Corporation)
mrt.exe -> C:\Windows\System32\mrt.exe -> [2009/08/29 05:38:20 | 24,689,600 | ---- | M] ()
LOCALDEVICE.INI -> C:\Windows\System32\LOCALDEVICE.INI -> [2009/08/24 20:36:27 | 00,000,099 | ---- | M] ()
REMOTEDEVICE.INI -> C:\Windows\System32\REMOTEDEVICE.INI -> [2009/08/23 21:01:40 | 00,000,132 | ---- | M] ()
avgldx86.sys -> C:\Windows\System32\drivers\avgldx86.sys -> [2009/08/20 18:31:24 | 00,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgmfx86.sys -> C:\Windows\System32\drivers\avgmfx86.sys -> [2009/08/20 18:31:24 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgrsstx.dll -> C:\Windows\System32\avgrsstx.dll -> [2009/08/20 18:31:24 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.)
Default.rdp -> C:\Users\brenton\Documents\Default.rdp -> [2009/08/18 22:12:22 | 00,001,812 | -H-- | M] ()
tcpip.sys -> C:\Windows\System32\drivers\tcpip.sys -> [2009/08/15 00:27:34 | 00,904,776 | ---- | M] (Microsoft Corporation)
netevent.dll -> C:\Windows\System32\netevent.dll -> [2009/08/14 23:53:34 | 00,017,920 | ---- | M] (Microsoft Corporation)
TCPSVCS.EXE -> C:\Windows\System32\TCPSVCS.EXE -> [2009/08/14 21:49:20 | 00,009,728 | ---- | M] (Microsoft Corporation)
ROUTE.EXE -> C:\Windows\System32\ROUTE.EXE -> [2009/08/14 21:49:18 | 00,017,920 | ---- | M] (Microsoft Corporation)
MRINFO.EXE -> C:\Windows\System32\MRINFO.EXE -> [2009/08/14 21:49:18 | 00,011,264 | ---- | M] (Microsoft Corporation)
NETSTAT.EXE -> C:\Windows\System32\NETSTAT.EXE -> [2009/08/14 21:49:15 | 00,027,136 | ---- | M] (Microsoft Corporation)
ARP.EXE -> C:\Windows\System32\ARP.EXE -> [2009/08/14 21:49:14 | 00,019,968 | ---- | M] (Microsoft Corporation)
HOSTNAME.EXE -> C:\Windows\System32\HOSTNAME.EXE -> [2009/08/14 21:49:14 | 00,008,704 | ---- | M] (Microsoft Corporation)
finger.exe -> C:\Windows\System32\finger.exe -> [2009/08/14 21:49:13 | 00,010,240 | ---- | M] (Microsoft Corporation)
tcpipreg.sys -> C:\Windows\System32\drivers\tcpipreg.sys -> [2009/08/14 21:48:21 | 00,030,720 | ---- | M] (Microsoft Corporation)
netiohlp.dll -> C:\Windows\System32\netiohlp.dll -> [2009/08/14 21:48:02 | 00,105,984 | ---- | M] (Microsoft Corporation)
jre-6u15-windows-i586-iftw.exe -> C:\Users\brenton\AppData\Local\Temp\jre-6u15-windows-i586-iftw.exe -> [2009/08/02 01:29:47 | 00,714,528 | ---- | M] (Sun Microsystems, Inc.)
SkypeSetup.exe -> C:\Users\brenton\AppData\Local\Temp\SkypeSetup.exe -> [2009/06/28 03:05:32 | 00,005,120 | ---- | M] ()
isnetfx.exe -> C:\Users\brenton\AppData\Local\Temp\{E4BBFCF0-F825-44F1-B908-040A5B787E4E}\isnetfx.exe -> [2009/06/10 20:12:51 | 00,431,392 | ---- | M] (Acresso Software Inc.)
jre-6u13-windows-i586-p-iftw.exe -> C:\Users\brenton\AppData\Local\Temp\jre-6u13-windows-i586-p-iftw.exe -> [2009/05/21 08:34:08 | 00,607,640 | ---- | M] (Sun Microsystems, Inc.)
Mcx2.dat -> C:\ProgramData\Microsoft\User Account Pictures\Mcx2.dat -> [2008/12/06 10:49:49 | 00,000,000 | ---- | M] ()
Mcx1.dat -> C:\ProgramData\Microsoft\User Account Pictures\Mcx1.dat -> [2008/12/01 19:30:32 | 00,000,000 | ---- | M] ()
hhcolreg.dat -> C:\ProgramData\Microsoft\HTML Help\hhcolreg.dat -> [2008/09/26 10:02:38 | 00,000,184 | ---- | M] ()
index.dat -> C:\Windows\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2008/06/29 16:25:59 | 00,032,768 | -HS- | M] ()
index.dat -> C:\Windows\Temp\History\History.IE5\index.dat -> [2008/06/29 16:25:59 | 00,016,384 | -HS- | M] ()
index.dat -> C:\Windows\Temp\Cookies\index.dat -> [2008/06/29 16:25:59 | 00,016,384 | -HS- | M] ()
brenton.dat -> C:\ProgramData\Microsoft\User Account Pictures\brenton.dat -> [2008/05/27 22:42:19 | 00,000,000 | ---- | M] ()
_isE88F.exe -> C:\Users\brenton\AppData\Local\Temp\_isE88F.exe -> [2008/01/21 10:39:16 | 00,455,600 | R--- | M] (Macrovision Corporation)
_Setup.dll -> C:\Users\brenton\AppData\Local\Temp\{C3413D50-1C59-4887-9C58-A97928C26626}\_Setup.dll -> [2008/01/21 10:39:16 | 00,385,968 | R--- | M] (Macrovision Corporation)
ISSetup.dll -> C:\Users\brenton\AppData\Local\Temp\{C3413D50-1C59-4887-9C58-A97928C26626}\ISSetup.dll -> [2008/01/21 10:39:14 | 00,492,032 | R--- | M] (Macrovision Corporation)
_is6F5.exe -> C:\Users\brenton\AppData\Local\Temp\_is6F5.exe -> [2007/06/07 16:43:44 | 00,450,560 | R--- | M] (Macrovision Corporation)
ISSetup.dll -> C:\Users\brenton\AppData\Local\Temp\{C5A364F6-90E8-45AE-89EC-5A06F40BABE9}\ISSetup.dll -> [2007/06/07 16:43:39 | 00,492,032 | R--- | M] (Macrovision Corporation)
_Setup.dll -> C:\Users\brenton\AppData\Local\Temp\{C5A364F6-90E8-45AE-89EC-5A06F40BABE9}\_Setup.dll -> [2007/06/07 16:12:32 | 00,373,680 | R--- | M] (Macrovision Corporation)
unicows.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\unicows.dll -> [2005/09/23 07:57:06 | 00,245,408 | R--- | M] (Microsoft Corporation)
install.exe -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.exe -> [2005/09/23 07:01:16 | 00,609,472 | ---- | M] (Microsoft Corporation)
install.res.1049.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.1049.dll -> [2005/09/23 06:47:30 | 00,082,432 | ---- | M] (Microsoft Corporation)
vjscustom.1049.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.1049.dll -> [2005/09/23 06:47:30 | 00,042,496 | ---- | M] (Microsoft Corporation)
install.res.1046.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.1046.dll -> [2005/09/23 06:47:04 | 00,082,432 | ---- | M] (Microsoft Corporation)
vjscustom.1046.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.1046.dll -> [2005/09/23 06:47:04 | 00,042,496 | ---- | M] (Microsoft Corporation)
vjscustom.1042.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.1042.dll -> [2005/09/23 06:45:00 | 00,042,496 | ---- | M] (Microsoft Corporation)
install.res.1042.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.1042.dll -> [2005/09/23 06:44:58 | 00,080,896 | ---- | M] (Microsoft Corporation)
install.res.1041.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.1041.dll -> [2005/09/23 06:42:58 | 00,080,896 | ---- | M] (Microsoft Corporation)
vjscustom.1041.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.1041.dll -> [2005/09/23 06:42:58 | 00,042,496 | ---- | M] (Microsoft Corporation)
install.res.1040.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.1040.dll -> [2005/09/23 06:40:56 | 00,084,480 | ---- | M] (Microsoft Corporation)
vjscustom.1040.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.1040.dll -> [2005/09/23 06:40:56 | 00,042,496 | ---- | M] (Microsoft Corporation)
install.res.1036.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.1036.dll -> [2005/09/23 06:38:52 | 00,086,016 | ---- | M] (Microsoft Corporation)
vjscustom.1036.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.1036.dll -> [2005/09/23 06:38:52 | 00,042,496 | ---- | M] (Microsoft Corporation)
install.res.3082.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.3082.dll -> [2005/09/23 06:36:48 | 00,085,504 | ---- | M] (Microsoft Corporation)
vjscustom.3082.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.3082.dll -> [2005/09/23 06:36:48 | 00,042,496 | ---- | M] (Microsoft Corporation)
install.res.1031.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.1031.dll -> [2005/09/23 06:34:44 | 00,085,504 | ---- | M] (Microsoft Corporation)
vjscustom.1031.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.1031.dll -> [2005/09/23 06:34:44 | 00,042,496 | ---- | M] (Microsoft Corporation)
install.res.1028.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.1028.dll -> [2005/09/23 06:32:24 | 00,080,896 | ---- | M] (Microsoft Corporation)
vjscustom.1028.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.1028.dll -> [2005/09/23 06:32:24 | 00,042,496 | ---- | M] (Microsoft Corporation)
install.res.2052.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.2052.dll -> [2005/09/23 06:30:18 | 00,080,896 | ---- | M] (Microsoft Corporation)
vjscustom.2052.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.2052.dll -> [2005/09/23 06:30:18 | 00,042,496 | ---- | M] (Microsoft Corporation)
vjscustom.1033.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\vjscustom.1033.dll -> [2005/09/23 03:48:06 | 00,042,496 | ---- | M] (Microsoft Corporation)
install.res.1033.dll -> C:\Users\brenton\AppData\Local\Temp\IS8E3A.tmp\install.res.1033.dll -> [2005/09/23 03:46:14 | 00,080,896 | ---- | M] (Microsoft Corporation)
Setup.EXE -> C:\Users\brenton\AppData\Local\Temp\GLFC263\Setup.EXE -> [2005/01/28 03:00:02 | 03,394,408 | ---- | M] ()
Setup.EXE -> C:\Users\brenton\AppData\Local\Temp\GLFBB21\Setup.EXE -> [2005/01/28 03:00:02 | 03,394,408 | ---- | M] ()
INSTALLDB.DLL -> C:\Users\brenton\AppData\Local\Temp\GLFC263\INSTALLDB.DLL -> [2004/05/14 15:54:30 | 00,441,856 | ---- | M] ()
INSTALLDB.DLL -> C:\Users\brenton\AppData\Local\Temp\GLFBB21\INSTALLDB.DLL -> [2004/05/14 15:54:30 | 00,441,856 | ---- | M] ()
 
[File - Lop Check]
Roaming -> C:\Users\brenton\AppData\Roaming -> [2009/09/13 16:39:08 | 00,000,000 | ---D | M]
AccurateRip -> C:\Users\brenton\AppData\Roaming\AccurateRip -> [2009/08/10 23:24:00 | 00,000,000 | ---D | M]
Ahead -> C:\Users\brenton\AppData\Roaming\Ahead -> [2008/09/04 07:47:11 | 00,000,000 | ---D | M]
DAEMON Tools -> C:\Users\brenton\AppData\Roaming\DAEMON Tools -> [2008/10/24 21:56:15 | 00,000,000 | ---D | M]
dBpoweramp -> C:\Users\brenton\AppData\Roaming\dBpoweramp -> [2009/08/10 23:48:00 | 00,000,000 | ---D | M]
EPSON -> C:\Users\brenton\AppData\Roaming\EPSON -> [2008/05/30 16:56:33 | 00,000,000 | ---D | M]
Leadertech -> C:\Users\brenton\AppData\Roaming\Leadertech -> [2008/12/06 12:36:26 | 00,000,000 | ---D | M]
Media Center Programs -> C:\Users\brenton\AppData\Roaming\Media Center Programs -> [2006/11/02 20:35:50 | 00,000,000 | ---D | M]
NoteTab Light -> C:\Users\brenton\AppData\Roaming\NoteTab Light -> [2008/08/06 20:56:32 | 00,000,000 | ---D | M]
OpenOffice.org2 -> C:\Users\brenton\AppData\Roaming\OpenOffice.org2 -> [2009/09/08 23:53:47 | 00,000,000 | ---D | M]
uqm -> C:\Users\brenton\AppData\Roaming\uqm -> [2008/08/07 19:30:09 | 00,000,000 | ---D | M]
uTorrent -> C:\Users\brenton\AppData\Roaming\uTorrent -> [2009/09/13 16:41:30 | 00,000,000 | ---D | M]
Vso -> C:\Users\brenton\AppData\Roaming\Vso -> [2009/07/10 23:09:24 | 00,000,000 | ---D | M]
Roaming -> C:\Users\Default\AppData\Roaming -> [2006/11/02 20:35:50 | 00,000,000 | ---D | M]
Media Center Programs -> C:\Users\Default\AppData\Roaming\Media Center Programs -> [2006/11/02 20:35:50 | 00,000,000 | ---D | M]
Roaming -> C:\Users\Default User\AppData\Roaming -> [2006/11/02 20:35:50 | 00,000,000 | ---D | M]
Media Center Programs -> C:\Users\Default User\AppData\Roaming\Media Center Programs -> [2006/11/02 20:35:50 | 00,000,000 | ---D | M]
Roaming -> C:\Users\Mcx1\AppData\Roaming -> [2006/11/02 20:35:50 | 00,000,000 | ---D | M]
Media Center Programs -> C:\Users\Mcx1\AppData\Roaming\Media Center Programs -> [2006/11/02 20:35:50 | 00,000,000 | ---D | M]
Roaming -> C:\Users\Mcx2\AppData\Roaming -> [2006/11/02 20:35:50 | 00,000,000 | ---D | M]
Media Center Programs -> C:\Users\Mcx2\AppData\Roaming\Media Center Programs -> [2006/11/02 20:35:50 | 00,000,000 | ---D | M]
C:\Windows\Tasks\ -> C:\Windows\Tasks -> [2009/09/11 02:35:27 | 00,000,000 | ---D | M]
SA.DAT -> C:\Windows\Tasks\SA.DAT -> [2009/09/13 17:30:52 | 00,000,006 | -H-- | M] ()
SCHEDLGU.TXT -> C:\Windows\Tasks\SCHEDLGU.TXT -> [2009/09/13 16:42:08 | 00,032,636 | ---- | M] ()
User_Feed_Synchronization-{63B6EC25-FDA1-4089-96A5-81CA5DC576D1}.job -> C:\Windows\Tasks\User_Feed_Synchronization-{63B6EC25-FDA1-4089-96A5-81CA5DC576D1}.job -> [2009/09/13 16:43:30 | 00,000,422 | -H-- | M] ()
 
[File - Purity Scan]
 
< End of report >

  • 0

Advertisements


#2
Crozza

Crozza

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
I ran Malwarebytes last night and it didn't find anything either. But I definately still have something lurking on my system. Here's the full log from a scan last night:

Malwarebytes' Anti-Malware 1.41
Database version: 2788
Windows 6.0.6002 Service Pack 2

9/15/2009 7:20:59 AM
mbam-log-2009-09-15 (07-20-59).txt

Scan type: Full Scan (C:\|E:\|)
Objects scanned: 247258
Time elapsed: 31 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

#3
Transience

Transience

    Unofficial Music Guru

  • Retired Staff
  • 2,448 posts
Hello and welcome to Geeks to Go! I'm Dave and I'll be helping you out. Let's get started:

Please go to the GMER Rootkit Scanner Download Site.
  • Click on the Download EXE button.
  • The file you are downloading will have a random name in order to circumvent the attempts of malware to block it from running.
  • Take note of the name of the file (please don't change it), and then save it directly to your desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click on the file you downloaded (Vista users please right-click it and select Run as Administrator). The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure that the "Show all" box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity, don't worry.
  • Click Ok.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it to a location where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

Then:

Please visit this webpage for download links and instructions for running ComboFix:

http://www.bleepingc...to-use-combofix

Click on any of the links at that website to download ComboFix. At the window that appears, please change the name of the file from ComboFix to svchost. This name is important and must be exactly as I have given it to you here. Once you have changed the name, save the renamed file directly to your desktop.

Return to the above link and continue with the instructions provided there for running ComboFix. Be sure that you read ALL of the instructions on that page carefully and follow them exactly. It is particularly important to disable all your protection programs before running ComboFix. If you need further help figuring out how to disable a specific program look here for instructions. Installing the recovery console if you're running an XP machine is another critical step. Although these prelimiary steps may seem unnecessary, by following the directions in that guide closely you give ComboFix the best possible chance at a successful run and minimize the likelihood of having serious problems occur after an attempted removal of malware.

Once the program has finished running its log should pop up automatically, or if for some reason you lose it it can found at C:\ComboFix.txt. Please post the log's contents in your next reply.

Cheers,
Dave
  • 0

#4
Crozza

Crozza

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi Dave,

Thanks for the reply, and for your assistance. I am unable to download anything new to my desktop at the moment, whatever is on my computer just deletes the content straight away so I don't get a chance to run it. This happens for files of any type, be it .htm, .exe or .zip. So I was unable to save a copy of GMER Rootkit scanner even though the file was a random name. I attempted saving the file as a different name, like alg.exe or calc.exe but this didn't work either. I also attempted to download it as test.dll (with the intention of renaming it) but the malware deleted this file as well.

Before the virus got this bad, I managed to download combofix and install malwarebytes anti-malware, so I can run scans with this programs if required.

Would you like me to continue running combofix as 'svchost' ? Or would you like me to try something else to detect any possible rootkits.

Thanks
  • 0

#5
Transience

Transience

    Unofficial Music Guru

  • Retired Staff
  • 2,448 posts
Please go ahead with ComboFix and be sure to notate carefully any warnings it gives you about rootkit activity, these will be very important.
  • 0

#6
Crozza

Crozza

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
I ran combofix as svchost twice, once without safe mode and once with. Both times as administrator, but both times it complained that AVG was running, even though I have turned off resident shield.

Anyways, here is the combofix log without safe mode and i'll post with safe mode in another adjacent post:


ComboFix 09-09-16.02 - brenton 09/17/2009 18:46.3.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.2046.856 [GMT 8:00]
Running from: c:\users\brenton\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-08-17 to 2009-09-17 )))))))))))))))))))))))))))))))
.

2009-09-17 10:49 . 2009-09-17 10:49 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-09-13 11:48 . 2009-09-13 11:48 -------- d-----w- c:\users\brenton\AppData\Local\Apps
2009-09-13 09:28 . 2009-09-13 09:28 -------- d-----w- c:\program files\Test1-Malwarebytes' Anti-Malware
2009-09-13 08:55 . 2009-09-13 12:33 -------- d--h--w- c:\windows\PIF
2009-09-13 08:53 . 2009-09-13 09:06 -------- d-----w- c:\program files\Test-Malwarebytes' Anti-Malware
2009-09-13 08:39 . 2009-09-13 08:39 -------- d-----w- c:\users\brenton\AppData\Roaming\Malwarebytes
2009-09-13 08:39 . 2009-09-10 06:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-13 08:39 . 2009-09-13 08:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-13 08:39 . 2009-09-13 08:39 -------- d-----w- c:\programdata\Malwarebytes
2009-09-13 08:39 . 2009-09-10 06:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 20:47 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-08 20:47 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-08 20:47 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-08 20:47 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-08 20:47 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-08 20:47 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-08 20:47 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-08 20:47 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-08 20:47 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-08 20:47 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-08 20:47 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-09-08 20:22 . 2009-07-11 19:01 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-08 20:22 . 2009-07-11 19:01 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-08 20:22 . 2009-07-11 17:03 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-08 20:22 . 2009-07-11 19:01 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-08 20:22 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-08 20:22 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-05 07:10 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-09-03 10:53 . 2009-09-03 10:53 -------- d-----w- C:\JMB36X_WinDrv_R1.17.50_WHQL
2009-09-03 10:53 . 2009-08-13 08:10 96368 ----a-w- c:\windows\system32\drivers\jraid.sys
2009-09-03 09:32 . 2009-09-03 09:32 -------- d-----w- c:\users\brenton\AppData\Local\Microsoft Corporation
2009-09-03 09:32 . 2009-09-03 09:32 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-09-03 00:21 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-03 00:21 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-14 15:43 . 2008-07-31 13:49 -------- d-----w- c:\users\brenton\AppData\Roaming\Skype
2009-09-14 15:23 . 2008-05-31 02:28 -------- d-----w- c:\programdata\VMware
2009-09-14 15:12 . 2008-05-31 11:05 -------- d-----w- c:\users\brenton\AppData\Roaming\uTorrent
2009-09-14 12:59 . 2008-05-28 10:32 -------- d-----w- c:\users\brenton\AppData\Roaming\OpenOffice.org2
2009-09-14 11:34 . 2009-09-14 11:34 8457 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp DSP Effects.dat
2009-09-14 11:34 . 2009-08-10 15:24 2433400 ----a-w- c:\windows\system32\SpoonUninstall.exe
2009-09-14 11:34 . 2009-09-14 11:34 13281 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2009-09-14 11:28 . 2008-07-31 13:49 -------- d-----w- c:\users\brenton\AppData\Roaming\skypePM
2009-09-13 23:03 . 2008-05-27 23:36 -------- d-----w- c:\programdata\avg8
2009-09-13 12:54 . 2009-09-13 12:53 -------- d-----w- c:\program files\Test2-Malwarebytes' Anti-Malware
2009-09-11 14:36 . 2008-10-12 07:32 -------- d-----w- c:\programdata\TrackMania
2009-09-09 23:42 . 2008-11-26 13:57 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-08 23:58 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-08 16:19 . 2008-07-04 03:39 -------- d-----w- c:\program files\Java
2009-08-20 10:31 . 2008-05-27 23:36 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-20 10:31 . 2008-05-27 23:36 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-20 10:31 . 2008-05-27 23:36 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-10 15:48 . 2009-08-10 15:26 -------- d-----w- c:\users\brenton\AppData\Roaming\dBpoweramp
2009-08-10 15:47 . 2009-08-10 15:47 5813 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp CD Writer.dat
2009-08-10 15:24 . 2009-08-10 15:24 2989 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2009-08-10 15:24 . 2009-08-10 15:24 -------- d-----w- c:\users\brenton\AppData\Roaming\AccurateRip
2009-08-10 15:23 . 2009-08-10 15:23 -------- d-----w- c:\program files\Illustrate
2009-08-10 13:26 . 2009-08-10 13:26 -------- d-----w- c:\programdata\LogMeIn
2009-08-10 13:26 . 2009-08-10 13:26 -------- d-----w- c:\program files\LogMeIn
2009-08-08 04:06 . 2009-08-08 04:05 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-08-07 11:51 . 2009-08-07 11:51 15308424 ----a-w- c:\windows\system32\xlive.dll
2009-08-07 11:51 . 2009-08-07 11:51 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2009-08-03 07:07 . 2009-08-03 07:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 07:07 . 2009-08-03 07:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 07:07 . 2009-08-03 07:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-07-24 21:23 . 2008-12-07 03:43 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 21:52 . 2009-08-08 04:05 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-08-08 04:05 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-08-08 04:05 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-08-08 04:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 23:30 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-15 12:40 . 2009-08-12 23:30 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 23:30 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 23:30 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 23:30 7680 ----a-w- c:\windows\system32\spwmp.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-09-13_12.47.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:56 . 2009-09-14 15:26 54462 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:03 . 2009-09-14 15:26 86228 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-05-27 14:55 . 2009-09-14 15:26 11270 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2663051174-626813573-3717304182-1000_UserData.bin
- 2008-05-27 14:37 . 2009-09-13 11:56 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-05-27 14:37 . 2009-09-15 00:17 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-05-27 14:37 . 2009-09-13 11:56 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-27 14:37 . 2009-09-15 00:17 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-27 14:37 . 2009-09-13 11:56 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-05-27 14:37 . 2009-09-15 00:17 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-09-14 15:23 . 2009-09-14 15:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-13 12:39 . 2009-09-13 12:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-13 12:39 . 2009-09-13 12:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-09-14 15:23 . 2009-09-14 15:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2006-11-02 10:33 . 2009-09-13 12:44 636534 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-09-14 15:28 636534 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-09-13 12:44 118248 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-09-14 15:28 118248 c:\windows\System32\perfc009.dat
- 2006-11-02 10:22 . 2009-09-13 12:38 6615040 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 10:22 . 2009-09-14 15:22 6615040 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-20 2007832]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"VMware hqtray"="c:\program files\VMware\VMware Player\hqtray.exe" [2008-10-28 64048]
"BtTray"="c:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2009-02-27 315478]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-24 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Test2-Malwarebytes' Anti-Malware\alg.exe" [2009-09-10 1312080]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):bc,d4,af,d4,6a,f8,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2663051174-626813573-3717304182-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"c:\\Users\\brenton\\AppData\\Roaming\\printer.exe"= c:\users\brenton\AppData\Roaming\printer.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\system32\\printer.exe"= c:\windows\system32\printer.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\system32\\spoolvs.exe"= c:\windows\system32\spoolvs.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\shell.exe"= c:\windows\shell.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Users\\brenton\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\findfast.exe"= c:\users\brenton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\findfast.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\autorun.exe"= c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\autorun.exe:*:Enabled:@xpsp2res.dll,-22019
"%windir%\\system32\\winav.exe"= %windir%\system32\winav.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Users\\brenton\\AppData\\Roaming\\mcrupdate.exe"= c:\users\brenton\AppData\Roaming\mcrupdate.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Program Files\\TESTOUT\\Cmi\\Navigator.exe"= c:\program files\TESTOUT\Cmi\Navigator.exe:*:Disabled:TestOut Navigator

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D61CE018-E783-4034-B1C9-5DCB9C6BFF2C}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{8593A826-E917-452F-8419-D4891E40285A}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"TCP Query User{A9192762-ACF0-4109-AA36-6F0EEDEF2ED3}c:\\users\\brenton\\desktop\\utorrent.exe"= UDP:c:\users\brenton\desktop\utorrent.exe:utorrent.exe
"UDP Query User{B9A9782A-6407-4CEE-B710-6CB16AFD6925}c:\\users\\brenton\\desktop\\utorrent.exe"= TCP:c:\users\brenton\desktop\utorrent.exe:utorrent.exe
"TCP Query User{CE09816F-8EFD-4B24-A7D6-1F6042285B62}c:\\users\\brenton\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\brenton\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{984EFE97-6F53-4210-B947-D774C622860C}c:\\users\\brenton\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\brenton\program files\utorrent\utorrent.exe:utorrent.exe
"{0C70CC1D-5073-4BBE-86FD-5AB1EC3E434E}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{DA180CD6-8459-4710-AA63-0BFDA21FE477}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{8AC7EDA6-B077-44D1-B02B-D90534D988E4}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{5EF6868F-9AE4-4FB3-8406-A8978F203663}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"TCP Query User{06BE22C5-B787-4B2F-ABD4-554701D67239}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{7FD8F89D-674A-4521-8481-6A86C8F38400}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{797845ED-C3C8-4F9E-B1CF-60A6F2E79877}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{FEA4CA2D-2EDD-4F88-86FA-C2391FEBAA05}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{41C3FE3A-98FD-4B05-8251-E6339125157A}c:\\users\\brenton\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\brenton\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{D5B01BB7-F359-4071-9234-A19E8B15F161}c:\\users\\brenton\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\brenton\program files\utorrent\utorrent.exe:utorrent.exe
"TCP Query User{7C944DEA-E556-4143-9898-0F36A2DE7787}c:\\program files\\openvpn\\bin\\openvpn.exe"= UDP:c:\program files\openvpn\bin\openvpn.exe:openvpn
"UDP Query User{2973601A-9D7B-4241-B306-CCF34E2850F6}c:\\program files\\openvpn\\bin\\openvpn.exe"= TCP:c:\program files\openvpn\bin\openvpn.exe:openvpn
"TCP Query User{CBB631DE-36CA-45F4-8F95-64FAF8AAC9CD}c:\\program files\\tmnationsforever\\tmforever.exe"= UDP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"UDP Query User{5BDEC7CC-FA08-43EE-B2A3-1042C14F7B04}c:\\program files\\tmnationsforever\\tmforever.exe"= TCP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"TCP Query User{05D0707C-ADC6-47EB-B458-58DE9D0499FE}c:\\program files\\tmnationsforever\\tmforever.exe"= UDP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"UDP Query User{AE29EF9D-F8DC-4846-80FB-38A272D96472}c:\\program files\\tmnationsforever\\tmforever.exe"= TCP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"{29B5993B-84CE-4B72-AB1D-CAF92D0B7370}"= UDP:e:\games\fc2\Far Cry 2\bin\FarCry2.exe:Far Cry 2
"{3BAF3276-E683-48D4-B6CA-2087117265CA}"= TCP:e:\games\fc2\Far Cry 2\bin\FarCry2.exe:Far Cry 2
"{C451D318-C34F-433F-BC5E-1A55931CD620}"= UDP:e:\games\fc2\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{53654BDE-5906-4F96-B2F0-0E7E1B17AF0F}"= TCP:e:\games\fc2\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{7AA65315-A7F7-4E4E-86DB-165D78ABEF4E}"= UDP:e:\games\fc2\Far Cry 2\bin\FC2Editor.exe:Editor
"{552FBC3E-05FA-4F75-B738-A66FD1C49C4A}"= TCP:e:\games\fc2\Far Cry 2\bin\FC2Editor.exe:Editor
"TCP Query User{07DB002F-9872-46F7-851B-A66A0AD133B6}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3860F757-DAB5-4DE2-BC7F-27C38E146101}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{5E4307AE-7228-4E0C-A5FE-F5381A100820}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{6F7CF97B-CBF3-44AC-B7EF-4F968773AEA2}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{7B3CE9A2-7898-4D33-80B8-3C00F3DF432B}"= UDP:c:\program files\VMware\VMware Player\vmware-authd.exe:VMware Authd
"{3CB49D66-E096-42C2-8047-07EB5EBBD64A}"= TCP:c:\program files\VMware\VMware Player\vmware-authd.exe:VMware Authd
"TCP Query User{528C52EC-04F6-4B56-99E7-6FE422A81B53}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{2ABD6469-AFF6-44F7-BC62-EEA6A85649CA}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{C328829E-7C64-4CB1-BCAD-66CDE60AFF89}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"TCP Query User{EB20BFE1-43D4-4179-B308-F57EAF10E9E2}c:\\windows\\system32\\ftp.exe"= UDP:c:\windows\system32\ftp.exe:File Transfer Program
"UDP Query User{34D848FA-83D7-444F-9CB7-1A387C339164}c:\\windows\\system32\\ftp.exe"= TCP:c:\windows\system32\ftp.exe:File Transfer Program

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Users\\brenton\\AppData\\Roaming\\printer.exe"= c:\users\brenton\AppData\Roaming\printer.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\system32\\printer.exe"= c:\windows\system32\printer.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\system32\\spoolvs.exe"= c:\windows\system32\spoolvs.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\shell.exe"= c:\windows\shell.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Users\\brenton\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\findfast.exe"= c:\users\brenton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\findfast.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\autorun.exe"= c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\autorun.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Users\\brenton\\AppData\\Roaming\\mcrupdate.exe"= c:\users\brenton\AppData\Roaming\mcrupdate.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Program Files\\TESTOUT\\Cmi\\Navigator.exe"= c:\program files\TESTOUT\Cmi\Navigator.exe:*:Disabled:TestOut Navigator

R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\drivers\BtHidBus.sys [1/7/2009 11:39 PM 20744]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [5/28/2008 7:36 AM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [1/28/2009 8:47 PM 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/28/2008 7:36 AM 297752]
R2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [2/27/2009 4:40 PM 143467]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\System32\drivers\LMIRfsDriver.sys [8/10/2009 9:26 PM 47640]
R2 vmci;VMware vmci;c:\windows\System32\drivers\vmci.sys [10/28/2008 10:01 PM 54960]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\System32\drivers\btnetBus.sys [12/7/2008 12:44 PM 30088]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\System32\drivers\IvtBtBus.sys [7/2/2008 2:58 PM 26248]
R3 tap0901;TAP-Win32 Adapter V9;c:\windows\System32\drivers\tap0901.sys [11/20/2008 2:22 AM 25216]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/28/2008 7:36 AM 908056]
S2 vmserverdWin32;VMware Registration Service;c:\program files\VMware\VMware Server\vmserverdWin32.exe --> c:\program files\VMware\VMware Server\vmserverdWin32.exe [?]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\System32\drivers\massfilter.sys [2/25/2009 7:50 PM 7168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder

2009-09-16 c:\windows\Tasks\User_Feed_Synchronization-{63B6EC25-FDA1-4089-96A5-81CA5DC576D1}.job
- c:\windows\system32\msfeedssync.exe [2009-08-08 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = <local>
TCP: {68C8324E-2162-4CA3-956A-1B5971B17194} = 203.21.20.20,203.10.1.9
TCP: {6D524227-E6D7-4B91-9549-CD0AD5C11872} = 203.21.20.20,203.10.1.9
FF - ProfilePath - c:\users\brenton\AppData\Roaming\Mozilla\Firefox\Profiles\fy02zwzy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?|http://mail.google.com/mail/#inbox|http://finance.yahoo.com/|http://www.kitcometals.com/|http://www.anz.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\brenton\AppData\Roaming\Mozilla\Firefox\Profiles\fy02zwzy.default\extensions\[email protected]\plugins\npTVUAx.dll
FF - plugin: c:\users\brenton\AppData\Roaming\Mozilla\Firefox\Profiles\fy02zwzy.default\extensions\[email protected]\plugins\npRACtrl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-17 18:49
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(5520)
c:\windows\system32\BsMobileSDK.dll
c:\windows\system32\BsLangInDepRes.dll
c:\windows\system32\Bs2Res.dll
.
Completion time: 2009-09-17 18:50
ComboFix-quarantined-files.txt 2009-09-17 10:50
ComboFix2.txt 2009-09-14 15:18
ComboFix3.txt 2009-09-13 12:48

Pre-Run: 11,241,631,744 bytes free
Post-Run: 11,216,506,880 bytes free

281 --- E O F --- 2009-09-13 23:58
  • 0

#7
Crozza

Crozza

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
ComboFix 09-09-16.02 - brenton 09/17/2009 19:05.4.2 - NTFSx86 NETWORK
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.2046.1613 [GMT 8:00]
Running from: c:\users\brenton\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-08-17 to 2009-09-17 )))))))))))))))))))))))))))))))
.

2009-09-13 11:48 . 2009-09-13 11:48 -------- d-----w- c:\users\brenton\AppData\Local\Apps
2009-09-13 09:28 . 2009-09-13 09:28 -------- d-----w- c:\program files\Test1-Malwarebytes' Anti-Malware
2009-09-13 08:55 . 2009-09-13 12:33 -------- d--h--w- c:\windows\PIF
2009-09-13 08:53 . 2009-09-13 09:06 -------- d-----w- c:\program files\Test-Malwarebytes' Anti-Malware
2009-09-13 08:39 . 2009-09-13 08:39 -------- d-----w- c:\users\brenton\AppData\Roaming\Malwarebytes
2009-09-13 08:39 . 2009-09-10 06:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-13 08:39 . 2009-09-13 08:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-13 08:39 . 2009-09-13 08:39 -------- d-----w- c:\programdata\Malwarebytes
2009-09-13 08:39 . 2009-09-10 06:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 20:47 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-08 20:47 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-08 20:47 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-08 20:47 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-08 20:47 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-08 20:47 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-08 20:47 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-08 20:47 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-08 20:47 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-08 20:47 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-08 20:47 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-09-08 20:22 . 2009-07-11 19:01 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-08 20:22 . 2009-07-11 19:01 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-08 20:22 . 2009-07-11 17:03 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-08 20:22 . 2009-07-11 19:01 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-08 20:22 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-08 20:22 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-05 07:10 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-09-03 10:53 . 2009-09-03 10:53 -------- d-----w- C:\JMB36X_WinDrv_R1.17.50_WHQL
2009-09-03 10:53 . 2009-08-13 08:10 96368 ----a-w- c:\windows\system32\drivers\jraid.sys
2009-09-03 09:32 . 2009-09-03 09:32 -------- d-----w- c:\users\brenton\AppData\Local\Microsoft Corporation
2009-09-03 09:32 . 2009-09-03 09:32 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-09-03 00:21 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-03 00:21 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-14 15:43 . 2008-07-31 13:49 -------- d-----w- c:\users\brenton\AppData\Roaming\Skype
2009-09-14 15:23 . 2008-05-31 02:28 -------- d-----w- c:\programdata\VMware
2009-09-14 15:12 . 2008-05-31 11:05 -------- d-----w- c:\users\brenton\AppData\Roaming\uTorrent
2009-09-14 12:59 . 2008-05-28 10:32 -------- d-----w- c:\users\brenton\AppData\Roaming\OpenOffice.org2
2009-09-14 11:34 . 2009-09-14 11:34 8457 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp DSP Effects.dat
2009-09-14 11:34 . 2009-08-10 15:24 2433400 ----a-w- c:\windows\system32\SpoonUninstall.exe
2009-09-14 11:34 . 2009-09-14 11:34 13281 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2009-09-14 11:28 . 2008-07-31 13:49 -------- d-----w- c:\users\brenton\AppData\Roaming\skypePM
2009-09-13 23:03 . 2008-05-27 23:36 -------- d-----w- c:\programdata\avg8
2009-09-13 12:54 . 2009-09-13 12:53 -------- d-----w- c:\program files\Test2-Malwarebytes' Anti-Malware
2009-09-11 14:36 . 2008-10-12 07:32 -------- d-----w- c:\programdata\TrackMania
2009-09-09 23:42 . 2008-11-26 13:57 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-08 23:58 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-08 16:19 . 2008-07-04 03:39 -------- d-----w- c:\program files\Java
2009-08-20 10:31 . 2008-05-27 23:36 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-20 10:31 . 2008-05-27 23:36 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-20 10:31 . 2008-05-27 23:36 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-10 15:48 . 2009-08-10 15:26 -------- d-----w- c:\users\brenton\AppData\Roaming\dBpoweramp
2009-08-10 15:47 . 2009-08-10 15:47 5813 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp CD Writer.dat
2009-08-10 15:24 . 2009-08-10 15:24 2989 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2009-08-10 15:24 . 2009-08-10 15:24 -------- d-----w- c:\users\brenton\AppData\Roaming\AccurateRip
2009-08-10 15:23 . 2009-08-10 15:23 -------- d-----w- c:\program files\Illustrate
2009-08-10 13:26 . 2009-08-10 13:26 -------- d-----w- c:\programdata\LogMeIn
2009-08-10 13:26 . 2009-08-10 13:26 -------- d-----w- c:\program files\LogMeIn
2009-08-08 04:06 . 2009-08-08 04:05 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-08-07 11:51 . 2009-08-07 11:51 15308424 ----a-w- c:\windows\system32\xlive.dll
2009-08-07 11:51 . 2009-08-07 11:51 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2009-08-03 07:07 . 2009-08-03 07:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 07:07 . 2009-08-03 07:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 07:07 . 2009-08-03 07:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-07-24 21:23 . 2008-12-07 03:43 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 21:52 . 2009-08-08 04:05 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-08-08 04:05 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-08-08 04:05 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-08-08 04:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 23:30 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-15 12:40 . 2009-08-12 23:30 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 23:30 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 23:30 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 23:30 7680 ----a-w- c:\windows\system32\spwmp.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-09-13_12.47.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:56 . 2009-09-14 15:26 54462 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:03 . 2009-09-14 15:26 86228 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-05-27 14:55 . 2009-09-14 15:26 11270 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2663051174-626813573-3717304182-1000_UserData.bin
- 2008-05-27 14:37 . 2009-09-13 11:56 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-05-27 14:37 . 2009-09-15 00:17 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-05-27 14:37 . 2009-09-15 00:17 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-27 14:37 . 2009-09-13 11:56 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-27 14:37 . 2009-09-13 11:56 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-05-27 14:37 . 2009-09-15 00:17 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 10:33 . 2009-09-17 10:57 635786 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-09-17 10:57 117870 c:\windows\System32\perfc009.dat
- 2006-11-02 10:22 . 2009-09-13 12:38 6615040 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 10:22 . 2009-09-14 15:22 6615040 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-20 2007832]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"VMware hqtray"="c:\program files\VMware\VMware Player\hqtray.exe" [2008-10-28 64048]
"BtTray"="c:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2009-02-27 315478]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-24 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Test2-Malwarebytes' Anti-Malware\alg.exe" [2009-09-10 1312080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):bc,d4,af,d4,6a,f8,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2663051174-626813573-3717304182-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"c:\\Users\\brenton\\AppData\\Roaming\\printer.exe"= c:\users\brenton\AppData\Roaming\printer.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\system32\\printer.exe"= c:\windows\system32\printer.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\system32\\spoolvs.exe"= c:\windows\system32\spoolvs.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\shell.exe"= c:\windows\shell.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Users\\brenton\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\findfast.exe"= c:\users\brenton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\findfast.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\autorun.exe"= c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\autorun.exe:*:Enabled:@xpsp2res.dll,-22019
"%windir%\\system32\\winav.exe"= %windir%\system32\winav.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Users\\brenton\\AppData\\Roaming\\mcrupdate.exe"= c:\users\brenton\AppData\Roaming\mcrupdate.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Program Files\\TESTOUT\\Cmi\\Navigator.exe"= c:\program files\TESTOUT\Cmi\Navigator.exe:*:Disabled:TestOut Navigator

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D61CE018-E783-4034-B1C9-5DCB9C6BFF2C}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{8593A826-E917-452F-8419-D4891E40285A}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"TCP Query User{A9192762-ACF0-4109-AA36-6F0EEDEF2ED3}c:\\users\\brenton\\desktop\\utorrent.exe"= UDP:c:\users\brenton\desktop\utorrent.exe:utorrent.exe
"UDP Query User{B9A9782A-6407-4CEE-B710-6CB16AFD6925}c:\\users\\brenton\\desktop\\utorrent.exe"= TCP:c:\users\brenton\desktop\utorrent.exe:utorrent.exe
"TCP Query User{CE09816F-8EFD-4B24-A7D6-1F6042285B62}c:\\users\\brenton\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\brenton\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{984EFE97-6F53-4210-B947-D774C622860C}c:\\users\\brenton\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\brenton\program files\utorrent\utorrent.exe:utorrent.exe
"{0C70CC1D-5073-4BBE-86FD-5AB1EC3E434E}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{DA180CD6-8459-4710-AA63-0BFDA21FE477}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{8AC7EDA6-B077-44D1-B02B-D90534D988E4}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{5EF6868F-9AE4-4FB3-8406-A8978F203663}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"TCP Query User{06BE22C5-B787-4B2F-ABD4-554701D67239}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{7FD8F89D-674A-4521-8481-6A86C8F38400}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{797845ED-C3C8-4F9E-B1CF-60A6F2E79877}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{FEA4CA2D-2EDD-4F88-86FA-C2391FEBAA05}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{41C3FE3A-98FD-4B05-8251-E6339125157A}c:\\users\\brenton\\program files\\utorrent\\utorrent.exe"= UDP:c:\users\brenton\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{D5B01BB7-F359-4071-9234-A19E8B15F161}c:\\users\\brenton\\program files\\utorrent\\utorrent.exe"= TCP:c:\users\brenton\program files\utorrent\utorrent.exe:utorrent.exe
"TCP Query User{7C944DEA-E556-4143-9898-0F36A2DE7787}c:\\program files\\openvpn\\bin\\openvpn.exe"= UDP:c:\program files\openvpn\bin\openvpn.exe:openvpn
"UDP Query User{2973601A-9D7B-4241-B306-CCF34E2850F6}c:\\program files\\openvpn\\bin\\openvpn.exe"= TCP:c:\program files\openvpn\bin\openvpn.exe:openvpn
"TCP Query User{CBB631DE-36CA-45F4-8F95-64FAF8AAC9CD}c:\\program files\\tmnationsforever\\tmforever.exe"= UDP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"UDP Query User{5BDEC7CC-FA08-43EE-B2A3-1042C14F7B04}c:\\program files\\tmnationsforever\\tmforever.exe"= TCP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"TCP Query User{05D0707C-ADC6-47EB-B458-58DE9D0499FE}c:\\program files\\tmnationsforever\\tmforever.exe"= UDP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"UDP Query User{AE29EF9D-F8DC-4846-80FB-38A272D96472}c:\\program files\\tmnationsforever\\tmforever.exe"= TCP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"{29B5993B-84CE-4B72-AB1D-CAF92D0B7370}"= UDP:e:\games\fc2\Far Cry 2\bin\FarCry2.exe:Far Cry 2
"{3BAF3276-E683-48D4-B6CA-2087117265CA}"= TCP:e:\games\fc2\Far Cry 2\bin\FarCry2.exe:Far Cry 2
"{C451D318-C34F-433F-BC5E-1A55931CD620}"= UDP:e:\games\fc2\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{53654BDE-5906-4F96-B2F0-0E7E1B17AF0F}"= TCP:e:\games\fc2\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{7AA65315-A7F7-4E4E-86DB-165D78ABEF4E}"= UDP:e:\games\fc2\Far Cry 2\bin\FC2Editor.exe:Editor
"{552FBC3E-05FA-4F75-B738-A66FD1C49C4A}"= TCP:e:\games\fc2\Far Cry 2\bin\FC2Editor.exe:Editor
"TCP Query User{07DB002F-9872-46F7-851B-A66A0AD133B6}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3860F757-DAB5-4DE2-BC7F-27C38E146101}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{5E4307AE-7228-4E0C-A5FE-F5381A100820}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{6F7CF97B-CBF3-44AC-B7EF-4F968773AEA2}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{7B3CE9A2-7898-4D33-80B8-3C00F3DF432B}"= UDP:c:\program files\VMware\VMware Player\vmware-authd.exe:VMware Authd
"{3CB49D66-E096-42C2-8047-07EB5EBBD64A}"= TCP:c:\program files\VMware\VMware Player\vmware-authd.exe:VMware Authd
"TCP Query User{528C52EC-04F6-4B56-99E7-6FE422A81B53}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{2ABD6469-AFF6-44F7-BC62-EEA6A85649CA}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{C328829E-7C64-4CB1-BCAD-66CDE60AFF89}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"TCP Query User{EB20BFE1-43D4-4179-B308-F57EAF10E9E2}c:\\windows\\system32\\ftp.exe"= UDP:c:\windows\system32\ftp.exe:File Transfer Program
"UDP Query User{34D848FA-83D7-444F-9CB7-1A387C339164}c:\\windows\\system32\\ftp.exe"= TCP:c:\windows\system32\ftp.exe:File Transfer Program

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Users\\brenton\\AppData\\Roaming\\printer.exe"= c:\users\brenton\AppData\Roaming\printer.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\system32\\printer.exe"= c:\windows\system32\printer.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\system32\\spoolvs.exe"= c:\windows\system32\spoolvs.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Windows\\shell.exe"= c:\windows\shell.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Users\\brenton\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\findfast.exe"= c:\users\brenton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\findfast.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\autorun.exe"= c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\autorun.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Users\\brenton\\AppData\\Roaming\\mcrupdate.exe"= c:\users\brenton\AppData\Roaming\mcrupdate.exe:*:Enabled:@xpsp2res.dll,-22019
"c:\\Program Files\\TESTOUT\\Cmi\\Navigator.exe"= c:\program files\TESTOUT\Cmi\Navigator.exe:*:Disabled:TestOut Navigator

R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\drivers\BtHidBus.sys [1/7/2009 11:39 PM 20744]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [1/28/2009 8:47 PM 108552]
R3 tap0901;TAP-Win32 Adapter V9;c:\windows\System32\drivers\tap0901.sys [11/20/2008 2:22 AM 25216]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [5/28/2008 7:36 AM 335240]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/28/2008 7:36 AM 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/28/2008 7:36 AM 297752]
S2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [2/27/2009 4:40 PM 143467]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
S2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\System32\drivers\LMIRfsDriver.sys [8/10/2009 9:26 PM 47640]
S2 vmci;VMware vmci;c:\windows\System32\drivers\vmci.sys [10/28/2008 10:01 PM 54960]
S2 vmserverdWin32;VMware Registration Service;c:\program files\VMware\VMware Server\vmserverdWin32.exe --> c:\program files\VMware\VMware Server\vmserverdWin32.exe [?]
S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\System32\drivers\btnetBus.sys [12/7/2008 12:44 PM 30088]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\System32\drivers\IvtBtBus.sys [7/2/2008 2:58 PM 26248]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\System32\drivers\massfilter.sys [2/25/2009 7:50 PM 7168]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - ECACHE

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder

2009-09-16 c:\windows\Tasks\User_Feed_Synchronization-{63B6EC25-FDA1-4089-96A5-81CA5DC576D1}.job
- c:\windows\system32\msfeedssync.exe [2009-08-08 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = <local>
TCP: {68C8324E-2162-4CA3-956A-1B5971B17194} = 203.21.20.20,203.10.1.9
TCP: {6D524227-E6D7-4B91-9549-CD0AD5C11872} = 203.21.20.20,203.10.1.9
FF - ProfilePath - c:\users\brenton\AppData\Roaming\Mozilla\Firefox\Profiles\fy02zwzy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?|http://mail.google.com/mail/#inbox|http://finance.yahoo.com/|http://www.kitcometals.com/|http://www.anz.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\brenton\AppData\Roaming\Mozilla\Firefox\Profiles\fy02zwzy.default\extensions\[email protected]\plugins\npTVUAx.dll
FF - plugin: c:\users\brenton\AppData\Roaming\Mozilla\Firefox\Profiles\fy02zwzy.default\extensions\[email protected]\plugins\npRACtrl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKLM-RunOnce-<NO NAME> - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-17 19:08
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(1980)
c:\windows\system32\BsMobileSDK.dll
c:\windows\system32\BsLangInDepRes.dll
c:\windows\system32\Bs2Res.dll
.
Completion time: 2009-09-17 19:09
ComboFix-quarantined-files.txt 2009-09-17 11:09
ComboFix2.txt 2009-09-14 15:18
ComboFix3.txt 2009-09-13 12:48

Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 13,136,789,504 bytes free

280 --- E O F --- 2009-09-13 23:58
  • 0

#8
Transience

Transience

    Unofficial Music Guru

  • Retired Staff
  • 2,448 posts
Hello -

Quick heads-up for you before we continue:

I see you're using or have in the past used p2p software such as. Although p2p programs are not usually malware in their own right, oftentimes malware is installed alongside them. Even if the program is clean, people often upload infected files to be shared using these programs, and it is very easy to end up compromising your PC. It's your decision about whether or not you use p2p programs, you don't have to remove them to be deemed clean and I'll still give you help if you want to keep them. It's just important that you're aware of the risks. If you want to continue using p2p programs that's fine with me, all I ask is that you not download anything from them until you're clean so we aren't taking steps backwards here. To remove p2p programs if you wish to do so, uninstall them from the Add/Remove Programs (it's Programs and Features in Vista) menu of your Control Panel.

Let's go ahead and run these scans.

First we'll clean out your unnecessary temp files to speed up the scans:

1. TFC
  • Please download TFC to your desktop.
  • Save any work, then close all open windows.
  • Double-click TFC to run it, and allow the process to complete, which should not take more than a couple minutes.
  • You may or may not be prompted to reboot, if you are click "Yes" and allow the computer to reboot.
  • Close TFC when it has completed.
2. Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware from here.

Doubleclick (Vista users please right-click Run as Administrator) on mbam-setup.exe to install the program.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware at the end of setup, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Full Scan, then click Scan.
  • The scan is different from the quick scan and will take a fairly long time to finish (you can leave it to run and go do something else), please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab.
  • Copy & Paste the entire report in your next reply.
3. Kaspersky Online Scan

Kaspersky online scanner uses Java technology to perform the scan. Because your Java is out of date, we need to update it first so that the scan will run without issues.

Update Java

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts. A log will appear (JavaRa.log), DO NOT post this log, I have no need for it.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
Scan
  • Follow this link to the Kaspersky WebScanner
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure the following is checked.
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
So post back with the logs from MBAM and Kaspersky when you have them and give me an update on how the PC is running, and we should have you on your way :).

- Dave
  • 0

#9
Crozza

Crozza

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hey, thanks for your help - I've wiped things clean and installed Windows 7 as it was impacting my work.

I've installed AVG free, do you have any other recommended programs that I should install for anti Malware and anti spyware? Am I at risk from any exe files on my (non system) D drive?
  • 0

#10
Transience

Transience

    Unofficial Music Guru

  • Retired Staff
  • 2,448 posts
Sorry to hear about the reformat, however it sounds like it's for the best.

Here are some tips to reduce the potential for malware infection in the future; I strongly that you read them and take them to heart so that you don't have to endure the process of cleaning your computer again.

Make proper use of your antivirus and firewall

Antivirus and Firewall programs are integral to your computer security. However, just having them installed isn't enough. The definitions of these programs are frequently updated to detect the latest malware, and if you don't keep up with these updates then you'll be vulnerable to infection. Many antivirus and firewall programs have automatic update features, make use of those if you can. If your program doesn't, then get in the habit of routinely performing manual updates, because it's important.

You should keep your antivirus and firewall guard enabled at all times, don't shut them off unless there's a specific reason to do so. Also, regularly performing a full system scan with your antivirus program is a good idea to make sure you're still clean. Once a week works well for many people. You can set the scan to run during a time when you don't plan to use the computer and just leave it to complete on its own.

If you don't have a firewall, some great free options you can test out are: Online Armor, Outpost, and Sunbelt. I'd highly recommend that you install one of those. If you do decide to use a 3rd party firewall program, please be sure to disable the Windows firewall as per these instructions so they don't conflict:
  • Please click on Start -> Control Panel
  • Double click Windows Firewall
  • Click Change Settings
  • Choose Off to disable Windows Firewall.
Finally, for a great tutorial on how to get the best protection out of your firewall, take a look at this guide.

Use a safer web browser

Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are a few good free alternatives: Firefox, Opera, and Google Chrome. All of these are excellent faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these. If you wish to continue using Internet Explorer, it would be a good idea to follow the tutorial here which will help you to make IE much safer.

These browser add-ons will help to make your browser safer:

Web of Trust warns you about risky websites that try to scam visitors, deliver malware or send spam. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous ones: Green to go, Yellow for caution, and Red to stop. Available for Firefox and Internet Explorer.

NoScript helps to block malicious scripts and in general gives you much better control over what types of things webpages can do to your computer while you're browsing. Available for Firefox only.

These are just a couple of the most popular add-ons, if you're interested in more, take a look at this article.

Exercise common sense

Having security programs installed is very helpful to you, but none of them have the gift of human thought. The best way to make sure you don't get infected is to look before you leap. Be careful of what websites you visit - if a site looks suspicious, trust your instincts and get out of there. Be careful of what attachments you open in emails and files you download from websites - check them over carefully and look at the file extensions to make sure that you know what you're getting. Using peer-to-peer file sharing programs or downloading cracks and keygens is something else to avoid - the files you will be downloading are infected in the vast majority of cases, and the benefits simply aren't worth the risk to your computer.

Keep up on Windows updates

Along with keeping all of the security programs that you choose to use updated, it is also important to keep up on system updates from Microsoft, as these patch critical security vulnerabilities and help to keep you safe. Typically the windows update icon will appear in your taskbar when new updates are available, whenever you see it you should open the menu up and install the updates that are available. Although it may be an annoyance, that little bit of extra time it takes to stay updated is very well worth it instead of getting infected from an exploit and having to clean your PC again.

Slow computer?

If your computer begins to slow down again in the future for no particular reason, your first step should not be to come back to the malware forum. As your computer ages and is used, its parts wear, files and programs accumulate, and its performance speed can decrease. To restore your computer's performance to its best possible level, follow the steps in this guide written by tech expert Artellos.

I'll leave this thread open for a couple days in case you come across any lingering problems that need fixing, then I'll close it up. If you need it reopened for any reason just shoot me a PM. It's been a pleasure working with you, now best of luck!

Cheers,
Dave
  • 0

#11
Transience

Transience

    Unofficial Music Guru

  • Retired Staff
  • 2,448 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP