about a month ago i started getting an Anti virus pop up, i then had warnings through avg of a trojan, then the google redirect started.
ive had a similar problem about a year ago, which was resolved with the help of the geeks2go folk
im not sure if this new problem is left from before or whether ive been infected again.
Im using AVG as my anti virus. It has detected a few things over the last month, but when i scan it now it finds nothing.
MBAM log
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
17/05/2010 2:19:04 AM
mbam-log-2010-05-17 (02-19-04).txt
Scan type: Quick scan
Objects scanned: 135227
Time elapsed: 8 minute(s), 36 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
******gmer wouldnt run it either froze or blue screened.
OTL log...
OTL logfile created on: 17/05/2010 1:28:07 AM - Run 2
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\me\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1,022.00 Mb Total Physical Memory | 759.00 Mb Available Physical Memory | 74.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.54 Gb Total Space | 25.95 Gb Free Space | 23.26% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOMIE
Current User Name: me
Logged in as Administrator.
Current Boot Mode: SafeMode
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\me\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\me\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) -- File not found
SRV - (avg9wd) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (watcherservice) -- C:\Program Files\Flac to MP3\WatcherService.exe (Ata alla zangenh madar)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Adobe Version Cue CS3) -- C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
SRV - (GTMM Device Service) -- C:\Program Files\Telstra GlobeTrotter Mobility Manager\GtmmDeviceService.exe (Option NV)
SRV - (VirtualWirelessDevice) -- C:\Program Files\Telstra GlobeTrotter Mobility Manager\VirtualWirelessDevice.exe (Option NV)
SRV - (PropertyPublisher) -- C:\Program Files\Telstra GlobeTrotter Mobility Manager\PropertyPublisher.exe ()
SRV - (GtDetectSc) -- C:\WINDOWS\system32\GtDetectSc.exe (OptionNV)
SRV - (ACS) -- C:\Program Files\D-Link\D-Link RangeBooster N 650 DWA-645\acs.exe (Atheros)
SRV - (TAPPSRV) -- C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
SRV - (S24EventMonitor) Intel® -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) Intel® -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (CFSvcs) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (DVD-RAM_Service) -- C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
========== Driver Services (SafeList) ==========
DRV - (AvgTdiX) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Tcpip6) -- C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (UsbserFilt) -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) -- C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (pccsmcfd) -- C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (wsvad_driver) -- C:\WINDOWS\system32\drivers\VirtualAudio.sys (Wondershare)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AR5416) -- C:\WINDOWS\system32\drivers\ar5416.sys (D-Link)
DRV - (GTMNDISIRPXP) -- C:\WINDOWS\system32\drivers\Gtm51Irp.sys (Option NV)
DRV - (GTUQBUS) -- C:\WINDOWS\system32\drivers\gtuqbus.sys (Option N.V.)
DRV - (GTFFBUS) -- C:\WINDOWS\system32\drivers\gtffbus.sys (Option N.V.)
DRV - (GTPTSER) -- C:\WINDOWS\system32\drivers\gtptser.sys (Option N.V.)
DRV - (StarOpen) -- C:\WINDOWS\system32\drivers\StarOpen.sys ()
DRV - (WSIMD) -- C:\WINDOWS\system32\drivers\wsimd.sys (Atheros Communications, Inc.)
DRV - (FdRedir) -- C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys (UPEK Inc.)
DRV - (FileDisk2) -- C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys (UPEK Inc.)
DRV - (TcUsb) -- C:\WINDOWS\system32\drivers\tcusb.sys (UPEK Inc.)
DRV - (smihlp) -- C:\Program Files\Protector Suite QL\smihlp.sys (UPEK Inc.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (SynTP) -- C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (Tosrfhid) -- C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (Tosrfbd) -- C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfusb) -- C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfbnp) -- C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (w39n51) Intel® -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (Tvs) -- C:\WINDOWS\system32\drivers\Tvs.sys (TOSHIBA Corporation)
DRV - (tifm21) -- C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (tosporte) -- C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (TosRfSnd) Bluetooth Audio Device (WDM) -- C:\WINDOWS\system32\drivers\tosrfsnd.sys (TOSHIBA Corporation)
DRV - (TVALD) -- C:\WINDOWS\system32\drivers\NBSMI.sys (Toshiba Corporation)
DRV - (DLAUDFAM) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) -- C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (e1express) Intel® -- C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (DRVMCDB) -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (tosrfec) -- C:\WINDOWS\system32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DRVNDDM) -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (Tosrfcom) -- C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (toshidpt) -- C:\WINDOWS\system32\drivers\toshidpt.sys (TOSHIBA Corporation.)
DRV - (odysseyIM4) -- C:\WINDOWS\system32\drivers\odysseyIM4.sys (Funk Software, Inc.)
DRV - (meiudf) -- C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (tosrfnds) -- C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Iviaspi) -- C:\WINDOWS\system32\drivers\iviaspi.sys (InterVideo, Inc.)
DRV - (Netdevio) -- C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 14 63 CB C2 DE 27 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/...?FORM=IEFM1&q="
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..keyword.URL: "http://www.bing.com/...?FORM=IEFM1&q="
FF - prefs.js..network.proxy.autoconfig_url: "http://cache01.comin...o.com.au:8080/"
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009/10/03 01:56:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/04/27 20:27:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/09 06:36:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/09 06:36:22 | 000,000,000 | ---D | M]
[2009/01/07 17:35:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Mozilla\Extensions
[2010/05/16 20:37:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\z41hdmjv.default\extensions
[2009/09/03 05:04:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\z41hdmjv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/09 05:48:48 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\z41hdmjv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/05/16 20:37:23 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2006/11/28 02:14:17 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
O1 HOSTS File: ([2009/06/21 12:38:12 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O2 - BHO: (no name) - {c148d17d-89e0-45a6-b80a-5f684950fde7} - No CLSID value found.
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (no name) - {e584d28b-ddf3-4770-8c2e-081ca355c4e7} - No CLSID value found.
O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe_ID0EYTHM] C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NokiaMusic FastStart] C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe (Nokia)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVRotateSysTray] C:\WINDOWS\System32\nvsysrot.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\Protector Suite QL\launcher.exe (UPEK Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [TDispVol] C:\WINDOWS\System32\TDispVol.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [THotkey] C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe (PC Tools)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless Connection Manager.lnk = C:\Program Files\D-Link\D-Link RangeBooster N 650 DWA-645\wirelesscm.exe ( )
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: live.com ([login] https in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]* in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.syma...bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {3253344D-0000-0010-8000-00AA00389B71} http://codecs.micros...386/mpg4sax.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5ed80217-570b-4da9-bf44-be107c0ec166} http://cdn.scan.onec...lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1....loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {ef791a6b-fc12-4c68-99ef-fb9e207a39e6} http://download.mcaf...612/mcfscan.cab (McFreeScan Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\psfus: DllName - psqlpwd.dll - C:\WINDOWS\System32\psqlpwd.dll (UPEK Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\me\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\me\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/07 04:24:56 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{a14da5c8-72df-11de-8ffc-00037af450fa}\Shell\Shell00\Command - "" = E:\Start.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: Ias - C:\WINDOWS\system32\ias [2006/03/07 04:24:21 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Error starting restore point: The function was called in safe mode.
Error closing restore point: The sequence number is invalid.
========== Files/Folders - Created Within 90 Days ==========
[2010/05/16 20:23:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/05/15 04:51:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/05/12 04:18:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Desktop\judyphotos
[2010/05/09 05:34:12 | 000,000,000 | ---D | C] -- C:\Program Files\Fake Webcam
[2010/05/09 05:32:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Application Data\GetRightToGo
[2010/05/07 08:10:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Application Data\Windows Search
[2010/05/06 18:19:16 | 000,000,000 | R-SD | C] -- C:\Documents and Settings\me\My Documents\My Safe
[2010/05/05 18:44:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/05/05 05:21:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/04/21 19:10:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/04/21 19:09:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2010/04/21 19:09:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Application Data\Windows Desktop Search
[2010/04/21 19:07:55 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2010/04/21 19:07:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2010/04/16 18:14:10 | 000,000,000 | -H-D | C] -- C:\$AVG
[2010/04/16 18:13:18 | 000,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2010/04/16 18:13:15 | 000,242,896 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/04/16 18:13:10 | 000,216,200 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/04/16 18:13:08 | 000,029,512 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/04/16 18:12:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2010/04/16 18:09:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/04/15 14:19:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Desktop\celebs
[2010/04/08 07:26:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Desktop\music
[2010/04/08 04:21:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Desktop\walk
[2010/04/07 20:05:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Desktop\scandal
[2010/04/07 20:04:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Desktop\sunarvo
[2010/03/17 03:45:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Desktop\now
[2010/03/11 18:40:01 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2010/03/11 18:39:02 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2010/03/11 15:48:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Desktop\me
[2010/02/16 20:32:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\me\Desktop\heads
[2006/03/07 10:45:48 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\DLLVGA.dll
========== Files - Modified Within 90 Days ==========
[2010/05/17 01:07:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/05/17 00:57:50 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2010/05/17 00:57:37 | 000,045,378 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/05/17 00:56:39 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/05/17 00:21:37 | 012,058,624 | ---- | M] () -- C:\Documents and Settings\me\ntuser.dat
[2010/05/17 00:21:11 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\me\ntuser.ini
[2010/05/17 00:04:13 | 000,098,532 | ---- | M] () -- C:\Documents and Settings\me\Local Settings\Application Data\prvlcl.dat
[2010/05/16 22:16:29 | 000,826,880 | ---- | M] () -- C:\Documents and Settings\me\Desktop\wpbartcvbasic.doc
[2010/05/16 22:05:32 | 000,644,375 | ---- | M] () -- C:\Documents and Settings\me\Desktop\2010-Mosman-Art-Prize-entry-form.pdf
[2010/05/16 21:55:11 | 000,072,053 | ---- | M] () -- C:\Documents and Settings\me\My Documents\DMNPP%20Entry%20Form.pdf
[2010/05/16 21:47:26 | 000,131,355 | ---- | M] () -- C:\Documents and Settings\me\Desktop\455756652_7b796fd233.jpg
[2010/05/16 20:58:20 | 001,960,748 | ---- | M] () -- C:\Documents and Settings\me\Desktop\img_42181.jpg
[2010/05/16 20:57:53 | 001,960,748 | ---- | M] () -- C:\Documents and Settings\me\Desktop\go2.wordpress.com.htm
[2010/05/16 20:30:52 | 060,047,216 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/05/13 02:20:04 | 000,357,524 | ---- | M] () -- C:\Documents and Settings\me\Desktop\face4.ai
[2010/05/13 02:19:25 | 005,277,558 | ---- | M] () -- C:\Documents and Settings\me\Desktop\face4.psd
[2010/05/12 22:14:49 | 000,050,688 | ---- | M] () -- C:\Documents and Settings\me\Desktop\saville.doc
[2010/05/12 21:11:36 | 000,122,206 | ---- | M] () -- C:\Documents and Settings\me\Desktop\3628960734_46446e0868.jpg
[2010/05/12 09:44:35 | 000,075,191 | ---- | M] () -- C:\Documents and Settings\me\Desktop\face4.jpg
[2010/05/12 07:42:15 | 000,079,363 | ---- | M] () -- C:\Documents and Settings\me\Desktop\418770503_e6a30cb452_o.jpg
[2010/05/10 18:28:21 | 000,208,384 | ---- | M] () -- C:\Documents and Settings\me\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/08 06:25:22 | 000,031,609 | ---- | M] () -- C:\Documents and Settings\me\Desktop\studio23jpg.jpg
[2010/05/05 16:30:49 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/05/03 04:30:32 | 000,116,273 | ---- | M] () -- C:\Documents and Settings\me\Desktop\DMNPP%20Entry%20Form%202010.pdf
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/28 23:17:48 | 000,321,328 | ---- | M] (BitTorrent, Inc.) -- C:\Documents and Settings\me\Desktop\utorrent.exe
[2010/04/25 22:40:49 | 000,242,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/04/22 19:41:00 | 000,103,916 | ---- | M] () -- C:\Documents and Settings\me\Desktop\heads.jpg
[2010/04/22 17:58:03 | 017,035,508 | ---- | M] () -- C:\Documents and Settings\me\Desktop\Untitled_Panorama1.psd
[2010/04/22 17:34:21 | 000,097,050 | ---- | M] () -- C:\Documents and Settings\me\Desktop\7.jpg
[2010/04/22 17:33:56 | 000,108,628 | ---- | M] () -- C:\Documents and Settings\me\Desktop\6.jpg
[2010/04/22 17:33:34 | 000,142,744 | ---- | M] () -- C:\Documents and Settings\me\Desktop\5.jpg
[2010/04/22 17:33:11 | 000,123,234 | ---- | M] () -- C:\Documents and Settings\me\Desktop\4.jpg
[2010/04/22 17:32:42 | 000,145,878 | ---- | M] () -- C:\Documents and Settings\me\Desktop\3.jpg
[2010/04/22 17:32:02 | 000,149,939 | ---- | M] () -- C:\Documents and Settings\me\Desktop\2.jpg
[2010/04/22 17:31:32 | 000,085,549 | ---- | M] () -- C:\Documents and Settings\me\Desktop\1.jpg
[2010/04/21 19:36:27 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/04/21 19:25:26 | 000,496,304 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/21 19:25:26 | 000,430,228 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/04/21 19:25:26 | 000,075,892 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/04/21 19:08:22 | 000,001,798 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2010/04/21 18:47:41 | 136,306,688 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2010/04/16 18:13:19 | 000,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2010/04/16 18:13:10 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/04/16 18:13:09 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/04/16 18:13:08 | 000,113,461 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/04/07 22:49:44 | 000,307,075 | ---- | M] () -- C:\Documents and Settings\me\Desktop\flower6.jpg
[2010/04/04 06:11:42 | 000,023,005 | ---- | M] () -- C:\Documents and Settings\me\Desktop\eakins_photo.jpg
[2010/04/03 02:12:55 | 000,197,203 | ---- | M] () -- C:\Documents and Settings\me\Desktop\images-3D-sans-lunettes-Stéréoscopie-5.gif
[2010/03/29 07:42:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/11 20:46:08 | 018,499,623 | ---- | M] () -- C:\Documents and Settings\me\My Documents\vlc-1.0.5-win32.exe
========== Files Created - No Company Name ==========
[2010/05/16 22:16:29 | 000,826,880 | ---- | C] () -- C:\Documents and Settings\me\Desktop\wpbartcvbasic.doc
[2010/05/16 22:05:31 | 000,644,375 | ---- | C] () -- C:\Documents and Settings\me\Desktop\2010-Mosman-Art-Prize-entry-form.pdf
[2010/05/16 21:55:11 | 000,072,053 | ---- | C] () -- C:\Documents and Settings\me\My Documents\DMNPP%20Entry%20Form.pdf
[2010/05/16 21:47:21 | 000,131,355 | ---- | C] () -- C:\Documents and Settings\me\Desktop\455756652_7b796fd233.jpg
[2010/05/16 20:58:17 | 001,960,748 | ---- | C] () -- C:\Documents and Settings\me\Desktop\img_42181.jpg
[2010/05/16 20:57:46 | 001,960,748 | ---- | C] () -- C:\Documents and Settings\me\Desktop\go2.wordpress.com.htm
[2010/05/13 02:20:02 | 000,357,524 | ---- | C] () -- C:\Documents and Settings\me\Desktop\face4.ai
[2010/05/13 02:19:23 | 005,277,558 | ---- | C] () -- C:\Documents and Settings\me\Desktop\face4.psd
[2010/05/12 22:14:49 | 000,050,688 | ---- | C] () -- C:\Documents and Settings\me\Desktop\saville.doc
[2010/05/12 21:11:33 | 000,122,206 | ---- | C] () -- C:\Documents and Settings\me\Desktop\3628960734_46446e0868.jpg
[2010/05/12 09:38:04 | 000,075,191 | ---- | C] () -- C:\Documents and Settings\me\Desktop\face4.jpg
[2010/05/12 07:42:13 | 000,079,363 | ---- | C] () -- C:\Documents and Settings\me\Desktop\418770503_e6a30cb452_o.jpg
[2010/05/08 06:25:17 | 000,031,609 | ---- | C] () -- C:\Documents and Settings\me\Desktop\studio23jpg.jpg
[2010/05/04 01:37:49 | 012,058,624 | ---- | C] () -- C:\Documents and Settings\me\ntuser.dat
[2010/05/03 04:30:32 | 000,116,273 | ---- | C] () -- C:\Documents and Settings\me\Desktop\DMNPP%20Entry%20Form%202010.pdf
[2010/05/03 01:40:11 | 000,098,532 | ---- | C] () -- C:\Documents and Settings\me\Local Settings\Application Data\prvlcl.dat
[2010/04/22 19:15:06 | 000,103,916 | ---- | C] () -- C:\Documents and Settings\me\Desktop\heads.jpg
[2010/04/22 17:58:02 | 017,035,508 | ---- | C] () -- C:\Documents and Settings\me\Desktop\Untitled_Panorama1.psd
[2010/04/22 17:34:19 | 000,097,050 | ---- | C] () -- C:\Documents and Settings\me\Desktop\7.jpg
[2010/04/22 17:33:54 | 000,108,628 | ---- | C] () -- C:\Documents and Settings\me\Desktop\6.jpg
[2010/04/22 17:33:32 | 000,142,744 | ---- | C] () -- C:\Documents and Settings\me\Desktop\5.jpg
[2010/04/22 17:33:08 | 000,123,234 | ---- | C] () -- C:\Documents and Settings\me\Desktop\4.jpg
[2010/04/22 17:32:40 | 000,145,878 | ---- | C] () -- C:\Documents and Settings\me\Desktop\3.jpg
[2010/04/22 17:32:00 | 000,149,939 | ---- | C] () -- C:\Documents and Settings\me\Desktop\2.jpg
[2010/04/22 17:31:26 | 000,085,549 | ---- | C] () -- C:\Documents and Settings\me\Desktop\1.jpg
[2010/04/21 19:08:22 | 000,001,798 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2010/04/16 18:13:08 | 000,113,461 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/04/16 18:12:55 | 060,047,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/04/07 22:49:42 | 000,307,075 | ---- | C] () -- C:\Documents and Settings\me\Desktop\flower6.jpg
[2010/04/04 06:11:29 | 000,023,005 | ---- | C] () -- C:\Documents and Settings\me\Desktop\eakins_photo.jpg
[2010/04/03 02:12:44 | 000,197,203 | ---- | C] () -- C:\Documents and Settings\me\Desktop\images-3D-sans-lunettes-Stéréoscopie-5.gif
[2010/03/11 20:45:15 | 018,499,623 | ---- | C] () -- C:\Documents and Settings\me\My Documents\vlc-1.0.5-win32.exe
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/28 15:09:32 | 002,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2008/09/13 19:20:54 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2008/06/10 07:30:47 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2008/04/13 20:58:41 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2008/03/20 08:36:01 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/10/10 04:31:24 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\RPVersion.ini
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/09/05 23:24:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NDSBrow.INI
[2007/08/21 10:26:52 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2007/08/21 10:26:52 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2007/08/16 08:33:14 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/08/16 08:30:26 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/01/03 18:08:18 | 000,000,098 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI
[2006/11/16 18:41:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\tosOBEX.INI
[2006/11/16 11:46:17 | 000,000,080 | ---- | C] () -- C:\WINDOWS\init.ini
[2006/05/16 07:46:06 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/05/16 07:46:06 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/05/16 07:46:03 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006/05/16 07:46:00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/05/16 07:45:56 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006/03/09 06:51:33 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/03/07 10:45:48 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\TCtrlIO.dll
[2006/03/07 09:29:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2006/03/07 09:07:40 | 000,036,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\CSIIDecoder_kern_i386.sys
[2006/03/07 09:07:40 | 000,029,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2006/03/07 09:00:23 | 000,000,258 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/03/07 08:58:30 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/03/07 08:58:30 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/03/07 08:58:30 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/03/07 08:58:30 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/03/07 08:58:30 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/03/07 08:58:30 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/03/07 07:21:01 | 000,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006/03/07 07:20:31 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2006/03/07 07:20:30 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2006/03/07 07:20:30 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2006/03/07 07:20:29 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2006/03/07 05:33:40 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/03/07 04:28:53 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/03/07 03:02:27 | 000,002,392 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/11/28 22:33:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/09/03 08:44:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/23 15:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2004/07/21 11:04:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/16 08:43:28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TBTMonUI.dll
[2004/01/13 20:46:00 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\tifmicon.dll
========== LOP Check ==========
[2010/04/16 18:10:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2009/02/15 04:53:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLAC to MP3
[2009/10/03 01:54:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2009/10/03 02:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaMusic
[2009/10/03 03:33:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/01/26 04:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2006/11/29 01:45:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Telstra GlobeTrotter Mobility Manager
[2010/05/17 00:58:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/03/28 08:28:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/01/09 15:35:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/01/09 02:17:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/06/02 23:29:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Ambient Design
[2008/05/07 23:29:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Canon
[2010/05/09 05:34:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\GetRightToGo
[2009/07/27 23:41:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\gtk-2.0
[2007/03/20 02:59:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\ICQ Toolbar
[2009/07/27 23:36:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Inkscape
[2007/02/15 05:41:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\InterVideo
[2009/07/23 10:57:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\LaCie
[2007/01/31 05:56:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\MoyeaFLV2Video
[2006/11/17 16:55:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\MSNInstaller
[2009/10/03 02:54:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Nokia
[2009/10/08 11:42:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\PC Suite
[2006/11/19 23:39:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Protector Suite
[2007/09/29 06:28:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\SecondLife
[2008/04/09 00:15:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Softplicity
[2007/01/19 02:59:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Template
[2007/09/06 01:24:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\toshiba
[2008/06/08 07:05:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Uniblue
[2010/05/16 20:23:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\uTorrent
[2008/04/24 07:48:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Vso
[2010/04/21 19:09:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Windows Desktop Search
[2010/05/07 08:10:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\me\Application Data\Windows Search
[2010/05/17 00:57:50 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/04/15 00:51:47 | 000,000,002 | ---- | M] () -- C:\815375283
[2006/03/07 04:24:56 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/06/02 18:21:37 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2009/06/02 18:39:09 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2008/04/13 21:16:11 | 000,000,074 | ---- | M] () -- C:\CMLoader.log
[2006/03/07 04:24:56 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/09/21 00:35:43 | 000,001,164 | ---- | M] () -- C:\drmHeader.bin
[2005/11/30 07:20:10 | 000,219,780 | ---- | M] () -- C:\EULA.pdf
[2006/03/07 04:24:56 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/06/10 20:39:08 | 000,002,899 | ---- | M] () -- C:\JavaRa.log
[2010/05/07 09:45:16 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2006/03/07 04:24:56 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/04 22:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/01/11 02:51:49 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/05/17 01:06:49 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys
[2004/11/27 12:39:40 | 000,007,784 | ---- | M] () -- C:\ReadmeFirst.htm
[2007/09/14 03:48:58 | 000,004,238 | ---- | M] () -- C:\SetUp-Log-mpegable DS decoder.txt
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006/03/06 20:16:41 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/03/06 20:16:41 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006/03/06 20:16:41 | 000,892,928 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/16 18:13:10 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgldx86.sys
[2010/04/16 18:13:09 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgmfx86.sys
[2010/04/25 22:40:49 | 000,242,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgtdix.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010/02/24 23:11:07 | 000,455,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\mrxsmb.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
Thank you in advance and apologies if i have posted incorrectly.
oli