I ran the combofix and the OTL helper...please see below for the .txt files I got.
-----
Combofix:
ComboFix 10-06-23.02 - Priesha 06/23/2010 16:19:46.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1983.1321 [GMT -7:00]
Running from: f:\documents and settings\Priesha\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
((((((((((((((((((((((((( Files Created from 2010-05-23 to 2010-06-23 )))))))))))))))))))))))))))))))
.
2010-06-23 18:54 . 2010-06-23 18:54 -------- d-----w- f:\program files\ERUNT
2010-06-23 06:54 . 2010-06-23 06:54 -------- d-----w- F:\_OTL
2010-06-23 05:34 . 2010-06-23 05:34 -------- d-sh--w- f:\documents and settings\Administrator\PrivacIE
2010-06-23 04:47 . 2010-06-23 04:47 -------- d-----w- f:\documents and settings\Priesha\Local Settings\Application Data\Ahead
2010-06-22 19:25 . 2010-06-22 19:25 -------- d-----w- f:\documents and settings\LocalService\Local Settings\Application Data\Apple
2010-06-22 18:51 . 2010-06-22 18:51 -------- d-----w- f:\documents and settings\Administrator\Application Data\iolo
2010-06-22 18:16 . 2010-06-22 19:03 -------- d-----w- f:\program files\MSECACHE
2010-06-22 02:48 . 2010-06-22 02:48 439816 ----a-w- f:\documents and settings\Priesha\Application Data\Real\Update\setup3.10\setup.exe
2010-06-20 06:17 . 2010-06-20 06:17 133648 ----a-w- f:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-20 06:17 . 2010-06-20 06:17 133720 ----a-w- f:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-11 23:48 . 2010-05-06 10:41 743424 -c----w- f:\windows\system32\dllcache\iedvtool.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-23 22:37 . 2009-11-09 07:27 -------- d-----w- f:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-06-23 20:13 . 2009-12-13 04:31 518 ----a-w- f:\documents and settings\Priesha\Application Data\iolo\Registry\Last\restore.bat
2010-06-23 04:51 . 2009-11-09 21:46 -------- d-----w- f:\program files\Google
2010-06-22 22:21 . 2009-12-13 04:26 1527 ----a-w- f:\documents and settings\Priesha\Application Data\iolo\restore.bat
2010-06-22 18:49 . 2009-11-17 03:02 1324 ----a-w- f:\windows\system32\d3d9caps.dat
2010-06-21 17:55 . 2009-12-06 23:01 -------- d-----w- f:\documents and settings\Priesha\Application Data\BitTorrent
2010-06-12 12:18 . 2009-12-15 23:11 -------- d-----w- f:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-07 15:14 . 2009-11-17 03:25 -------- d-----w- f:\program files\Microsoft Silverlight
2010-06-01 06:58 . 2010-04-04 11:04 -------- d-----w- f:\program files\Britannica 10.0
2010-06-01 04:46 . 2009-12-08 01:55 -------- d-----w- f:\documents and settings\Priesha\Application Data\vlc
2010-05-30 02:21 . 2009-12-07 00:23 -------- d-----w- f:\documents and settings\Priesha\Application Data\Vso
2010-05-20 04:34 . 2009-12-08 04:55 -------- d-----w- f:\documents and settings\Priesha\Application Data\dvdcss
2010-05-06 10:41 . 2006-03-15 12:00 916480 ----a-w- f:\windows\system32\wininet.dll
2010-05-05 20:07 . 2009-12-13 04:17 -------- d-----w- f:\documents and settings\All Users\Application Data\iolo
2010-05-05 08:14 . 2009-11-09 07:28 97549 ----a-w- f:\windows\system32\drivers\klick.dat
2010-05-05 08:14 . 2009-11-09 07:28 113933 ----a-w- f:\windows\system32\drivers\klin.dat
2010-05-05 01:16 . 2010-05-05 01:16 -------- d-----w- f:\program files\Nike+ Utility
2010-05-04 19:51 . 2010-05-04 19:50 -------- d-----w- f:\program files\iTunes
2010-05-04 19:50 . 2010-05-04 19:50 -------- d-----w- f:\program files\iPod
2010-05-04 19:50 . 2009-12-28 03:49 -------- d-----w- f:\program files\Common Files\Apple
2010-05-04 19:41 . 2010-05-04 19:41 -------- d-----w- f:\program files\Bonjour
2010-05-04 19:37 . 2010-05-04 19:37 73000 ----a-w- f:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-02 05:22 . 2006-03-15 12:00 1851264 ----a-w- f:\windows\system32\win32k.sys
2010-04-30 23:25 . 2009-11-17 03:53 -------- d-----w- f:\documents and settings\Priesha\Application Data\Skype
2010-04-30 23:03 . 2009-11-20 04:32 -------- d-----w- f:\documents and settings\Priesha\Application Data\skypePM
2010-04-29 20:40 . 2010-04-29 20:40 -------- d-----w- f:\program files\CDCheck
2010-04-29 19:19 . 2010-06-22 18:48 -------- d-----w- f:\documents and settings\Administrator\Application Data\Apple Computer
2010-04-29 19:19 . 2010-04-29 19:19 -------- d-----w- f:\documents and settings\Default User\Application Data\Apple Computer
2010-04-21 21:54 . 2009-12-13 04:23 93096 ----a-w- f:\windows\system32\IncContxMenu.dll
2010-04-21 21:54 . 2009-12-13 04:23 2316712 ----a-w- f:\windows\system32\Incinerator.dll
2010-04-20 05:30 . 2006-03-15 12:00 285696 ----a-w- f:\windows\system32\atmfd.dll
2010-04-15 00:00 . 2010-05-05 20:07 10934656 ----a-w- f:\documents and settings\All Users\Application Data\iolo\System Shield\SSEngineUpd.exe
2010-04-08 20:20 . 2010-04-08 20:20 91424 ----a-w- f:\windows\system32\dnssd.dll
2010-04-08 20:20 . 2010-04-08 20:20 107808 ----a-w- f:\windows\system32\dns-sd.exe
2010-04-04 06:01 . 2009-11-09 07:09 72784 ----a-w- f:\documents and settings\Priesha\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="f:\progra~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" [2005-02-26 212992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="f:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NvCplDaemon"="f:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
"nwiz"="nwiz.exe" [2008-09-18 1657376]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"SoundMAXPnP"="f:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"googletalk"="f:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"LogitechCommunicationsManager"="f:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 488984]
"LogitechQuickCamRibbon"="f:\program files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 774168]
"ElbyCheckAnyDVD"="f:\program files\SlySoft\AnyDVD\ElbyCheck.exe" [2003-09-20 45056]
"TkBellExe"="f:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-08 185896]
"nmctxth"="f:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-13 642856]
"GrooveMonitor"="f:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SMSTray"="f:\program files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-02-24 126976]
"MAAgent"="f:\program files\MarkAny\ContentSafer\MAAgent.exe" [2007-01-31 57344]
"AppleSyncNotifier"="f:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"NeroFilterCheck"="f:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"iTunesHelper"="f:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
f:\documents and settings\Priesha\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - f:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
f:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - f:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-12-21 67128]
Nike+ Utility.lnk - f:\program files\Nike+ Utility\Nike+ Utility.exe [2008-4-30 1228800]
Windows Search.lnk - f:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "f:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\BitTorrent\\bittorrent.exe"=
"f:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"f:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"f:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"f:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"f:\\Program Files\\Skype\\Phone\\Skype.exe"=
"f:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R0 klbg;Kaspersky Lab Boot Guard Driver;f:\windows\system32\drivers\klbg.sys [10/14/2009 10:18 PM 36880]
R2 ioloFileInfoList;iolo FileInfoList Service;f:\program files\iolo\Common\Lib\ioloServiceManager.exe [12/12/2009 9:23 PM 704432]
R2 ioloSystemService;iolo System Service;f:\program files\iolo\Common\Lib\ioloServiceManager.exe [12/12/2009 9:23 PM 704432]
R2 WMP300NSvc;WMP300NSvc;f:\program files\Linksys\WMP300N\WLService.exe [11/15/2009 9:14 PM 53307]
R3 klmouflt;Kaspersky Lab KLMOUFLT;f:\windows\system32\drivers\klmouflt.sys [10/2/2009 8:39 PM 19472]
R3 WMP300Nv1;Linksys Wireless-N PCI Adapter WMP300N Driver;f:\windows\system32\drivers\WMP300Nv1.sys [11/15/2009 9:14 PM 822400]
S2 gupdate;Google Update Service (gupdate);f:\program files\Google\Update\GoogleUpdate.exe [12/20/2009 12:55 AM 135664]
S2 LinksysUpdater;Linksys Updater;f:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [11/13/2008 12:43 PM 204800]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;f:\windows\system32\DRIVERS\klim5.sys --> f:\windows\system32\DRIVERS\klim5.sys [?]
S3 UCharger;Energizer Usb Charger Driver;f:\windows\system32\drivers\UCharger.sys [5/15/2007 8:43 AM 13765]
.
Contents of the 'Scheduled Tasks' folder
2010-06-22 f:\windows\Tasks\AppleSoftwareUpdate.job
- f:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2010-06-23 f:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- f:\program files\Google\Update\GoogleUpdate.exe [2009-12-20 07:55]
2010-06-23 f:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- f:\program files\Google\Update\GoogleUpdate.exe [2009-12-20 07:55]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Anti-Banner - f:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - f:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.ca/s/v/61.17/uploader2.cab
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-23 16:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(996)
f:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(1152)
f:\windows\system32\WININET.dll
f:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
f:\program files\MarkAny\ContentSafer\MaCSProHook.DLL
f:\program files\Windows Desktop Search\deskbar.dll
f:\program files\Windows Desktop Search\en-us\dbres.dll.mui
f:\program files\Windows Desktop Search\dbres.dll
f:\program files\Windows Desktop Search\wordwheel.dll
f:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
f:\program files\Windows Desktop Search\msnlExtRes.dll
f:\windows\system32\ieframe.dll
f:\windows\system32\webcheck.dll
f:\windows\system32\WPDShServiceObj.dll
f:\windows\system32\PortableDeviceTypes.dll
f:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-23 16:28:02
ComboFix-quarantined-files.txt 2010-06-23 23:27
ComboFix2.txt 2010-06-23 22:57
ComboFix3.txt 2010-06-22 20:56
ComboFix4.txt 2010-06-22 20:40
Pre-Run: 275,322,171,392 bytes free
Post-Run: 275,308,879,872 bytes free
- - End Of File - - F1C7EBEFC739D81042995DAAE2C12977
========
OTL:
OTL logfile created on: 6/23/2010 4:30:39 PM - Run 3
OTL by OldTimer - Version 3.2.7.0 Folder = F:\Documents and Settings\Priesha\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 66.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): F:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files
C: Drive not present or media not loaded
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 596.16 Gb Total Space | 256.44 Gb Free Space | 43.01% Space Free | Partition Type: NTFS
Drive G: | 377.95 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PRIESHA-CCE7252
Current User Name: Priesha
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/06/23 16:29:21 | 000,574,464 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Priesha\Desktop\OTL.exe
PRC - [2010/04/21 14:34:14 | 000,704,432 | ---- | M] () -- F:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- F:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/12/07 18:33:11 | 000,185,896 | ---- | M] (RealNetworks, Inc.) -- F:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/02/26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- F:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2008/05/26 23:19:14 | 000,123,904 | ---- | M] (Microsoft Corporation) -- F:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- F:\WINDOWS\explorer.exe
PRC - [2007/08/20 04:22:00 | 005,306,368 | ---- | M] (Linksys) -- F:\Program Files\Linksys\WMP300N\WMP300N.exe
PRC - [2007/02/08 02:13:48 | 000,774,168 | ---- | M] () -- F:\Program Files\Logitech\QuickCam10\QuickCam10.exe
PRC - [2007/02/08 02:12:48 | 000,488,984 | ---- | M] (Logitech Inc.) -- F:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2007/02/08 02:12:20 | 000,230,936 | ---- | M] (Logitech Inc.) -- F:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2007/02/06 18:43:26 | 000,252,704 | ---- | M] (Logitech Inc.) -- F:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
PRC - [2007/01/30 21:36:30 | 000,057,344 | ---- | M] ((주)마크애니) -- F:\Program Files\MarkAny\ContentSafer\MaAgent.exe
PRC - [2005/07/25 12:00:56 | 000,876,032 | ---- | M] (Nero AG) -- F:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2005/07/04 02:46:04 | 000,053,307 | ---- | M] (GEMTEKS) -- F:\Program Files\Linksys\WMP300N\WLService.exe
PRC - [2005/05/19 18:11:06 | 000,925,696 | R--- | M] (Analog Devices, Inc.) -- F:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2005/02/25 17:28:03 | 000,212,992 | ---- | M] (Ahead Software) -- F:\Program Files\Ahead\Nero PhotoShow\data\Xtras\mssysmgr.exe
========== Modules (SafeList) ==========
MOD - [2010/06/23 16:29:21 | 000,574,464 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Priesha\Desktop\OTL.exe
MOD - [2008/04/13 17:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- F:\WINDOWS\system32\msscript.ocx
MOD - [2004/11/24 21:58:24 | 000,163,840 | ---- | M] (MarkAny Co., Ltd.) -- F:\Program Files\MarkAny\ContentSafer\MaCSProHook.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Running] -- -- (WMP300NSvc)
SRV - [2010/04/21 14:34:14 | 000,704,432 | ---- | M] () [Auto | Running] -- F:\Program Files\iolo\Common\Lib\ioloServiceManager.exe -- (ioloSystemService)
SRV - [2010/04/21 14:34:14 | 000,704,432 | ---- | M] () [Auto | Running] -- F:\Program Files\iolo\Common\Lib\ioloServiceManager.exe -- (ioloFileInfoList)
SRV - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- F:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/10/20 21:39:28 | 000,340,456 | ---- | M] (Kaspersky Lab) [Auto | Stopped] -- F:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe -- (AVP)
SRV - [2008/12/12 19:06:40 | 000,642,856 | ---- | M] (Cisco Systems, Inc.) [Auto | Stopped] -- F:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
SRV - [2008/11/13 12:43:49 | 000,204,800 | ---- | M] () [Auto | Stopped] -- F:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe -- (LinksysUpdater)
SRV - [2007/02/06 18:47:12 | 000,105,248 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- F:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2007/02/06 18:45:26 | 000,109,344 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- f:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2005/07/25 12:00:56 | 000,876,032 | ---- | M] (Nero AG) [Auto | Stopped] -- F:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrvR) InCD Helper (read only)
SRV - [2005/07/25 12:00:56 | 000,876,032 | ---- | M] (Nero AG) [Auto | Running] -- F:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2010/01/08 16:42:40 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2009/11/16 19:04:56 | 000,315,408 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- F:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2009/10/14 22:18:34 | 000,036,880 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- F:\WINDOWS\system32\drivers\klbg.sys -- (klbg)
DRV - [2009/10/02 20:39:44 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009/09/01 16:29:50 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\kl1.sys -- (kl1)
DRV - [2009/02/10 17:23:02 | 000,082,320 | ---- | M] (EZB Systems, Inc.) [File_System | System | Running] -- F:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive)
DRV - [2008/12/12 19:05:20 | 000,025,264 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- F:\WINDOWS\system32\drivers\purendis.sys -- (purendis)
DRV - [2008/12/12 19:05:18 | 000,023,984 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- F:\WINDOWS\system32\drivers\pnarp.sys -- (pnarp)
DRV - [2008/09/18 00:55:00 | 006,132,576 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2008/08/01 19:36:26 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008/08/01 19:36:20 | 000,054,784 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008/04/13 11:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 09:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/10/18 07:17:22 | 000,822,400 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\WMP300Nv1.sys -- (WMP300Nv1)
DRV - [2007/05/15 08:43:50 | 000,013,765 | ---- | M] () [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\UCharger.sys -- (UCharger)
DRV - [2007/02/06 18:45:04 | 000,025,632 | ---- | M] () [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2007/02/06 18:44:36 | 001,964,064 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/02/06 18:42:40 | 001,691,808 | ---- | M] () [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007/02/03 11:32:36 | 000,041,504 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007/02/03 11:25:56 | 001,075,360 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\Camdrl.sys -- (CamDrL) Logitech QuickCam Pro 3000(CamDrl)
DRV - [2007/01/27 11:40:43 | 000,015,440 | ---- | M] (Elaborate Bytes AG) [Kernel | Auto | Running] -- F:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2006/12/13 16:41:48 | 000,011,984 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2006/07/24 18:51:34 | 000,009,341 | ---- | M] (iolo technologies, LLC (based on original work by Bo Brantén)) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\filedisk.sys -- (FileDisk)
DRV - [2006/07/07 15:24:24 | 000,564,224 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005/09/14 21:56:48 | 000,141,312 | R--- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV - [2005/08/10 22:49:28 | 000,393,088 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2005/07/25 11:53:28 | 000,101,504 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- F:\WINDOWS\system32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005/07/25 11:53:04 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2005/07/25 02:52:59 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\InCDrm.sys -- (incdrm)
DRV - [2005/03/09 16:53:00 | 000,036,352 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2004/10/27 16:21:30 | 000,145,920 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService)
DRV - [2004/10/14 02:52:28 | 000,004,962 | R--- | M] () [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO)
DRV - [2004/08/12 19:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2003/09/29 13:32:59 | 000,022,912 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2003/09/25 08:15:32 | 000,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- F:\Program Files\Linksys\WMP300N\GTNDIS5.sys -- (GTNDIS5)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: F:\Program Files\Real\RealPlayer\browserrecord [2009/12/07 18:33:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: F:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2009/11/16 18:47:14 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2010/06/22 13:34:30 | 000,000,027 | ---- | M]) - F:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - F:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - F:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - F:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - F:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] F:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ElbyCheckAnyDVD] F:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe (Elaborate Bytes AG)
O4 - HKLM..\Run: [googletalk] F:\Program Files\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] F:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [LogitechCommunicationsManager] F:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] F:\Program Files\Logitech\QuickCam10\QuickCam10.exe ()
O4 - HKLM..\Run: [MAAgent] F:\Program Files\MarkAny\ContentSafer\MaAgent.exe ((주)마크애니)
O4 - HKLM..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [nmctxth] F:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] F:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] F:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SMSTray] F:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe (SAMSUNG ELECTRONICS)
O4 - HKLM..\Run: [SoundMAXPnP] F:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] F:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [PhotoShow Deluxe Media Manager] F:\Program Files\Ahead\Nero PhotoShow\data\Xtras\mssysmgr.exe (Ahead Software)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nike+ Utility.lnk = F:\Program Files\Nike+ Utility\Nike+ Utility.exe ()
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = F:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: F:\Documents and Settings\Priesha\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = F:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = F:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = F:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Anti-Banner - F:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - F:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - F:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - F:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - F:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - F:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Reg Error: Value error.)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.goo...7/uploader2.cab (UploadListView Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1257800191765 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail....ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.59.144.16 64.59.144.17
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - F:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - F:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - F:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - F:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - F:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - F:\WINDOWS\system32\klogon.dll - F:\WINDOWS\system32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: F:\Documents and Settings\Priesha\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: F:\Documents and Settings\Priesha\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - F:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {88485281-8b4b-4f8d-9ede-82e29a064277} - F:\Program Files\MarkAny\ContentSafer\MACSMANAGER.dll (MarkAny Cooperation.)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - F:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/16 09:09:36 | 000,000,045 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/06/23 16:29:20 | 000,574,464 | ---- | C] (OldTimer Tools) -- F:\Documents and Settings\Priesha\Desktop\OTL.exe
[2010/06/23 16:18:58 | 000,000,000 | ---D | C] -- F:\ComboFix
[2010/06/23 11:54:30 | 000,000,000 | ---D | C] -- F:\Program Files\ERUNT
[2010/06/23 11:52:52 | 000,791,393 | ---- | C] (Lars Hederer ) -- F:\Documents and Settings\Priesha\Desktop\erunt_setup.exe
[2010/06/23 11:30:04 | 000,444,416 | ---- | C] (OldTimer Tools) -- F:\Documents and Settings\Priesha\Desktop\TFC.exe
[2010/06/23 00:31:09 | 000,000,000 | ---D | C] -- F:\WINDOWS\temp
[2010/06/22 23:54:40 | 000,000,000 | ---D | C] -- F:\_OTL
[2010/06/22 22:33:44 | 000,000,000 | -HSD | C] -- F:\WINDOWS\CSC
[2010/06/22 21:47:39 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Priesha\Local Settings\Application Data\Ahead
[2010/06/22 13:27:50 | 000,000,000 | RHSD | C] -- F:\cmdcons
[2010/06/22 13:26:55 | 000,212,480 | ---- | C] (SteelWerX) -- F:\WINDOWS\SWXCACLS.exe
[2010/06/22 13:26:55 | 000,161,792 | ---- | C] (SteelWerX) -- F:\WINDOWS\SWREG.exe
[2010/06/22 13:26:55 | 000,136,704 | ---- | C] (SteelWerX) -- F:\WINDOWS\SWSC.exe
[2010/06/22 13:26:55 | 000,031,232 | ---- | C] (NirSoft) -- F:\WINDOWS\NIRCMD.exe
[2010/06/22 13:26:49 | 000,000,000 | ---D | C] -- F:\WINDOWS\ERDNT
[2010/06/22 13:26:35 | 000,000,000 | ---D | C] -- F:\Qoobox
[2010/06/22 12:25:00 | 000,000,000 | ---D | C] -- F:\Documents and Settings\LocalService\Local Settings\Application Data\Apple
[2010/06/22 11:16:31 | 000,000,000 | ---D | C] -- F:\Program Files\MSECACHE
[2010/06/22 11:16:25 | 000,359,656 | ---- | C] (Microsoft Corporation) -- F:\Documents and Settings\Priesha\Desktop\msicuu2.exe
[2010/06/21 19:48:15 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Application Data\Real
[2010/06/21 12:12:42 | 073,543,224 | ---- | C] (Kaspersky Lab) -- F:\Documents and Settings\Priesha\Desktop\kis2010_9.0.0.736en.exe
[2010/06/11 16:48:21 | 000,743,424 | ---- | C] (Microsoft Corporation) -- F:\WINDOWS\System32\dllcache\iedvtool.dll
========== Files - Modified Within 30 Days ==========
[2010/06/23 16:33:16 | 005,242,880 | ---- | M] () -- F:\Documents and Settings\Priesha\ntuser.dat
[2010/06/23 16:29:21 | 000,574,464 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Priesha\Desktop\OTL.exe
[2010/06/23 16:28:03 | 000,000,006 | -H-- | M] () -- F:\WINDOWS\tasks\SA.DAT
[2010/06/23 16:25:33 | 000,000,227 | ---- | M] () -- F:\WINDOWS\system.ini
[2010/06/23 16:13:03 | 000,000,888 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/23 15:43:51 | 003,719,180 | R--- | M] () -- F:\Documents and Settings\Priesha\Desktop\ComboFix.exe
[2010/06/23 15:37:14 | 000,192,954 | ---- | M] () -- F:\WINDOWS\System32\nvapps.xml
[2010/06/23 15:37:09 | 000,000,884 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/23 15:36:32 | 000,002,048 | --S- | M] () -- F:\WINDOWS\bootstat.dat
[2010/06/23 11:54:30 | 000,000,611 | ---- | M] () -- F:\Documents and Settings\Priesha\Desktop\NTREGOPT.lnk
[2010/06/23 11:54:30 | 000,000,592 | ---- | M] () -- F:\Documents and Settings\Priesha\Desktop\ERUNT.lnk
[2010/06/23 11:52:54 | 000,791,393 | ---- | M] (Lars Hederer ) -- F:\Documents and Settings\Priesha\Desktop\erunt_setup.exe
[2010/06/23 11:30:05 | 000,444,416 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Priesha\Desktop\TFC.exe
[2010/06/22 22:50:31 | 000,487,086 | ---- | M] () -- F:\Documents and Settings\Priesha\Desktop\kavremover9.zip
[2010/06/22 22:08:32 | 000,000,116 | ---- | M] () -- F:\WINDOWS\NeroDigital.ini
[2010/06/22 21:47:52 | 000,000,043 | -HS- | M] () -- F:\Documents and Settings\All Users\Application Data\.zreglib
[2010/06/22 21:43:40 | 000,000,745 | ---- | M] () -- F:\Documents and Settings\Priesha\Desktop\xp_exe_fix.zip
[2010/06/22 13:34:30 | 000,000,027 | ---- | M] () -- F:\WINDOWS\System32\drivers\etc\hosts
[2010/06/22 13:27:55 | 000,000,279 | RHS- | M] () -- F:\boot.ini
[2010/06/22 12:25:00 | 000,000,284 | ---- | M] () -- F:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/22 11:49:20 | 000,001,324 | ---- | M] () -- F:\WINDOWS\System32\d3d9caps.dat
[2010/06/22 11:22:18 | 000,526,285 | ---- | M] () -- F:\Documents and Settings\Priesha\Desktop\PlatformInstallClean.zip
[2010/06/22 11:16:30 | 000,359,656 | ---- | M] (Microsoft Corporation) -- F:\Documents and Settings\Priesha\Desktop\msicuu2.exe
[2010/06/22 10:03:29 | 001,768,236 | ---- | M] () -- F:\Documents and Settings\Priesha\Desktop\Windows6.0-KB942288-v2-x86.msu
[2010/06/21 12:12:43 | 073,543,224 | ---- | M] (Kaspersky Lab) -- F:\Documents and Settings\Priesha\Desktop\kis2010_9.0.0.736en.exe
[2010/06/21 10:45:11 | 000,013,646 | ---- | M] () -- F:\WINDOWS\System32\wpa.dbl
[2010/06/21 01:40:01 | 000,002,315 | -H-- | M] () -- F:\.picasa.ini
[2010/06/20 23:57:34 | 000,166,912 | ---- | M] () -- F:\Documents and Settings\Priesha\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/19 22:58:21 | 000,274,168 | ---- | M] () -- F:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/12 07:16:05 | 000,000,178 | -HS- | M] () -- F:\Documents and Settings\Priesha\ntuser.ini
[2010/06/12 04:12:41 | 000,641,190 | ---- | M] () -- F:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/12 04:12:41 | 000,543,850 | ---- | M] () -- F:\WINDOWS\System32\perfh009.dat
[2010/06/12 04:12:41 | 000,105,554 | ---- | M] () -- F:\WINDOWS\System32\perfc009.dat
[2010/05/31 20:27:01 | 000,000,170 | ---- | M] () -- F:\Documents and Settings\Priesha\default.pls
[2010/05/29 21:04:54 | 000,001,044 | ---- | M] () -- F:\Documents and Settings\Priesha\Application Data\vso_ts_preview.xml
========== Files Created - No Company Name ==========
[2010/06/23 11:54:30 | 000,000,611 | ---- | C] () -- F:\Documents and Settings\Priesha\Desktop\NTREGOPT.lnk
[2010/06/23 11:54:30 | 000,000,592 | ---- | C] () -- F:\Documents and Settings\Priesha\Desktop\ERUNT.lnk
[2010/06/22 22:43:29 | 000,487,086 | ---- | C] () -- F:\Documents and Settings\Priesha\Desktop\kavremover9.zip
[2010/06/22 21:43:40 | 000,000,745 | ---- | C] () -- F:\Documents and Settings\Priesha\Desktop\xp_exe_fix.zip
[2010/06/22 13:27:54 | 000,260,272 | ---- | C] () -- F:\cmldr
[2010/06/22 13:26:55 | 000,256,512 | ---- | C] () -- F:\WINDOWS\PEV.exe
[2010/06/22 13:26:55 | 000,098,816 | ---- | C] () -- F:\WINDOWS\sed.exe
[2010/06/22 13:26:55 | 000,080,412 | ---- | C] () -- F:\WINDOWS\grep.exe
[2010/06/22 13:26:55 | 000,077,312 | ---- | C] () -- F:\WINDOWS\MBR.exe
[2010/06/22 13:26:55 | 000,068,096 | ---- | C] () -- F:\WINDOWS\zip.exe
[2010/06/22 13:15:16 | 003,719,180 | R--- | C] () -- F:\Documents and Settings\Priesha\Desktop\ComboFix.exe
[2010/06/22 11:20:36 | 000,526,285 | ---- | C] () -- F:\Documents and Settings\Priesha\Desktop\PlatformInstallClean.zip
[2010/06/22 10:03:25 | 001,768,236 | ---- | C] () -- F:\Documents and Settings\Priesha\Desktop\Windows6.0-KB942288-v2-x86.msu
[2010/06/21 01:13:30 | 000,002,315 | -H-- | C] () -- F:\.picasa.ini
[2010/04/08 02:50:34 | 000,000,116 | ---- | C] () -- F:\WINDOWS\NeroDigital.ini
[2010/02/24 20:58:15 | 000,000,065 | ---- | C] () -- F:\WINDOWS\FISHUI.INI
[2009/12/21 14:55:50 | 000,299,008 | ---- | C] () -- F:\WINDOWS\System32\LAME_MP3.dll
[2009/12/21 14:54:33 | 000,921,600 | ---- | C] () -- F:\WINDOWS\System32\vorbisenc.dll
[2009/12/21 14:54:33 | 000,188,416 | ---- | C] () -- F:\WINDOWS\System32\vorbis.dll
[2009/12/21 14:54:32 | 000,237,568 | ---- | C] () -- F:\WINDOWS\System32\OggDS.dll
[2009/12/21 14:54:32 | 000,045,056 | ---- | C] () -- F:\WINDOWS\System32\Ogg.dll
[2009/12/21 14:44:48 | 000,000,332 | ---- | C] () -- F:\WINDOWS\System32\CNCMFP23.INI
[2009/12/21 14:40:43 | 000,040,960 | ---- | C] () -- F:\WINDOWS\System32\IPPCPUID.DLL
[2009/12/21 14:40:18 | 000,011,776 | ---- | C] () -- F:\WINDOWS\System32\pmsbfn32.dll
[2009/12/12 21:23:06 | 002,316,712 | ---- | C] () -- F:\WINDOWS\System32\Incinerator.dll
[2009/12/12 21:21:26 | 000,074,703 | ---- | C] () -- F:\WINDOWS\System32\mfc45.dll
[2009/11/19 21:20:25 | 000,050,127 | ---- | C] () -- F:\WINDOWS\System32\lvcoinst.ini
[2009/11/15 21:14:19 | 000,139,264 | ---- | C] () -- F:\WINDOWS\System32\preflib.dll
[2009/11/15 21:14:18 | 000,753,664 | ---- | C] () -- F:\WINDOWS\System32\bcm1xsup.dll
[2009/11/15 21:14:12 | 000,000,786 | ---- | C] () -- F:\WINDOWS\System32\WLAN.INI
[2009/11/09 14:06:24 | 000,094,208 | ---- | C] () -- F:\WINDOWS\System32\GTW32N50.dll
[2009/11/09 13:43:06 | 000,024,576 | R--- | C] () -- F:\WINDOWS\System32\AsIO.dll
[2009/11/09 13:43:06 | 000,004,962 | R--- | C] () -- F:\WINDOWS\System32\drivers\AsIO.sys
[2009/11/09 13:43:04 | 000,005,120 | ---- | C] () -- F:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2009/11/09 13:43:04 | 000,003,328 | ---- | C] () -- F:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2009/11/09 13:33:01 | 000,000,265 | R--- | C] () -- F:\WINDOWS\System32\raidmgmt.ini
[2009/11/09 13:32:49 | 000,005,810 | R--- | C] () -- F:\WINDOWS\System32\drivers\ASACPI.sys
[2009/11/09 13:32:30 | 000,020,910 | ---- | C] () -- F:\WINDOWS\Ascd_tmp.ini
[2009/11/09 13:32:27 | 000,005,824 | ---- | C] () -- F:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/09/27 11:51:02 | 000,020,698 | ---- | C] () -- F:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | ---- | C] () -- F:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | ---- | C] () -- F:\WINDOWS\System32\gthrctr.ini
[2007/05/15 08:43:50 | 000,013,765 | ---- | C] () -- F:\WINDOWS\System32\drivers\UCharger.sys
[2007/02/06 18:45:04 | 000,025,632 | ---- | C] () -- F:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/06 18:42:40 | 001,691,808 | ---- | C] () -- F:\WINDOWS\System32\drivers\Lvckap.sys
[2006/03/15 05:00:00 | 001,287,680 | ---- | C] () -- F:\WINDOWS\System32\quartz(2).dll
[2006/03/15 05:00:00 | 000,059,904 | ---- | C] () -- F:\WINDOWS\System32\devenum(2).dll
[2006/03/15 05:00:00 | 000,014,336 | ---- | C] () -- F:\WINDOWS\System32\msdmo(2).dll
[2005/09/17 17:32:00 | 001,724,416 | ---- | C] () -- F:\WINDOWS\System32\nvwdmcpl.dll
[2005/09/17 17:32:00 | 001,503,232 | ---- | C] () -- F:\WINDOWS\System32\nview.dll
[2005/09/17 17:32:00 | 001,101,824 | ---- | C] () -- F:\WINDOWS\System32\nvwimg.dll
[2005/09/17 17:32:00 | 000,573,440 | ---- | C] () -- F:\WINDOWS\System32\nvhwvid.dll
[2005/09/17 17:32:00 | 000,466,944 | ---- | C] () -- F:\WINDOWS\System32\nvshell.dll
[2005/09/17 17:32:00 | 000,286,720 | ---- | C] () -- F:\WINDOWS\System32\nvnt4cpl.dll
[2005/08/05 15:01:54 | 000,235,008 | ---- | C] () -- F:\WINDOWS\System32\psisdecd.dll
[2004/12/20 12:08:28 | 000,155,648 | ---- | C] () -- F:\WINDOWS\System32\xvidvfw.dll
[2004/12/20 12:03:26 | 000,679,936 | ---- | C] () -- F:\WINDOWS\System32\xvidcore.dll
< End of report >
=====
Would really appreciate the help.
Thanks