Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Virus


  • This topic is locked This topic is locked

#1
tonyjh

tonyjh

    Member

  • Member
  • PipPip
  • 18 posts
Hi well were do i start

It All started when i was browsing a a website i recieved a popup cant really remember what it was i usually close these straight away by clicking on the red x.
cant really remember what i did but i saw some java popus in the toolbar maybe the loaded something? but im not really sure.
anyways i had this antivirus action warnings so i looked it up turns out to be malware.
So i look for a removal guide and find one.
okay it says to run in safe mode my first problem. my computer wont boot into safemode keeps crashing and restarting wen trying to enter safemode.
The guide tells me to use malwearbytes so i have run that program. it deletes quite a few things. Restarts and bam windows loads but stops at desktop with background but no icons.
ohh crap i think whats wrong now.
so i have to manually shut down holding power butto power button down.
Power on again all good everything is going well all icons are there everything looks ok.
Got to use internet explorer bam no connection, try diagnose problems still cant get connected.
okay it seems that it changed something to do with a proxy any ways changed all that back no have connection.
I update my avg anti virus then run a full scan it to finds some problems and fixes them.

But the computer is still having problems.
still having computer issues starting up.
still no safemode just keeps rebooting after putting in logon password.
So i have come here for help.

here is my log

OTL logfile created on: 30/10/2010 5:43:20 PM - Run 2
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Documents and Settings\User1\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1,023.00 Mb Total Physical Memory | 473.00 Mb Available Physical Memory | 46.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1534 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 70.32 Gb Free Space | 15.10% Space Free | Partition Type: NTFS
Drive E: | 650.17 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: JULLE-FD9C65E74 | User Name: User1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User1\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
PRC - C:\WINDOWS\system32\UAService7.exe ()
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\User1\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\MsgPlusLoader.dll (Patchou)


========== Win32 Services (SafeList) ==========

SRV - (sdCoreService) -- C:\Program Files\Spyware Doctor\swdsvc.exe (PC Tools)
SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (avgwd) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ServiceLayer) -- C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (spupdsvc) -- C:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)
SRV - (WLSetupSvc) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (AcrSch2Svc) -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Acronis)
SRV - (StarWindServiceAE) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (sdAuxService) -- C:\Program Files\Spyware Doctor\svcntaux.exe (PC Tools)
SRV - (CCALib8) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (Diskeeper) -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV - (UserAccess7) SecuROM User Access Service (V7) -- C:\WINDOWS\system32\UAService7.exe ()
SRV - (SNDSrvc) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (Perpeervc) -- C:\WINDOWS\system32\EPSTP32U.EXE (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (AVGIDSEH) -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AnyDVD) -- C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (ElbyCDIO) -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (UsbserFilt) -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) -- C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (pccsmcfd) -- C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (timounter) -- C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) -- C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (atapi) -- C:\WINDOWS\system32\DRIVERS\atapi.sys ()
DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (gdrv) -- C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (xusb21) -- C:\WINDOWS\system32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (IKSysSec) -- C:\WINDOWS\system32\drivers\iksyssec.sys (PCTools Research Pty Ltd.)
DRV - (IkSysFlt) -- C:\WINDOWS\system32\drivers\iksysflt.sys (PCTools Research Pty Ltd.)
DRV - (IKFileSec) -- C:\WINDOWS\system32\drivers\ikfilesec.sys (PCTools Research Pty Ltd.)
DRV - (IKFileFlt) -- C:\WINDOWS\system32\drivers\ikfileflt.sys (PCTools Research Pty Ltd.)
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (vaxscsi) -- C:\WINDOWS\System32\Drivers\vaxscsi.sys (Alcohol Soft Co., Ltd.)
DRV - (MayPro) -- C:\WINDOWS\system32\drivers\Maypro.sys (TigerGame.,Ltd)
DRV - (dtscsi) -- C:\WINDOWS\System32\Drivers\dtscsi.sys (DT Soft Ltd.)
DRV - (EZWRIT3) -- C:\WINDOWS\system32\drivers\ezwrit3.sys (USTC)
DRV - (ASPI32) -- C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (APLOADER) -- C:\WINDOWS\system32\drivers\ApLoader.SYS (Texas Instruments)
DRV - (Hardlock) -- C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (VIAudio) Vinyl AC'97 Audio Controller (WDM) -- C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.)
DRV - (d347prt) -- C:\WINDOWS\System32\Drivers\d347prt.sys ( )
DRV - (d347bus) -- C:\WINDOWS\system32\DRIVERS\d347bus.sys ( )
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (a347bus) -- C:\WINDOWS\system32\DRIVERS\a347bus.sys ( )
DRV - (a347scsi) -- C:\WINDOWS\System32\Drivers\a347scsi.sys ( )
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ALCXSENS) -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (yukonwxp) -- C:\WINDOWS\system32\drivers\yukonwxp.sys (Marvell Semiconductor Inc.)
DRV - (LMouFlt2) -- C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) -- C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (SiSRaid) -- C:\WINDOWS\system32\DRIVERS\SiSRaid.sys (Silicon Integrated Systems)
DRV - (SISAGP) -- C:\WINDOWS\system32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (SiSide) -- C:\WINDOWS\system32\DRIVERS\siside.sys (Silicon Integrated Systems Corp.)
DRV - (sisidex) -- C:\WINDOWS\system32\drivers\sisidex.sys (Windows ® 2000 DDK provider)
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (sisperf) -- C:\WINDOWS\system32\drivers\sisperf.sys (Silicon Integrated Systems Corp.)
DRV - (SISNIC) -- C:\WINDOWS\system32\drivers\sisnic.sys (SiS Corporation)
DRV - (StreamDispatcher) -- C:\WINDOWS\system32\drivers\strmdisp.sys (Conexant Systems)
DRV - (HSFHWBS2) -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems)
DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = My Web Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultUrl = http://www.mywebsear...r={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dodo.com.au/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:28091

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..network.proxy.http: "127.0.0.1");user_pref("network.proxy.http_port", 81);user_pref("network.proxy.type", 1

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009/02/27 22:24:33 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/10/26 15:52:34 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2010/10/23 09:32:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/30 17:12:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/30 17:12:19 | 000,000,000 | ---D | M]

[2008/12/15 14:54:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Mozilla\Extensions
[2010/10/30 17:12:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\6aecx7x9.julie\extensions
[2010/10/29 15:28:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\6aecx7x9.julie\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010/08/18 15:17:13 | 000,000,000 | ---D | M] (ReloadEvery) -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\6aecx7x9.julie\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2010/10/29 15:28:38 | 000,000,000 | ---D | M] (ReminderFox) -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\6aecx7x9.julie\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2010/08/30 16:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\uryozul3.default\extensions
[2005/01/22 15:54:38 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\uryozul3.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/08/30 16:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\uryozul3.default\extensions\[email protected]
[2010/10/30 17:12:51 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2004/01/14 13:09:25 | 000,176,176 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2005/09/05 11:11:48 | 000,098,304 | ---- | M] (Zylom) -- C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll

O1 HOSTS File: ([2010/10/27 19:16:28 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PlaySushi) - {21608B66-026F-4DCB-9244-0DACA328DCED} - C:\Program Files\PlaySushi\PSText.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunServices: [CPQHotKeys] File not found
O4 - HKLM..\RunServices: [tcp checker] File not found
O4 - HKCU..\RunServices: [tcp checker] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStrCmpLogical = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 177
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoTrayNotify = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - Reg Error: Value error. File not found
O9 - Extra Button: Go to PlaySushi web site - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - C:\Program Files\PlaySushi\PSText.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.micr...922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {447F8438-8124-4369-905B-A249E13CBBFC} http://pickles.liveb...l/new/lgbkc.cab (LgbContent Control)
O16 - DPF: {680285A8-96D3-43DA-9D3D-51DD987D0B77} http://www.nero.com/...ckerControl.cab (NeroVersionCheckerControl Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (MsgPlusLoader.dll) - C:\WINDOWS\System32\MsgPlusLoader.dll (Patchou)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\User1\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User1\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\urqOGVnM) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/13 08:21:27 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004/08/18 19:55:50 | 000,000,000 | R--D | M] - E:\AutoRun -- [ CDFS ]
O32 - AutoRun File - [2004/08/18 19:37:22 | 000,663,552 | R--- | M] () - E:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2004/08/18 19:33:44 | 000,598,016 | R--- | M] () - E:\AutoRunGUI.dll -- [ CDFS ]
O32 - AutoRun File - [2004/08/18 19:54:43 | 000,000,083 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

File not found -- C:\Documents and Settings\User1\My Documents\User1.
[2010/10/30 12:46:03 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User1\Desktop\OTL.exe
[2010/10/30 00:24:51 | 007,462,768 | ---- | C] (AVG ) -- C:\Documents and Settings\User1\Desktop\avg_pct_stf_all_2011_22.exe
[2010/10/28 19:00:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\Bitrix Security
[2010/10/28 17:47:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Bitrix Security
[2010/10/28 17:47:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/10/28 17:46:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/10/27 18:20:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/10/27 18:18:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/10/26 22:44:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Documents\Server
[2010/10/26 22:43:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\BBA3C47041CC05CF5F7CEAE09FFAF8B6
[2010/10/26 22:21:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\Y.S.v1.4.0.0
[2010/10/26 16:58:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\The Learning Company
[2010/10/25 20:46:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\a.b.hal.propper
[2010/10/24 00:35:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\tgatetress
[2010/10/22 00:31:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\IPOD
[2010/10/16 12:44:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Local Settings\Application Data\AVG Security Toolbar
[2010/10/16 12:35:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\AVG10
[2010/10/16 12:33:42 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/10/16 12:33:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/10/16 12:32:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/16 12:32:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2010/10/16 11:50:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/10/15 20:08:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\Realore_Whiterra Roads Of Rome
[2010/10/15 16:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\Roads of Rome
[2010/10/15 16:37:38 | 000,000,000 | ---D | C] -- C:\Program Files\Kate Arrow - Deserted Wood
[2010/10/15 16:36:40 | 000,000,000 | ---D | C] -- C:\Program Files\Help Felix Find a Cure
[2010/10/15 16:34:31 | 000,000,000 | ---D | C] -- C:\Program Files\Enlightenus II - The Timeless Tower
[2010/10/15 16:27:57 | 000,000,000 | ---D | C] -- C:\Program Files\Dark Tales - Edgar Allan Poe's The Black Cat Collector's Edition
[2010/10/15 15:25:54 | 000,000,000 | ---D | C] -- C:\Program Files\Columbus - Ghost of the Mystery Stone
[2010/10/12 20:47:43 | 000,000,000 | ---D | C] -- C:\Program Files\EA Sports
[2010/10/11 17:09:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\Anarchy
[2010/10/11 17:07:33 | 000,000,000 | ---D | C] -- C:\Program Files\Coffee Rush 2
[2010/10/04 13:53:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\TheIslandCastaway
[2010/10/03 13:13:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\Sahmon Games
[2009/02/04 17:45:55 | 000,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys
[2009/02/04 17:45:55 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys
[2008/06/05 16:34:49 | 000,403,856 | ---- | C] (Pantaray Research LTD.) -- C:\Program Files\un_Star Defender 4_26816.exe
[2005/07/25 18:37:28 | 000,160,640 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347bus.sys
[2005/07/25 18:37:28 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found -- C:\Documents and Settings\User1\My Documents\User1.
[2010/10/30 17:45:44 | 000,762,368 | ---- | M] () -- C:\WINDOWS\System32\drivers\ztkbxvda.sys
[2010/10/30 17:41:48 | 000,000,388 | ---- | M] () -- C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On Windows Logon.job
[2010/10/30 17:38:18 | 000,000,000 | ---- | M] () -- C:\WINDOWS\TempFile
[2010/10/30 17:37:55 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/30 17:37:51 | 000,000,438 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2010/10/30 17:37:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/10/30 17:37:16 | 1073,270,784 | -HS- | M] () -- C:\hiberfil.sys
[2010/10/30 15:37:13 | 000,001,984 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/30 15:15:59 | 098,021,486 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2010/10/30 14:50:26 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/30 11:04:14 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User1\Desktop\OTL.exe
[2010/10/30 04:43:13 | 000,000,191 | ---- | M] () -- C:\Documents and Settings\User1\Application Data\ahfg.bat
[2010/10/30 00:25:34 | 000,000,860 | ---- | M] () -- C:\Documents and Settings\User1\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2010/10/30 00:25:34 | 000,000,842 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\AVG PC Tuneup 2011.lnk
[2010/10/30 00:24:57 | 007,462,768 | ---- | M] (AVG ) -- C:\Documents and Settings\User1\Desktop\avg_pct_stf_all_2011_22.exe
[2010/10/29 23:52:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/10/28 09:18:26 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2010/10/28 09:00:00 | 000,000,186 | ---- | M] () -- C:\WINDOWS\tasks\C and K.job
[2010/10/27 23:04:31 | 000,452,500 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/10/27 23:04:31 | 000,075,314 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/10/27 19:16:28 | 000,000,734 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/10/27 07:17:58 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/10/26 23:11:25 | 000,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/10/26 17:00:55 | 000,000,036 | ---- | M] () -- C:\WINDOWS\Tiny_Run.ini
[2010/10/24 16:23:55 | 068,346,571 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\Y.S.v1.4.0.0.rar
[2010/10/24 15:31:02 | 009,838,549 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\a.b.hal.propper.rar
[2010/10/19 21:00:41 | 111,586,305 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\s.c.v1.0.rar
[2010/10/14 03:40:00 | 000,000,372 | ---- | M] () -- C:\WINDOWS\tasks\RegCure.job
[2010/10/12 20:36:06 | 517,080,144 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\V8 Challenge.bin
[2010/10/12 20:36:06 | 000,000,201 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\V8 Challenge.cue
[2010/10/12 20:27:45 | 000,000,090 | ---- | M] () -- C:\WINDOWS���������������������������
[2010/10/11 17:03:26 | 000,001,596 | ---- | M] () -- C:\Documents and Settings\User1\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2010/10/10 22:11:24 | 000,120,129 | ---- | M] () -- C:\Documents and Settings\User1\My Documents\cover111.jpg
[2010/10/07 20:14:46 | 000,120,192 | ---- | M] () -- C:\Documents and Settings\User1\My Documents\haunted_house.jpg
[2010/10/05 22:21:55 | 000,000,083 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/10/04 13:58:56 | 000,000,907 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\The Island - Castaway.lnk
[2010/10/04 13:53:05 | 141,078,024 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\TheIslandCastaway.rar
[2010/10/01 19:41:39 | 173,817,219 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\s.b.and.s.v1.0.5.rar
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/30 15:15:59 | 098,021,486 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2010/10/30 09:04:57 | 1073,270,784 | -HS- | C] () -- C:\hiberfil.sys
[2010/10/30 04:43:13 | 000,000,191 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\ahfg.bat
[2010/10/30 04:42:35 | 000,762,368 | ---- | C] () -- C:\WINDOWS\System32\drivers\ztkbxvda.sys
[2010/10/30 00:25:49 | 000,000,388 | ---- | C] () -- C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On Windows Logon.job
[2010/10/30 00:25:34 | 000,000,860 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2010/10/30 00:25:34 | 000,000,842 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\AVG PC Tuneup 2011.lnk
[2010/10/26 16:56:34 | 000,000,036 | ---- | C] () -- C:\WINDOWS\Tiny_Run.ini
[2010/10/24 16:23:49 | 068,346,571 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\Y.S.v1.4.0.0.rar
[2010/10/24 15:31:00 | 009,838,549 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\a.b.hal.propper.rar
[2010/10/19 21:00:24 | 111,586,305 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\s.c.v1.0.rar
[2010/10/16 12:33:18 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2010/10/12 20:36:06 | 000,000,201 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\V8 Challenge.cue
[2010/10/12 20:33:53 | 517,080,144 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\V8 Challenge.bin
[2010/10/11 18:12:22 | 000,001,548 | -H-- | C] () -- C:\Documents and Settings\User1\Desktop\UltraISO.lnk
[2010/10/11 17:03:26 | 000,001,596 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2010/10/10 22:11:43 | 000,120,129 | ---- | C] () -- C:\Documents and Settings\User1\My Documents\cover111.jpg
[2010/10/07 20:15:46 | 000,120,192 | ---- | C] () -- C:\Documents and Settings\User1\My Documents\haunted_house.jpg
[2010/10/04 13:58:56 | 000,000,907 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\The Island - Castaway.lnk
[2010/10/04 13:52:40 | 141,078,024 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\TheIslandCastaway.rar
[2010/10/01 19:41:23 | 173,817,219 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\s.b.and.s.v1.0.5.rar
[2010/09/16 19:21:41 | 000,000,083 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/04/29 22:41:52 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\SuperSafer.cfg
[2010/02/03 18:22:05 | 000,000,253 | ---- | C] () -- C:\WINDOWS\Sin_setup.INI
[2009/12/13 23:42:05 | 000,359,592 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/10/28 23:14:35 | 000,155,648 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2009/08/03 00:21:54 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2009/07/21 13:49:53 | 000,001,044 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\vso_ts_preview.xml
[2009/04/26 18:49:27 | 000,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/04/18 20:13:10 | 000,000,107 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\default.pls
[2009/03/14 21:19:47 | 000,009,629 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2009/03/01 19:19:18 | 000,012,060 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\NMM-MetaData.db
[2009/02/05 18:31:33 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\User1\Local Settings\Application Data\fusioncache.dat
[2009/02/01 11:29:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2008/12/31 17:04:42 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2008/10/23 21:26:32 | 000,000,635 | ---- | C] () -- C:\WINDOWS\Dc.INI
[2008/09/05 10:47:04 | 000,000,120 | ---- | C] () -- C:\WINDOWS\WINRESAZ.INI
[2008/09/01 14:21:46 | 000,000,121 | ---- | C] () -- C:\WINDOWS\SwDrvs.ini
[2008/09/01 14:21:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\drvxl32.INI
[2008/09/01 14:21:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\drvwd32.INI
[2008/09/01 13:20:32 | 000,000,343 | ---- | C] () -- C:\WINDOWS\9ed.ini
[2008/08/13 21:31:17 | 000,029,088 | -HS- | C] () -- C:\WINDOWS\System32\MnVGOqru.ini2
[2008/08/13 21:31:17 | 000,029,088 | -HS- | C] () -- C:\WINDOWS\System32\MnVGOqru.ini
[2008/08/03 18:24:01 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/06/09 18:43:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2008/06/05 16:34:49 | 000,006,933 | ---- | C] () -- C:\Program Files\un_Star Defender 4_26816.txt
[2008/03/08 07:44:35 | 000,000,061 | ---- | C] () -- C:\WINDOWS\TLCAPPS.INI
[2008/03/05 12:54:19 | 000,000,000 | ---- | C] () -- C:\Program Files\temp01
[2008/03/01 22:20:38 | 003,049,984 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/03/01 22:20:38 | 000,404,480 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008/03/01 22:20:38 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008/03/01 22:20:38 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/01/30 14:05:30 | 000,002,568 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/01/24 15:47:46 | 000,000,052 | ---- | C] () -- C:\WINDOWS\cool.ini
[2008/01/24 15:45:27 | 000,000,011 | ---- | C] () -- C:\WINDOWS\wordpad.ini
[2007/12/20 21:45:27 | 000,000,028 | ---- | C] () -- C:\WINDOWS\v2d.INI
[2007/11/30 00:15:49 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ADsSecurity.dll
[2007/11/30 00:15:49 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\dxinputdll.dll
[2007/11/26 21:56:28 | 000,151,415 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2007/11/16 22:34:58 | 000,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/10/29 10:54:51 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\_psisdecd.dll
[2007/10/01 15:08:34 | 000,000,035 | ---- | C] () -- C:\WINDOWS\WDIRECT.INI
[2007/09/06 13:19:50 | 000,000,117 | ---- | C] () -- C:\WINDOWS\Prof.ini
[2007/09/06 00:55:21 | 000,000,447 | ---- | C] () -- C:\WINDOWS\Clony2.ini
[2007/07/26 00:24:28 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/05/28 18:21:04 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/05/28 18:21:03 | 000,084,480 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007/05/23 15:56:10 | 000,000,205 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2007/04/05 00:15:37 | 000,000,397 | ---- | C] () -- C:\WINDOWS\Proxyrama.INI
[2007/03/29 22:00:40 | 000,203,264 | ---- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
[2007/03/10 22:51:48 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/02/28 14:33:51 | 000,286,208 | ---- | C] () -- C:\WINDOWS\System32\CNCS232.DLL
[2007/02/12 17:45:22 | 000,000,344 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2007/01/31 00:01:15 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2007/01/31 00:01:15 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2007/01/04 01:48:05 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\infcpy.dll
[2006/10/21 15:34:09 | 000,000,004 | ---- | C] () -- C:\WINDOWS\info147.sys
[2006/07/24 20:16:51 | 000,000,011 | ---- | C] () -- C:\WINDOWS\KPP.INI
[2006/07/15 10:45:10 | 000,000,019 | ---- | C] () -- C:\WINDOWS\System32\systilde32.dll
[2006/05/11 23:13:56 | 000,001,743 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/30 21:07:17 | 000,056,320 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2006/04/30 20:30:02 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2006/04/23 00:59:13 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2006/03/31 15:05:53 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2006/01/16 00:34:21 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2006/01/10 19:00:25 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDER310E.ini
[2006/01/09 12:20:04 | 000,000,073 | ---- | C] () -- C:\WINDOWS\EurekaLog.ini
[2005/12/23 13:15:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\RAWImage.INI
[2005/12/04 11:56:56 | 000,000,011 | ---- | C] () -- C:\WINDOWS\ABC.INI
[2005/10/27 16:41:47 | 000,000,020 | ---- | C] () -- C:\WINDOWS\Converter.INI
[2005/10/04 10:01:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Quicktools.INI
[2005/07/25 15:41:18 | 000,000,036 | ---- | C] () -- C:\WINDOWS\ibu.dll
[2005/06/27 18:08:31 | 000,000,551 | ---- | C] () -- C:\WINDOWS\Clubhouse.ini
[2005/06/23 17:00:08 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\TTSServer.dll
[2005/06/22 10:05:22 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVSyd.DLL
[2005/06/22 10:05:13 | 000,000,599 | ---- | C] () -- C:\WINDOWS\System32\CNCMP51.INI
[2005/05/25 10:04:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2005/05/25 09:57:09 | 000,000,111 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2005/05/11 14:01:36 | 000,001,125 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2005/04/08 14:38:48 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\tmpid.dll
[2005/04/05 18:41:14 | 000,000,397 | ---- | C] () -- C:\WINDOWS\MYOBP.INI
[2005/04/05 18:41:14 | 000,000,039 | ---- | C] () -- C:\WINDOWS\MYOB.INI
[2005/02/09 12:59:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2005/01/30 10:22:58 | 000,001,125 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2005/01/29 11:25:02 | 008,956,040 | ---- | C] () -- C:\Program Files\InstallSnSBingo.exe
[2005/01/26 16:50:53 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2005/01/26 16:50:53 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2005/01/26 05:25:04 | 000,247,808 | ---- | C] () -- C:\Documents and Settings\User1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/01/22 04:00:05 | 000,000,712 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2005/01/22 04:00:03 | 000,000,780 | ---- | C] () -- C:\WINDOWS\ka.ini
[2005/01/20 09:32:33 | 000,000,855 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2005/01/20 06:23:29 | 000,000,700 | ---- | C] () -- C:\WINDOWS\disney.ini
[2005/01/19 12:26:31 | 000,000,119 | ---- | C] () -- C:\WINDOWS\compedia.ini
[2005/01/13 08:36:54 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\property.dll
[2005/01/13 08:33:58 | 000,139,264 | R--- | C] () -- C:\WINDOWS\System32\IDEproperty.dll
[2005/01/13 00:10:32 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/22 17:04:56 | 000,069,120 | ---- | C] () -- C:\WINDOWS\daemon.dll
[2004/08/04 23:00:00 | 000,096,512 | ---- | C] () -- C:\WINDOWS\System32\drivers\atapi.sys
[2004/04/22 13:58:26 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
[2003/07/14 12:20:16 | 000,000,025 | R--- | C] () -- C:\WINDOWS\MPower23.ini
[2003/04/09 07:21:50 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\trayocx.dll
[2002/11/04 15:09:46 | 000,000,025 | R--- | C] () -- C:\WINDOWS\MPowerK1.ini
[2002/10/16 09:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2000/01/31 09:02:00 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\Wh2Robo.dll
[1999/01/23 08:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1997/04/01 00:00:00 | 001,664,272 | ---- | C] () -- C:\WINDOWS\System32\MSO97V.DLL
[1997/04/01 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/04/01 00:00:00 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\MSORFS.DLL
[1997/04/01 00:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL

========== LOP Check ==========

[2008/06/26 20:57:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Activision
[2010/10/23 16:43:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Artist Colony
[2010/10/16 12:33:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/10/30 09:06:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/16 11:55:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2008/03/07 16:41:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Awem
[2005/05/25 09:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund
[2010/10/16 12:33:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2007/03/12 14:29:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\dslic
[2007/03/12 14:36:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\dslicense
[2008/05/29 18:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EdAlive
[2008/06/23 12:04:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
[2009/08/30 20:08:49 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\F1E9A331CBDB4A7EBD262857943DCAB7
[2010/03/07 11:25:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy-PizzaParty
[2010/04/22 17:56:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2010/04/25 17:08:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy3_America
[2010/05/27 17:09:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy3_Arctica
[2008/09/21 19:04:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2007/08/20 10:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FloodLightGames
[2007/08/26 19:22:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreshGames
[2010/06/13 19:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
[2008/09/15 22:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GeoVid
[2010/04/26 16:27:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GoBit Games
[2008/11/17 11:34:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HiddenSecretsNightmare
[2006/12/21 14:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Imaginext™
[2009/02/27 23:15:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2007/04/24 21:58:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterAction studios
[2007/01/04 01:20:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LearningPOWER
[2008/06/23 14:16:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ludia
[2010/07/16 17:30:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Merscom
[2005/04/25 12:47:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2010/10/16 11:52:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2008/02/02 21:52:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MGS
[2009/11/28 16:14:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/04/19 23:37:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Musicnotes
[2010/08/29 14:45:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MyVirtualHome
[2007/07/06 20:11:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2009/02/27 23:15:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2009/12/04 15:38:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaMusic
[2008/01/11 21:33:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/08/13 17:13:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/01/16 18:55:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayPond
[2010/04/26 19:19:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2009/08/09 04:34:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2010/01/12 20:55:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Princess Isabella
[2010/07/21 19:18:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2008/05/22 18:48:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2007/05/11 19:45:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/04/22 23:13:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sierra
[2009/07/08 09:47:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2010/04/29 22:42:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spotmau
[2010/06/14 20:11:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SulusGames
[2010/10/30 17:41:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/26 16:58:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\The Learning Company
[2006/01/10 19:08:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2005/11/29 11:18:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/12/06 12:11:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/02/14 15:04:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VirtualFarm
[2005/12/17 13:47:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Vivendi Universal Games
[2009/07/22 10:32:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2008/10/20 23:13:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vuvyrglo
[2007/10/09 13:22:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\XemiComputers
[2007/05/15 01:42:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom
[2010/07/19 20:54:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/08/02 06:10:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2006/02/09 17:24:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\.bittorrent
[2010/07/07 14:58:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\abgx360
[2007/04/11 15:07:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Alawar
[2010/10/11 17:09:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Anarchy
[2010/10/16 12:35:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\AVG10
[2010/04/19 20:34:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\AVG9
[2010/10/23 16:10:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Azureus
[2010/10/26 22:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\BBA3C47041CC05CF5F7CEAE09FFAF8B6
[2010/01/17 21:16:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\bfgbar
[2010/06/03 17:36:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Big Fish Games
[2010/10/28 19:00:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Bitrix Security
[2008/11/17 15:17:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Boomzap
[2007/02/25 18:17:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Canon
[2010/01/16 16:45:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Cloanto
[2010/08/16 20:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\com.gog.downloader.87F90EC6C28C7E479115BE2E026DB87A08BC420D.1
[2008/04/27 01:26:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\DAEMON Tools Pro
[2007/05/23 17:00:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Disney Interactive Studios
[2008/11/16 15:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\DiVision Studios XAvenger
[2009/12/25 19:42:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\EleFun Games
[2007/07/20 18:30:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Eyeblaster
[2008/09/21 19:04:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Flood Light Games
[2007/08/20 10:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\FloodLightGames
[2008/10/13 13:48:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\ForgottenRiddles
[2009/11/28 12:05:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Friday's games
[2007/07/22 20:13:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\GameHouse
[2008/09/15 22:39:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\GeoVid
[2007/11/13 13:35:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\GetRight
[2010/02/06 18:19:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\GetRightToGo
[2007/08/22 13:57:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\GrabIt
[2006/01/27 14:08:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Imageview
[2009/08/31 07:59:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\ImgBurn
[2005/01/21 07:46:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\InterTrust
[2007/08/24 18:21:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\iWin
[2007/11/30 00:17:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\KALiNKOsoft
[2006/01/08 15:31:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Leadertech
[2008/06/23 14:16:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Ludia
[2007/07/02 00:06:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Magic Academy
[2010/06/04 15:09:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\MagicIndie
[2010/07/16 17:30:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Merscom
[2007/07/06 20:21:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\My Games
[2010/09/13 01:56:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\NewsLeecher
[2010/08/29 11:00:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Nokia
[2009/02/27 22:24:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Nokia Multimedia Player
[2009/12/13 21:17:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Nseries
[2005/12/11 18:22:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Opera
[2009/12/04 15:27:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\PC Suite
[2010/09/03 23:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\PeaceCraft2
[2007/10/19 18:13:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\PgcEdit
[2010/08/13 17:13:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\PlayFirst
[2008/03/18 14:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\PSPDocMaker
[2009/05/26 10:00:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\RipIt4Me
[2009/11/01 12:57:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\runic games
[2010/10/03 13:13:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Sahmon Games
[2008/01/11 12:41:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\SecondLife
[2005/02/26 11:52:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\SEGA
[2010/06/14 20:11:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\SulusGames
[2009/02/01 19:58:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\TeamViewer
[2008/05/06 20:21:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\The Labyrinth Plus! Edition
[2009/03/29 22:12:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\The Path
[2007/04/28 13:10:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\tunebite
[2005/11/22 14:34:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Ulead Systems
[2007/08/26 10:13:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\VeniceMysteryData
[2007/06/23 22:30:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Viewpoint
[2009/07/23 09:10:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Vso
[2005/03/08 02:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\WholeSecurity
[2008/08/02 20:29:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Xbins
[2007/10/09 13:22:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\XemiComputers
[2007/06/29 22:53:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Zylom
[2010/10/30 17:41:48 | 000,000,388 | ---- | M] () -- C:\WINDOWS\Tasks\AVG PC Tuneup 2011 Integrator Start On Windows Logon.job
[2010/10/28 09:00:00 | 000,000,186 | ---- | M] () -- C:\WINDOWS\Tasks\C and K.job
[2010/10/30 17:37:51 | 000,000,438 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Program Check.job
[2010/10/14 03:40:00 | 000,000,372 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 48 bytes -> C:\WINDOWS:8D09A0EF29FDE6E4
@Alternate Data Stream - 40 bytes -> C:\WINDOWS\system32:7170a6db.zreglib
@Alternate Data Stream - 239 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:178093AE
@Alternate Data Stream - 238 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B722BCE5
@Alternate Data Stream - 237 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:38FF076E
@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BF6C81B2
@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A02025CE
@Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FC51BA36
@Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F43B7E8F
@Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:864881BF
@Alternate Data Stream - 230 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9D6EAEC3
@Alternate Data Stream - 228 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:22741C1F
@Alternate Data Stream - 227 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:00811B66
@Alternate Data Stream - 224 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CEE4A457
@Alternate Data Stream - 224 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:99AC3203
@Alternate Data Stream - 221 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8C81B36D
@Alternate Data Stream - 220 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:008586AE
@Alternate Data Stream - 219 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D055FC10
@Alternate Data Stream - 218 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6FD36C4B
@Alternate Data Stream - 216 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3942462
@Alternate Data Stream - 215 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ED9B661E
@Alternate Data Stream - 215 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3DB6F365
@Alternate Data Stream - 214 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8140CB50
@Alternate Data Stream - 214 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:80E965A3
@Alternate Data Stream - 213 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:56C17A93
@Alternate Data Stream - 209 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:109734F6
@Alternate Data Stream - 208 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EC2381A4
@Alternate Data Stream - 208 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A0CB43B2
@Alternate Data Stream - 206 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC0528D9
@Alternate Data Stream - 204 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BFAD7A5D
@Alternate Data Stream - 204 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:15752405
@Alternate Data Stream - 203 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F11C259D
@Alternate Data Stream - 202 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:76A59E49
@Alternate Data Stream - 201 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F0762150
@Alternate Data Stream - 201 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EC7C9796
@Alternate Data Stream - 201 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:66AA0486
@Alternate Data Stream - 200 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EC0A74A1
@Alternate Data Stream - 200 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D507B5A8
@Alternate Data Stream - 200 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:57CC1FDC
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7A0EFE63
@Alternate Data Stream - 191 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59846E5E
@Alternate Data Stream - 190 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FC4EA67C
@Alternate Data Stream - 189 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A3063E0E
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:98F0614F
@Alternate Data Stream - 158 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ED51D3ED
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:80EA2EA3
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07D9FF25
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7ADA8871
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A235FA9E
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:151760F0
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3BF63E4A
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2B4123E9
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:57B4E612
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9857FAE3
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1B7E2022
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3D36932D
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ABE30DDB
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AEBFFE08
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BEBD9BCF

< End of report >


Any help greatly appreciated
Regards
tonyjh

Edited by tonyjh, 30 October 2010 - 01:06 AM.

  • 0

Advertisements


#2
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello tonyjh,

Download ComboFix here:

Link 1
Link 2

You can use another pc to download it and then tranfer it using a USB-disk.

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Here is a guide on how to disable them

    Click me

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.

Thunderbird1988
  • 0

#3
tonyjh

tonyjh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Hi Thunderbird

Will get the the logs ASAP
Regards
tonyjh
  • 0

#4
tonyjh

tonyjh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Hi thunderbird
sorry for the delay
but i have another problem.I was installing updates from microsoft website. now i have blue screen error so am not able to get windows to load.

will have to start new topic in help forum to fix this problem first.

as computer will only boot to a blue screen with a error message.

Sorry for the inconvenience.

tonyjh
  • 0

#5
tonyjh

tonyjh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Here is the log you requested
thunderbird

ComboFix 10-11-05.05 - User1 07/11/2010 11:36:58.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.1023.483 [GMT 11:00]
Running from: c:\documents and settings\User1\Desktop\ComboFix.exe
.
ADS - system32: deleted 40 bytes in 1 streams.
ADS - WINDOWS: deleted 48 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\NetworkService\Application Data\Bitrix Security
c:\documents and settings\NetworkService\Application Data\Bitrix Security\cet.txt
c:\documents and settings\NetworkService\Application Data\Bitrix Security\exlyu
c:\documents and settings\NetworkService\Application Data\Bitrix Security\mlkee_shrd
c:\documents and settings\NetworkService\Application Data\Bitrix Security\vhrejy1_shrd
c:\documents and settings\User1\Application Data\Bitrix Security
c:\documents and settings\User1\Application Data\Bitrix Security\vhrejy1_shrd
C:\Install.exe
c:\windows\daemon.dll
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15.inf
c:\windows\system\QTIM32.DLL
c:\windows\system32\AutoRun.inf
c:\windows\system32\CBUTTON.OCX
c:\windows\system32\MnVGOqru.ini
c:\windows\system32\MnVGOqru.ini2
c:\windows\WINDOWS
c:\windows\WINDOWS\_default.pif
c:\windows\WINDOWS\0.log
c:\windows\WINDOWS\ABC.emm
c:\windows\WINDOWS\ABC.INI
c:\windows\WINDOWS\acc1.txt
c:\windows\WINDOWS\Active Setup Log.txt
c:\windows\WINDOWS\alcrmv.exe
c:\windows\WINDOWS\alcupd.exe
c:\windows\WINDOWS\AM_D8.PRF
c:\windows\WINDOWS\atmoUn.exe
c:\windows\WINDOWS\AviSplitter.INI
c:\windows\WINDOWS\avrack.ini
c:\windows\WINDOWS\BlendSettings.ini
c:\windows\WINDOWS\Blue Lace 16.bmp
c:\windows\WINDOWS\bootstat.dat
c:\windows\WINDOWS\Castles n' Dragons.jpg
c:\windows\WINDOWS\Castlesn'DragonsSS.scr
c:\windows\WINDOWS\CDER310E.ini
c:\windows\WINDOWS\CIF.ini
c:\windows\WINDOWS\clock.avi
c:\windows\WINDOWS\Clony2.ini
c:\windows\WINDOWS\Clubhouse.ini
c:\windows\WINDOWS\cmsetacl.log
c:\windows\WINDOWS\Coffee Bean.bmp
c:\windows\WINDOWS\COM+.log
c:\windows\WINDOWS\compedia.ini
c:\windows\WINDOWS\comsetup.log
c:\windows\WINDOWS\control.ini
c:\windows\WINDOWS\Converter.INI
c:\windows\WINDOWS\cool.ini
c:\windows\WINDOWS\d3dx.dat
c:\windows\WINDOWS\data4711.bak
c:\windows\WINDOWS\desktop.ini
c:\windows\WINDOWS\DirectX.log
c:\windows\WINDOWS\disney.ini
c:\windows\WINDOWS\disneysy.ini
c:\windows\WINDOWS\DPINST.LOG
c:\windows\WINDOWS\DtcInstall.log
c:\windows\WINDOWS\DUMP7493.tmp
c:\windows\WINDOWS\EGirl_v15.scr
c:\windows\WINDOWS\egirllic15
c:\windows\WINDOWS\EPISME00.SWB
c:\windows\WINDOWS\EPSTPLOG.BAK
c:\windows\WINDOWS\EPSTPLOG.TXT
c:\windows\WINDOWS\EReg077.dat
c:\windows\WINDOWS\EurekaLog.ini
c:\windows\WINDOWS\explorer.exe
c:\windows\WINDOWS\explorer.scf
c:\windows\WINDOWS\FaxSetup.log
c:\windows\WINDOWS\FeatherTexture.bmp
c:\windows\WINDOWS\FInstaller.exe
c:\windows\WINDOWS\Firefox Wallpaper.bmp
c:\windows\WINDOWS\gdrv.sys
c:\windows\WINDOWS\GEARInstall.log
c:\windows\WINDOWS\Gone Fishing.bmp
c:\windows\WINDOWS\Greenstone.bmp
c:\windows\WINDOWS\hegames.ini
c:\windows\WINDOWS\hh.exe
c:\windows\WINDOWS\hpoins15.dat
c:\windows\WINDOWS\hpomdl15.dat
c:\windows\WINDOWS\hpqins16.dat
c:\windows\WINDOWS\ibu.dll
c:\windows\WINDOWS\IDNMitigationAPIs.log
c:\windows\WINDOWS\IE4 Error Log.txt
c:\windows\WINDOWS\iis6.log
c:\windows\WINDOWS\imsins.BAK
c:\windows\WINDOWS\imsins.log
c:\windows\WINDOWS\info147.sys
c:\windows\WINDOWS\IsUn0404.exe
c:\windows\WINDOWS\IsUninst.exe
c:\windows\WINDOWS\iun506.exe
c:\windows\WINDOWS\iun507.exe
c:\windows\WINDOWS\iun6002.exe
c:\windows\WINDOWS\iun6002ev.exe
c:\windows\WINDOWS\ka.ini
c:\windows\WINDOWS\KB834707.log
c:\windows\WINDOWS\KB867282.log
c:\windows\WINDOWS\KB873333.log
c:\windows\WINDOWS\KB873339.log
c:\windows\WINDOWS\KB883939.log
c:\windows\WINDOWS\KB885250.log
c:\windows\WINDOWS\KB885835.log
c:\windows\WINDOWS\KB885836.log
c:\windows\WINDOWS\KB886185.log
c:\windows\WINDOWS\KB887472.log
c:\windows\WINDOWS\KB887742.log
c:\windows\WINDOWS\KB887797.log
c:\windows\WINDOWS\KB888113.log
c:\windows\WINDOWS\KB888302.log
c:\windows\WINDOWS\KB890046.log
c:\windows\WINDOWS\KB890047.log
c:\windows\WINDOWS\KB890175.log
c:\windows\WINDOWS\KB890859.log
c:\windows\WINDOWS\KB890923.log
c:\windows\WINDOWS\KB891781.log
c:\windows\WINDOWS\KB893066.log
c:\windows\WINDOWS\KB893086.log
c:\windows\WINDOWS\KB893756.log
c:\windows\WINDOWS\KB893803.log
c:\windows\WINDOWS\KB893803v2.log
c:\windows\WINDOWS\KB893803v2Uninst.log
c:\windows\WINDOWS\KB894391.log
c:\windows\WINDOWS\KB896358.log
c:\windows\WINDOWS\KB896422.log
c:\windows\WINDOWS\KB896423.log
c:\windows\WINDOWS\KB896424.log
c:\windows\WINDOWS\KB896428.log
c:\windows\WINDOWS\KB896688.log
c:\windows\WINDOWS\KB896727.log
c:\windows\WINDOWS\KB898461.log
c:\windows\WINDOWS\KB899587.log
c:\windows\WINDOWS\KB899588.log
c:\windows\WINDOWS\KB899591.log
c:\windows\WINDOWS\KB900485.log
c:\windows\WINDOWS\KB900725.log
c:\windows\WINDOWS\KB901017.log
c:\windows\WINDOWS\KB901190.log
c:\windows\WINDOWS\KB901214.log
c:\windows\WINDOWS\KB902400.log
c:\windows\WINDOWS\KB903235.log
c:\windows\WINDOWS\KB904706.log
c:\windows\WINDOWS\KB904942.log
c:\windows\WINDOWS\KB905414.log
c:\windows\WINDOWS\KB905749.log
c:\windows\WINDOWS\KB905915.log
c:\windows\WINDOWS\KB908519.log
c:\windows\WINDOWS\KB908531.log
c:\windows\WINDOWS\KB910437.log
c:\windows\WINDOWS\KB911280.log
c:\windows\WINDOWS\KB911562.log
c:\windows\WINDOWS\KB911564.log
c:\windows\WINDOWS\KB911565.log
c:\windows\WINDOWS\KB911567.log
c:\windows\WINDOWS\KB911927.log
c:\windows\WINDOWS\KB912475.log
c:\windows\WINDOWS\KB912475Uninst.log
c:\windows\WINDOWS\KB912812.log
c:\windows\WINDOWS\KB912919.log
c:\windows\WINDOWS\KB913446.log
c:\windows\WINDOWS\KB913580.log
c:\windows\WINDOWS\KB914388.log
c:\windows\WINDOWS\KB914389.log
c:\windows\WINDOWS\KB914440.log
c:\windows\WINDOWS\KB915865.log
c:\windows\WINDOWS\KB916281.log
c:\windows\WINDOWS\KB916595.log
c:\windows\WINDOWS\KB917013.log
c:\windows\WINDOWS\KB917159.log
c:\windows\WINDOWS\KB917344.log
c:\windows\WINDOWS\KB917422.log
c:\windows\WINDOWS\KB917734.log
c:\windows\WINDOWS\KB917953.log
c:\windows\WINDOWS\KB918118.log
c:\windows\WINDOWS\KB918439.log
c:\windows\WINDOWS\KB918899.log
c:\windows\WINDOWS\KB919007.log
c:\windows\WINDOWS\KB920213.log
c:\windows\WINDOWS\KB920214.log
c:\windows\WINDOWS\KB920670.log
c:\windows\WINDOWS\KB920683.log
c:\windows\WINDOWS\KB920685.log
c:\windows\WINDOWS\KB920872.log
c:\windows\WINDOWS\KB921398.log
c:\windows\WINDOWS\KB921503.log
c:\windows\WINDOWS\KB921883.log
c:\windows\WINDOWS\KB922582.log
c:\windows\WINDOWS\KB922616.log
c:\windows\WINDOWS\KB922760.log
c:\windows\WINDOWS\KB922819.log
c:\windows\WINDOWS\KB923191.log
c:\windows\WINDOWS\KB923414.log
c:\windows\WINDOWS\KB923689.log
c:\windows\WINDOWS\KB923694.log
c:\windows\WINDOWS\KB923980.log
c:\windows\WINDOWS\KB924191.log
c:\windows\WINDOWS\KB924270.log
c:\windows\WINDOWS\KB924496.log
c:\windows\WINDOWS\KB924667.log
c:\windows\WINDOWS\KB925398.log
c:\windows\WINDOWS\KB925454.log
c:\windows\WINDOWS\KB925486.log
c:\windows\WINDOWS\KB925902.log
c:\windows\WINDOWS\KB926239.log
c:\windows\WINDOWS\KB926255.log
c:\windows\WINDOWS\KB926436.log
c:\windows\WINDOWS\KB927779.log
c:\windows\WINDOWS\KB927802.log
c:\windows\WINDOWS\KB927891.log
c:\windows\WINDOWS\KB928090.log
c:\windows\WINDOWS\KB928255.log
c:\windows\WINDOWS\KB928843.log
c:\windows\WINDOWS\KB929120.log
c:\windows\WINDOWS\KB929123.log
c:\windows\WINDOWS\KB929399.log
c:\windows\WINDOWS\KB929969.log
c:\windows\WINDOWS\KB930178.log
c:\windows\WINDOWS\KB930916.log
c:\windows\WINDOWS\KB931261.log
c:\windows\WINDOWS\KB931784.log
c:\windows\WINDOWS\KB931836.log
c:\windows\WINDOWS\KB932168.log
c:\windows\WINDOWS\KB933360.log
c:\windows\WINDOWS\KB933729.log
c:\windows\WINDOWS\KB935839.log
c:\windows\WINDOWS\KB935840.log
c:\windows\WINDOWS\KB936021.log
c:\windows\WINDOWS\KB936357.log
c:\windows\WINDOWS\KB936782.log
c:\windows\WINDOWS\KB937143.log
c:\windows\WINDOWS\KB938127.log
c:\windows\WINDOWS\KB938828.log
c:\windows\WINDOWS\KB938829.log
c:\windows\WINDOWS\KB939653.log
c:\windows\WINDOWS\KB939683.log
c:\windows\WINDOWS\KB941202.log
c:\windows\WINDOWS\KB941568.log
c:\windows\WINDOWS\KB941569.log
c:\windows\WINDOWS\KB941644.log
c:\windows\WINDOWS\KB941693.log
c:\windows\WINDOWS\KB942763.log
c:\windows\WINDOWS\KB943055.log
c:\windows\WINDOWS\KB943460.log
c:\windows\WINDOWS\KB943485.log
c:\windows\WINDOWS\KB944653.log
c:\windows\WINDOWS\KB945553.log
c:\windows\WINDOWS\KB946026.log
c:\windows\WINDOWS\KB948590.log
c:\windows\WINDOWS\KB948881.log
c:\windows\WINDOWS\KB950749.log
c:\windows\WINDOWS\KPP.INI
c:\windows\WINDOWS\LOGI_MWX.EXE
c:\windows\WINDOWS\LOTR Dark Rider.exe
c:\windows\WINDOWS\LOTR Dark Rider.scr
c:\windows\WINDOWS\LOTR Eye of Sauron.exe
c:\windows\WINDOWS\LOTR Eye of Sauron.scr
c:\windows\WINDOWS\LOTR_Aragorn.exe
c:\windows\WINDOWS\LOTR_Aragorn.scr
c:\windows\WINDOWS\LOTR_Arwen.exe
c:\windows\WINDOWS\LOTR_Arwen.scr
c:\windows\WINDOWS\MCENU.HLP
c:\windows\WINDOWS\MFRWORDS.INI
c:\windows\WINDOWS\mickey32.dll
c:\windows\WINDOWS\ModemLog_PCI SoftV92 Modem.txt
c:\windows\WINDOWS\ModemLog_SoftK56 Data Fax Voice Speakerphone CARP.txt
c:\windows\WINDOWS\ModemLog_SoftV92 Data Fax Modem.txt
c:\windows\WINDOWS\ModemLog_Standard 56000 bps Modem.txt
c:\windows\WINDOWS\mozver.dat
c:\windows\WINDOWS\MPower23.ini
c:\windows\WINDOWS\MPowerK1.ini
c:\windows\WINDOWS\MSagent.exe
c:\windows\WINDOWS\MSCompPackV1.log
c:\windows\WINDOWS\msdfmap.ini
c:\windows\WINDOWS\msgsocm.log
c:\windows\WINDOWS\msxml4-KB936181-enu.LOG
c:\windows\WINDOWS\MYOB.INI
c:\windows\WINDOWS\MYOBP.INI
c:\windows\WINDOWS\ncc1.txt
c:\windows\WINDOWS\NeroDigital.ini
c:\windows\WINDOWS\NLSDownlevelMapping.log
c:\windows\WINDOWS\NOTEPAD.EXE
c:\windows\WINDOWS\nsreg.dat
c:\windows\WINDOWS\nsw.log
c:\windows\WINDOWS\ntbtlog.txt
c:\windows\WINDOWS\ntdtcsetup.log
c:\windows\WINDOWS\num41.jbd
c:\windows\WINDOWS\NuNinst.cfg
c:\windows\WINDOWS\NuNinst.exe
c:\windows\WINDOWS\ocgen.log
c:\windows\WINDOWS\ocmsn.log
c:\windows\WINDOWS\ODBCINST.INI
c:\windows\WINDOWS\OEWABLog.txt
c:\windows\WINDOWS\OpPrintServer.INI
c:\windows\WINDOWS\pcdlib32.dll
c:\windows\WINDOWS\PCGWIN32.LI4
c:\windows\WINDOWS\PCSPATS.DAT
c:\windows\WINDOWS\PLAY32.EXE
c:\windows\WINDOWS\PLAYENU.HLP
c:\windows\WINDOWS\PlusDMESetup.log
c:\windows\WINDOWS\popcinfo.dat
c:\windows\WINDOWS\PowerReg.dat
c:\windows\WINDOWS\Prairie Wind.bmp
c:\windows\WINDOWS\Prof.ini
c:\windows\WINDOWS\Proxyrama.INI
c:\windows\WINDOWS\PS1.ini
c:\windows\WINDOWS\QT32INST.EXE
c:\windows\WINDOWS\QTFont.for
c:\windows\WINDOWS\QTFont.qfn
c:\windows\WINDOWS\QTW.INI
c:\windows\WINDOWS\QTW32DEL.EXE
c:\windows\WINDOWS\Quicktools.INI
c:\windows\WINDOWS\RAWImage.INI
c:\windows\WINDOWS\READQT32.WRI
c:\windows\WINDOWS\regedit.exe
c:\windows\WINDOWS\regopt.log
c:\windows\WINDOWS\RESULT.QTW
c:\windows\WINDOWS\Rhododendron.bmp
c:\windows\WINDOWS\River Sumida.bmp
c:\windows\WINDOWS\robotscd.txt
c:\windows\WINDOWS\SAMPLE.MOV
c:\windows\WINDOWS\Santa Fe Stucco.bmp
c:\windows\WINDOWS\SchedLgU.Txt
c:\windows\WINDOWS\sessmgr.setup.log
c:\windows\WINDOWS\SET3.tmp
c:\windows\WINDOWS\SET4.tmp
c:\windows\WINDOWS\SET8.tmp
c:\windows\WINDOWS\setup.log
c:\windows\WINDOWS\Setup1.exe
c:\windows\WINDOWS\SETUP32.INI
c:\windows\WINDOWS\setupact.log
c:\windows\WINDOWS\setupapi.log
c:\windows\WINDOWS\setupapi.log.0.old
c:\windows\WINDOWS\setuperr.log
c:\windows\WINDOWS\setuplog.txt
c:\windows\WINDOWS\SIERRA.INI
c:\windows\WINDOWS\Soap Bubbles.bmp
c:\windows\WINDOWS\SOUNDMAN.EXE
c:\windows\WINDOWS\SpchApi.exe
c:\windows\WINDOWS\SpchCpl.exe
c:\windows\WINDOWS\spslpsrm.log
c:\windows\WINDOWS\spupdsvc.log
c:\windows\WINDOWS\SpywareDoctor5Install.log
c:\windows\WINDOWS\ssunstl.exe
c:\windows\WINDOWS\ST6UNST.EXE
c:\windows\WINDOWS\Sti_Trace.log
c:\windows\WINDOWS\SYMEVENT.LOG
c:\windows\WINDOWS\SYSINI.QTW
c:\windows\WINDOWS\syskbs2.dat
c:\windows\WINDOWS\SYSTEM.INI
c:\windows\WINDOWS\system32RegistryCleaner.txt
c:\windows\WINDOWS\TASKMAN.EXE
c:\windows\WINDOWS\Temp\50bf0f37-a907-4047-8972-5e94310f0a48.tmp
c:\windows\WINDOWS\Temp\ASPNETSetup_00000.log
c:\windows\WINDOWS\Temp\ASPNETSetup_00001.log
c:\windows\WINDOWS\Temp\ASPNETSetup_00002.log
c:\windows\WINDOWS\Temp\ASPNETSetup_00003.log
c:\windows\WINDOWS\Temp\avg8info.id
c:\windows\WINDOWS\Temp\b1498829-dee4-45a8-aae0-bb26a0f3e9a4.tmp
c:\windows\WINDOWS\Temp\BCInstaller.exe
c:\windows\WINDOWS\Temp\cbff3de3-fff0-4f1e-8dcf-8c37ba16061d.tmp
c:\windows\WINDOWS\Temp\conf.ini
c:\windows\WINDOWS\Temp\dd_depcheck_NETFX20_EXP_35.txt
c:\windows\WINDOWS\Temp\dd_dotnetfx20error.txt
c:\windows\WINDOWS\Temp\dd_dotnetfx20install.txt
c:\windows\WINDOWS\Temp\dd_NET_Framework20_Setup5466.txt
c:\windows\WINDOWS\Temp\DFC5A2B2.TMP
c:\windows\WINDOWS\Temp\hppldcoi.log
c:\windows\WINDOWS\Temp\hpqddsvc.log
c:\windows\WINDOWS\Temp\hpzEN5ha.chm
c:\windows\WINDOWS\Temp\hpzEN5ha.hlp
c:\windows\WINDOWS\Temp\HPZIDS000.log
c:\windows\WINDOWS\Temp\JLH
c:\windows\WINDOWS\Temp\MSI478f5.LOG
c:\windows\WINDOWS\Temp\MSI5167d.LOG
c:\windows\WINDOWS\Temp\MSI59be9.LOG
c:\windows\WINDOWS\Temp\netfxsl.log
c:\windows\WINDOWS\Temp\NetFxUpdate_v1.1.4322.log
c:\windows\WINDOWS\Temp\Perflib_Perfdata_164.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_184.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_1bc.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_1cc.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_1f8.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_200.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_20c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_214.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_21c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_220.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_224.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_234.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_238.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_23c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_250.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_254.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_260.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_270.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_274.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_278.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_27c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_284.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_288.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_290.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_298.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_29c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2a0.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2a4.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2a8.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2ac.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2b0.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2b4.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2b8.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2bc.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2c0.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2c4.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2c8.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2cc.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2d0.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2d4.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2d8.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2dc.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2e0.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2e4.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2e8.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2ec.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2f0.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2f4.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2f8.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_2fc.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_300.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_304.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_308.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_30c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_310.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_314.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_318.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_31c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_320.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_324.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_328.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_32c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_330.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_334.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_338.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_33c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_340.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_344.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_348.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_34c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_350.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_354.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_358.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_35c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_360.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_364.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_368.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_36c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_370.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_374.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_378.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_37c.dat
c:\windows\WINDOWS\Temp\Perflib_Perfdata_384.dat
c:\windows\WINDOWS\Thumbs.db
c:\windows\WINDOWS\TLCAPPS.INI
c:\windows\WINDOWS\TLCUninstall.exe
c:\windows\WINDOWS\tsoc.log
c:\windows\WINDOWS\Tv_enua.exe
c:\windows\WINDOWS\twain.dll
c:\windows\WINDOWS\twain_32.dll
c:\windows\WINDOWS\twain_32\hpqgnds2
c:\windows\WINDOWS\twain_32\hpqgnds2.tmp
c:\windows\WINDOWS\twain_32\hpsj_0012\hpsj_0012.ds
c:\windows\WINDOWS\twain_32\MP360\CANOIT32.EXE
c:\windows\WINDOWS\twain_32\MP360\CISDS.DS
c:\windows\WINDOWS\twain_32\MP360\CNC360.DAT
c:\windows\WINDOWS\twain_32\MP360\CNC360M.DAT
c:\windows\WINDOWS\twain_32\MP360\CSUI.DLL
c:\windows\WINDOWS\twain_32\MP360\CSUI_RES.DLL
c:\windows\WINDOWS\twain_32\MP360\DEV.DLL
c:\windows\WINDOWS\twain_32\MP360\IMGENH.DLL
c:\windows\WINDOWS\twain_32\MP360\IOP.DLL
c:\windows\WINDOWS\twain_32\MP360\ITLIB32.DLL
c:\windows\WINDOWS\twain_32\MP360\JDA_CIMG.DLL
c:\windows\WINDOWS\twain_32\MP360\JDA_MEM.DLL
c:\windows\WINDOWS\twain_32\MP360\NBS4MB.DLL
c:\windows\WINDOWS\twain_32\MP360\NBSCOR4M.DLL
c:\windows\WINDOWS\twain_32\MP360\RMSLANTC.DLL
c:\windows\WINDOWS\twain_32\MP360\SCANINTF.DLL
c:\windows\WINDOWS\twain_32\MP360\SCRPRMV.DLL
c:\windows\WINDOWS\twain_32\MP360\TPM.DLL
c:\windows\WINDOWS\twain_32\wiatwain.ds
c:\windows\WINDOWS\Twunk_16.dll
c:\windows\WINDOWS\twunk_16.exe
c:\windows\WINDOWS\Twunk_32.dll
c:\windows\WINDOWS\twunk_32.exe
c:\windows\WINDOWS\Unin.exe
c:\windows\WINDOWS\uninst.exe
c:\windows\WINDOWS\UninstallFirefox.exe
c:\windows\WINDOWS\UninstFrankClub.exe
c:\windows\WINDOWS\UNNeroVision.cfg
c:\windows\WINDOWS\UNNeroVision.exe
c:\windows\WINDOWS\UNNMP.cfg
c:\windows\WINDOWS\UNNMP.exe
c:\windows\WINDOWS\updspapi.log
c:\windows\WINDOWS\v2d.INI
c:\windows\WINDOWS\vb.ini
c:\windows\WINDOWS\vbaddin.ini
c:\windows\WINDOWS\VBRT.exe
c:\windows\WINDOWS\VIEW32.EXE
c:\windows\WINDOWS\VIEWENU.HLP
c:\windows\WINDOWS\vmmreg32.dll
c:\windows\WINDOWS\WBEM\msfeeds.mof
c:\windows\WINDOWS\WBEM\msfeedsbs.mof
c:\windows\WINDOWS\Wdf01005Inst.log
c:\windows\WINDOWS\WDIRECT.INI
c:\windows\WINDOWS\Web\AOpenClient.htm
c:\windows\WINDOWS\Web\bullet.gif
c:\windows\WINDOWS\Web\deskmovr.htt
c:\windows\WINDOWS\Web\exclam.gif
c:\windows\WINDOWS\Web\printers\images\ipp_0002.gif
c:\windows\WINDOWS\Web\printers\images\ipp_0003.gif
c:\windows\WINDOWS\Web\printers\images\ipp_0004.gif
c:\windows\WINDOWS\Web\printers\images\ipp_0005.gif
c:\windows\WINDOWS\Web\printers\images\ipp_0012.gif
c:\windows\WINDOWS\Web\printers\images\ipp_0015.gif
c:\windows\WINDOWS\Web\printers\ipp_0000.inc
c:\windows\WINDOWS\Web\printers\ipp_0001.asp
c:\windows\WINDOWS\Web\printers\ipp_0002.asp
c:\windows\WINDOWS\Web\printers\ipp_0003.asp
c:\windows\WINDOWS\Web\printers\ipp_0004.asp
c:\windows\WINDOWS\Web\printers\ipp_0005.asp
c:\windows\WINDOWS\Web\printers\ipp_0006.asp
c:\windows\WINDOWS\Web\printers\ipp_0007.asp
c:\windows\WINDOWS\Web\printers\ipp_0010.asp
c:\windows\WINDOWS\Web\printers\ipp_0013.asp
c:\windows\WINDOWS\Web\printers\ipp_0014.asp
c:\windows\WINDOWS\Web\printers\ipp_0015.asp
c:\windows\WINDOWS\Web\printers\ipp_adsi.inc
c:\windows\WINDOWS\Web\printers\ipp_res.inc
c:\windows\WINDOWS\Web\printers\ipp_util.inc
c:\windows\WINDOWS\Web\printers\page1.asp
c:\windows\WINDOWS\Web\printers\prtwebvw.css
c:\windows\WINDOWS\Web\safemode.htt
c:\windows\WINDOWS\Web\tip.htm
c:\windows\WINDOWS\Web\tips.gif
c:\windows\WINDOWS\Web\Wallpaper\Ascent.jpg
c:\windows\WINDOWS\Web\Wallpaper\Autumn.jpg
c:\windows\WINDOWS\Web\Wallpaper\Azul.jpg
c:\windows\WINDOWS\Web\Wallpaper\Bliss.bmp
c:\windows\WINDOWS\Web\Wallpaper\Crystal.jpg
c:\windows\WINDOWS\Web\Wallpaper\Follow.jpg
c:\windows\WINDOWS\Web\Wallpaper\Friend.jpg
c:\windows\WINDOWS\Web\Wallpaper\Home.jpg
c:\windows\WINDOWS\Web\Wallpaper\Moon flower.jpg
c:\windows\WINDOWS\Web\Wallpaper\Peace.jpg
c:\windows\WINDOWS\Web\Wallpaper\Power.jpg
c:\windows\WINDOWS\Web\Wallpaper\Purple flower.jpg
c:\windows\WINDOWS\Web\Wallpaper\Radiance.jpg
c:\windows\WINDOWS\Web\Wallpaper\Red moon desert.jpg
c:\windows\WINDOWS\Web\Wallpaper\Ripple.jpg
c:\windows\WINDOWS\Web\Wallpaper\Stonehenge.jpg
c:\windows\WINDOWS\Web\Wallpaper\Tulips.jpg
c:\windows\WINDOWS\Web\Wallpaper\Vortec space.jpg
c:\windows\WINDOWS\Web\Wallpaper\Wind.jpg
c:\windows\WINDOWS\Web\Wallpaper\Windows XP.jpg
c:\windows\WINDOWS\WGA.log
c:\windows\WINDOWS\WgaNotify.log
c:\windows\WINDOWS\wiadebug.log
c:\windows\WINDOWS\wiaservc.log
c:\windows\WINDOWS\WIC.log
c:\windows\WINDOWS\win.ini
c:\windows\WINDOWS\winamp.ini
c:\windows\WINDOWS\WindowsShell.Manifest
c:\windows\WINDOWS\WindowsUpdate.log
c:\windows\WINDOWS\winhelp.exe
c:\windows\WINDOWS\winhlp32.exe
c:\windows\WINDOWS\WININI.QTW
c:\windows\WINDOWS\WININIT.INI
c:\windows\WINDOWS\winnt.bmp
c:\windows\WINDOWS\winnt256.bmp
c:\windows\WINDOWS\WinSxS\Manifests\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9839.0_x-ww_ed80bd5c.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9839.0_x-ww_ed80bd5c.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_6e85597b.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_6e85597b.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a.manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.0.0_x-ww_fc342b0b.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.0.0_x-ww_fc342b0b.Manifest
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_bcc9a281.cat
c:\windows\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_bcc9a281.Manifest
c:\windows\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac\1.0.2600.2180.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac\1.0.2600.2180.Policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9839.0.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9839.0.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9841.0.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9848.0.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.4.20.Microsoft.MSXML2_6bd6b9abf345378f_x-ww_88e8eab8\4.20.9848.0.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510\5.1.2600.2000.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510\5.1.2600.2000.Policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd\5.2.2.3.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd\5.2.2.3.Policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f\5.2.2.3.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f\5.2.2.3.Policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_x-ww_527a1c68\6.0.9792.0.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_x-ww_527a1c68\6.0.9792.0.Policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2982.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2982.Policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_x-ww_a317e4b3\7.0.2600.2180.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_x-ww_a317e4b3\7.0.2600.2180.Policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\8.0.50727.42.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\8.0.50727.42.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\8.0.50727.762.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\8.0.50727.762.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\8.0.50727.91.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\8.0.50727.91.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.1433.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.1433.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.163.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.163.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.42.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.42.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.762.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.762.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.91.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.91.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_x-ww_0f75c32e\8.0.50727.42.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_x-ww_0f75c32e\8.0.50727.42.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_x-ww_0f75c32e\8.0.50727.762.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_x-ww_0f75c32e\8.0.50727.762.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_x-ww_0f75c32e\8.0.50727.91.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_x-ww_0f75c32e\8.0.50727.91.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_x-ww_caeee150\8.0.50727.42.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_x-ww_caeee150\8.0.50727.42.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_x-ww_caeee150\8.0.50727.762.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_x-ww_caeee150\8.0.50727.762.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_x-ww_caeee150\8.0.50727.91.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_x-ww_caeee150\8.0.50727.91.policy
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_x-ww_7d81c9f9\8.0.50727.762.cat
c:\windows\WINDOWS\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_x-ww_7d81c9f9\8.0.50727.762.policy
c:\windows\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\msxml4.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9839.0_x-ww_ed80bd5c\msxml4.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\msxml4.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\msxml4r.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\atl.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\mfc42.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\mfc42u.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\msvcp60.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_6e85597b\ATL80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcm80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcm80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcp80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcr80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfc80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfc80u.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfcm80.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfcm80u.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a\mfc80CHS.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a\mfc80CHT.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a\mfc80DEU.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a\mfc80ENU.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a\mfc80ESP.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a\mfc80FRA.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a\mfc80ITA.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a\mfc80JPN.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_341af80a\mfc80KOR.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcirt.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9\msvcirt.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9\msvcrt.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13\GdiPlus.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\GdiPlus.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
c:\windows\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0\rtcres.dll
c:\windows\WINDOWS\WLXPGSS.SCR
c:\windows\WINDOWS\WMFDist11.log
c:\windows\WINDOWS\wmp11.log
c:\windows\WINDOWS\wmsetup.log
c:\windows\WINDOWS\wmsetup10.log
c:\windows\WINDOWS\WMSysPr9.prx
c:\windows\WINDOWS\Wocpt.ini
c:\windows\WINDOWS\wordpad.ini
c:\windows\WINDOWS\Wudf01000Inst.log
c:\windows\WINDOWS\Zapotec.bmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_TDSSSERV


((((((((((((((((((((((((( Files Created from 2010-10-07 to 2010-11-07 )))))))))))))))))))))))))))))))
.

2010-11-02 05:22 . 2010-08-13 12:53 5120 ------w- c:\windows\system32\xpsp4res.dll
2010-11-02 05:07 . 2008-10-16 03:06 208744 ----a-w- c:\windows\system32\muweb.dll
2010-11-02 05:07 . 2008-10-16 03:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2010-11-02 05:07 . 2009-08-06 08:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-11-02 05:07 . 2009-08-06 08:24 35552 -c--a-w- c:\windows\system32\dllcache\wups.dll
2010-11-02 05:07 . 2009-08-06 08:24 35552 ----a-w- c:\windows\system32\wups.dll
2010-11-02 05:07 . 2008-10-16 03:13 202776 ----a-w- c:\windows\system32\wuweb.dll
2010-11-02 05:07 . 2008-10-16 03:12 323608 ----a-w- c:\windows\system32\wucltui.dll
2010-11-02 05:07 . 2008-10-16 03:13 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2010-11-02 05:07 . 2008-10-16 03:12 561688 ----a-w- c:\windows\system32\wuapi.dll
2010-11-02 05:07 . 2008-10-16 03:12 213528 ----a-w- c:\windows\system32\wuaucpl.cpl
2010-11-02 05:07 . 2008-10-16 03:09 92696 ----a-w- c:\windows\system32\cdm.dll
2010-11-02 05:07 . 2008-10-16 03:09 51224 ----a-w- c:\windows\system32\wuauclt.exe
2010-11-01 09:13 . 2009-09-07 03:02 27944 ----a-w- c:\windows\system32\sbbd.exe
2010-11-01 09:13 . 2009-08-05 04:58 93872 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-11-01 09:12 . 2010-11-01 14:27 -------- d-----w- C:\VIPRERESCUE
2010-10-29 17:43 . 2010-10-29 17:43 191 ----a-w- c:\documents and settings\User1\Application Data\ahfg.bat
2010-10-28 06:47 . 2010-10-28 06:50 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-10-26 11:43 . 2010-10-26 11:43 -------- d-----w- c:\documents and settings\User1\Application Data\BBA3C47041CC05CF5F7CEAE09FFAF8B6
2010-10-26 05:58 . 2010-10-26 05:58 -------- d-----w- c:\documents and settings\All Users\Application Data\The Learning Company
2010-10-16 01:44 . 2010-10-16 01:44 -------- d-----w- c:\documents and settings\User1\Local Settings\Application Data\AVG Security Toolbar
2010-10-16 01:35 . 2010-10-16 01:35 -------- d-----w- c:\documents and settings\User1\Application Data\AVG10
2010-10-16 01:33 . 2010-10-16 01:33 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2010-10-16 01:33 . 2010-10-16 01:33 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-10-16 01:32 . 2010-11-06 08:55 -------- d-----w- c:\windows\system32\drivers\AVG
2010-10-16 01:32 . 2010-11-02 04:14 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG10
2010-10-16 00:50 . 2010-10-16 00:52 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2010-10-15 09:08 . 2010-10-23 05:50 -------- d-----w- c:\documents and settings\User1\Application Data\Realore_Whiterra Roads Of Rome
2010-10-15 05:41 . 2010-10-15 05:42 -------- d-----w- c:\program files\Roads of Rome
2010-10-15 05:37 . 2010-10-15 05:39 -------- d-----w- c:\program files\Kate Arrow - Deserted Wood
2010-10-15 05:36 . 2010-10-15 05:37 -------- d-----w- c:\program files\Help Felix Find a Cure
2010-10-15 05:34 . 2010-10-15 05:36 -------- d-----w- c:\program files\Enlightenus II - The Timeless Tower
2010-10-15 05:27 . 2010-10-15 05:34 -------- d-----w- c:\program files\Dark Tales - Edgar Allan Poe's The Black Cat Collector's Edition
2010-10-15 04:25 . 2010-10-15 04:26 -------- d-----w- c:\program files\Columbus - Ghost of the Mystery Stone
2010-10-12 09:47 . 2010-10-12 09:47 -------- d-----w- c:\program files\EA Sports
2010-10-11 06:09 . 2010-10-11 06:09 -------- d-----w- c:\documents and settings\User1\Application Data\Anarchy
2010-10-11 06:07 . 2010-10-11 06:07 -------- d-----w- c:\program files\Coffee Rush 2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 06:53 . 2004-08-04 12:00 954368 ------w- c:\windows\system32\mfc40.dll
2010-09-18 01:23 . 2004-08-04 12:00 974848 ------w- c:\windows\system32\mfc42u.dll
2010-09-13 05:27 . 2010-09-13 05:27 25680 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2010-09-09 13:38 . 2004-08-04 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-09-09 13:38 . 2004-08-04 12:00 1830912 ------w- c:\windows\system32\inetcpl.cpl
2010-09-06 16:49 . 2010-09-06 16:49 298448 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-09-06 16:48 . 2010-09-06 16:48 34384 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-09-06 16:48 . 2010-09-06 16:48 249424 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-09-06 16:48 . 2010-09-06 16:48 26064 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-08-19 10:42 . 2010-08-19 10:42 30288 ----a-w- c:\windows\system32\drivers\AVGIDSFilter.sys
2010-08-19 10:42 . 2010-08-19 10:42 123472 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
2010-08-19 10:42 . 2010-08-19 10:42 26192 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2010-08-09 19:15 . 2010-08-09 19:15 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-08-09 19:15 . 2010-08-09 19:15 69632 ----a-w- c:\windows\system32\QuickTime.qts
2007-05-25 23:26 . 2008-06-05 05:34 403856 ----a-w- c:\program files\un_Star Defender 4_26816.exe
2005-01-29 00:25 . 2005-01-29 00:25 8956040 ----a-w- c:\program files\InstallSnSBingo.exe
.

------- Sigcheck -------

[-] 2007-02-09 . 05AB81909514BFD69CBB1F2C147CF6B9 . 574976 . . [5.1.2600.3081] . . c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
[-] 2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . [5.1.2600.3081] . . c:\windows\$NtServicePackUninstall$\ntfs.sys
[-] 2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . [5.1.2600.3081] . . c:\windows\system32\dllcache\ntfs.sys
[-] 2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . [5.1.2600.3081] . . c:\windows\system32\drivers\ntfs.sys
[7] 2004-08-04 . B78BE402C3F63DD55521F73876951CDD . 574592 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB930916$\ntfs.sys

[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\$NtServicePackUninstall$\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\system32\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\system32\dllcache\netman.dll
[-] 2005-08-22 . 3516D8A18B36784B1005B950B84232E1 . 197632 . . [5.1.2600.2743] . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll
[7] 2004-08-04 . DAB9E6C7105D2EF49876FE92C524F565 . 198144 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB905414$\netman.dll

[7] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\rpcss.dll
[7] 2009-02-09 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[7] 2009-02-09 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\rpcss.dll
[7] 2009-02-09 . 01095FEBF33BEEA00C2A0730B9B3EC28 . 399360 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\rpcss.dll
[7] 2009-02-09 . 24B5D53B9ACCC1E2EDCF0A878D6659D4 . 401408 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\rpcss.dll
[7] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\system32\rpcss.dll
[-] 2005-07-26 . CE94A2BD25E3E9F4D46A7373FF455C6D . 397824 . . [5.1.2600.2726] . . c:\windows\system32\dllcache\rpcss.dll
[-] 2005-07-26 . C369DF215D352B6F3A0B8C3469AA34F8 . 398336 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\rpcss.dll
[-] 2005-04-28 . DA383FB39A6F1C445F3AFC94B3EB1248 . 396288 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll
[-] 2005-04-28 . C8061F289E000703E7672916B7FE1571 . 395776 . . [5.1.2600.2665] . . c:\windows\$NtUninstallKB902400$\rpcss.dll
[-] 2005-01-14 . 419899803CA479B73B02390318C787C0 . 395776 . . [5.1.2600.2595] . . c:\windows\$NtUninstallKB894391$\rpcss.dll
[-] 2005-01-14 . 94456045BEB4545B5EBE1DCC85951AFA . 395776 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2QFE\rpcss.dll
[7] 2004-08-04 . 5C83A4408604F737717AB96371201680 . 395776 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB873333$\rpcss.dll

[7] 2010-08-17 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024] . . c:\windows\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[7] 2010-08-17 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024] . . c:\windows\SoftwareDistribution\Download\9460002f6d8231358fc1eb590f9b1dce\sp3qfe\spoolsv.exe
[7] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\SoftwareDistribution\Download\9460002f6d8231358fc1eb590f9b1dce\sp3gdr\spoolsv.exe
[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2347290$\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\system32\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\system32\dllcache\spoolsv.exe
[7] 2004-08-04 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896423$\spoolsv.exe

[7] 2010-08-23 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82] . . c:\windows\SoftwareDistribution\Download\21cbd3f70584651805685eba1753505f\SP3QFE\comctl32.dll
[7] 2010-08-23 . 736B12B725AEB2B07F0241A9F680CB10 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\21cbd3f70584651805685eba1753505f\asms\60\msft\windows\common\controls\comctl32.dll
[7] 2010-08-23 . 736B12B725AEB2B07F0241A9F680CB10 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\21cbd3f70584651805685eba1753505f\SP3QFE\asms\60\msft\windows\common\controls\comctl32.dll
[7] 2010-08-23 . 736B12B725AEB2B07F0241A9F680CB10 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
[7] 2008-04-14 . BD38D1EBE24A46BD3EDA059560AFBA12 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
[7] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\$NtUninstallKB2296011$\comctl32.dll
[-] 2006-08-25 . B0124CB21D28B1C9F678B566B6B57D92 . 617472 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll
[-] 2006-08-25 . B0124CB21D28B1C9F678B566B6B57D92 . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2006-08-25 . B0124CB21D28B1C9F678B566B6B57D92 . 617472 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll
[-] 2006-08-25 . C4E80875C1CF1222FC5EFD0314AE5C01 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
[7] 2004-08-04 . A77DFB85FAEE49D66C74DA6024EBC69B . 611328 . . [5.82] . . c:\windows\$NtUninstallKB923191$\comctl32.dll
[7] 2004-08-04 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[7] 2004-08-04 . 5AF68A5E44734A082442668E9C787743 . 1050624 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[7] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\SoftwareDistribution\Download\022593ca08eb4cd8e9681a7116f902d9\sp3gdr\kernel32.dll
[7] 2009-03-21 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[7] 2009-03-21 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\SoftwareDistribution\Download\022593ca08eb4cd8e9681a7116f902d9\sp3qfe\kernel32.dll
[7] 2008-04-14 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB959426$\kernel32.dll
[7] 2008-04-14 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\022593ca08eb4cd8e9681a7116f902d9\backup\sp3gdr\kernel32.dll
[-] 2007-04-16 . 09F7CB3687F86EDAA4CA081F7AB66C03 . 986112 . . [5.1.2600.3119] . . c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
[-] 2007-04-16 . A01F9CA902A88F7CED06884174D6419D . 984576 . . [5.1.2600.3119] . . c:\windows\$NtServicePackUninstall$\kernel32.dll
[-] 2007-04-16 . A01F9CA902A88F7CED06884174D6419D . 984576 . . [5.1.2600.3119] . . c:\windows\system32\kernel32.dll
[-] 2007-04-16 . A01F9CA902A88F7CED06884174D6419D . 984576 . . [5.1.2600.3119] . . c:\windows\system32\dllcache\kernel32.dll
[-] 2006-07-05 . 0FDD84928A5DDE2510761B7EC76CCEC9 . 985088 . . [5.1.2600.2945] . . c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
[-] 2006-07-05 . D8DB5397DE07577C1CB50BA6D23B3AD4 . 984064 . . [5.1.2600.2945] . . c:\windows\$NtUninstallKB935839$\kernel32.dll
[7] 2004-08-04 . 888190E31455FAD793312F8D087146EB . 983552 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB917422$\kernel32.dll

[-] 2005-09-01 . 648BF0B4DDE4F7A1156DAE7174D36EFA . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\system32\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\system32\dllcache\linkinfo.dll
[7] 2004-08-04 . C2BBD044C741EA4292016C36F718D2E4 . 18944 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB900725$\linkinfo.dll

[-] 2005-07-08 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\system32\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\system32\dllcache\tapisrv.dll
[7] 2004-08-04 . EB4A4187D74A8EFDCBEA3EA2CB1BDFBD . 246272 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB893756$\tapisrv.dll

[-] 2007-03-08 . 7AA4F6C00405DFC4B70ED4214E7D687B . 578048 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\system32\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\system32\dllcache\user32.dll
[-] 2005-03-02 . 1800F293BCCC8EDE8A70E12B88D80036 . 577024 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2005-03-02 . DE2DB164BBB35DB061AF0997E4499054 . 577024 . . [5.1.2600.2622] . . c:\windows\$NtUninstallKB925902$\user32.dll
[7] 2004-08-04 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB890859$\user32.dll

[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\system32\dllcache\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe

[7] 2010-07-16 . 7A6A7900B5E322763430BA6FD9A31224 . 1288192 . . [5.1.2600.6010] . . c:\windows\SoftwareDistribution\Download\e104dcd29adf1c6c473a5efad2d509be\sp3gdr\ole32.dll
[7] 2010-07-16 . 8D51FB47062F2A1A9EFECCEF338A4C46 . 1289216 . . [5.1.2600.6010] . . c:\windows\$hf_mig$\KB979687\SP3QFE\ole32.dll
[7] 2010-07-16 . 8D51FB47062F2A1A9EFECCEF338A4C46 . 1289216 . . [5.1.2600.6010] . . c:\windows\SoftwareDistribution\Download\e104dcd29adf1c6c473a5efad2d509be\sp3qfe\ole32.dll
[7] 2008-04-14 . ECCE74BC6168375016450A86A164D976 . 1287168 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB979687$\ole32.dll
[-] 2005-07-26 . AB8231D13692AC5088EB9C226B0C0576 . 1285120 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\ole32.dll
[-] 2005-07-26 . AB8231D13692AC5088EB9C226B0C0576 . 1285120 . . [5.1.2600.2726] . . c:\windows\system32\ole32.dll
[-] 2005-07-26 . AB8231D13692AC5088EB9C226B0C0576 . 1285120 . . [5.1.2600.2726] . . c:\windows\system32\dllcache\ole32.dll
[-] 2005-07-26 . A2F755E237FA2CDD748A80BFBE6657F3 . 1285632 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\ole32.dll
[-] 2005-04-28 . 7440D29F257B7E44329343F944F2142C . 1286144 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\ole32.dll
[-] 2005-04-28 . 5950E4F28FDA9D147576BF6798937397 . 1285120 . . [5.1.2600.2665] . . c:\windows\$NtUninstallKB902400$\ole32.dll
[-] 2005-01-14 . ABDEF60CED7C04AB35A415EFB6B96D81 . 1285120 . . [5.1.2600.2595] . . c:\windows\$NtUninstallKB894391$\ole32.dll
[-] 2005-01-14 . 2E752611C9A9AE1B6BFD0DA03CF7F17E . 1284608 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2QFE\ole32.dll
[7] 2004-08-04 . 4FE9D9FA62D020E35E0AC6D1AEEB96F0 . 1281536 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB873333$\ole32.dll

[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\system32\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\system32\dllcache\shsvcs.dll
[-] 2006-12-19 . 53D9184A21C5CBF600D918E51EF3A7E5 . 135168 . . [6.00.2900.3051] . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll
[7] 2004-08-04 . E7518DC542D3EBDCB80EDD98462C7821 . 134656 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB928255$\shsvcs.dll

[-] 2006-02-15 00:30 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$hf_mig$\KB900485\SP2QFE\aec.sys
[-] 2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$NtServicePackUninstall$\aec.sys
[-] 2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\Driver Cache\i386\aec.sys
[-] 2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\system32\dllcache\aec.sys
[-] 2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\system32\drivers\aec.sys
[7] 2004-08-04 06:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\$NtUninstallKB900485$\aec.sys

[7] 2010-09-18 07:18 . 842900DEDBC8E3E8DBCCCB298FD88F65 . 953856 . . [4.1.6151] . . c:\windows\$hf_mig$\KB2387149\SP3QFE\mfc40u.dll
[7] 2010-09-18 07:18 . 842900DEDBC8E3E8DBCCCB298FD88F65 . 953856 . . [4.1.6151] . . c:\windows\SoftwareDistribution\Download\b91377d1d56820d9d699c0c2dc7c8e80\SP3QFE\mfc40u.dll
[7] 2010-09-18 06:53 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . c:\windows\SoftwareDistribution\Download\b91377d1d56820d9d699c0c2dc7c8e80\SP3GDR\mfc40u.dll
[7] 2008-04-14 00:11 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\$NtUninstallKB2387149$\mfc40u.dll
[-] 2006-11-01 19:17 . 925F8B61ED301A317BA850EBEECBDAA0 . 927504 . . [4.1.0.61] . . c:\windows\$NtServicePackUninstall$\mfc40u.dll
[-] 2006-11-01 19:17 . 925F8B61ED301A317BA850EBEECBDAA0 . 927504 . . [4.1.0.61] . . c:\windows\system32\mfc40u.dll
[-] 2006-11-01 19:17 . 925F8B61ED301A317BA850EBEECBDAA0 . 927504 . . [4.1.0.61] . . c:\windows\system32\dllcache\mfc40u.dll
[-] 2004-08-04 12:00 . DDF8D47ACF8FC3FE5F7F2B95C4D4D136 . 924432 . . [4.1.6140] . . c:\windows\$NtUninstallKB924667$\mfc40u.dll

[-] 2007-02-05 . 36ACA6CDC19C95FF468A1426EB7F32F0 . 185344 . . [5.1.2600.3077] . . c:\windows\$hf_mig$\KB931261\SP2QFE\upnphost.dll
[-] 2007-02-05 . ACA5D98663D879C6BAAFCEA7E2F1B710 . 185344 . . [5.1.2600.3077] . . c:\windows\$NtServicePackUninstall$\upnphost.dll
[-] 2007-02-05 . ACA5D98663D879C6BAAFCEA7E2F1B710 . 185344 . . [5.1.2600.3077] . . c:\windows\system32\upnphost.dll
[-] 2007-02-05 . ACA5D98663D879C6BAAFCEA7E2F1B710 . 185344 . . [5.1.2600.3077] . . c:\windows\system32\dllcache\upnphost.dll
[7] 2004-08-04 . 0546477BDE979E33294FE97F6B3DE84A . 185344 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB931261$\upnphost.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-12 68856]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-05-14 67072]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-04-02 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-08-31 421160]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2010-09-14 2745696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoWelcomeScreen"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-31 11:39 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\MsgPlusLoader.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Nokia Ovi Suite.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Nokia Ovi Suite.lnk
backup=c:\windows\pss\Nokia Ovi Suite.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^User1^Start Menu^Programs^Startup^Xfire.lnk]
path=c:\documents and settings\User1\Start Menu\Programs\Startup\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2007-08-08 07:51 148760 ----a-w- c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-08-08 08:00 1945424 ----a-w- c:\program files\Seagate\DiscWizard\TimounterMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-02 18:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2009-03-17 07:21 203928 ----a-w- c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2009-08-08 12:30 2980800 ----a-w- c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
2004-08-22 06:05 81920 ----a-w- c:\program files\D-Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Desktop Calendar XP]
2007-01-16 19:36 471040 ----a-w- c:\program files\Desktop Calendar XP\Desktop Calendar XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiscWizardMonitor.exe]
2007-08-08 07:47 1169456 ----a-w- c:\program files\Seagate\DiscWizard\DiscWizardMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskeeperSystray]
2005-11-22 06:38 221184 ----a-w- c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo R310 Series]
2003-09-11 03:00 99840 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_S4I3F2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EverioService]
2006-11-22 10:10 151552 ----a-w- c:\program files\CyberLink\PCM4Everio\EverioService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 14:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 10:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2004-08-04 12:00 44032 ----a-w- c:\windows\ime\imkr6_1\imekrmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-08-04 12:00 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-12-11 21:31 1840424 ----a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-08-31 22:32 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
2003-12-16 22:50 19968 ------w- c:\windows\LOGI_MWX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2004-08-04 12:00 59392 ----a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2008-12-02 04:29 2221352 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-11-05 21:25 570664 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia FastStart]
2008-10-17 08:18 2323680 ----a-w- c:\program files\Nokia\Nokia Music\NokiaMusic.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2008-12-03 01:47 1205760 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCCloneEX]
2008-06-09 07:53 4204032 ------w- c:\program files\PCCloneEX\PCCloneEX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
2007-01-29 14:39 1432064 ----a-w- c:\program files\PeerGuardian2\pg2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2004-08-04 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2004-08-04 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-09-06 05:09 413696 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 00:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2009-03-04 07:39 1830128 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-10-12 00:22 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\PeerGuardian2\\pg2.exe"=
"c:\\Program Files\\Alcohol Soft\\Alcohol 120\\Alcohol.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\EGirl_v15\\EGirl_Loader.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\DVD Decrypter\\DVDDecrypter.exe"=
"c:\\Program Files\\DVD Shrink\\DVD Shrink 3.2.exe"=
"c:\\ijji\\ENGLISH\\u_sf\\soldierfront.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe"=
"c:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe"=
"c:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"c:\\Documents and Settings\\User1\\Desktop\\TONY\\Xbins\\Xbins\\bin\\xbins.exe"=
"c:\\Program Files\\DVDFab Platinum 4\\DVDFabPlatinum.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MP.exe"=
"c:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MPLite.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Documents and Settings\\User1\\My Documents\\dshutdown\\DShutdown\\RDShutdown.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2001:TCP"= 2001:TCP:dc++
"2000:UDP"= 2000:UDP:dc++
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800

R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [25/07/2005 6:37 PM 5248]
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [13/09/2010 4:27 PM 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7/09/2010 3:48 AM 26064]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [4/02/2009 5:45 PM 5248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26/04/2009 6:49 PM 685816]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7/09/2010 3:48 AM 249424]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/09/2010 3:49 AM 298448]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [28/05/2008 11:33 AM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [28/05/2008 11:33 AM 55024]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [1/11/2010 8:13 PM 93872]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [11/10/2010 12:58 PM 6104656]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [19/08/2010 9:42 PM 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [19/08/2010 9:42 PM 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [19/08/2010 9:42 PM 26192]
S0 a347bus;a347bus;c:\windows\system32\DRIVERS\a347bus.sys --> c:\windows\system32\DRIVERS\a347bus.sys [?]
S0 d347bus;d347bus;c:\windows\system32\DRIVERS\d347bus.sys --> c:\windows\system32\DRIVERS\d347bus.sys [?]
S0 ztkbxvda;ztkbxvda; [x]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [10/09/2010 1:45 AM 265400]
S2 EZWRIT3;EZWRIT3;c:\windows\system32\drivers\ezwrit3.sys [23/02/2007 2:46 PM 12672]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6/02/2010 11:19 AM 135664]
S3 APLOADER;APLOADER;c:\windows\system32\drivers\ApLoader.SYS [23/02/2007 2:45 PM 21376]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe --> c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [?]
S3 Dual Mode;Dual Mode Video Capture;c:\windows\system32\drivers\CoachVc.sys [4/01/2007 1:48 AM 44928]
S3 MayPro;TigerGame SuperJoy Box Pro Filter Service;c:\windows\system32\drivers\Maypro.sys [31/05/2007 11:21 PM 12160]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [28/05/2008 11:33 AM 7408]
S3 sdAuxService;Spyware Doctor Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [18/05/2007 11:24 PM 708176]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [13/10/2006 7:18 PM 223128]
S4 Perpeervc;Perpeervc;c:\windows\system32\EPSTP32U.EXE [9/04/2004 6:06 AM 892928]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-10-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 01:50]

2010-11-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 00:12]

2010-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 00:12]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=zuzed004YYAU_ZZzer000&fl=0&ptb=PzN_SO5Cim2gy1uJCmB.Uw&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
uStart Page = hxxp://www.dodo.com.au/
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:28091
uSearchURL,(Default) = hxxp://www.accoona.com/search?q=%s
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949}
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
FF - ProfilePath - c:\documents and settings\User1\Application Data\Mozilla\Firefox\Profiles\6aecx7x9.julie\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cb900e7&v=6.010.006.004&i=23&tp=ab&iy=&ychte=au&lng=en-US&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 81
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\User1\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected]\components\PlaySushiFF.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPOFF12.DLL
FF - plugin: c:\program files\Picasa2\npPicasa3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- FIREFOX POLICIES ----
c:\progra~1\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\progra~1\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\progra~1\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\progra~1\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\progra~1\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\progra~1\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\progra~1\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\progra~1\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\progra~1\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\progra~1\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\progra~1\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-RunServices-tcp checker - tcpcheck.exe
HKU-Default-RunServices-tcp checker - tcpcheck.exe
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
AddRemove-AVG - c:\program files\AVG\AVG10\avgmfapx.exe
AddRemove-BFG-Cake Mania - Lights, Camera, Action - c:\program files\Cake Mania - Lights
AddRemove-BFG-Wedding Dash - Ready, Aim, Love - c:\program files\Wedding Dash - Ready
AddRemove-{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1 - c:\program files\AVG\AVG PC Tuneup 2011\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-07 12:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1220945662-1532298954-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{42F7913E-DCED-900F-61DE-39C97326557E}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1220945662-1532298954-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:99,a0,a2,16,d4,df,47,17,f4,f5,99,0e,84,23,fa,f5,68,3c,f4,ba,00,dc,09,
e4,0a,be,d3,1d,e2,fa,5d,6f,0a,36,57,23,7c,ba,da,fa,f6,64,4e,83,0f,b1,01,0b,\
"??"=hex:c1,60,1f,b9,56,6f,c7,85,eb,0b,21,2f,04,b8,6f,83

[HKEY_USERS\S-1-5-21-1220945662-1532298954-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:59,53,1c,5f,43,06,44,30,03,cd,b8,73,12,04,03,97,93,fe,4f,bd,47,
50,a3,7f,d8,50,1c,45,b3,a6,f6,2e,0c,9d,03,66,bf,13,5e,13,ab,dd,a4,8b,ee,a6,\
"rkeysecu"=hex:59,27,7a,7e,e9,f6,d3,63,af,88,b2,41,e1,cb,a3,86

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(972)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1048)
c:\windows\system32\relog_ap.dll

- - - - - - - > 'explorer.exe'(2944)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\AVG\AVG10\avgrsx.exe
c:\program files\Common Files\Seagate\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\UAService7.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Nokia\PC Connectivity Solution\ServiceLayer.exe
c:\program files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Completion time: 2010-11-07 12:44:42 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-07 01:44

Pre-Run: 82,619,101,184 bytes free
Post-Run: 92,094,156,800 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 5FD7C1B63FB0B32EA4BF5B29F9752FB0

Sorry for the delay
Regards
tonyjh
  • 0

#6
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello,

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    Posted Image

  • If an infected file is detected, the default action will be Cure, click on Continue.


    Posted Image

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    Posted Image

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    Posted Image

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    • c:\windows\explorer.exe
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

After that, please post the logs and a new OTL log.

Thunderbird1988
  • 0

#7
tonyjh

tonyjh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Here's the first

2010/11/08 20:22:15.0062 TDSS rootkit removing tool 2.4.5.1 Oct 26 2010 11:28:49
2010/11/08 20:22:15.0062 ================================================================================
2010/11/08 20:22:15.0062 SystemInfo:
2010/11/08 20:22:15.0062
2010/11/08 20:22:15.0062 OS Version: 5.1.2600 ServicePack: 3.0
2010/11/08 20:22:15.0062 Product type: Workstation
2010/11/08 20:22:15.0062 ComputerName: JULLE-FD9C65E74
2010/11/08 20:22:15.0062 UserName: User1
2010/11/08 20:22:15.0062 Windows directory: C:\WINDOWS
2010/11/08 20:22:15.0062 System windows directory: C:\WINDOWS
2010/11/08 20:22:15.0062 Processor architecture: Intel x86
2010/11/08 20:22:15.0062 Number of processors: 2
2010/11/08 20:22:15.0062 Page size: 0x1000
2010/11/08 20:22:15.0062 Boot type: Normal boot
2010/11/08 20:22:15.0062 ================================================================================
2010/11/08 20:22:15.0328 Initialize success
2010/11/08 20:22:23.0296 ================================================================================
2010/11/08 20:22:23.0296 Scan started
2010/11/08 20:22:23.0296 Mode: Manual;
2010/11/08 20:22:23.0296 ================================================================================
2010/11/08 20:22:23.0921 a347scsi (113e4b318bbaa7483ca4e582a4d63f49) C:\WINDOWS\system32\Drivers\a347scsi.sys
2010/11/08 20:22:24.0046 a347scsi - detected Unsigned file (1)
2010/11/08 20:22:24.0203 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/11/08 20:22:24.0968 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2010/11/08 20:22:25.0453 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
2010/11/08 20:22:25.0484 aec - detected Unsigned file (1)
2010/11/08 20:22:25.0546 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
2010/11/08 20:22:25.0906 ALCXSENS (ba88534a3ceb6161e7432438b9ea4f54) C:\WINDOWS\system32\drivers\ALCXSENS.SYS
2010/11/08 20:22:26.0156 ALCXWDM (a886a879d2d05d942c3565c4d451ec23) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2010/11/08 20:22:26.0468 AnyDVD (cb5f75ea66bf555ba6dff01c1e63ab84) C:\WINDOWS\system32\Drivers\AnyDVD.sys
2010/11/08 20:22:26.0734 APLOADER (4cb340d7ddfbcb52bbe6979fde6106b3) C:\WINDOWS\system32\drivers\ApLoader.sys
2010/11/08 20:22:26.0750 APLOADER - detected Unsigned file (1)
2010/11/08 20:22:27.0062 ASPI32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\aspi32.sys
2010/11/08 20:22:27.0093 ASPI32 - detected Unsigned file (1)
2010/11/08 20:22:27.0203 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/11/08 20:22:27.0406 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/11/08 20:22:27.0703 ati2mtag (4938ad74de9088f70922fabf86912eee) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2010/11/08 20:22:27.0875 atksgt (6e996cf8459a2594e0e9609d0e34d41f) C:\WINDOWS\system32\DRIVERS\atksgt.sys
2010/11/08 20:22:27.0921 atksgt - detected Unsigned file (1)
2010/11/08 20:22:27.0984 Atmarp
  • 0

#8
tonyjh

tonyjh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Here's the first

2010/11/08 20:22:15.0062 TDSS rootkit removing tool 2.4.5.1 Oct 26 2010 11:28:49
2010/11/08 20:22:15.0062 ================================================================================
2010/11/08 20:22:15.0062 SystemInfo:
2010/11/08 20:22:15.0062
2010/11/08 20:22:15.0062 OS Version: 5.1.2600 ServicePack: 3.0
2010/11/08 20:22:15.0062 Product type: Workstation
2010/11/08 20:22:15.0062 ComputerName: JULLE-FD9C65E74
2010/11/08 20:22:15.0062 UserName: User1
2010/11/08 20:22:15.0062 Windows directory: C:\WINDOWS
2010/11/08 20:22:15.0062 System windows directory: C:\WINDOWS
2010/11/08 20:22:15.0062 Processor architecture: Intel x86
2010/11/08 20:22:15.0062 Number of processors: 2
2010/11/08 20:22:15.0062 Page size: 0x1000
2010/11/08 20:22:15.0062 Boot type: Normal boot
2010/11/08 20:22:15.0062 ================================================================================
2010/11/08 20:22:15.0328 Initialize success
2010/11/08 20:22:23.0296 ================================================================================
2010/11/08 20:22:23.0296 Scan started
2010/11/08 20:22:23.0296 Mode: Manual;
2010/11/08 20:22:23.0296 ================================================================================
2010/11/08 20:22:23.0921 a347scsi (113e4b318bbaa7483ca4e582a4d63f49) C:\WINDOWS\system32\Drivers\a347scsi.sys
2010/11/08 20:22:24.0046 a347scsi - detected Unsigned file (1)
2010/11/08 20:22:24.0203 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/11/08 20:22:24.0968 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2010/11/08 20:22:25.0453 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
2010/11/08 20:22:25.0484 aec - detected Unsigned file (1)
2010/11/08 20:22:25.0546 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
2010/11/08 20:22:25.0906 ALCXSENS (ba88534a3ceb6161e7432438b9ea4f54) C:\WINDOWS\system32\drivers\ALCXSENS.SYS
2010/11/08 20:22:26.0156 ALCXWDM (a886a879d2d05d942c3565c4d451ec23) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2010/11/08 20:22:26.0468 AnyDVD (cb5f75ea66bf555ba6dff01c1e63ab84) C:\WINDOWS\system32\Drivers\AnyDVD.sys
2010/11/08 20:22:26.0734 APLOADER (4cb340d7ddfbcb52bbe6979fde6106b3) C:\WINDOWS\system32\drivers\ApLoader.sys
2010/11/08 20:22:26.0750 APLOADER - detected Unsigned file (1)
2010/11/08 20:22:27.0062 ASPI32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\aspi32.sys
2010/11/08 20:22:27.0093 ASPI32 - detected Unsigned file (1)
2010/11/08 20:22:27.0203 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/11/08 20:22:27.0406 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/11/08 20:22:27.0703 ati2mtag (4938ad74de9088f70922fabf86912eee) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2010/11/08 20:22:27.0875 atksgt (6e996cf8459a2594e0e9609d0e34d41f) C:\WINDOWS\system32\DRIVERS\atksgt.sys
2010/11/08 20:22:27.0921 atksgt - detected Unsigned file (1)
2010/11/08 20:22:27.0984 Atmarp
  • 0

#9
tonyjh

tonyjh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Here's the next

VirSCAN.org Scanned Report :
Scanned time : 2010/11/08 20:07:44 (EST)
Scanner results: Scanners did not find malware!
File Name : explorer.exe
File Size : 1033216 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 97bd6515465659ff8f3b7be375b2ea87
SHA1 : 972307a3ef93680afdd03603df20f2241047a934
Online report : http://virscan.org/r...8fab6c5f4c.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.0.0.20 20101106030637 2010-11-06 40.09 -
AhnLab V3 2010.11.07.00 2010.11.07 2010-11-07 40.09 -
AntiVir 8.2.4.92 7.10.13.166 2010-11-08 0.27 -
Antiy 2.0.18 20101106.5534523 2010-11-06 0.02 -
Arcavir 2010 201011081357 2010-11-08 0.13 -
Authentium 5.1.1 201011080202 2010-11-08 2.29 -
AVAST! 4.7.4 101107-1 2010-11-07 0.06 -
AVG 8.5.850 271.1.1/3243 2010-11-08 0.27 -
BitDefender 7.90123.6206867 7.34592 2010-11-08 4.70 -
ClamAV 0.96.3 12213 2010-11-06 0.23 -
Comodo 4.0 6650 2010-11-08 40.09 -
CP Secure 1.3.0.5 2010.11.08 2010-11-08 0.11 -
Dr.Web 5.0.2.3300 2010.11.08 2010-11-08 9.85 -
F-Prot 4.4.4.56 20101107 2010-11-07 2.23 -
F-Secure 7.02.73807 2010.11.08.02 2010-11-08 11.31 -
Fortinet 4.2.249 12.542 2010-11-07 40.08 -
GData 21.1061/21.458 20101108 2010-11-08 40.09 -
ViRobot 20101106 2010.11.06 2010-11-06 40.09 -
Ikarus T3.1.32.15.0 2010.11.08.77111 2010-11-08 4.89 -
JiangMin 13.0.900 2010.11.06 2010-11-06 40.09 -
Kaspersky 5.5.10 2010.11.07 2010-11-07 0.09 -
KingSoft 2009.2.5.15 2010.11.8.14 2010-11-08 40.09 -
McAfee 5400.1158 6160 2010-11-07 18.38 -
Microsoft 1.6301 2010.11.08 2010-11-08 40.09 -
Norman 6.06.10 6.06.00 2010-11-07 8.01 -
Panda 9.05.01 2010.11.06 2010-11-06 40.09 -
Trend Micro 9.120-1004 7.602.06 2010-11-07 0.00 -
Quick Heal 11.00 2010.11.06 2010-11-06 40.09 -
Rising 20.0 22.72.06.04 2010-11-07 40.09 -
Sophos 3.13.1 4.59 2010-11-08 3.69 -
Sunbelt 3.9.2457.2 7248 2010-11-07 33.89 -
Symantec 1.3.0.24 20101107.003 2010-11-07 0.44 -
nProtect 20101108.01 9055740 2010-11-08 31.99 -
The Hacker 6.7.0.1 v00080 2010-11-07 0.47 -
VBA32 3.12.14.1 20101105.0833 2010-11-05 7.95 -
VirusBuster 4.5.11.10 10.130.14/1984733 2010-11-08 2.91 -
  • 0

#10
tonyjh

tonyjh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
OTL logfile created on: 8/11/2010 9:16:00 PM - Run 3
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Documents and Settings\User1\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1,023.00 Mb Total Physical Memory | 575.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 1534 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 85.67 Gb Free Space | 18.39% Space Free | Partition Type: NTFS
Drive F: | 612.14 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: JULLE-FD9C65E74 | User Name: User1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\User1\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Acronis)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
PRC - C:\WINDOWS\system32\UAService7.exe ()
PRC - C:\WINDOWS\system32\ssmypics.scr (Microsoft Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\User1\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\MsgPlusLoader.dll (Patchou)


========== Win32 Services (SafeList) ==========

SRV - (napagent) -- C:\WINDOWS\System32\qagentrt.dll File not found
SRV - (hkmsvc) -- C:\WINDOWS\System32\kmsvc.dll File not found
SRV - (HidServ) -- C:\WINDOWS\System32\hidserv.dll File not found
SRV - (EapHost) -- C:\WINDOWS\System32\eapsvc.dll File not found
SRV - (Dot3svc) -- C:\WINDOWS\System32\dot3svc.dll File not found
SRV - (AVG Security Toolbar Service) -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe File not found
SRV - (AppMgmt) -- C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (sdCoreService) -- C:\Program Files\Spyware Doctor\swdsvc.exe (PC Tools)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ServiceLayer) -- C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (WLSetupSvc) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (AcrSch2Svc) -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Acronis)
SRV - (spupdsvc) -- C:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)
SRV - (StarWindServiceAE) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (sdAuxService) -- C:\Program Files\Spyware Doctor\svcntaux.exe (PC Tools)
SRV - (CCALib8) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (Diskeeper) -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV - (UserAccess7) SecuROM User Access Service (V7) -- C:\WINDOWS\system32\UAService7.exe ()
SRV - (SNDSrvc) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (Perpeervc) -- C:\WINDOWS\system32\EPSTP32U.EXE (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (d347bus) -- C:\WINDOWS\System32\DRIVERS\d347bus.sys File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (agp440) -- C:\WINDOWS\System32\DRIVERS\agp440.sys File not found
DRV - (a347bus) -- C:\WINDOWS\System32\DRIVERS\a347bus.sys File not found
DRV - (AnyDVD) -- C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (SBRE) -- C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (ElbyCDIO) -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (UsbserFilt) -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) -- C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (pccsmcfd) -- C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (timounter) -- C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) -- C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (gdrv) -- C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (xusb21) -- C:\WINDOWS\system32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (IKSysSec) -- C:\WINDOWS\system32\drivers\iksyssec.sys (PCTools Research Pty Ltd.)
DRV - (IkSysFlt) -- C:\WINDOWS\system32\drivers\iksysflt.sys (PCTools Research Pty Ltd.)
DRV - (IKFileSec) -- C:\WINDOWS\system32\drivers\ikfilesec.sys (PCTools Research Pty Ltd.)
DRV - (IKFileFlt) -- C:\WINDOWS\system32\drivers\ikfileflt.sys (PCTools Research Pty Ltd.)
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (vaxscsi) -- C:\WINDOWS\System32\Drivers\vaxscsi.sys (Alcohol Soft Co., Ltd.)
DRV - (MayPro) -- C:\WINDOWS\system32\drivers\Maypro.sys (TigerGame.,Ltd)
DRV - (dtscsi) -- C:\WINDOWS\System32\Drivers\dtscsi.sys (DT Soft Ltd.)
DRV - (EZWRIT3) -- C:\WINDOWS\system32\drivers\ezwrit3.sys (USTC)
DRV - (ASPI32) -- C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (APLOADER) -- C:\WINDOWS\system32\drivers\ApLoader.SYS (Texas Instruments)
DRV - (Hardlock) -- C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (VIAudio) Vinyl AC'97 Audio Controller (WDM) -- C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.)
DRV - (d347prt) -- C:\WINDOWS\System32\Drivers\d347prt.sys ( )
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (a347scsi) -- C:\WINDOWS\System32\Drivers\a347scsi.sys ( )
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ALCXSENS) -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (yukonwxp) -- C:\WINDOWS\system32\drivers\yukonwxp.sys (Marvell Semiconductor Inc.)
DRV - (LMouFlt2) -- C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) -- C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (SiSRaid) -- C:\WINDOWS\system32\DRIVERS\SiSRaid.sys (Silicon Integrated Systems)
DRV - (SISAGP) -- C:\WINDOWS\system32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (SiSide) -- C:\WINDOWS\system32\DRIVERS\siside.sys (Silicon Integrated Systems Corp.)
DRV - (sisidex) -- C:\WINDOWS\system32\drivers\sisidex.sys (Windows ® 2000 DDK provider)
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (sisperf) -- C:\WINDOWS\system32\drivers\sisperf.sys (Silicon Integrated Systems Corp.)
DRV - (SISNIC) -- C:\WINDOWS\system32\drivers\sisnic.sys (SiS Corporation)
DRV - (StreamDispatcher) -- C:\WINDOWS\system32\drivers\strmdisp.sys (Conexant Systems)
DRV - (HSFHWBS2) -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems)
DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = My Web Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultUrl = http://www.mywebsear...r={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dodo.com.au/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:28091

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..network.proxy.http: "127.0.0.1");user_pref("network.proxy.http_port", 81);user_pref("network.proxy.type", 1

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009/02/27 22:24:33 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/30 17:12:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/30 17:12:19 | 000,000,000 | ---D | M]

[2008/12/15 14:54:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Mozilla\Extensions
[2010/10/30 17:12:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\6aecx7x9.julie\extensions
[2010/10/29 15:28:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\6aecx7x9.julie\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010/08/18 15:17:13 | 000,000,000 | ---D | M] (ReloadEvery) -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\6aecx7x9.julie\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2010/10/29 15:28:38 | 000,000,000 | ---D | M] (ReminderFox) -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\6aecx7x9.julie\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2010/08/30 16:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\uryozul3.default\extensions
[2005/01/22 15:54:38 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\uryozul3.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/08/30 16:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Application Data\Mozilla\Firefox\Profiles\uryozul3.default\extensions\[email protected]
[2010/10/30 18:02:33 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2004/01/14 13:09:25 | 000,176,176 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2005/09/05 11:11:48 | 000,098,304 | ---- | M] (Zylom) -- C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll

O1 HOSTS File: ([2010/11/07 12:35:02 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStrCmpLogical = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoTrayNotify = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.micr...922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {447F8438-8124-4369-905B-A249E13CBBFC} http://pickles.liveb...l/new/lgbkc.cab (LgbContent Control)
O16 - DPF: {680285A8-96D3-43DA-9D3D-51DD987D0B77} http://www.nero.com/...ckerControl.cab (NeroVersionCheckerControl Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - File not found
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\MsgPlusLoader.dll) - C:\WINDOWS\system32\MsgPlusLoader.dll (Patchou)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\User1\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User1\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/13 08:21:27 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2000/08/04 01:32:39 | 000,098,304 | R--- | M] (Humongous Entertainment) - F:\AUTORUN.EXE -- [ CDFS ]
O32 - AutoRun File - [2000/07/08 04:52:18 | 000,000,432 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O32 - AutoRun File - [2000/08/04 01:32:39 | 000,085,200 | R--- | M] () - F:\AUTORUN.pcx -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

File not found -- C:\Documents and Settings\User1\My Documents\User1.
[2010/11/08 20:21:16 | 001,317,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\User1\Desktop\TDSSKiller.exe
[2010/11/08 13:41:36 | 000,000,000 | ---D | C] -- C:\Program Files\Hidden Expedition Titanic
[2010/11/08 13:41:08 | 000,000,000 | ---D | C] -- C:\Program Files\ReflexiveArcade
[2010/11/08 13:14:04 | 000,000,000 | ---D | C] -- C:\Program Files\GameHouse
[2010/11/08 13:07:04 | 000,000,000 | ---D | C] -- C:\Program Files\Hasbro Interactive
[2010/11/08 13:00:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\My Documents\The Learning Company
[2010/11/07 15:04:26 | 000,345,600 | R--- | C] (Apple Computer, Inc.) -- C:\WINDOWS\System\QTIM32.DLL
[2010/11/07 13:49:23 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/11/07 13:04:55 | 013,063,352 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\User1\Desktop\mssefullinstall-x86fre-en-us-xp.exe
[2010/11/07 11:31:37 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/11/07 11:26:39 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/11/07 11:26:39 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/11/07 11:26:39 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/11/07 11:26:39 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/11/06 20:50:30 | 000,546,224 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\User1\Desktop\avg_remover_stf_x86_2011_1149.exe.to_delete
[2010/11/02 16:54:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\MALWEAR VIRUS CLEANERS
[2010/11/02 16:07:34 | 000,268,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2010/11/02 16:07:33 | 000,323,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll
[2010/11/02 16:07:33 | 000,044,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wups2.dll
[2010/11/02 16:07:33 | 000,035,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wups.dll
[2010/11/02 16:07:33 | 000,035,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wups.dll
[2010/11/02 16:07:32 | 000,561,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll
[2010/11/02 16:07:32 | 000,092,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cdm.dll
[2010/11/02 15:56:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/11/02 07:34:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\GooredFix Backups
[2010/11/01 20:13:07 | 000,093,872 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/11/01 20:13:07 | 000,027,944 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\sbbd.exe
[2010/11/01 20:12:53 | 000,000,000 | ---D | C] -- C:\VIPRERESCUE
[2010/11/01 14:59:49 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/10/30 12:46:03 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User1\Desktop\OTL.exe
[2010/10/28 17:47:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/10/28 17:46:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/10/27 18:20:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/10/27 18:18:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/10/26 22:44:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Documents\Server
[2010/10/26 22:43:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\BBA3C47041CC05CF5F7CEAE09FFAF8B6
[2010/10/26 22:21:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\Y.S.v1.4.0.0
[2010/10/26 16:58:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\The Learning Company
[2010/10/25 20:46:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\a.b.hal.propper
[2010/10/24 00:35:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\tgatetress
[2010/10/22 00:31:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Desktop\IPOD
[2010/10/16 12:44:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Local Settings\Application Data\AVG Security Toolbar
[2010/10/16 12:35:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\AVG10
[2010/10/16 12:33:42 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/10/16 11:50:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/10/16 01:01:17 | 074,840,872 | ---- | C] (Apple Inc.) -- C:\Documents and Settings\User1\Desktop\iTunesSetup10.exe
[2010/10/15 20:08:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\Realore_Whiterra Roads Of Rome
[2010/10/15 16:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\Roads of Rome
[2010/10/15 16:37:38 | 000,000,000 | ---D | C] -- C:\Program Files\Kate Arrow - Deserted Wood
[2010/10/15 16:36:40 | 000,000,000 | ---D | C] -- C:\Program Files\Help Felix Find a Cure
[2010/10/15 16:34:31 | 000,000,000 | ---D | C] -- C:\Program Files\Enlightenus II - The Timeless Tower
[2010/10/15 16:27:57 | 000,000,000 | ---D | C] -- C:\Program Files\Dark Tales - Edgar Allan Poe's The Black Cat Collector's Edition
[2010/10/15 15:25:54 | 000,000,000 | ---D | C] -- C:\Program Files\Columbus - Ghost of the Mystery Stone
[2010/10/12 20:47:43 | 000,000,000 | ---D | C] -- C:\Program Files\EA Sports
[2010/10/11 17:09:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Application Data\Anarchy
[2010/10/11 17:07:33 | 000,000,000 | ---D | C] -- C:\Program Files\Coffee Rush 2
[2009/02/04 17:45:55 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys
[2008/06/05 16:34:49 | 000,403,856 | ---- | C] (Pantaray Research LTD.) -- C:\Program Files\un_Star Defender 4_26816.exe
[2005/07/25 18:37:28 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found -- C:\Documents and Settings\User1\My Documents\User1.
[2010/11/08 20:50:25 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/08 17:50:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/08 17:30:12 | 000,001,271 | ---- | M] () -- C:\WINDOWS\hegames.ini
[2010/11/08 13:44:25 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/11/08 13:41:45 | 000,000,826 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\Hidden Expedition Titanic.lnk
[2010/11/08 13:14:10 | 000,000,805 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Posh Shop.lnk
[2010/11/08 13:14:10 | 000,000,169 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\More Games at GameHouse.com.url
[2010/11/08 12:46:07 | 000,001,984 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/11/08 12:20:08 | 000,000,000 | ---- | M] () -- C:\WINDOWS\TempFile
[2010/11/08 12:19:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/07 15:19:27 | 000,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/07 13:05:03 | 013,063,352 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\User1\Desktop\mssefullinstall-x86fre-en-us-xp.exe
[2010/11/07 12:35:02 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/11/07 11:31:43 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2010/11/07 11:26:19 | 000,452,500 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/07 11:26:19 | 000,075,314 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/11/06 20:50:31 | 000,546,224 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\User1\Desktop\avg_remover_stf_x86_2011_1149.exe.to_delete
[2010/11/06 17:56:19 | 003,903,800 | R--- | M] () -- C:\Documents and Settings\User1\Desktop\ComboFix.exe
[2010/11/06 13:36:39 | 000,311,584 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/05 21:15:49 | 000,088,576 | ---- | M] () -- C:\WINDOWS\MBR.exe
[2010/11/02 17:43:50 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/11/02 17:35:03 | 000,000,933 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2010/10/30 11:04:14 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User1\Desktop\OTL.exe
[2010/10/30 04:43:13 | 000,000,191 | ---- | M] () -- C:\Documents and Settings\User1\Application Data\ahfg.bat
[2010/10/29 23:52:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/10/26 17:00:55 | 000,000,036 | ---- | M] () -- C:\WINDOWS\Tiny_Run.ini
[2010/10/26 11:30:08 | 001,317,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\User1\Desktop\TDSSKiller.exe
[2010/10/25 21:20:33 | 024,408,441 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\Fallout_New_Vegas_Official_eGuide_pdf.rar
[2010/10/24 16:23:55 | 068,346,571 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\Y.S.v1.4.0.0.rar
[2010/10/24 15:31:02 | 009,838,549 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\a.b.hal.propper.rar
[2010/10/19 21:00:41 | 111,586,305 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\s.c.v1.0.rar
[2010/10/16 01:01:21 | 074,840,872 | ---- | M] (Apple Inc.) -- C:\Documents and Settings\User1\Desktop\iTunesSetup10.exe
[2010/10/12 20:36:06 | 517,080,144 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\V8 Challenge.bin
[2010/10/12 20:36:06 | 000,000,201 | ---- | M] () -- C:\Documents and Settings\User1\Desktop\V8 Challenge.cue
[2010/10/12 20:27:45 | 000,000,090 | ---- | M] () -- C:\WINDOWS
[2010/10/11 17:03:26 | 000,001,596 | ---- | M] () -- C:\Documents and Settings\User1\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2010/10/10 22:11:24 | 000,120,129 | ---- | M] () -- C:\Documents and Settings\User1\My Documents\cover111.jpg
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/08 13:41:45 | 000,000,826 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\Hidden Expedition Titanic.lnk
[2010/11/08 13:14:10 | 000,000,805 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Posh Shop.lnk
[2010/11/08 13:14:10 | 000,000,169 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\More Games at GameHouse.com.url
[2010/11/08 13:07:13 | 000,045,568 | ---- | C] () -- C:\WINDOWS\UniFish3.exe
[2010/11/07 11:31:43 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/11/07 11:31:39 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2010/11/07 11:26:39 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/11/07 11:26:39 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/11/07 11:26:39 | 000,088,576 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/11/07 11:26:39 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/11/07 11:26:39 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/11/06 17:56:19 | 003,903,800 | R--- | C] () -- C:\Documents and Settings\User1\Desktop\ComboFix.exe
[2010/10/30 04:43:13 | 000,000,191 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\ahfg.bat
[2010/10/26 16:56:34 | 000,000,036 | ---- | C] () -- C:\WINDOWS\Tiny_Run.ini
[2010/10/25 21:20:31 | 024,408,441 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\Fallout_New_Vegas_Official_eGuide_pdf.rar
[2010/10/24 16:23:49 | 068,346,571 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\Y.S.v1.4.0.0.rar
[2010/10/24 15:31:00 | 009,838,549 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\a.b.hal.propper.rar
[2010/10/19 21:00:24 | 111,586,305 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\s.c.v1.0.rar
[2010/10/12 20:36:06 | 000,000,201 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\V8 Challenge.cue
[2010/10/12 20:33:53 | 517,080,144 | ---- | C] () -- C:\Documents and Settings\User1\Desktop\V8 Challenge.bin
[2010/10/11 18:12:22 | 000,001,548 | -H-- | C] () -- C:\Documents and Settings\User1\Desktop\UltraISO.lnk
[2010/10/11 17:03:26 | 000,001,596 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2010/10/10 22:11:43 | 000,120,129 | ---- | C] () -- C:\Documents and Settings\User1\My Documents\cover111.jpg
[2010/09/16 19:21:41 | 000,000,083 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/04/29 22:41:52 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\SuperSafer.cfg
[2010/02/03 18:22:05 | 000,000,253 | ---- | C] () -- C:\WINDOWS\Sin_setup.INI
[2009/10/28 23:14:35 | 000,155,648 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2009/08/03 00:21:54 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2009/07/21 13:49:53 | 000,001,044 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\vso_ts_preview.xml
[2009/04/26 18:49:27 | 000,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/04/18 20:13:10 | 000,000,107 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\default.pls
[2009/03/14 21:19:47 | 000,009,629 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2009/03/01 19:19:18 | 000,012,060 | ---- | C] () -- C:\Documents and Settings\User1\Application Data\NMM-MetaData.db
[2009/02/05 18:31:33 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\User1\Local Settings\Application Data\fusioncache.dat
[2009/02/01 11:29:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2008/12/31 17:04:42 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2008/10/23 21:26:32 | 000,000,635 | ---- | C] () -- C:\WINDOWS\Dc.INI
[2008/09/05 10:47:04 | 000,000,120 | ---- | C] () -- C:\WINDOWS\WINRESAZ.INI
[2008/09/01 14:21:46 | 000,000,121 | ---- | C] () -- C:\WINDOWS\SwDrvs.ini
[2008/09/01 14:21:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\drvxl32.INI
[2008/09/01 14:21:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\drvwd32.INI
[2008/09/01 13:20:32 | 000,000,343 | ---- | C] () -- C:\WINDOWS\9ed.ini
[2008/08/03 18:24:01 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/06/09 18:43:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2008/06/05 16:34:49 | 000,006,933 | ---- | C] () -- C:\Program Files\un_Star Defender 4_26816.txt
[2008/03/08 07:44:35 | 000,000,061 | ---- | C] () -- C:\WINDOWS\TLCAPPS.INI
[2008/03/05 12:54:19 | 000,000,000 | ---- | C] () -- C:\Program Files\temp01
[2008/03/01 22:20:38 | 003,049,984 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/03/01 22:20:38 | 000,404,480 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008/03/01 22:20:38 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008/03/01 22:20:38 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/01/30 14:05:30 | 000,002,568 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/01/24 15:47:46 | 000,000,052 | ---- | C] () -- C:\WINDOWS\cool.ini
[2008/01/24 15:45:27 | 000,000,011 | ---- | C] () -- C:\WINDOWS\wordpad.ini
[2007/12/20 21:45:27 | 000,000,028 | ---- | C] () -- C:\WINDOWS\v2d.INI
[2007/11/30 00:15:49 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ADsSecurity.dll
[2007/11/30 00:15:49 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\dxinputdll.dll
[2007/11/26 21:56:28 | 000,151,415 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2007/11/16 22:34:58 | 000,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/10/29 10:54:51 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\_psisdecd.dll
[2007/10/01 15:08:34 | 000,000,035 | ---- | C] () -- C:\WINDOWS\WDIRECT.INI
[2007/09/06 13:19:50 | 000,000,117 | ---- | C] () -- C:\WINDOWS\Prof.ini
[2007/09/06 00:55:21 | 000,000,447 | ---- | C] () -- C:\WINDOWS\Clony2.ini
[2007/07/26 00:24:28 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/05/28 18:21:04 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/05/28 18:21:03 | 000,084,480 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007/05/23 15:56:10 | 000,000,205 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2007/04/05 00:15:37 | 000,000,397 | ---- | C] () -- C:\WINDOWS\Proxyrama.INI
[2007/03/29 22:00:40 | 000,203,264 | ---- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
[2007/03/10 22:51:48 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/02/28 14:33:51 | 000,286,208 | ---- | C] () -- C:\WINDOWS\System32\CNCS232.DLL
[2007/02/12 17:45:22 | 000,000,344 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2007/01/31 00:01:15 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2007/01/31 00:01:15 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2007/01/04 01:48:05 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\infcpy.dll
[2006/10/21 15:34:09 | 000,000,004 | ---- | C] () -- C:\WINDOWS\info147.sys
[2006/07/24 20:16:51 | 000,000,011 | ---- | C] () -- C:\WINDOWS\KPP.INI
[2006/07/15 10:45:10 | 000,000,019 | ---- | C] () -- C:\WINDOWS\System32\systilde32.dll
[2006/05/11 23:13:56 | 000,001,743 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/30 21:07:17 | 000,056,320 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2006/04/30 20:30:02 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2006/04/23 00:59:13 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2006/03/31 15:05:53 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2006/01/16 00:34:21 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2006/01/10 19:00:25 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDER310E.ini
[2006/01/09 12:20:04 | 000,000,073 | ---- | C] () -- C:\WINDOWS\EurekaLog.ini
[2005/12/23 13:15:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\RAWImage.INI
[2005/12/04 11:56:56 | 000,000,011 | ---- | C] () -- C:\WINDOWS\ABC.INI
[2005/10/27 16:41:47 | 000,000,020 | ---- | C] () -- C:\WINDOWS\Converter.INI
[2005/10/04 10:01:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Quicktools.INI
[2005/07/25 15:41:18 | 000,000,036 | ---- | C] () -- C:\WINDOWS\ibu.dll
[2005/06/27 18:08:31 | 000,000,551 | ---- | C] () -- C:\WINDOWS\Clubhouse.ini
[2005/06/23 17:00:08 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\TTSServer.dll
[2005/06/22 10:05:22 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVSyd.DLL
[2005/06/22 10:05:13 | 000,000,599 | ---- | C] () -- C:\WINDOWS\System32\CNCMP51.INI
[2005/05/25 10:04:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2005/05/25 09:57:09 | 000,000,111 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2005/05/11 14:01:36 | 000,001,125 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2005/04/08 14:38:48 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\tmpid.dll
[2005/04/05 18:41:14 | 000,000,397 | ---- | C] () -- C:\WINDOWS\MYOBP.INI
[2005/04/05 18:41:14 | 000,000,039 | ---- | C] () -- C:\WINDOWS\MYOB.INI
[2005/02/09 12:59:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2005/01/30 10:22:58 | 000,001,125 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2005/01/29 11:25:02 | 008,956,040 | ---- | C] () -- C:\Program Files\InstallSnSBingo.exe
[2005/01/26 16:50:53 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2005/01/26 16:50:53 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2005/01/26 05:25:04 | 000,247,808 | ---- | C] () -- C:\Documents and Settings\User1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/01/22 04:00:05 | 000,000,712 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2005/01/22 04:00:03 | 000,000,780 | ---- | C] () -- C:\WINDOWS\ka.ini
[2005/01/20 09:32:33 | 000,001,271 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2005/01/20 06:23:29 | 000,000,700 | ---- | C] () -- C:\WINDOWS\disney.ini
[2005/01/19 12:26:31 | 000,000,119 | ---- | C] () -- C:\WINDOWS\compedia.ini
[2005/01/13 08:36:54 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\property.dll
[2005/01/13 08:33:58 | 000,139,264 | R--- | C] () -- C:\WINDOWS\System32\IDEproperty.dll
[2005/01/13 00:10:32 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/04/22 13:58:26 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
[2003/07/14 12:20:16 | 000,000,025 | R--- | C] () -- C:\WINDOWS\MPower23.ini
[2003/04/09 07:21:50 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\trayocx.dll
[2002/11/04 15:09:46 | 000,000,025 | R--- | C] () -- C:\WINDOWS\MPowerK1.ini
[2002/10/16 09:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2000/01/31 09:02:00 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\Wh2Robo.dll
[1999/01/23 08:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1997/04/01 00:00:00 | 001,664,272 | ---- | C] () -- C:\WINDOWS\System32\MSO97V.DLL
[1997/04/01 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/04/01 00:00:00 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\MSORFS.DLL
[1997/04/01 00:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL

========== Alternate Data Streams ==========

@Alternate Data Stream - 239 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:178093AE
@Alternate Data Stream - 238 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B722BCE5
@Alternate Data Stream - 237 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:38FF076E
@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BF6C81B2
@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A02025CE
@Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FC51BA36
@Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F43B7E8F
@Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:864881BF
@Alternate Data Stream - 230 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9D6EAEC3
@Alternate Data Stream - 228 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:22741C1F
@Alternate Data Stream - 227 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:00811B66
@Alternate Data Stream - 224 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CEE4A457
@Alternate Data Stream - 224 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:99AC3203
@Alternate Data Stream - 221 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8C81B36D
@Alternate Data Stream - 220 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:008586AE
@Alternate Data Stream - 219 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D055FC10
@Alternate Data Stream - 218 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6FD36C4B
@Alternate Data Stream - 216 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3942462
@Alternate Data Stream - 215 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ED9B661E
@Alternate Data Stream - 215 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3DB6F365
@Alternate Data Stream - 214 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8140CB50
@Alternate Data Stream - 214 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:80E965A3
@Alternate Data Stream - 213 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:56C17A93
@Alternate Data Stream - 209 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:109734F6
@Alternate Data Stream - 208 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EC2381A4
@Alternate Data Stream - 208 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A0CB43B2
@Alternate Data Stream - 206 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC0528D9
@Alternate Data Stream - 204 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BFAD7A5D
@Alternate Data Stream - 204 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:15752405
@Alternate Data Stream - 203 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F11C259D
@Alternate Data Stream - 202 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:76A59E49
@Alternate Data Stream - 201 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F0762150
@Alternate Data Stream - 201 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EC7C9796
@Alternate Data Stream - 201 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:66AA0486
@Alternate Data Stream - 200 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EC0A74A1
@Alternate Data Stream - 200 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D507B5A8
@Alternate Data Stream - 200 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:57CC1FDC
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7A0EFE63
@Alternate Data Stream - 191 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59846E5E
@Alternate Data Stream - 190 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FC4EA67C
@Alternate Data Stream - 189 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A3063E0E
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:98F0614F
@Alternate Data Stream - 158 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ED51D3ED
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:80EA2EA3
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07D9FF25
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7ADA8871
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A235FA9E
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:151760F0
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3BF63E4A
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2B4123E9
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:57B4E612
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9857FAE3
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1B7E2022
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3D36932D
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ABE30DDB
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AEBFFE08
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BEBD9BCF

< End of report >

Hope this helps

Edited by tonyjh, 08 November 2010 - 04:35 AM.

  • 0

Advertisements


#11
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello,

The tdsskiller logfile is incomplete. Can you post it again?

Thunderbird1988
  • 0

#12
tonyjh

tonyjh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
2010/11/09 18:55:10.0843 TDSS rootkit removing tool 2.4.7.0 Nov 8 2010 10:52:22
2010/11/09 18:55:10.0843 ================================================================================
2010/11/09 18:55:10.0843 SystemInfo:
2010/11/09 18:55:10.0843
2010/11/09 18:55:10.0843 OS Version: 5.1.2600 ServicePack: 3.0
2010/11/09 18:55:10.0843 Product type: Workstation
2010/11/09 18:55:10.0843 ComputerName: JULLE-FD9C65E74
2010/11/09 18:55:10.0843 UserName: User1
2010/11/09 18:55:10.0843 Windows directory: C:\WINDOWS
2010/11/09 18:55:10.0843 System windows directory: C:\WINDOWS
2010/11/09 18:55:10.0843 Processor architecture: Intel x86
2010/11/09 18:55:10.0843 Number of processors: 2
2010/11/09 18:55:10.0843 Page size: 0x1000
2010/11/09 18:55:10.0843 Boot type: Normal boot
2010/11/09 18:55:10.0843 ================================================================================
2010/11/09 18:55:10.0968 Initialize success
2010/11/09 18:55:19.0312 ================================================================================
2010/11/09 18:55:19.0312 Scan started
2010/11/09 18:55:19.0312 Mode: Manual;
2010/11/09 18:55:19.0312 ================================================================================
2010/11/09 18:55:19.0765 a347scsi (113e4b318bbaa7483ca4e582a4d63f49) C:\WINDOWS\system32\Drivers\a347scsi.sys
2010/11/09 18:55:19.0953 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/11/09 18:55:20.0000 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2010/11/09 18:55:20.0156 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
2010/11/09 18:55:20.0203 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
2010/11/09 18:55:20.0500 ALCXSENS (ba88534a3ceb6161e7432438b9ea4f54) C:\WINDOWS\system32\drivers\ALCXSENS.SYS
2010/11/09 18:55:20.0609 ALCXWDM (a886a879d2d05d942c3565c4d451ec23) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2010/11/09 18:55:20.0828 AnyDVD (cb5f75ea66bf555ba6dff01c1e63ab84) C:\WINDOWS\system32\Drivers\AnyDVD.sys
2010/11/09 18:55:20.0890 APLOADER (4cb340d7ddfbcb52bbe6979fde6106b3) C:\WINDOWS\system32\drivers\ApLoader.sys
2010/11/09 18:55:21.0187 ASPI32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\aspi32.sys
2010/11/09 18:55:21.0281 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/11/09 18:55:21.0359 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/11/09 18:55:21.0593 ati2mtag (4938ad74de9088f70922fabf86912eee) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2010/11/09 18:55:21.0671 atksgt (6e996cf8459a2594e0e9609d0e34d41f) C:\WINDOWS\system32\DRIVERS\atksgt.sys
2010/11/09 18:55:21.0734 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2010/11/09 18:55:21.0812 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2010/11/09 18:55:21.0890 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2010/11/09 18:55:22.0015 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2010/11/09 18:55:22.0109 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2010/11/09 18:55:22.0218 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2010/11/09 18:55:22.0296 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
2010/11/09 18:55:22.0359 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2010/11/09 18:55:22.0609 CoachUsb (4a7ede105df9b57dac32b38dc2db05cb) C:\WINDOWS\system32\DRIVERS\CoachUsb.sys
2010/11/09 18:55:22.0875 d347prt (b49f79ace459763f4e0380071be9cb45) C:\WINDOWS\system32\Drivers\d347prt.sys
2010/11/09 18:55:23.0093 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/11/09 18:55:23.0218 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
2010/11/09 18:55:23.0265 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys
2010/11/09 18:55:23.0328 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2010/11/09 18:55:23.0453 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
2010/11/09 18:55:23.0546 dot4 (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
2010/11/09 18:55:23.0625 Dot4Print (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
2010/11/09 18:55:23.0671 dot4usb (6ec3af6bb5b30e488a0c559921f012e1) C:\WINDOWS\system32\DRIVERS\dot4usb.sys
2010/11/09 18:55:23.0828 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
2010/11/09 18:55:23.0875 dtscsi (12aca694b50ea53563c1e7c99e7bb27d) C:\WINDOWS\System32\Drivers\dtscsi.sys
2010/11/09 18:55:23.0937 Dual Mode (4fc1d342f3a2256f954b2e1b05f432fe) C:\WINDOWS\system32\DRIVERS\CoachVc.sys
2010/11/09 18:55:24.0000 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2010/11/09 18:55:24.0078 ElbyCDIO (178cc9403816c082d22a1d47fa1f9c85) C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
2010/11/09 18:55:24.0187 EZWRIT3 (cdfe94eea35b06f40d70b1970a3073bb) C:\WINDOWS\system32\Drivers\ezwrit3.sys
2010/11/09 18:55:24.0265 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
2010/11/09 18:55:24.0359 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
2010/11/09 18:55:24.0406 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
2010/11/09 18:55:24.0437 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2010/11/09 18:55:24.0531 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys
2010/11/09 18:55:24.0609 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2010/11/09 18:55:24.0656 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2010/11/09 18:55:24.0734 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
2010/11/09 18:55:24.0765 gdrv (54789f9ba0d59072cdd4e7c200e122c4) C:\WINDOWS\gdrv.sys
2010/11/09 18:55:24.0843 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2010/11/09 18:55:24.0921 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2010/11/09 18:55:25.0015 hamachi (7929a161f9951d173ca9900fe7067391) C:\WINDOWS\system32\DRIVERS\hamachi.sys
2010/11/09 18:55:25.0109 Hardlock (c1cc0c9742b881c42f1cc628e6f9ebd1) C:\WINDOWS\system32\drivers\hardlock.sys
2010/11/09 18:55:25.0218 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2010/11/09 18:55:25.0390 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2010/11/09 18:55:25.0453 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2010/11/09 18:55:25.0515 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2010/11/09 18:55:25.0578 HSFHWBS2 (127f6638eb09050f5a490bbd6507b37a) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
2010/11/09 18:55:25.0640 HSF_DP (0ade6a9622ff72599ef2980036112f17) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
2010/11/09 18:55:25.0750 HTTP (cb77bb47e67e84deb17ba29632501730) C:\WINDOWS\system32\Drivers\HTTP.sys
2010/11/09 18:55:25.0984 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2010/11/09 18:55:26.0109 IKFileFlt (34f40507dddb19700914eb09862fc74d) C:\WINDOWS\system32\drivers\ikfileflt.sys
2010/11/09 18:55:26.0156 IKFileSec (86882f5132bc9807863ee8f631a51b40) C:\WINDOWS\system32\drivers\ikfilesec.sys
2010/11/09 18:55:26.0218 IkSysFlt (dbf937414b9630252cb48e6863139c54) C:\WINDOWS\system32\drivers\iksysflt.sys
2010/11/09 18:55:26.0265 IKSysSec (57a34b3b557b924e7b6655ad20f031cc) C:\WINDOWS\system32\drivers\iksyssec.sys
2010/11/09 18:55:26.0343 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
2010/11/09 18:55:26.0531 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2010/11/09 18:55:26.0625 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2010/11/09 18:55:26.0703 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys
2010/11/09 18:55:26.0750 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2010/11/09 18:55:26.0796 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2010/11/09 18:55:26.0875 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2010/11/09 18:55:26.0937 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2010/11/09 18:55:26.0984 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
2010/11/09 18:55:27.0031 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2010/11/09 18:55:27.0109 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2010/11/09 18:55:27.0171 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
2010/11/09 18:55:27.0281 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys
2010/11/09 18:55:27.0375 L8042pr2 (0f8b7bf7097d1e8d78f2f52a2bea03cd) C:\WINDOWS\system32\DRIVERS\L8042pr2.Sys
2010/11/09 18:55:27.0562 lirsgt (975b6cf65f44e95883f3855bae8cecaf) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
2010/11/09 18:55:27.0656 LMouFlt2 (aef09673376a4d93c09e8341854f1bf4) C:\WINDOWS\system32\DRIVERS\LMouFlt2.Sys
2010/11/09 18:55:27.0703 MayPro (065bdc5cdb24a1c691854db60ae057f8) C:\WINDOWS\system32\Drivers\MayPro.sys
2010/11/09 18:55:27.0765 mdmxsdk (a1e9d936eac07ee9386e87bac1377fad) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2010/11/09 18:55:27.0875 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2010/11/09 18:55:27.0984 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
2010/11/09 18:55:28.0031 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
2010/11/09 18:55:28.0078 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2010/11/09 18:55:28.0125 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2010/11/09 18:55:28.0187 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
2010/11/09 18:55:28.0328 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2010/11/09 18:55:28.0375 MRxSmb (6f2d483b97b395544e59749c47963c6a) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2010/11/09 18:55:28.0500 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
2010/11/09 18:55:28.0593 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010/11/09 18:55:28.0640 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010/11/09 18:55:28.0718 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
2010/11/09 18:55:28.0750 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2010/11/09 18:55:28.0828 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
2010/11/09 18:55:28.0906 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
2010/11/09 18:55:28.0937 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2010/11/09 18:55:29.0031 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
2010/11/09 18:55:29.0078 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2010/11/09 18:55:29.0140 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2010/11/09 18:55:29.0218 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2010/11/09 18:55:29.0265 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
2010/11/09 18:55:29.0343 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
2010/11/09 18:55:29.0390 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
2010/11/09 18:55:29.0687 nmwcd (4a8a2aa0706b659175169decf198e9d7) C:\WINDOWS\system32\drivers\ccdcmb.sys
2010/11/09 18:55:29.0750 nmwcdc (fd3e61831095ac62e6840d986b5a2016) C:\WINDOWS\system32\drivers\ccdcmbo.sys
2010/11/09 18:55:29.0843 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
2010/11/09 18:55:29.0906 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
2010/11/09 18:55:30.0000 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2010/11/09 18:55:30.0062 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2010/11/09 18:55:30.0125 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2010/11/09 18:55:30.0281 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys
2010/11/09 18:55:30.0343 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
2010/11/09 18:55:30.0421 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2010/11/09 18:55:30.0484 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
2010/11/09 18:55:30.0546 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
2010/11/09 18:55:30.0687 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2010/11/09 18:55:30.0765 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys
2010/11/09 18:55:30.0843 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
2010/11/09 18:55:31.0265 pfc (ed2e7f396b4098608c95bc3806bdf6fc) C:\WINDOWS\system32\drivers\pfc.sys
2010/11/09 18:55:31.0421 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2010/11/09 18:55:31.0484 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
2010/11/09 18:55:31.0546 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2010/11/09 18:55:31.0625 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
2010/11/09 18:55:31.0921 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2010/11/09 18:55:32.0031 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2010/11/09 18:55:32.0093 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2010/11/09 18:55:32.0140 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2010/11/09 18:55:32.0187 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2010/11/09 18:55:32.0234 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/11/09 18:55:32.0390 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
2010/11/09 18:55:32.0453 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/11/09 18:55:32.0562 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2010/11/09 18:55:32.0703 SASDIFSV (c030c9a39e85b6f04a8dd25d1a50258a) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2010/11/09 18:55:32.0734 SASENUM (e9c2d75c748c3f0a4c34d6cf2ae1d754) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
2010/11/09 18:55:32.0781 SASKUTIL (64c100dbf57c6cb6e7d5d24153f5e444) C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
2010/11/09 18:55:32.0890 SBRE (e121185abcc7f6f2875843ed3236d245) C:\WINDOWS\system32\drivers\SBREdrv.sys
2010/11/09 18:55:33.0000 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2010/11/09 18:55:33.0125 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
2010/11/09 18:55:33.0203 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys
2010/11/09 18:55:33.0343 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
2010/11/09 18:55:33.0484 SISAGP (61ca562def09a782d26b3e7edec5369a) C:\WINDOWS\system32\DRIVERS\SISAGPX.sys
2010/11/09 18:55:33.0531 SiSide (b4485881bd8aed9b157a2e6cf43c2d51) C:\WINDOWS\system32\DRIVERS\siside.sys
2010/11/09 18:55:33.0593 sisidex (6225224b8e846ac230f8d9b343635910) C:\WINDOWS\system32\drivers\sisidex.sys
2010/11/09 18:55:33.0671 SISNIC (8204c49cde112f7b9c2f15707fe2cc5a) C:\WINDOWS\system32\DRIVERS\sisnic.sys
2010/11/09 18:55:33.0734 sisperf (596d4a7052002d2bd344d8937da6f66d) C:\WINDOWS\system32\drivers\sisperf.sys
2010/11/09 18:55:33.0812 SiSRaid (4c597e4de6edf6453990059ba0eac7d0) C:\WINDOWS\system32\DRIVERS\SiSRaid.sys
2010/11/09 18:55:33.0921 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2010/11/09 18:55:34.0000 snapman (b6aa9bbff890ffea333ffe81d0b888ff) C:\WINDOWS\system32\DRIVERS\snapman.sys
2010/11/09 18:55:34.0156 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
2010/11/09 18:55:34.0234 sptd (d390675b8ce45e5fb359338e5e649329) C:\WINDOWS\system32\Drivers\sptd.sys
2010/11/09 18:55:34.0234 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d390675b8ce45e5fb359338e5e649329
2010/11/09 18:55:34.0250 sptd - detected Locked file (1)
2010/11/09 18:55:34.0312 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
2010/11/09 18:55:34.0406 Srv (ab9c79ed12d65e800aaad3d72a04792f) C:\WINDOWS\system32\DRIVERS\srv.sys
2010/11/09 18:55:34.0515 StreamDispatcher (0aaf9a073b37eda0f479a6aae76b0fbf) C:\WINDOWS\system32\DRIVERS\strmdisp.sys
2010/11/09 18:55:34.0578 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2010/11/09 18:55:34.0656 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
2010/11/09 18:55:34.0687 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
2010/11/09 18:55:34.0890 SYMREDRV (f26e71125da173d57caba3457c5e48cf) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
2010/11/09 18:55:34.0953 SYMTDI (23b6adbaa7026c53b5ef102e56750b13) C:\WINDOWS\System32\Drivers\SYMTDI.SYS
2010/11/09 18:55:35.0125 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
2010/11/09 18:55:35.0203 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2010/11/09 18:55:35.0250 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
2010/11/09 18:55:35.0281 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
2010/11/09 18:55:35.0359 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
2010/11/09 18:55:35.0468 tifsfilter (b84b82c0cbeb1b0d7eb7a946bade5830) C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
2010/11/09 18:55:35.0546 timounter (68b3daa08ea06737022832fccffb9b75) C:\WINDOWS\system32\DRIVERS\timntr.sys
2010/11/09 18:55:35.0703 uagp35 (49c805d42d75eddc9b6a7130999c9054) C:\WINDOWS\system32\DRIVERS\uagp35.sys
2010/11/09 18:55:35.0781 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
2010/11/09 18:55:35.0921 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
2010/11/09 18:55:36.0015 upperdev (587e643a4e2ffd9a00f114b057ceb773) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
2010/11/09 18:55:36.0125 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\WINDOWS\system32\Drivers\usbaapl.sys
2010/11/09 18:55:36.0203 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2010/11/09 18:55:36.0250 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2010/11/09 18:55:36.0296 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2010/11/09 18:55:36.0375 usbohci (bdfe799a8531bad8a5a985821fe78760) C:\WINDOWS\system32\DRIVERS\usbohci.sys
2010/11/09 18:55:36.0421 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2010/11/09 18:55:36.0484 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2010/11/09 18:55:36.0562 usbser (49106ee29074e6a3d3ac9e24c6d791d8) C:\WINDOWS\system32\drivers\usbser.sys
2010/11/09 18:55:36.0625 UsbserFilt (fca6a196d47cb972a0e4adc0db9cd17c) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
2010/11/09 18:55:36.0703 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2010/11/09 18:55:36.0750 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2010/11/09 18:55:36.0875 vaxscsi (92cebc2bc7be2c8d49391b365569f306) C:\WINDOWS\System32\Drivers\vaxscsi.sys
2010/11/09 18:55:36.0968 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
2010/11/09 18:55:37.0062 VIAudio (2e1ffc794290d9b16f1db1084583e655) C:\WINDOWS\system32\drivers\vinyl97.sys
2010/11/09 18:55:37.0109 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
2010/11/09 18:55:37.0171 vulfnths (16409c468ceee99b6b129fcaa5c0f206) C:\WINDOWS\System32\Drivers\vulfnth.sys
2010/11/09 18:55:37.0218 vulfntrs (541447e05eddd1164a5ea925778b209d) C:\WINDOWS\System32\Drivers\vulfntr.sys
2010/11/09 18:55:37.0375 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2010/11/09 18:55:37.0437 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
2010/11/09 18:55:37.0546 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
2010/11/09 18:55:37.0625 winachsf (533adeb3b84c2e24d9a85d55f3d69955) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2010/11/09 18:55:38.0203 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2010/11/09 18:55:38.0250 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2010/11/09 18:55:38.0343 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2010/11/09 18:55:38.0453 WudfPf (6ff66513d372d479ef1810223c8d20ce) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2010/11/09 18:55:38.0484 WudfRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2010/11/09 18:55:38.0625 xusb21 (f5e5f944e63a9b5f6e76c2ebb2ac462f) C:\WINDOWS\system32\DRIVERS\xusb21.sys
2010/11/09 18:55:38.0671 yukonwxp (265b882e0501ac6d06f083b04af488a8) C:\WINDOWS\system32\DRIVERS\yukonwxp.sys
2010/11/09 18:55:39.0015 ================================================================================
2010/11/09 18:55:39.0015 Scan finished
2010/11/09 18:55:39.0015 ================================================================================
2010/11/09 18:55:39.0062 Detected object count: 1
2010/11/09 18:55:50.0109 Locked file(sptd) - User select action: Skip

had to run it again as i didn't save last log.
Also I had uninstalled avg antivirus to get combofix to run but it seems that its not completely gone as i cant install the microsoft antivirus program that i want to change to when computer is free of malwear.

regards
tonyjh

Edited by tonyjh, 09 November 2010 - 02:12 AM.

  • 0

#13
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello,

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL 
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = My Web Search
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultUrl = http://www.mywebsear...r={searchTerms}
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:28091
    FF - prefs.js..network.proxy.http: "127.0.0.1");user_pref("network.proxy.http_port", 81);user_pref("network.proxy.type", 1
    
    
     
    :Services 
     
    :Reg 
     
    :Files 
     
    :Commands 
    [purity] 
    [resethosts] 
    [emptytemp] 
    [EMPTYFLASH] 
    [CREATERESTOREPOINT] 
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Download Dr.Web CureIt to the desktop.
  • Doubleclick the drweb-cureit.exe file, then on Start and allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, chose the Complete Scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow Posted Image at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look and see if you can click the following icon next to the files found:
    Posted Image
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    Posted Image
  • This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer to allow files that were in use to be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply along with a new OTL log.
NOTE: During the scan, a pop-up window will open asking for full version purchase. Simply close the window by clicking on X in upper right corner.

Thunderbird1988
  • 0

#14
tonyjh

tonyjh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Hi the log is huge but basically this is what it found

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Scanned: 126548
Infected: 3
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 1
Cured: 0
Deleted: 2
Renamed: 0
Moved: 1
Ignored: 0
Scan speed: 105 Kb/s
Scan time: 4:48:06
-----------------------------------------------------------------------------

C:\SlySoft AnyDVD v6.5.5.9 - incurable - moved

=============================================================================
Total session statistics
=============================================================================
Scanned: 126551
Infected: 3
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 1
Cured: 0
Deleted: 2
Renamed: 0
Moved: 2
Ignored: 0
Scan speed: 105 Kb/s
Scan time: 4:48:06
=============================================================================

OTL.exe;C:\Documents and Settings\User1\Desktop;Trojan.Siggen2.7261;Incurable.Moved.;
Terminator.Skynet-www.oldgames.sk-Compilation.exe;C:\Documents and Settings\User1\Desktop\all the icons\Team viewer;Trojan.Packed.19697;Deleted.;
Witchaven-www.oldgames.sk-Compilation.exe;C:\Documents and Settings\User1\Desktop\all the icons\Team viewer;Trojan.Packed.19697;Deleted.;
AnyDVD Cleaner v6.exe;C:\SlySoft AnyDVD v6.5.5.9;Tool.Siggen.6047;Incurable.Moved.;

Regards
tonyjh

Edited by tonyjh, 12 November 2010 - 04:01 AM.

  • 0

#15
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello,

Dr. Web flagged OTL as being a trojan and removed it. Can you download it again and post a log.

Also, how is your computer running?

Thunderbird1988
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP