Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Dell Laptop with Recurring Virus'/Trojons


  • Please log in to reply

#1
Emma&Pat

Emma&Pat

    New Member

  • Member
  • Pip
  • 8 posts
Hello there

I hope someone can help. I keep getting a variety of trojans and viruses infecting my Dell Inspiron 6400 laptop. I can find and fix them with Mcafee or Malwarebytes or Spybot (they find different things to each other, usually) but infections spring back very quickly. It doesn't seem to matter whether I'm using the internet or not, so I guess there are some hidden things on my machine which download random nasties in the background. There are some favourites - oops1.exe keeps appearing, for instance. For a while I kept getting a "generic win32 has encountered a problem and must close" message, coupled with the laptop sparodically disconnecting from the internet and a failure to find the internal speakers, though this hasn't popped up in the last couple of days.

If someone can help with clearing the machine out, and offering advice on keeping it clean, that would be fantastic.

Here is an OTL log I ran last night:

OTL logfile created on: 06/01/2011 00:43:14 - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Emma Nelder\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 217.11 Gb Total Space | 69.55 Gb Free Space | 32.03% Space Free | Partition Type: NTFS
Drive D: | 12.55 Gb Total Space | 12.38 Gb Free Space | 98.66% Space Free | Partition Type: NTFS

Computer Name: EMMA | User Name: Emma Nelder | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
PRC - [2010/10/27 19:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/10/03 22:43:16 | 000,767,208 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2010/08/25 10:27:44 | 000,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010/08/13 17:51:04 | 000,030,192 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2010/05/19 23:20:44 | 012,776,728 | ---- | M] () -- C:\Program Files\RegCure\RegCure.exe
PRC - [2010/04/16 07:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/03/04 14:52:58 | 000,202,016 | R--- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprtsvc.exe
PRC - [2009/03/04 14:52:22 | 000,202,016 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprtcmd.exe
PRC - [2008/05/22 20:50:00 | 000,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
PRC - [2008/05/22 20:50:00 | 000,111,952 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2008/05/22 20:50:00 | 000,054,608 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/10/25 16:37:32 | 002,178,832 | ---- | M] () -- C:\Program Files\Logitech\QuickCam\Quickcam.exe
PRC - [2007/10/25 16:33:22 | 000,563,984 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2007/10/25 16:32:58 | 000,407,824 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2007/10/25 15:06:00 | 000,086,016 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\Mctray.exe
PRC - [2007/10/25 10:05:40 | 000,136,512 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2007/10/25 10:04:56 | 000,136,512 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2007/10/25 10:03:28 | 000,103,744 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2007/10/19 13:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2007/10/19 13:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2007/06/24 19:17:54 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007/04/13 16:20:22 | 000,097,432 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe
PRC - [2007/04/04 01:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2006/09/11 15:47:38 | 000,026,112 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\realplay.exe
PRC - [2006/07/16 20:29:54 | 000,389,120 | ---- | M] (Gteko Ltd.) -- C:\Program Files\Dell Support\DSAgnt.exe
PRC - [2006/04/06 13:57:54 | 000,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2006/03/24 22:30:44 | 000,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2005/06/10 09:44:02 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2005/02/23 14:57:24 | 000,057,344 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Mixer\CTSVolFE.exe
PRC - [2005/01/27 00:02:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2003/10/29 01:06:00 | 000,024,576 | ---- | M] (BVRP Software) -- C:\Program Files\Digital Line Detect\DLG.exe


========== Modules (SafeList) ==========

MOD - [2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
MOD - [2010/08/23 16:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/03/04 14:52:40 | 000,116,000 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprthook.dll
MOD - [2008/04/14 00:12:01 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll
MOD - [2007/10/19 13:19:10 | 000,109,080 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcInj.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/10/03 22:43:16 | 000,767,208 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2010/08/13 17:51:04 | 000,030,192 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-051210-111108)
SRV - [2010/04/16 07:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/03/04 14:52:58 | 000,202,016 | R--- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\O2\bin\sprtsvc.exe -- (sprtsvc_O2) SupportSoft Sprocket Service (O2)
SRV - [2008/05/22 20:50:00 | 000,144,704 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe -- (McShield)
SRV - [2008/05/22 20:50:00 | 000,054,608 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
SRV - [2007/10/25 10:03:28 | 000,103,744 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2007/10/19 13:21:16 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2007/10/19 13:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2007/10/19 13:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)
SRV - [2007/07/27 05:39:32 | 000,382,320 | ---- | M] (SupportSoft, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2007/04/13 16:20:22 | 000,097,432 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2006/05/01 08:34:00 | 000,262,217 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER) Intel®
SRV - [2006/05/01 08:22:42 | 000,540,745 | ---- | M] (Intel Corporation ) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2006/05/01 08:20:52 | 000,114,753 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2006/05/01 08:20:26 | 000,217,164 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2006/04/06 13:57:54 | 000,380,928 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\wusoc.sys -- (qsryxq)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\PavSRK.sys -- (PavSRK.sys)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\ncyyvqao.sys -- (ilgecs)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\COMFiltr.sys -- (ComFiltr)
DRV - [2010/10/03 22:54:04 | 000,034,792 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys -- (RapportCerberus_19917)
DRV - [2010/10/03 22:43:44 | 000,169,320 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2010/10/03 22:43:44 | 000,059,240 | ---- | M] (Trusteer Ltd.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2009/02/19 13:22:52 | 000,127,744 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ArcHlp.sys -- (archlp)
DRV - [2008/07/16 09:43:16 | 000,160,648 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\pctfw2.sys -- (pctfw2)
DRV - [2008/05/22 20:50:00 | 000,174,952 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2008/05/22 20:50:00 | 000,072,936 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2008/05/22 20:50:00 | 000,064,232 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2008/05/22 20:50:00 | 000,052,104 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2008/05/22 20:50:00 | 000,033,960 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2008/05/22 20:50:00 | 000,031,816 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys -- (mferkdk)
DRV - [2008/04/13 18:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 18:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 18:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 16:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/10/19 13:16:30 | 002,109,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007/10/11 18:59:24 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2007/10/11 18:59:02 | 002,142,488 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/05/11 03:10:50 | 000,034,704 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007/05/09 01:59:40 | 000,036,496 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007/03/05 06:00:04 | 000,027,792 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2007/03/05 05:59:04 | 000,018,320 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btnetdrv.sys -- (BT)
DRV - [2007/03/05 05:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2007/03/05 05:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - [2007/03/05 05:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2007/03/05 05:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2006/11/21 22:41:18 | 000,022,416 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Program Files\IVT Corporation\BlueSoleil\device\Win2k\BTNetFilter.sys -- (BTNetFilter)
DRV - [2006/11/10 19:48:02 | 000,040,352 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2006/11/10 19:43:16 | 000,933,536 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2006/11/10 19:43:16 | 000,013,344 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2006/09/11 15:47:41 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2006/05/01 08:52:02 | 000,013,568 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/04/26 22:13:04 | 001,429,632 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel®
DRV - [2006/03/24 22:34:30 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/03/08 17:35:10 | 000,191,872 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2006/01/10 11:07:58 | 000,004,864 | ---- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/10/14 14:40:18 | 000,307,968 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/10/14 14:40:18 | 000,051,328 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/10/14 14:40:18 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/08/30 17:59:00 | 000,094,000 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2005/08/30 17:58:56 | 000,008,304 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2005/08/30 17:57:18 | 000,058,320 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)
DRV - [2005/08/12 16:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/08/05 15:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/22 02:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 02:01:08 | 000,201,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/07/22 02:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/02/23 13:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2004/12/06 00:05:00 | 000,100,603 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudfa.sys -- (tfsnudfa)
DRV - [2004/12/06 00:05:00 | 000,098,714 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudf.sys -- (tfsnudf)
DRV - [2004/12/06 00:05:00 | 000,086,586 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnifs.sys -- (tfsnifs)
DRV - [2004/12/06 00:05:00 | 000,034,843 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsncofs.sys -- (tfsncofs)
DRV - [2004/12/06 00:05:00 | 000,025,883 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnboio.sys -- (tfsnboio)
DRV - [2004/12/06 00:05:00 | 000,015,227 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnopio.sys -- (tfsnopio)
DRV - [2004/12/06 00:05:00 | 000,006,363 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnpool.sys -- (tfsnpool)
DRV - [2004/12/06 00:05:00 | 000,004,123 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndrct.sys -- (tfsndrct)
DRV - [2004/12/06 00:05:00 | 000,002,239 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndres.sys -- (tfsndres)
DRV - [2004/12/01 02:22:00 | 000,087,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb)
DRV - [2004/11/23 01:56:00 | 000,040,480 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\drvnddm.sys -- (drvnddm)
DRV - [2004/08/03 21:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004/07/14 10:29:04 | 000,005,627 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\sscdbhk5.sys -- (sscdbhk5)
DRV - [2004/07/14 10:28:50 | 000,023,545 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\ssrtln.sys -- (ssrtln)
DRV - [2004/02/13 15:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
DRV - [2001/08/17 13:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 13:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 13:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 13:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 13:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 12:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 12:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 12:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 12:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 12:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 12:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 12:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 12:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 12:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 12:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074

========== FireFox ==========

FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..browser.startup.homepage: "http://flvdirect.iamwired.net/"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..keyword.URL: "http://flvdirect.iam...c=tops&search="
FF - prefs.js..keyword.enabled: true
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaulturl: "http://flvdirect.iam...c=tops&search="
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"


FF - HKLM\software\mozilla\Firefox\extensions\\{8779B4BC-1A5D-4E0E-B83B-171D20F2236D}: C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\{8779B4BC-1A5D-4E0E-B83B-171D20F2236D} [2010/07/27 07:18:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{387D07D6-5CF8-44EB-AECB-C4B4A82A9511}: C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\{387D07D6-5CF8-44EB-AECB-C4B4A82A9511} [2010/12/13 16:18:40 | 000,000,000 | ---D | M]

[2010/05/20 16:24:03 | 000,000,266 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\Application Data\Mozilla\Firefox\Profiles\2w0v2hf2.default\searchplugins\Search.xml

O1 HOSTS File: ([2009/01/23 17:23:52 | 000,000,736 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1ed61cb2-86f5-82b1-b5d1-e81934c7bfbe} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [CTSVolFE.exe] C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [O2] C:\Program Files\O2\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\4.0; GTB0.0; Mozilla\4.0 ( File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnote...ad/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {1288683E-8FB1-46E3-AF62-9BB668505759} http://www.wireless....der_activex.ocx (xc_loader_activex.cntMain)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {17D667BA-5675-4AAB-9221-08B9379384D4} http://cdnimg.piczo....st_uploader.cab (Image Uploader Control)
O16 - DPF: {483912CF-8995-4434-AD61-6163756E05DF} http://download.live...tivex/AXTNS.ocx (AXTNS Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcaf...01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8EF9626B-2251-4C5E-BD17-D5F3E0E98B03} http://www.wireless....der_activex.ocx (xc_loader_activex.cntMain)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius....tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} http://www.tescophot...opcuploader.cab (Image Uploader 3.0 Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe\yhlgyfgg.exe) - C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe\yhlgyfgg.exe File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Emma Nelder\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Emma Nelder\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O29 - HKLM SecurityProviders - (mcmvxqyx.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/06 00:42:18 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
[2011/01/01 05:08:44 | 000,000,000 | ---D | C] -- C:\Program Files\ert
[2010/12/30 06:27:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Emma Nelder\Recent
[2010/12/29 23:50:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Start Menu\Programs\Scanner
[2010/12/25 21:58:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\My Received Files
[2010/12/25 19:46:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Loypfa
[2010/12/25 19:46:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Alpob
[2010/12/25 14:43:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Oxdy
[2010/12/25 14:43:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ivenny
[2010/12/25 09:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Erxoun
[2010/12/25 09:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Cyan
[2010/12/23 16:22:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Miuly
[2010/12/23 16:22:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Avtyib
[2010/12/22 17:31:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ibkyf
[2010/12/22 17:31:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Wiyh
[2010/12/21 15:21:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/12/21 15:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ylbu
[2010/12/21 15:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Onra
[2010/12/21 10:09:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Boepp
[2010/12/18 10:05:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Uropy
[2010/12/18 10:05:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Isgeat
[2010/12/16 21:55:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Uxaf
[2010/12/16 21:55:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Exci
[2010/12/16 21:26:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/12/14 23:58:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2010/12/14 21:28:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Umquxy
[2010/12/14 21:28:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Idxycy
[2010/12/14 09:48:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Edazg
[2010/12/13 22:22:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Yqaff
[2010/12/13 22:22:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ulneiw
[2010/12/13 16:18:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\{387D07D6-5CF8-44EB-AECB-C4B4A82A9511}
[2010/12/13 13:04:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\Pictures - Digital Camera
[2010/12/13 09:29:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Duoh
[2010/12/12 10:57:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Saze
[2010/12/12 10:57:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Duegid
[2010/12/12 10:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Myce
[2010/12/12 10:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Kazyu
[2010/12/12 09:52:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Kiadqy
[2010/12/12 09:52:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Egewop
[2010/12/12 09:52:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Tuaw
[2010/12/12 09:52:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Imuhc
[2010/12/12 08:12:10 | 000,000,000 | ---D | C] -- C:\Program Files\qwert
[2010/12/12 08:12:08 | 000,000,000 | ---D | C] -- C:\Program Files\qwers
[2010/12/12 00:38:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ungod
[2010/12/12 00:38:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Soac
[2010/12/12 00:38:22 | 000,000,000 | ---D | C] -- C:\Program Files\qwer
[2010/12/12 00:38:17 | 000,000,000 | ---D | C] -- C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe
[2010/12/10 15:19:25 | 000,680,288 | ---- | C] (ScreenTime Media) -- C:\WINDOWS\System32\Doctor-Who-2010-Series.scr
[2010/12/10 15:19:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Screentime
[2010/12/10 15:19:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\Screentime
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Emma Nelder\My Documents\*.tmp files -> C:\Documents and Settings\Emma Nelder\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
[2011/01/06 00:17:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/06 00:11:41 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/06 00:09:07 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/06 00:09:04 | 000,000,376 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Startup.job
[2011/01/06 00:09:04 | 000,000,292 | -H-- | M] () -- C:\WINDOWS\tasks\38480230.job
[2011/01/06 00:08:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/06 00:08:44 | 2137,456,640 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/05 23:35:21 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{F0A36E4F-8866-4030-B42F-1A4DE747284D}.job
[2011/01/05 14:02:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/04 10:25:25 | 000,303,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/04 10:21:49 | 000,000,049 | ---- | M] () -- C:\WINDOWS\kh7ptSJh
[2011/01/04 10:21:49 | 000,000,044 | ---- | M] () -- C:\WINDOWS\JJvvDR
[2011/01/04 10:21:49 | 000,000,043 | ---- | M] () -- C:\WINDOWS\YpDSJy
[2011/01/04 10:21:49 | 000,000,043 | ---- | M] () -- C:\WINDOWS\2Uk4Omx
[2011/01/04 10:21:49 | 000,000,042 | ---- | M] () -- C:\WINDOWS\nvCd6if3w
[2011/01/04 10:21:49 | 000,000,040 | ---- | M] () -- C:\WINDOWS\AdSXd
[2011/01/04 10:21:49 | 000,000,039 | ---- | M] () -- C:\WINDOWS\5G58LL14A
[2011/01/04 10:21:49 | 000,000,035 | ---- | M] () -- C:\WINDOWS\fITo5SKO
[2011/01/04 10:21:49 | 000,000,033 | ---- | M] () -- C:\WINDOWS\E78qDIH
[2011/01/04 10:21:49 | 000,000,032 | ---- | M] () -- C:\WINDOWS\OQ3G8wK
[2011/01/04 10:21:49 | 000,000,032 | ---- | M] () -- C:\WINDOWS\1DG6BCm
[2011/01/04 10:21:49 | 000,000,031 | ---- | M] () -- C:\WINDOWS\QD8HB
[2011/01/04 10:21:49 | 000,000,030 | ---- | M] () -- C:\WINDOWS\qDgOR
[2011/01/04 10:21:49 | 000,000,030 | ---- | M] () -- C:\WINDOWS\C62hiui
[2011/01/04 10:21:49 | 000,000,029 | ---- | M] () -- C:\WINDOWS\kBAie
[2011/01/04 10:21:49 | 000,000,028 | ---- | M] () -- C:\WINDOWS\u4XNSwghot
[2011/01/04 10:21:49 | 000,000,027 | ---- | M] () -- C:\WINDOWS\ruqvTxBnU
[2011/01/04 10:21:49 | 000,000,026 | ---- | M] () -- C:\WINDOWS\hUcwRlUJ
[2011/01/04 10:21:46 | 000,000,047 | ---- | M] () -- C:\WINDOWS\slVqcQews
[2011/01/04 10:21:46 | 000,000,046 | ---- | M] () -- C:\WINDOWS\IWwDT
[2011/01/04 10:21:46 | 000,000,045 | ---- | M] () -- C:\WINDOWS\fXxE7bT
[2011/01/04 10:21:46 | 000,000,045 | ---- | M] () -- C:\WINDOWS\8VDa7CXl
[2011/01/04 10:21:46 | 000,000,044 | ---- | M] () -- C:\WINDOWS\vQpJrTcBQF
[2011/01/04 10:21:46 | 000,000,041 | ---- | M] () -- C:\WINDOWS\Wrx6EWy5NX
[2011/01/04 10:21:46 | 000,000,041 | ---- | M] () -- C:\WINDOWS\NEjhJ
[2011/01/04 10:21:46 | 000,000,039 | ---- | M] () -- C:\WINDOWS\U3fOBPUBc
[2011/01/04 10:21:46 | 000,000,038 | ---- | M] () -- C:\WINDOWS\O5AtO
[2011/01/04 10:21:46 | 000,000,038 | ---- | M] () -- C:\WINDOWS\lolVp8E2Sq
[2011/01/04 10:21:46 | 000,000,037 | ---- | M] () -- C:\WINDOWS\i7JEeABY
[2011/01/04 10:21:46 | 000,000,037 | ---- | M] () -- C:\WINDOWS\22BMW7
[2011/01/04 10:21:46 | 000,000,036 | ---- | M] () -- C:\WINDOWS\IxigT
[2011/01/04 10:21:46 | 000,000,035 | ---- | M] () -- C:\WINDOWS\InU5UjE
[2011/01/04 10:21:46 | 000,000,035 | ---- | M] () -- C:\WINDOWS\4tqPC3lA
[2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\RehIFV
[2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\jwdbJS7
[2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\6JJRwDUT
[2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\QVVVN
[2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\myAcFSqAAJ
[2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\5nyf1fEa
[2011/01/04 10:21:46 | 000,000,031 | ---- | M] () -- C:\WINDOWS\63Cp1Oet
[2011/01/04 10:21:46 | 000,000,031 | ---- | M] () -- C:\WINDOWS\5Wa87L
[2011/01/04 10:21:46 | 000,000,029 | ---- | M] () -- C:\WINDOWS\XYOHDo
[2011/01/04 10:21:46 | 000,000,028 | ---- | M] () -- C:\WINDOWS\kipV83i
[2011/01/04 10:21:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\GJgrd
[2011/01/04 10:21:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\FgoHg
[2011/01/04 10:21:44 | 000,000,044 | ---- | M] () -- C:\WINDOWS\sNYXsj
[2011/01/04 10:21:44 | 000,000,037 | ---- | M] () -- C:\WINDOWS\7gLkamXCV
[2011/01/04 10:21:44 | 000,000,031 | ---- | M] () -- C:\WINDOWS\cG5Hstso
[2011/01/04 10:21:43 | 000,000,048 | ---- | M] () -- C:\WINDOWS\OyLaFpY
[2011/01/04 10:21:43 | 000,000,046 | ---- | M] () -- C:\WINDOWS\KG5olI
[2011/01/04 10:21:43 | 000,000,045 | ---- | M] () -- C:\WINDOWS\KSj8pJ
[2011/01/04 10:21:43 | 000,000,045 | ---- | M] () -- C:\WINDOWS\Jj7rN
[2011/01/04 10:21:43 | 000,000,042 | ---- | M] () -- C:\WINDOWS\3jKGcwC
[2011/01/04 10:21:43 | 000,000,041 | ---- | M] () -- C:\WINDOWS\LeHXF
[2011/01/04 10:21:43 | 000,000,040 | ---- | M] () -- C:\WINDOWS\v6OmO
[2011/01/04 10:21:43 | 000,000,040 | ---- | M] () -- C:\WINDOWS\egE75Sxs
[2011/01/04 10:21:43 | 000,000,039 | ---- | M] () -- C:\WINDOWS\OqM5GLT
[2011/01/04 10:21:43 | 000,000,038 | ---- | M] () -- C:\WINDOWS\VoTElV
[2011/01/04 10:21:43 | 000,000,036 | ---- | M] () -- C:\WINDOWS\NJUaq4
[2011/01/04 10:21:43 | 000,000,036 | ---- | M] () -- C:\WINDOWS\E1cotQ5ms
[2011/01/04 10:21:43 | 000,000,034 | ---- | M] () -- C:\WINDOWS\VAGuFigpQh
[2011/01/04 10:21:43 | 000,000,034 | ---- | M] () -- C:\WINDOWS\noxvIPvM8
[2011/01/04 10:21:43 | 000,000,033 | ---- | M] () -- C:\WINDOWS\y78eJvW
[2011/01/04 10:21:43 | 000,000,032 | ---- | M] () -- C:\WINDOWS\lBYMDKb
[2011/01/04 10:21:43 | 000,000,031 | ---- | M] () -- C:\WINDOWS\Lixec7
[2011/01/04 10:21:43 | 000,000,031 | ---- | M] () -- C:\WINDOWS\IKTrTG
[2011/01/04 10:21:43 | 000,000,030 | ---- | M] () -- C:\WINDOWS\nhj8qXLov
[2011/01/04 10:21:43 | 000,000,030 | ---- | M] () -- C:\WINDOWS\GnFLPKDtyK
[2011/01/04 10:21:43 | 000,000,029 | ---- | M] () -- C:\WINDOWS\APpT6oqFk
[2011/01/04 10:21:43 | 000,000,028 | ---- | M] () -- C:\WINDOWS\e6JaP
[2011/01/04 10:21:43 | 000,000,027 | ---- | M] () -- C:\WINDOWS\bVIeGoH
[2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\X2VUkW
[2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\otJuGY
[2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\3Pa3wiYfqd
[2011/01/04 10:21:41 | 000,000,044 | ---- | M] () -- C:\WINDOWS\VXIEcq
[2011/01/04 10:21:41 | 000,000,042 | ---- | M] () -- C:\WINDOWS\pfS2Um
[2011/01/04 10:21:41 | 000,000,040 | ---- | M] () -- C:\WINDOWS\Jtd8F
[2011/01/04 10:21:41 | 000,000,039 | ---- | M] () -- C:\WINDOWS\t8NAq
[2011/01/04 10:21:41 | 000,000,038 | ---- | M] () -- C:\WINDOWS\LmkGgkiF
[2011/01/04 10:21:41 | 000,000,037 | ---- | M] () -- C:\WINDOWS\gJhLQHw8
[2011/01/04 10:21:41 | 000,000,036 | ---- | M] () -- C:\WINDOWS\Tx7Wm3eg
[2011/01/04 10:21:41 | 000,000,036 | ---- | M] () -- C:\WINDOWS\NWGnE5
[2011/01/04 10:21:41 | 000,000,035 | ---- | M] () -- C:\WINDOWS\j5MHLUC
[2011/01/04 10:21:41 | 000,000,035 | ---- | M] () -- C:\WINDOWS\GCRklH23
[2011/01/04 10:21:41 | 000,000,034 | ---- | M] () -- C:\WINDOWS\xwgRvKN2dT
[2011/01/04 10:21:41 | 000,000,032 | ---- | M] () -- C:\WINDOWS\YmH1HIPww
[2011/01/04 10:21:41 | 000,000,032 | ---- | M] () -- C:\WINDOWS\awW5Ltxpf
[2011/01/04 10:21:41 | 000,000,031 | ---- | M] () -- C:\WINDOWS\thNrSB2V
[2011/01/04 10:21:41 | 000,000,031 | ---- | M] () -- C:\WINDOWS\EjLkeU
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\uH2whCXiG
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\lRvp8qsw
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\JfKDsowR
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\birbkGtK
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\ax8uM4r7LP
[2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\Usf1ElUGS
[2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\Fd5jCgjD
[2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\dUAU1UB
[2011/01/04 10:13:40 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/01/03 17:00:01 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2011/01/03 12:00:00 | 000,000,374 | ---- | M] () -- C:\WINDOWS\tasks\PerfectOptimizer_home.job
[2011/01/02 20:34:54 | 000,000,000 | ---- | M] () -- C:\WINDOWS\jx6b6bucz4x987sj87zgw63fxbs0qigk.ini
[2011/01/01 02:21:21 | 000,060,928 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/29 21:55:46 | 000,000,260 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2010/12/29 21:02:13 | 000,069,518 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\cc_20101229_210204.reg
[2010/12/29 19:40:27 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Wqesojudoya.dat
[2010/12/29 09:55:48 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Qmodehoko.bin
[2010/12/28 20:29:48 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/14 12:18:59 | 000,000,712 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\GHremoval.bat
[2010/12/13 17:34:30 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\365.doc
[2010/12/12 04:32:01 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\Driver Robot.job
[2010/12/12 04:21:25 | 000,000,384 | ---- | M] () -- C:\WINDOWS\tasks\RegCure.job
[2010/12/10 15:19:25 | 000,680,288 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\System32\Doctor-Who-2010-Series.scr
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Emma Nelder\My Documents\*.tmp files -> C:\Documents and Settings\Emma Nelder\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/04 10:11:30 | 000,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/01/02 23:22:54 | 2137,456,640 | -HS- | C] () -- C:\hiberfil.sys
[2011/01/02 20:34:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\jx6b6bucz4x987sj87zgw63fxbs0qigk.ini
[2011/01/02 20:34:47 | 000,000,049 | ---- | C] () -- C:\WINDOWS\kh7ptSJh
[2011/01/02 20:34:47 | 000,000,048 | ---- | C] () -- C:\WINDOWS\OyLaFpY
[2011/01/02 20:34:47 | 000,000,047 | ---- | C] () -- C:\WINDOWS\slVqcQews
[2011/01/02 20:34:47 | 000,000,047 | ---- | C] () -- C:\WINDOWS\3Pa3wiYfqd
[2011/01/02 20:34:47 | 000,000,046 | ---- | C] () -- C:\WINDOWS\KG5olI
[2011/01/02 20:34:47 | 000,000,046 | ---- | C] () -- C:\WINDOWS\IWwDT
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\KSj8pJ
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\Jj7rN
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\fXxE7bT
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\8VDa7CXl
[2011/01/02 20:34:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\vQpJrTcBQF
[2011/01/02 20:34:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\sNYXsj
[2011/01/02 20:34:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\JJvvDR
[2011/01/02 20:34:47 | 000,000,043 | ---- | C] () -- C:\WINDOWS\YpDSJy
[2011/01/02 20:34:47 | 000,000,043 | ---- | C] () -- C:\WINDOWS\2Uk4Omx
[2011/01/02 20:34:47 | 000,000,042 | ---- | C] () -- C:\WINDOWS\nvCd6if3w
[2011/01/02 20:34:47 | 000,000,042 | ---- | C] () -- C:\WINDOWS\3jKGcwC
[2011/01/02 20:34:47 | 000,000,041 | ---- | C] () -- C:\WINDOWS\Wrx6EWy5NX
[2011/01/02 20:34:47 | 000,000,041 | ---- | C] () -- C:\WINDOWS\NEjhJ
[2011/01/02 20:34:47 | 000,000,041 | ---- | C] () -- C:\WINDOWS\LeHXF
[2011/01/02 20:34:47 | 000,000,040 | ---- | C] () -- C:\WINDOWS\v6OmO
[2011/01/02 20:34:47 | 000,000,040 | ---- | C] () -- C:\WINDOWS\egE75Sxs
[2011/01/02 20:34:47 | 000,000,040 | ---- | C] () -- C:\WINDOWS\AdSXd
[2011/01/02 20:34:47 | 000,000,039 | ---- | C] () -- C:\WINDOWS\U3fOBPUBc
[2011/01/02 20:34:47 | 000,000,039 | ---- | C] () -- C:\WINDOWS\OqM5GLT
[2011/01/02 20:34:47 | 000,000,039 | ---- | C] () -- C:\WINDOWS\5G58LL14A
[2011/01/02 20:34:47 | 000,000,038 | ---- | C] () -- C:\WINDOWS\VoTElV
[2011/01/02 20:34:47 | 000,000,038 | ---- | C] () -- C:\WINDOWS\O5AtO
[2011/01/02 20:34:47 | 000,000,038 | ---- | C] () -- C:\WINDOWS\lolVp8E2Sq
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\i7JEeABY
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\gJhLQHw8
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\7gLkamXCV
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\22BMW7
[2011/01/02 20:34:47 | 000,000,036 | ---- | C] () -- C:\WINDOWS\NJUaq4
[2011/01/02 20:34:47 | 000,000,036 | ---- | C] () -- C:\WINDOWS\IxigT
[2011/01/02 20:34:47 | 000,000,036 | ---- | C] () -- C:\WINDOWS\E1cotQ5ms
[2011/01/02 20:34:47 | 000,000,035 | ---- | C] () -- C:\WINDOWS\InU5UjE
[2011/01/02 20:34:47 | 000,000,035 | ---- | C] () -- C:\WINDOWS\fITo5SKO
[2011/01/02 20:34:47 | 000,000,035 | ---- | C] () -- C:\WINDOWS\4tqPC3lA
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\VAGuFigpQh
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\RehIFV
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\noxvIPvM8
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\jwdbJS7
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\6JJRwDUT
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\y78eJvW
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\QVVVN
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\myAcFSqAAJ
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\E78qDIH
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\5nyf1fEa
[2011/01/02 20:34:47 | 000,000,032 | ---- | C] () -- C:\WINDOWS\OQ3G8wK
[2011/01/02 20:34:47 | 000,000,032 | ---- | C] () -- C:\WINDOWS\lBYMDKb
[2011/01/02 20:34:47 | 000,000,032 | ---- | C] () -- C:\WINDOWS\1DG6BCm
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\QD8HB
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\Lixec7
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\IKTrTG
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\EjLkeU
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\cG5Hstso
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\63Cp1Oet
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\5Wa87L
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\qDgOR
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\nhj8qXLov
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\GnFLPKDtyK
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\C62hiui
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\XYOHDo
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\lRvp8qsw
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\kBAie
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\APpT6oqFk
[2011/01/02 20:34:47 | 000,000,028 | ---- | C] () -- C:\WINDOWS\u4XNSwghot
[2011/01/02 20:34:47 | 000,000,028 | ---- | C] () -- C:\WINDOWS\kipV83i
[2011/01/02 20:34:47 | 000,000,028 | ---- | C] () -- C:\WINDOWS\e6JaP
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\ruqvTxBnU
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\GJgrd
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\FgoHg
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\bVIeGoH
[2011/01/02 20:34:47 | 000,000,026 | ---- | C] () -- C:\WINDOWS\hUcwRlUJ
[2011/01/02 20:34:46 | 000,000,047 | ---- | C] () -- C:\WINDOWS\X2VUkW
[2011/01/02 20:34:46 | 000,000,047 | ---- | C] () -- C:\WINDOWS\otJuGY
[2011/01/02 20:34:46 | 000,000,044 | ---- | C] () -- C:\WINDOWS\VXIEcq
[2011/01/02 20:34:46 | 000,000,042 | ---- | C] () -- C:\WINDOWS\pfS2Um
[2011/01/02 20:34:46 | 000,000,040 | ---- | C] () -- C:\WINDOWS\Jtd8F
[2011/01/02 20:34:46 | 000,000,039 | ---- | C] () -- C:\WINDOWS\t8NAq
[2011/01/02 20:34:46 | 000,000,038 | ---- | C] () -- C:\WINDOWS\LmkGgkiF
[2011/01/02 20:34:46 | 000,000,036 | ---- | C] () -- C:\WINDOWS\Tx7Wm3eg
[2011/01/02 20:34:46 | 000,000,036 | ---- | C] () -- C:\WINDOWS\NWGnE5
[2011/01/02 20:34:46 | 000,000,035 | ---- | C] () -- C:\WINDOWS\j5MHLUC
[2011/01/02 20:34:46 | 000,000,035 | ---- | C] () -- C:\WINDOWS\GCRklH23
[2011/01/02 20:34:46 | 000,000,034 | ---- | C] () -- C:\WINDOWS\xwgRvKN2dT
[2011/01/02 20:34:46 | 000,000,032 | ---- | C] () -- C:\WINDOWS\YmH1HIPww
[2011/01/02 20:34:46 | 000,000,032 | ---- | C] () -- C:\WINDOWS\awW5Ltxpf
[2011/01/02 20:34:46 | 000,000,031 | ---- | C] () -- C:\WINDOWS\thNrSB2V
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\uH2whCXiG
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\JfKDsowR
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\birbkGtK
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\ax8uM4r7LP
[2011/01/02 20:34:46 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Usf1ElUGS
[2011/01/02 20:34:46 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Fd5jCgjD
[2011/01/02 20:34:46 | 000,000,028 | ---- | C] () -- C:\WINDOWS\dUAU1UB
[2010/12/29 21:02:09 | 000,069,518 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\My Documents\cc_20101229_210204.reg
[2010/12/14 12:19:08 | 000,000,712 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\My Documents\GHremoval.bat
[2010/05/18 03:01:12 | 001,634,304 | ---- | C] () -- C:\WINDOWS\System32\d-L-_2CD1_H.dll
[2010/04/28 16:41:04 | 000,001,112 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\VVcku64agTJJ
[2010/04/28 16:41:04 | 000,001,112 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\VVcku64agTJJ
[2010/04/23 08:15:24 | 000,001,444 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\Mi715R2
[2010/04/23 08:15:24 | 000,001,444 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\Mi715R2
[2010/04/16 08:36:28 | 000,016,316 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\018LBPw26q64R
[2010/04/16 08:36:28 | 000,016,316 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\018LBPw26q64R
[2010/04/12 22:34:57 | 000,015,054 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\V8i44CYn52
[2010/04/12 22:34:57 | 000,015,054 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\V8i44CYn52
[2010/03/05 17:18:25 | 000,004,562 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\2Y04MW11w
[2010/03/04 17:51:11 | 000,011,668 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\deQagCc75
[2010/02/26 17:25:16 | 000,018,432 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\5c9c.exe
[2010/01/31 12:55:45 | 000,000,030 | ---- | C] () -- C:\WINDOWS\WAR2R.INI
[2009/12/04 23:04:26 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/12/04 23:04:26 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/12/03 23:08:59 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/10/18 12:14:37 | 000,127,744 | ---- | C] () -- C:\WINDOWS\System32\drivers\ArcHlp.sys
[2009/10/15 21:11:05 | 000,000,173 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/10/02 15:20:51 | 000,019,639 | ---- | C] () -- C:\Program Files\Common Files\qysyno.dll
[2009/10/02 15:20:51 | 000,017,438 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\oludije.ban
[2009/10/02 15:20:51 | 000,014,531 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ycapymej.ban
[2009/10/02 15:20:51 | 000,013,680 | ---- | C] () -- C:\Program Files\Common Files\kumiceqa.com
[2009/10/01 13:34:26 | 000,000,014 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\iniasd.txt
[2009/09/25 14:07:40 | 000,000,728 | ---- | C] () -- C:\WINDOWS\{4507868A-A9CD-4ECC-BD54-0EAB6EE81D42}_WiseFW.ini
[2009/01/23 17:32:51 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/12/01 17:26:37 | 000,000,140 | -H-- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\lakerda1967.sys
[2008/12/01 17:26:17 | 000,010,584 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\docXConverter (3).ini
[2007/10/11 18:59:24 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/04 21:43:25 | 002,067,140 | R--- | C] () -- C:\WINDOWS\System32\avcodec.dll
[2006/12/28 15:38:46 | 000,042,594 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2006/10/01 13:53:02 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\606D16E445.sys
[2006/09/20 19:16:15 | 000,060,928 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/16 19:25:47 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\45E4166D60.sys
[2006/09/15 22:23:05 | 000,000,077 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\FASTWiz.log
[2006/09/15 22:21:15 | 000,000,748 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\wklnhst.dat
[2006/09/15 22:13:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/09/15 12:57:17 | 000,000,134 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\fusioncache.dat
[2006/09/15 11:55:42 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/09/11 15:57:31 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/09/11 15:44:50 | 000,712,704 | ---- | C] () -- C:\WINDOWS\System32\DellSystemRestore.dll
[2006/09/11 15:42:19 | 000,000,260 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/09/11 15:38:36 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/09/11 14:28:50 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2006/09/11 14:28:44 | 000,000,474 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/06/01 22:10:25 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/04/09 16:04:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 12:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[1999/01/22 18:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 08:00:00 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\REGOBJ.DLL

========== LOP Check ==========

[2010/02/10 16:55:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bluetooth
[2007/08/25 14:20:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/10/28 08:33:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2009/01/23 18:57:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2009/01/24 18:30:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverCure
[2009/09/21 10:34:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/01/23 18:57:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/05/25 14:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegCure
[2006/09/15 22:17:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBT
[2010/12/10 15:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Screentime
[2008/02/03 15:40:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SongbirdVLC
[2009/09/25 14:08:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/10/27 10:08:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/14 16:20:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2006/09/11 15:48:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/09/13 10:42:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2010/04/04 16:02:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/11 18:46:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/01/01 01:40:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Alpob
[2010/12/01 14:00:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Anzeuz
[2011/01/01 01:40:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Avtyib
[2009/09/16 20:49:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2010/12/30 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Biniiz
[2010/12/29 20:01:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Boepp
[2011/01/01 01:40:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Cyan
[2009/01/24 14:34:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Cyrusoft
[2009/01/23 18:58:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\DriverCure
[2010/12/12 10:57:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Duegid
[2010/12/30 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Duoh
[2010/12/14 10:18:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Edazg
[2010/12/12 09:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Egewop
[2010/12/13 18:18:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Ehure
[2010/12/25 09:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Erxoun
[2010/12/16 21:55:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Exci
[2010/03/07 19:06:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Facebook
[2010/03/05 17:29:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Facebook(2)
[2010/11/30 01:09:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Fiezk
[2010/12/30 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Ibkyf
[2010/12/30 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Idxycy
[2010/12/12 09:52:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Imuhc
[2010/12/29 21:55:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Inbeox
[2010/12/18 10:05:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Isgeat
[2011/01/01 01:40:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Ivenny
[2010/12/12 10:18:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Kazyu
[2010/12/12 09:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Kiadqy
[2006/09/17 19:40:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Leadertech
[2007/09/30 21:31:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\LimeWire
[2010/12/25 19:46:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Loypfa
[2010/11/30 01:09:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Meib
[2010/12/23 16:22:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Miuly
[2006/09/15 21:49:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\MSNInstaller
[2010/12/06 19:51:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Muqi
[2010/12/12 23:07:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Myce
[2011/01/01 01:40:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Onra
[2010/12/25 14:43:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Oxdy
[2010/12/29 20:49:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Pyzog
[2008/02/03 15:49:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Qtrax1
[2008/08/23 23:25:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Samsung
[2010/12/12 10:57:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Saze
[2010/12/12 00:38:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Soac
[2007/12/18 22:44:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Template
[2010/08/14 16:24:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Trusteer
[2010/12/12 09:52:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Tuaw
[2010/12/01 14:00:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Ukni
[2010/12/13 22:22:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Ulneiw
[2011/01/01 01:40:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Umquxy
[2010/12/12 00:38:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Ungod
[2011/01/01 01:40:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Uropy
[2010/12/26 23:24:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\uTorrent
[2011/01/01 01:40:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Uxaf
[2009/01/17 13:28:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Viewpoint
[2010/12/29 21:55:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Voomqo
[2010/12/29 21:55:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Wiyh
[2010/12/06 19:51:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Xiywi
[2010/12/30 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Ylabbu
[2010/12/21 15:13:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Ylbu
[2010/12/13 21:17:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Ynuza
[2011/01/05 20:28:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma Nelder\Application Data\Yqaff
[2011/01/06 00:09:04 | 000,000,292 | -H-- | M] () -- C:\WINDOWS\Tasks\38480230.job
[2010/12/12 04:32:01 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\Driver Robot.job
[2011/01/03 12:00:00 | 000,000,374 | ---- | M] () -- C:\WINDOWS\Tasks\PerfectOptimizer_home.job
[2011/01/03 17:00:01 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Program Check.job
[2011/01/06 00:09:04 | 000,000,376 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Startup.job
[2010/12/12 04:21:25 | 000,000,384 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure.job
[2011/01/05 23:35:21 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{F0A36E4F-8866-4030-B42F-1A4DE747284D}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >


OTL Extras logfile created on: 06/01/2011 00:43:14 - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Emma Nelder\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 217.11 Gb Total Space | 69.55 Gb Free Space | 32.03% Space Free | Partition Type: NTFS
Drive D: | 12.55 Gb Total Space | 12.38 Gb Free Space | 98.66% Space Free | Partition Type: NTFS

Computer Name: EMMA | User Name: Emma Nelder | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"45538:TCP" = 45538:TCP:*:Enabled:LimeWire
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- File not found
"C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL -- File not found
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) -- File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- File not found
"C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL -- File not found
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) -- File not found
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Kontiki\KService.exe" = C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service -- File not found
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" = C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service -- (McAfee, Inc.)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- File not found
"C:\Program Files\O2\agent\bin\bcont.exe" = C:\Program Files\O2\agent\bin\bcont.exe:*:Enabled:bcont.exe -- (SupportSoft, Inc.)
"C:\Program Files\O2\bin\wificfg.exe" = C:\Program Files\O2\bin\wificfg.exe:*:Enabled:sprtcmd.exe -- (SupportSoft, Inc.)
"C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe" = C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe:*:Enabled:ssrc.exe -- (SupportSoft, Inc.)
"C:\Program Files\O2\agent\bin\bcont_nm.exe" = C:\Program Files\O2\agent\bin\bcont_nm.exe:*:Enabled:bcont_nm.exe -- (SupportSoft, Inc.)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil_.exe" = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:*:Enabled:BlueSoleil -- (IVT Corporation.)
"C:\Documents and Settings\Emma Nelder\Application Data\5c9c.exe" = C:\Documents and Settings\Emma Nelder\Application Data\5c9c.exe:*:Enabled:Win32load -- ()
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Disc 2
"{01521746-02A6-4A72-00BD-A285DF6B80C6}" = The Sims 2 University
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP3500_series" = Canon iP3500 series
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4300" = Canon iP4300
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1D3C662A-F6C6-4767-A788-7AA43A9A1317}" = ARTEuro
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 15
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{35C03C04-3F1F-42C2-A989-A757EE691F65}" = McAfee VirusScan Enterprise
"{3846E811-639D-4DE1-844B-30491C0A6C0C}" = Dell Support 3.2
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{41888B21-922B-4241-4594-EF1E6828A72B}" = BBC iPlayer Desktop
"{438BB9B4-65FE-4626-91D9-A8F57B18001D}" = Bluesoleil2.6.0.8 Release 070517
"{4507868A-A9CD-4ECC-BD54-0EAB6EE81D42}" = O2 Broadband Assistant
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}" = The Sims 2 Family Fun Stuff
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = The Sims 2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}" = RollerCoaster Tycoon 2
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = The Sims™ 2 FreeTime
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}" = Logitech QuickCam
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}" = Dell Media Experience
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{AEEB3643-71DE-414d-9E3F-1159177FE211}" = Office Animation Runtime
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AF6841FE-7A9D-45C1-ACE8-1BE7F2F6A027}" = ArcSoft TotalMedia Extreme
"{AFFC90AE-A34A-4198-A3EC-95E1D074FE2B}" = Mulberry
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6F5B704-06D3-4687-90F3-6195304AD755}" = The Sims™ 2 Apartment Life
"{BE8913B7-B2C4-48BE-8A26-84390FF4F231}" = DMX Update
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CECFDD53-35DB-4235-9363-7964A0C88E0E}" = Samsung PC Studio
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Sims™ 2 Seasons
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = The Sims™ 2 Celebration! Stuff
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{F04CAFE3-D52F-4EFC-A1E8-316BD4C525D6}" = NTI Shadow
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Sims™ 2 Bon Voyage
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"7-Zip" = 7-Zip 4.65
"ABC Amber LIT Converter" = ABC Amber LIT Converter
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AviSynth" = AviSynth 2.5
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"Canon iP3500 series User Registration" = Canon iP3500 series User Registration
"Canon iP4300 User Registration" = Canon iP4300 User Registration
"Canon Setup Utility 2.3" = Canon Setup Utility 2.3
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"Connection Manager" = Microsoft Connection Manager
"Doctor-Who-2010-Series" = Doctor-Who-2010-Series Screen Saver
"docXConverter3_is1" = docXConverter 3.1.2
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint" = Easy-WebPrint
"ExpressBurn" = Express Burn
"Google Desktop" = Google Desktop
"Google Video Converter_is1" = Google Video Converter 4.0.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"legacyqcam_10.40" = Logitech Legacy USB Camera Driver Package
"lvdrivers_11.50" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MIXERLITE" = Mixer
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Prism" = Prism Video Converter
"ProInst" = Intel® PROSet/Wireless Software
"Rapport_msi" = Rapport
"RealPlayer 6.0" = RealPlayer Basic
"RegCure" = RegCure
"RollerCoaster Tycoon Setup" = Roll
"Rundll Errors Fix Wizard_is1" = Rundll Errors Fix Wizard
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SearchAssist" = SearchAssist
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"tunnel" = tunnel Screen Saver
"ViewpointMediaPlayer" = Viewpoint Media Player
"Vodafone 804SS USB driver" = Vodafone 804SS USB driver Software
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.2 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 05/01/2011 16:14:51 | Computer Name = EMMA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2000

Error - 05/01/2011 16:14:52 | Computer Name = EMMA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 05/01/2011 16:14:52 | Computer Name = EMMA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3969

Error - 05/01/2011 16:14:52 | Computer Name = EMMA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3969

Error - 05/01/2011 16:14:54 | Computer Name = EMMA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 05/01/2011 16:14:54 | Computer Name = EMMA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 5953

Error - 05/01/2011 16:14:54 | Computer Name = EMMA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5953

Error - 05/01/2011 16:14:56 | Computer Name = EMMA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 05/01/2011 16:14:56 | Computer Name = EMMA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7906

Error - 05/01/2011 16:14:56 | Computer Name = EMMA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7906

[ System Events ]
Error - 04/01/2011 06:25:48 | Computer Name = EMMA | Source = NetBT | ID = 4311
Description = Initialization failed because the driver device could not be created.

Error - 04/01/2011 06:25:48 | Computer Name = EMMA | Source = NetBT | ID = 4311
Description = Initialization failed because the driver device could not be created.

Error - 04/01/2011 06:25:48 | Computer Name = EMMA | Source = NetBT | ID = 4311
Description = Initialization failed because the driver device could not be created.

Error - 05/01/2011 20:09:09 | Computer Name = EMMA | Source = NetBT | ID = 4311
Description = Initialization failed because the driver device could not be created.

Error - 05/01/2011 20:09:09 | Computer Name = EMMA | Source = NetBT | ID = 4311
Description = Initialization failed because the driver device could not be created.

Error - 05/01/2011 20:09:09 | Computer Name = EMMA | Source = NetBT | ID = 4311
Description = Initialization failed because the driver device could not be created.

Error - 05/01/2011 20:09:09 | Computer Name = EMMA | Source = NetBT | ID = 4311
Description = Initialization failed because the driver device could not be created.

Error - 05/01/2011 20:09:09 | Computer Name = EMMA | Source = NetBT | ID = 4311
Description = Initialization failed because the driver device could not be created.

Error - 05/01/2011 20:09:09 | Computer Name = EMMA | Source = NetBT | ID = 4311
Description = Initialization failed because the driver device could not be created.

Error - 05/01/2011 20:09:09 | Computer Name = EMMA | Source = NetBT | ID = 4311
Description = Initialization failed because the driver device could not be created.


< End of report >

Thanks!
Emma

Edited by Emma&Pat, 06 January 2011 - 10:17 AM.

  • 0

Advertisements


#2
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello Emma&Pat

Welcome to Geeks to Go.
=====================

One or more of the identified infections is a backdoor trojan or rootkit.

This type of infection has the capabilities to allows hacker to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identity Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do.

If you still want to clean it please do the following


===================
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
========
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • 0

#3
Emma&Pat

Emma&Pat

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi,

I've run both the TDSSKiller and ComboFix. The TDSSKiller log is below; however, while combofix was running the desktop went blank, with all icons and the taskbar disappearing leaving just the desktop wallpaper. There was nothing showing in Task Manager, and when I restarted the laptop I got an "ending non-responsive program googledesktop.e" message. The laptop then shut down and restarted normally.

TDSSKiller log:
2011/01/08 00:06:38.0093 TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46
2011/01/08 00:06:38.0093 ================================================================================
2011/01/08 00:06:38.0093 SystemInfo:
2011/01/08 00:06:38.0093
2011/01/08 00:06:38.0093 OS Version: 5.1.2600 ServicePack: 3.0
2011/01/08 00:06:38.0093 Product type: Workstation
2011/01/08 00:06:38.0093 ComputerName: EMMA
2011/01/08 00:06:38.0093 UserName: Emma Nelder
2011/01/08 00:06:38.0093 Windows directory: C:\WINDOWS
2011/01/08 00:06:38.0093 System windows directory: C:\WINDOWS
2011/01/08 00:06:38.0093 Processor architecture: Intel x86
2011/01/08 00:06:38.0093 Number of processors: 2
2011/01/08 00:06:38.0093 Page size: 0x1000
2011/01/08 00:06:38.0093 Boot type: Normal boot
2011/01/08 00:06:38.0093 ================================================================================
2011/01/08 00:06:38.0515 Initialize success
2011/01/08 00:06:49.0718 ================================================================================
2011/01/08 00:06:49.0718 Scan started
2011/01/08 00:06:49.0718 Mode: Manual;
2011/01/08 00:06:49.0718 ================================================================================
2011/01/08 00:06:53.0343 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
2011/01/08 00:06:53.0453 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/01/08 00:06:53.0515 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/01/08 00:06:53.0562 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
2011/01/08 00:06:53.0656 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/01/08 00:06:53.0828 AegisP (91f3df93f40a74d222cd166fe95db633) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/01/08 00:06:53.0906 Afc (a7b8a3a79d35215d798a300df49ed23f) C:\WINDOWS\system32\drivers\Afc.sys
2011/01/08 00:06:54.0046 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/01/08 00:06:54.0156 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/01/08 00:06:54.0218 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
2011/01/08 00:06:54.0312 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
2011/01/08 00:06:54.0421 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
2011/01/08 00:06:54.0531 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
2011/01/08 00:06:54.0765 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
2011/01/08 00:06:54.0843 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
2011/01/08 00:06:54.0921 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
2011/01/08 00:06:55.0000 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
2011/01/08 00:06:55.0109 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS
2011/01/08 00:06:55.0203 archlp (d781cb30626ff2f391bc9ec6e20801b9) C:\WINDOWS\system32\drivers\archlp.sys
2011/01/08 00:06:55.0281 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/01/08 00:06:55.0375 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
2011/01/08 00:06:55.0484 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
2011/01/08 00:06:55.0562 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
2011/01/08 00:06:55.0671 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys
2011/01/08 00:06:55.0812 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/01/08 00:06:55.0921 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/01/08 00:06:56.0031 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/01/08 00:06:56.0140 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/01/08 00:06:56.0234 bcm4sbxp (c768c8a463d32c219ce291645a0621a4) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
2011/01/08 00:06:56.0296 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/01/08 00:06:56.0406 BlueletAudio (852a1bd08e7dfeb9e30b5440881c0501) C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
2011/01/08 00:06:56.0468 BlueletSCOAudio (8fc27b12a02b43947787f0ef1885df9b) C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys
2011/01/08 00:06:56.0546 BT (c5cce2b26f73f8cf7f3c82159e79aa08) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
2011/01/08 00:06:56.0609 Btcsrusb (da473d279420234170da795f1cad4479) C:\WINDOWS\system32\Drivers\btcusb.sys
2011/01/08 00:06:56.0656 BTHidEnum (ce643d0918123d76a5caab008fca9663) C:\WINDOWS\system32\Drivers\vbtenum.sys
2011/01/08 00:06:56.0687 BTHidMgr (dfca4fe4c8aec786b4d0f432eb730f48) C:\WINDOWS\system32\Drivers\BTHidMgr.sys
2011/01/08 00:06:56.0859 BTNetFilter (4f26303becbb7cc5ca8ff39593124cf2) C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys
2011/01/08 00:06:56.0953 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
2011/01/08 00:06:57.0015 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/01/08 00:06:57.0093 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/01/08 00:06:57.0171 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
2011/01/08 00:06:57.0312 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/01/08 00:06:57.0359 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/01/08 00:06:57.0421 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/01/08 00:06:57.0531 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/01/08 00:06:57.0578 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
2011/01/08 00:06:57.0609 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/01/08 00:06:57.0656 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
2011/01/08 00:06:57.0718 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
2011/01/08 00:06:57.0734 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
2011/01/08 00:06:57.0796 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/01/08 00:06:57.0875 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/01/08 00:06:57.0937 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/01/08 00:06:57.0984 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/01/08 00:06:58.0046 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/01/08 00:06:58.0140 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
2011/01/08 00:06:58.0203 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/01/08 00:06:58.0437 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys
2011/01/08 00:06:58.0687 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys
2011/01/08 00:06:58.0968 DSproct (2ac2372ffad9adc85672cc8e8ae14be9) C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys
2011/01/08 00:06:59.0031 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/01/08 00:06:59.0140 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/01/08 00:06:59.0203 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/01/08 00:06:59.0312 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/01/08 00:06:59.0375 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/01/08 00:06:59.0515 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/01/08 00:06:59.0562 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/01/08 00:06:59.0625 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/01/08 00:06:59.0718 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2011/01/08 00:06:59.0828 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/01/08 00:06:59.0937 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/01/08 00:07:00.0000 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/01/08 00:07:00.0046 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
2011/01/08 00:07:00.0140 HSFHWAZL (1c8caa80e91fb71864e9426f9eed048d) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
2011/01/08 00:07:00.0250 HSF_DPV (698204d9c2832e53633e53a30a53fc3d) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
2011/01/08 00:07:00.0375 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/01/08 00:07:00.0468 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
2011/01/08 00:07:00.0562 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
2011/01/08 00:07:00.0609 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/01/08 00:07:00.0750 ialm (cc449157474d5e43daea7e20f52c635a) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
2011/01/08 00:07:00.0890 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/01/08 00:07:01.0000 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
2011/01/08 00:07:01.0093 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/01/08 00:07:01.0171 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/01/08 00:07:01.0234 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/01/08 00:07:01.0250 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/01/08 00:07:01.0281 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/01/08 00:07:01.0328 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/01/08 00:07:01.0375 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/01/08 00:07:01.0421 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/01/08 00:07:01.0468 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/01/08 00:07:01.0531 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/01/08 00:07:01.0625 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/01/08 00:07:01.0718 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/01/08 00:07:01.0906 LVcKap (8113133ec42dd6c566908008ce913edd) C:\WINDOWS\system32\DRIVERS\LVcKap.sys
2011/01/08 00:07:02.0109 LVMVDrv (0dd5b8af4917a2821047450195c511b3) C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys
2011/01/08 00:07:02.0296 LVPr2Mon (406b1d186f75b4b4832d6237859e1b00) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
2011/01/08 00:07:02.0578 LVUSBSta (ccff53b1fcdfa9ede919e3bdbd10d0fd) C:\WINDOWS\system32\drivers\lvusbsta.sys
2011/01/08 00:07:02.0718 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/01/08 00:07:02.0843 mfeapfk (6a7418672657547e543d8c04f94258e1) C:\WINDOWS\system32\drivers\mfeapfk.sys
2011/01/08 00:07:02.0921 mfeavfk (63c29d5148a1fb26beb60e45b94e6df2) C:\WINDOWS\system32\drivers\mfeavfk.sys
2011/01/08 00:07:03.0031 mfebopk (a4d0923fb0f233c6476e1fa2b5d6c0b1) C:\WINDOWS\system32\drivers\mfebopk.sys
2011/01/08 00:07:03.0125 mfehidk (791e08dca5e1d347551ae27edf32a2b6) C:\WINDOWS\system32\drivers\mfehidk.sys
2011/01/08 00:07:03.0296 mferkdk (2f875c69112eeed976b7d7e397fd6871) C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys
2011/01/08 00:07:03.0562 mfetdik (923b88a31c63fb2b1bde239fef6ed158) C:\WINDOWS\system32\drivers\mfetdik.sys
2011/01/08 00:07:03.0718 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/01/08 00:07:03.0796 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/01/08 00:07:03.0875 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/01/08 00:07:03.0953 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/01/08 00:07:04.0015 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/01/08 00:07:04.0078 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
2011/01/08 00:07:04.0093 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/01/08 00:07:04.0171 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/01/08 00:07:04.0234 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/01/08 00:07:04.0312 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/01/08 00:07:04.0375 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/01/08 00:07:04.0453 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/01/08 00:07:04.0531 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/01/08 00:07:04.0578 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/01/08 00:07:04.0609 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/01/08 00:07:04.0671 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/01/08 00:07:04.0718 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/01/08 00:07:04.0781 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/01/08 00:07:04.0843 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/01/08 00:07:04.0890 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/01/08 00:07:04.0921 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/01/08 00:07:04.0984 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/01/08 00:07:05.0046 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/01/08 00:07:05.0125 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/01/08 00:07:05.0234 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/01/08 00:07:05.0328 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/01/08 00:07:05.0421 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/01/08 00:07:05.0531 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/01/08 00:07:05.0671 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/01/08 00:07:05.0859 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/01/08 00:07:05.0968 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/01/08 00:07:06.0046 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/01/08 00:07:06.0125 omci (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys
2011/01/08 00:07:06.0187 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/01/08 00:07:06.0218 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/01/08 00:07:06.0250 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/01/08 00:07:06.0281 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/01/08 00:07:06.0328 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/01/08 00:07:06.0375 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/01/08 00:07:06.0453 pctfw2 (86e92f65df9b3185bee2e7023ede18d1) C:\WINDOWS\system32\drivers\pctfw2.sys
2011/01/08 00:07:06.0593 pepifilter (1c23843f1f61a07e2aaaba80136cda19) C:\WINDOWS\system32\DRIVERS\lv302af.sys
2011/01/08 00:07:06.0703 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
2011/01/08 00:07:06.0781 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
2011/01/08 00:07:06.0890 PID_PEPI (87a74c342b9b291cb013093d5df7b916) C:\WINDOWS\system32\DRIVERS\LV302V32.SYS
2011/01/08 00:07:07.0031 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/01/08 00:07:07.0109 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/01/08 00:07:07.0140 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/01/08 00:07:07.0203 PxHelp20 (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/01/08 00:07:07.0250 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
2011/01/08 00:07:07.0281 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
2011/01/08 00:07:07.0296 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
2011/01/08 00:07:07.0375 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
2011/01/08 00:07:07.0453 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
2011/01/08 00:07:07.0703 RapportCerberus_19917 (539fbdcff37a24102c507092b333ec2b) C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys
2011/01/08 00:07:07.0796 RapportKELL (b64262f33c53d690ed662fde57102b10) C:\WINDOWS\system32\Drivers\RapportKELL.sys
2011/01/08 00:07:07.0968 RapportPG (c9b8a131aaf77d969cbc3987537b319d) C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys
2011/01/08 00:07:08.0031 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/01/08 00:07:08.0125 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/01/08 00:07:08.0203 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/01/08 00:07:08.0265 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/01/08 00:07:08.0312 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/01/08 00:07:08.0500 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/01/08 00:07:08.0796 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/01/08 00:07:08.0890 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/01/08 00:07:08.0953 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/01/08 00:07:09.0093 rimmptsk (24ed7af20651f9fa1f249482e7c1f165) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
2011/01/08 00:07:09.0140 rimsptsk (1bdba2d2d402415a78a4ba766dfe0f7b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
2011/01/08 00:07:09.0218 rismxdp (f774ecd11a064f0debb2d4395418153c) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
2011/01/08 00:07:09.0281 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2011/01/08 00:07:09.0406 s24trans (2c0e9e777ab1849b43494626c1f308b5) C:\WINDOWS\system32\DRIVERS\s24trans.sys
2011/01/08 00:07:09.0531 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
2011/01/08 00:07:09.0671 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/01/08 00:07:09.0765 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/01/08 00:07:09.0828 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/01/08 00:07:09.0906 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys
2011/01/08 00:07:09.0984 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
2011/01/08 00:07:10.0078 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/01/08 00:07:10.0234 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
2011/01/08 00:07:10.0328 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/01/08 00:07:10.0375 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
2011/01/08 00:07:10.0421 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/01/08 00:07:10.0453 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/01/08 00:07:10.0546 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/01/08 00:07:10.0656 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
2011/01/08 00:07:10.0687 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
2011/01/08 00:07:10.0734 ss_bus (bd15182e9d2d3fabc1d1313badbd2415) C:\WINDOWS\system32\DRIVERS\ss_bus.sys
2011/01/08 00:07:10.0765 ss_mdfl (67d1144f249a3c5e03ebd7a2304dee11) C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
2011/01/08 00:07:10.0859 ss_mdm (954b7ce2d54c703d6a8471d6b05a5e13) C:\WINDOWS\system32\DRIVERS\ss_mdm.sys
2011/01/08 00:07:11.0000 STHDA (3ad78e22210d3fbd9f76de84a8df19b5) C:\WINDOWS\system32\drivers\sthda.sys
2011/01/08 00:07:11.0109 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/01/08 00:07:11.0156 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/01/08 00:07:11.0187 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/01/08 00:07:11.0250 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
2011/01/08 00:07:11.0281 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
2011/01/08 00:07:11.0296 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
2011/01/08 00:07:11.0328 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
2011/01/08 00:07:11.0390 SynTP (fa2daa32bed908023272a0f77d625dae) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2011/01/08 00:07:11.0421 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/01/08 00:07:11.0531 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/01/08 00:07:11.0640 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/01/08 00:07:11.0718 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/01/08 00:07:11.0765 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/01/08 00:07:11.0843 tfsnboio (30698355067d07da5f9eb81132c9fdd6) C:\WINDOWS\system32\dla\tfsnboio.sys
2011/01/08 00:07:11.0859 tfsncofs (fb9d825bb4a2abdf24600f7505050e2b) C:\WINDOWS\system32\dla\tfsncofs.sys
2011/01/08 00:07:11.0875 tfsndrct (cafd8cca11aa1e8b6d2ea1ba8f70ec33) C:\WINDOWS\system32\dla\tfsndrct.sys
2011/01/08 00:07:11.0906 tfsndres (8db1e78fbf7c426d8ec3d8f1a33d6485) C:\WINDOWS\system32\dla\tfsndres.sys
2011/01/08 00:07:11.0937 tfsnifs (b92f67a71cc8176f331b8aa8d9f555ad) C:\WINDOWS\system32\dla\tfsnifs.sys
2011/01/08 00:07:12.0031 tfsnopio (85985faa9a71e2358fcc2edefc2a3c5c) C:\WINDOWS\system32\dla\tfsnopio.sys
2011/01/08 00:07:12.0046 tfsnpool (bba22094f0f7c210567efdaf11f64495) C:\WINDOWS\system32\dla\tfsnpool.sys
2011/01/08 00:07:12.0078 tfsnudf (81340bef80b9811e98ce64611e67e3ff) C:\WINDOWS\system32\dla\tfsnudf.sys
2011/01/08 00:07:12.0093 tfsnudfa (c035fd116224ccc8325f384776b6a8bb) C:\WINDOWS\system32\dla\tfsnudfa.sys
2011/01/08 00:07:12.0468 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
2011/01/08 00:07:12.0515 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/01/08 00:07:12.0562 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
2011/01/08 00:07:12.0703 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/01/08 00:07:12.0859 USBAAPL (e8c1b9ebac65288e1b51e8a987d98af6) C:\WINDOWS\system32\Drivers\usbaapl.sys
2011/01/08 00:07:13.0140 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/01/08 00:07:13.0281 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/01/08 00:07:13.0328 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/01/08 00:07:13.0359 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/01/08 00:07:13.0437 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/01/08 00:07:13.0468 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/01/08 00:07:13.0546 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/01/08 00:07:13.0625 VComm (51750b0539986186c6931fc40d171521) C:\WINDOWS\system32\DRIVERS\VComm.sys
2011/01/08 00:07:13.0687 VcommMgr (6d9c891c0a761afed1f3609c2e56f2b9) C:\WINDOWS\system32\Drivers\VcommMgr.sys
2011/01/08 00:07:13.0734 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/01/08 00:07:13.0796 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
2011/01/08 00:07:13.0875 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2011/01/08 00:07:13.0953 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/01/08 00:07:14.0109 w39n51 (95c7421f8bafc85ba09d33364058937d) C:\WINDOWS\system32\DRIVERS\w39n51.sys
2011/01/08 00:07:14.0281 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/01/08 00:07:14.0437 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/01/08 00:07:14.0531 winachsf (74cf3f2e4e40c4a2e18d39d6300a5c24) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/01/08 00:07:14.0703 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/01/08 00:07:14.0812 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/01/08 00:07:14.0875 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/01/08 00:07:14.0937 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/01/08 00:07:15.0078 ================================================================================
2011/01/08 00:07:15.0078 Scan finished
2011/01/08 00:07:15.0078 ================================================================================
2011/01/08 00:07:58.0703 Deinitialize success
  • 0

#4
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Ok open OTL once more and click on Run scan.
Post the new log that opens please.
  • 0

#5
Emma&Pat

Emma&Pat

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
OTL logfile created on: 09/01/2011 11:21:22 - Run 2
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Emma Nelder\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 53.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 217.11 Gb Total Space | 69.60 Gb Free Space | 32.06% Space Free | Partition Type: NTFS
Drive D: | 12.55 Gb Total Space | 12.38 Gb Free Space | 98.66% Space Free | Partition Type: NTFS

Computer Name: EMMA | User Name: Emma Nelder | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
PRC - [2010/10/27 19:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/10/03 22:43:16 | 000,767,208 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2010/08/25 10:27:44 | 000,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010/08/13 17:51:04 | 000,030,192 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2010/04/16 18:36:42 | 000,026,480 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2010/04/16 07:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009/03/04 14:52:58 | 000,202,016 | R--- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprtsvc.exe
PRC - [2009/03/04 14:52:22 | 000,202,016 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprtcmd.exe
PRC - [2008/05/22 20:50:00 | 000,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
PRC - [2008/05/22 20:50:00 | 000,111,952 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2008/05/22 20:50:00 | 000,054,608 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
PRC - [2008/04/14 00:12:32 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\proquota.exe
PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/10/25 16:37:32 | 002,178,832 | ---- | M] () -- C:\Program Files\Logitech\QuickCam\Quickcam.exe
PRC - [2007/10/25 16:33:22 | 000,563,984 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2007/10/25 16:32:58 | 000,407,824 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2007/10/25 15:06:00 | 000,086,016 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\Mctray.exe
PRC - [2007/10/25 10:05:40 | 000,136,512 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2007/10/25 10:04:56 | 000,136,512 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2007/10/25 10:03:28 | 000,103,744 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2007/10/19 13:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2007/06/24 19:17:54 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007/04/13 16:20:22 | 000,097,432 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe
PRC - [2007/04/04 01:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2006/09/11 15:47:38 | 000,026,112 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\realplay.exe
PRC - [2006/07/16 20:29:54 | 000,389,120 | ---- | M] (Gteko Ltd.) -- C:\Program Files\Dell Support\DSAgnt.exe
PRC - [2006/04/06 13:57:54 | 000,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2006/03/24 22:30:44 | 000,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2005/06/10 09:44:02 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2005/02/23 14:57:24 | 000,057,344 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Mixer\CTSVolFE.exe
PRC - [2005/01/27 00:02:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2003/10/29 01:06:00 | 000,024,576 | ---- | M] (BVRP Software) -- C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2000/02/24 17:23:44 | 008,810,548 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office\WINWORD.EXE
PRC - [1998/12/16 21:09:20 | 000,057,393 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE


========== Modules (SafeList) ==========

MOD - [2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
MOD - [2010/08/23 16:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/03/04 14:52:40 | 000,116,000 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprthook.dll
MOD - [2008/04/14 00:12:01 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/10/03 22:43:16 | 000,767,208 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2010/08/13 17:51:04 | 000,030,192 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-051210-111108)
SRV - [2010/04/16 07:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/03/04 14:52:58 | 000,202,016 | R--- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\O2\bin\sprtsvc.exe -- (sprtsvc_O2) SupportSoft Sprocket Service (O2)
SRV - [2008/05/22 20:50:00 | 000,144,704 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe -- (McShield)
SRV - [2008/05/22 20:50:00 | 000,054,608 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
SRV - [2007/10/25 10:03:28 | 000,103,744 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2007/10/19 13:21:16 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2007/10/19 13:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2007/10/19 13:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)
SRV - [2007/07/27 05:39:32 | 000,382,320 | ---- | M] (SupportSoft, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2007/04/13 16:20:22 | 000,097,432 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2006/05/01 08:34:00 | 000,262,217 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER) Intel®
SRV - [2006/05/01 08:22:42 | 000,540,745 | ---- | M] (Intel Corporation ) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2006/05/01 08:20:52 | 000,114,753 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2006/05/01 08:20:26 | 000,217,164 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2006/04/06 13:57:54 | 000,380,928 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\wusoc.sys -- (qsryxq)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\PavSRK.sys -- (PavSRK.sys)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\ncyyvqao.sys -- (ilgecs)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\COMFiltr.sys -- (ComFiltr)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\EMMANE~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/10/03 22:54:04 | 000,034,792 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys -- (RapportCerberus_19917)
DRV - [2010/10/03 22:43:44 | 000,169,320 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2010/10/03 22:43:44 | 000,059,240 | ---- | M] (Trusteer Ltd.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2009/02/19 13:22:52 | 000,127,744 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ArcHlp.sys -- (archlp)
DRV - [2008/07/16 09:43:16 | 000,160,648 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\pctfw2.sys -- (pctfw2)
DRV - [2008/05/22 20:50:00 | 000,174,952 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2008/05/22 20:50:00 | 000,072,936 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2008/05/22 20:50:00 | 000,064,232 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2008/05/22 20:50:00 | 000,052,104 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2008/05/22 20:50:00 | 000,033,960 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2008/05/22 20:50:00 | 000,031,816 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys -- (mferkdk)
DRV - [2008/04/13 18:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 18:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 18:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 16:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/10/19 13:16:30 | 002,109,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007/10/11 18:59:24 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2007/10/11 18:59:02 | 002,142,488 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/05/11 03:10:50 | 000,034,704 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007/05/09 01:59:40 | 000,036,496 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007/03/05 06:00:04 | 000,027,792 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2007/03/05 05:59:04 | 000,018,320 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btnetdrv.sys -- (BT)
DRV - [2007/03/05 05:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2007/03/05 05:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - [2007/03/05 05:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2007/03/05 05:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2006/11/21 22:41:18 | 000,022,416 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Program Files\IVT Corporation\BlueSoleil\device\Win2k\BTNetFilter.sys -- (BTNetFilter)
DRV - [2006/11/10 19:48:02 | 000,040,352 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2006/11/10 19:43:16 | 000,933,536 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2006/11/10 19:43:16 | 000,013,344 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2006/09/11 15:47:41 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2006/05/01 08:52:02 | 000,013,568 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/04/26 22:13:04 | 001,429,632 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel®
DRV - [2006/03/24 22:34:30 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/03/08 17:35:10 | 000,191,872 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2006/01/10 11:07:58 | 000,004,864 | ---- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/10/14 14:40:18 | 000,307,968 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/10/14 14:40:18 | 000,051,328 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/10/14 14:40:18 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/08/30 17:59:00 | 000,094,000 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2005/08/30 17:58:56 | 000,008,304 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2005/08/30 17:57:18 | 000,058,320 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)
DRV - [2005/08/12 16:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/08/05 15:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/22 02:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 02:01:08 | 000,201,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/07/22 02:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/02/23 13:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2004/12/06 00:05:00 | 000,100,603 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudfa.sys -- (tfsnudfa)
DRV - [2004/12/06 00:05:00 | 000,098,714 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudf.sys -- (tfsnudf)
DRV - [2004/12/06 00:05:00 | 000,086,586 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnifs.sys -- (tfsnifs)
DRV - [2004/12/06 00:05:00 | 000,034,843 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsncofs.sys -- (tfsncofs)
DRV - [2004/12/06 00:05:00 | 000,025,883 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnboio.sys -- (tfsnboio)
DRV - [2004/12/06 00:05:00 | 000,015,227 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnopio.sys -- (tfsnopio)
DRV - [2004/12/06 00:05:00 | 000,006,363 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnpool.sys -- (tfsnpool)
DRV - [2004/12/06 00:05:00 | 000,004,123 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndrct.sys -- (tfsndrct)
DRV - [2004/12/06 00:05:00 | 000,002,239 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndres.sys -- (tfsndres)
DRV - [2004/12/01 02:22:00 | 000,087,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb)
DRV - [2004/11/23 01:56:00 | 000,040,480 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\drvnddm.sys -- (drvnddm)
DRV - [2004/08/03 21:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004/07/14 10:29:04 | 000,005,627 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\sscdbhk5.sys -- (sscdbhk5)
DRV - [2004/07/14 10:28:50 | 000,023,545 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\ssrtln.sys -- (ssrtln)
DRV - [2004/02/13 15:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
DRV - [2001/08/17 13:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 13:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 13:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 13:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 13:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 12:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 12:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 12:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 12:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 12:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 12:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 12:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 12:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 12:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 12:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074

========== FireFox ==========

FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..browser.startup.homepage: "http://flvdirect.iamwired.net/"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..keyword.URL: "http://flvdirect.iam...c=tops&search="
FF - prefs.js..keyword.enabled: true
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaulturl: "http://flvdirect.iam...c=tops&search="
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"


FF - HKLM\software\mozilla\Firefox\extensions\\{8779B4BC-1A5D-4E0E-B83B-171D20F2236D}: C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\{8779B4BC-1A5D-4E0E-B83B-171D20F2236D} [2010/07/27 07:18:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{387D07D6-5CF8-44EB-AECB-C4B4A82A9511}: C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\{387D07D6-5CF8-44EB-AECB-C4B4A82A9511}

[2010/05/20 16:24:03 | 000,000,266 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\Application Data\Mozilla\Firefox\Profiles\2w0v2hf2.default\searchplugins\Search.xml

O1 HOSTS File: ([2009/01/23 17:23:52 | 000,000,736 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1ed61cb2-86f5-82b1-b5d1-e81934c7bfbe} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [CTSVolFE.exe] C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [O2] C:\Program Files\O2\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnote...ad/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {1288683E-8FB1-46E3-AF62-9BB668505759} http://www.wireless....der_activex.ocx (xc_loader_activex.cntMain)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {17D667BA-5675-4AAB-9221-08B9379384D4} http://cdnimg.piczo....st_uploader.cab (Image Uploader Control)
O16 - DPF: {483912CF-8995-4434-AD61-6163756E05DF} http://download.live...tivex/AXTNS.ocx (AXTNS Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcaf...01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8EF9626B-2251-4C5E-BD17-D5F3E0E98B03} http://www.wireless....der_activex.ocx (xc_loader_activex.cntMain)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius....tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} http://www.tescophot...opcuploader.cab (Image Uploader 3.0 Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe\yhlgyfgg.exe) - C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe\yhlgyfgg.exe File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Emma Nelder\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Emma Nelder\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O29 - HKLM SecurityProviders - (mcmvxqyx.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/08 11:06:28 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/01/08 10:29:02 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\proquota.exe
[2011/01/08 10:29:02 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\proquota.exe
[2011/01/08 10:21:09 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/01/08 10:15:38 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/01/08 10:15:38 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/01/08 10:15:38 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/01/08 10:15:38 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/01/08 10:15:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/01/08 10:12:18 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/01/07 14:31:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\AnyBizSoft PDF to PowerPoint
[2011/01/07 14:31:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AnyBizSoft
[2011/01/07 14:31:20 | 000,000,000 | ---D | C] -- C:\Program Files\AnyBizSoft
[2011/01/07 14:22:07 | 000,000,000 | ---D | C] -- C:\Program Files\SomePDF
[2011/01/07 14:19:09 | 000,000,000 | ---D | C] -- C:\Program Files\AXPDF
[2011/01/07 14:19:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AXPDF
[2011/01/06 00:42:18 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
[2011/01/03 10:13:05 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/01/03 10:10:51 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2011/01/01 05:08:44 | 000,000,000 | ---D | C] -- C:\Program Files\ert
[2010/12/30 06:27:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Emma Nelder\Recent
[2010/12/25 21:58:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\My Received Files
[2010/12/25 19:46:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Loypfa
[2010/12/25 19:46:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Alpob
[2010/12/25 14:43:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Oxdy
[2010/12/25 14:43:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ivenny
[2010/12/25 09:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Erxoun
[2010/12/25 09:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Cyan
[2010/12/23 16:22:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Miuly
[2010/12/23 16:22:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Avtyib
[2010/12/22 17:31:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ibkyf
[2010/12/22 17:31:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Wiyh
[2010/12/21 15:21:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/12/21 15:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ylbu
[2010/12/21 15:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Onra
[2010/12/21 10:09:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Boepp
[2010/12/18 10:05:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Uropy
[2010/12/18 10:05:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Isgeat
[2010/12/16 21:55:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Uxaf
[2010/12/16 21:55:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Exci
[2010/12/16 21:26:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/12/14 23:58:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2010/12/14 21:28:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Umquxy
[2010/12/14 21:28:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Idxycy
[2010/12/14 09:48:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Edazg
[2010/12/13 22:22:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Yqaff
[2010/12/13 22:22:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ulneiw
[2010/12/13 13:04:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\Pictures - Digital Camera
[2010/12/13 09:29:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Duoh
[2010/12/12 10:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Myce
[2010/12/12 08:12:08 | 000,000,000 | ---D | C] -- C:\Program Files\qwers
[2010/12/12 00:38:22 | 000,000,000 | ---D | C] -- C:\Program Files\qwer
[2010/12/12 00:38:17 | 000,000,000 | ---D | C] -- C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe
[2010/12/10 15:19:25 | 000,680,288 | ---- | C] (ScreenTime Media) -- C:\WINDOWS\System32\Doctor-Who-2010-Series.scr
[2010/12/10 15:19:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Screentime
[2010/12/10 15:19:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\Screentime
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Emma Nelder\My Documents\*.tmp files -> C:\Documents and Settings\Emma Nelder\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/09 11:17:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/09 09:53:12 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{F0A36E4F-8866-4030-B42F-1A4DE747284D}.job
[2011/01/08 12:00:00 | 000,000,374 | ---- | M] () -- C:\WINDOWS\tasks\PerfectOptimizer_home.job
[2011/01/08 11:05:30 | 000,000,376 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Startup.job
[2011/01/08 10:55:43 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/08 10:55:39 | 000,000,292 | -H-- | M] () -- C:\WINDOWS\tasks\38480230.job
[2011/01/08 10:55:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/08 10:55:18 | 2137,456,640 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/08 10:21:14 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/01/08 10:11:00 | 004,150,017 | R--- | M] () -- C:\Documents and Settings\Emma Nelder\Desktop\ComboFix.exe
[2011/01/07 17:00:01 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2011/01/07 14:31:27 | 000,000,801 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AnyBizSoft PDF to PowerPoint.lnk
[2011/01/07 14:19:11 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PDF to Word Converter.lnk
[2011/01/07 13:33:51 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\365.doc
[2011/01/06 16:53:26 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
[2011/01/05 14:02:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/04 10:25:25 | 000,303,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/04 10:21:49 | 000,000,049 | ---- | M] () -- C:\WINDOWS\kh7ptSJh
[2011/01/04 10:21:49 | 000,000,044 | ---- | M] () -- C:\WINDOWS\JJvvDR
[2011/01/04 10:21:49 | 000,000,043 | ---- | M] () -- C:\WINDOWS\YpDSJy
[2011/01/04 10:21:49 | 000,000,043 | ---- | M] () -- C:\WINDOWS\2Uk4Omx
[2011/01/04 10:21:49 | 000,000,042 | ---- | M] () -- C:\WINDOWS\nvCd6if3w
[2011/01/04 10:21:49 | 000,000,040 | ---- | M] () -- C:\WINDOWS\AdSXd
[2011/01/04 10:21:49 | 000,000,039 | ---- | M] () -- C:\WINDOWS\5G58LL14A
[2011/01/04 10:21:49 | 000,000,035 | ---- | M] () -- C:\WINDOWS\fITo5SKO
[2011/01/04 10:21:49 | 000,000,033 | ---- | M] () -- C:\WINDOWS\E78qDIH
[2011/01/04 10:21:49 | 000,000,032 | ---- | M] () -- C:\WINDOWS\OQ3G8wK
[2011/01/04 10:21:49 | 000,000,032 | ---- | M] () -- C:\WINDOWS\1DG6BCm
[2011/01/04 10:21:49 | 000,000,031 | ---- | M] () -- C:\WINDOWS\QD8HB
[2011/01/04 10:21:49 | 000,000,030 | ---- | M] () -- C:\WINDOWS\qDgOR
[2011/01/04 10:21:49 | 000,000,030 | ---- | M] () -- C:\WINDOWS\C62hiui
[2011/01/04 10:21:49 | 000,000,029 | ---- | M] () -- C:\WINDOWS\kBAie
[2011/01/04 10:21:49 | 000,000,028 | ---- | M] () -- C:\WINDOWS\u4XNSwghot
[2011/01/04 10:21:49 | 000,000,027 | ---- | M] () -- C:\WINDOWS\ruqvTxBnU
[2011/01/04 10:21:49 | 000,000,026 | ---- | M] () -- C:\WINDOWS\hUcwRlUJ
[2011/01/04 10:21:46 | 000,000,047 | ---- | M] () -- C:\WINDOWS\slVqcQews
[2011/01/04 10:21:46 | 000,000,046 | ---- | M] () -- C:\WINDOWS\IWwDT
[2011/01/04 10:21:46 | 000,000,045 | ---- | M] () -- C:\WINDOWS\fXxE7bT
[2011/01/04 10:21:46 | 000,000,045 | ---- | M] () -- C:\WINDOWS\8VDa7CXl
[2011/01/04 10:21:46 | 000,000,044 | ---- | M] () -- C:\WINDOWS\vQpJrTcBQF
[2011/01/04 10:21:46 | 000,000,041 | ---- | M] () -- C:\WINDOWS\Wrx6EWy5NX
[2011/01/04 10:21:46 | 000,000,041 | ---- | M] () -- C:\WINDOWS\NEjhJ
[2011/01/04 10:21:46 | 000,000,039 | ---- | M] () -- C:\WINDOWS\U3fOBPUBc
[2011/01/04 10:21:46 | 000,000,038 | ---- | M] () -- C:\WINDOWS\O5AtO
[2011/01/04 10:21:46 | 000,000,038 | ---- | M] () -- C:\WINDOWS\lolVp8E2Sq
[2011/01/04 10:21:46 | 000,000,037 | ---- | M] () -- C:\WINDOWS\i7JEeABY
[2011/01/04 10:21:46 | 000,000,037 | ---- | M] () -- C:\WINDOWS\22BMW7
[2011/01/04 10:21:46 | 000,000,036 | ---- | M] () -- C:\WINDOWS\IxigT
[2011/01/04 10:21:46 | 000,000,035 | ---- | M] () -- C:\WINDOWS\InU5UjE
[2011/01/04 10:21:46 | 000,000,035 | ---- | M] () -- C:\WINDOWS\4tqPC3lA
[2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\RehIFV
[2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\jwdbJS7
[2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\6JJRwDUT
[2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\QVVVN
[2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\myAcFSqAAJ
[2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\5nyf1fEa
[2011/01/04 10:21:46 | 000,000,031 | ---- | M] () -- C:\WINDOWS\63Cp1Oet
[2011/01/04 10:21:46 | 000,000,031 | ---- | M] () -- C:\WINDOWS\5Wa87L
[2011/01/04 10:21:46 | 000,000,029 | ---- | M] () -- C:\WINDOWS\XYOHDo
[2011/01/04 10:21:46 | 000,000,028 | ---- | M] () -- C:\WINDOWS\kipV83i
[2011/01/04 10:21:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\GJgrd
[2011/01/04 10:21:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\FgoHg
[2011/01/04 10:21:44 | 000,000,044 | ---- | M] () -- C:\WINDOWS\sNYXsj
[2011/01/04 10:21:44 | 000,000,037 | ---- | M] () -- C:\WINDOWS\7gLkamXCV
[2011/01/04 10:21:44 | 000,000,031 | ---- | M] () -- C:\WINDOWS\cG5Hstso
[2011/01/04 10:21:43 | 000,000,048 | ---- | M] () -- C:\WINDOWS\OyLaFpY
[2011/01/04 10:21:43 | 000,000,046 | ---- | M] () -- C:\WINDOWS\KG5olI
[2011/01/04 10:21:43 | 000,000,045 | ---- | M] () -- C:\WINDOWS\KSj8pJ
[2011/01/04 10:21:43 | 000,000,045 | ---- | M] () -- C:\WINDOWS\Jj7rN
[2011/01/04 10:21:43 | 000,000,042 | ---- | M] () -- C:\WINDOWS\3jKGcwC
[2011/01/04 10:21:43 | 000,000,041 | ---- | M] () -- C:\WINDOWS\LeHXF
[2011/01/04 10:21:43 | 000,000,040 | ---- | M] () -- C:\WINDOWS\v6OmO
[2011/01/04 10:21:43 | 000,000,040 | ---- | M] () -- C:\WINDOWS\egE75Sxs
[2011/01/04 10:21:43 | 000,000,039 | ---- | M] () -- C:\WINDOWS\OqM5GLT
[2011/01/04 10:21:43 | 000,000,038 | ---- | M] () -- C:\WINDOWS\VoTElV
[2011/01/04 10:21:43 | 000,000,036 | ---- | M] () -- C:\WINDOWS\NJUaq4
[2011/01/04 10:21:43 | 000,000,036 | ---- | M] () -- C:\WINDOWS\E1cotQ5ms
[2011/01/04 10:21:43 | 000,000,034 | ---- | M] () -- C:\WINDOWS\VAGuFigpQh
[2011/01/04 10:21:43 | 000,000,034 | ---- | M] () -- C:\WINDOWS\noxvIPvM8
[2011/01/04 10:21:43 | 000,000,033 | ---- | M] () -- C:\WINDOWS\y78eJvW
[2011/01/04 10:21:43 | 000,000,032 | ---- | M] () -- C:\WINDOWS\lBYMDKb
[2011/01/04 10:21:43 | 000,000,031 | ---- | M] () -- C:\WINDOWS\Lixec7
[2011/01/04 10:21:43 | 000,000,031 | ---- | M] () -- C:\WINDOWS\IKTrTG
[2011/01/04 10:21:43 | 000,000,030 | ---- | M] () -- C:\WINDOWS\nhj8qXLov
[2011/01/04 10:21:43 | 000,000,030 | ---- | M] () -- C:\WINDOWS\GnFLPKDtyK
[2011/01/04 10:21:43 | 000,000,029 | ---- | M] () -- C:\WINDOWS\APpT6oqFk
[2011/01/04 10:21:43 | 000,000,028 | ---- | M] () -- C:\WINDOWS\e6JaP
[2011/01/04 10:21:43 | 000,000,027 | ---- | M] () -- C:\WINDOWS\bVIeGoH
[2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\X2VUkW
[2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\otJuGY
[2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\3Pa3wiYfqd
[2011/01/04 10:21:41 | 000,000,044 | ---- | M] () -- C:\WINDOWS\VXIEcq
[2011/01/04 10:21:41 | 000,000,042 | ---- | M] () -- C:\WINDOWS\pfS2Um
[2011/01/04 10:21:41 | 000,000,040 | ---- | M] () -- C:\WINDOWS\Jtd8F
[2011/01/04 10:21:41 | 000,000,039 | ---- | M] () -- C:\WINDOWS\t8NAq
[2011/01/04 10:21:41 | 000,000,038 | ---- | M] () -- C:\WINDOWS\LmkGgkiF
[2011/01/04 10:21:41 | 000,000,037 | ---- | M] () -- C:\WINDOWS\gJhLQHw8
[2011/01/04 10:21:41 | 000,000,036 | ---- | M] () -- C:\WINDOWS\Tx7Wm3eg
[2011/01/04 10:21:41 | 000,000,036 | ---- | M] () -- C:\WINDOWS\NWGnE5
[2011/01/04 10:21:41 | 000,000,035 | ---- | M] () -- C:\WINDOWS\j5MHLUC
[2011/01/04 10:21:41 | 000,000,035 | ---- | M] () -- C:\WINDOWS\GCRklH23
[2011/01/04 10:21:41 | 000,000,034 | ---- | M] () -- C:\WINDOWS\xwgRvKN2dT
[2011/01/04 10:21:41 | 000,000,032 | ---- | M] () -- C:\WINDOWS\YmH1HIPww
[2011/01/04 10:21:41 | 000,000,032 | ---- | M] () -- C:\WINDOWS\awW5Ltxpf
[2011/01/04 10:21:41 | 000,000,031 | ---- | M] () -- C:\WINDOWS\thNrSB2V
[2011/01/04 10:21:41 | 000,000,031 | ---- | M] () -- C:\WINDOWS\EjLkeU
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\uH2whCXiG
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\lRvp8qsw
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\JfKDsowR
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\birbkGtK
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\ax8uM4r7LP
[2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\Usf1ElUGS
[2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\Fd5jCgjD
[2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\dUAU1UB
[2011/01/04 10:13:54 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/01/02 20:34:54 | 000,000,000 | ---- | M] () -- C:\WINDOWS\jx6b6bucz4x987sj87zgw63fxbs0qigk.ini
[2011/01/01 02:21:21 | 000,060,928 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/29 21:55:46 | 000,000,260 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2010/12/29 21:02:13 | 000,069,518 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\cc_20101229_210204.reg
[2010/12/29 19:40:27 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Wqesojudoya.dat
[2010/12/29 09:55:48 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Qmodehoko.bin
[2010/12/28 20:29:48 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/14 12:18:59 | 000,000,712 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\GHremoval.bat
[2010/12/12 04:32:01 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\Driver Robot.job
[2010/12/12 04:21:25 | 000,000,384 | ---- | M] () -- C:\WINDOWS\tasks\RegCure.job
[2010/12/10 15:19:25 | 000,680,288 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\System32\Doctor-Who-2010-Series.scr
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Emma Nelder\My Documents\*.tmp files -> C:\Documents and Settings\Emma Nelder\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/08 10:21:14 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/01/08 10:21:11 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/01/08 10:15:38 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/01/08 10:15:38 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/01/08 10:15:38 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/01/08 10:15:38 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/01/08 10:15:38 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/01/08 10:11:00 | 004,150,017 | R--- | C] () -- C:\Documents and Settings\Emma Nelder\Desktop\ComboFix.exe
[2011/01/07 14:31:27 | 000,000,801 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AnyBizSoft PDF to PowerPoint.lnk
[2011/01/07 14:19:09 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PDF to Word Converter.lnk
[2011/01/04 10:11:30 | 000,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/01/02 23:22:54 | 2137,456,640 | -HS- | C] () -- C:\hiberfil.sys
[2011/01/02 20:34:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\jx6b6bucz4x987sj87zgw63fxbs0qigk.ini
[2011/01/02 20:34:47 | 000,000,049 | ---- | C] () -- C:\WINDOWS\kh7ptSJh
[2011/01/02 20:34:47 | 000,000,048 | ---- | C] () -- C:\WINDOWS\OyLaFpY
[2011/01/02 20:34:47 | 000,000,047 | ---- | C] () -- C:\WINDOWS\slVqcQews
[2011/01/02 20:34:47 | 000,000,047 | ---- | C] () -- C:\WINDOWS\3Pa3wiYfqd
[2011/01/02 20:34:47 | 000,000,046 | ---- | C] () -- C:\WINDOWS\KG5olI
[2011/01/02 20:34:47 | 000,000,046 | ---- | C] () -- C:\WINDOWS\IWwDT
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\KSj8pJ
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\Jj7rN
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\fXxE7bT
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\8VDa7CXl
[2011/01/02 20:34:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\vQpJrTcBQF
[2011/01/02 20:34:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\sNYXsj
[2011/01/02 20:34:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\JJvvDR
[2011/01/02 20:34:47 | 000,000,043 | ---- | C] () -- C:\WINDOWS\YpDSJy
[2011/01/02 20:34:47 | 000,000,043 | ---- | C] () -- C:\WINDOWS\2Uk4Omx
[2011/01/02 20:34:47 | 000,000,042 | ---- | C] () -- C:\WINDOWS\nvCd6if3w
[2011/01/02 20:34:47 | 000,000,042 | ---- | C] () -- C:\WINDOWS\3jKGcwC
[2011/01/02 20:34:47 | 000,000,041 | ---- | C] () -- C:\WINDOWS\Wrx6EWy5NX
[2011/01/02 20:34:47 | 000,000,041 | ---- | C] () -- C:\WINDOWS\NEjhJ
[2011/01/02 20:34:47 | 000,000,041 | ---- | C] () -- C:\WINDOWS\LeHXF
[2011/01/02 20:34:47 | 000,000,040 | ---- | C] () -- C:\WINDOWS\v6OmO
[2011/01/02 20:34:47 | 000,000,040 | ---- | C] () -- C:\WINDOWS\egE75Sxs
[2011/01/02 20:34:47 | 000,000,040 | ---- | C] () -- C:\WINDOWS\AdSXd
[2011/01/02 20:34:47 | 000,000,039 | ---- | C] () -- C:\WINDOWS\U3fOBPUBc
[2011/01/02 20:34:47 | 000,000,039 | ---- | C] () -- C:\WINDOWS\OqM5GLT
[2011/01/02 20:34:47 | 000,000,039 | ---- | C] () -- C:\WINDOWS\5G58LL14A
[2011/01/02 20:34:47 | 000,000,038 | ---- | C] () -- C:\WINDOWS\VoTElV
[2011/01/02 20:34:47 | 000,000,038 | ---- | C] () -- C:\WINDOWS\O5AtO
[2011/01/02 20:34:47 | 000,000,038 | ---- | C] () -- C:\WINDOWS\lolVp8E2Sq
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\i7JEeABY
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\gJhLQHw8
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\7gLkamXCV
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\22BMW7
[2011/01/02 20:34:47 | 000,000,036 | ---- | C] () -- C:\WINDOWS\NJUaq4
[2011/01/02 20:34:47 | 000,000,036 | ---- | C] () -- C:\WINDOWS\IxigT
[2011/01/02 20:34:47 | 000,000,036 | ---- | C] () -- C:\WINDOWS\E1cotQ5ms
[2011/01/02 20:34:47 | 000,000,035 | ---- | C] () -- C:\WINDOWS\InU5UjE
[2011/01/02 20:34:47 | 000,000,035 | ---- | C] () -- C:\WINDOWS\fITo5SKO
[2011/01/02 20:34:47 | 000,000,035 | ---- | C] () -- C:\WINDOWS\4tqPC3lA
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\VAGuFigpQh
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\RehIFV
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\noxvIPvM8
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\jwdbJS7
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\6JJRwDUT
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\y78eJvW
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\QVVVN
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\myAcFSqAAJ
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\E78qDIH
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\5nyf1fEa
[2011/01/02 20:34:47 | 000,000,032 | ---- | C] () -- C:\WINDOWS\OQ3G8wK
[2011/01/02 20:34:47 | 000,000,032 | ---- | C] () -- C:\WINDOWS\lBYMDKb
[2011/01/02 20:34:47 | 000,000,032 | ---- | C] () -- C:\WINDOWS\1DG6BCm
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\QD8HB
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\Lixec7
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\IKTrTG
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\EjLkeU
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\cG5Hstso
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\63Cp1Oet
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\5Wa87L
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\qDgOR
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\nhj8qXLov
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\GnFLPKDtyK
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\C62hiui
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\XYOHDo
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\lRvp8qsw
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\kBAie
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\APpT6oqFk
[2011/01/02 20:34:47 | 000,000,028 | ---- | C] () -- C:\WINDOWS\u4XNSwghot
[2011/01/02 20:34:47 | 000,000,028 | ---- | C] () -- C:\WINDOWS\kipV83i
[2011/01/02 20:34:47 | 000,000,028 | ---- | C] () -- C:\WINDOWS\e6JaP
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\ruqvTxBnU
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\GJgrd
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\FgoHg
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\bVIeGoH
[2011/01/02 20:34:47 | 000,000,026 | ---- | C] () -- C:\WINDOWS\hUcwRlUJ
[2011/01/02 20:34:46 | 000,000,047 | ---- | C] () -- C:\WINDOWS\X2VUkW
[2011/01/02 20:34:46 | 000,000,047 | ---- | C] () -- C:\WINDOWS\otJuGY
[2011/01/02 20:34:46 | 000,000,044 | ---- | C] () -- C:\WINDOWS\VXIEcq
[2011/01/02 20:34:46 | 000,000,042 | ---- | C] () -- C:\WINDOWS\pfS2Um
[2011/01/02 20:34:46 | 000,000,040 | ---- | C] () -- C:\WINDOWS\Jtd8F
[2011/01/02 20:34:46 | 000,000,039 | ---- | C] () -- C:\WINDOWS\t8NAq
[2011/01/02 20:34:46 | 000,000,038 | ---- | C] () -- C:\WINDOWS\LmkGgkiF
[2011/01/02 20:34:46 | 000,000,036 | ---- | C] () -- C:\WINDOWS\Tx7Wm3eg
[2011/01/02 20:34:46 | 000,000,036 | ---- | C] () -- C:\WINDOWS\NWGnE5
[2011/01/02 20:34:46 | 000,000,035 | ---- | C] () -- C:\WINDOWS\j5MHLUC
[2011/01/02 20:34:46 | 000,000,035 | ---- | C] () -- C:\WINDOWS\GCRklH23
[2011/01/02 20:34:46 | 000,000,034 | ---- | C] () -- C:\WINDOWS\xwgRvKN2dT
[2011/01/02 20:34:46 | 000,000,032 | ---- | C] () -- C:\WINDOWS\YmH1HIPww
[2011/01/02 20:34:46 | 000,000,032 | ---- | C] () -- C:\WINDOWS\awW5Ltxpf
[2011/01/02 20:34:46 | 000,000,031 | ---- | C] () -- C:\WINDOWS\thNrSB2V
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\uH2whCXiG
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\JfKDsowR
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\birbkGtK
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\ax8uM4r7LP
[2011/01/02 20:34:46 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Usf1ElUGS
[2011/01/02 20:34:46 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Fd5jCgjD
[2011/01/02 20:34:46 | 000,000,028 | ---- | C] () -- C:\WINDOWS\dUAU1UB
[2010/12/29 21:02:09 | 000,069,518 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\My Documents\cc_20101229_210204.reg
[2010/12/14 12:19:08 | 000,000,712 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\My Documents\GHremoval.bat
[2010/05/18 03:01:12 | 001,634,304 | ---- | C] () -- C:\WINDOWS\System32\d-L-_2CD1_H.dll
[2010/04/28 16:41:04 | 000,001,112 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\VVcku64agTJJ
[2010/04/28 16:41:04 | 000,001,112 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\VVcku64agTJJ
[2010/04/23 08:15:24 | 000,001,444 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\Mi715R2
[2010/04/23 08:15:24 | 000,001,444 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\Mi715R2
[2010/04/16 08:36:28 | 000,016,316 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\018LBPw26q64R
[2010/04/16 08:36:28 | 000,016,316 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\018LBPw26q64R
[2010/04/12 22:34:57 | 000,015,054 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\V8i44CYn52
[2010/04/12 22:34:57 | 000,015,054 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\V8i44CYn52
[2010/03/05 17:18:25 | 000,004,562 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\2Y04MW11w
[2010/03/04 17:51:11 | 000,011,668 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\deQagCc75
[2010/01/31 12:55:45 | 000,000,030 | ---- | C] () -- C:\WINDOWS\WAR2R.INI
[2009/12/04 23:04:26 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/12/04 23:04:26 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/12/03 23:08:59 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/10/18 12:14:37 | 000,127,744 | ---- | C] () -- C:\WINDOWS\System32\drivers\ArcHlp.sys
[2009/10/15 21:11:05 | 000,000,173 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/10/02 15:20:51 | 000,019,639 | ---- | C] () -- C:\Program Files\Common Files\qysyno.dll
[2009/10/02 15:20:51 | 000,017,438 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\oludije.ban
[2009/10/02 15:20:51 | 000,014,531 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ycapymej.ban
[2009/10/02 15:20:51 | 000,013,680 | ---- | C] () -- C:\Program Files\Common Files\kumiceqa.com
[2009/09/25 14:07:40 | 000,000,728 | ---- | C] () -- C:\WINDOWS\{4507868A-A9CD-4ECC-BD54-0EAB6EE81D42}_WiseFW.ini
[2009/01/23 17:32:51 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/12/01 17:26:37 | 000,000,140 | -H-- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\lakerda1967.sys
[2008/12/01 17:26:17 | 000,010,584 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\docXConverter (3).ini
[2007/10/11 18:59:24 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/04 21:43:25 | 002,067,140 | R--- | C] () -- C:\WINDOWS\System32\avcodec.dll
[2006/12/28 15:38:46 | 000,042,594 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2006/10/01 13:53:02 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\606D16E445.sys
[2006/09/20 19:16:15 | 000,060,928 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/16 19:25:47 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\45E4166D60.sys
[2006/09/15 22:23:05 | 000,000,077 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\FASTWiz.log
[2006/09/15 22:21:15 | 000,000,748 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\wklnhst.dat
[2006/09/15 22:13:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/09/15 12:57:17 | 000,000,134 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\fusioncache.dat
[2006/09/15 11:55:42 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/09/11 15:57:31 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/09/11 15:44:50 | 000,712,704 | ---- | C] () -- C:\WINDOWS\System32\DellSystemRestore.dll
[2006/09/11 15:42:19 | 000,000,260 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/09/11 15:38:36 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/09/11 14:28:50 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2006/09/11 14:28:44 | 000,000,474 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/06/01 22:10:25 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/04/09 16:04:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 12:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[1999/01/22 18:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 08:00:00 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\REGOBJ.DLL

========== Alternate Data Streams ==========

@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
  • 0

#6
Emma&Pat

Emma&Pat

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
OTL logfile created on: 09/01/2011 11:21:22 - Run 2
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Emma Nelder\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 53.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 217.11 Gb Total Space | 69.60 Gb Free Space | 32.06% Space Free | Partition Type: NTFS
Drive D: | 12.55 Gb Total Space | 12.38 Gb Free Space | 98.66% Space Free | Partition Type: NTFS

Computer Name: EMMA | User Name: Emma Nelder | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
PRC - [2010/10/27 19:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/10/03 22:43:16 | 000,767,208 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2010/08/25 10:27:44 | 000,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010/08/13 17:51:04 | 000,030,192 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2010/04/16 18:36:42 | 000,026,480 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2010/04/16 07:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009/03/04 14:52:58 | 000,202,016 | R--- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprtsvc.exe
PRC - [2009/03/04 14:52:22 | 000,202,016 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprtcmd.exe
PRC - [2008/05/22 20:50:00 | 000,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
PRC - [2008/05/22 20:50:00 | 000,111,952 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2008/05/22 20:50:00 | 000,054,608 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
PRC - [2008/04/14 00:12:32 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\proquota.exe
PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/10/25 16:37:32 | 002,178,832 | ---- | M] () -- C:\Program Files\Logitech\QuickCam\Quickcam.exe
PRC - [2007/10/25 16:33:22 | 000,563,984 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2007/10/25 16:32:58 | 000,407,824 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2007/10/25 15:06:00 | 000,086,016 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\Mctray.exe
PRC - [2007/10/25 10:05:40 | 000,136,512 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2007/10/25 10:04:56 | 000,136,512 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2007/10/25 10:03:28 | 000,103,744 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2007/10/19 13:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2007/06/24 19:17:54 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007/04/13 16:20:22 | 000,097,432 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe
PRC - [2007/04/04 01:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2006/09/11 15:47:38 | 000,026,112 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\realplay.exe
PRC - [2006/07/16 20:29:54 | 000,389,120 | ---- | M] (Gteko Ltd.) -- C:\Program Files\Dell Support\DSAgnt.exe
PRC - [2006/04/06 13:57:54 | 000,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2006/03/24 22:30:44 | 000,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2005/06/10 09:44:02 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2005/02/23 14:57:24 | 000,057,344 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Mixer\CTSVolFE.exe
PRC - [2005/01/27 00:02:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2003/10/29 01:06:00 | 000,024,576 | ---- | M] (BVRP Software) -- C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2000/02/24 17:23:44 | 008,810,548 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office\WINWORD.EXE
PRC - [1998/12/16 21:09:20 | 000,057,393 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE


========== Modules (SafeList) ==========

MOD - [2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
MOD - [2010/08/23 16:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/03/04 14:52:40 | 000,116,000 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprthook.dll
MOD - [2008/04/14 00:12:01 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/10/03 22:43:16 | 000,767,208 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2010/08/13 17:51:04 | 000,030,192 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-051210-111108)
SRV - [2010/04/16 07:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/03/04 14:52:58 | 000,202,016 | R--- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\O2\bin\sprtsvc.exe -- (sprtsvc_O2) SupportSoft Sprocket Service (O2)
SRV - [2008/05/22 20:50:00 | 000,144,704 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe -- (McShield)
SRV - [2008/05/22 20:50:00 | 000,054,608 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
SRV - [2007/10/25 10:03:28 | 000,103,744 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2007/10/19 13:21:16 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2007/10/19 13:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2007/10/19 13:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)
SRV - [2007/07/27 05:39:32 | 000,382,320 | ---- | M] (SupportSoft, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2007/04/13 16:20:22 | 000,097,432 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2006/05/01 08:34:00 | 000,262,217 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER) Intel®
SRV - [2006/05/01 08:22:42 | 000,540,745 | ---- | M] (Intel Corporation ) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2006/05/01 08:20:52 | 000,114,753 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2006/05/01 08:20:26 | 000,217,164 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2006/04/06 13:57:54 | 000,380,928 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\wusoc.sys -- (qsryxq)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\PavSRK.sys -- (PavSRK.sys)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\ncyyvqao.sys -- (ilgecs)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\COMFiltr.sys -- (ComFiltr)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\EMMANE~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/10/03 22:54:04 | 000,034,792 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys -- (RapportCerberus_19917)
DRV - [2010/10/03 22:43:44 | 000,169,320 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2010/10/03 22:43:44 | 000,059,240 | ---- | M] (Trusteer Ltd.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2009/02/19 13:22:52 | 000,127,744 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ArcHlp.sys -- (archlp)
DRV - [2008/07/16 09:43:16 | 000,160,648 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\pctfw2.sys -- (pctfw2)
DRV - [2008/05/22 20:50:00 | 000,174,952 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2008/05/22 20:50:00 | 000,072,936 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2008/05/22 20:50:00 | 000,064,232 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2008/05/22 20:50:00 | 000,052,104 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2008/05/22 20:50:00 | 000,033,960 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2008/05/22 20:50:00 | 000,031,816 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys -- (mferkdk)
DRV - [2008/04/13 18:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 18:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 18:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 16:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/10/19 13:16:30 | 002,109,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007/10/11 18:59:24 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2007/10/11 18:59:02 | 002,142,488 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/05/11 03:10:50 | 000,034,704 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007/05/09 01:59:40 | 000,036,496 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007/03/05 06:00:04 | 000,027,792 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2007/03/05 05:59:04 | 000,018,320 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btnetdrv.sys -- (BT)
DRV - [2007/03/05 05:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2007/03/05 05:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - [2007/03/05 05:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2007/03/05 05:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2006/11/21 22:41:18 | 000,022,416 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Program Files\IVT Corporation\BlueSoleil\device\Win2k\BTNetFilter.sys -- (BTNetFilter)
DRV - [2006/11/10 19:48:02 | 000,040,352 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2006/11/10 19:43:16 | 000,933,536 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2006/11/10 19:43:16 | 000,013,344 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2006/09/11 15:47:41 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2006/05/01 08:52:02 | 000,013,568 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/04/26 22:13:04 | 001,429,632 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel®
DRV - [2006/03/24 22:34:30 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/03/08 17:35:10 | 000,191,872 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2006/01/10 11:07:58 | 000,004,864 | ---- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/10/14 14:40:18 | 000,307,968 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/10/14 14:40:18 | 000,051,328 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/10/14 14:40:18 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/08/30 17:59:00 | 000,094,000 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2005/08/30 17:58:56 | 000,008,304 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2005/08/30 17:57:18 | 000,058,320 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)
DRV - [2005/08/12 16:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/08/05 15:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/22 02:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 02:01:08 | 000,201,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/07/22 02:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/02/23 13:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2004/12/06 00:05:00 | 000,100,603 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudfa.sys -- (tfsnudfa)
DRV - [2004/12/06 00:05:00 | 000,098,714 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudf.sys -- (tfsnudf)
DRV - [2004/12/06 00:05:00 | 000,086,586 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnifs.sys -- (tfsnifs)
DRV - [2004/12/06 00:05:00 | 000,034,843 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsncofs.sys -- (tfsncofs)
DRV - [2004/12/06 00:05:00 | 000,025,883 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnboio.sys -- (tfsnboio)
DRV - [2004/12/06 00:05:00 | 000,015,227 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnopio.sys -- (tfsnopio)
DRV - [2004/12/06 00:05:00 | 000,006,363 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnpool.sys -- (tfsnpool)
DRV - [2004/12/06 00:05:00 | 000,004,123 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndrct.sys -- (tfsndrct)
DRV - [2004/12/06 00:05:00 | 000,002,239 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndres.sys -- (tfsndres)
DRV - [2004/12/01 02:22:00 | 000,087,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb)
DRV - [2004/11/23 01:56:00 | 000,040,480 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\drvnddm.sys -- (drvnddm)
DRV - [2004/08/03 21:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004/07/14 10:29:04 | 000,005,627 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\sscdbhk5.sys -- (sscdbhk5)
DRV - [2004/07/14 10:28:50 | 000,023,545 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\ssrtln.sys -- (ssrtln)
DRV - [2004/02/13 15:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
DRV - [2001/08/17 13:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 13:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 13:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 13:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 13:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 12:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 12:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 12:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 12:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 12:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 12:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 12:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 12:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 12:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 12:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074

========== FireFox ==========

FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..browser.startup.homepage: "http://flvdirect.iamwired.net/"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..keyword.URL: "http://flvdirect.iam...c=tops&search="
FF - prefs.js..keyword.enabled: true
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaulturl: "http://flvdirect.iam...c=tops&search="
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"


FF - HKLM\software\mozilla\Firefox\extensions\\{8779B4BC-1A5D-4E0E-B83B-171D20F2236D}: C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\{8779B4BC-1A5D-4E0E-B83B-171D20F2236D} [2010/07/27 07:18:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{387D07D6-5CF8-44EB-AECB-C4B4A82A9511}: C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\{387D07D6-5CF8-44EB-AECB-C4B4A82A9511}

[2010/05/20 16:24:03 | 000,000,266 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\Application Data\Mozilla\Firefox\Profiles\2w0v2hf2.default\searchplugins\Search.xml

O1 HOSTS File: ([2009/01/23 17:23:52 | 000,000,736 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1ed61cb2-86f5-82b1-b5d1-e81934c7bfbe} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [CTSVolFE.exe] C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [O2] C:\Program Files\O2\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnote...ad/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {1288683E-8FB1-46E3-AF62-9BB668505759} http://www.wireless....der_activex.ocx (xc_loader_activex.cntMain)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {17D667BA-5675-4AAB-9221-08B9379384D4} http://cdnimg.piczo....st_uploader.cab (Image Uploader Control)
O16 - DPF: {483912CF-8995-4434-AD61-6163756E05DF} http://download.live...tivex/AXTNS.ocx (AXTNS Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcaf...01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8EF9626B-2251-4C5E-BD17-D5F3E0E98B03} http://www.wireless....der_activex.ocx (xc_loader_activex.cntMain)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius....tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} http://www.tescophot...opcuploader.cab (Image Uploader 3.0 Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe\yhlgyfgg.exe) - C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe\yhlgyfgg.exe File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Emma Nelder\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Emma Nelder\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O29 - HKLM SecurityProviders - (mcmvxqyx.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/08 11:06:28 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/01/08 10:29:02 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\proquota.exe
[2011/01/08 10:29:02 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\proquota.exe
[2011/01/08 10:21:09 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/01/08 10:15:38 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/01/08 10:15:38 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/01/08 10:15:38 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/01/08 10:15:38 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/01/08 10:15:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/01/08 10:12:18 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/01/07 14:31:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\AnyBizSoft PDF to PowerPoint
[2011/01/07 14:31:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AnyBizSoft
[2011/01/07 14:31:20 | 000,000,000 | ---D | C] -- C:\Program Files\AnyBizSoft
[2011/01/07 14:22:07 | 000,000,000 | ---D | C] -- C:\Program Files\SomePDF
[2011/01/07 14:19:09 | 000,000,000 | ---D | C] -- C:\Program Files\AXPDF
[2011/01/07 14:19:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AXPDF
[2011/01/06 00:42:18 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
[2011/01/03 10:13:05 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/01/03 10:10:51 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2011/01/01 05:08:44 | 000,000,000 | ---D | C] -- C:\Program Files\ert
[2010/12/30 06:27:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Emma Nelder\Recent
[2010/12/25 21:58:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\My Received Files
[2010/12/25 19:46:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Loypfa
[2010/12/25 19:46:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Alpob
[2010/12/25 14:43:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Oxdy
[2010/12/25 14:43:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ivenny
[2010/12/25 09:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Erxoun
[2010/12/25 09:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Cyan
[2010/12/23 16:22:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Miuly
[2010/12/23 16:22:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Avtyib
[2010/12/22 17:31:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ibkyf
[2010/12/22 17:31:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Wiyh
[2010/12/21 15:21:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/12/21 15:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ylbu
[2010/12/21 15:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Onra
[2010/12/21 10:09:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Boepp
[2010/12/18 10:05:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Uropy
[2010/12/18 10:05:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Isgeat
[2010/12/16 21:55:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Uxaf
[2010/12/16 21:55:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Exci
[2010/12/16 21:26:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/12/14 23:58:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2010/12/14 21:28:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Umquxy
[2010/12/14 21:28:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Idxycy
[2010/12/14 09:48:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Edazg
[2010/12/13 22:22:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Yqaff
[2010/12/13 22:22:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ulneiw
[2010/12/13 13:04:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\Pictures - Digital Camera
[2010/12/13 09:29:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Duoh
[2010/12/12 10:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Myce
[2010/12/12 08:12:08 | 000,000,000 | ---D | C] -- C:\Program Files\qwers
[2010/12/12 00:38:22 | 000,000,000 | ---D | C] -- C:\Program Files\qwer
[2010/12/12 00:38:17 | 000,000,000 | ---D | C] -- C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe
[2010/12/10 15:19:25 | 000,680,288 | ---- | C] (ScreenTime Media) -- C:\WINDOWS\System32\Doctor-Who-2010-Series.scr
[2010/12/10 15:19:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Screentime
[2010/12/10 15:19:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\Screentime
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Emma Nelder\My Documents\*.tmp files -> C:\Documents and Settings\Emma Nelder\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/09 11:17:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/09 09:53:12 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{F0A36E4F-8866-4030-B42F-1A4DE747284D}.job
[2011/01/08 12:00:00 | 000,000,374 | ---- | M] () -- C:\WINDOWS\tasks\PerfectOptimizer_home.job
[2011/01/08 11:05:30 | 000,000,376 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Startup.job
[2011/01/08 10:55:43 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/08 10:55:39 | 000,000,292 | -H-- | M] () -- C:\WINDOWS\tasks\38480230.job
[2011/01/08 10:55:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/08 10:55:18 | 2137,456,640 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/08 10:21:14 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/01/08 10:11:00 | 004,150,017 | R--- | M] () -- C:\Documents and Settings\Emma Nelder\Desktop\ComboFix.exe
[2011/01/07 17:00:01 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2011/01/07 14:31:27 | 000,000,801 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AnyBizSoft PDF to PowerPoint.lnk
[2011/01/07 14:19:11 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PDF to Word Converter.lnk
[2011/01/07 13:33:51 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\365.doc
[2011/01/06 16:53:26 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
[2011/01/05 14:02:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/04 10:25:25 | 000,303,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/04 10:21:49 | 000,000,049 | ---- | M] () -- C:\WINDOWS\kh7ptSJh
[2011/01/04 10:21:49 | 000,000,044 | ---- | M] () -- C:\WINDOWS\JJvvDR
[2011/01/04 10:21:49 | 000,000,043 | ---- | M] () -- C:\WINDOWS\YpDSJy
[2011/01/04 10:21:49 | 000,000,043 | ---- | M] () -- C:\WINDOWS\2Uk4Omx
[2011/01/04 10:21:49 | 000,000,042 | ---- | M] () -- C:\WINDOWS\nvCd6if3w
[2011/01/04 10:21:49 | 000,000,040 | ---- | M] () -- C:\WINDOWS\AdSXd
[2011/01/04 10:21:49 | 000,000,039 | ---- | M] () -- C:\WINDOWS\5G58LL14A
[2011/01/04 10:21:49 | 000,000,035 | ---- | M] () -- C:\WINDOWS\fITo5SKO
[2011/01/04 10:21:49 | 000,000,033 | ---- | M] () -- C:\WINDOWS\E78qDIH
[2011/01/04 10:21:49 | 000,000,032 | ---- | M] () -- C:\WINDOWS\OQ3G8wK
[2011/01/04 10:21:49 | 000,000,032 | ---- | M] () -- C:\WINDOWS\1DG6BCm
[2011/01/04 10:21:49 | 000,000,031 | ---- | M] () -- C:\WINDOWS\QD8HB
[2011/01/04 10:21:49 | 000,000,030 | ---- | M] () -- C:\WINDOWS\qDgOR
[2011/01/04 10:21:49 | 000,000,030 | ---- | M] () -- C:\WINDOWS\C62hiui
[2011/01/04 10:21:49 | 000,000,029 | ---- | M] () -- C:\WINDOWS\kBAie
[2011/01/04 10:21:49 | 000,000,028 | ---- | M] () -- C:\WINDOWS\u4XNSwghot
[2011/01/04 10:21:49 | 000,000,027 | ---- | M] () -- C:\WINDOWS\ruqvTxBnU
[2011/01/04 10:21:49 | 000,000,026 | ---- | M] () -- C:\WINDOWS\hUcwRlUJ
[2011/01/04 10:21:46 | 000,000,047 | ---- | M] () -- C:\WINDOWS\slVqcQews
[2011/01/04 10:21:46 | 000,000,046 | ---- | M] () -- C:\WINDOWS\IWwDT
[2011/01/04 10:21:46 | 000,000,045 | ---- | M] () -- C:\WINDOWS\fXxE7bT
[2011/01/04 10:21:46 | 000,000,045 | ---- | M] () -- C:\WINDOWS\8VDa7CXl
[2011/01/04 10:21:46 | 000,000,044 | ---- | M] () -- C:\WINDOWS\vQpJrTcBQF
[2011/01/04 10:21:46 | 000,000,041 | ---- | M] () -- C:\WINDOWS\Wrx6EWy5NX
[2011/01/04 10:21:46 | 000,000,041 | ---- | M] () -- C:\WINDOWS\NEjhJ
[2011/01/04 10:21:46 | 000,000,039 | ---- | M] () -- C:\WINDOWS\U3fOBPUBc
[2011/01/04 10:21:46 | 000,000,038 | ---- | M] () -- C:\WINDOWS\O5AtO
[2011/01/04 10:21:46 | 000,000,038 | ---- | M] () -- C:\WINDOWS\lolVp8E2Sq
[2011/01/04 10:21:46 | 000,000,037 | ---- | M] () -- C:\WINDOWS\i7JEeABY
[2011/01/04 10:21:46 | 000,000,037 | ---- | M] () -- C:\WINDOWS\22BMW7
[2011/01/04 10:21:46 | 000,000,036 | ---- | M] () -- C:\WINDOWS\IxigT
[2011/01/04 10:21:46 | 000,000,035 | ---- | M] () -- C:\WINDOWS\InU5UjE
[2011/01/04 10:21:46 | 000,000,035 | ---- | M] () -- C:\WINDOWS\4tqPC3lA
[2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\RehIFV
[2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\jwdbJS7
[2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\6JJRwDUT
[2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\QVVVN
[2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\myAcFSqAAJ
[2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\5nyf1fEa
[2011/01/04 10:21:46 | 000,000,031 | ---- | M] () -- C:\WINDOWS\63Cp1Oet
[2011/01/04 10:21:46 | 000,000,031 | ---- | M] () -- C:\WINDOWS\5Wa87L
[2011/01/04 10:21:46 | 000,000,029 | ---- | M] () -- C:\WINDOWS\XYOHDo
[2011/01/04 10:21:46 | 000,000,028 | ---- | M] () -- C:\WINDOWS\kipV83i
[2011/01/04 10:21:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\GJgrd
[2011/01/04 10:21:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\FgoHg
[2011/01/04 10:21:44 | 000,000,044 | ---- | M] () -- C:\WINDOWS\sNYXsj
[2011/01/04 10:21:44 | 000,000,037 | ---- | M] () -- C:\WINDOWS\7gLkamXCV
[2011/01/04 10:21:44 | 000,000,031 | ---- | M] () -- C:\WINDOWS\cG5Hstso
[2011/01/04 10:21:43 | 000,000,048 | ---- | M] () -- C:\WINDOWS\OyLaFpY
[2011/01/04 10:21:43 | 000,000,046 | ---- | M] () -- C:\WINDOWS\KG5olI
[2011/01/04 10:21:43 | 000,000,045 | ---- | M] () -- C:\WINDOWS\KSj8pJ
[2011/01/04 10:21:43 | 000,000,045 | ---- | M] () -- C:\WINDOWS\Jj7rN
[2011/01/04 10:21:43 | 000,000,042 | ---- | M] () -- C:\WINDOWS\3jKGcwC
[2011/01/04 10:21:43 | 000,000,041 | ---- | M] () -- C:\WINDOWS\LeHXF
[2011/01/04 10:21:43 | 000,000,040 | ---- | M] () -- C:\WINDOWS\v6OmO
[2011/01/04 10:21:43 | 000,000,040 | ---- | M] () -- C:\WINDOWS\egE75Sxs
[2011/01/04 10:21:43 | 000,000,039 | ---- | M] () -- C:\WINDOWS\OqM5GLT
[2011/01/04 10:21:43 | 000,000,038 | ---- | M] () -- C:\WINDOWS\VoTElV
[2011/01/04 10:21:43 | 000,000,036 | ---- | M] () -- C:\WINDOWS\NJUaq4
[2011/01/04 10:21:43 | 000,000,036 | ---- | M] () -- C:\WINDOWS\E1cotQ5ms
[2011/01/04 10:21:43 | 000,000,034 | ---- | M] () -- C:\WINDOWS\VAGuFigpQh
[2011/01/04 10:21:43 | 000,000,034 | ---- | M] () -- C:\WINDOWS\noxvIPvM8
[2011/01/04 10:21:43 | 000,000,033 | ---- | M] () -- C:\WINDOWS\y78eJvW
[2011/01/04 10:21:43 | 000,000,032 | ---- | M] () -- C:\WINDOWS\lBYMDKb
[2011/01/04 10:21:43 | 000,000,031 | ---- | M] () -- C:\WINDOWS\Lixec7
[2011/01/04 10:21:43 | 000,000,031 | ---- | M] () -- C:\WINDOWS\IKTrTG
[2011/01/04 10:21:43 | 000,000,030 | ---- | M] () -- C:\WINDOWS\nhj8qXLov
[2011/01/04 10:21:43 | 000,000,030 | ---- | M] () -- C:\WINDOWS\GnFLPKDtyK
[2011/01/04 10:21:43 | 000,000,029 | ---- | M] () -- C:\WINDOWS\APpT6oqFk
[2011/01/04 10:21:43 | 000,000,028 | ---- | M] () -- C:\WINDOWS\e6JaP
[2011/01/04 10:21:43 | 000,000,027 | ---- | M] () -- C:\WINDOWS\bVIeGoH
[2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\X2VUkW
[2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\otJuGY
[2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\3Pa3wiYfqd
[2011/01/04 10:21:41 | 000,000,044 | ---- | M] () -- C:\WINDOWS\VXIEcq
[2011/01/04 10:21:41 | 000,000,042 | ---- | M] () -- C:\WINDOWS\pfS2Um
[2011/01/04 10:21:41 | 000,000,040 | ---- | M] () -- C:\WINDOWS\Jtd8F
[2011/01/04 10:21:41 | 000,000,039 | ---- | M] () -- C:\WINDOWS\t8NAq
[2011/01/04 10:21:41 | 000,000,038 | ---- | M] () -- C:\WINDOWS\LmkGgkiF
[2011/01/04 10:21:41 | 000,000,037 | ---- | M] () -- C:\WINDOWS\gJhLQHw8
[2011/01/04 10:21:41 | 000,000,036 | ---- | M] () -- C:\WINDOWS\Tx7Wm3eg
[2011/01/04 10:21:41 | 000,000,036 | ---- | M] () -- C:\WINDOWS\NWGnE5
[2011/01/04 10:21:41 | 000,000,035 | ---- | M] () -- C:\WINDOWS\j5MHLUC
[2011/01/04 10:21:41 | 000,000,035 | ---- | M] () -- C:\WINDOWS\GCRklH23
[2011/01/04 10:21:41 | 000,000,034 | ---- | M] () -- C:\WINDOWS\xwgRvKN2dT
[2011/01/04 10:21:41 | 000,000,032 | ---- | M] () -- C:\WINDOWS\YmH1HIPww
[2011/01/04 10:21:41 | 000,000,032 | ---- | M] () -- C:\WINDOWS\awW5Ltxpf
[2011/01/04 10:21:41 | 000,000,031 | ---- | M] () -- C:\WINDOWS\thNrSB2V
[2011/01/04 10:21:41 | 000,000,031 | ---- | M] () -- C:\WINDOWS\EjLkeU
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\uH2whCXiG
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\lRvp8qsw
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\JfKDsowR
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\birbkGtK
[2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\ax8uM4r7LP
[2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\Usf1ElUGS
[2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\Fd5jCgjD
[2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\dUAU1UB
[2011/01/04 10:13:54 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/01/02 20:34:54 | 000,000,000 | ---- | M] () -- C:\WINDOWS\jx6b6bucz4x987sj87zgw63fxbs0qigk.ini
[2011/01/01 02:21:21 | 000,060,928 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/29 21:55:46 | 000,000,260 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2010/12/29 21:02:13 | 000,069,518 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\cc_20101229_210204.reg
[2010/12/29 19:40:27 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Wqesojudoya.dat
[2010/12/29 09:55:48 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Qmodehoko.bin
[2010/12/28 20:29:48 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/14 12:18:59 | 000,000,712 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\GHremoval.bat
[2010/12/12 04:32:01 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\Driver Robot.job
[2010/12/12 04:21:25 | 000,000,384 | ---- | M] () -- C:\WINDOWS\tasks\RegCure.job
[2010/12/10 15:19:25 | 000,680,288 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\System32\Doctor-Who-2010-Series.scr
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Emma Nelder\My Documents\*.tmp files -> C:\Documents and Settings\Emma Nelder\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/08 10:21:14 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/01/08 10:21:11 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/01/08 10:15:38 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/01/08 10:15:38 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/01/08 10:15:38 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/01/08 10:15:38 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/01/08 10:15:38 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/01/08 10:11:00 | 004,150,017 | R--- | C] () -- C:\Documents and Settings\Emma Nelder\Desktop\ComboFix.exe
[2011/01/07 14:31:27 | 000,000,801 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AnyBizSoft PDF to PowerPoint.lnk
[2011/01/07 14:19:09 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PDF to Word Converter.lnk
[2011/01/04 10:11:30 | 000,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/01/02 23:22:54 | 2137,456,640 | -HS- | C] () -- C:\hiberfil.sys
[2011/01/02 20:34:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\jx6b6bucz4x987sj87zgw63fxbs0qigk.ini
[2011/01/02 20:34:47 | 000,000,049 | ---- | C] () -- C:\WINDOWS\kh7ptSJh
[2011/01/02 20:34:47 | 000,000,048 | ---- | C] () -- C:\WINDOWS\OyLaFpY
[2011/01/02 20:34:47 | 000,000,047 | ---- | C] () -- C:\WINDOWS\slVqcQews
[2011/01/02 20:34:47 | 000,000,047 | ---- | C] () -- C:\WINDOWS\3Pa3wiYfqd
[2011/01/02 20:34:47 | 000,000,046 | ---- | C] () -- C:\WINDOWS\KG5olI
[2011/01/02 20:34:47 | 000,000,046 | ---- | C] () -- C:\WINDOWS\IWwDT
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\KSj8pJ
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\Jj7rN
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\fXxE7bT
[2011/01/02 20:34:47 | 000,000,045 | ---- | C] () -- C:\WINDOWS\8VDa7CXl
[2011/01/02 20:34:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\vQpJrTcBQF
[2011/01/02 20:34:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\sNYXsj
[2011/01/02 20:34:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\JJvvDR
[2011/01/02 20:34:47 | 000,000,043 | ---- | C] () -- C:\WINDOWS\YpDSJy
[2011/01/02 20:34:47 | 000,000,043 | ---- | C] () -- C:\WINDOWS\2Uk4Omx
[2011/01/02 20:34:47 | 000,000,042 | ---- | C] () -- C:\WINDOWS\nvCd6if3w
[2011/01/02 20:34:47 | 000,000,042 | ---- | C] () -- C:\WINDOWS\3jKGcwC
[2011/01/02 20:34:47 | 000,000,041 | ---- | C] () -- C:\WINDOWS\Wrx6EWy5NX
[2011/01/02 20:34:47 | 000,000,041 | ---- | C] () -- C:\WINDOWS\NEjhJ
[2011/01/02 20:34:47 | 000,000,041 | ---- | C] () -- C:\WINDOWS\LeHXF
[2011/01/02 20:34:47 | 000,000,040 | ---- | C] () -- C:\WINDOWS\v6OmO
[2011/01/02 20:34:47 | 000,000,040 | ---- | C] () -- C:\WINDOWS\egE75Sxs
[2011/01/02 20:34:47 | 000,000,040 | ---- | C] () -- C:\WINDOWS\AdSXd
[2011/01/02 20:34:47 | 000,000,039 | ---- | C] () -- C:\WINDOWS\U3fOBPUBc
[2011/01/02 20:34:47 | 000,000,039 | ---- | C] () -- C:\WINDOWS\OqM5GLT
[2011/01/02 20:34:47 | 000,000,039 | ---- | C] () -- C:\WINDOWS\5G58LL14A
[2011/01/02 20:34:47 | 000,000,038 | ---- | C] () -- C:\WINDOWS\VoTElV
[2011/01/02 20:34:47 | 000,000,038 | ---- | C] () -- C:\WINDOWS\O5AtO
[2011/01/02 20:34:47 | 000,000,038 | ---- | C] () -- C:\WINDOWS\lolVp8E2Sq
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\i7JEeABY
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\gJhLQHw8
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\7gLkamXCV
[2011/01/02 20:34:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\22BMW7
[2011/01/02 20:34:47 | 000,000,036 | ---- | C] () -- C:\WINDOWS\NJUaq4
[2011/01/02 20:34:47 | 000,000,036 | ---- | C] () -- C:\WINDOWS\IxigT
[2011/01/02 20:34:47 | 000,000,036 | ---- | C] () -- C:\WINDOWS\E1cotQ5ms
[2011/01/02 20:34:47 | 000,000,035 | ---- | C] () -- C:\WINDOWS\InU5UjE
[2011/01/02 20:34:47 | 000,000,035 | ---- | C] () -- C:\WINDOWS\fITo5SKO
[2011/01/02 20:34:47 | 000,000,035 | ---- | C] () -- C:\WINDOWS\4tqPC3lA
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\VAGuFigpQh
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\RehIFV
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\noxvIPvM8
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\jwdbJS7
[2011/01/02 20:34:47 | 000,000,034 | ---- | C] () -- C:\WINDOWS\6JJRwDUT
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\y78eJvW
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\QVVVN
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\myAcFSqAAJ
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\E78qDIH
[2011/01/02 20:34:47 | 000,000,033 | ---- | C] () -- C:\WINDOWS\5nyf1fEa
[2011/01/02 20:34:47 | 000,000,032 | ---- | C] () -- C:\WINDOWS\OQ3G8wK
[2011/01/02 20:34:47 | 000,000,032 | ---- | C] () -- C:\WINDOWS\lBYMDKb
[2011/01/02 20:34:47 | 000,000,032 | ---- | C] () -- C:\WINDOWS\1DG6BCm
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\QD8HB
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\Lixec7
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\IKTrTG
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\EjLkeU
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\cG5Hstso
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\63Cp1Oet
[2011/01/02 20:34:47 | 000,000,031 | ---- | C] () -- C:\WINDOWS\5Wa87L
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\qDgOR
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\nhj8qXLov
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\GnFLPKDtyK
[2011/01/02 20:34:47 | 000,000,030 | ---- | C] () -- C:\WINDOWS\C62hiui
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\XYOHDo
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\lRvp8qsw
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\kBAie
[2011/01/02 20:34:47 | 000,000,029 | ---- | C] () -- C:\WINDOWS\APpT6oqFk
[2011/01/02 20:34:47 | 000,000,028 | ---- | C] () -- C:\WINDOWS\u4XNSwghot
[2011/01/02 20:34:47 | 000,000,028 | ---- | C] () -- C:\WINDOWS\kipV83i
[2011/01/02 20:34:47 | 000,000,028 | ---- | C] () -- C:\WINDOWS\e6JaP
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\ruqvTxBnU
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\GJgrd
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\FgoHg
[2011/01/02 20:34:47 | 000,000,027 | ---- | C] () -- C:\WINDOWS\bVIeGoH
[2011/01/02 20:34:47 | 000,000,026 | ---- | C] () -- C:\WINDOWS\hUcwRlUJ
[2011/01/02 20:34:46 | 000,000,047 | ---- | C] () -- C:\WINDOWS\X2VUkW
[2011/01/02 20:34:46 | 000,000,047 | ---- | C] () -- C:\WINDOWS\otJuGY
[2011/01/02 20:34:46 | 000,000,044 | ---- | C] () -- C:\WINDOWS\VXIEcq
[2011/01/02 20:34:46 | 000,000,042 | ---- | C] () -- C:\WINDOWS\pfS2Um
[2011/01/02 20:34:46 | 000,000,040 | ---- | C] () -- C:\WINDOWS\Jtd8F
[2011/01/02 20:34:46 | 000,000,039 | ---- | C] () -- C:\WINDOWS\t8NAq
[2011/01/02 20:34:46 | 000,000,038 | ---- | C] () -- C:\WINDOWS\LmkGgkiF
[2011/01/02 20:34:46 | 000,000,036 | ---- | C] () -- C:\WINDOWS\Tx7Wm3eg
[2011/01/02 20:34:46 | 000,000,036 | ---- | C] () -- C:\WINDOWS\NWGnE5
[2011/01/02 20:34:46 | 000,000,035 | ---- | C] () -- C:\WINDOWS\j5MHLUC
[2011/01/02 20:34:46 | 000,000,035 | ---- | C] () -- C:\WINDOWS\GCRklH23
[2011/01/02 20:34:46 | 000,000,034 | ---- | C] () -- C:\WINDOWS\xwgRvKN2dT
[2011/01/02 20:34:46 | 000,000,032 | ---- | C] () -- C:\WINDOWS\YmH1HIPww
[2011/01/02 20:34:46 | 000,000,032 | ---- | C] () -- C:\WINDOWS\awW5Ltxpf
[2011/01/02 20:34:46 | 000,000,031 | ---- | C] () -- C:\WINDOWS\thNrSB2V
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\uH2whCXiG
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\JfKDsowR
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\birbkGtK
[2011/01/02 20:34:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\ax8uM4r7LP
[2011/01/02 20:34:46 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Usf1ElUGS
[2011/01/02 20:34:46 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Fd5jCgjD
[2011/01/02 20:34:46 | 000,000,028 | ---- | C] () -- C:\WINDOWS\dUAU1UB
[2010/12/29 21:02:09 | 000,069,518 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\My Documents\cc_20101229_210204.reg
[2010/12/14 12:19:08 | 000,000,712 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\My Documents\GHremoval.bat
[2010/05/18 03:01:12 | 001,634,304 | ---- | C] () -- C:\WINDOWS\System32\d-L-_2CD1_H.dll
[2010/04/28 16:41:04 | 000,001,112 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\VVcku64agTJJ
[2010/04/28 16:41:04 | 000,001,112 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\VVcku64agTJJ
[2010/04/23 08:15:24 | 000,001,444 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\Mi715R2
[2010/04/23 08:15:24 | 000,001,444 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\Mi715R2
[2010/04/16 08:36:28 | 000,016,316 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\018LBPw26q64R
[2010/04/16 08:36:28 | 000,016,316 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\018LBPw26q64R
[2010/04/12 22:34:57 | 000,015,054 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\V8i44CYn52
[2010/04/12 22:34:57 | 000,015,054 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\V8i44CYn52
[2010/03/05 17:18:25 | 000,004,562 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\2Y04MW11w
[2010/03/04 17:51:11 | 000,011,668 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\deQagCc75
[2010/01/31 12:55:45 | 000,000,030 | ---- | C] () -- C:\WINDOWS\WAR2R.INI
[2009/12/04 23:04:26 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/12/04 23:04:26 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/12/03 23:08:59 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/10/18 12:14:37 | 000,127,744 | ---- | C] () -- C:\WINDOWS\System32\drivers\ArcHlp.sys
[2009/10/15 21:11:05 | 000,000,173 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/10/02 15:20:51 | 000,019,639 | ---- | C] () -- C:\Program Files\Common Files\qysyno.dll
[2009/10/02 15:20:51 | 000,017,438 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\oludije.ban
[2009/10/02 15:20:51 | 000,014,531 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ycapymej.ban
[2009/10/02 15:20:51 | 000,013,680 | ---- | C] () -- C:\Program Files\Common Files\kumiceqa.com
[2009/09/25 14:07:40 | 000,000,728 | ---- | C] () -- C:\WINDOWS\{4507868A-A9CD-4ECC-BD54-0EAB6EE81D42}_WiseFW.ini
[2009/01/23 17:32:51 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/12/01 17:26:37 | 000,000,140 | -H-- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\lakerda1967.sys
[2008/12/01 17:26:17 | 000,010,584 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\docXConverter (3).ini
[2007/10/11 18:59:24 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/04 21:43:25 | 002,067,140 | R--- | C] () -- C:\WINDOWS\System32\avcodec.dll
[2006/12/28 15:38:46 | 000,042,594 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2006/10/01 13:53:02 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\606D16E445.sys
[2006/09/20 19:16:15 | 000,060,928 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/16 19:25:47 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\45E4166D60.sys
[2006/09/15 22:23:05 | 000,000,077 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\FASTWiz.log
[2006/09/15 22:21:15 | 000,000,748 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\wklnhst.dat
[2006/09/15 22:13:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/09/15 12:57:17 | 000,000,134 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\fusioncache.dat
[2006/09/15 11:55:42 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/09/11 15:57:31 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/09/11 15:44:50 | 000,712,704 | ---- | C] () -- C:\WINDOWS\System32\DellSystemRestore.dll
[2006/09/11 15:42:19 | 000,000,260 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/09/11 15:38:36 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/09/11 14:28:50 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2006/09/11 14:28:44 | 000,000,474 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/06/01 22:10:25 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/04/09 16:04:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 12:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[1999/01/22 18:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 08:00:00 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\REGOBJ.DLL

========== Alternate Data Streams ==========

@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
  • 0

#7
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\wusoc.sys -- (qsryxq)
    DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\ncyyvqao.sys -- (ilgecs)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {1ed61cb2-86f5-82b1-b5d1-e81934c7bfbe} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O20 - HKLM Winlogon: UserInit - (C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe\yhlgyfgg.exe) - C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe\yhlgyfgg.exe File not found
    O29 - HKLM SecurityProviders - (mcmvxqyx.dll) - File not found
    [2011/01/01 05:08:44 | 000,000,000 | ---D | C] -- C:\Program Files\ert
    [2010/12/25 19:46:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Loypfa
    [2010/12/25 19:46:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Alpob
    [2010/12/25 14:43:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Oxdy
    [2010/12/25 14:43:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ivenny
    [2010/12/25 09:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Erxoun
    [2010/12/25 09:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Cyan
    [2010/12/23 16:22:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Miuly
    [2010/12/23 16:22:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Avtyib
    [2010/12/22 17:31:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ibkyf
    [2010/12/22 17:31:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Wiyh
    [2010/12/21 15:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ylbu
    [2010/12/21 15:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Onra
    [2010/12/21 10:09:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Boepp
    [2010/12/18 10:05:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Uropy
    [2010/12/18 10:05:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Isgeat
    [2010/12/16 21:55:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Uxaf
    [2010/12/16 21:55:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Exci
    [2010/12/14 21:28:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Umquxy
    [2010/12/14 21:28:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Idxycy
    [2010/12/14 09:48:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Edazg
    [2010/12/13 22:22:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Yqaff
    [2010/12/13 22:22:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Ulneiw
    [2010/12/13 09:29:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Duoh
    [2010/12/12 10:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\Application Data\Myce
    [2010/12/12 08:12:08 | 000,000,000 | ---D | C] -- C:\Program Files\qwers
    [2010/12/12 00:38:22 | 000,000,000 | ---D | C] -- C:\Program Files\qwer
    [2010/12/12 00:38:17 | 000,000,000 | ---D | C] -- C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe
    [2011/01/08 10:55:39 | 000,000,292 | -H-- | M] () -- C:\WINDOWS\tasks\38480230.job
    [2011/01/04 10:21:49 | 000,000,049 | ---- | M] () -- C:\WINDOWS\kh7ptSJh
    [2011/01/04 10:21:49 | 000,000,044 | ---- | M] () -- C:\WINDOWS\JJvvDR
    [2011/01/04 10:21:49 | 000,000,043 | ---- | M] () -- C:\WINDOWS\YpDSJy
    [2011/01/04 10:21:49 | 000,000,043 | ---- | M] () -- C:\WINDOWS\2Uk4Omx
    [2011/01/04 10:21:49 | 000,000,042 | ---- | M] () -- C:\WINDOWS\nvCd6if3w
    [2011/01/04 10:21:49 | 000,000,040 | ---- | M] () -- C:\WINDOWS\AdSXd
    [2011/01/04 10:21:49 | 000,000,039 | ---- | M] () -- C:\WINDOWS\5G58LL14A
    [2011/01/04 10:21:49 | 000,000,035 | ---- | M] () -- C:\WINDOWS\fITo5SKO
    [2011/01/04 10:21:49 | 000,000,033 | ---- | M] () -- C:\WINDOWS\E78qDIH
    [2011/01/04 10:21:49 | 000,000,032 | ---- | M] () -- C:\WINDOWS\OQ3G8wK
    [2011/01/04 10:21:49 | 000,000,032 | ---- | M] () -- C:\WINDOWS\1DG6BCm
    [2011/01/04 10:21:49 | 000,000,031 | ---- | M] () -- C:\WINDOWS\QD8HB
    [2011/01/04 10:21:49 | 000,000,030 | ---- | M] () -- C:\WINDOWS\qDgOR
    [2011/01/04 10:21:49 | 000,000,030 | ---- | M] () -- C:\WINDOWS\C62hiui
    [2011/01/04 10:21:49 | 000,000,029 | ---- | M] () -- C:\WINDOWS\kBAie
    [2011/01/04 10:21:49 | 000,000,028 | ---- | M] () -- C:\WINDOWS\u4XNSwghot
    [2011/01/04 10:21:49 | 000,000,027 | ---- | M] () -- C:\WINDOWS\ruqvTxBnU
    [2011/01/04 10:21:49 | 000,000,026 | ---- | M] () -- C:\WINDOWS\hUcwRlUJ
    [2011/01/04 10:21:46 | 000,000,047 | ---- | M] () -- C:\WINDOWS\slVqcQews
    [2011/01/04 10:21:46 | 000,000,046 | ---- | M] () -- C:\WINDOWS\IWwDT
    [2011/01/04 10:21:46 | 000,000,045 | ---- | M] () -- C:\WINDOWS\fXxE7bT
    [2011/01/04 10:21:46 | 000,000,045 | ---- | M] () -- C:\WINDOWS\8VDa7CXl
    [2011/01/04 10:21:46 | 000,000,044 | ---- | M] () -- C:\WINDOWS\vQpJrTcBQF
    [2011/01/04 10:21:46 | 000,000,041 | ---- | M] () -- C:\WINDOWS\Wrx6EWy5NX
    [2011/01/04 10:21:46 | 000,000,041 | ---- | M] () -- C:\WINDOWS\NEjhJ
    [2011/01/04 10:21:46 | 000,000,039 | ---- | M] () -- C:\WINDOWS\U3fOBPUBc
    [2011/01/04 10:21:46 | 000,000,038 | ---- | M] () -- C:\WINDOWS\O5AtO
    [2011/01/04 10:21:46 | 000,000,038 | ---- | M] () -- C:\WINDOWS\lolVp8E2Sq
    [2011/01/04 10:21:46 | 000,000,037 | ---- | M] () -- C:\WINDOWS\i7JEeABY
    [2011/01/04 10:21:46 | 000,000,037 | ---- | M] () -- C:\WINDOWS\22BMW7
    [2011/01/04 10:21:46 | 000,000,036 | ---- | M] () -- C:\WINDOWS\IxigT
    [2011/01/04 10:21:46 | 000,000,035 | ---- | M] () -- C:\WINDOWS\InU5UjE
    [2011/01/04 10:21:46 | 000,000,035 | ---- | M] () -- C:\WINDOWS\4tqPC3lA
    [2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\RehIFV
    [2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\jwdbJS7
    [2011/01/04 10:21:46 | 000,000,034 | ---- | M] () -- C:\WINDOWS\6JJRwDUT
    [2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\QVVVN
    [2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\myAcFSqAAJ
    [2011/01/04 10:21:46 | 000,000,033 | ---- | M] () -- C:\WINDOWS\5nyf1fEa
    [2011/01/04 10:21:46 | 000,000,031 | ---- | M] () -- C:\WINDOWS\63Cp1Oet
    [2011/01/04 10:21:46 | 000,000,031 | ---- | M] () -- C:\WINDOWS\5Wa87L
    [2011/01/04 10:21:46 | 000,000,029 | ---- | M] () -- C:\WINDOWS\XYOHDo
    [2011/01/04 10:21:46 | 000,000,028 | ---- | M] () -- C:\WINDOWS\kipV83i
    [2011/01/04 10:21:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\GJgrd
    [2011/01/04 10:21:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\FgoHg
    [2011/01/04 10:21:44 | 000,000,044 | ---- | M] () -- C:\WINDOWS\sNYXsj
    [2011/01/04 10:21:44 | 000,000,037 | ---- | M] () -- C:\WINDOWS\7gLkamXCV
    [2011/01/04 10:21:44 | 000,000,031 | ---- | M] () -- C:\WINDOWS\cG5Hstso
    [2011/01/04 10:21:43 | 000,000,048 | ---- | M] () -- C:\WINDOWS\OyLaFpY
    [2011/01/04 10:21:43 | 000,000,046 | ---- | M] () -- C:\WINDOWS\KG5olI
    [2011/01/04 10:21:43 | 000,000,045 | ---- | M] () -- C:\WINDOWS\KSj8pJ
    [2011/01/04 10:21:43 | 000,000,045 | ---- | M] () -- C:\WINDOWS\Jj7rN
    [2011/01/04 10:21:43 | 000,000,042 | ---- | M] () -- C:\WINDOWS\3jKGcwC
    [2011/01/04 10:21:43 | 000,000,041 | ---- | M] () -- C:\WINDOWS\LeHXF
    [2011/01/04 10:21:43 | 000,000,040 | ---- | M] () -- C:\WINDOWS\v6OmO
    [2011/01/04 10:21:43 | 000,000,040 | ---- | M] () -- C:\WINDOWS\egE75Sxs
    [2011/01/04 10:21:43 | 000,000,039 | ---- | M] () -- C:\WINDOWS\OqM5GLT
    [2011/01/04 10:21:43 | 000,000,038 | ---- | M] () -- C:\WINDOWS\VoTElV
    [2011/01/04 10:21:43 | 000,000,036 | ---- | M] () -- C:\WINDOWS\NJUaq4
    [2011/01/04 10:21:43 | 000,000,036 | ---- | M] () -- C:\WINDOWS\E1cotQ5ms
    [2011/01/04 10:21:43 | 000,000,034 | ---- | M] () -- C:\WINDOWS\VAGuFigpQh
    [2011/01/04 10:21:43 | 000,000,034 | ---- | M] () -- C:\WINDOWS\noxvIPvM8
    [2011/01/04 10:21:43 | 000,000,033 | ---- | M] () -- C:\WINDOWS\y78eJvW
    [2011/01/04 10:21:43 | 000,000,032 | ---- | M] () -- C:\WINDOWS\lBYMDKb
    [2011/01/04 10:21:43 | 000,000,031 | ---- | M] () -- C:\WINDOWS\Lixec7
    [2011/01/04 10:21:43 | 000,000,031 | ---- | M] () -- C:\WINDOWS\IKTrTG
    [2011/01/04 10:21:43 | 000,000,030 | ---- | M] () -- C:\WINDOWS\nhj8qXLov
    [2011/01/04 10:21:43 | 000,000,030 | ---- | M] () -- C:\WINDOWS\GnFLPKDtyK
    [2011/01/04 10:21:43 | 000,000,029 | ---- | M] () -- C:\WINDOWS\APpT6oqFk
    [2011/01/04 10:21:43 | 000,000,028 | ---- | M] () -- C:\WINDOWS\e6JaP
    [2011/01/04 10:21:43 | 000,000,027 | ---- | M] () -- C:\WINDOWS\bVIeGoH
    [2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\X2VUkW
    [2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\otJuGY
    [2011/01/04 10:21:41 | 000,000,047 | ---- | M] () -- C:\WINDOWS\3Pa3wiYfqd
    [2011/01/04 10:21:41 | 000,000,044 | ---- | M] () -- C:\WINDOWS\VXIEcq
    [2011/01/04 10:21:41 | 000,000,042 | ---- | M] () -- C:\WINDOWS\pfS2Um
    [2011/01/04 10:21:41 | 000,000,040 | ---- | M] () -- C:\WINDOWS\Jtd8F
    [2011/01/04 10:21:41 | 000,000,039 | ---- | M] () -- C:\WINDOWS\t8NAq
    [2011/01/04 10:21:41 | 000,000,038 | ---- | M] () -- C:\WINDOWS\LmkGgkiF
    [2011/01/04 10:21:41 | 000,000,037 | ---- | M] () -- C:\WINDOWS\gJhLQHw8
    [2011/01/04 10:21:41 | 000,000,036 | ---- | M] () -- C:\WINDOWS\Tx7Wm3eg
    [2011/01/04 10:21:41 | 000,000,036 | ---- | M] () -- C:\WINDOWS\NWGnE5
    [2011/01/04 10:21:41 | 000,000,035 | ---- | M] () -- C:\WINDOWS\j5MHLUC
    [2011/01/04 10:21:41 | 000,000,035 | ---- | M] () -- C:\WINDOWS\GCRklH23
    [2011/01/04 10:21:41 | 000,000,034 | ---- | M] () -- C:\WINDOWS\xwgRvKN2dT
    [2011/01/04 10:21:41 | 000,000,032 | ---- | M] () -- C:\WINDOWS\YmH1HIPww
    [2011/01/04 10:21:41 | 000,000,032 | ---- | M] () -- C:\WINDOWS\awW5Ltxpf
    [2011/01/04 10:21:41 | 000,000,031 | ---- | M] () -- C:\WINDOWS\thNrSB2V
    [2011/01/04 10:21:41 | 000,000,031 | ---- | M] () -- C:\WINDOWS\EjLkeU
    [2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\uH2whCXiG
    [2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\lRvp8qsw
    [2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\JfKDsowR
    [2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\birbkGtK
    [2011/01/04 10:21:41 | 000,000,029 | ---- | M] () -- C:\WINDOWS\ax8uM4r7LP
    [2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\Usf1ElUGS
    [2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\Fd5jCgjD
    [2011/01/04 10:21:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\dUAU1UB
    [2011/01/04 10:13:54 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2011/01/02 20:34:54 | 000,000,000 | ---- | M] () -- C:\WINDOWS\jx6b6bucz4x987sj87zgw63fxbs0qigk.ini
    [2010/12/29 19:40:27 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Wqesojudoya.dat
    [2010/12/29 09:55:48 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Qmodehoko.bin
    [2009/10/02 15:20:51 | 000,019,639 | ---- | C] () -- C:\Program Files\Common Files\qysyno.dll
    
    :Commands
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.
================================Malwarebytes' Anti-Malware=================================
Please update\run Malwarebytes' Anti-Malware.

Double Click the Malwarebytes Anti-Malware icon to run the application.
  • Click on the update tab then click on Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the update has loaded, go to the Scanner tab and select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley.
================================Follow up scan=================================
Please click here to download Kaspersky Virus Removal Tool.

  • Double click on the file you just downloaded and let it install.
  • It will install to your desktop.
  • After that leave what is selected and put a check next to My Computer.
  • Click on the option that says Threat Detection and change it to Disinfect,delete if disinfection fails.
  • Then click on Start Scan.
  • Before it is done it may prompt for action regardless of the setting so choose delete if prompted.
  • When the scan is done no log will be produced.
  • Click on the bottom where it says Report to open the report.
  • Then highlight of of the items found by using ctrl + a on your keyboard to select all or use your mouse to select all then right click and choose copy.
  • This will copy the items that it found to the clipboard you can then open notepad (go to start then run then type in notepad) and choose paste to paste the contents into Notepad.
  • You can save this on the desktop.
  • Post the contents of the document in your next reply.

Note: This tool will self uninstall when you close it so please save the log before closing it.


  • 0

#8
Emma&Pat

Emma&Pat

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
OTL Log:
Autoscan: completed 8 minutes ago (events: 79, objects: 204201, time: 02:45:27)
10/01/2011 00:28:07 Task started
10/01/2011 00:33:31 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\aluq.exe
10/01/2011 08:42:34 Task stopped
10/01/2011 08:59:23 Task started
10/01/2011 09:06:43 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\povura.exe
10/01/2011 09:06:43 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\sayz.exe
10/01/2011 09:06:43 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\egicup.exe
10/01/2011 09:07:12 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\povura.exe
10/01/2011 09:07:13 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\egicup.exe
10/01/2011 09:07:14 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\sayz.exe
10/01/2011 11:17:05 Detected: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Egewop\yfoz.exe.vir
10/01/2011 11:17:05 Detected: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Kazyu\ilhu.exe.vir
10/01/2011 11:17:05 Detected: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Duegid\haebe.exe.vir
10/01/2011 11:17:55 Deleted: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Egewop\yfoz.exe.vir
10/01/2011 11:17:57 Detected: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Ungod\gouk.exe.vir
10/01/2011 11:17:58 Deleted: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Duegid\haebe.exe.vir
10/01/2011 11:18:00 Deleted: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Kazyu\ilhu.exe.vir
10/01/2011 11:18:02 Deleted: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Ungod\gouk.exe.vir
10/01/2011 11:19:52 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000101.exe
10/01/2011 11:20:01 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000102.exe
10/01/2011 11:20:06 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000102.exe
10/01/2011 11:20:07 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000103.exe
10/01/2011 11:20:08 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000101.exe
10/01/2011 11:20:09 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000106.exe
10/01/2011 11:20:11 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000103.exe
10/01/2011 11:20:13 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000106.exe
10/01/2011 11:20:52 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000265.exe
10/01/2011 11:20:53 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000266.exe
10/01/2011 11:20:53 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000267.exe
10/01/2011 11:20:53 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000265.exe
10/01/2011 11:20:54 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000266.exe
10/01/2011 11:20:54 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000291.exe
10/01/2011 11:20:54 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000290.exe
10/01/2011 11:20:55 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000267.exe
10/01/2011 11:20:55 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000292.exe
10/01/2011 11:20:56 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000290.exe
10/01/2011 11:20:56 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000291.exe
10/01/2011 11:20:58 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000292.exe
10/01/2011 11:39:47 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:55 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:55 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:01 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:01 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:01 Deleted: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:44:51 Task completed
Disinfect active threats: completed 3 hours ago (events: 10, objects: 5987, time: 00:05:32)
10/01/2011 08:42:34 Task started
10/01/2011 08:42:34 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\aluq.exe
10/01/2011 08:43:25 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\aluq.exe
10/01/2011 08:47:20 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\elryh.exe
10/01/2011 08:47:24 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\elryh.exe
10/01/2011 08:47:24 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\elryh.exe
10/01/2011 08:47:25 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\sariv.exe
10/01/2011 08:47:28 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\sariv.exe
10/01/2011 08:47:28 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\sariv.exe
10/01/2011 08:48:06 Task completed


Malwarebytes log:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5488

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

09/01/2011 17:27:37
mbam-log-2011-01-09 (17-27-37).txt

Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 250115
Time elapsed: 1 hour(s), 51 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\qni8hj710fdl (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Kaspersky Log:
Autoscan: completed 8 minutes ago (events: 79, objects: 204201, time: 02:45:27)
10/01/2011 00:28:07 Task started
10/01/2011 00:33:31 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\aluq.exe
10/01/2011 08:42:34 Task stopped
10/01/2011 08:59:23 Task started
10/01/2011 09:06:43 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\povura.exe
10/01/2011 09:06:43 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\sayz.exe
10/01/2011 09:06:43 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\egicup.exe
10/01/2011 09:07:12 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\povura.exe
10/01/2011 09:07:13 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\egicup.exe
10/01/2011 09:07:14 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Default User\Start Menu\Programs\Startup\sayz.exe
10/01/2011 11:17:05 Detected: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Egewop\yfoz.exe.vir
10/01/2011 11:17:05 Detected: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Kazyu\ilhu.exe.vir
10/01/2011 11:17:05 Detected: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Duegid\haebe.exe.vir
10/01/2011 11:17:55 Deleted: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Egewop\yfoz.exe.vir
10/01/2011 11:17:57 Detected: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Ungod\gouk.exe.vir
10/01/2011 11:17:58 Deleted: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Duegid\haebe.exe.vir
10/01/2011 11:18:00 Deleted: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Kazyu\ilhu.exe.vir
10/01/2011 11:18:02 Deleted: Packed.Win32.Krap.ar C:\Qoobox\Quarantine\C\Documents and Settings\Emma Nelder\Application Data\Ungod\gouk.exe.vir
10/01/2011 11:19:52 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000101.exe
10/01/2011 11:20:01 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000102.exe
10/01/2011 11:20:06 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000102.exe
10/01/2011 11:20:07 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000103.exe
10/01/2011 11:20:08 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000101.exe
10/01/2011 11:20:09 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000106.exe
10/01/2011 11:20:11 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000103.exe
10/01/2011 11:20:13 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000106.exe
10/01/2011 11:20:52 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000265.exe
10/01/2011 11:20:53 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000266.exe
10/01/2011 11:20:53 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000267.exe
10/01/2011 11:20:53 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000265.exe
10/01/2011 11:20:54 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000266.exe
10/01/2011 11:20:54 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000291.exe
10/01/2011 11:20:54 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000290.exe
10/01/2011 11:20:55 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000267.exe
10/01/2011 11:20:55 Detected: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000292.exe
10/01/2011 11:20:56 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000290.exe
10/01/2011 11:20:56 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000291.exe
10/01/2011 11:20:58 Deleted: Packed.Win32.Krap.ar C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000292.exe
10/01/2011 11:39:47 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:55 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:55 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:56 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:57 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:58 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:40:59 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:00 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:01 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:01 Detected: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:41:01 Deleted: not-a-virus:AdWare.Win32.EZula.heur C:\WINDOWS\system32\d-L-_2CD1_H.dll
10/01/2011 11:44:51 Task completed
Disinfect active threats: completed 3 hours ago (events: 10, objects: 5987, time: 00:05:32)
10/01/2011 08:42:34 Task started
10/01/2011 08:42:34 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\aluq.exe
10/01/2011 08:43:25 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\aluq.exe
10/01/2011 08:47:20 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\elryh.exe
10/01/2011 08:47:24 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\elryh.exe
10/01/2011 08:47:24 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\elryh.exe
10/01/2011 08:47:25 Detected: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\sariv.exe
10/01/2011 08:47:28 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\sariv.exe
10/01/2011 08:47:28 Deleted: Packed.Win32.Krap.ar C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\sariv.exe
10/01/2011 08:48:06 Task completed
  • 0

#9
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hi can you post the OTL results log it should be found here > C:_\OTL\Moved Files\*.txt where the * stands for the date that you ran it.
Then post that log and open OTL once more and click on run scan and post that log when it completes please.
  • 0

#10
Emma&Pat

Emma&Pat

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Results log:

All processes killed
========== OTL ==========
Service qsryxq stopped successfully!
Service qsryxq deleted successfully!
File C:\WINDOWS\System32\drivers\wusoc.sys not found.
Service ilgecs stopped successfully!
Service ilgecs deleted successfully!
File C:\WINDOWS\System32\drivers\ncyyvqao.sys not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1ed61cb2-86f5-82b1-b5d1-e81934c7bfbe}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1ed61cb2-86f5-82b1-b5d1-e81934c7bfbe}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe\yhlgyfgg.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:mcmvxqyx.dll deleted successfully.
C:\Program Files\ert folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Loypfa folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Alpob folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Oxdy folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Ivenny folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Erxoun folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Cyan folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Miuly folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Avtyib folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Ibkyf folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Wiyh folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Ylbu folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Onra folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Boepp folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Uropy folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Isgeat folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Uxaf folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Exci folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Umquxy folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Idxycy folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Edazg folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Yqaff folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Ulneiw folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Duoh folder moved successfully.
C:\Documents and Settings\Emma Nelder\Application Data\Myce folder moved successfully.
C:\Program Files\qwers folder moved successfully.
C:\Program Files\qwer folder moved successfully.
C:\Program Files\aiDrdaMtjÞ”™Ëyhlgyfgg.exe folder moved successfully.
C:\WINDOWS\tasks\38480230.job moved successfully.
C:\WINDOWS\kh7ptSJh moved successfully.
C:\WINDOWS\JJvvDR moved successfully.
C:\WINDOWS\YpDSJy moved successfully.
C:\WINDOWS\2Uk4Omx moved successfully.
C:\WINDOWS\nvCd6if3w moved successfully.
C:\WINDOWS\AdSXd moved successfully.
C:\WINDOWS\5G58LL14A moved successfully.
C:\WINDOWS\fITo5SKO moved successfully.
C:\WINDOWS\E78qDIH moved successfully.
C:\WINDOWS\OQ3G8wK moved successfully.
C:\WINDOWS\1DG6BCm moved successfully.
C:\WINDOWS\QD8HB moved successfully.
C:\WINDOWS\qDgOR moved successfully.
C:\WINDOWS\C62hiui moved successfully.
C:\WINDOWS\kBAie moved successfully.
C:\WINDOWS\u4XNSwghot moved successfully.
C:\WINDOWS\ruqvTxBnU moved successfully.
C:\WINDOWS\hUcwRlUJ moved successfully.
C:\WINDOWS\slVqcQews moved successfully.
C:\WINDOWS\IWwDT moved successfully.
C:\WINDOWS\fXxE7bT moved successfully.
C:\WINDOWS\8VDa7CXl moved successfully.
C:\WINDOWS\vQpJrTcBQF moved successfully.
C:\WINDOWS\Wrx6EWy5NX moved successfully.
C:\WINDOWS\NEjhJ moved successfully.
C:\WINDOWS\U3fOBPUBc moved successfully.
C:\WINDOWS\O5AtO moved successfully.
C:\WINDOWS\lolVp8E2Sq moved successfully.
C:\WINDOWS\i7JEeABY moved successfully.
C:\WINDOWS\22BMW7 moved successfully.
C:\WINDOWS\IxigT moved successfully.
C:\WINDOWS\InU5UjE moved successfully.
C:\WINDOWS\4tqPC3lA moved successfully.
C:\WINDOWS\RehIFV moved successfully.
C:\WINDOWS\jwdbJS7 moved successfully.
C:\WINDOWS\6JJRwDUT moved successfully.
C:\WINDOWS\QVVVN moved successfully.
C:\WINDOWS\myAcFSqAAJ moved successfully.
C:\WINDOWS\5nyf1fEa moved successfully.
C:\WINDOWS\63Cp1Oet moved successfully.
C:\WINDOWS\5Wa87L moved successfully.
C:\WINDOWS\XYOHDo moved successfully.
C:\WINDOWS\kipV83i moved successfully.
C:\WINDOWS\GJgrd moved successfully.
C:\WINDOWS\FgoHg moved successfully.
C:\WINDOWS\sNYXsj moved successfully.
C:\WINDOWS\7gLkamXCV moved successfully.
C:\WINDOWS\cG5Hstso moved successfully.
C:\WINDOWS\OyLaFpY moved successfully.
C:\WINDOWS\KG5olI moved successfully.
C:\WINDOWS\KSj8pJ moved successfully.
C:\WINDOWS\Jj7rN moved successfully.
C:\WINDOWS\3jKGcwC moved successfully.
C:\WINDOWS\LeHXF moved successfully.
C:\WINDOWS\v6OmO moved successfully.
C:\WINDOWS\egE75Sxs moved successfully.
C:\WINDOWS\OqM5GLT moved successfully.
C:\WINDOWS\VoTElV moved successfully.
C:\WINDOWS\NJUaq4 moved successfully.
C:\WINDOWS\E1cotQ5ms moved successfully.
C:\WINDOWS\VAGuFigpQh moved successfully.
C:\WINDOWS\noxvIPvM8 moved successfully.
C:\WINDOWS\y78eJvW moved successfully.
C:\WINDOWS\lBYMDKb moved successfully.
C:\WINDOWS\Lixec7 moved successfully.
C:\WINDOWS\IKTrTG moved successfully.
C:\WINDOWS\nhj8qXLov moved successfully.
C:\WINDOWS\GnFLPKDtyK moved successfully.
C:\WINDOWS\APpT6oqFk moved successfully.
C:\WINDOWS\e6JaP moved successfully.
C:\WINDOWS\bVIeGoH moved successfully.
C:\WINDOWS\X2VUkW moved successfully.
C:\WINDOWS\otJuGY moved successfully.
C:\WINDOWS\3Pa3wiYfqd moved successfully.
C:\WINDOWS\VXIEcq moved successfully.
C:\WINDOWS\pfS2Um moved successfully.
C:\WINDOWS\Jtd8F moved successfully.
C:\WINDOWS\t8NAq moved successfully.
C:\WINDOWS\LmkGgkiF moved successfully.
C:\WINDOWS\gJhLQHw8 moved successfully.
C:\WINDOWS\Tx7Wm3eg moved successfully.
C:\WINDOWS\NWGnE5 moved successfully.
C:\WINDOWS\j5MHLUC moved successfully.
C:\WINDOWS\GCRklH23 moved successfully.
C:\WINDOWS\xwgRvKN2dT moved successfully.
C:\WINDOWS\YmH1HIPww moved successfully.
C:\WINDOWS\awW5Ltxpf moved successfully.
C:\WINDOWS\thNrSB2V moved successfully.
C:\WINDOWS\EjLkeU moved successfully.
C:\WINDOWS\uH2whCXiG moved successfully.
C:\WINDOWS\lRvp8qsw moved successfully.
C:\WINDOWS\JfKDsowR moved successfully.
C:\WINDOWS\birbkGtK moved successfully.
C:\WINDOWS\ax8uM4r7LP moved successfully.
C:\WINDOWS\Usf1ElUGS moved successfully.
C:\WINDOWS\Fd5jCgjD moved successfully.
C:\WINDOWS\dUAU1UB moved successfully.
C:\WINDOWS\imsins.BAK moved successfully.
C:\WINDOWS\jx6b6bucz4x987sj87zgw63fxbs0qigk.ini moved successfully.
C:\WINDOWS\Wqesojudoya.dat moved successfully.
C:\WINDOWS\Qmodehoko.bin moved successfully.
C:\Program Files\Common Files\qysyno.dll moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 41044 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 41620 bytes

User: Emma Nelder
->Temp folder emptied: 395293 bytes
->Temporary Internet Files folder emptied: 145641484 bytes
->Java cache emptied: 4303 bytes
->Flash cache emptied: 57100 bytes

User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 8208598 bytes
->Java cache emptied: 14411 bytes
->Flash cache emptied: 16146 bytes

User: NetworkService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 214711796 bytes
->Java cache emptied: 166017 bytes
->Flash cache emptied: 23171 bytes

User: Owner

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 729025 bytes
%systemroot%\System32 .tmp files removed: 2280977 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 71407840 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 423.00 mb


OTL by OldTimer - Version 3.2.20.1 log created on 01092011_143319

Files\Folders moved on Reboot...
C:\Documents and Settings\Emma Nelder\Local Settings\Temporary Internet Files\Content.IE5\PFCBCMLL\page__pid__1952828[1].htm moved successfully.
C:\Documents and Settings\Emma Nelder\Local Settings\Temporary Internet Files\Content.IE5\8DK862LC\like[1].htm moved successfully.
C:\Documents and Settings\Emma Nelder\Local Settings\Temporary Internet Files\Content.IE5\8DK862LC\xd_proxy[1].htm moved successfully.
C:\Documents and Settings\Emma Nelder\Local Settings\Temporary Internet Files\SuggestedSites.dat moved successfully.

Registry entries deleted on Reboot...

Running OTL again now, will post when done.
  • 0

Advertisements


#11
Emma&Pat

Emma&Pat

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
OTL logfile created on: 10/01/2011 14:29:44 - Run 3
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Emma Nelder\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 217.11 Gb Total Space | 87.11 Gb Free Space | 40.12% Space Free | Partition Type: NTFS
Drive D: | 12.55 Gb Total Space | 12.38 Gb Free Space | 98.66% Space Free | Partition Type: NTFS

Computer Name: EMMA | User Name: Emma Nelder | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
PRC - [2010/10/27 19:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/10/03 22:43:16 | 000,767,208 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2010/08/25 10:27:44 | 000,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010/08/13 17:51:04 | 000,030,192 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2010/05/19 23:20:44 | 012,776,728 | ---- | M] () -- C:\Program Files\RegCure\RegCure.exe
PRC - [2010/04/16 07:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/03/04 14:52:58 | 000,202,016 | R--- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprtsvc.exe
PRC - [2009/03/04 14:52:22 | 000,202,016 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprtcmd.exe
PRC - [2008/05/22 20:50:00 | 000,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
PRC - [2008/05/22 20:50:00 | 000,111,952 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2008/05/22 20:50:00 | 000,054,608 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
PRC - [2008/04/14 00:12:32 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\proquota.exe
PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/10/25 16:37:32 | 002,178,832 | ---- | M] () -- C:\Program Files\Logitech\QuickCam\Quickcam.exe
PRC - [2007/10/25 16:33:22 | 000,563,984 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2007/10/25 16:32:58 | 000,407,824 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2007/10/25 15:06:00 | 000,086,016 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\Mctray.exe
PRC - [2007/10/25 10:05:40 | 000,136,512 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2007/10/25 10:04:56 | 000,136,512 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2007/10/25 10:03:28 | 000,103,744 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2007/10/19 13:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2007/10/19 13:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2007/06/24 19:17:54 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007/04/13 16:20:22 | 000,097,432 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe
PRC - [2007/04/04 01:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2006/09/11 15:47:38 | 000,026,112 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\realplay.exe
PRC - [2006/07/16 20:29:54 | 000,389,120 | ---- | M] (Gteko Ltd.) -- C:\Program Files\Dell Support\DSAgnt.exe
PRC - [2006/04/06 13:57:54 | 000,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2006/03/24 22:30:44 | 000,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2005/06/10 09:44:02 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2005/02/23 14:57:24 | 000,057,344 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Mixer\CTSVolFE.exe
PRC - [2005/01/27 00:02:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2003/10/29 01:06:00 | 000,024,576 | ---- | M] (BVRP Software) -- C:\Program Files\Digital Line Detect\DLG.exe
PRC - [1998/12/16 21:09:20 | 000,057,393 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE


========== Modules (SafeList) ==========

MOD - [2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
MOD - [2010/08/23 16:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/03/04 14:52:40 | 000,116,000 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\O2\bin\sprthook.dll
MOD - [2008/04/14 00:12:01 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll
MOD - [2007/10/19 13:19:10 | 000,109,080 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcInj.dll
MOD - [2005/12/13 22:39:58 | 000,073,728 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\hccutils.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/10/03 22:43:16 | 000,767,208 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2010/08/13 17:51:04 | 000,030,192 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-051210-111108)
SRV - [2010/04/16 07:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/03/04 14:52:58 | 000,202,016 | R--- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\O2\bin\sprtsvc.exe -- (sprtsvc_O2) SupportSoft Sprocket Service (O2)
SRV - [2008/05/22 20:50:00 | 000,144,704 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe -- (McShield)
SRV - [2008/05/22 20:50:00 | 000,054,608 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
SRV - [2007/10/25 10:03:28 | 000,103,744 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2007/10/19 13:21:16 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2007/10/19 13:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2007/10/19 13:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)
SRV - [2007/07/27 05:39:32 | 000,382,320 | ---- | M] (SupportSoft, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2007/04/13 16:20:22 | 000,097,432 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2006/05/01 08:34:00 | 000,262,217 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER) Intel®
SRV - [2006/05/01 08:22:42 | 000,540,745 | ---- | M] (Intel Corporation ) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2006/05/01 08:20:52 | 000,114,753 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2006/05/01 08:20:26 | 000,217,164 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2006/04/06 13:57:54 | 000,380,928 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\PavSRK.sys -- (PavSRK.sys)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\COMFiltr.sys -- (ComFiltr)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\EMMANE~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/10/03 22:54:04 | 000,034,792 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys -- (RapportCerberus_19917)
DRV - [2010/10/03 22:43:44 | 000,169,320 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2010/10/03 22:43:44 | 000,059,240 | ---- | M] (Trusteer Ltd.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2009/02/19 13:22:52 | 000,127,744 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ArcHlp.sys -- (archlp)
DRV - [2008/07/16 09:43:16 | 000,160,648 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\pctfw2.sys -- (pctfw2)
DRV - [2008/05/22 20:50:00 | 000,174,952 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2008/05/22 20:50:00 | 000,072,936 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2008/05/22 20:50:00 | 000,064,232 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2008/05/22 20:50:00 | 000,052,104 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2008/05/22 20:50:00 | 000,033,960 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2008/05/22 20:50:00 | 000,031,816 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys -- (mferkdk)
DRV - [2008/04/13 18:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 18:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 18:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 16:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/10/19 13:16:30 | 002,109,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007/10/11 18:59:24 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2007/10/11 18:59:02 | 002,142,488 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/05/11 03:10:50 | 000,034,704 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007/05/09 01:59:40 | 000,036,496 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007/03/05 06:00:04 | 000,027,792 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2007/03/05 05:59:04 | 000,018,320 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btnetdrv.sys -- (BT)
DRV - [2007/03/05 05:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2007/03/05 05:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - [2007/03/05 05:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2007/03/05 05:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2006/11/21 22:41:18 | 000,022,416 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Program Files\IVT Corporation\BlueSoleil\device\Win2k\BTNetFilter.sys -- (BTNetFilter)
DRV - [2006/11/10 19:48:02 | 000,040,352 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2006/11/10 19:43:16 | 000,933,536 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2006/11/10 19:43:16 | 000,013,344 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2006/09/11 15:47:41 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2006/05/01 08:52:02 | 000,013,568 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/04/26 22:13:04 | 001,429,632 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel®
DRV - [2006/03/24 22:34:30 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/03/08 17:35:10 | 000,191,872 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2006/01/10 11:07:58 | 000,004,864 | ---- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/10/14 14:40:18 | 000,307,968 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/10/14 14:40:18 | 000,051,328 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/10/14 14:40:18 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/08/30 17:59:00 | 000,094,000 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2005/08/30 17:58:56 | 000,008,304 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2005/08/30 17:57:18 | 000,058,320 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)
DRV - [2005/08/12 16:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/08/05 15:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/22 02:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 02:01:08 | 000,201,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/07/22 02:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/02/23 13:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2004/12/06 00:05:00 | 000,100,603 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudfa.sys -- (tfsnudfa)
DRV - [2004/12/06 00:05:00 | 000,098,714 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudf.sys -- (tfsnudf)
DRV - [2004/12/06 00:05:00 | 000,086,586 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnifs.sys -- (tfsnifs)
DRV - [2004/12/06 00:05:00 | 000,034,843 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsncofs.sys -- (tfsncofs)
DRV - [2004/12/06 00:05:00 | 000,025,883 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnboio.sys -- (tfsnboio)
DRV - [2004/12/06 00:05:00 | 000,015,227 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnopio.sys -- (tfsnopio)
DRV - [2004/12/06 00:05:00 | 000,006,363 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnpool.sys -- (tfsnpool)
DRV - [2004/12/06 00:05:00 | 000,004,123 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndrct.sys -- (tfsndrct)
DRV - [2004/12/06 00:05:00 | 000,002,239 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndres.sys -- (tfsndres)
DRV - [2004/12/01 02:22:00 | 000,087,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb)
DRV - [2004/11/23 01:56:00 | 000,040,480 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\drvnddm.sys -- (drvnddm)
DRV - [2004/08/03 21:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004/07/14 10:29:04 | 000,005,627 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\sscdbhk5.sys -- (sscdbhk5)
DRV - [2004/07/14 10:28:50 | 000,023,545 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\ssrtln.sys -- (ssrtln)
DRV - [2004/02/13 15:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
DRV - [2001/08/17 13:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 13:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 13:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 13:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 13:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 12:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 12:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 12:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 12:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 12:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 12:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 12:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 12:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 12:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 12:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..browser.startup.homepage: "http://flvdirect.iamwired.net/"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..keyword.URL: "http://flvdirect.iam...c=tops&search="
FF - prefs.js..keyword.enabled: true
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaulturl: "http://flvdirect.iam...c=tops&search="
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"
FF - prefs.js..network.proxy.autoconfig_url: "http://wwwcache.bris....uk/autoconfig"


FF - HKLM\software\mozilla\Firefox\extensions\\{8779B4BC-1A5D-4E0E-B83B-171D20F2236D}: C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\{8779B4BC-1A5D-4E0E-B83B-171D20F2236D} [2010/07/27 07:18:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{387D07D6-5CF8-44EB-AECB-C4B4A82A9511}: C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\{387D07D6-5CF8-44EB-AECB-C4B4A82A9511}

[2010/05/20 16:24:03 | 000,000,266 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\Application Data\Mozilla\Firefox\Profiles\2w0v2hf2.default\searchplugins\Search.xml

O1 HOSTS File: ([2009/01/23 17:23:52 | 000,000,736 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1ed61cb2-86f5-82b1-b5d1-e81934c7bfbe} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [CTSVolFE.exe] C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [O2] C:\Program Files\O2\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnote...ad/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {1288683E-8FB1-46E3-AF62-9BB668505759} http://www.wireless....der_activex.ocx (xc_loader_activex.cntMain)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {17D667BA-5675-4AAB-9221-08B9379384D4} http://cdnimg.piczo....st_uploader.cab (Image Uploader Control)
O16 - DPF: {483912CF-8995-4434-AD61-6163756E05DF} http://download.live...tivex/AXTNS.ocx (AXTNS Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcaf...01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8EF9626B-2251-4C5E-BD17-D5F3E0E98B03} http://www.wireless....der_activex.ocx (xc_loader_activex.cntMain)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius....tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} http://www.tescophot...opcuploader.cab (Image Uploader 3.0 Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Emma Nelder\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Emma Nelder\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/10 00:23:26 | 088,010,112 | ---- | C] ( ) -- C:\Documents and Settings\Emma Nelder\Desktop\setup_9.0.0.722_10.01.2011_02-37.exe
[2011/01/09 14:33:19 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/01/08 11:06:28 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/01/08 10:29:02 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\proquota.exe
[2011/01/08 10:29:02 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\proquota.exe
[2011/01/08 10:21:09 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/01/08 10:15:38 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/01/08 10:15:38 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/01/08 10:15:38 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/01/08 10:15:38 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/01/08 10:15:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/01/08 10:12:18 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/01/07 14:31:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\AnyBizSoft PDF to PowerPoint
[2011/01/07 14:31:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AnyBizSoft
[2011/01/07 14:31:20 | 000,000,000 | ---D | C] -- C:\Program Files\AnyBizSoft
[2011/01/07 14:22:07 | 000,000,000 | ---D | C] -- C:\Program Files\SomePDF
[2011/01/07 14:19:09 | 000,000,000 | ---D | C] -- C:\Program Files\AXPDF
[2011/01/07 14:19:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AXPDF
[2011/01/06 00:42:18 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
[2011/01/03 10:13:05 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/01/03 10:10:51 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2010/12/30 06:27:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Emma Nelder\Recent
[2010/12/25 21:58:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\My Received Files
[2010/12/21 15:21:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/12/16 21:26:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/12/14 23:58:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2010/12/13 13:04:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Emma Nelder\My Documents\Pictures - Digital Camera
[1 C:\Documents and Settings\Emma Nelder\My Documents\*.tmp files -> C:\Documents and Settings\Emma Nelder\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/10 14:21:19 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{F0A36E4F-8866-4030-B42F-1A4DE747284D}.job
[2011/01/10 14:17:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/10 12:35:50 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/10 12:35:47 | 000,000,376 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Startup.job
[2011/01/10 12:35:31 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/10 12:35:25 | 2137,456,640 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/10 12:00:00 | 000,000,374 | ---- | M] () -- C:\WINDOWS\tasks\PerfectOptimizer_home.job
[2011/01/10 11:39:53 | 000,000,668 | -HS- | M] () -- C:\WINDOWS\setup_9.0.0.722_10.01.2011_02-37drv.spi
[2011/01/10 00:23:25 | 088,010,112 | ---- | M] ( ) -- C:\Documents and Settings\Emma Nelder\Desktop\setup_9.0.0.722_10.01.2011_02-37.exe
[2011/01/09 17:00:04 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2011/01/08 10:21:14 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/01/08 10:11:00 | 004,150,017 | R--- | M] () -- C:\Documents and Settings\Emma Nelder\Desktop\ComboFix.exe
[2011/01/07 14:31:27 | 000,000,801 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AnyBizSoft PDF to PowerPoint.lnk
[2011/01/07 14:19:11 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PDF to Word Converter.lnk
[2011/01/07 13:33:51 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\365.doc
[2011/01/06 16:53:26 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/06 00:42:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Emma Nelder\Desktop\OTL.exe
[2011/01/05 14:02:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/04 10:25:25 | 000,303,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/01 02:21:21 | 000,060,928 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/29 21:55:46 | 000,000,260 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2010/12/29 21:02:13 | 000,069,518 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\cc_20101229_210204.reg
[2010/12/28 20:29:48 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/14 12:18:59 | 000,000,712 | ---- | M] () -- C:\Documents and Settings\Emma Nelder\My Documents\GHremoval.bat
[2010/12/12 04:32:01 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\Driver Robot.job
[2010/12/12 04:21:25 | 000,000,384 | ---- | M] () -- C:\WINDOWS\tasks\RegCure.job
[1 C:\Documents and Settings\Emma Nelder\My Documents\*.tmp files -> C:\Documents and Settings\Emma Nelder\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/10 09:06:43 | 000,000,668 | -HS- | C] () -- C:\WINDOWS\setup_9.0.0.722_10.01.2011_02-37drv.spi
[2011/01/08 10:21:14 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/01/08 10:21:11 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/01/08 10:15:38 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/01/08 10:15:38 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/01/08 10:15:38 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/01/08 10:15:38 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/01/08 10:15:38 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/01/08 10:11:00 | 004,150,017 | R--- | C] () -- C:\Documents and Settings\Emma Nelder\Desktop\ComboFix.exe
[2011/01/07 14:31:27 | 000,000,801 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AnyBizSoft PDF to PowerPoint.lnk
[2011/01/07 14:19:09 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PDF to Word Converter.lnk
[2011/01/02 23:22:54 | 2137,456,640 | -HS- | C] () -- C:\hiberfil.sys
[2010/12/29 21:02:09 | 000,069,518 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\My Documents\cc_20101229_210204.reg
[2010/12/14 12:19:08 | 000,000,712 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\My Documents\GHremoval.bat
[2010/04/28 16:41:04 | 000,001,112 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\VVcku64agTJJ
[2010/04/28 16:41:04 | 000,001,112 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\VVcku64agTJJ
[2010/04/23 08:15:24 | 000,001,444 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\Mi715R2
[2010/04/23 08:15:24 | 000,001,444 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\Mi715R2
[2010/04/16 08:36:28 | 000,016,316 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\018LBPw26q64R
[2010/04/16 08:36:28 | 000,016,316 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\018LBPw26q64R
[2010/04/12 22:34:57 | 000,015,054 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\V8i44CYn52
[2010/04/12 22:34:57 | 000,015,054 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\V8i44CYn52
[2010/03/05 17:18:25 | 000,004,562 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\2Y04MW11w
[2010/03/04 17:51:11 | 000,011,668 | -HS- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\deQagCc75
[2010/01/31 12:55:45 | 000,000,030 | ---- | C] () -- C:\WINDOWS\WAR2R.INI
[2009/12/04 23:04:26 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/12/04 23:04:26 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/12/03 23:08:59 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/10/18 12:14:37 | 000,127,744 | ---- | C] () -- C:\WINDOWS\System32\drivers\ArcHlp.sys
[2009/10/15 21:11:05 | 000,000,173 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/10/02 15:20:51 | 000,017,438 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\oludije.ban
[2009/10/02 15:20:51 | 000,014,531 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ycapymej.ban
[2009/10/02 15:20:51 | 000,013,680 | ---- | C] () -- C:\Program Files\Common Files\kumiceqa.com
[2009/09/25 14:07:40 | 000,000,728 | ---- | C] () -- C:\WINDOWS\{4507868A-A9CD-4ECC-BD54-0EAB6EE81D42}_WiseFW.ini
[2009/01/23 17:32:51 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/12/01 17:26:37 | 000,000,140 | -H-- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\lakerda1967.sys
[2008/12/01 17:26:17 | 000,010,584 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\docXConverter (3).ini
[2007/10/11 18:59:24 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/04 21:43:25 | 002,067,140 | R--- | C] () -- C:\WINDOWS\System32\avcodec.dll
[2006/12/28 15:38:46 | 000,042,594 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2006/10/01 13:53:02 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\606D16E445.sys
[2006/09/20 19:16:15 | 000,060,928 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/16 19:25:47 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\45E4166D60.sys
[2006/09/15 22:23:05 | 000,000,077 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\FASTWiz.log
[2006/09/15 22:21:15 | 000,000,748 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Application Data\wklnhst.dat
[2006/09/15 22:13:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/09/15 12:57:17 | 000,000,134 | ---- | C] () -- C:\Documents and Settings\Emma Nelder\Local Settings\Application Data\fusioncache.dat
[2006/09/15 11:55:42 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/09/11 15:57:31 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/09/11 15:44:50 | 000,712,704 | ---- | C] () -- C:\WINDOWS\System32\DellSystemRestore.dll
[2006/09/11 15:42:19 | 000,000,260 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/09/11 15:38:36 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/09/11 14:28:50 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2006/09/11 14:28:44 | 000,000,474 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/06/01 22:10:25 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/04/09 16:04:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 12:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[1999/01/22 18:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 08:00:00 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\REGOBJ.DLL

========== Alternate Data Streams ==========

@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
  • 0

#12
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Looks a lot better.
Please delete the current version of Combofix now then do the following:

Please visit this webpage for download links, and instructions for running ComboFix:

http://www.bleepingc...to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.
  • 0

#13
Emma&Pat

Emma&Pat

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
ComboFix 11-01-10.08 - Emma Nelder 11/01/2011 16:15:50.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1441 [GMT 0:00]
Running from: c:\documents and settings\Emma Nelder\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *Disabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

-- Previous Run --

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe

--------

.
((((((((((((((((((((((((( Files Created from 2010-12-11 to 2011-01-11 )))))))))))))))))))))))))))))))
.

2011-01-09 14:33 . 2011-01-09 14:33 -------- d-----w- C:\_OTL
2011-01-08 10:29 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2011-01-08 10:29 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2011-01-07 14:22 . 2011-01-07 14:22 -------- d-----w- c:\program files\SomePDF
2011-01-03 10:13 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2011-01-03 10:10 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
2010-12-21 15:21 . 2010-12-21 15:21 -------- d-----w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-12-16 21:26 . 2010-12-16 21:26 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 18:09 . 2009-11-25 23:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 18:08 . 2009-11-25 23:28 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-10 15:19 . 2010-12-10 15:19 680288 ----a-w- c:\windows\system32\Doctor-Who-2010-Series.scr
2010-11-18 18:12 . 2004-08-10 12:02 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-06 00:26 . 2004-08-10 11:51 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2004-08-10 11:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2004-08-10 11:51 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-10 11:51 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-10 11:51 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-10 11:50 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2004-08-10 11:51 1853312 ----a-w- c:\windows\system32\win32k.sys
2009-10-02 15:20 . 2009-10-02 15:20 13680 ----a-w- c:\program files\Common Files\kumiceqa.com
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-07-16 389120]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-24 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 282624]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"CTSVolFE.exe"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-09-11 26112]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-13 30192]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-04-04 1603152]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-05-22 111952]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2007-10-25 136512]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-9-11 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\O2\\agent\\bin\\bcont.exe"=
"c:\\Program Files\\O2\\bin\\wificfg.exe"=
"c:\\Program Files\\Common Files\\SupportSoft\\bin\\ssrc.exe"=
"c:\\Program Files\\O2\\agent\\bin\\bcont_nm.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil_.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"45538:TCP"= 45538:TCP:LimeWire

R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [03/10/2010 22:43 59240]
R1 archlp;archlp;c:\windows\system32\drivers\ArcHlp.sys [18/10/2009 12:14 127744]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [02/10/2009 13:48 160648]
R1 RapportCerberus_19917;RapportCerberus_19917;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys [03/10/2010 22:54 34792]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [03/10/2010 22:43 169320]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [03/10/2010 22:43 767208]
R2 sprtsvc_O2;SupportSoft Sprocket Service (O2);c:\program files\O2\bin\sprtsvc.exe [04/03/2009 14:52 202016]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [07/02/2010 10:04 135664]
S3 ComFiltr;Panda Anti-Dialer;\??\c:\windows\system32\DRIVERS\COMFiltr.sys --> c:\windows\system32\DRIVERS\COMFiltr.sys [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [11/09/2006 15:50 30192]
S3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\PavSRK.sys --> c:\windows\system32\PavSRK.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2011-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2011-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 10:04]

2011-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 10:04]

2011-01-10 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]

2011-01-11 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]

2010-12-12 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]

2011-01-11 c:\windows\Tasks\User_Feed_Synchronization-{F0A36E4F-8866-4030-B42F-1A4DE747284D}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bbc.co.uk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=4060911
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
DPF: {1288683E-8FB1-46E3-AF62-9BB668505759} - hxxp://www.wireless.bris.ac.uk/ignition/eduroam/tools/xc_loader_activex.ocx
DPF: {17D667BA-5675-4AAB-9221-08B9379384D4} - hxxp://cdnimg.piczo.com/images/uploader/piczo_fast_uploader.cab
DPF: {483912CF-8995-4434-AD61-6163756E05DF} - hxxp://download.livemath.com/activex/AXTNS.ocx
DPF: {8EF9626B-2251-4C5E-BD17-D5F3E0E98B03} - hxxp://www.wireless.bris.ac.uk/ignition/eduroam/tools/xc_loader_activex.ocx
.
- - - - ORPHANS REMOVED - - - -

BHO-{1ed61cb2-86f5-82b1-b5d1-e81934c7bfbe} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellIconOverlayIdentifiers-{DF7B3869-38F7-13D1-143F-5E9D8A3FF451} - (no file)
SafeBoot-klmdb.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-11 16:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(9396)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\stsystra.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2011-01-11 16:32:22 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-11 16:32

Pre-Run: 93,532,016,640 bytes free
Post-Run: 93,665,689,600 bytes free

- - End Of File - - 50043C9B13A21A71D55E350F96FBCCFF
  • 0

#14
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Great how are things running?
  • 0

#15
Emma&Pat

Emma&Pat

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Everything's running fine, the web redirecting has stopped, audio is back, everything that was going wrong before seems to be ok now.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP