Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

S&D found PerfectKeylogger in msconfig.exe


  • This topic is locked This topic is locked

#1
Theo Haris

Theo Haris

    Member

  • Member
  • PipPip
  • 43 posts
Hello, and thank you in advance for your assistance.

I ran today msconfig.exe to disable the automatic Divxupdate. After having done so, Spybot S&D gave me an alarm that Perfectkeylogger was found on C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe, which looked weird since there's no possibility someone has manually installed a keylogger in my computer - I don't know whether Perfect Keylogger can be installed through distance.

I told S&D to delete the file, but it has re-appeared. I ran Trend Micro Housecall, updated AVG and ran a scan, updated Spybot and ran a scan, but in all cases no threats were found. So I turn to you guys for expert help. I'd hate it if there's a keylogger in my system...

Here's the OTL logs. Thanks!

Theoharis

PS. Some of it is in Greek. "Επιφάνεια εργασίας" is desktop.



OTL logfile created on: 9/2/2011 8:38:45 μμ - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000408 | Country: Ελλάδα | Language: ELL | Date Format: d/M/yyyy

1.022,00 Mb Total Physical Memory | 105,00 Mb Available Physical Memory | 10,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 51,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 44,37 Gb Total Space | 16,92 Gb Free Space | 38,12% Space Free | Partition Type: FAT32
Drive D: | 44,86 Gb Total Space | 12,13 Gb Free Space | 27,03% Space Free | Partition Type: FAT32
Drive G: | 1397,26 Gb Total Space | 1187,83 Gb Free Space | 85,01% Space Free | Partition Type: NTFS

Computer Name: ACER-92EDFFD6C3 | User Name: Theo Haris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/09 20:35:40 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
PRC - [2011/01/07 01:22:54 | 003,989,856 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgui.exe
PRC - [2011/01/07 01:22:54 | 002,747,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/01/07 01:22:44 | 001,084,256 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/01/06 15:23:20 | 000,737,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/12/11 05:00:10 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010/12/11 04:59:50 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/12/05 16:26:40 | 000,654,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/12/05 16:26:12 | 000,650,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/11/22 11:18:50 | 001,634,128 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Theo Haris\Local Settings\Temp\HouseCall\housecall.bin
PRC - [2010/11/12 13:20:16 | 001,100,640 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgscanx.exe
PRC - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/10/22 04:56:58 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2010/03/26 10:13:54 | 000,136,840 | ---- | M] () -- C:\Program Files\Join Air\UIExec.exe
PRC - [2010/03/26 09:59:00 | 000,251,016 | ---- | M] () -- C:\Program Files\Join Air\AssistantServices.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:12 | 005,365,592 | ---- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
PRC - [2008/04/14 18:30:36 | 001,038,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/21 11:30:44 | 000,061,440 | ---- | M] () -- C:\Program Files\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
PRC - [2006/08/31 16:52:06 | 000,118,784 | ---- | M] (Bytemobile, Inc.) -- C:\WINDOWS\system32\bmwebcfg.exe
PRC - [2005/12/01 17:38:38 | 000,458,752 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\QtZgAcer.EXE
PRC - [2005/11/25 15:59:44 | 000,212,992 | ---- | M] (Acer Inc) -- C:\Acer\Empowering Technology\ePower\epm-dm.exe
PRC - [2005/11/16 17:00:50 | 000,397,312 | ---- | M] (acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\Monitor.exe
PRC - [2005/11/09 22:01:00 | 000,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2005/11/09 21:59:08 | 000,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2005/11/09 21:58:26 | 000,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2005/10/24 16:45:32 | 002,462,208 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admtray.exe
PRC - [2005/10/24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admServ.exe
PRC - [2005/10/19 09:30:16 | 000,069,632 | ---- | M] (HiTRUST) -- C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
PRC - [2005/01/07 16:17:16 | 000,102,491 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004/08/09 06:03:38 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () -- C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe


========== Modules (SafeList) ==========

MOD - [2011/02/09 20:35:40 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
MOD - [2010/08/23 19:12:06 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2005/12/05 16:00:10 | 000,053,248 | ---- | M] (HiTRUST) -- C:\WINDOWS\system32\sysenv.dll
MOD - [2005/08/24 01:24:00 | 000,010,752 | ---- | M] () -- C:\WINDOWS\system32\MSNChatHook.dll
MOD - [2005/01/07 16:17:08 | 000,069,723 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll
MOD - [2003/03/18 21:12:12 | 001,047,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MFC71u.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (Pcmrome)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Disabled | Stopped] -- -- (gupdate1c998781007dfbe) Google Update Service (gupdate1c998781007dfbe)
SRV - File not found [Disabled | Stopped] -- -- (CLTNetCnService)
SRV - File not found [Disabled | Stopped] -- -- (ccSetMgr)
SRV - File not found [Disabled | Stopped] -- -- (ccPwdSvc)
SRV - File not found [Disabled | Stopped] -- -- (ccEvtMgr)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/06/14 15:07:14 | 000,615,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010/03/26 09:59:00 | 000,251,016 | ---- | M] () [Auto | Running] -- C:\Program Files\Join Air\AssistantServices.exe -- (UI Assistant Service)
SRV - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2006/08/31 16:52:06 | 000,118,784 | ---- | M] (Bytemobile, Inc.) [Auto | Running] -- C:\WINDOWS\System32\bmwebcfg.exe -- (bmwebcfg)
SRV - [2005/11/14 01:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2005/11/09 22:01:00 | 000,540,745 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2005/11/09 21:59:08 | 000,114,753 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2005/11/09 21:58:26 | 000,217,164 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2005/10/24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) [Auto | Running] -- C:\Acer\Empowering Technology\admServ.exe -- (AWService)
SRV - [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2004/09/07 20:00:00 | 000,003,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\System32\regedt32.exe -- (.EsetTrialReset)
SRV - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe -- (Network WanMiniport First Position)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | Unknown | Running] -- -- (mbmiodrvr)
DRV - [2011/02/04 12:42:58 | 000,071,680 | ---- | M] (Notebook Hardware Control) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\nhcDriver.sys -- (nhcDriverDevice)
DRV - [2010/12/08 04:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/11/12 13:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/09/13 15:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/09/06 11:26:20 | 000,189,520 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2010/08/19 20:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/08/19 20:42:36 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/19 20:42:34 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/02/26 14:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010/02/26 14:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010/02/26 14:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/02/26 14:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009/10/29 19:28:24 | 000,009,216 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter.sys -- (massfilter)
DRV - [2009/10/07 10:49:50 | 000,023,832 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
DRV - [2009/10/07 10:49:38 | 006,756,632 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 120(UVC)
DRV - [2009/10/07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009/09/25 08:05:20 | 000,278,984 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2009/01/06 20:07:28 | 000,124,464 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2008/09/05 21:25:04 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008/08/29 00:10:18 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/04/13 20:36:40 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 20:36:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 18:36:06 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2006/10/16 14:45:26 | 000,088,960 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2006/08/31 16:58:22 | 000,018,560 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2006/01/06 07:53:34 | 000,006,144 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV - [2006/01/04 07:46:42 | 001,420,288 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/11/17 15:45:40 | 004,069,888 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/11/09 14:45:56 | 000,013,440 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2005/10/23 19:20:52 | 000,218,496 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/10/18 01:53:24 | 000,998,656 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/10/18 01:52:30 | 000,721,280 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/10/15 18:20:44 | 000,012,106 | ---- | M] (OSA Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\OsaFsLoc.sys -- (OsaFsLoc)
DRV - [2005/09/29 20:11:42 | 000,078,720 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2005/09/13 15:34:40 | 000,004,392 | ---- | M] (OSA Technologies) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NdisFilt.sys -- (NdisFilt)
DRV - [2005/09/11 19:49:44 | 003,298,432 | ---- | M] (IntelŽ Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2005/08/03 05:10:14 | 000,032,512 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2005/06/30 16:58:24 | 000,007,296 | ---- | M] (OSA Technologies, An Avocent Company) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio)
DRV - [2005/05/02 12:13:42 | 000,009,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETMNT.sys -- (NETMNT)
DRV - [2005/04/07 18:08:46 | 000,078,208 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-shd.sys -- (EpmShd)
DRV - [2005/01/14 15:57:16 | 000,004,010 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm)
DRV - [2005/01/13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys)
DRV - [2005/01/07 16:03:42 | 000,191,456 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2004/12/08 14:10:00 | 000,016,896 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2004/09/07 20:00:00 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2004/09/07 20:00:00 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2004/09/07 20:00:00 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2004/09/07 20:00:00 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2004/09/07 20:00:00 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2004/09/07 20:00:00 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2004/09/07 20:00:00 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2004/09/07 20:00:00 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2004/09/07 20:00:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2004/09/07 20:00:00 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2004/09/07 20:00:00 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2004/09/07 20:00:00 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2004/09/07 20:00:00 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2004/09/07 20:00:00 | 000,006,784 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
DRV - [2004/09/07 20:00:00 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2004/07/19 13:10:00 | 000,004,096 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-psd.sys -- (EpmPsd)
DRV - [2004/06/26 13:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vncdrv.sys -- (vncdrv)
DRV - [2004/03/08 12:55:50 | 000,013,567 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)
DRV - [2003/12/15 18:22:00 | 000,038,448 | ---- | M] (OLYMPUS OPTICAL CO.,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VNUSB.sys -- (VNUSB)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://e-learning.hau.gr/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "en.wikipedia.org"
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.48.3
FF - prefs.js..extensions.enabledItems: {3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}:0.9.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.7
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.7.2
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: {F270F1AF-34D6-41CB-A9F5-8200EF7DB41F}:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:2.4.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.732
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1167
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0

FF - user.js..network.proxy.type: 0
FF - user.js..network.proxy.http: ""
FF - user.js..network.proxy.http_port: 0
FF - user.js..network.proxy.ssl: ""
FF - user.js..network.proxy.ssl_port: 0
FF - user.js..network.proxy.ftp: ""
FF - user.js..network.proxy.ftp_port: 0
FF - user.js..network.proxy.gopher: ""
FF - user.js..network.proxy.gopher_port: 0
FF - user.js..network.proxy.socks_version: 5
FF - user.js..network.proxy.socks: ""
FF - user.js..network.proxy.socks_port: 0

FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/11/17 13:28:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/11/26 13:57:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2006/07/15 20:42:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2006/07/15 20:42:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2008/08/29 02:37:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Extensions
[2006/07/15 20:49:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions
[2011/02/07 12:48:04 | 000,000,000 | ---D | M] (Session Manager) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2011/01/07 13:33:32 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2008/05/22 19:44:28 | 000,000,000 | ---D | M] (Forecastbar Enhanced) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}
[2011/02/03 14:20:48 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/04/29 18:32:16 | 000,000,000 | ---D | M] (Tamper Data) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2010/09/10 02:45:26 | 000,000,000 | ---D | M] (WOT) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/01/12 14:03:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/12/27 00:48:18 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/09/07 14:58:42 | 000,000,000 | ---D | M] ("BetterPrivacy") -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010/06/18 13:12:38 | 000,000,000 | ---D | M] ("Tab Mix Plus") -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2011/01/27 19:16:54 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/11/22 23:18:32 | 000,000,000 | ---D | M] (Ghostery) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\[email protected]
[2008/11/04 20:21:56 | 000,005,179 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\searchplugins\BitTorrent.xml
[2006/07/15 20:42:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/25 19:35:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/02/12 00:33:58 | 000,000,000 | ---D | M] (Zwunzi) -- C:\Program Files\Mozilla Firefox\extensions\{F270F1AF-34D6-41CB-A9F5-8200EF7DB41F}
[2010/11/26 13:57:20 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2010/04/19 15:02:14 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/17 13:28:06 | 000,000,000 | ---D | M] (PC Sync 2 Synchronisation Extension) -- C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC
[2009/03/16 21:28:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2007/01/04 02:29:08 | 000,049,152 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/02/12 00:33:58 | 000,002,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zwunzi14.xml
[2010/02/12 01:00:58 | 000,002,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zwunzi141.xml
[2010/08/03 18:40:56 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/08/03 18:40:56 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/08/03 18:40:56 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/08/03 18:40:56 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/02/05 18:00:30 | 000,001,152 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (no name) - {0CF5D165-517E-48B6-B3C7-3054A24F8BF6} - File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {B7FC60D5-AB79-477E-96EE-5C7770EAEAB9} - File not found
O4 - HKLM..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe (Acer Value Labs, Taiwan)
O4 - HKLM..\Run: [ADMTray.exe] C:\Acer\Empowering Technology\admtray.exe (Avocent Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe (HiTRUST)
O4 - HKLM..\Run: [EPM-DM] c:\Acer\Empowering Technology\ePower\epm-dm.exe (Acer Inc)
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe (acer Inc.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [UIExec] C:\Program Files\Join Air\UIExec.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [yahoo!] C:\Documents and Settings\Theo Haris\Local Settings\Temp\16967197Wsy.dll (Blizzard Entertainment)
O4 - HKLM..\RunOnce\Setup: [Registering ActiveScan 2.0 Components] C:\Program Files\Panda Security\ActiveScan 2.0\as2guiie.dll (Panda Security, S.L.)
O4 - HKLM..\RunOnce\Setup: [Registering ActiveScan 2.0 Components.] File not found
O4 - HKLM..\RunOnce\Setup: [Registering ActiveScan 2.0 Components..] File not found
O4 - HKLM..\RunOnce\Setup: [Registering ActiveScan 2.0 Components...] C:\Program Files\Panda Security\ActiveScan 2.0\as2inst.dll (Panda Security, S.L.)
O4 - Startup: C:\Documents and Settings\Theo Haris\Start Menu\Προγράμματα\Εκκίνηση\new1.exe (Blizzard Entertainment)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Sample Toolband Serach - C:\WINDOWS\System32\ToolBand.dll (HiTRUST)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1152986441640 (MUWebControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\cbXrPFXn: DllName - cbXrPFXn.dll - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Τρέχουσα αρχική σελίδα) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {0CF5D165-517E-48B6-B3C7-3054A24F8BF6} - File not found
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/20 23:33:42 | 000,000,065 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2006/01/06 07:54:00 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.FRK -- [ FAT32 ]
O33 - MountPoints2\{220c1ed0-b7a8-11db-849c-eaf2d30bfb47}\Shell\AutoRun\command - "" = F:\JDSecure\Windows\JDSecure31.exe
O33 - MountPoints2\{23f54bcc-ceca-11de-89fd-0013ced19ef5}\Shell\AutoRun\command - "" = F:\__DTMEDIA\DTMedia.exe
O33 - MountPoints2\{402b7953-68c4-11db-8422-0013ced19ef5}\Shell\AutoRun\command - "" = G:\setupSNK.exe
O33 - MountPoints2\{402b7954-68c4-11db-8422-0013ced19ef5}\Shell - "" = AutoRun
O33 - MountPoints2\{402b7954-68c4-11db-8422-0013ced19ef5}\Shell\AutoRun\command - "" = F:\LaunchU3.exe
O33 - MountPoints2\{60210892-c5ae-11dc-863d-0013ced19ef5}\Shell - "" = AutoRun
O33 - MountPoints2\{60210892-c5ae-11dc-863d-0013ced19ef5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{60210893-c5ae-11dc-863d-0013ced19ef5}\Shell - "" = AutoRun
O33 - MountPoints2\{60210893-c5ae-11dc-863d-0013ced19ef5}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{613b763a-c73c-11df-8b6b-0013ced19ef5}\Shell - "" = AutoRun
O33 - MountPoints2\{613b763a-c73c-11df-8b6b-0013ced19ef5}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{6265d7aa-5bd1-11dc-856a-0013ced19ef5}\Shell - "" = AutoRun
O33 - MountPoints2\{6265d7aa-5bd1-11dc-856a-0013ced19ef5}\Shell\AutoRun\command - "" = C:\WINDOWS\explorer.exe -- [2008/04/14 18:30:36 | 001,038,336 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\{6a670ee2-4551-11de-88f2-00163624641f}\Shell - "" = AutoRun
O33 - MountPoints2\{6a670ee2-4551-11de-88f2-00163624641f}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{9c96631a-3284-11dd-870a-0013ced19ef5}\Shell\AutoRun\command - "" = G:\wd_windows_tools\setup.exe
O33 - MountPoints2\{af1e4050-c369-11dc-8639-0013ced19ef5}\Shell - "" = AutoRun
O33 - MountPoints2\{af1e4050-c369-11dc-8639-0013ced19ef5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{af1e4051-c369-11dc-8639-0013ced19ef5}\Shell - "" = AutoRun
O33 - MountPoints2\{af1e4051-c369-11dc-8639-0013ced19ef5}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{cf952148-16a2-11e0-8bf4-0013ced19ef5}\Shell\AutoRun\command - "" = Toshiba\more4you.exe
O33 - MountPoints2\{f54288c5-2942-11e0-8c07-0013ced19ef5}\Shell - "" = AutoRun
O33 - MountPoints2\{f54288c5-2942-11e0-8c07-0013ced19ef5}\Shell\AutoRun\command - "" = H:\cipralex.exe
O33 - MountPoints2\{fb2ce5c4-c2e6-11dc-8637-0013ced19ef5}\Shell - "" = AutoRun
O33 - MountPoints2\{fb2ce5c4-c2e6-11dc-8637-0013ced19ef5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{fb2ce5c5-c2e6-11dc-8637-0013ced19ef5}\Shell - "" = AutoRun
O33 - MountPoints2\{fb2ce5c5-c2e6-11dc-8637-0013ced19ef5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/09 20:56:07 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Theo Haris\Recent
[2011/02/09 20:52:51 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/02/09 20:50:48 | 003,006,368 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\ccsetup303.exe
[2011/02/09 20:35:42 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
[2011/02/09 20:00:49 | 000,189,520 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/02/09 19:58:55 | 001,912,872 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\HousecallLauncher.exe
[2011/02/09 19:57:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2011/02/09 19:57:15 | 000,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2011/02/07 01:43:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Quiz #3
[2011/02/04 12:42:56 | 000,071,680 | ---- | C] (Notebook Hardware Control) -- C:\WINDOWS\System32\drivers\nhcDriver.sys
[2011/02/04 12:42:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Application Data\Notebook Hardware Control
[2011/02/04 00:04:26 | 000,000,000 | ---D | C] -- C:\Program Files\Motherboard Monitor 5
[2011/02/03 23:57:59 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedFan
[2011/01/27 00:57:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Stefanos translations
[2011/01/18 21:01:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\Downloads
[2011/01/12 13:57:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Διορθώσεις Στέλιου
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/09 21:03:50 | 000,441,598 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\cc_20110209_210017.reg
[2011/02/09 20:53:10 | 000,000,590 | ---- | M] () -- C:\Documents and Settings\All Users\Επιφάνεια εργασίας\CCleaner.lnk
[2011/02/09 20:51:34 | 003,006,368 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\ccsetup303.exe
[2011/02/09 20:35:40 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
[2011/02/09 19:59:12 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\housecall.guid.cache
[2011/02/09 19:58:56 | 001,912,872 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\HousecallLauncher.exe
[2011/02/09 19:55:32 | 000,178,152 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\activescan2_en.exe
[2011/02/09 19:35:54 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2011/02/09 19:32:28 | 000,034,304 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/09 12:58:18 | 000,000,494 | ---- | M] () -- C:\WINDOWS\System32\eRLog.ini
[2011/02/09 12:57:22 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/09 12:53:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/09 12:53:40 | 000,341,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/09 12:53:38 | 1071,763,456 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/09 01:35:28 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2011/02/08 16:53:32 | 000,073,728 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\An Introduction.doc
[2011/02/08 01:59:30 | 000,075,264 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\8.1.11.doc
[2011/02/08 01:54:42 | 000,176,129 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Equity, Social Justice, and Sustainable.pdf
[2011/02/04 12:42:58 | 000,071,680 | ---- | M] (Notebook Hardware Control) -- C:\WINDOWS\System32\drivers\nhcDriver.sys
[2011/02/04 12:27:48 | 000,522,285 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\History of Yemen.pdf
[2011/02/03 23:58:00 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
[2011/02/03 18:26:26 | 001,123,328 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\KorelasMScGHRDissertation1.doc
[2011/02/03 14:37:32 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\prvlcl.dat
[2011/02/02 17:28:12 | 000,141,010 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\tc-yasi-31jan11-900utc.jpg
[2011/02/02 16:47:40 | 000,139,031 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Plastic river.jpg
[2011/02/02 16:38:38 | 000,585,728 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia- Greek.doc
[2011/02/02 14:34:36 | 000,702,464 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia jen revised.doc
[2011/01/28 15:46:26 | 000,295,451 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_guidelines_content-language.pdf
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/09 20:53:07 | 000,000,590 | ---- | C] () -- C:\Documents and Settings\All Users\Επιφάνεια εργασίας\CCleaner.lnk
[2011/02/09 19:59:10 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\housecall.guid.cache
[2011/02/09 19:55:34 | 000,178,152 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\activescan2_en.exe
[2011/02/08 16:53:56 | 000,073,728 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\An Introduction.doc
[2011/02/08 01:59:30 | 000,075,264 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\8.1.11.doc
[2011/02/08 01:54:43 | 000,176,129 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Equity, Social Justice, and Sustainable.pdf
[2011/02/04 12:27:44 | 000,522,285 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\History of Yemen.pdf
[2011/02/03 23:57:56 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo
[2011/02/02 17:28:08 | 000,141,010 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\tc-yasi-31jan11-900utc.jpg
[2011/02/02 16:47:37 | 000,139,031 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Plastic river.jpg
[2011/02/02 14:34:23 | 000,702,464 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia jen revised.doc
[2011/02/02 13:15:43 | 000,585,728 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia- Greek.doc
[2011/01/31 13:50:56 | 001,123,328 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\KorelasMScGHRDissertation1.doc
[2011/01/28 15:46:24 | 000,295,451 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_guidelines_content-language.pdf
[2010/02/28 05:12:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\prvlcl.dat
[2010/02/08 18:38:51 | 000,034,304 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/01 16:02:13 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\fusioncache.dat
[2010/01/26 23:06:44 | 000,082,289 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/01/11 20:09:21 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Game.INI
[2009/12/17 14:11:59 | 000,000,025 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\.119889580931711767808769176
[2009/12/17 14:10:09 | 000,000,021 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\.24554863501262644635642126105
[2009/10/07 01:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/08/25 04:14:35 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
[2009/08/20 23:51:10 | 000,758,272 | ---- | C] () -- C:\WINDOWS\System32\kcpp.dll
[2009/06/12 22:04:55 | 000,000,251 | ---- | C] () -- C:\WINDOWS\MugE.ini
[2009/03/29 15:09:11 | 000,000,367 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Application Data\flashfavorite.htm
[2009/02/28 16:37:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\ncvDS61.dll
[2009/02/28 16:37:36 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\ncCompress.dll
[2009/02/28 16:37:36 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ncUtil62.dll
[2009/02/28 16:37:31 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\nczlib.dll
[2009/02/28 16:37:31 | 000,053,760 | ---- | C] () -- C:\WINDOWS\System32\zlib32.dll
[2008/08/29 00:10:18 | 000,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008/08/29 00:10:17 | 000,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/07/10 01:30:59 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/06/15 18:53:21 | 000,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008/06/14 18:00:16 | 000,000,335 | ---- | C] () -- C:\WINDOWS\cookies.ini
[2008/06/10 23:40:22 | 000,000,000 | ---- | C] () -- C:\Program Files\temp01
[2008/05/26 22:22:52 | 000,017,986 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008/05/26 22:22:50 | 000,022,822 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008/05/26 22:22:48 | 000,017,066 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008/04/01 00:45:25 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008/02/08 00:59:16 | 000,241,664 | ---- | C] () -- C:\WINDOWS\NwtGatewayDLL.dll
[2008/02/08 00:59:16 | 000,001,110 | ---- | C] () -- C:\WINDOWS\NwtGatewayConfig.ini
[2007/10/25 00:40:19 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02D.ini
[2007/10/25 00:32:35 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02C.ini
[2007/10/24 23:18:19 | 000,000,187 | ---- | C] () -- C:\WINDOWS\RELATION.INI
[2007/10/24 22:55:10 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02B.ini
[2007/10/24 22:22:26 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02A.ini
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/04/15 14:21:23 | 000,000,683 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2007/04/11 21:12:12 | 000,001,387 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/10 16:09:23 | 000,000,258 | ---- | C] () -- C:\WINDOWS\QTW.ini
[2007/02/13 16:17:29 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2007/02/13 16:17:29 | 000,000,340 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2007/02/13 16:14:01 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2007/02/13 16:14:01 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2007/02/13 16:14:01 | 000,000,073 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2007/02/13 16:14:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\serauth2.dll
[2007/02/13 16:14:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\serauth1.dll
[2007/02/13 16:14:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nsprs.dll
[2006/11/23 17:36:56 | 000,000,031 | ---- | C] () -- C:\WINDOWS\warhead.ini
[2006/10/13 15:18:40 | 000,108,544 | ---- | C] () -- C:\WINDOWS\System32\vbis4032.dll
[2006/10/13 15:18:31 | 000,000,082 | ---- | C] () -- C:\WINDOWS\System32\lexiko.ini
[2006/09/30 15:44:20 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2006/08/18 21:24:10 | 000,005,509 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/08/18 21:24:10 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/07/26 02:57:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
[2006/07/17 17:22:43 | 000,007,224 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/07/17 04:06:41 | 000,000,265 | ---- | C] () -- C:\WINDOWS\scummvm.ini
[2006/07/16 00:49:43 | 000,000,319 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2006/07/16 00:39:27 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/07/16 00:34:16 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2006/07/16 00:34:11 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/07/15 20:44:44 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/07/15 18:17:57 | 000,000,494 | ---- | C] () -- C:\WINDOWS\System32\eRLog.ini
[2006/07/15 18:11:20 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2006/07/15 18:10:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NT.INI
[2006/07/15 18:09:01 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\SC_res.dll
[2006/07/15 18:09:01 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\EN_res.dll
[2006/07/15 18:09:01 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\TC_res.dll
[2006/07/15 18:09:01 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\MSNChatHook.dll
[2006/07/15 18:09:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\APISlice.dll
[2006/03/16 10:42:57 | 000,002,772 | ---- | C] () -- C:\WINDOWS\AntiV.INI
[2006/01/06 14:30:08 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/01/06 07:54:24 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIBUN4.dll
[2006/01/06 07:53:38 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMPEG2.dll
[2006/01/06 07:53:38 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMP3.dll
[2006/01/06 07:53:38 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIFCD3.dll
[2006/01/06 07:53:38 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTICDMK7.dll
[2006/01/06 07:26:26 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/12/14 20:59:52 | 000,000,038 | ---- | C] () -- C:\WINDOWS\Acer.ini
[2005/12/01 00:24:56 | 000,037,706 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/10/21 00:58:52 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\vspxvfw.dll
[2005/09/01 16:20:46 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\vspxcore.dll
[2005/05/02 12:13:42 | 000,009,600 | ---- | C] () -- C:\WINDOWS\System32\drivers\NETMNT.sys
[2005/03/28 00:45:26 | 000,000,093 | ---- | C] () -- C:\WINDOWS\ALaunch.ini
[2004/09/07 20:00:00 | 000,003,341 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/12/29 20:45:08 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ServiceControl.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/12/26 15:12:30 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll
[2001/09/03 22:46:38 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 15:33:56 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 21:04:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1996/04/03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2006/07/15 18:14:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acer
[2007/02/10 01:20:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2007/02/16 03:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/09/21 18:46:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Emotum
[2008/01/24 23:26:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Valusoft
[2008/06/11 01:26:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
[2008/09/29 14:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Games
[2008/10/06 23:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/10/10 22:27:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2008/12/06 23:43:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NevoSoft Games
[2009/03/14 06:06:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2009/03/14 06:12:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/12/17 14:10:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Final Draft
[2010/01/04 15:47:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\The Mirror Mysteries
[2010/01/10 23:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SulusGames
[2010/01/18 00:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\River Past G5
[2010/01/25 01:57:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/02/18 21:06:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ludia
[2010/05/29 22:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nifflas
[2010/08/03 18:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010/09/07 19:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/11 22:57:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2010/11/13 15:21:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeHideIP
[2010/11/13 15:30:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Arovax
[2010/11/26 00:58:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/11/26 13:55:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/11/26 14:09:50 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/12/16 01:22:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Clarus
[2006/07/15 18:14:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Acer
[2006/08/19 14:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\BitTorrent
[2006/09/30 16:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Image Zone Express
[2007/01/21 21:06:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\PlayFirst
[2007/01/31 19:36:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\BSplayer
[2007/03/01 14:09:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\BSplayer Pro
[2007/05/02 14:24:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\uTorrent
[2008/01/24 23:26:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Valusoft
[2008/02/08 00:59:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Bytemobile
[2008/02/08 00:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\ICS
[2008/02/08 01:06:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Vodafone Mobile Connect
[2008/06/11 00:01:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Home Sweet Home
[2008/09/05 21:24:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\DAEMON Tools
[2009/03/16 21:01:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Windows Desktop Search
[2009/03/16 21:05:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Windows Search
[2009/06/12 21:55:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\GetRight
[2009/09/02 18:46:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\GraveyardShift
[2009/09/20 18:26:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Flood Light Games
[2009/09/25 08:19:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Games
[2009/12/17 14:12:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Final Draft
[2009/12/24 12:42:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\com.adobe.example.avatarAirApplication.199ED43C2CFEB351CD0244628B93195D7C58F98C.1
[2010/01/10 23:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\SulusGames
[2010/01/10 23:11:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Enlightenus
[2010/01/11 20:20:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Orneon
[2010/01/17 21:30:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\WebCam Recorder
[2010/01/18 00:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\River Past G5
[2010/01/22 01:42:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\GetRightToGo
[2010/01/26 23:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Leadertech
[2010/02/12 00:34:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Free Mp3 Wma Ogg Converter
[2010/02/18 21:06:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Ludia
[2010/05/09 04:34:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\NotMyIp
[2010/05/09 16:53:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Hide IP NG
[2010/05/29 22:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Nifflas
[2010/08/04 00:07:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\ESET
[2010/09/25 04:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Big Fish Games
[2010/11/13 15:21:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\FreeHideIP
[2010/11/15 18:18:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Dropbox
[2010/11/17 13:29:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\PC Suite
[2010/11/17 13:29:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Nokia
[2010/11/26 14:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\AVG10
[2010/11/26 14:49:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\AVG
[2010/11/28 03:11:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Phenomenon 32 Saves
[2010/12/15 01:26:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\.minecraft
[2011/02/04 12:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Notebook Hardware Control

========== Purity Check ==========



< End of report >OTL Extras logfile created on: 9/2/2011 8:38:46 μμ - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000408 | Country: Ελλάδα | Language: ELL | Date Format: d/M/yyyy

1.022,00 Mb Total Physical Memory | 105,00 Mb Available Physical Memory | 10,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 51,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 44,37 Gb Total Space | 16,92 Gb Free Space | 38,12% Space Free | Partition Type: FAT32
Drive D: | 44,86 Gb Total Space | 12,13 Gb Free Space | 27,03% Space Free | Partition Type: FAT32
Drive G: | 1397,26 Gb Total Space | 1187,83 Gb Free Space | 85,01% Space Free | Partition Type: NTFS

Computer Name: ACER-92EDFFD6C3 | User Name: Theo Haris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Υπηρεσία κοινής χρήσης δικτύου του Windows Media Player

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"F:\eMule\emule.exe" = F:\eMule\emule.exe:*:Enabled:eMule
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk -- (Google)
"C:\Documents and Settings\Theo Haris\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Theo Haris\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin -- (Google)
"C:\Documents and Settings\Theo Haris\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Theo Haris\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" = C:\Program Files\ATI Technologies\ATI.ACE\cli.exe:*:Enabled:CLI Application (Command Line Interface) -- (ATI Technologies Inc.)
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- ()
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"E:\HIW\stInstall.exe" = E:\HIW\stInstall.exe:*:Enabled:Thomson Home Install Wizard
"C:\Program Files\Logitech\Logitech Vid\Vid.exe" = C:\Program Files\Logitech\Logitech Vid\Vid.exe:*:Enabled:Logitech Vid -- (Logitech Inc.)
"C:\Documents and Settings\Theo Haris\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Theo Haris\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- ()
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:ľTorrent -- (BitTorrent, Inc.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{089DD780-DB3F-4CDB-A0C2-111360247298}" = PC Connectivity Solution
"{0A053D60-9267-11D5-8A2B-0050DA8B7D89}" = Planescape - Torment
"{10F0C60A-6CF4-4D10-8B85-B5D43DCC69F5}_is1" = The Strange and Somewhat Sinister Tale of the House at Desert B
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15B70821-7893-4607-805A-BB80F3EA8279}" = Acer Empowering Technology framework
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{1B9B5B3B-28E7-4E59-A80D-D670AA984514}" = Nokia Connectivity Cable Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}" = Nokia PC Suite
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 21
"{281D28EC-1357-4778-B2D7-DEA56D70EF96}" = Logitech High Quality Video
"{2EAF7E61-068E-11DF-953C-005056806466}" = Google Earth
"{350C9408-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{385979FE-DC4F-4140-8EAD-A59625000D72}" = NTI Backup NOW! 4
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{3D9E9EB7-B14F-4AE4-8C1F-1AD4CF3093BE}" = Microsoft .NET Framework 1.1 Greek Language Pack
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{45235788-142C-44BE-8A4D-DDE9A84492E5}" = AGEIA PhysX v7.09.13
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AFC0F3B-0678-44F5-A70C-FACE61310F27}" = Enhancer
"{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{5607C1B8-DA2B-31D0-93A6-968D8C23A944}" = Microsoft .NET Framework 3.5 Language Pack SP1 - ell
"{57481C12-C102-395A-8BC3-941F2D79A114}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - ELL
"{57D9FDCA-B3DF-4637-902F-857B56FF8273}" = STELLA 9.0.1
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{591C113C-8D3B-4FEC-AF5E-36F0DFEEA8C0}" = Cooking Academy
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5EFDFC8B-D438-4792-A298-E87AA9ADA816}" = Acer eDataSecurity Management
"{63A6E9A9-A190-46D4-9430-2DB28654AFD8}" = Norton 360
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6AA26B7C-7C26-33B4-88DD-431CB7C94742}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - ELL
"{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}" = Acer eLock Management
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78D62D17-D970-42DA-B8CF-5E5576293B33}" = Final Draft 7
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86ACFE52-BE3A-4E54-840F-D031339825AD}" = ATI Catalyst Control Center
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{901F0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Proofing Tools
"{9977BB98-D0E6-4850-A3BF-2BD8CFB9D794}" = Βοηθός εισόδου του Windows Live
"{9A18357B-5DA5-4F33-8037-19E528DD2F5B}" = isee Player 9.0.1
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A276502A-8979-44FB-8090-90CF72F22ABC}" = AVG 2011
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A589DA26-51BD-475D-8C32-E19E34145842}" = Camtasia Studio 6
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9D65D46-3708-4F5B-9117-0199C7098D11}" = WanMiniport1st
"{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}" = Join Air
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BBF6D0CD-A081-369F-B0B8-F168594CBB6B}" = Google Talk Plugin
"{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2784EF8-89B9-4992-935B-389F225AD377}" = Vodafone Mobile Connect
"{D458BBDC-0363-42E0-8FF9-4736E3CB3CA2}" = Acer Screensaver
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DB8CEC42-30B1-4F49-BD06-9393EB81CCF7}" = SPSS 13.0 for Windows
"{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}" = ccCommon
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{DEE08946-40F0-4890-853E-60A6C3306041}" = Acer ePerformance Management
"{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}" = Acer eSettings Management
"{E431C518-2EE2-471E-9234-BE995C36D513}" = Acer eDataSecurity Management 1.00.23
"{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton AntiVirus Parent MSI
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype・5.0
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EA4FA30B-7321-4428-90E9-28B088EC8DC9}" = Runtime 8.0 Libraries
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4C68898-EBA5-46A9-82B3-2D30426086BF}" = AVG 2011
"{F4E74C05-CD77-4422-B5BB-E82693EE2FA3}" = iSpQ VideoChat 8.0
"{FB91E774-867B-4567-ACE7-8144EF036068}" = Olympus Digital Wave Player
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"34EA302E7F4CBD17A19E33BBCB72363234956D7E" = Πακέτο προγραμμάτων οδήγησης των Windows - Nokia Modem (06/09/2010 4.5)
"504244733D18C8F63FF584AEB290E3904E791693" = Πακέτο προγραμμάτων οδήγησης των Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"All ATI Software" = ATI - Βοηθητικό πρόγραμμα απεγκατάστασης λογισμικού
"ATI Display Driver" = ATI Display Driver
"AVG" = AVG 2011
"BFGC" = Big Fish Games: Game Manager
"BFG-Cooking Dash" = Cooking Dash
"BFG-Home Sweet Home" = Home Sweet Home
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_AcrS009E" = HDAUDIO Soft Data Fax Modem with SmartCP
"Cooking Academy 2 World Cuisine1.0.1" = Cooking Academy 2 World Cuisine
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"EEEE705096F837B7907659F100C9FE6DA001970F" = Πακέτο προγραμμάτων οδήγησης των Windows - Nokia Modem (06/09/2010 7.01.0.7)
"ePresentation" = Acer ePresentation Management
"Farm Craft1.0.5" = Farm Craft
"Farm Frenzy 2_is1" = Farm Frenzy 2
"Farm Mania1.0" = Farm Mania
"GridVista" = Acer GridVista
"Hot Dish 2 Cross Country Cook-off 1.00" = Hot Dish 2 Cross Country Cook-off 1.00
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{15B70821-7893-4607-805A-BB80F3EA8279}" = Acer Empowering Technology framework
"InstallShield_{385979FE-DC4F-4140-8EAD-A59625000D72}" = NTI Backup NOW! 4
"InstallShield_{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}" = Acer eLock Management
"InstallShield_{DEE08946-40F0-4890-853E-60A6C3306041}" = Acer ePerformance Management
"InstallShield_{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}" = Acer eSettings Management
"KLiteCodecPack_is1" = K-Lite Codec Pack 2.72 Full
"LHTTSENG" = L&H TTS3000 British English
"LManager" = Launch Manager
"lvdrivers_12.10" = Πακέτο προγράμματος οδήγησης του Logitech Webcam Software
"MEL" = MEL
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - ell" = Πακέτο γλώσσας του Microsoft .NET Framework 3.5 SP1 - ELL
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia PC Suite" = Nokia PC Suite
"ProInst" = Intel® PROSet/Wireless Software
"RealPlayer 6.0" = RealPlayer
"Recuva" = Recuva (remove only)
"Simtegra.MapSys.1.5_is1" = MapSys 1.5
"Starcraft" = Starcraft
"SymSetup.{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2005 (Symantec Corporation)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"The Rosetta Stone" = The Rosetta Stone
"uTorrent" = ľTorrent
"VLC media player" = VLC media player 0.9.8a
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WMV9_VCM" = Microsoft Windows Media Video 9 VCM
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 28/11/2010 6:26:25 μμ | Computer Name = ACER-92EDFFD6C3 | Source = Application Error | ID = 1000
Description = Ελαττωματική εφαρμογή phenomenon 32.exe, έκδοση 0.0.0.0, ελαττωματική
λειτουργική μονάδα ntdll.dll, έκδοση 5.1.2600.5755, ελαττωματική διεύθυνση 0x0001168b.

Error - 3/12/2010 7:03:58 μμ | Computer Name = ACER-92EDFFD6C3 | Source = PerfNet | ID = 2004
Description = Δεν είναι δυνατό το άνοιγμα της υπηρεσίας διακομιστή. Δεν θα επιστραφούν
δεδομένα
για τις επιδόσεις του διακομιστή. Ο κωδικός σφάλματος που επιστράφηκε βρίσκεται
στα δεδομένα DWORD 0.

Error - 6/12/2010 8:53:04 πμ | Computer Name = ACER-92EDFFD6C3 | Source = PerfNet | ID = 2004
Description = Δεν είναι δυνατό το άνοιγμα της υπηρεσίας διακομιστή. Δεν θα επιστραφούν
δεδομένα
για τις επιδόσεις του διακομιστή. Ο κωδικός σφάλματος που επιστράφηκε βρίσκεται
στα δεδομένα DWORD 0.

Error - 8/12/2010 9:41:07 πμ | Computer Name = ACER-92EDFFD6C3 | Source = Microsoft Office 11 | ID = 1000
Description = Faulting application excel.exe, version 11.0.8328.0, stamp 4c717ddb,
faulting module olconnector.dll, version 2.0.2313.0, stamp 491c07db, debug? 0,
fault address 0x0001152b.

Error - 8/12/2010 9:41:19 πμ | Computer Name = ACER-92EDFFD6C3 | Source = Microsoft Office 11 | ID = 2001
Description = Rejected Safe Mode action : Microsoft Office Excel.

Error - 15/12/2010 8:23:13 μμ | Computer Name = ACER-92EDFFD6C3 | Source = Application Error | ID = 1000
Description = Ελαττωματική εφαρμογή plugin-container.exe, έκδοση 1.9.2.3989, ελαττωματική
λειτουργική μονάδα ntdll.dll, έκδοση 5.1.2600.5755, ελαττωματική διεύθυνση 0x0000100b.

Error - 18/1/2011 12:14:01 μμ | Computer Name = ACER-92EDFFD6C3 | Source = Application Error | ID = 1000
Description = Ελαττωματική εφαρμογή mel.exe, έκδοση 1.0.0.0, ελαττωματική λειτουργική
μονάδα gtlist32.ocx, έκδοση 1.0.0.19, ελαττωματική διεύθυνση 0x0000f31b.

Error - 28/1/2011 1:45:26 μμ | Computer Name = ACER-92EDFFD6C3 | Source = PerfNet | ID = 2004
Description = Δεν είναι δυνατό το άνοιγμα της υπηρεσίας διακομιστή. Δεν θα επιστραφούν
δεδομένα
για τις επιδόσεις του διακομιστή. Ο κωδικός σφάλματος που επιστράφηκε βρίσκεται
στα δεδομένα DWORD 0.

Error - 2/2/2011 7:04:36 πμ | Computer Name = ACER-92EDFFD6C3 | Source = PerfNet | ID = 2004
Description = Δεν είναι δυνατό το άνοιγμα της υπηρεσίας διακομιστή. Δεν θα επιστραφούν
δεδομένα
για τις επιδόσεις του διακομιστή. Ο κωδικός σφάλματος που επιστράφηκε βρίσκεται
στα δεδομένα DWORD 0.

Error - 2/2/2011 7:19:43 μμ | Computer Name = ACER-92EDFFD6C3 | Source = PerfNet | ID = 2004
Description = Δεν είναι δυνατό το άνοιγμα της υπηρεσίας διακομιστή. Δεν θα επιστραφούν
δεδομένα
για τις επιδόσεις του διακομιστή. Ο κωδικός σφάλματος που επιστράφηκε βρίσκεται
στα δεδομένα DWORD 0.

[ System Events ]
Error - 8/2/2011 10:47:01 πμ | Computer Name = ACER-92EDFFD6C3 | Source = Service Control Manager | ID = 7009
Description = Χρονικό όριο αναμονής (30000 χιλιοστά του δευτερολέπτου) για τη σύνδεση
της υπηρεσίας Eset Trial Reset.

Error - 8/2/2011 10:47:01 πμ | Computer Name = ACER-92EDFFD6C3 | Source = Service Control Manager | ID = 7000
Description = Δεν ήταν δυνατή η εκκίνηση της υπηρεσίας Eset Trial Reset εξαιτίας
του ακόλουθου σφάλματος: %%1053

Error - 8/2/2011 10:47:05 πμ | Computer Name = ACER-92EDFFD6C3 | Source = Service Control Manager | ID = 7026
Description = Απέτυχε η φόρτωση των ακόλουθων προγραμμάτων οδήγησης της εκκίνησης
του υπολογιστή ή της εκκίνησης του συστήματος: nhcDriverDevice

Error - 8/2/2011 7:14:19 μμ | Computer Name = ACER-92EDFFD6C3 | Source = Service Control Manager | ID = 7009
Description = Χρονικό όριο αναμονής (30000 χιλιοστά του δευτερολέπτου) για τη σύνδεση
της υπηρεσίας Eset Trial Reset.

Error - 8/2/2011 7:14:19 μμ | Computer Name = ACER-92EDFFD6C3 | Source = Service Control Manager | ID = 7000
Description = Δεν ήταν δυνατή η εκκίνηση της υπηρεσίας Eset Trial Reset εξαιτίας
του ακόλουθου σφάλματος: %%1053

Error - 8/2/2011 7:14:34 μμ | Computer Name = ACER-92EDFFD6C3 | Source = Service Control Manager | ID = 7026
Description = Απέτυχε η φόρτωση των ακόλουθων προγραμμάτων οδήγησης της εκκίνησης
του υπολογιστή ή της εκκίνησης του συστήματος: nhcDriverDevice

Error - 9/2/2011 6:57:10 πμ | Computer Name = ACER-92EDFFD6C3 | Source = Service Control Manager | ID = 7009
Description = Χρονικό όριο αναμονής (30000 χιλιοστά του δευτερολέπτου) για τη σύνδεση
της υπηρεσίας Eset Trial Reset.

Error - 9/2/2011 6:57:10 πμ | Computer Name = ACER-92EDFFD6C3 | Source = Service Control Manager | ID = 7000
Description = Δεν ήταν δυνατή η εκκίνηση της υπηρεσίας Eset Trial Reset εξαιτίας
του ακόλουθου σφάλματος: %%1053

Error - 9/2/2011 6:57:10 πμ | Computer Name = ACER-92EDFFD6C3 | Source = Service Control Manager | ID = 7009
Description = Χρονικό όριο αναμονής (30000 χιλιοστά του δευτερολέπτου) για τη σύνδεση
της υπηρεσίας AdminWorks Agent X6.

Error - 9/2/2011 6:57:49 πμ | Computer Name = ACER-92EDFFD6C3 | Source = Service Control Manager | ID = 7026
Description = Απέτυχε η φόρτωση των ακόλουθων προγραμμάτων οδήγησης της εκκίνησης
του υπολογιστή ή της εκκίνησης του συστήματος: nhcDriverDevice


< End of report >

Edited by Theo Haris, 09 February 2011 - 01:52 PM.

  • 0

Advertisements


#2
michaelg9

michaelg9

    Trusted Helper

  • Malware Removal
  • 2,949 posts
Hi ;)
:D . My name is Michael and I am here to help you fix your computer. :D
If you have already received help elsewhere please inform me so that this topic can be closed.
If you haven't, please keep reading:
Note: Before we start the process you should:
  • POST your logs, don't attach them, as it makes it harder to read.
  • Save or print these instructions as a part of the fix will be in safe mode where you will not be able to access the internet.
  • Disable ANY programs that offer real-time protection features while executing my instructions. That includes your antivirus, antispyware, windows defender or any other program that offers protection. When you're clean or waiting for my next set of instructions, re-enable them .If you need any help disabling them, ask.
  • Each time I instruct you to download a file to use it, please do it even if I have told you before to download it again. This is because these tools are frequently updated to detect newer infections.
  • Last, as most of the tools we use here need administrative rights in order to function properly, I expect that you will be running them from an administrator account.


Sorry for the late replay. Κανένα πρόβλημα με τα ελληνικά :D

There are some nasties lurking in there....


Warning!!
You have an information stealing trojan installed on your computer.
Backdoor Trojans, IRCBots, keyloggers and Infostealers are very dangerous because they provide a way of accessing a computer system that bypasses security mechanisms and can steal sensitive information like passwords, personal and financial data which they send back to the hacker. Remote attackers use backdoor Trojans as part of an exploit to to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, I suggest you do the following.
  • All passwords should be changed to include those used for banking, email, eBay and forums. You should consider them to be compromised. They should be changed using a different computer and not the infected one. If you use the infected computer, an attacker may get the new passwords and transaction information.
  • Banking and credit card institutions should be notified of the possible security breach.


Next:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    SRV - File not found [Disabled | Stopped] -- -- (gupdate1c998781007dfbe) Google Update Service (gupdate1c998781007dfbe)
    FF - prefs.js..network.proxy.share_proxy_settings: true
    [2010/02/12 00:33:58 | 000,000,000 | ---D | M] (Zwunzi) -- C:\Program Files\Mozilla Firefox\extensions\{F270F1AF-34D6-41CB-A9F5-8200EF7DB41F}
    [2010/02/12 00:33:58 | 000,002,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zwunzi14.xml
    [2010/02/12 01:00:58 | 000,002,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zwunzi141.xml
    O1 - Hosts: 127.0.0.1 activate.adobe.com
    O2 - BHO: (no name) - {0CF5D165-517E-48B6-B3C7-3054A24F8BF6} - File not found
    O2 - BHO: (no name) - {B7FC60D5-AB79-477E-96EE-5C7770EAEAB9} - File not found
    O4 - HKCU..\Run: [yahoo!] C:\Documents and Settings\Theo Haris\Local Settings\Temp\16967197Wsy.dll (Blizzard Entertainment)
    O4 - Startup: C:\Documents and Settings\Theo Haris\Start Menu\Προγράμματα\Εκκίνηση\new1.exe (Blizzard Entertainment)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O20 - Winlogon\Notify\cbXrPFXn: DllName - cbXrPFXn.dll - File not found
    O28 - HKLM ShellExecuteHooks: {0CF5D165-517E-48B6-B3C7-3054A24F8BF6} - File not found
    O33 - MountPoints2\{220c1ed0-b7a8-11db-849c-eaf2d30bfb47}\Shell\AutoRun\command - "" = F:\JDSecure\Windows\JDSecure31.exe
    O33 - MountPoints2\{23f54bcc-ceca-11de-89fd-0013ced19ef5}\Shell\AutoRun\command - "" = F:\__DTMEDIA\DTMedia.exe
    O33 - MountPoints2\{402b7953-68c4-11db-8422-0013ced19ef5}\Shell\AutoRun\command - "" = G:\setupSNK.exe
    O33 - MountPoints2\{402b7954-68c4-11db-8422-0013ced19ef5}\Shell - "" = AutoRun
    O33 - MountPoints2\{402b7954-68c4-11db-8422-0013ced19ef5}\Shell\AutoRun\command - "" = F:\LaunchU3.exe
    O33 - MountPoints2\{60210892-c5ae-11dc-863d-0013ced19ef5}\Shell - "" = AutoRun
    O33 - MountPoints2\{60210892-c5ae-11dc-863d-0013ced19ef5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{60210893-c5ae-11dc-863d-0013ced19ef5}\Shell - "" = AutoRun
    O33 - MountPoints2\{60210893-c5ae-11dc-863d-0013ced19ef5}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{613b763a-c73c-11df-8b6b-0013ced19ef5}\Shell - "" = AutoRun
    O33 - MountPoints2\{613b763a-c73c-11df-8b6b-0013ced19ef5}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
    O33 - MountPoints2\{6265d7aa-5bd1-11dc-856a-0013ced19ef5}\Shell - "" = AutoRun
    O33 - MountPoints2\{6265d7aa-5bd1-11dc-856a-0013ced19ef5}\Shell\AutoRun\command - "" = C:\WINDOWS\explorer.exe -- [2008/04/14 18:30:36 | 001,038,336 | ---- | M] (Microsoft Corporation)
    O33 - MountPoints2\{6a670ee2-4551-11de-88f2-00163624641f}\Shell - "" = AutoRun
    O33 - MountPoints2\{6a670ee2-4551-11de-88f2-00163624641f}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{9c96631a-3284-11dd-870a-0013ced19ef5}\Shell\AutoRun\command - "" = G:\wd_windows_tools\setup.exe
    O33 - MountPoints2\{af1e4050-c369-11dc-8639-0013ced19ef5}\Shell - "" = AutoRun
    O33 - MountPoints2\{af1e4050-c369-11dc-8639-0013ced19ef5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{af1e4051-c369-11dc-8639-0013ced19ef5}\Shell - "" = AutoRun
    O33 - MountPoints2\{af1e4051-c369-11dc-8639-0013ced19ef5}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{cf952148-16a2-11e0-8bf4-0013ced19ef5}\Shell\AutoRun\command - "" = Toshiba\more4you.exe
    O33 - MountPoints2\{f54288c5-2942-11e0-8c07-0013ced19ef5}\Shell - "" = AutoRun
    O33 - MountPoints2\{f54288c5-2942-11e0-8c07-0013ced19ef5}\Shell\AutoRun\command - "" = H:\cipralex.exe
    O33 - MountPoints2\{fb2ce5c4-c2e6-11dc-8637-0013ced19ef5}\Shell - "" = AutoRun
    O33 - MountPoints2\{fb2ce5c4-c2e6-11dc-8637-0013ced19ef5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    O33 - MountPoints2\{fb2ce5c5-c2e6-11dc-8637-0013ced19ef5}\Shell - "" = AutoRun
    O33 - MountPoints2\{fb2ce5c5-c2e6-11dc-8637-0013ced19ef5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
    [10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2011/02/03 14:37:32 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\prvlcl.dat
    [2010/02/28 05:12:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\prvlcl.dat
    [2009/12/17 14:11:59 | 000,000,025 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\.119889580931711767808769176
    [2009/12/17 14:10:09 | 000,000,021 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\.24554863501262644635642126105
    [2008/06/10 23:40:22 | 000,000,000 | ---- | C] () -- C:\Program Files\temp01
    [2007/02/13 16:17:29 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
    [2007/02/13 16:17:29 | 000,000,340 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
    [2007/02/13 16:14:01 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
    [2007/02/13 16:14:01 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
    [2007/02/13 16:14:01 | 000,000,073 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
    [2007/02/13 16:14:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\serauth2.dll
    [2007/02/13 16:14:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\serauth1.dll
    [2007/02/13 16:14:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nsprs.dll
    [2006/01/06 07:54:24 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIBUN4.dll
    [2006/01/06 07:53:38 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMPEG2.dll
    [2006/01/06 07:53:38 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMP3.dll
    [2006/01/06 07:53:38 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIFCD3.dll
    [2006/01/06 07:53:38 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTICDMK7.dll

    :Services

    :Reg

    :Files

    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.


Next:

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
  • 0

#3
Theo Haris

Theo Haris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Hi Michael!

I can't thank you enough for your help...

I attach below the new OTL and Combofix logs.

Can you tell me if there's a way to know who/when/how the Keylogger was installed?

Thanks!
Theoharis


~*~

OTL logfile created on: 13/2/2011 5:17:16 μμ - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000408 | Country: Ελλάδα | Language: ELL | Date Format: d/M/yyyy

1.022,00 Mb Total Physical Memory | 536,00 Mb Available Physical Memory | 52,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 44,37 Gb Total Space | 20,47 Gb Free Space | 46,13% Space Free | Partition Type: FAT32
Drive D: | 44,86 Gb Total Space | 9,94 Gb Free Space | 22,16% Space Free | Partition Type: FAT32
Drive G: | 1397,26 Gb Total Space | 1184,18 Gb Free Space | 84,75% Space Free | Partition Type: NTFS

Computer Name: ACER-92EDFFD6C3 | User Name: Theo Haris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/13 16:18:48 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
PRC - [2010/03/26 10:13:54 | 000,136,840 | ---- | M] () -- C:\Program Files\Join Air\UIExec.exe
PRC - [2010/03/26 09:59:00 | 000,251,016 | ---- | M] () -- C:\Program Files\Join Air\AssistantServices.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/11/13 09:33:54 | 000,097,128 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
PRC - [2008/04/14 18:30:36 | 001,038,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/21 11:30:44 | 000,061,440 | ---- | M] () -- C:\Program Files\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
PRC - [2006/08/31 16:52:06 | 000,118,784 | ---- | M] (Bytemobile, Inc.) -- C:\WINDOWS\system32\bmwebcfg.exe
PRC - [2005/12/01 17:38:38 | 000,458,752 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\QtZgAcer.EXE
PRC - [2005/11/25 15:59:44 | 000,212,992 | ---- | M] (Acer Inc) -- C:\Acer\Empowering Technology\ePower\epm-dm.exe
PRC - [2005/11/16 17:00:50 | 000,397,312 | ---- | M] (acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\Monitor.exe
PRC - [2005/11/09 22:01:00 | 000,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2005/11/09 21:59:08 | 000,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2005/11/09 21:58:26 | 000,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2005/10/24 16:45:32 | 002,462,208 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admtray.exe
PRC - [2005/10/24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admServ.exe
PRC - [2005/10/19 09:30:16 | 000,069,632 | ---- | M] (HiTRUST) -- C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
PRC - [2005/01/07 16:17:16 | 000,102,491 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004/08/09 06:03:38 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () -- C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe


========== Modules (SafeList) ==========

MOD - [2011/02/13 16:18:48 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
MOD - [2010/08/23 19:12:06 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2005/12/05 16:00:10 | 000,053,248 | ---- | M] (HiTRUST) -- C:\WINDOWS\system32\sysenv.dll
MOD - [2005/08/24 01:24:00 | 000,010,752 | ---- | M] () -- C:\WINDOWS\system32\MSNChatHook.dll
MOD - [2005/01/07 16:17:08 | 000,069,723 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll
MOD - [2003/03/18 21:12:12 | 001,047,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MFC71u.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (Pcmrome)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Disabled | Stopped] -- -- (gupdate1c998781007dfbe) Google Update Service (gupdate1c998781007dfbe)
SRV - File not found [Disabled | Stopped] -- -- (CLTNetCnService)
SRV - File not found [Disabled | Stopped] -- -- (ccSetMgr)
SRV - File not found [Disabled | Stopped] -- -- (ccPwdSvc)
SRV - File not found [Disabled | Stopped] -- -- (ccEvtMgr)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2010/06/14 15:07:14 | 000,615,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010/03/26 09:59:00 | 000,251,016 | ---- | M] () [Auto | Running] -- C:\Program Files\Join Air\AssistantServices.exe -- (UI Assistant Service)
SRV - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2006/08/31 16:52:06 | 000,118,784 | ---- | M] (Bytemobile, Inc.) [Auto | Running] -- C:\WINDOWS\System32\bmwebcfg.exe -- (bmwebcfg)
SRV - [2005/11/14 01:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2005/11/09 22:01:00 | 000,540,745 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2005/11/09 21:59:08 | 000,114,753 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2005/11/09 21:58:26 | 000,217,164 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2005/10/24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) [Auto | Running] -- C:\Acer\Empowering Technology\admServ.exe -- (AWService)
SRV - [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2004/09/07 20:00:00 | 000,003,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\System32\regedt32.exe -- (.EsetTrialReset)
SRV - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe -- (Network WanMiniport First Position)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2011/02/04 12:42:58 | 000,071,680 | ---- | M] (Notebook Hardware Control) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\nhcDriver.sys -- (nhcDriverDevice)
DRV - [2010/02/26 14:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010/02/26 14:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010/02/26 14:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/02/26 14:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009/10/29 19:28:24 | 000,009,216 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter.sys -- (massfilter)
DRV - [2009/10/07 10:49:50 | 000,023,832 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
DRV - [2009/10/07 10:49:38 | 006,756,632 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 120(UVC)
DRV - [2009/10/07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009/09/25 08:05:20 | 000,278,984 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2009/01/06 20:07:28 | 000,124,464 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2008/09/05 21:25:04 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008/08/29 00:10:18 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/04/13 20:36:40 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 20:36:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 18:36:06 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2006/10/16 14:45:26 | 000,088,960 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2006/08/31 16:58:22 | 000,018,560 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2006/01/06 07:53:34 | 000,006,144 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV - [2006/01/04 07:46:42 | 001,420,288 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/11/17 15:45:40 | 004,069,888 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/11/09 14:45:56 | 000,013,440 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2005/10/23 19:20:52 | 000,218,496 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/10/18 01:53:24 | 000,998,656 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/10/18 01:52:30 | 000,721,280 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/10/15 18:20:44 | 000,012,106 | ---- | M] (OSA Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\OsaFsLoc.sys -- (OsaFsLoc)
DRV - [2005/09/29 20:11:42 | 000,078,720 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2005/09/13 15:34:40 | 000,004,392 | ---- | M] (OSA Technologies) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NdisFilt.sys -- (NdisFilt)
DRV - [2005/09/11 19:49:44 | 003,298,432 | ---- | M] (IntelŽ Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2005/06/30 16:58:24 | 000,007,296 | ---- | M] (OSA Technologies, An Avocent Company) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio)
DRV - [2005/05/02 12:13:42 | 000,009,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETMNT.sys -- (NETMNT)
DRV - [2005/04/07 18:08:46 | 000,078,208 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-shd.sys -- (EpmShd)
DRV - [2005/01/14 15:57:16 | 000,004,010 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm)
DRV - [2005/01/13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys)
DRV - [2005/01/07 16:03:42 | 000,191,456 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2004/12/08 14:10:00 | 000,016,896 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2004/09/07 20:00:00 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2004/09/07 20:00:00 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2004/09/07 20:00:00 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2004/09/07 20:00:00 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2004/09/07 20:00:00 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2004/09/07 20:00:00 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2004/09/07 20:00:00 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2004/09/07 20:00:00 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2004/09/07 20:00:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2004/09/07 20:00:00 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2004/09/07 20:00:00 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2004/09/07 20:00:00 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2004/09/07 20:00:00 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2004/09/07 20:00:00 | 000,006,784 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
DRV - [2004/09/07 20:00:00 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2004/07/19 13:10:00 | 000,004,096 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-psd.sys -- (EpmPsd)
DRV - [2004/06/26 13:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vncdrv.sys -- (vncdrv)
DRV - [2004/03/08 12:55:50 | 000,013,567 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)
DRV - [2003/12/15 18:22:00 | 000,038,448 | ---- | M] (OLYMPUS OPTICAL CO.,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VNUSB.sys -- (VNUSB)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://e-learning.hau.gr/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "en.wikipedia.org"
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.48.3
FF - prefs.js..extensions.enabledItems: {3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}:0.9.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.7
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.7.4
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: [email protected]:2.4.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.732
FF - prefs.js..network.proxy.type: 0

FF - user.js..network.proxy.type: 0
FF - user.js..network.proxy.http: ""
FF - user.js..network.proxy.http_port: 0
FF - user.js..network.proxy.ssl: ""
FF - user.js..network.proxy.ssl_port: 0
FF - user.js..network.proxy.ftp: ""
FF - user.js..network.proxy.ftp_port: 0
FF - user.js..network.proxy.gopher: ""
FF - user.js..network.proxy.gopher_port: 0
FF - user.js..network.proxy.socks_version: 5
FF - user.js..network.proxy.socks: ""
FF - user.js..network.proxy.socks_port: 0

FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/11/17 13:28:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2006/07/15 20:42:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2006/07/15 20:42:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2008/08/29 02:37:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Extensions
[2006/07/15 20:49:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions
[2011/02/10 21:53:34 | 000,000,000 | ---D | M] (Session Manager) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2011/01/07 13:33:32 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2008/05/22 19:44:28 | 000,000,000 | ---D | M] (Forecastbar Enhanced) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}
[2011/02/03 14:20:48 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/04/29 18:32:16 | 000,000,000 | ---D | M] (Tamper Data) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2010/09/10 02:45:26 | 000,000,000 | ---D | M] (WOT) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/01/12 14:03:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/12/27 00:48:18 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/09/07 14:58:42 | 000,000,000 | ---D | M] ("BetterPrivacy") -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010/06/18 13:12:38 | 000,000,000 | ---D | M] ("Tab Mix Plus") -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2011/01/27 19:16:54 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/11/22 23:18:32 | 000,000,000 | ---D | M] (Ghostery) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\[email protected]
[2008/11/04 20:21:56 | 000,005,179 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\searchplugins\BitTorrent.xml
[2006/07/15 20:42:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/25 19:35:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/04/19 15:02:14 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/17 13:28:06 | 000,000,000 | ---D | M] (PC Sync 2 Synchronisation Extension) -- C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC
[2009/03/16 21:28:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2007/01/04 02:29:08 | 000,049,152 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/08/03 18:40:56 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/08/03 18:40:56 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/08/03 18:40:56 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/08/03 18:40:56 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/02/13 17:10:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe (Acer Value Labs, Taiwan)
O4 - HKLM..\Run: [ADMTray.exe] C:\Acer\Empowering Technology\admtray.exe (Avocent Inc.)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe (HiTRUST)
O4 - HKLM..\Run: [EPM-DM] c:\Acer\Empowering Technology\ePower\epm-dm.exe (Acer Inc)
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe (acer Inc.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [UIExec] C:\Program Files\Join Air\UIExec.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Sample Toolband Serach - C:\WINDOWS\System32\ToolBand.dll (HiTRUST)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1152986441640 (MUWebControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Τρέχουσα αρχική σελίδα) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/20 23:33:42 | 000,000,065 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2006/01/06 07:54:00 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.FRK -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/13 17:02:52 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/02/13 16:59:54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/02/13 16:59:54 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/02/13 16:59:54 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/02/13 16:59:54 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/02/13 16:59:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/02/13 16:39:34 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/02/13 16:30:09 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/02/13 16:18:49 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
[2011/02/09 20:56:07 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Theo Haris\Recent
[2011/02/09 20:52:51 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/02/09 19:57:15 | 000,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2011/02/07 01:43:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Quiz #3
[2011/02/04 12:42:56 | 000,071,680 | ---- | C] (Notebook Hardware Control) -- C:\WINDOWS\System32\drivers\nhcDriver.sys
[2011/02/04 12:42:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Application Data\Notebook Hardware Control
[2011/02/04 00:04:26 | 000,000,000 | ---D | C] -- C:\Program Files\Motherboard Monitor 5
[2011/02/03 23:57:59 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedFan
[2011/01/27 00:57:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Stefanos translations
[2011/01/21 16:44:06 | 000,441,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shimgvw.dll
[2011/01/18 21:01:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\Downloads

========== Files - Modified Within 30 Days ==========

[2011/02/13 17:16:32 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\~$Help.rtf
[2011/02/13 17:12:20 | 000,000,546 | ---- | M] () -- C:\WINDOWS\System32\eRLog.ini
[2011/02/13 17:10:44 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/13 17:09:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/13 17:09:32 | 1071,763,456 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/13 17:02:58 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/02/13 16:21:52 | 004,267,346 | R--- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\ComboFix.exe
[2011/02/13 16:18:48 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
[2011/02/13 16:15:24 | 000,012,369 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Help.rtf
[2011/02/13 13:05:48 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Η εξέγερση στην Αίγυπτο.doc
[2011/02/13 11:51:20 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2011/02/13 03:58:32 | 000,466,254 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Tali-riding-on-crescent-moon-p192w250.psd
[2011/02/12 19:52:34 | 000,053,731 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\n539515072_373915_9429.jpg
[2011/02/12 19:43:38 | 000,020,574 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\woman-riding-on-crescent-moon-p192w250.jpg
[2011/02/12 16:38:00 | 090,387,384 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Easy Star All-Stars - Dub Side Of The Moon.rar
[2011/02/11 00:06:48 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/10 22:08:14 | 000,033,792 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_FAQ.doc
[2011/02/10 21:50:18 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/02/09 21:03:50 | 000,441,598 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\cc_20110209_210017.reg
[2011/02/09 19:59:12 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\housecall.guid.cache
[2011/02/09 12:53:40 | 000,341,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/08 16:53:32 | 000,073,728 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\An Introduction.doc
[2011/02/08 01:59:30 | 000,075,264 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\8.1.11.doc
[2011/02/08 01:54:42 | 000,176,129 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Equity, Social Justice, and Sustainable.pdf
[2011/02/04 12:42:58 | 000,071,680 | ---- | M] (Notebook Hardware Control) -- C:\WINDOWS\System32\drivers\nhcDriver.sys
[2011/02/04 12:27:48 | 000,522,285 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\History of Yemen.pdf
[2011/02/03 23:58:00 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
[2011/02/03 18:26:26 | 001,123,328 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\KorelasMScGHRDissertation1.doc
[2011/02/02 17:28:12 | 000,141,010 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\tc-yasi-31jan11-900utc.jpg
[2011/02/02 16:47:40 | 000,139,031 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Plastic river.jpg
[2011/02/02 16:38:38 | 000,585,728 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia- Greek.doc
[2011/02/02 14:34:36 | 000,702,464 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia jen revised.doc
[2011/01/28 15:46:26 | 000,295,451 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_guidelines_content-language.pdf
[2011/01/21 16:44:06 | 008,525,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shell32.dll
[2011/01/21 16:44:06 | 000,441,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shimgvw.dll

========== Files Created - No Company Name ==========

[2011/02/13 17:16:31 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\~$Help.rtf
[2011/02/13 17:02:56 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/02/13 17:02:54 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/02/13 16:59:54 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/02/13 16:59:54 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/02/13 16:59:54 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/02/13 16:59:54 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/02/13 16:59:54 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/02/13 16:21:32 | 004,267,346 | R--- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\ComboFix.exe
[2011/02/13 16:15:23 | 000,012,369 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Help.rtf
[2011/02/13 13:05:47 | 000,034,816 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Η εξέγερση στην Αίγυπτο.doc
[2011/02/12 20:01:57 | 000,466,254 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Tali-riding-on-crescent-moon-p192w250.psd
[2011/02/12 19:52:31 | 000,053,731 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\n539515072_373915_9429.jpg
[2011/02/12 19:43:30 | 000,020,574 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\woman-riding-on-crescent-moon-p192w250.jpg
[2011/02/12 16:26:26 | 090,387,384 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Easy Star All-Stars - Dub Side Of The Moon.rar
[2011/02/10 22:08:14 | 000,033,792 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_FAQ.doc
[2011/02/09 21:00:30 | 000,441,598 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\cc_20110209_210017.reg
[2011/02/09 19:59:10 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\housecall.guid.cache
[2011/02/08 16:53:56 | 000,073,728 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\An Introduction.doc
[2011/02/08 01:59:30 | 000,075,264 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\8.1.11.doc
[2011/02/08 01:54:43 | 000,176,129 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Equity, Social Justice, and Sustainable.pdf
[2011/02/04 12:27:44 | 000,522,285 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\History of Yemen.pdf
[2011/02/03 23:57:56 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo
[2011/02/02 17:28:08 | 000,141,010 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\tc-yasi-31jan11-900utc.jpg
[2011/02/02 16:47:37 | 000,139,031 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Plastic river.jpg
[2011/02/02 14:34:23 | 000,702,464 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia jen revised.doc
[2011/02/02 13:15:43 | 000,585,728 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia- Greek.doc
[2011/01/31 13:50:56 | 001,123,328 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\KorelasMScGHRDissertation1.doc
[2011/01/28 15:46:24 | 000,295,451 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_guidelines_content-language.pdf
[2010/02/08 18:38:51 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/01 16:02:13 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\fusioncache.dat
[2010/01/26 23:06:44 | 000,082,289 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/01/11 20:09:21 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Game.INI
[2009/10/07 01:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/08/25 04:14:35 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
[2009/08/20 23:51:10 | 000,758,272 | ---- | C] () -- C:\WINDOWS\System32\kcpp.dll
[2009/06/12 22:04:55 | 000,000,251 | ---- | C] () -- C:\WINDOWS\MugE.ini
[2009/03/29 15:09:11 | 000,000,367 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Application Data\flashfavorite.htm
[2009/02/28 16:37:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\ncvDS61.dll
[2009/02/28 16:37:36 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\ncCompress.dll
[2009/02/28 16:37:36 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ncUtil62.dll
[2009/02/28 16:37:31 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\nczlib.dll
[2009/02/28 16:37:31 | 000,053,760 | ---- | C] () -- C:\WINDOWS\System32\zlib32.dll
[2008/08/29 00:10:18 | 000,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008/08/29 00:10:17 | 000,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/07/10 01:30:59 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/06/15 18:53:21 | 000,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008/05/26 22:22:52 | 000,017,986 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008/05/26 22:22:50 | 000,022,822 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008/05/26 22:22:48 | 000,017,066 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008/04/01 00:45:25 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008/02/08 00:59:16 | 000,241,664 | ---- | C] () -- C:\WINDOWS\NwtGatewayDLL.dll
[2008/02/08 00:59:16 | 000,001,110 | ---- | C] () -- C:\WINDOWS\NwtGatewayConfig.ini
[2007/10/25 00:40:19 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02D.ini
[2007/10/25 00:32:35 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02C.ini
[2007/10/24 23:18:19 | 000,000,187 | ---- | C] () -- C:\WINDOWS\RELATION.INI
[2007/10/24 22:55:10 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02B.ini
[2007/10/24 22:22:26 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02A.ini
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/04/15 14:21:23 | 000,000,683 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2007/04/11 21:12:12 | 000,001,387 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/10 16:09:23 | 000,000,258 | ---- | C] () -- C:\WINDOWS\QTW.ini
[2006/11/23 17:36:56 | 000,000,031 | ---- | C] () -- C:\WINDOWS\warhead.ini
[2006/10/13 15:18:40 | 000,108,544 | ---- | C] () -- C:\WINDOWS\System32\vbis4032.dll
[2006/10/13 15:18:31 | 000,000,082 | ---- | C] () -- C:\WINDOWS\System32\lexiko.ini
[2006/09/30 15:44:20 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2006/08/18 21:24:10 | 000,005,509 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/08/18 21:24:10 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/07/26 02:57:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
[2006/07/17 17:22:43 | 000,007,224 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/07/17 04:06:41 | 000,000,265 | ---- | C] () -- C:\WINDOWS\scummvm.ini
[2006/07/16 00:49:43 | 000,000,319 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2006/07/16 00:39:27 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/07/16 00:34:16 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2006/07/16 00:34:11 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/07/15 20:44:44 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/07/15 18:17:57 | 000,000,546 | ---- | C] () -- C:\WINDOWS\System32\eRLog.ini
[2006/07/15 18:10:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NT.INI
[2006/07/15 18:09:01 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\SC_res.dll
[2006/07/15 18:09:01 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\EN_res.dll
[2006/07/15 18:09:01 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\TC_res.dll
[2006/07/15 18:09:01 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\MSNChatHook.dll
[2006/07/15 18:09:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\APISlice.dll
[2006/03/16 10:42:57 | 000,002,772 | ---- | C] () -- C:\WINDOWS\AntiV.INI
[2006/01/06 14:30:08 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/01/06 07:26:26 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/12/14 20:59:52 | 000,000,038 | ---- | C] () -- C:\WINDOWS\Acer.ini
[2005/12/01 00:24:56 | 000,037,706 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/10/21 00:58:52 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\vspxvfw.dll
[2005/09/01 16:20:46 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\vspxcore.dll
[2005/05/02 12:13:42 | 000,009,600 | ---- | C] () -- C:\WINDOWS\System32\drivers\NETMNT.sys
[2005/03/28 00:45:26 | 000,000,093 | ---- | C] () -- C:\WINDOWS\ALaunch.ini
[2004/09/07 20:00:00 | 000,003,341 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/12/29 20:45:08 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ServiceControl.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/12/26 15:12:30 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll
[2001/09/03 22:46:38 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 15:33:56 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 21:04:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1996/04/03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

< End of report >



~*~



ComboFix 11-02-12.02 - Theo Haris 13/02/2011 17:03:58.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1253.30.1032.18.1022.569 [GMT 2:00]
Running from: c:\documents and settings\Theo Haris\Επιφάνεια εργασίας\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\cookies.ini
c:\windows\system\QTIM32.DLL
c:\windows\system32\drivers\npf.sys
c:\windows\system32\msupdte.exe
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2011-01-13 to 2011-02-13 )))))))))))))))))))))))))))))))
.

2011-02-13 14:30 . 2011-02-13 14:30 -------- d-----w- C:\_OTL
2011-02-09 18:52 . 2011-02-09 18:52 -------- d-----w- c:\program files\CCleaner
2011-02-09 17:57 . 2011-02-09 17:57 -------- d-----w- c:\program files\Panda Security
2011-02-04 10:42 . 2011-02-04 10:42 71680 ----a-w- c:\windows\system32\drivers\nhcDriver.sys
2011-02-04 10:42 . 2011-02-04 10:42 -------- d-----w- c:\documents and settings\Theo Haris\Application Data\Notebook Hardware Control
2011-02-03 22:04 . 2011-02-03 22:04 -------- d-----w- c:\program files\Motherboard Monitor 5
2011-02-03 21:57 . 2011-02-03 21:58 -------- d-----w- c:\program files\SpeedFan
2011-01-30 12:57 . 2011-01-30 12:57 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-01-30 12:57 . 2011-01-30 12:57 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2011-01-21 14:44 . 2011-01-21 14:44 441344 ------w- c:\windows\system32\dllcache\shimgvw.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2004-09-07 18:00 441344 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-09-07 18:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2004-09-07 18:00 1855232 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-09-07 18:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 17:26 . 2004-09-07 18:00 738304 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-09 15:15 . 2004-09-07 18:00 754688 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2004-09-07 18:00 2199808 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2004-09-07 18:00 2076416 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2004-09-07 18:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-12-06 18:03 . 2010-12-06 18:02 967 ----a-w- c:\windows\ScUnin.pif
2010-12-06 18:03 . 2010-12-06 18:02 68096 ----a-w- c:\windows\ScUnin.exe
2010-11-18 18:12 . 2004-09-07 18:00 86016 ----a-w- c:\windows\system32\isign32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Theo Haris\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Theo Haris\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Theo Haris\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2007-01-05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-07 102491]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-07 692315]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-10-19 69632]
"EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-25 212992]
"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 3084288]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2005-12-01 458752]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 397312]
"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-17 15600128]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"UIExec"="c:\program files\Join Air\UIExec.exe" [2010-03-26 136840]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^Device Detector 2.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\Device Detector 2.lnk
backup=c:\windows\pss\Device Detector 2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnk
backup=c:\windows\pss\ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Theo Haris^Start Menu^Προγράμματα^Εκκίνηση^PowerReg Scheduler.exe]
path=c:\documents and settings\Theo Haris\Start Menu\Προγράμματα\Εκκίνηση\PowerReg Scheduler.exe
backup=c:\windows\pss\PowerReg Scheduler.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 16:43 69632 ----a-w- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2005-08-12 12:43 45056 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 16:30 15360 ----a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-01 07:39 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-01-01 20:22 3739648 ----a-w- c:\program files\Google\Google Talk\googletalk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-09-23 22:08 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-07-18 18:06 77824 ----a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-07-18 18:10 114688 ----a-w- c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-07-18 18:09 94208 ----a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-09-07 18:00 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2009-10-14 11:36 2793304 ----a-w- c:\program files\Logitech\Logitech WebCam Software\LWS.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2004-09-07 18:00 59392 ----a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2004-09-07 18:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2004-09-07 18:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 09:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2007-01-05 18:49 204288 ------w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gupdate1c998781007dfbe"=2 (0x2)
"CyberLink Media Library Service"=2 (0x2)
"CLTNetCnService"=2 (0x2)
"CLSched"=2 (0x2)
"CLCapSvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Theo Haris\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Theo Haris\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=
"c:\\Documents and Settings\\Theo Haris\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15/6/2008 6:53 μμ 717296]
R2 Network WanMiniport First Position;Network WanMiniport First Position;c:\program files\Telecom Italia\WanMiniport1st\srvany.exe [11/6/2009 1:47 μμ 8192]
R2 UI Assistant Service;UI Assistant Service;c:\program files\Join Air\AssistantServices.exe [21/12/2010 3:14 μμ 251016]
S2 .EsetTrialReset;Eset Trial Reset;c:\windows\system32\regedt32.exe [7/9/2004 8:00 μμ 3584]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [21/12/2010 3:14 μμ 9216]
S3 ONDAusbmdm6k;ONDA Proprietary USB Driver;c:\windows\system32\DRIVERS\ONDAusbmdm6k.sys --> c:\windows\system32\DRIVERS\ONDAusbmdm6k.sys [?]
S3 ONDAusbnet;ONDA USB-NDIS miniport;c:\windows\system32\DRIVERS\ONDAusbnet.sys --> c:\windows\system32\DRIVERS\ONDAusbnet.sys [?]
S3 ONDAusbnmea;ONDA NMEA Port;c:\windows\system32\DRIVERS\ONDAusbnmea.sys --> c:\windows\system32\DRIVERS\ONDAusbnmea.sys [?]
S3 ONDAusbser6k;ONDA Diagnostic Port;c:\windows\system32\DRIVERS\ONDAusbser6k.sys --> c:\windows\system32\DRIVERS\ONDAusbser6k.sys [?]
S3 ONDAusbvoice;ONDA VoUSB Port;c:\windows\system32\DRIVERS\ONDAusbvoice.sys --> c:\windows\system32\DRIVERS\ONDAusbvoice.sys [?]
S3 TMPassthruMP;TMPassthruMP;c:\windows\system32\DRIVERS\TMPassthru.sys --> c:\windows\system32\DRIVERS\TMPassthru.sys [?]
S4 gupdate1c998781007dfbe;Google Update Service (gupdate1c998781007dfbe);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S4 Pcmrome;Pcmrome; [x]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://e-learning.hau.gr/
IE: &Sample Toolband Serach - c:\windows\system32\ToolBand.dll/MENUSEARCH.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: bmnet.dll
FF - ProfilePath - c:\documents and settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\
FF - prefs.js: browser.startup.homepage - en.wikipedia.org
FF - prefs.js: network.proxy.type - 0
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: Session Manager: {1280606b-2510-4fe0-97ef-9b5a22eafe30} - %profile%\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
FF - Ext: Forecastbar Enhanced: {3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8} - %profile%\extensions\{3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}
FF - Ext: Image Zoom: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68} - %profile%\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
FF - Ext: Tab Mix Plus: {dc572301-7619-498c-a57d-39143191b318} - %profile%\extensions\{dc572301-7619-498c-a57d-39143191b318}
FF - Ext: BetterPrivacy: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3} - %profile%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Ghostery: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: Tamper Data: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947} - %profile%\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: PC Sync 2 Synchronisation Extension: [email protected] - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
FF - user.js: network.proxy.http_port - 0
FF - user.js: network.proxy.ssl -
FF - user.js: network.proxy.ssl_port - 0
FF - user.js: network.proxy.ftp -
FF - user.js: network.proxy.ftp_port - 0
FF - user.js: network.proxy.gopher -
FF - user.js: network.proxy.gopher_port - 0
FF - user.js: network.proxy.socks_version - 5
FF - user.js: network.proxy.socks -
FF - user.js: network.proxy.socks_port - 0
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-BitTorrent - c:\program files\BitTorrent\bittorrent.exe
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-Google Update - c:\documents and settings\Theo Haris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-13 17:11
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\9 ™’t*’F*’*\GK]
"SaveDataPath"="d:\\Games\\sawa2"
DUMPHIVE0.003 (REGF)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(692)
c:\windows\system32\bmnet.dll

- - - - - - - > 'explorer.exe'(3368)
c:\windows\system32\MSNChatHook.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\MSVCR71.dll
c:\documents and settings\Theo Haris\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\bmnet.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\Ati2evxx.exe
c:\acer\Empowering Technology\admServ.exe
c:\windows\system32\bmwebcfg.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Completion time: 2011-02-13 17:14:41 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-13 15:14

Pre-Run: 19 Κατάλογοι 22.114.566.144 διαθέσιμα byte
Post-Run: 24 Κατάλογοι 21.939.159.040 διαθέσιμα byte

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 14584DA9B5E5F48BBA60906B25086A84
  • 0

#4
michaelg9

michaelg9

    Trusted Helper

  • Malware Removal
  • 2,949 posts
Hey,

We can't say accurately when you got infected, in this case, at all. How it was installed, most probably by a crack or these stuff, or by programs downloaded using P2P programs (BitTorrent in this case). These are the most common sources of malware.

You have a trial resetter for Eset. I'll delete that, as usually these things are infected, please don't re-install it, I'll give you advice for antivirus programs after.

Next:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    SRV - [2004/09/07 20:00:00 | 000,003,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\System32\regedt32.exe -- (.EsetTrialReset)

    :Services

    :Reg

    :Files

    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.


Next:

Download avz4.zip from HERE
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: Posted Image
  • Click Start to begin the update
Note: If you receive an error message, chose a different source, then click Start again


  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the "Advanced System Analysis with malware removal mode enabled" check box.
    Posted Image
  • Click on the “Execute selected scripts”.
  • Automatic scanning, healing and system check will be executed.
  • A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip.
  • It is necessary to reboot your machine, because AVZ might disturb some program operations (like antiviruses and firewall) during the system scan.
  • All applications will work properly after the system restart.

When restarted

  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Analysis" check box.
    Posted Image
  • Click on the "Execute selected scripts".
  • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.

Attach both virusinfo_syscure.zip and virusinfo_syscheck.zip to your next post

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on Posted Image to insert the attachment into your post


Next:

Malwarebytes' Anti-Malware
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
  • 0

#5
Theo Haris

Theo Haris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Thank you, Michael! Those scans have already removed some trojans from my system...

Pasted you'll find the new OTL log and the Malwarebytes' log, and attached the zips from AVZ4. I ran AVZ4 twice, because I had forgot to check the second partition of my hard drive..

Thank you,
Theoharis

~*~

OTL logfile created on: 13/2/2011 6:04:32 μμ - Run 3
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000408 | Country: Ελλάδα | Language: ELL | Date Format: d/M/yyyy

1.022,00 Mb Total Physical Memory | 235,00 Mb Available Physical Memory | 23,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 73,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 44,37 Gb Total Space | 19,74 Gb Free Space | 44,48% Space Free | Partition Type: FAT32
Drive D: | 44,86 Gb Total Space | 9,94 Gb Free Space | 22,16% Space Free | Partition Type: FAT32
Drive G: | 1397,26 Gb Total Space | 1184,18 Gb Free Space | 84,75% Space Free | Partition Type: NTFS

Computer Name: ACER-92EDFFD6C3 | User Name: Theo Haris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/13 16:18:48 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
PRC - [2011/01/25 12:10:42 | 003,313,504 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgmfapx.exe
PRC - [2011/01/07 01:22:54 | 002,747,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/01/07 01:22:44 | 001,084,256 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/01/06 15:23:20 | 000,737,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/12/05 16:26:40 | 000,654,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/12/05 16:26:12 | 000,650,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/03/26 10:13:54 | 000,136,840 | ---- | M] () -- C:\Program Files\Join Air\UIExec.exe
PRC - [2010/03/26 09:59:00 | 000,251,016 | ---- | M] () -- C:\Program Files\Join Air\AssistantServices.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/11/13 09:33:54 | 000,097,128 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
PRC - [2008/04/14 18:30:36 | 001,038,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/21 11:30:44 | 000,061,440 | ---- | M] () -- C:\Program Files\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
PRC - [2006/08/31 16:52:06 | 000,118,784 | ---- | M] (Bytemobile, Inc.) -- C:\WINDOWS\system32\bmwebcfg.exe
PRC - [2005/12/01 17:38:38 | 000,458,752 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\QtZgAcer.EXE
PRC - [2005/11/25 15:59:44 | 000,212,992 | ---- | M] (Acer Inc) -- C:\Acer\Empowering Technology\ePower\epm-dm.exe
PRC - [2005/11/16 17:00:50 | 000,397,312 | ---- | M] (acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\Monitor.exe
PRC - [2005/11/09 22:01:00 | 000,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2005/11/09 21:59:08 | 000,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2005/11/09 21:58:26 | 000,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2005/10/24 16:45:32 | 002,462,208 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admtray.exe
PRC - [2005/10/24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admServ.exe
PRC - [2005/10/19 09:30:16 | 000,069,632 | ---- | M] (HiTRUST) -- C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
PRC - [2005/01/07 16:17:16 | 000,102,491 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004/08/09 06:03:38 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () -- C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe


========== Modules (SafeList) ==========

MOD - [2011/02/13 16:18:48 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
MOD - [2010/08/23 19:12:06 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2005/12/05 16:00:10 | 000,053,248 | ---- | M] (HiTRUST) -- C:\WINDOWS\system32\sysenv.dll
MOD - [2005/08/24 01:24:00 | 000,010,752 | ---- | M] () -- C:\WINDOWS\system32\MSNChatHook.dll
MOD - [2005/01/07 16:17:08 | 000,069,723 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll
MOD - [2003/03/18 21:12:12 | 001,047,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MFC71u.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (Pcmrome)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Disabled | Stopped] -- -- (gupdate1c998781007dfbe) Google Update Service (gupdate1c998781007dfbe)
SRV - File not found [Disabled | Stopped] -- -- (CLTNetCnService)
SRV - File not found [Disabled | Stopped] -- -- (ccSetMgr)
SRV - File not found [Disabled | Stopped] -- -- (ccPwdSvc)
SRV - File not found [Disabled | Stopped] -- -- (ccEvtMgr)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/06/14 15:07:14 | 000,615,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010/03/26 09:59:00 | 000,251,016 | ---- | M] () [Auto | Running] -- C:\Program Files\Join Air\AssistantServices.exe -- (UI Assistant Service)
SRV - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2006/08/31 16:52:06 | 000,118,784 | ---- | M] (Bytemobile, Inc.) [Auto | Running] -- C:\WINDOWS\System32\bmwebcfg.exe -- (bmwebcfg)
SRV - [2005/11/14 01:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2005/11/09 22:01:00 | 000,540,745 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2005/11/09 21:59:08 | 000,114,753 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2005/11/09 21:58:26 | 000,217,164 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2005/10/24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) [Auto | Running] -- C:\Acer\Empowering Technology\admServ.exe -- (AWService)
SRV - [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe -- (Network WanMiniport First Position)


========== Driver Services (SafeList) ==========

DRV - [2011/02/04 12:42:58 | 000,071,680 | ---- | M] (Notebook Hardware Control) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\nhcDriver.sys -- (nhcDriverDevice)
DRV - [2010/12/08 04:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/11/12 13:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/09/13 15:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/08/03 15:23:36 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/08/03 15:23:34 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/03 15:23:32 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/02/26 14:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010/02/26 14:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010/02/26 14:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/02/26 14:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009/10/29 19:28:24 | 000,009,216 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter.sys -- (massfilter)
DRV - [2009/10/07 10:49:50 | 000,023,832 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
DRV - [2009/10/07 10:49:38 | 006,756,632 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 120(UVC)
DRV - [2009/10/07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009/09/25 08:05:20 | 000,278,984 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2009/01/06 20:07:28 | 000,124,464 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2008/09/05 21:25:04 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008/08/29 00:10:18 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/04/13 20:36:40 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 20:36:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 18:36:06 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2006/10/16 14:45:26 | 000,088,960 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2006/08/31 16:58:22 | 000,018,560 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2006/01/06 07:53:34 | 000,006,144 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV - [2006/01/04 07:46:42 | 001,420,288 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/11/17 15:45:40 | 004,069,888 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/11/09 14:45:56 | 000,013,440 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2005/10/23 19:20:52 | 000,218,496 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/10/18 01:53:24 | 000,998,656 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/10/18 01:52:30 | 000,721,280 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/10/15 18:20:44 | 000,012,106 | ---- | M] (OSA Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\OsaFsLoc.sys -- (OsaFsLoc)
DRV - [2005/09/29 20:11:42 | 000,078,720 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2005/09/13 15:34:40 | 000,004,392 | ---- | M] (OSA Technologies) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NdisFilt.sys -- (NdisFilt)
DRV - [2005/09/11 19:49:44 | 003,298,432 | ---- | M] (IntelŽ Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2005/06/30 16:58:24 | 000,007,296 | ---- | M] (OSA Technologies, An Avocent Company) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio)
DRV - [2005/05/02 12:13:42 | 000,009,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETMNT.sys -- (NETMNT)
DRV - [2005/04/07 18:08:46 | 000,078,208 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-shd.sys -- (EpmShd)
DRV - [2005/01/14 15:57:16 | 000,004,010 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm)
DRV - [2005/01/13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys)
DRV - [2005/01/07 16:03:42 | 000,191,456 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2004/12/08 14:10:00 | 000,016,896 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2004/09/07 20:00:00 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2004/09/07 20:00:00 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2004/09/07 20:00:00 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2004/09/07 20:00:00 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2004/09/07 20:00:00 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2004/09/07 20:00:00 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2004/09/07 20:00:00 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2004/09/07 20:00:00 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2004/09/07 20:00:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2004/09/07 20:00:00 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2004/09/07 20:00:00 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2004/09/07 20:00:00 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2004/09/07 20:00:00 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2004/09/07 20:00:00 | 000,006,784 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
DRV - [2004/09/07 20:00:00 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2004/07/19 13:10:00 | 000,004,096 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-psd.sys -- (EpmPsd)
DRV - [2004/06/26 13:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vncdrv.sys -- (vncdrv)
DRV - [2004/03/08 12:55:50 | 000,013,567 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)
DRV - [2003/12/15 18:22:00 | 000,038,448 | ---- | M] (OLYMPUS OPTICAL CO.,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VNUSB.sys -- (VNUSB)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://e-learning.hau.gr/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "en.wikipedia.org"
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.48.3
FF - prefs.js..extensions.enabledItems: {3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}:0.9.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.7
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.7.4
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: [email protected]:2.4.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.732
FF - prefs.js..network.proxy.type: 0

FF - user.js..network.proxy.type: 0
FF - user.js..network.proxy.http: ""
FF - user.js..network.proxy.http_port: 0
FF - user.js..network.proxy.ssl: ""
FF - user.js..network.proxy.ssl_port: 0
FF - user.js..network.proxy.ftp: ""
FF - user.js..network.proxy.ftp_port: 0
FF - user.js..network.proxy.gopher: ""
FF - user.js..network.proxy.gopher_port: 0
FF - user.js..network.proxy.socks_version: 5
FF - user.js..network.proxy.socks: ""
FF - user.js..network.proxy.socks_port: 0

FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/11/17 13:28:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/02/13 17:28:42 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2006/07/15 20:42:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2006/07/15 20:42:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2008/08/29 02:37:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Extensions
[2006/07/15 20:49:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions
[2011/02/10 21:53:34 | 000,000,000 | ---D | M] (Session Manager) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2011/01/07 13:33:32 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2008/05/22 19:44:28 | 000,000,000 | ---D | M] (Forecastbar Enhanced) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}
[2011/02/03 14:20:48 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/04/29 18:32:16 | 000,000,000 | ---D | M] (Tamper Data) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2010/09/10 02:45:26 | 000,000,000 | ---D | M] (WOT) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/01/12 14:03:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/12/27 00:48:18 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/09/07 14:58:42 | 000,000,000 | ---D | M] ("BetterPrivacy") -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010/06/18 13:12:38 | 000,000,000 | ---D | M] ("Tab Mix Plus") -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2011/01/27 19:16:54 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/11/22 23:18:32 | 000,000,000 | ---D | M] (Ghostery) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\[email protected]
[2008/11/04 20:21:56 | 000,005,179 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\searchplugins\BitTorrent.xml
[2006/07/15 20:42:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/25 19:35:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/04/19 15:02:14 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/17 13:28:06 | 000,000,000 | ---D | M] (PC Sync 2 Synchronisation Extension) -- C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC
[2009/03/16 21:28:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2007/01/04 02:29:08 | 000,049,152 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/08/03 18:40:56 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/08/03 18:40:56 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/08/03 18:40:56 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/08/03 18:40:56 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/02/13 17:10:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {0CF5D165-517E-48B6-B3C7-3054A24F8BF6} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {B7FC60D5-AB79-477E-96EE-5C7770EAEAB9} - No CLSID value found.
O4 - HKLM..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe (Acer Value Labs, Taiwan)
O4 - HKLM..\Run: [ADMTray.exe] C:\Acer\Empowering Technology\admtray.exe (Avocent Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe (HiTRUST)
O4 - HKLM..\Run: [EPM-DM] c:\Acer\Empowering Technology\ePower\epm-dm.exe (Acer Inc)
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe (acer Inc.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [UIExec] C:\Program Files\Join Air\UIExec.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Sample Toolband Serach - C:\WINDOWS\System32\ToolBand.dll (HiTRUST)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1152986441640 (MUWebControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\cbXrPFXn: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Τρέχουσα αρχική σελίδα) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/20 23:33:42 | 000,000,065 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2006/01/06 07:54:00 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.FRK -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/13 17:59:13 | 000,000,000 | -HSD | C] -- C:\Recycled
[2011/02/13 17:55:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\avz4
[2011/02/13 17:52:35 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\mbam-setup-1.50.1.1100.exe
[2011/02/13 17:31:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Προγράμματα\AVG 2011
[2011/02/13 17:28:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2011/02/13 17:28:07 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2011/02/13 17:24:25 | 004,738,880 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\avg_free_stb_all_2011_1204_cnet.exe
[2011/02/13 17:02:52 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/02/13 16:59:54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/02/13 16:59:54 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/02/13 16:59:54 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/02/13 16:59:54 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/02/13 16:59:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/02/13 16:39:34 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/02/13 16:30:09 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/02/13 16:18:49 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
[2011/02/09 20:56:07 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Theo Haris\Recent
[2011/02/09 20:52:51 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/02/09 19:57:15 | 000,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2011/02/07 01:43:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Quiz #3
[2011/02/04 12:42:56 | 000,071,680 | ---- | C] (Notebook Hardware Control) -- C:\WINDOWS\System32\drivers\nhcDriver.sys
[2011/02/04 12:42:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Application Data\Notebook Hardware Control
[2011/02/04 00:04:26 | 000,000,000 | ---D | C] -- C:\Program Files\Motherboard Monitor 5
[2011/02/03 23:57:59 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedFan
[2011/01/27 00:57:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Stefanos translations
[2011/01/18 21:01:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\Downloads

========== Files - Modified Within 30 Days ==========

[2011/02/13 18:04:00 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\~$Help2.doc
[2011/02/13 18:03:28 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/13 18:03:14 | 000,000,546 | ---- | M] () -- C:\WINDOWS\System32\eRLog.ini
[2011/02/13 18:00:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/13 18:00:38 | 1071,763,456 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/13 17:55:30 | 000,137,216 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Help2.doc
[2011/02/13 17:54:48 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2011/02/13 17:52:48 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\mbam-setup-1.50.1.1100.exe
[2011/02/13 17:52:24 | 006,175,589 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\avz4.zip
[2011/02/13 17:37:18 | 106,049,661 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/02/13 17:31:28 | 000,000,598 | ---- | M] () -- C:\Documents and Settings\All Users\Επιφάνεια εργασίας\AVG 2011.lnk
[2011/02/13 17:26:04 | 000,069,120 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\case study 2.doc
[2011/02/13 17:24:34 | 004,738,880 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\avg_free_stb_all_2011_1204_cnet.exe
[2011/02/13 17:02:58 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/02/13 16:21:52 | 004,267,346 | R--- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\ComboFix.exe
[2011/02/13 16:18:48 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
[2011/02/13 16:15:24 | 000,012,369 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Help.rtf
[2011/02/13 13:05:48 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Η εξέγερση στην Αίγυπτο.doc
[2011/02/13 03:58:32 | 000,466,254 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Tali-riding-on-crescent-moon-p192w250.psd
[2011/02/12 19:52:34 | 000,053,731 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\n539515072_373915_9429.jpg
[2011/02/12 19:43:38 | 000,020,574 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\woman-riding-on-crescent-moon-p192w250.jpg
[2011/02/12 16:38:00 | 090,387,384 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Easy Star All-Stars - Dub Side Of The Moon.rar
[2011/02/11 00:06:48 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/10 22:08:14 | 000,033,792 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_FAQ.doc
[2011/02/10 21:50:18 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/02/09 21:03:50 | 000,441,598 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\cc_20110209_210017.reg
[2011/02/09 19:59:12 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\housecall.guid.cache
[2011/02/09 12:53:40 | 000,341,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/08 16:53:32 | 000,073,728 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\An Introduction.doc
[2011/02/08 01:59:30 | 000,075,264 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\8.1.11.doc
[2011/02/08 01:54:42 | 000,176,129 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Equity, Social Justice, and Sustainable.pdf
[2011/02/04 12:42:58 | 000,071,680 | ---- | M] (Notebook Hardware Control) -- C:\WINDOWS\System32\drivers\nhcDriver.sys
[2011/02/04 12:27:48 | 000,522,285 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\History of Yemen.pdf
[2011/02/03 23:58:00 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
[2011/02/03 18:26:26 | 001,123,328 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\KorelasMScGHRDissertation1.doc
[2011/02/02 17:28:12 | 000,141,010 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\tc-yasi-31jan11-900utc.jpg
[2011/02/02 16:47:40 | 000,139,031 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Plastic river.jpg
[2011/02/02 16:38:38 | 000,585,728 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia- Greek.doc
[2011/02/02 14:34:36 | 000,702,464 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia jen revised.doc
[2011/01/28 15:46:26 | 000,295,451 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_guidelines_content-language.pdf

========== Files Created - No Company Name ==========

[2011/02/13 18:03:58 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\~$Help2.doc
[2011/02/13 17:55:27 | 000,137,216 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Help2.doc
[2011/02/13 17:51:58 | 006,175,589 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\avz4.zip
[2011/02/13 17:37:16 | 106,049,661 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/02/13 17:31:27 | 000,000,598 | ---- | C] () -- C:\Documents and Settings\All Users\Επιφάνεια εργασίας\AVG 2011.lnk
[2011/02/13 17:26:04 | 000,069,120 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\case study 2.doc
[2011/02/13 17:02:56 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/02/13 17:02:54 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/02/13 16:59:54 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/02/13 16:59:54 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/02/13 16:59:54 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/02/13 16:59:54 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/02/13 16:59:54 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/02/13 16:21:32 | 004,267,346 | R--- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\ComboFix.exe
[2011/02/13 16:15:23 | 000,012,369 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Help.rtf
[2011/02/13 13:05:47 | 000,034,816 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Η εξέγερση στην Αίγυπτο.doc
[2011/02/12 20:01:57 | 000,466,254 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Tali-riding-on-crescent-moon-p192w250.psd
[2011/02/12 19:52:31 | 000,053,731 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\n539515072_373915_9429.jpg
[2011/02/12 19:43:30 | 000,020,574 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\woman-riding-on-crescent-moon-p192w250.jpg
[2011/02/12 16:26:26 | 090,387,384 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Easy Star All-Stars - Dub Side Of The Moon.rar
[2011/02/10 22:08:14 | 000,033,792 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_FAQ.doc
[2011/02/09 21:00:30 | 000,441,598 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\cc_20110209_210017.reg
[2011/02/09 19:59:10 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\housecall.guid.cache
[2011/02/08 16:53:56 | 000,073,728 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\An Introduction.doc
[2011/02/08 01:59:30 | 000,075,264 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\8.1.11.doc
[2011/02/08 01:54:43 | 000,176,129 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Equity, Social Justice, and Sustainable.pdf
[2011/02/04 12:27:44 | 000,522,285 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\History of Yemen.pdf
[2011/02/03 23:57:56 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo
[2011/02/02 17:28:08 | 000,141,010 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\tc-yasi-31jan11-900utc.jpg
[2011/02/02 16:47:37 | 000,139,031 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Plastic river.jpg
[2011/02/02 14:34:23 | 000,702,464 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia jen revised.doc
[2011/02/02 13:15:43 | 000,585,728 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia- Greek.doc
[2011/01/31 13:50:56 | 001,123,328 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\KorelasMScGHRDissertation1.doc
[2011/01/28 15:46:24 | 000,295,451 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_guidelines_content-language.pdf
[2010/02/08 18:38:51 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/01 16:02:13 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\fusioncache.dat
[2010/01/26 23:06:44 | 000,082,289 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/01/11 20:09:21 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Game.INI
[2009/10/07 01:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/08/25 04:14:35 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
[2009/08/20 23:51:10 | 000,758,272 | ---- | C] () -- C:\WINDOWS\System32\kcpp.dll
[2009/06/12 22:04:55 | 000,000,251 | ---- | C] () -- C:\WINDOWS\MugE.ini
[2009/03/29 15:09:11 | 000,000,367 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Application Data\flashfavorite.htm
[2009/02/28 16:37:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\ncvDS61.dll
[2009/02/28 16:37:36 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\ncCompress.dll
[2009/02/28 16:37:36 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ncUtil62.dll
[2009/02/28 16:37:31 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\nczlib.dll
[2009/02/28 16:37:31 | 000,053,760 | ---- | C] () -- C:\WINDOWS\System32\zlib32.dll
[2008/08/29 00:10:18 | 000,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008/08/29 00:10:17 | 000,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/07/10 01:30:59 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/06/15 18:53:21 | 000,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008/05/26 22:22:52 | 000,017,986 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008/05/26 22:22:50 | 000,022,822 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008/05/26 22:22:48 | 000,017,066 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008/04/01 00:45:25 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008/02/08 00:59:16 | 000,241,664 | ---- | C] () -- C:\WINDOWS\NwtGatewayDLL.dll
[2008/02/08 00:59:16 | 000,001,110 | ---- | C] () -- C:\WINDOWS\NwtGatewayConfig.ini
[2007/10/25 00:40:19 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02D.ini
[2007/10/25 00:32:35 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02C.ini
[2007/10/24 23:18:19 | 000,000,187 | ---- | C] () -- C:\WINDOWS\RELATION.INI
[2007/10/24 22:55:10 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02B.ini
[2007/10/24 22:22:26 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02A.ini
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/04/15 14:21:23 | 000,000,683 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2007/04/11 21:12:12 | 000,001,387 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/10 16:09:23 | 000,000,258 | ---- | C] () -- C:\WINDOWS\QTW.ini
[2006/11/23 17:36:56 | 000,000,031 | ---- | C] () -- C:\WINDOWS\warhead.ini
[2006/10/13 15:18:40 | 000,108,544 | ---- | C] () -- C:\WINDOWS\System32\vbis4032.dll
[2006/10/13 15:18:31 | 000,000,082 | ---- | C] () -- C:\WINDOWS\System32\lexiko.ini
[2006/09/30 15:44:20 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2006/08/18 21:24:10 | 000,005,509 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/08/18 21:24:10 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/07/26 02:57:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
[2006/07/17 17:22:43 | 000,007,224 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/07/17 04:06:41 | 000,000,265 | ---- | C] () -- C:\WINDOWS\scummvm.ini
[2006/07/16 00:49:43 | 000,000,319 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2006/07/16 00:39:27 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/07/16 00:34:16 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2006/07/16 00:34:11 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/07/15 20:44:44 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/07/15 18:17:57 | 000,000,546 | ---- | C] () -- C:\WINDOWS\System32\eRLog.ini
[2006/07/15 18:10:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NT.INI
[2006/07/15 18:09:01 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\SC_res.dll
[2006/07/15 18:09:01 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\EN_res.dll
[2006/07/15 18:09:01 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\TC_res.dll
[2006/07/15 18:09:01 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\MSNChatHook.dll
[2006/07/15 18:09:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\APISlice.dll
[2006/03/16 10:42:57 | 000,002,772 | ---- | C] () -- C:\WINDOWS\AntiV.INI
[2006/01/06 14:30:08 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/01/06 07:26:26 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/12/14 20:59:52 | 000,000,038 | ---- | C] () -- C:\WINDOWS\Acer.ini
[2005/12/01 00:24:56 | 000,037,706 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/10/21 00:58:52 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\vspxvfw.dll
[2005/09/01 16:20:46 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\vspxcore.dll
[2005/05/02 12:13:42 | 000,009,600 | ---- | C] () -- C:\WINDOWS\System32\drivers\NETMNT.sys
[2005/03/28 00:45:26 | 000,000,093 | ---- | C] () -- C:\WINDOWS\ALaunch.ini
[2004/09/07 20:00:00 | 000,003,341 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/12/29 20:45:08 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ServiceControl.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/12/26 15:12:30 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll
[2001/09/03 22:46:38 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 15:33:56 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 21:04:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1996/04/03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2006/07/15 18:14:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acer
[2007/02/10 01:20:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2007/02/16 03:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/09/21 18:46:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Emotum
[2008/01/24 23:26:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Valusoft
[2008/06/11 01:26:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
[2008/09/29 14:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Games
[2008/10/06 23:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/10/10 22:27:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2008/12/06 23:43:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NevoSoft Games
[2009/03/14 06:06:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2009/03/14 06:12:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/12/17 14:10:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Final Draft
[2010/01/04 15:47:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\The Mirror Mysteries
[2010/01/10 23:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SulusGames
[2010/01/18 00:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\River Past G5
[2010/01/25 01:57:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/02/18 21:06:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ludia
[2010/05/29 22:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nifflas
[2010/08/03 18:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010/09/07 19:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/11 22:57:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2010/11/13 15:21:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeHideIP
[2010/11/13 15:30:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Arovax
[2010/11/26 00:58:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/11/26 13:55:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/11/26 14:09:50 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/12/16 01:22:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Clarus
[2006/07/15 18:14:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Acer
[2006/08/19 14:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\BitTorrent
[2006/09/30 16:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Image Zone Express
[2007/01/21 21:06:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\PlayFirst
[2007/01/31 19:36:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\BSplayer
[2007/03/01 14:09:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\BSplayer Pro
[2007/05/02 14:24:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\uTorrent
[2008/01/24 23:26:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Valusoft
[2008/02/08 00:59:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Bytemobile
[2008/02/08 00:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\ICS
[2008/02/08 01:06:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Vodafone Mobile Connect
[2008/06/11 00:01:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Home Sweet Home
[2008/09/05 21:24:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\DAEMON Tools
[2009/03/16 21:01:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Windows Desktop Search
[2009/03/16 21:05:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Windows Search
[2009/06/12 21:55:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\GetRight
[2009/09/02 18:46:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\GraveyardShift
[2009/09/20 18:26:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Flood Light Games
[2009/09/25 08:19:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Games
[2009/12/17 14:12:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Final Draft
[2009/12/24 12:42:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\com.adobe.example.avatarAirApplication.199ED43C2CFEB351CD0244628B93195D7C58F98C.1
[2010/01/10 23:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\SulusGames
[2010/01/10 23:11:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Enlightenus
[2010/01/11 20:20:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Orneon
[2010/01/17 21:30:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\WebCam Recorder
[2010/01/18 00:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\River Past G5
[2010/01/22 01:42:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\GetRightToGo
[2010/01/26 23:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Leadertech
[2010/02/12 00:34:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Free Mp3 Wma Ogg Converter
[2010/02/18 21:06:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Ludia
[2010/05/09 04:34:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\NotMyIp
[2010/05/09 16:53:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Hide IP NG
[2010/05/29 22:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Nifflas
[2010/08/04 00:07:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\ESET
[2010/09/25 04:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Big Fish Games
[2010/11/13 15:21:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\FreeHideIP
[2010/11/15 18:18:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Dropbox
[2010/11/17 13:29:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\PC Suite
[2010/11/17 13:29:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Nokia
[2010/11/26 14:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\AVG10
[2010/11/28 03:11:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Phenomenon 32 Saves
[2010/12/15 01:26:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\.minecraft
[2011/02/04 12:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Notebook Hardware Control

========== Purity Check ==========



< End of report >


~*~

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5754

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

13/2/2011 7:37:18 μμ
mbam-log-2011-02-13 (19-37-18).txt

Scan type: Quick scan
Objects scanned: 146657
Time elapsed: 3 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6} (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\bm0a6725ef.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\bm0a6725ef.xml (Trojan.Vundo) -> Quarantined and deleted successfully.

Attached File  virusinfo_syscheck.zip   29.08KB   39 downloads
Attached File  virusinfo_syscure.zip   29.37KB   35 downloads
  • 0

#6
michaelg9

michaelg9

    Trusted Helper

  • Malware Removal
  • 2,949 posts
Hey,

How's your computer running? Are there any other problems?
  • 0

#7
Theo Haris

Theo Haris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Nope, everything's fine, and it even works faster :D
  • 0

#8
michaelg9

michaelg9

    Trusted Helper

  • Malware Removal
  • 2,949 posts
Hey,

First of all, you have more than one antivirus installed. That's something bad.
I'd suggest you to uninstall all antivirus programs from your computer and install a new one, better at my opinion.

If you don't want to follow my opinion, there is no problem, but you have to uninstall either AVG or Norton/Eset. Having more than one antivirus installed is a disadvantage from many sides.

My suggestion is this:

Please uninstall the following programs:

AVG PC Tuneup 2011
Norton 360
AVG 2011
Norton AntiVirus Parent MSI
AVG 2011
AVG 2011
Norton AntiVirus 2005 (Symantec Corporation)

AVG2011 is listed three times, because that's what I found in you list of programs. Search well and uninstall all instances.

Then install:



Tell me if you need any assistance of that :D
  • 0

#9
Theo Haris

Theo Haris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Ditto!

I had Norton and ESET in the past, but I have removed them - at least I think I did, there were some problems with the uninstalls and I guess some folders have still remained. I'll delete those and follow your advice on the new antivirus!

Thanks so much, Michael, I owe you a beer if you ever come to Athens! :D
  • 0

#10
michaelg9

michaelg9

    Trusted Helper

  • Malware Removal
  • 2,949 posts
Hey,

If you want me to delete any remainings of the antivirus, post another OTL log.
If not, tell me to post some general advices on how to keep clean :D
  • 0

#11
Theo Haris

Theo Haris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
I would appreciate it, since I can't find them in the Add/Remove Programs... And of course any suggestions for protection are much appreciated!

Thanks again,
Th.


Here's the OTL log:

OTL logfile created on: 13/2/2011 10:10:42 μμ - Run 4
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000408 | Country: Ελλάδα | Language: ELL | Date Format: d/M/yyyy

1.022,00 Mb Total Physical Memory | 318,00 Mb Available Physical Memory | 31,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 73,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 44,37 Gb Total Space | 19,44 Gb Free Space | 43,80% Space Free | Partition Type: FAT32
Drive D: | 44,86 Gb Total Space | 9,94 Gb Free Space | 22,16% Space Free | Partition Type: FAT32
Drive G: | 1397,26 Gb Total Space | 1184,08 Gb Free Space | 84,74% Space Free | Partition Type: NTFS

Computer Name: ACER-92EDFFD6C3 | User Name: Theo Haris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/13 22:01:10 | 049,788,256 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\avira_antivir_personal_en.exe
PRC - [2011/02/13 16:18:48 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
PRC - [2011/01/13 15:20:24 | 000,666,792 | ---- | M] (Avira GmbH) -- C:\Documents and Settings\Theo Haris\Local Settings\temp\RarSFX0\setup.exe
PRC - [2011/01/10 14:23:42 | 000,588,456 | ---- | M] (Avira GmbH) -- C:\Documents and Settings\Theo Haris\Local Settings\temp\RarSFX0\presetup.exe
PRC - [2011/01/10 14:23:42 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/01/10 14:23:32 | 000,435,368 | ---- | M] (Avira GmbH) -- c:\Program Files\Avira\AntiVir Desktop\avscan.exe
PRC - [2011/01/10 14:23:32 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/01/10 14:23:30 | 000,389,288 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
PRC - [2011/01/10 14:23:30 | 000,361,128 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avconfig.exe
PRC - [2011/01/10 14:23:30 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/03/26 10:13:54 | 000,136,840 | ---- | M] () -- C:\Program Files\Join Air\UIExec.exe
PRC - [2010/03/26 09:59:00 | 000,251,016 | ---- | M] () -- C:\Program Files\Join Air\AssistantServices.exe
PRC - [2010/01/14 21:11:02 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/04/14 18:30:36 | 001,038,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/21 11:30:44 | 000,061,440 | ---- | M] () -- C:\Program Files\Telecom Italia\WanMiniport1st\WanMiniport1st_srv.exe
PRC - [2006/08/31 16:52:06 | 000,118,784 | ---- | M] (Bytemobile, Inc.) -- C:\WINDOWS\system32\bmwebcfg.exe
PRC - [2005/12/01 17:38:38 | 000,458,752 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\QtZgAcer.EXE
PRC - [2005/11/25 15:59:44 | 000,212,992 | ---- | M] (Acer Inc) -- C:\Acer\Empowering Technology\ePower\epm-dm.exe
PRC - [2005/11/16 17:00:50 | 000,397,312 | ---- | M] (acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\Monitor.exe
PRC - [2005/11/09 22:01:00 | 000,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2005/11/09 21:59:08 | 000,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2005/11/09 21:58:26 | 000,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2005/10/24 16:45:32 | 002,462,208 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admtray.exe
PRC - [2005/10/24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admServ.exe
PRC - [2005/10/19 09:30:16 | 000,069,632 | ---- | M] (HiTRUST) -- C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
PRC - [2005/01/07 16:17:16 | 000,102,491 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004/08/09 06:03:38 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () -- C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe


========== Modules (SafeList) ==========

MOD - [2011/02/13 16:18:48 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
MOD - [2010/08/23 19:12:06 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2005/12/05 16:00:10 | 000,053,248 | ---- | M] (HiTRUST) -- C:\WINDOWS\system32\sysenv.dll
MOD - [2005/08/24 01:24:00 | 000,010,752 | ---- | M] () -- C:\WINDOWS\system32\MSNChatHook.dll
MOD - [2005/01/07 16:17:08 | 000,069,723 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll
MOD - [2003/03/18 21:12:12 | 001,047,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MFC71u.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (Pcmrome)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Disabled | Stopped] -- -- (gupdate1c998781007dfbe) Google Update Service (gupdate1c998781007dfbe)
SRV - File not found [Disabled | Stopped] -- -- (CLTNetCnService)
SRV - File not found [Disabled | Stopped] -- -- (ccSetMgr)
SRV - File not found [Disabled | Stopped] -- -- (ccPwdSvc)
SRV - File not found [Disabled | Stopped] -- -- (ccEvtMgr)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/01/10 14:23:42 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/01/10 14:23:32 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/06/14 15:07:14 | 000,615,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010/03/26 09:59:00 | 000,251,016 | ---- | M] () [Auto | Running] -- C:\Program Files\Join Air\AssistantServices.exe -- (UI Assistant Service)
SRV - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2006/08/31 16:52:06 | 000,118,784 | ---- | M] (Bytemobile, Inc.) [Auto | Running] -- C:\WINDOWS\System32\bmwebcfg.exe -- (bmwebcfg)
SRV - [2005/11/14 01:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2005/11/09 22:01:00 | 000,540,745 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2005/11/09 21:59:08 | 000,114,753 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2005/11/09 21:58:26 | 000,217,164 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2005/10/24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) [Auto | Running] -- C:\Acer\Empowering Technology\admServ.exe -- (AWService)
SRV - [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\Program Files\Telecom Italia\WanMiniport1st\srvany.exe -- (Network WanMiniport First Position)


========== Driver Services (SafeList) ==========

DRV - [2011/02/04 12:42:58 | 000,071,680 | ---- | M] (Notebook Hardware Control) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\nhcDriver.sys -- (nhcDriverDevice)
DRV - [2011/01/10 14:23:54 | 000,135,096 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/01/10 14:23:54 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/06/17 14:27:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/06/17 14:27:14 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2010/02/26 14:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010/02/26 14:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010/02/26 14:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/02/26 14:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/10/29 19:28:24 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009/10/29 19:28:24 | 000,009,216 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter.sys -- (massfilter)
DRV - [2009/10/07 10:49:50 | 000,023,832 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
DRV - [2009/10/07 10:49:38 | 006,756,632 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 120(UVC)
DRV - [2009/10/07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009/09/25 08:05:20 | 000,278,984 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2009/01/06 20:07:28 | 000,124,464 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2008/09/05 21:25:04 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008/08/29 00:10:18 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/04/13 20:36:40 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 20:36:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 18:36:06 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2006/10/16 14:45:26 | 000,088,960 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2006/08/31 16:58:22 | 000,018,560 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2006/01/06 07:53:34 | 000,006,144 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV - [2006/01/04 07:46:42 | 001,420,288 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/11/17 15:45:40 | 004,069,888 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/11/09 14:45:56 | 000,013,440 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2005/10/23 19:20:52 | 000,218,496 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/10/18 01:53:24 | 000,998,656 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/10/18 01:52:30 | 000,721,280 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/10/15 18:20:44 | 000,012,106 | ---- | M] (OSA Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\OsaFsLoc.sys -- (OsaFsLoc)
DRV - [2005/09/29 20:11:42 | 000,078,720 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2005/09/13 15:34:40 | 000,004,392 | ---- | M] (OSA Technologies) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NdisFilt.sys -- (NdisFilt)
DRV - [2005/09/11 19:49:44 | 003,298,432 | ---- | M] (IntelŽ Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2005/06/30 16:58:24 | 000,007,296 | ---- | M] (OSA Technologies, An Avocent Company) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio)
DRV - [2005/05/02 12:13:42 | 000,009,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETMNT.sys -- (NETMNT)
DRV - [2005/04/07 18:08:46 | 000,078,208 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-shd.sys -- (EpmShd)
DRV - [2005/01/14 15:57:16 | 000,004,010 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm)
DRV - [2005/01/13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys)
DRV - [2005/01/07 16:03:42 | 000,191,456 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2004/12/08 14:10:00 | 000,016,896 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2004/09/07 20:00:00 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2004/09/07 20:00:00 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2004/09/07 20:00:00 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2004/09/07 20:00:00 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2004/09/07 20:00:00 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2004/09/07 20:00:00 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2004/09/07 20:00:00 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2004/09/07 20:00:00 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2004/09/07 20:00:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2004/09/07 20:00:00 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2004/09/07 20:00:00 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2004/09/07 20:00:00 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2004/09/07 20:00:00 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2004/09/07 20:00:00 | 000,006,784 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
DRV - [2004/09/07 20:00:00 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2004/07/19 13:10:00 | 000,004,096 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-psd.sys -- (EpmPsd)
DRV - [2004/06/26 13:22:00 | 000,004,736 | ---- | M] (RDV Soft) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vncdrv.sys -- (vncdrv)
DRV - [2004/03/08 12:55:50 | 000,013,567 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)
DRV - [2003/12/15 18:22:00 | 000,038,448 | ---- | M] (OLYMPUS OPTICAL CO.,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VNUSB.sys -- (VNUSB)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://e-learning.hau.gr/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "en.wikipedia.org"
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.48.3
FF - prefs.js..extensions.enabledItems: {3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}:0.9.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.7
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.7.4
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: [email protected]:2.4.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.732
FF - prefs.js..network.proxy.type: 0

FF - user.js..network.proxy.type: 0
FF - user.js..network.proxy.http: ""
FF - user.js..network.proxy.http_port: 0
FF - user.js..network.proxy.ssl: ""
FF - user.js..network.proxy.ssl_port: 0
FF - user.js..network.proxy.ftp: ""
FF - user.js..network.proxy.ftp_port: 0
FF - user.js..network.proxy.gopher: ""
FF - user.js..network.proxy.gopher_port: 0
FF - user.js..network.proxy.socks_version: 5
FF - user.js..network.proxy.socks: ""
FF - user.js..network.proxy.socks_port: 0

FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/11/17 13:28:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2006/07/15 20:42:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2006/07/15 20:42:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2008/08/29 02:37:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Extensions
[2006/07/15 20:49:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions
[2011/02/10 21:53:34 | 000,000,000 | ---D | M] (Session Manager) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2011/01/07 13:33:32 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2008/05/22 19:44:28 | 000,000,000 | ---D | M] (Forecastbar Enhanced) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}
[2011/02/03 14:20:48 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/04/29 18:32:16 | 000,000,000 | ---D | M] (Tamper Data) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2010/09/10 02:45:26 | 000,000,000 | ---D | M] (WOT) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/01/12 14:03:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/12/27 00:48:18 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/09/07 14:58:42 | 000,000,000 | ---D | M] ("BetterPrivacy") -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010/06/18 13:12:38 | 000,000,000 | ---D | M] ("Tab Mix Plus") -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2011/01/27 19:16:54 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/11/22 23:18:32 | 000,000,000 | ---D | M] (Ghostery) -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\extensions\[email protected]
[2008/11/04 20:21:56 | 000,005,179 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Profiles\ixy64s0q.default\searchplugins\BitTorrent.xml
[2006/07/15 20:42:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/25 19:35:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/04/19 15:02:14 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/17 13:28:06 | 000,000,000 | ---D | M] (PC Sync 2 Synchronisation Extension) -- C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC
[2009/03/16 21:28:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2007/01/04 02:29:08 | 000,049,152 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/08/03 18:40:56 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/08/03 18:40:56 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/08/03 18:40:56 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/08/03 18:40:56 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/02/13 17:10:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {B7FC60D5-AB79-477E-96EE-5C7770EAEAB9} - No CLSID value found.
O4 - HKLM..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe (Acer Value Labs, Taiwan)
O4 - HKLM..\Run: [ADMTray.exe] C:\Acer\Empowering Technology\admtray.exe (Avocent Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe (HiTRUST)
O4 - HKLM..\Run: [EPM-DM] c:\Acer\Empowering Technology\ePower\epm-dm.exe (Acer Inc)
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe (acer Inc.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [UIExec] C:\Program Files\Join Air\UIExec.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Sample Toolband Serach - C:\WINDOWS\System32\ToolBand.dll (HiTRUST)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1152986441640 (MUWebControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\cbXrPFXn: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Τρέχουσα αρχική σελίδα) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Theo Haris\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/20 23:33:42 | 000,000,065 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2006/01/06 07:54:00 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.FRK -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/13 22:10:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2011/02/13 22:08:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Application Data\Avira
[2011/02/13 22:06:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Προγράμματα\Avira
[2011/02/13 22:06:09 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/02/13 22:06:08 | 000,135,096 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011/02/13 22:06:08 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/02/13 22:06:08 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/02/13 22:06:08 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/02/13 22:06:07 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/02/13 22:06:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2011/02/13 19:31:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Application Data\Malwarebytes
[2011/02/13 19:31:19 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/13 19:31:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Προγράμματα\Malwarebytes' Anti-Malware
[2011/02/13 19:31:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/13 19:31:14 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/13 19:31:14 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/13 17:59:13 | 000,000,000 | -HSD | C] -- C:\Recycled
[2011/02/13 17:55:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\avz4
[2011/02/13 17:28:07 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2011/02/13 17:02:52 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/02/13 16:59:54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/02/13 16:59:54 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/02/13 16:59:54 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/02/13 16:59:54 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/02/13 16:59:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/02/13 16:39:34 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/02/13 16:30:09 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/02/13 16:18:49 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
[2011/02/09 20:56:07 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Theo Haris\Recent
[2011/02/09 20:52:51 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/02/09 19:57:15 | 000,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2011/02/07 01:43:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Quiz #3
[2011/02/04 12:42:56 | 000,071,680 | ---- | C] (Notebook Hardware Control) -- C:\WINDOWS\System32\drivers\nhcDriver.sys
[2011/02/04 12:42:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Application Data\Notebook Hardware Control
[2011/02/04 00:04:26 | 000,000,000 | ---D | C] -- C:\Program Files\Motherboard Monitor 5
[2011/02/03 23:57:59 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedFan
[2011/01/27 00:57:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Stefanos translations
[2011/01/18 21:01:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\Downloads

========== Files - Modified Within 30 Days ==========

[2011/02/13 22:24:26 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\~$εξέγερση στην Αίγυπτο.doc
[2011/02/13 22:05:02 | 000,000,546 | ---- | M] () -- C:\WINDOWS\System32\eRLog.ini
[2011/02/13 22:04:10 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/13 22:02:56 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/13 22:02:48 | 1071,763,456 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/13 19:59:02 | 000,120,832 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Case study.doc
[2011/02/13 19:31:20 | 000,000,692 | ---- | M] () -- C:\Documents and Settings\All Users\Επιφάνεια εργασίας\Malwarebytes' Anti-Malware.lnk
[2011/02/13 17:54:48 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2011/02/13 17:02:58 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/02/13 16:21:52 | 004,267,346 | R--- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\ComboFix.exe
[2011/02/13 16:18:48 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\OTL.exe
[2011/02/13 13:05:48 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Η εξέγερση στην Αίγυπτο.doc
[2011/02/13 03:58:32 | 000,466,254 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Tali-riding-on-crescent-moon-p192w250.psd
[2011/02/12 19:52:34 | 000,053,731 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\n539515072_373915_9429.jpg
[2011/02/12 19:43:38 | 000,020,574 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\woman-riding-on-crescent-moon-p192w250.jpg
[2011/02/11 00:06:48 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/10 22:08:14 | 000,033,792 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_FAQ.doc
[2011/02/10 21:50:18 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/02/09 21:03:50 | 000,441,598 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\cc_20110209_210017.reg
[2011/02/09 19:59:12 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\housecall.guid.cache
[2011/02/09 12:53:40 | 000,341,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/08 16:53:32 | 000,073,728 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\An Introduction.doc
[2011/02/08 01:54:42 | 000,176,129 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Equity, Social Justice, and Sustainable.pdf
[2011/02/04 12:42:58 | 000,071,680 | ---- | M] (Notebook Hardware Control) -- C:\WINDOWS\System32\drivers\nhcDriver.sys
[2011/02/04 12:27:48 | 000,522,285 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\History of Yemen.pdf
[2011/02/03 23:58:00 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
[2011/02/03 18:26:26 | 001,123,328 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\KorelasMScGHRDissertation1.doc
[2011/02/02 16:38:38 | 000,585,728 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia- Greek.doc
[2011/02/02 14:34:36 | 000,702,464 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia jen revised.doc
[2011/01/28 15:46:26 | 000,295,451 | ---- | M] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_guidelines_content-language.pdf

========== Files Created - No Company Name ==========

[2011/02/13 19:59:00 | 000,120,832 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Case study.doc
[2011/02/13 19:31:19 | 000,000,692 | ---- | C] () -- C:\Documents and Settings\All Users\Επιφάνεια εργασίας\Malwarebytes' Anti-Malware.lnk
[2011/02/13 17:02:56 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/02/13 17:02:54 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/02/13 16:59:54 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/02/13 16:59:54 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/02/13 16:59:54 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/02/13 16:59:54 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/02/13 16:59:54 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/02/13 16:21:32 | 004,267,346 | R--- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\ComboFix.exe
[2011/02/13 13:05:47 | 000,034,816 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Η εξέγερση στην Αίγυπτο.doc
[2011/02/12 20:01:57 | 000,466,254 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Tali-riding-on-crescent-moon-p192w250.psd
[2011/02/12 19:52:31 | 000,053,731 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\n539515072_373915_9429.jpg
[2011/02/12 19:43:30 | 000,020,574 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\woman-riding-on-crescent-moon-p192w250.jpg
[2011/02/10 22:08:14 | 000,033,792 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_FAQ.doc
[2011/02/09 21:00:30 | 000,441,598 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\cc_20110209_210017.reg
[2011/02/09 19:59:10 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\housecall.guid.cache
[2011/02/08 16:53:56 | 000,073,728 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\An Introduction.doc
[2011/02/08 01:54:43 | 000,176,129 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\Equity, Social Justice, and Sustainable.pdf
[2011/02/04 12:27:44 | 000,522,285 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\History of Yemen.pdf
[2011/02/03 23:57:56 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo
[2011/02/02 14:34:23 | 000,702,464 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia jen revised.doc
[2011/02/02 13:15:43 | 000,585,728 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\The Story of Gaia- Greek.doc
[2011/01/31 13:50:56 | 001,123,328 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Τα έγγραφά μου\KorelasMScGHRDissertation1.doc
[2011/01/28 15:46:24 | 000,295,451 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Επιφάνεια εργασίας\WAC_guidelines_content-language.pdf
[2010/02/08 18:38:51 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/01 16:02:13 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Local Settings\Application Data\fusioncache.dat
[2010/01/26 23:06:44 | 000,082,289 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/01/11 20:09:21 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Game.INI
[2009/10/07 01:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/08/25 04:14:35 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
[2009/08/20 23:51:10 | 000,758,272 | ---- | C] () -- C:\WINDOWS\System32\kcpp.dll
[2009/06/12 22:04:55 | 000,000,251 | ---- | C] () -- C:\WINDOWS\MugE.ini
[2009/03/29 15:09:11 | 000,000,367 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Application Data\flashfavorite.htm
[2009/02/28 16:37:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\ncvDS61.dll
[2009/02/28 16:37:36 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\ncCompress.dll
[2009/02/28 16:37:36 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ncUtil62.dll
[2009/02/28 16:37:31 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\nczlib.dll
[2009/02/28 16:37:31 | 000,053,760 | ---- | C] () -- C:\WINDOWS\System32\zlib32.dll
[2008/08/29 00:10:18 | 000,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008/08/29 00:10:17 | 000,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/07/10 01:30:59 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/06/15 18:53:21 | 000,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008/05/26 22:22:52 | 000,017,986 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008/05/26 22:22:50 | 000,022,822 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008/05/26 22:22:48 | 000,017,066 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008/04/01 00:45:25 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008/02/08 00:59:16 | 000,241,664 | ---- | C] () -- C:\WINDOWS\NwtGatewayDLL.dll
[2008/02/08 00:59:16 | 000,001,110 | ---- | C] () -- C:\WINDOWS\NwtGatewayConfig.ini
[2007/10/25 00:40:19 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02D.ini
[2007/10/25 00:32:35 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02C.ini
[2007/10/24 23:18:19 | 000,000,187 | ---- | C] () -- C:\WINDOWS\RELATION.INI
[2007/10/24 22:55:10 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02B.ini
[2007/10/24 22:22:26 | 000,002,004 | ---- | C] () -- C:\WINDOWS\IMM02A.ini
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/04/15 14:21:23 | 000,000,683 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2007/04/11 21:12:12 | 000,001,387 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/10 16:09:23 | 000,000,258 | ---- | C] () -- C:\WINDOWS\QTW.ini
[2006/11/23 17:36:56 | 000,000,031 | ---- | C] () -- C:\WINDOWS\warhead.ini
[2006/10/13 15:18:40 | 000,108,544 | ---- | C] () -- C:\WINDOWS\System32\vbis4032.dll
[2006/10/13 15:18:31 | 000,000,082 | ---- | C] () -- C:\WINDOWS\System32\lexiko.ini
[2006/09/30 15:44:20 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2006/08/18 21:24:10 | 000,005,509 | ---- | C] () -- C:\Documents and Settings\Theo Haris\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/08/18 21:24:10 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/07/26 02:57:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
[2006/07/17 17:22:43 | 000,007,224 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/07/17 04:06:41 | 000,000,265 | ---- | C] () -- C:\WINDOWS\scummvm.ini
[2006/07/16 00:49:43 | 000,000,319 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2006/07/16 00:39:27 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/07/16 00:34:16 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2006/07/16 00:34:11 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/07/15 20:44:44 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/07/15 18:17:57 | 000,000,546 | ---- | C] () -- C:\WINDOWS\System32\eRLog.ini
[2006/07/15 18:10:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NT.INI
[2006/07/15 18:09:01 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\SC_res.dll
[2006/07/15 18:09:01 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\EN_res.dll
[2006/07/15 18:09:01 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\TC_res.dll
[2006/07/15 18:09:01 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\MSNChatHook.dll
[2006/07/15 18:09:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\APISlice.dll
[2006/03/16 10:42:57 | 000,002,772 | ---- | C] () -- C:\WINDOWS\AntiV.INI
[2006/01/06 14:30:08 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/01/06 07:26:26 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/12/14 20:59:52 | 000,000,038 | ---- | C] () -- C:\WINDOWS\Acer.ini
[2005/12/01 00:24:56 | 000,037,706 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/10/21 00:58:52 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\vspxvfw.dll
[2005/09/01 16:20:46 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\vspxcore.dll
[2005/05/02 12:13:42 | 000,009,600 | ---- | C] () -- C:\WINDOWS\System32\drivers\NETMNT.sys
[2005/03/28 00:45:26 | 000,000,093 | ---- | C] () -- C:\WINDOWS\ALaunch.ini
[2004/09/07 20:00:00 | 000,003,341 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/12/29 20:45:08 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ServiceControl.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/12/26 15:12:30 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll
[2001/09/03 22:46:38 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 15:33:56 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 21:04:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1996/04/03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2006/07/15 18:14:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acer
[2007/02/10 01:20:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2007/02/16 03:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/09/21 18:46:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Emotum
[2008/01/24 23:26:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Valusoft
[2008/06/11 01:26:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
[2008/09/29 14:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Games
[2008/10/06 23:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/10/10 22:27:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2008/12/06 23:43:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NevoSoft Games
[2009/03/14 06:06:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2009/03/14 06:12:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/12/17 14:10:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Final Draft
[2010/01/04 15:47:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\The Mirror Mysteries
[2010/01/10 23:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SulusGames
[2010/01/18 00:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\River Past G5
[2010/01/25 01:57:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/02/18 21:06:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ludia
[2010/05/29 22:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nifflas
[2010/08/03 18:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010/09/07 19:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/11 22:57:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2010/11/13 15:21:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeHideIP
[2010/11/13 15:30:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Arovax
[2010/11/26 00:58:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/11/26 13:55:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/11/26 14:09:50 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/12/16 01:22:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Clarus
[2006/07/15 18:14:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Acer
[2006/08/19 14:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\BitTorrent
[2006/09/30 16:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Image Zone Express
[2007/01/21 21:06:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\PlayFirst
[2007/01/31 19:36:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\BSplayer
[2007/03/01 14:09:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\BSplayer Pro
[2007/05/02 14:24:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\uTorrent
[2008/01/24 23:26:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Valusoft
[2008/02/08 00:59:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Bytemobile
[2008/02/08 00:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\ICS
[2008/02/08 01:06:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Vodafone Mobile Connect
[2008/06/11 00:01:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Home Sweet Home
[2008/09/05 21:24:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\DAEMON Tools
[2009/03/16 21:01:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Windows Desktop Search
[2009/03/16 21:05:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Windows Search
[2009/06/12 21:55:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\GetRight
[2009/09/02 18:46:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\GraveyardShift
[2009/09/20 18:26:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Flood Light Games
[2009/09/25 08:19:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Games
[2009/12/17 14:12:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Final Draft
[2009/12/24 12:42:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\com.adobe.example.avatarAirApplication.199ED43C2CFEB351CD0244628B93195D7C58F98C.1
[2010/01/10 23:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\SulusGames
[2010/01/10 23:11:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Enlightenus
[2010/01/11 20:20:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Orneon
[2010/01/17 21:30:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\WebCam Recorder
[2010/01/18 00:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\River Past G5
[2010/01/22 01:42:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\GetRightToGo
[2010/01/26 23:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Leadertech
[2010/02/12 00:34:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Free Mp3 Wma Ogg Converter
[2010/02/18 21:06:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Ludia
[2010/05/09 04:34:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\NotMyIp
[2010/05/09 16:53:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Hide IP NG
[2010/05/29 22:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Nifflas
[2010/08/04 00:07:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\ESET
[2010/09/25 04:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Big Fish Games
[2010/11/13 15:21:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\FreeHideIP
[2010/11/15 18:18:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Dropbox
[2010/11/17 13:29:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\PC Suite
[2010/11/17 13:29:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Nokia
[2010/11/26 14:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\AVG10
[2010/11/28 03:11:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Phenomenon 32 Saves
[2010/12/15 01:26:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\.minecraft
[2011/02/04 12:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Theo Haris\Application Data\Notebook Hardware Control

========== Purity Check ==========



< End of report >
  • 0

#12
michaelg9

michaelg9

    Trusted Helper

  • Malware Removal
  • 2,949 posts
Hey,

It's ok like this :D

Congratulations! Your logs are clean! :D Now that you are clean, please follow these precautions in order to keep safe:


Over the course of the fix you've used a variety of special tools to help with the cleaning process - none of these are of any use to you now that you're clean, and it's best not to have them hanging around on your computer. OTC is a small program that removes all the leftover tools and logs from cleanup of malware.

Please download OTC to your desktop.
  • Double-click OTC to run it. (Vista users, please right click on OTC and select "Run as an Administrator")
  • Click on the CleanUp! button and follow the prompts.
  • You will be asked to reboot the machine to finish the Cleanup process, choose Yes.
  • After the reboot all the tools we used should be gone.
Note: Some more recently created tools may not yet be removed by OTC. Feel free to manually delete any tools it leaves behind.


Next:


Uninstall ComboFix from your computer:
  • Click on Start > Run
  • Type Combofix /u in the run box and click Ok. Note the space between the x and the /u, it needs to be there.
    Posted Image


Next:


Make your Internet Explorer more secure - Internet Explorer is not the most secure browser you can use, but as long as it exists on your system, take these simple steps to make it more secure:
From within Internet Explorer click on the Tools menu and then click on Options. Click once on the Security tab Click once on the Internet icon so it becomes highlighted. Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt.
  • Change the Download unsigned ActiveX controls to Disable.
  • Change the Initialize and script ActiveX controls not marked as safe to Disable.
  • Change the Installation of desktop items to Prompt.
  • Change the Launching programs and files in an IFRAME to Prompt.
  • Change the Navigate sub-frames across different domains to Prompt.
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Now navigate to Advanced tab and select:
  • Empty temporary Internet files folder when browser is closed.
Next press the Apply button and then the OK to exit the Internet Properties page.


Next:


Use Firefox instead of Internet Explorer, as most of malware are exploiting Internet Explorer's vulnerabilities, with Firefox you will be more secure.
Note: If you are going to use Firefox I would suggest the use of these add-ons:
  • NoScript - for blocking ads and other potential website attacks.
  • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling.


Next:


Automatic Updates for Windows
  • Click Start.
  • Select Settings and then Control Panel.
  • Select Automatic Updates.
  • Click Automatic (recommended)
  • Choose a day and a time when you know the computer will be on and connected to the internet.
  • Click Apply then OK.


Next:


Antivirus - No need to explain how important is the use of ONE antivirus. It is not recommended to run more than one firewall or anti-virus program. Running more than one of these at a time can cause system crashes, high system usage and/or conflicts with each other
If you already have one installed, keep it.


Next:


Firewall - Another very important security tool called firewall. The are my recommendations, however you must use only one:
If you already have one installed, keep it.


Next:


Additional security programs - For additional security, the use of these tools is important:
  • Malwarebytes Anti-Malware. - Update the free version and scan with it often. It is an excellent scanning tool to have on your side.
  • Javacool's SpywareBlaster: - It will protect you from most spy/foistware in it's database by blocking installation of their ActiveX objects.
    Download and install, download the latest updates, and you'll see a list of all spyware programs covered by the program (NOTE: this is NOT spyware found on your computer)

    Press "Enable All Protection", and you're done.
    The spyware that you told Spywareblaster to set the "kill bit" for won't be a hazard to you any longer.
    Although it won't protect you from every form of spyware known to man, it is a very potent extra layer of protection.
    Don't forget to check for updates every week or so.
  • The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer. This little program packs a powerful punch as it block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial


Next:


Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.


Next:


Posted ImageUpgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE).
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the file and select "Run as an Administrator.")


Next:


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.


Next:


Keep a backup of your important files to prevent future data loss.


Happy safe computing !! ;)
  • 0

#13
Theo Haris

Theo Haris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Thank you, Michael. I have followed all of your instructions and now I feel safer :D

Thank you for your time and help.
  • 0

#14
michaelg9

michaelg9

    Trusted Helper

  • Malware Removal
  • 2,949 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :D

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP