also avast gives URL blocked pop ups for 199.80.55.19 as Malicious URL Blocked, also we can not access windows update from the PC (running Windows XP Home sp3) and when trying to post to the fourms we got an error saying "request timed out" (im posting from a clean laptop)
Thanks for reading and help in advance
WigglesGRN
OTL Logs:
OTL logfile created on: 29/04/2011 15:26:45 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Gilli\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format:
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 2.90 Gb Free Space | 7.79% Space Free | Partition Type: NTFS
Computer Name: PAIRENTSPC | User Name: Gilli | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/04/29 15:26:04 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Gilli\My Documents\Downloads\OTL.exe
PRC - [2011/04/20 16:57:04 | 002,423,752 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2011/04/18 18:25:12 | 003,460,784 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/04/18 18:25:10 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/04/14 17:41:09 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/03/07 12:21:00 | 000,107,008 | ---- | M] (Eastman Kodak Company) -- C:\Program Files\Kodak\KODAK Share Button App\Listener.exe
PRC - [2011/01/31 13:16:40 | 000,703,360 | ---- | M] (Nokia) -- C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
PRC - [2010/12/08 15:31:06 | 000,628,736 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2010/11/23 18:49:24 | 001,540,096 | ---- | M] (Nokia) -- C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
PRC - [2010/11/16 15:48:32 | 000,152,576 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2010/11/15 14:41:18 | 000,367,496 | ---- | M] () -- C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe
PRC - [2010/05/11 11:11:58 | 000,134,144 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
PRC - [2010/01/27 09:40:58 | 000,323,584 | ---- | M] (Eastman Kodak Company) -- C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
PRC - [2009/10/27 10:15:02 | 000,120,832 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2009/04/08 10:34:06 | 001,662,976 | ---- | M] (Belkin) -- C:\Program Files\Belkin\F5D8055\v2\Belkinwcui.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/02/23 11:13:10 | 000,077,824 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2003/08/29 19:05:35 | 000,360,448 | ---- | M] () -- C:\Program Files\SpywareGuard\sgmain.exe
PRC - [2003/08/29 11:14:56 | 000,233,472 | ---- | M] () -- C:\Program Files\SpywareGuard\sgbhp.exe
========== Modules (SafeList) ==========
MOD - [2011/04/29 15:26:04 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Gilli\My Documents\Downloads\OTL.exe
MOD - [2011/04/18 18:25:09 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2010/08/23 17:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/04/18 18:25:10 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/12/08 15:31:06 | 000,628,736 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
========== Driver Services (SafeList) ==========
DRV - [2011/04/18 18:17:46 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/04/18 18:17:34 | 000,307,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/04/18 18:16:18 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/04/18 18:16:06 | 000,102,488 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/04/18 18:13:21 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/04/18 18:13:02 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/04/18 18:12:58 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/07/30 15:16:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010/07/30 15:16:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010/07/30 15:16:42 | 000,023,040 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/07/30 15:16:38 | 000,018,048 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2010/05/10 19:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/04/12 02:40:28 | 000,019,200 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)
DRV - [2010/04/12 02:17:36 | 000,324,608 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
DRV - [2010/02/17 19:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/04/04 16:08:08 | 000,713,344 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt2870.sys -- (rt2870)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/04/16 22:46:00 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2006/12/19 17:00:56 | 000,011,648 | ---- | M] (Hewlett-Packard Development Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hpnucmp.sys -- (HPNUCMP)
DRV - [2006/12/19 17:00:50 | 000,011,136 | ---- | M] (Hewlett-Packard Development Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hpnuhst.sys -- (hpnuhst)
DRV - [2006/12/19 17:00:44 | 000,037,248 | ---- | M] (Hewlett-Packard Development Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hpnuhub.sys -- (HPNUHUB)
DRV - [2006/01/19 22:10:50 | 000,363,008 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt61.sys -- (RT61)
DRV - [2005/10/03 13:18:08 | 000,189,908 | ---- | M] (Zoran Microelectronics Ltd.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\CoachWdm.sys -- (CoachWdm)
DRV - [2005/02/24 07:20:22 | 002,311,680 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/11/05 04:29:30 | 000,121,728 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys -- (SiSGbeXP)
DRV - [2000/10/15 17:38:54 | 000,016,068 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\PCANDIS5.SYS -- (PCANDIS5)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://uk.msn.com/"
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/05/25 10:03:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/04 10:57:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/03/09 15:47:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/28 21:57:53 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/03/09 15:47:29 | 000,000,000 | ---D | M]
[2011/04/28 21:58:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Gilli\Application Data\Mozilla\Extensions
[2011/04/28 21:57:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2010/02/16 21:02:20 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/04/14 17:41:09 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 09:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 09:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/01/01 09:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
Hosts file not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-CFC3-3CECC9AB2EDA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [F5D8055v2] C:\Program Files\Belkin\F5D8055\v2\Belkinwcui.exe (Belkin)
O4 - HKLM..\Run: [KodakShareButtonApp] C:\Program Files\Kodak\KODAK Share Button App\Listener.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [SiSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [{C0695248-403D-F9F5-D7F3-EAE9822F2566}] File not found
O4 - HKCU..\Run: [{EA078DD4-9E1E-380F-5DB8-938D97002912}] File not found
O4 - HKCU..\Run: [GHWAUC6NNZ] File not found
O4 - HKCU..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe (Nokia)
O4 - HKCU..\Run: [NtWqIVLZEWZU] File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [Ulafogaxeyuvasax] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
O4 - Startup: C:\Documents and Settings\Gilli\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: microsoft.com ([update] http in Local intranet)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus....ek_sys_ctrl.cab (asusTek_sysctrl Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebo...toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1128332850703 (WUWebControl Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symant...ex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1148978116000 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.c.../cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1....loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} http://h30043.www3.h.../qdiagh.cab?326 (QDiagHUpdateObj Class)
O16 - DPF: {FD0EBBED-0C42-4D0F-82DA-44399B5C420A} http://downloads.vir...er1/xp_mail.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Gilli\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Gilli\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/30 10:15:43 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{483e6160-d218-11df-9b0e-002275408818}\Shell - "" = AutoRun
O33 - MountPoints2\{483e6160-d218-11df-9b0e-002275408818}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{483e6160-d218-11df-9b0e-002275408818}\Shell\AutoRun\command - "" = F:\KODAK_Software_Downloader.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/04/28 22:23:28 | 001,377,112 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Gilli\Desktop\TDSSKiller.exe
[2011/04/28 22:19:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gilli\Desktop\hosts
[2011/04/28 22:02:20 | 000,000,000 | ---D | C] -- C:\Program Files\SpywareGuard
[2011/04/28 22:02:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SpywareGuard
[2011/04/28 22:01:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gilli\My Documents\Downloads
[2011/04/28 21:58:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gilli\Local Settings\Application Data\Mozilla
[2011/04/28 21:58:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gilli\Application Data\Mozilla
[2011/04/28 21:57:49 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011/04/28 21:56:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/04/28 21:56:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SpywareBlaster
[2011/04/28 21:56:13 | 000,000,000 | ---D | C] -- C:\Program Files\SpywareBlaster
[2011/04/28 21:47:24 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/04/28 21:08:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2011/04/28 20:53:36 | 000,000,000 | ---D | C] -- C:\MGTools
[2011/04/28 20:42:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/04/28 20:26:33 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/04/28 20:22:26 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/04/28 20:22:26 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/04/28 20:22:26 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/04/28 20:22:26 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/04/28 20:22:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/04/28 20:21:18 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/28 19:21:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011/04/28 19:17:33 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Gilli\Recent
[2011/04/28 19:15:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/04/28 19:15:22 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/04/28 17:58:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Real
[2011/04/28 17:00:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/04/28 17:00:48 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/04/27 21:44:49 | 000,307,288 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/04/27 21:44:49 | 000,019,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/04/27 21:44:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/04/27 21:44:47 | 000,025,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/04/27 21:44:46 | 000,441,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/04/27 21:44:46 | 000,049,240 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/04/27 21:44:45 | 000,102,488 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/04/27 21:44:45 | 000,096,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/04/27 21:44:44 | 000,030,680 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/04/27 21:44:31 | 000,040,112 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/04/27 21:44:30 | 000,199,304 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/04/27 21:44:20 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/04/27 21:44:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/27 21:10:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gilli\Application Data\SUPERAntiSpyware.com
[2011/04/27 20:52:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2011/04/27 20:28:13 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2011/04/27 17:59:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/04/27 17:19:32 | 000,000,000 | ---D | C] -- C:\fe7425e4a7ef88f65276324cdaaabd
[2011/04/27 17:02:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/04/27 16:54:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gilli\Application Data\Osonov
[2011/04/27 16:54:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gilli\Application Data\Asbiiw
[2011/04/27 16:23:02 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2011/04/27 16:23:02 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2011/04/27 16:21:27 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2011/04/27 15:16:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gilli\Application Data\Oxyc
[2011/04/27 15:16:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gilli\Application Data\Efwya
[2011/04/27 15:14:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/04/27 15:14:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/04/27 15:13:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/04/27 15:13:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/04/27 15:05:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gilli\Local Settings\Application Data\{38D68470-C99F-456A-B49C-FB15EF747F88}
[2011/04/06 11:18:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Nokia PC Suite
[2011/04/06 11:18:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PCSuite
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/29 15:36:00 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{F2CD3050-988F-4A9B-B8A5-396F3AB4127C}.job
[2011/04/29 15:33:08 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2011/04/29 15:21:02 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{A01C03DB-872A-4DA0-A521-43DC3FA62DC0}.job
[2011/04/29 15:19:07 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/29 15:17:39 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/28 22:18:54 | 000,151,515 | ---- | M] () -- C:\Documents and Settings\Gilli\Desktop\hosts.zip
[2011/04/28 22:03:25 | 205,674,200 | ---- | M] () -- C:\Documents and Settings\Gilli\Desktop\100_235_PS_AIO_02_Full_NonNet_enu_NB.exe
[2011/04/28 22:02:20 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\Gilli\Desktop\SpywareGuard LiveUpdate.lnk
[2011/04/28 22:02:20 | 000,000,650 | ---- | M] () -- C:\Documents and Settings\Gilli\Start Menu\Programs\Startup\SpywareGuard.lnk
[2011/04/28 22:02:20 | 000,000,638 | ---- | M] () -- C:\Documents and Settings\Gilli\Desktop\SpywareGuard.lnk
[2011/04/28 21:58:07 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2011/04/28 21:57:56 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\Gilli\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/28 21:57:55 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/28 21:56:16 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\Gilli\Desktop\SpywareBlaster.lnk
[2011/04/28 21:39:53 | 000,045,093 | ---- | M] () -- C:\Documents and Settings\Gilli\Desktop\HP Installation Error - XP.hta
[2011/04/28 21:26:15 | 000,164,678 | ---- | M] () -- C:\WINDOWS\hpoins21.dat
[2011/04/28 21:11:09 | 000,001,858 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HP Photosmart Essential 2.5.lnk
[2011/04/28 21:10:22 | 000,001,960 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Shop for HP Supplies.lnk
[2011/04/28 20:57:23 | 000,116,918 | ---- | M] () -- C:\MGlogs.zip
[2011/04/28 20:26:38 | 000,000,331 | RHS- | M] () -- C:\boot.ini
[2011/04/28 19:15:23 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/04/28 17:04:24 | 000,469,718 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/04/28 17:04:24 | 000,080,758 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/04/28 17:00:52 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/04/28 16:41:30 | 000,000,215 | ---- | M] () -- C:\Boot.bak
[2011/04/28 16:32:54 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Gilli\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/27 21:44:49 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/04/27 21:44:45 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/04/27 21:02:33 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/04/27 20:53:21 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2011/04/27 20:51:33 | 000,282,128 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/27 17:51:20 | 002,418,162 | ---- | M] () -- C:\MGtools.exe
[2011/04/27 17:28:55 | 000,015,404 | -HS- | M] () -- C:\Documents and Settings\Gilli\Local Settings\Application Data\61q6o46e8220c14y4uxr01jg5f00adhtyl0247wa
[2011/04/27 17:28:55 | 000,015,404 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\61q6o46e8220c14y4uxr01jg5f00adhtyl0247wa
[2011/04/27 17:19:55 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/04/27 17:09:29 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Efevuqejak.dat
[2011/04/27 16:25:17 | 000,000,288 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/04/27 16:19:56 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/04/27 16:19:56 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/04/27 16:19:43 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2011/04/27 16:17:36 | 000,023,444 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/04/27 15:05:28 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Oseyafidac.bin
[2011/04/27 15:03:25 | 000,122,880 | RHS- | M] () -- C:\WINDOWS\System32\ssmyst9.dll
[2011/04/27 15:03:25 | 000,122,880 | RHS- | M] () -- C:\WINDOWS\System32\pifmgr9.dll
[2011/04/27 15:03:24 | 000,122,880 | RHS- | M] () -- C:\WINDOWS\System32\dskquouin.dll
[2011/04/27 14:32:07 | 000,163,633 | ---- | M] () -- C:\WINDOWS\setupapi.old
[2011/04/26 10:15:41 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/19 15:59:54 | 000,516,042 | ---- | M] () -- C:\Documents and Settings\Gilli\My Documents\Baby Farenden Jackson 30weeks + 5 Days Scan.JPG
[2011/04/19 15:58:00 | 000,614,424 | ---- | M] () -- C:\Documents and Settings\Gilli\My Documents\3D Baby Face.JPG
[2011/04/19 15:57:37 | 000,516,042 | ---- | M] () -- C:\Documents and Settings\Gilli\My Documents\30wks + 5days Scan.JPG
[2011/04/18 18:25:12 | 000,040,112 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/04/18 18:25:10 | 000,199,304 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/04/18 18:17:46 | 000,441,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/04/18 18:17:34 | 000,307,288 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/04/18 18:16:18 | 000,049,240 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/04/18 18:16:06 | 000,102,488 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/04/18 18:16:02 | 000,096,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/04/18 18:13:21 | 000,025,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/04/18 18:13:02 | 000,030,680 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/04/18 18:12:58 | 000,019,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/04/18 17:28:35 | 037,977,088 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2011/04/18 17:28:34 | 018,449,408 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb
[2011/04/18 16:46:13 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2011/04/15 16:07:31 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Gilli\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2011/04/08 15:39:25 | 000,081,920 | ---- | M] () -- C:\Documents and Settings\Gilli\My Documents\Wedding acceptence.pub
[2011/04/08 15:36:58 | 000,002,461 | ---- | M] () -- C:\Documents and Settings\Gilli\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Publisher 2003.lnk
[2011/04/06 11:18:21 | 000,001,763 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Nokia PC Suite.lnk
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/28 22:18:54 | 000,151,515 | ---- | C] () -- C:\Documents and Settings\Gilli\Desktop\hosts.zip
[2011/04/28 22:02:20 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\Gilli\Desktop\SpywareGuard LiveUpdate.lnk
[2011/04/28 22:02:20 | 000,000,650 | ---- | C] () -- C:\Documents and Settings\Gilli\Start Menu\Programs\Startup\SpywareGuard.lnk
[2011/04/28 22:02:20 | 000,000,638 | ---- | C] () -- C:\Documents and Settings\Gilli\Desktop\SpywareGuard.lnk
[2011/04/28 21:58:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/04/28 21:57:55 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\Gilli\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/28 21:57:55 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/04/28 21:57:55 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/28 21:56:16 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\Gilli\Desktop\SpywareBlaster.lnk
[2011/04/28 21:39:53 | 000,045,093 | ---- | C] () -- C:\Documents and Settings\Gilli\Desktop\HP Installation Error - XP.hta
[2011/04/28 21:10:22 | 000,001,960 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Shop for HP Supplies.lnk
[2011/04/28 21:05:15 | 000,164,678 | ---- | C] () -- C:\WINDOWS\hpoins21.dat
[2011/04/28 21:05:15 | 000,007,262 | ---- | C] () -- C:\WINDOWS\hpomdl21.dat
[2011/04/28 20:53:56 | 000,116,918 | ---- | C] () -- C:\MGlogs.zip
[2011/04/28 20:53:53 | 002,418,162 | ---- | C] () -- C:\MGtools.exe
[2011/04/28 20:26:38 | 000,000,215 | ---- | C] () -- C:\Boot.bak
[2011/04/28 20:26:36 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/04/28 20:22:26 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/04/28 20:22:26 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/04/28 20:22:26 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/04/28 20:22:26 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/04/28 20:22:26 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/04/28 19:15:23 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/04/28 18:50:11 | 205,674,200 | ---- | C] () -- C:\Documents and Settings\Gilli\Desktop\100_235_PS_AIO_02_Full_NonNet_enu_NB.exe
[2011/04/28 17:00:52 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/04/27 21:44:49 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/04/27 17:26:37 | 000,015,404 | -HS- | C] () -- C:\Documents and Settings\Gilli\Local Settings\Application Data\61q6o46e8220c14y4uxr01jg5f00adhtyl0247wa
[2011/04/27 17:26:37 | 000,015,404 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\61q6o46e8220c14y4uxr01jg5f00adhtyl0247wa
[2011/04/27 17:19:55 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/04/27 16:22:53 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2011/04/27 16:22:22 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2011/04/27 16:22:12 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2011/04/27 16:22:11 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2011/04/27 16:22:09 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2011/04/27 16:21:59 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2011/04/27 16:21:52 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2011/04/27 16:21:30 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2011/04/27 16:04:57 | 001,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT
[2011/04/27 16:04:57 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2011/04/27 16:04:57 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2011/04/27 16:04:57 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2011/04/27 16:04:57 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2011/04/27 16:04:57 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2011/04/27 16:04:57 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2011/04/27 15:05:28 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Efevuqejak.dat
[2011/04/27 15:05:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Oseyafidac.bin
[2011/04/27 15:03:21 | 000,122,880 | RHS- | C] () -- C:\WINDOWS\System32\ssmyst9.dll
[2011/04/27 15:03:21 | 000,122,880 | RHS- | C] () -- C:\WINDOWS\System32\pifmgr9.dll
[2011/04/27 15:03:21 | 000,122,880 | RHS- | C] () -- C:\WINDOWS\System32\dskquouin.dll
[2011/04/19 15:59:54 | 000,516,042 | ---- | C] () -- C:\Documents and Settings\Gilli\My Documents\Baby Farenden Jackson 30weeks + 5 Days Scan.JPG
[2011/04/19 15:58:00 | 000,614,424 | ---- | C] () -- C:\Documents and Settings\Gilli\My Documents\3D Baby Face.JPG
[2011/04/19 15:57:37 | 000,516,042 | ---- | C] () -- C:\Documents and Settings\Gilli\My Documents\30wks + 5days Scan.JPG
[2011/04/07 16:31:20 | 000,081,920 | ---- | C] () -- C:\Documents and Settings\Gilli\My Documents\Wedding acceptence.pub
[2011/04/06 11:18:21 | 000,001,763 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Nokia PC Suite.lnk
[2010/02/16 18:27:18 | 000,013,931 | ---- | C] () -- C:\WINDOWS\System32\RaCoInst.dat
[2010/02/16 18:27:11 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\UpdateDriver.exe
[2010/02/16 18:27:11 | 000,005,116 | ---- | C] () -- C:\WINDOWS\System32\ucuiinfo.ini
[2010/02/16 18:27:10 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\RT2870.bin
[2009/12/04 10:53:59 | 000,023,123 | ---- | C] () -- C:\WINDOWS\hpqins15.dat
[2009/11/27 17:00:05 | 000,077,350 | ---- | C] () -- C:\WINDOWS\hpqins05.dat
[2009/11/10 20:58:29 | 001,354,880 | ---- | C] () -- C:\WINDOWS\System32\drivers\sfi.dat
[2009/09/10 15:30:42 | 000,116,840 | ---- | C] () -- C:\WINDOWS\hpqins00.dat
[2009/07/10 18:05:34 | 000,000,399 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/05/26 22:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 22:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/26 10:47:22 | 000,009,728 | ---- | C] () -- C:\Documents and Settings\Gilli\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/18 10:40:42 | 000,000,052 | ---- | C] () -- C:\WINDOWS\hpqwrap.INI
[2007/09/27 11:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/06/16 13:20:08 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2005/10/12 14:03:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
[2005/10/07 13:07:44 | 000,000,022 | ---- | C] () -- C:\WINDOWS\kodakpcd.Gilli.ini
[2005/10/03 15:59:55 | 000,001,292 | ---- | C] () -- C:\Documents and Settings\Gilli\Local Settings\Application Data\FASTWiz.html
[2005/10/03 13:11:39 | 000,000,271 | ---- | C] () -- C:\WINDOWS\hpqcopy.INI
[2005/10/03 11:47:31 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/09/30 11:14:16 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/09/30 11:12:33 | 000,083,471 | R--- | C] () -- C:\WINDOWS\VGAsetup.ini
[2005/09/30 11:12:33 | 000,035,026 | ---- | C] () -- C:\WINDOWS\System32\VGAunistlog.ini
[2005/09/30 11:12:29 | 000,049,152 | ---- | C] () -- C:\WINDOWS\InstFunc.exe
[2005/09/30 10:59:34 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\sis760.bin
[2005/09/30 10:59:34 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\sis741.bin
[2005/09/30 10:59:34 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\sis660.bin
[2005/09/30 10:56:29 | 000,156,672 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2005/09/30 10:55:43 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/09/30 10:55:03 | 000,003,926 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2005/09/30 10:55:02 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2005/09/30 10:54:21 | 000,282,128 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/09/30 10:20:11 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/09/30 10:12:01 | 000,023,444 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/04 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 13:00:00 | 000,469,718 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 13:00:00 | 000,080,758 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 13:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 13:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 13:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2000/10/21 22:29:26 | 000,102,912 | ---- | C] () -- C:\WINDOWS\System32\Jpegpriv.dll
[2000/10/21 22:29:26 | 000,102,912 | ---- | C] () -- C:\WINDOWS\System32\JpegCode.dll
========== LOP Check ==========
[2011/04/27 21:44:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/06 11:15:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2010/03/08 11:15:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2010/06/22 08:29:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
[2010/03/02 10:11:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache
[2008/12/22 12:23:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/07/27 13:14:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSettings
[2011/04/28 21:59:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/07 14:40:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{0310DF63-1877-4629-A86D-90A10BD5C548}
[2011/02/05 09:37:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{41054FB7-AE0F-4DCF-9073-74BC03EFC472}
[2010/10/25 16:51:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{49FC035F-4D1B-4459-B8B7-1EF5D11C6BAC}
[2011/03/19 16:49:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{A2A58654-12AA-408A-B411-58A76959BE7F}
[2011/04/27 17:12:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\Asbiiw
[2011/04/27 16:38:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\Efwya
[2010/02/16 18:39:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\Facebook
[2010/02/14 16:20:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\MSNInstaller
[2010/03/02 10:33:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\Nokia
[2011/04/28 18:32:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\Osonov
[2011/04/28 20:37:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\Oxyc
[2010/06/20 09:28:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\PC Suite
[2010/10/07 16:58:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\Skinux
[2010/07/21 15:04:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\VIRGINMEDIATOOLBAR
[2010/02/16 19:26:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\Windows Desktop Search
[2010/07/15 14:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gilli\Application Data\Windows Search
[2011/04/29 15:33:08 | 000,000,256 | ---- | M] () -- C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2006/05/29 02:33:00 | 000,000,262 | ---- | M] () -- C:\WINDOWS\Tasks\Disc Defrag.job
[2011/04/29 15:21:02 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{A01C03DB-872A-4DA0-A521-43DC3FA62DC0}.job
[2011/04/29 15:36:00 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{F2CD3050-988F-4A9B-B8A5-396F3AB4127C}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
Edited by WigglesGRN, 29 April 2011 - 09:07 AM.