I found the Sheur3 trojan after I started having increased problems a few days ago with sluggishness with my computer in general. I cleared a lot of things out of my computer including modifying the startup processes. I found a startup process called ifoludej.dll and I turned it off. Upon restart I started getting virus protection warnings from AVG and PC Tools Internet Security which quickly removed ifoludej.dll when it tried to turn itself back on, but failed with a file called "C:\Windows\Temp\adus\setup.exe" because it couldn't be found... every time setup tries to do something the 4 letters "adus" are different. Among other things, SETUP tries to access the internet and open such sites as "www.findstuff.com", "ads.randomletters.com" and "tags.randomletters.com". I say tries because PC Tools stops it most times. This is much more noticeable than the Google redirect problem I've had off and on no matter what I try for months now, because it tries to access the internet even when no browser is open.
My other main problem is that inevitably svchost.exe starts monopolizing my computer's CPU time after it has been on a short while. The instance of svchost.exe in question is one that handles a number of things. I ran "Tasklist \SVC" in the command prompt right now and it came back with about 2 dozen services using the one process. The process in question is PID 308, svchost.exe, with the services being: "AudioSrv, BITS, CryptSvc, Dhcp, dmserver, EventSystem, FastUserSwitchingCapability, helpsvc, HidServ, lanmanserver, lanmanworkstation, Netman, Nla, RasMan, Schedule, SENS, SharedAccess, ShellHWDetection, TapiSrv, Themes, TrkWks, winmgmt, wscsvc, wuauserv, WZCSVC".
To try and get rid of the problems, first I ran my main anti-virus, PC Tools Internet Security 2011, a few times on full scan and removed an obfuscated Trojan and a bunch of malware/spyware/adware. Then, I ran AVG Free 2011's full scan 2x and its rootkit scan once and it removed a few objects on the full scan and didnt even find the trojan until it tried to do something actively. Last, I ran Malwarebytes 2-3x and it found 2 objects and removed them.
I added PC Tools to my antiviruses a few months ago when I tried to get rid of the Google redirect on my computer. At that time I tried AVG, Malwarebytes, and some specialty programs by Microsoft and other vendors that were supposed to target the rootkit responsible... but they didnt help... PC Tools helped about 90% I think.
Anyway, I think that about covers it. Here's my OTL report and thanks in advance for any help.
Report:
"OTL logfile created on: 6/12/2011 9:38:51 AM - Run 1
OTL by OldTimer - Version 3.2.24.0 Folder = C:\Documents and Settings\Mr Smith\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.33 Gb Available Physical Memory | 16.71% Memory free
6.35 Gb Paging File | 4.26 Gb Available in Paging File | 67.12% Paging File free
Paging file location(s): C:\pagefile.sys 4608 4608 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 83.24 Gb Total Space | 10.61 Gb Free Space | 12.74% Space Free | Partition Type: NTFS
Drive H: | 87.89 Gb Total Space | 81.32 Gb Free Space | 92.52% Space Free | Partition Type: NTFS
Computer Name: IAINPC | User Name: Mr Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found --
PRC - [2011/02/24 01:13:52 | 002,314,048 | ---- | M] (Maxthon International ltd.) -- C:\Program Files\Maxthon3\Bin\Maxthon.exe
PRC - [2011/01/13 15:17:26 | 001,589,208 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Security\pctsGui.exe
PRC - [2011/01/07 14:54:12 | 000,108,496 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\PC Tools Security\BDT\FGuard.exe
PRC - [2011/01/07 14:54:08 | 000,247,760 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
PRC - [2011/01/07 02:22:54 | 002,747,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/01/07 02:22:44 | 001,084,256 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/01/07 02:22:12 | 001,052,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2011/01/06 16:23:20 | 000,737,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/01/06 16:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/12/31 09:36:22 | 000,070,928 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Security\TFEngine\TFService.exe
PRC - [2010/12/05 17:26:40 | 000,654,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/12/05 17:26:12 | 000,650,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/11/19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Security\pctsSvc.exe
PRC - [2010/10/22 05:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/10/22 05:56:58 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2010/03/15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Security\pctsAuxs.exe
PRC - [2009/10/22 01:23:14 | 001,577,984 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\ATT-SST\McciTrayApp.exe
PRC - [2008/07/21 12:37:06 | 000,086,016 | ---- | M] (Nektra S.A.) -- C:\Program Files\Common Files\PC Tools\Outlook Express API\launcher.exe
PRC - [2008/05/02 02:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008/05/02 02:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/03/14 05:00:00 | 000,226,624 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2008/03/14 05:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2007/09/04 19:25:44 | 000,131,072 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
PRC - [2007/09/02 13:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.exe
PRC - [2007/05/03 14:12:14 | 002,061,816 | ---- | M] (AT&T) -- C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
PRC - [2003/08/29 19:05:35 | 000,360,448 | ---- | M] () -- C:\Program Files\SpywareGuard\sgmain.exe
PRC - [2003/08/29 11:14:56 | 000,233,472 | ---- | M] () -- C:\Program Files\SpywareGuard\sgbhp.exe
PRC - [2002/10/15 18:00:20 | 001,818,624 | ---- | M] (C-Media Electronic Inc. (www.cmedia.com.tw)) -- C:\WINDOWS\mixer.exe
========== Modules (SafeList) ==========
MOD - [2011/01/11 04:27:10 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\msvcr80.dll
MOD - [2010/12/31 09:36:32 | 000,406,800 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Security\TFEngine\TFWAH.dll
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2008/05/02 02:42:50 | 000,045,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\lgscroll.dll
MOD - [2007/09/02 13:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (WPFFontCache_v0400)
SRV - File not found [Disabled | Stopped] -- -- (NetTcpPortSharing)
SRV - File not found [On_Demand | Stopped] -- -- (LiveTurbineNetworkService)
SRV - File not found [On_Demand | Stopped] -- -- (LiveTurbineMessageService)
SRV - File not found [Auto | Stopped] -- -- (itlperf)
SRV - File not found [On_Demand | Stopped] -- -- (aspnet_state)
SRV - [2011/01/07 14:54:08 | 000,247,760 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2011/01/06 16:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/12/31 09:36:22 | 000,070,928 | ---- | M] (PC Tools) [On_Demand | Running] -- C:\Program Files\PC Tools Security\TFEngine\TFService.exe -- (ThreatFire)
SRV - [2010/11/19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\PC Tools Security\pctsSvc.exe -- (sdCoreService)
SRV - [2010/10/22 05:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/03/15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/06/03 12:39:00 | 003,116,380 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2008/05/02 02:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2008/03/14 05:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2007/09/04 19:25:44 | 000,131,072 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService)
SRV - [2006/12/02 06:17:54 | 002,805,000 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon80)
========== Driver Services (SafeList) ==========
DRV - [2011/01/17 09:11:12 | 000,125,248 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pctplfw.sys -- (pctplfw)
DRV - [2011/01/17 09:10:26 | 000,251,560 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\pctgntdi.sys -- (pctgntdi)
DRV - [2011/01/12 11:36:22 | 000,089,472 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pctNdis-PacketFilter.sys -- (PCTFW-PacketFilter)
DRV - [2010/12/31 09:36:40 | 000,069,392 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\TfSysMon.sys -- (TfSysMon)
DRV - [2010/12/31 09:36:38 | 000,033,552 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TfNetMon.sys -- (TfNetMon)
DRV - [2010/12/31 09:36:36 | 000,051,984 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\TfFsMon.sys -- (TfFsMon)
DRV - [2010/12/16 08:46:04 | 000,070,536 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pctplsg.sys -- (pctplsg)
DRV - [2010/12/10 16:57:26 | 000,160,448 | ---- | M] (PC Tools) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PCTAppEvent.sys -- (PCTAppEvent)
DRV - [2010/12/10 13:24:12 | 000,239,168 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2010/12/08 05:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/11/12 14:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/09/13 16:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/08/19 21:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/08/19 21:42:36 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/19 21:42:34 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/08/10 17:58:50 | 000,056,536 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pctNdis.sys -- (pctNdisMP)
DRV - [2010/08/10 17:58:50 | 000,056,536 | ---- | M] (PC Tools) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pctNdis.sys -- (pctNdis)
DRV - [2010/07/16 14:59:54 | 000,656,320 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pctEFA.sys -- (pctEFA)
DRV - [2010/07/16 14:59:54 | 000,338,880 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\pctDS.sys -- (pctDS)
DRV - [2009/10/01 18:41:44 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2009/09/04 12:46:04 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2009/09/04 12:46:04 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2008/06/01 13:11:13 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008/04/13 13:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008/02/29 03:13:46 | 000,028,944 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2008/02/29 03:13:36 | 000,079,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2008/02/29 03:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008/02/29 03:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2008/02/29 03:12:56 | 000,063,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2008/02/29 03:12:48 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2008/01/23 16:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tapvpn.sys -- (tapvpn)
DRV - [2007/09/27 15:46:12 | 000,048,896 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\JmtFltr.sys -- (JmtFltr)
DRV - [2007/09/19 18:01:06 | 000,012,672 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vhidmini.sys -- (vhidmini)
DRV - [2007/09/04 19:26:32 | 000,029,696 | ---- | M] (NVidia Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\nvoclock.sys -- (NVR0Dev)
DRV - [2005/09/29 23:52:22 | 000,013,056 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/09/29 23:52:20 | 000,034,048 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005/08/18 16:52:06 | 000,093,568 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005/03/09 15:53:00 | 000,036,352 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2003/07/23 14:16:48 | 000,022,821 | ---- | M] (Belkin Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bcgame.sys -- (bcgame)
DRV - [2002/11/18 15:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [1996/04/03 14:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.att.net
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E6 1B F2 E6 9C A7 CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.wowhead.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.8
FF - prefs.js..extensions.enabledItems: {daf44bf7-a45e-4450-979c-91cf07434c3d}:1.5.8
FF - prefs.js..extensions.enabledItems: {469CEB59-8266-438b-91D9-82F56D595E15}:1.19
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.21.0.11
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: {d33c2f7c-b1e6-4d46-ab0e-be1f6d05c904}:2.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.0.20
FF - prefs.js..extensions.enabledItems: {46868735-c3fa-47ce-8ce7-cce51a66aceb}:1.2
FF - prefs.js..extensions.enabledItems: {F9EFC5C2-7787-49CE-A0D4-7C9280995F0A}:1.9.1
FF - prefs.js..extensions.enabledItems: [email protected]:0.8.9.8
FF - prefs.js..extensions.enabledItems: {5384767E-00D9-40E9-B72F-9CC39D655D6F}:1.4.1.0
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {cb84136f-9c44-433a-9048-c5cd9df1dc16}:3.0.0.300
FF - prefs.js..extensions.enabledItems: {6BD345A9-782E-4516-B177-E733784A1FBB}:1.9.1
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..extensions.enabledItems: {50931610-3d8e-11dd-ae16-0800200c9a66}:1.0
FF - prefs.js..keyword.URL: "http://us.yhs.search...2-tb-web_us&p="
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: 0
FF - prefs.js..network.proxy.backup.gopher: ""
FF - prefs.js..network.proxy.backup.gopher_port: 0
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: 0
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: 0
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 8118
FF - prefs.js..network.proxy.no_proxies_on: "127.0.0.1"
FF - prefs.js..network.proxy.ssl: "127.0.0.1"
FF - prefs.js..network.proxy.ssl_port: 8118
FF - HKLM\software\mozilla\Firefox\extensions\\{F9EFC5C2-7787-49CE-A0D4-7C9280995F0A}: C:\Documents and Settings\Mr Smith\Local Settings\Application Data\{F9EFC5C2-7787-49CE-A0D4-7C9280995F0A} [2010/05/31 19:34:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{D34AFABD-3FBC-4747-A8F9-85F14B97AF96}: C:\Documents and Settings\other\Local Settings\Application Data\{D34AFABD-3FBC-4747-A8F9-85F14B97AF96}\
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\MSN Toolbar\Platform\5.0.1423.0\Firefox [2010/06/29 20:32:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/06/30 03:01:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/01/01 11:10:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/01/01 11:10:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2011/03/21 04:47:26 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{6BD345A9-782E-4516-B177-E733784A1FBB}: C:\Documents and Settings\Mr Smith\Local Settings\Application Data\{6BD345A9-782E-4516-B177-E733784A1FBB} [2011/06/10 06:45:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/06/11 05:38:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/11 02:47:33 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/11 02:47:33 | 000,000,000 | ---D | M]
[2010/02/05 01:51:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Extensions
[2010/02/05 01:51:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Extensions\[email protected]
[2011/06/12 08:07:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions
[2010/10/15 06:15:42 | 000,000,000 | ---D | M] (Flashblock) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2011/04/14 06:33:50 | 000,000,000 | ---D | M] (FoxyTunes) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2008/06/18 19:08:24 | 000,000,000 | ---D | M] (oldbar) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb}
[2010/03/17 13:01:41 | 000,000,000 | ---D | M] (FoxyTunes Skin - OnyxOrbs) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{469CEB59-8266-438b-91D9-82F56D595E15}
[2009/07/07 22:28:40 | 000,000,000 | ---D | M] (zblack) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{50931610-3d8e-11dd-ae16-0800200c9a66}
[2011/02/18 13:23:57 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2009/11/30 20:34:19 | 000,000,000 | ---D | M] ("Profile Manager and Synchronizer") -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{69f6e5ea-e975-4d70-a983-1e5c094ded79}
[2011/05/25 06:49:02 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/11/22 21:11:05 | 000,000,000 | ---D | M] (Tiny Menu) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{d33c2f7c-b1e6-4d46-ab0e-be1f6d05c904}
[2011/06/11 09:53:10 | 000,000,000 | ---D | M] (Extended Statusbar) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d}
[2011/05/31 08:32:18 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/04/20 01:55:30 | 000,000,000 | ---D | M] (Torbutton) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2011/06/11 09:53:09 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/04/14 06:51:44 | 000,000,000 | ---D | M] (Разпознаване на устройство Logitech) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\[email protected]
[2011/05/10 06:11:58 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\[email protected]
[2008/11/23 23:32:04 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\[email protected]
[2010/06/08 17:46:24 | 000,000,000 | ---D | M] (Solid State ION) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\[email protected]
[2009/08/05 17:21:13 | 000,000,000 | ---D | M] ("YoYo Games InstantPlay") -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\extensions\[email protected]
[2009/11/30 20:37:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\qhd75kbb.Iain\extensions
[2009/11/30 20:37:42 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\qhd75kbb.Iain\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/11/14 01:28:57 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\qhd75kbb.Iain\extensions\[email protected]
[2007/12/27 15:11:00 | 000,001,878 | ---- | M] () -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\searchplugins\aolsearch.xml
[2008/06/21 15:52:34 | 000,001,196 | ---- | M] () -- C:\Documents and Settings\Mr Smith\Application Data\Mozilla\Firefox\Profiles\5lg58vfa.default\searchplugins\winamp-search.xml
[2011/06/12 08:07:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/14 00:23:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/06/10 06:45:23 | 000,000,000 | ---D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\MR SMITH\LOCAL SETTINGS\APPLICATION DATA\{6BD345A9-782E-4516-B177-E733784A1FBB}
[2010/05/31 19:34:30 | 000,000,000 | ---D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\MR SMITH\LOCAL SETTINGS\APPLICATION DATA\{F9EFC5C2-7787-49CE-A0D4-7C9280995F0A}
[2011/06/11 05:38:40 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2011/01/01 11:10:38 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO
[2011/01/01 11:10:39 | 000,000,000 | ---D | M] (DivX HiQ) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA
[2009/04/23 13:10:19 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/21 04:47:26 | 000,000,000 | ---D | M] (Browser Defender Toolbar) -- C:\PROGRAM FILES\PC TOOLS SECURITY\BDT\FIREFOX
[2009/09/01 23:28:08 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2010/04/12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/02/19 16:59:07 | 000,221,184 | ---- | M] (CNN) -- C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
Hosts file not found
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (AT&&T Toolbar) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\Program Files\ATTToolbar\ATTToolbar.dll (AT&T)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (AT&&T Toolbar) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\Program Files\ATTToolbar\ATTToolbar.dll (AT&T)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AT&&T Toolbar) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\Program Files\ATTToolbar\ATTToolbar.dll (AT&T)
O4 - HKLM..\Run: [Adadelijosifaduj] File not found
O4 - HKLM..\Run: [ATT-SST_McciTrayApp] C:\Program Files\ATT-SST\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [C-Media Mixer] C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [ISW.exe] C:\Program Files\AT&T\Internet Security Wizard\ISW.exe (AT&T)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [Nektra OEAPI] C:\Program Files\Common Files\PC Tools\Outlook Express API\launcher.exe (Nektra S.A.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SystemTray] C:\WINDOWS\System32\systray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O4 - HKCU..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AT&T [2010/06/16 16:58:19 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\Mr Smith\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SetVisualStyle = %windir%\resources\Themes\RedTheme.theme
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKCU\..Trusted Domains: aol.com ([music] https in Trusted sites)
O15 - HKCU\..Trusted Domains: shoutcast.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: winamp.com ([]https in Trusted sites)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\itlntfy: DllName - itlnfw32.dll - File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Mr Smith\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mr Smith\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/04/23 16:51:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{d805c8f1-6020-11dc-b94e-0016e6dd225c}\Shell\AutoRun\command - "" = F:\Autorun.exe /run
O33 - MountPoints2\{d805c8f1-6020-11dc-b94e-0016e6dd225c}\Shell\Shell00\Command - "" = F:\Autorun.exe /run
O33 - MountPoints2\{d805c8f1-6020-11dc-b94e-0016e6dd225c}\Shell\Shell01\Command - "" = F:\Autorun.exe /action
O33 - MountPoints2\{d805c8f1-6020-11dc-b94e-0016e6dd225c}\Shell\Shell02\Command - "" = F:\Autorun.exe /uninstall
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O36 - AppCertDlls: autol386 - (C:\WINDOWS\system32\pxinrcp.dll) - File not found
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/12 07:27:15 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mr Smith\Desktop\random.exe
[2011/06/11 06:35:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/11 05:38:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011
[2011/06/11 03:57:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mr Smith\Start Menu\Programs\Internet
[2011/06/11 03:57:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Internet
[2011/06/11 00:20:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/06/11 00:20:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Apple Computer
[2011/06/10 21:07:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Real
[2011/06/10 06:54:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Identities
[2011/06/10 06:48:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/06/10 06:48:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/06/10 06:45:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mr Smith\Local Settings\Application Data\{6BD345A9-782E-4516-B177-E733784A1FBB}
[2011/05/26 05:39:39 | 000,000,000 | ---D | C] -- C:\Program Files\Comical
[2011/05/25 06:36:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mr Smith\Local Settings\Application Data\cYo
[2011/05/25 06:36:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mr Smith\Application Data\cYo
[31 C:\*.tmp files -> C:\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/12 07:33:38 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/06/12 07:27:19 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mr Smith\Desktop\random.exe
[2011/06/12 07:19:13 | 000,013,736 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/12 07:13:51 | 000,272,073 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2011/06/12 07:13:45 | 000,000,308 | -HS- | M] () -- C:\WINDOWS\tasks\mbnj.job
[2011/06/12 07:13:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/12 07:13:39 | 2147,012,608 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/11 05:35:26 | 117,987,023 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/06/11 05:07:50 | 000,481,752 | ---- | M] () -- C:\Documents and Settings\Mr Smith\My Documents\The Poet.epub
[2011/06/11 04:48:45 | 000,000,223 | RHS- | M] () -- C:\boot.ini
[2011/06/11 03:36:43 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\Mr Smith\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/11 03:34:54 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Ddetiyov.dat
[2011/06/11 01:22:09 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Uwalucoruwuy.bin
[2011/06/10 21:02:15 | 000,166,400 | RHS- | M] () -- C:\WINDOWS\System32\ntmsoprq6.dll
[2011/06/10 06:33:00 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\Mr Smith\Application Data\h9ngajrf.bat
[2011/06/10 06:01:06 | 000,002,205 | ---- | M] () -- C:\Documents and Settings\Mr Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\Safari.lnk
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/26 07:49:16 | 000,510,800 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/05/26 07:49:16 | 000,098,712 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[31 C:\*.tmp files -> C:\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/11 05:08:40 | 000,481,752 | ---- | C] () -- C:\Documents and Settings\Mr Smith\My Documents\The Poet.epub
[2011/06/10 21:02:15 | 000,166,400 | RHS- | C] () -- C:\WINDOWS\System32\ntmsoprq6.dll
[2011/06/10 21:02:15 | 000,000,308 | -HS- | C] () -- C:\WINDOWS\tasks\mbnj.job
[2011/06/10 06:33:00 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\Mr Smith\Application Data\h9ngajrf.bat
[2011/03/21 04:47:25 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2011/03/18 00:39:06 | 000,017,308 | -HS- | C] () -- C:\Documents and Settings\Mr Smith\Local Settings\Application Data\2440507339
[2011/03/18 00:39:06 | 000,017,308 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2440507339
[2011/03/18 00:18:19 | 000,017,396 | -HS- | C] () -- C:\Documents and Settings\Mr Smith\Local Settings\Application Data\1368123653
[2011/03/18 00:18:19 | 000,017,396 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\1368123653
[2010/06/29 23:26:16 | 000,705,096 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/05/31 19:34:31 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Ddetiyov.dat
[2010/05/31 19:34:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Uwalucoruwuy.bin
[2010/05/31 19:32:41 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\Mr Smith\Application Data\vqdlkr.dat
[2010/05/10 00:09:09 | 002,183,470 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/04/30 20:52:46 | 000,024,256 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/04/22 18:51:19 | 000,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/04/01 05:47:17 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\SI.bin
[2010/03/31 16:24:21 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/03/28 16:29:03 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\mk4vc60.dll
[2010/03/23 13:33:27 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2009/10/24 19:40:05 | 000,000,020 | ---- | C] () -- C:\WINDOWS\prefs_zb.dll
[2009/10/13 11:56:52 | 000,087,040 | ---- | C] () -- C:\WINDOWS\UnGins.exe
[2009/10/02 13:06:33 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\Mr Smith\Local Settings\Application Data\fusioncache.dat
[2009/08/09 19:21:32 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2009/07/26 21:42:33 | 000,066,936 | -HS- | C] () -- C:\WINDOWS\slinfo_0.drv
[2009/07/26 21:41:14 | 000,086,528 | ---- | C] () -- C:\WINDOWS\bnetunin.exe
[2009/07/26 21:41:14 | 000,061,440 | ---- | C] () -- C:\WINDOWS\diabswun.exe
[2009/05/26 19:18:59 | 000,000,025 | ---- | C] () -- C:\WINDOWS\popcinfot.dat
[2009/02/15 15:10:57 | 000,048,896 | ---- | C] () -- C:\WINDOWS\System32\drivers\JmtFltr.sys
[2008/12/25 09:49:56 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Mr Smith\Application Data\PnkBstrK.sys
[2008/12/14 10:00:38 | 000,000,044 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\{3D55D1F4-1059-11DC-B281-197056D89593}
[2008/12/13 14:50:03 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/12/05 00:46:04 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2008/12/04 19:26:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PowerReg.dat
[2008/09/09 16:41:55 | 000,000,008 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat
[2008/08/31 13:53:19 | 000,000,172 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/07/14 03:57:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\WB.ini
[2008/06/13 20:15:16 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2008/06/09 18:14:43 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2008/06/05 08:58:26 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/06/01 13:49:52 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2008/06/01 13:49:52 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2008/06/01 13:49:52 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2007/12/08 16:44:05 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2007/11/29 19:55:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/09/06 00:14:31 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Mr Smith\Local Settings\Application Data\PUTTY.RND
[2007/06/28 23:43:00 | 001,018,772 | ---- | C] () -- C:\WINDOWS\System32\nvucode.bin
[2007/06/14 02:40:27 | 000,000,101 | ---- | C] () -- C:\WINDOWS\CMMIXER.INI
[2007/06/09 15:59:22 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2007/06/04 02:20:33 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\Mr Smith\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/16 14:24:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2007/05/16 14:21:55 | 000,107,134 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2007/05/16 14:21:40 | 000,003,073 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2007/05/16 14:06:31 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2007/05/16 13:27:20 | 000,000,102 | ---- | C] () -- C:\WINDOWS\VSWizard.ini
[2007/04/23 16:52:55 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2007/04/23 16:48:44 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2007/04/23 09:36:21 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007/04/23 09:35:24 | 000,112,584 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/03/12 12:01:30 | 000,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
[2006/08/11 23:45:20 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 23:43:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2004/08/04 07:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,510,800 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,098,712 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2002/11/19 15:46:20 | 000,039,104 | ---- | C] () -- C:\WINDOWS\cmijack.dat
[2002/11/19 15:43:38 | 000,022,178 | ---- | C] () -- C:\WINDOWS\cmaudio.dat
[2002/09/18 00:45:00 | 000,119,808 | ---- | C] () -- C:\WINDOWS\lsb_un20.exe
[2001/11/08 02:27:00 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\glut32.dll
[1996/04/03 14:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2011/06/11 01:05:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2DBoy
[2009/12/08 13:55:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AT&T
[2009/12/08 15:26:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATTToolbar
[2011/06/11 05:46:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/09/30 09:27:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2009/10/22 20:00:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Awem
[2007/06/23 16:58:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2011/06/11 02:30:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BioWare
[2010/09/30 10:31:50 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/06/01 17:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DinsCurse
[2009/05/26 19:50:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Enkord
[2010/05/13 21:54:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gamerizon
[2010/09/30 09:21:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/03/09 07:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/06/08 22:52:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NexonUS
[2009/05/26 18:22:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/08/31 13:44:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2011/06/12 09:29:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/02 12:49:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Turbine
[2007/10/29 01:22:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/08/05 17:24:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YoYoGames
[2010/04/30 20:25:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/20 11:02:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2008/07/14 03:50:36 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{8227D5D4-E2F9-4B81-98FA-54E4E78F5238}
[2009/04/28 22:42:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/11/09 02:47:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\.BitZip
[2010/08/13 07:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\.minecraft
[2009/06/21 19:13:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Amazon
[2009/12/08 13:55:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\AT&T
[2009/12/08 13:55:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\ATTToolbar
[2010/10/12 12:13:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\AVG
[2010/09/30 10:32:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\AVG10
[2010/03/29 01:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Azgard
[2011/05/25 08:12:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Azureus
[2007/05/18 13:36:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\BitTorrent
[2010/03/23 13:59:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Braid
[2011/03/15 01:41:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\calibre
[2007/08/18 18:05:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\CiscoCAA
[2011/01/17 02:16:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\com.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1
[2010/08/26 10:26:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\crawl
[2011/05/25 06:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\cYo
[2008/06/01 13:11:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\DAEMON Tools
[2009/05/19 14:29:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\dota-allstars.71E01812711E1682B196CE418CDA466F24682743.1
[2009/05/19 14:30:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\dota_allstars
[2008/12/13 14:57:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\FileZilla
[2009/05/21 17:10:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\FOG Downloader
[2008/11/15 14:58:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Galcon
[2011/03/18 01:19:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\GetRightToGo
[2009/04/06 19:57:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\gtk-2.0
[2010/12/11 11:05:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\IceChat
[2009/04/01 15:22:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Inkscape
[2007/05/16 13:32:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Leadertech
[2011/01/01 11:10:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Local
[2010/04/24 22:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2011/03/06 07:04:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Maxthon3
[2010/03/21 00:55:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Mind Control Software
[2011/02/02 12:48:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\n52te
[2011/03/09 07:25:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\NCH Swift Sound
[2011/06/11 03:16:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Notepad++
[2011/03/21 04:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\PCToolsFirewallPlus
[2008/11/27 01:10:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Pi Eye Games
[2010/03/21 00:55:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\PlayFirst
[2010/05/13 22:10:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\runic games
[2007/11/01 20:06:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Screaming Bee
[2008/12/08 06:01:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\SmartDraw
[2008/12/14 07:57:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\smc
[2011/03/18 01:38:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Spam Monitor
[2008/08/07 00:36:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\SystemRequirementsLab
[2008/12/14 10:24:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Tandem Games
[2007/11/04 14:51:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Uniblue
[2011/06/12 06:50:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\uTorrent
[2009/07/18 18:53:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\Wizards of the Coast
[2007/08/10 11:44:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mr Smith\Application Data\WowAceUpdater
[2011/03/28 00:34:03 | 000,000,290 | ---- | M] () -- C:\WINDOWS\Tasks\doxillionShakeIcon.job
[2011/06/12 07:13:45 | 000,000,308 | -HS- | M] () -- C:\WINDOWS\Tasks\mbnj.job
[2011/03/12 07:34:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\switchShakeIcon.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 517 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:3E748A0BD09161C9
@Alternate Data Stream - 194 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEE39B00
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5160F090
< End of report >"