Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

rundll startup error: specified module not found


  • This topic is locked This topic is locked

#1
princessmimi

princessmimi

    Member

  • Member
  • PipPip
  • 48 posts
Hi!

For the past week or so, I've been receiving a message upon start-up: Error loading C:\Documents and Settings\MimiII\Local Settings\Application Data\xpAuthenticationRpl\UtilEventVdn.dll The specified module could not be found.

I've looked through the forum already and found pages like: this one or this one, but every resolution seems to be different and targeted towards specific files and folders. Since I have NO clue what I'm doing, I thought it would be safer to just start a new topic.

So far, I've scanned my computer with MalwareBytes' Anti-Malware almost every day and keep getting the same, icky infection with my registry data [latest log excerpt: HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (???????????) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.]. Once or twice after restart, I've gotten the Windows scandisk (or whatever it's called on XP) and it's apparently repaired some damaged items, but the startup message still pops up. I've downloaded Combofix; not sure what to do with it, so I think it's best for me to wait for some of... guidance. I'm not good with these things... :yes:

Hijackthis log is posted below. Thank you SO much in advance!!! :)

Scan saved at 10:30:05 AM, on 10/7/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\FirefoxPortable\FirefoxPortable.exe
C:\Program Files\Mozilla Firefox\FirefoxPortable\App\firefox\firefox.exe
C:\Program Files\Mozilla Firefox\FirefoxPortable\App\firefox\plugin-container.exe
C:\Program Files\AVG\AVG9\avgupd.exe
C:\Documents and Settings\Mimi II\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [UtilEventVdm] rundll32.exe "C:\Documents and Settings\Mimi II\Local Settings\Application Data\xpAuthenticationRpl\UtilEventVdm.dll",oleMobileTray MSNcfgNotifier
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmat...enWebRadio.html (file missing)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Mimi II\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebo...toUploader5.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail....es/MSNPUpld.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebo...oUploader55.cab
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} (Image Uploader Control) - http://cameracanadap...PUploader57.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate1c9bee52bba4c2c) (gupdate1c9bee52bba4c2c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: RPC Security - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: winsocket - Unknown owner - C:\WINDOWS\system32\winsocket.exe (file missing)
O23 - Service: Systart (Winsys32) - Unknown owner - C:\WINDOWS\winstc.exe (file missing)

--
End of file - 12818 bytes
  • 0

Advertisements


#2
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hello princessmimi and welcome to G2G! :)

My nick is maliprog and I'll will be your technical support on this issue. Before we start please read my notes carefully:

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted. Order is crucial in cleaning process.
  • Please DO NOT run any scans or fix on your own without my direction.
  • Please read all of my response through at least once before attempting to follow the procedures described.
  • If there's anything you don't understand or isn't totally clear, please come back to me for clarification.
  • Please do not attach any log files to your replies unless I specifically ask you. Instead please copy and paste so as to include the log in your reply.
  • You must reply within 3 days or your topic will be closed

Step 1

Download OTL to your Desktop

  • Double click on the icon to run it (If running Vista or Windows 7, right click on it and select "Run as an Administrator")
    . Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in

netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%\*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.

Step 2

Download GMER from Here. Note the file's name and save it to your root folder, such as C:.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "No", save the log and post back the results.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.

Step 3

Please don't forget to include these items in your reply:

  • OTL log
  • OTL Extras log
  • GMER log
It would be helpful if you could post each log in separate post
  • 0

#3
princessmimi

princessmimi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Thanks for your response! I appreciate you attempting to work with un-computer saavy me. ^^

OTL.txt:

OTL logfile created on: 10/13/2011 7:36:14 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Mimi II\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.07 Mb Total Physical Memory | 641.79 Mb Available Physical Memory | 62.79% Memory free
2.40 Gb Paging File | 1.78 Gb Available in Paging File | 73.95% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.68 Gb Total Space | 8.31 Gb Free Space | 11.59% Space Free | Partition Type: NTFS

Computer Name: D3T0R661 | User Name: Mimi II | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/10/13 19:35:52 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mimi II\Desktop\OTL.exe
PRC - [2011/10/13 16:43:27 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
PRC - [2011/09/13 10:12:06 | 002,076,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2011/05/21 16:46:58 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2011/03/21 14:56:16 | 001,230,704 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/11/24 10:40:25 | 000,725,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/09/20 10:28:11 | 000,621,920 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/06/22 10:27:59 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/06/22 10:27:55 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/06/22 10:27:44 | 005,897,808 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/06/22 10:27:44 | 000,596,560 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2010/06/22 10:27:00 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/06/22 10:26:59 | 000,842,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2009/09/14 11:07:30 | 000,472,112 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Pure Networks\Network Magic\nmapp.exe
PRC - [2009/07/07 14:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/11/06 11:08:10 | 000,397,312 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
PRC - [2006/09/29 11:55:14 | 000,057,344 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
PRC - [2004/02/25 10:04:16 | 001,123,440 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
PRC - [2001/11/27 09:10:00 | 000,106,560 | ---- | M] (WinZip Computing, Inc.) -- C:\Program Files\WinZip\WZQKPICK.EXE


========== Modules (No Company Name) ==========

MOD - [2011/10/13 11:14:27 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
MOD - [2011/10/13 11:13:28 | 000,025,600 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
MOD - [2011/10/13 11:12:03 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
MOD - [2011/10/13 11:11:55 | 012,430,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
MOD - [2011/10/13 11:11:37 | 001,587,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll
MOD - [2011/10/13 11:08:33 | 007,950,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
MOD - [2011/10/13 11:08:06 | 011,490,816 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011/10/13 11:06:19 | 000,303,104 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2011/10/13 11:05:36 | 005,242,880 | ---- | M] () -- C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
MOD - [2011/07/06 19:01:53 | 000,011,776 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Runtime\2.0.3693.42552__90ba9c70f846762e\CLI.Caste.HydraVision.Runtime.dll
MOD - [2011/07/06 19:01:53 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Shared\2.0.3693.42552__90ba9c70f846762e\CLI.Caste.HydraVision.Shared.dll
MOD - [2011/07/06 19:01:53 | 000,007,680 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Wizard\2.0.3693.42556__90ba9c70f846762e\CLI.Caste.HydraVision.Wizard.dll
MOD - [2011/07/06 19:01:53 | 000,007,680 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Dashboard\2.0.3693.42552__90ba9c70f846762e\CLI.Caste.HydraVision.Dashboard.dll
MOD - [2011/07/06 19:01:52 | 000,290,816 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3693.42442__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:52 | 000,204,800 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3693.42461__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:52 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3693.42456__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:52 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3693.42451__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:51 | 001,728,512 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3693.42460__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:51 | 000,692,224 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3693.42508__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:51 | 000,491,520 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3693.42537__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:51 | 000,364,544 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3693.42522__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:51 | 000,077,824 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3693.42517__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:51 | 000,069,632 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3693.42499__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:51 | 000,036,864 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3693.42486__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:50 | 000,139,264 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3693.42537__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:50 | 000,106,496 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3693.42461__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:50 | 000,073,728 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3693.42450__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:49 | 000,364,544 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3693.42504__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:49 | 000,094,208 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3693.42504__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:49 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3693.42460__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:48 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3693.42503__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:45 | 000,811,008 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3693.42488__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:45 | 000,405,504 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3693.42512__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:45 | 000,081,920 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3693.42487__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:44 | 000,712,704 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3693.42452__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:44 | 000,589,824 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3693.42462__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:44 | 000,225,280 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3693.42462__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:44 | 000,126,976 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3693.42496__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:44 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3693.42466__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:44 | 000,036,864 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3693.42496__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:43 | 000,798,720 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3693.42518__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:43 | 000,450,560 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3693.42482__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:43 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3693.42497__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:42 | 000,675,840 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3693.42500__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:42 | 000,438,272 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3693.42487__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:42 | 000,065,536 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3693.42486__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:42 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3693.42487__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:41 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3309.28617__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3309.28608__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3309.28629__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3309.28645__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3309.28647__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3309.28627__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3309.28647__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2011/07/06 19:01:40 | 000,007,168 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2011/07/06 19:01:39 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3309.28601__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2011/07/06 19:01:39 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3309.28603__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2011/07/06 19:01:39 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3309.28630__90ba9c70f846762e\DEM.OS.I0602.dll
MOD - [2011/07/06 19:01:39 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3309.28626__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2011/07/06 19:01:39 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.OS\2.0.3309.28645__90ba9c70f846762e\DEM.OS.dll
MOD - [2011/07/06 19:01:39 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll
MOD - [2011/07/06 19:01:38 | 000,073,728 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3309.28604__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2011/07/06 19:01:38 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2011/07/06 19:01:38 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3309.28669__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2011/07/06 19:01:38 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3309.28620__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2011/07/06 19:01:38 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3309.28617__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2011/07/06 19:01:38 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3309.28611__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2011/07/06 19:01:38 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.3309.28630__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2011/07/06 19:01:38 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2011/07/06 19:01:38 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3309.28617__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2011/07/06 19:01:37 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3309.28618__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2011/07/06 19:01:37 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.3309.28631__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll
MOD - [2011/07/06 19:01:37 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3309.28631__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2011/07/06 19:01:37 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3309.28630__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2011/07/06 19:01:36 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3309.28644__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2011/07/06 19:01:35 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3309.28636__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,065,536 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3309.28636__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3309.28634__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,049,152 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3309.28634__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3309.28636__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3309.28624__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3309.28632__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3309.28630__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3309.28635__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3309.28630__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2011/07/06 19:01:32 | 000,503,808 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ResourceManagement.Foundation.Implementation\2.0.3693.42564__90ba9c70f846762e\ResourceManagement.Foundation.Implementation.dll
MOD - [2011/07/06 19:01:32 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3309.28634__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2011/07/06 19:01:32 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3693.42545__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2011/07/06 19:01:32 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3309.28627__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2011/07/06 19:01:32 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll
MOD - [2011/07/06 19:01:32 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.3309.28626__90ba9c70f846762e\APM.Foundation.dll
MOD - [2011/07/06 19:01:32 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3309.28617__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2011/07/06 19:01:31 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3309.28612__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll
MOD - [2011/07/06 19:01:31 | 000,014,848 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll
MOD - [2011/07/06 19:01:31 | 000,013,312 | ---- | M] () -- C:\WINDOWS\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll
MOD - [2011/07/06 19:01:31 | 000,007,168 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3693.42437__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2011/07/06 19:01:30 | 000,544,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3693.42525__90ba9c70f846762e\CLI.Component.Systemtray.dll
MOD - [2011/07/06 19:01:30 | 000,405,504 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3693.42455__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2011/07/06 19:01:30 | 000,106,496 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3693.42531__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2011/07/06 19:01:30 | 000,081,920 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3693.42440__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2011/07/06 19:01:30 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3693.42530__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2011/07/06 19:01:30 | 000,057,344 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3693.42441__90ba9c70f846762e\CLI.Component.SkinFactory.dll
MOD - [2011/07/06 19:01:30 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3309.28628__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2011/07/06 19:01:30 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3309.28608__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2011/07/06 19:01:30 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3309.28614__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2011/07/06 19:01:30 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3309.28627__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2011/07/06 19:01:30 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3309.28626__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2011/07/06 19:01:28 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3309.28624__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2011/07/06 19:01:26 | 001,142,784 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3693.42446__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2011/07/06 19:01:25 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3309.28621__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2011/07/06 19:01:25 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3309.28637__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2011/07/06 19:01:24 | 000,081,920 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ATIDEMOS\2.0.3693.42440__90ba9c70f846762e\ATIDEMOS.dll
MOD - [2011/07/06 19:01:24 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2011/07/06 19:01:24 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3693.42531__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2011/07/06 19:01:23 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3693.42439__90ba9c70f846762e\APM.Server.dll
MOD - [2011/07/06 19:01:23 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3693.42438__90ba9c70f846762e\AEM.Server.dll
MOD - [2011/03/21 14:57:34 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/03/21 14:56:16 | 001,230,704 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2010/08/10 00:01:06 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2009/11/24 13:36:36 | 000,016,384 | R--- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2009/11/04 11:57:14 | 000,057,344 | ---- | M] () -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\boost_thread-vc71-mt-1_32.dll
MOD - [2009/11/04 11:57:13 | 000,077,824 | ---- | M] () -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\boost_log-vc71-mt-1_32.dll
MOD - [2009/07/13 17:37:04 | 000,152,112 | ---- | M] () -- C:\Program Files\Common Files\Pure Networks Shared\Platform\CAntiVirusCOM.dll
MOD - [2009/07/13 17:37:04 | 000,098,304 | ---- | M] () -- C:\Program Files\Common Files\Pure Networks Shared\Platform\CFirewallCOM.dll
MOD - [2004/12/26 21:34:38 | 000,121,344 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2004/06/18 11:29:44 | 000,007,680 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\dlbtmcro.dll
MOD - [2004/06/18 11:27:50 | 000,065,536 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\JetScan.dll
MOD - [2004/06/18 11:26:42 | 000,065,536 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\JetImage.dll
MOD - [2004/06/18 11:26:18 | 000,028,672 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\JetPDF.dll
MOD - [2004/06/18 11:25:56 | 000,036,864 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\JetFunc.dll
MOD - [2004/03/29 12:45:52 | 000,075,264 | ---- | M] () -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBTPP5C.DLL
MOD - [2004/03/10 10:36:24 | 000,061,440 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\ConvDIB.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (Winsys32)
SRV - File not found [Auto | Stopped] -- -- (winsocket)
SRV - File not found [Auto | Stopped] -- -- (RPC Security)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/10/13 16:43:27 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
SRV - [2010/06/22 10:27:55 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/06/22 10:27:44 | 005,897,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2008/04/13 20:12:02 | 000,105,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\p2pgasvc.dll -- (p2pgasvc)
SRV - [2008/04/13 20:11:55 | 000,035,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\SYSTEM32\iprip.dll -- (Iprip)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2004/03/16 16:33:24 | 000,421,888 | ---- | M] (Dell) [On_Demand | Stopped] -- C:\WINDOWS\System32\dlbtcoms.exe -- (dlbt_device)
SRV - [2004/02/25 10:04:16 | 001,123,440 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe -- (AOL ACS)


========== Driver Services (SafeList) ==========

DRV - [2011/09/13 10:11:56 | 000,029,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2011/05/05 10:28:03 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/06/22 10:27:48 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys -- (AVGIDSFilterxpx)
DRV - [2010/06/22 10:27:48 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys -- (AVGIDSShimxpx)
DRV - [2010/06/22 10:27:48 | 000,025,168 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\AVGIDSxx.sys -- (AVGIDSErHrxpx)
DRV - [2010/06/22 10:27:47 | 000,122,448 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys -- (AVGIDSDriverxpx)
DRV - [2010/06/22 10:27:02 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/03/05 11:13:41 | 000,052,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\System32\Drivers\avgrkx86.sys -- (AvgRkx86)
DRV - [2010/02/11 08:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys -- (Tcpip6)
DRV - [2010/02/11 03:38:10 | 003,565,056 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2010/01/01 14:07:51 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\atksgt.sys -- (atksgt)
DRV - [2010/01/01 14:07:50 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\lirsgt.sys -- (lirsgt)
DRV - [2009/07/07 14:48:44 | 000,026,672 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\purendis.sys -- (purendis)
DRV - [2009/07/07 14:48:44 | 000,025,392 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\pnarp.sys -- (pnarp)
DRV - [2008/06/27 12:09:32 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2007/08/01 22:47:26 | 000,102,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys -- (tmcomm)
DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/09/05 12:03:16 | 000,003,968 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys -- (AvgAsCln)
DRV - [2005/11/21 01:48:21 | 000,016,512 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ASPI32.SYS -- (ASPI32)
DRV - [2004/06/16 00:52:40 | 000,061,157 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys -- (IntelC53)
DRV - [2004/03/06 00:15:34 | 000,647,929 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys -- (IntelC52)
DRV - [2004/03/06 00:14:42 | 001,233,525 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys -- (IntelC51)
DRV - [2004/03/06 00:13:38 | 000,037,048 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys -- (mohfilt)
DRV - [2004/02/22 00:27:05 | 000,015,872 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\Mimi II\Local Settings\Temp\krdpdre.sys -- (krdpdre)
DRV - [2003/08/28 20:58:40 | 000,004,272 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\bvrp_pci.sys -- (bvrp_pci)
DRV - [2003/06/13 10:53:06 | 000,015,232 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdrbsvsd.sys -- (cdrbsvsd)
DRV - [2003/01/10 18:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2002/11/08 15:45:06 | 000,017,217 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.hotmail.com"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.647: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.647: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2011/09/13 10:19:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/05/21 16:47:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/23 00:28:29 | 000,134,104 | ---- | M] (Mozilla Foundation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/28 12:06:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape 7.2\Extensions\\Components: C:\Program Files\Netscape\Netscape\Components [2011/07/27 18:16:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape 7.2\Extensions\\Plugins: C:\Program Files\Netscape\Netscape\Plugins [2011/07/01 10:28:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape Navigator 9.0.0.6\extensions\\Components: C:\Program Files\Netscape\Navigator 9\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape Navigator 9.0.0.6\extensions\\Plugins: C:\Program Files\Netscape\Navigator 9\plugins [2011/03/08 19:33:17 | 000,000,000 | ---D | M]

[2011/10/06 11:18:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mimi II\Application Data\Mozilla\Extensions
[2011/09/28 12:06:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/10 18:17:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/11 18:08:55 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/14 11:33:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/11 11:27:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/11 11:24:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/10 18:19:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2009/04/17 10:22:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\App\Firefox\extensions
[2011/09/28 12:02:19 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\App\Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/10/12 19:13:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions
[2010/07/13 11:27:20 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/30 21:38:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\{b80f591e-fe9a-46cf-a13e-180377240586}
[2010/11/17 19:05:10 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]mozilla.org
[2011/10/12 19:12:29 | 000,000,000 | ---D | M] (Canadian English Dictionary) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2010/12/30 21:38:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/03/04 11:10:35 | 000,000,000 | ---D | M] (Suomen kielen oikoluku) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/10/12 11:30:57 | 000,000,000 | ---D | M] (Dictionnaire français «Moderne») -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/04/28 20:47:12 | 000,000,000 | ---D | M] (Icelandic Dictionary) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/04/28 20:47:11 | 000,000,000 | ---D | M] (Dizionario italiano) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/06/28 21:08:22 | 000,000,000 | ---D | M] (Norsk bokmÃ¥l ordliste) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/07/01 11:16:54 | 000,000,000 | ---D | M] (Polski slownik poprawnej pisowni) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2010/09/15 18:05:52 | 000,000,000 | ---D | M] (Russian spellchecking dictionary) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/07/01 11:16:54 | 000,000,000 | ---D | M] (Svensk ordlista) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2010/04/10 18:17:39 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/01 18:07:07 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/22 21:16:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2009/08/12 18:19:22 | 000,000,813 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [UtilEventVdm] rundll32.exe "C:\Documents and Settings\Mimi II\Local Settings\Application Data\xpAuthenticationRpl\UtilEventVdm.dll",oleMobileTray MSNcfgNotifier File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LUMIX Simple Viewer.lnk = C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMovingBands = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCloseDragDropBands = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmat...enWebRadio.html File not found
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Mimi II\Start Menu\Programs\IMVU\Run IMVU.lnk File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.t...ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} http://cameracanadap...PUploader57.cab (Image Uploader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{08B6E02A-BBEA-450C-A110-EED00DD6157E}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Mimi II\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mimi II\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{038ec433-a4f2-11e0-96a2-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{038ec433-a4f2-11e0-96a2-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{038ec433-a4f2-11e0-96a2-00038a000015}\Shell\AutoRun\command - "" = F:\Autorun.exe
O33 - MountPoints2\{2615f4ef-7bac-11df-9342-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{2615f4ef-7bac-11df-9342-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2615f4ef-7bac-11df-9342-00038a000015}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{6fc80b2e-3b23-11de-8f74-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc80b2e-3b23-11de-8f74-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6fc80b2e-3b23-11de-8f74-00038a000015}\Shell\AutoRun\command - "" = F:\S3\Autorun.exe
O33 - MountPoints2\{b4e67a7e-4463-11dd-8de2-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{b4e67a7e-4463-11dd-8de2-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b4e67a7e-4463-11dd-8de2-00038a000015}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\Shell\AutoRun\command - "" = F:\Autorun.exe
O33 - MountPoints2\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\Shell\AutoRun\command - "" = F:\_AUTORUN\AUTORUN.EXE
O33 - MountPoints2\{ebf1aea6-3e45-11de-8f7b-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{ebf1aea6-3e45-11de-8f7b-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ebf1aea6-3e45-11de-8f7b-00038a000015}\Shell\AutoRun\command - "" = F:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\SYSTEM32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/10/13 19:35:50 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mimi II\Desktop\OTL.exe
[2011/10/13 11:03:34 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/10/07 10:21:12 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Mimi II\My Documents\HijackThis.exe
[2011/10/01 19:14:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/10/01 19:14:37 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/10/01 19:14:00 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/09/26 11:44:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NCH Software
[2011/09/26 11:44:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mimi II\Application Data\NCH Software
[2011/09/24 17:28:33 | 000,000,000 | ---D | C] -- C:\Program Files\MALWAREBYTES ANTI-MALWARE
[2008/05/28 10:22:26 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Mimi II\Application Data\pcouffin.sys
[1980/01/01 02:00:00 | 000,151,552 | ---- | C] ( ) -- C:\WINDOWS\System32\ATIDEMGR.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[18 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/13 19:38:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/13 19:35:52 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mimi II\Desktop\OTL.exe
[2011/10/13 18:46:53 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Mimi II\Local Settings\Application Data\prvlcl.dat
[2011/10/13 17:38:02 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/13 16:45:17 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-536494136-2410558530-2963846775-1008.job
[2011/10/13 16:45:09 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2011/10/13 16:41:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2011/10/13 16:41:44 | 1071,796,224 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/13 13:46:46 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/13 12:30:31 | 000,397,552 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/13 11:07:07 | 000,445,830 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2011/10/13 11:07:07 | 000,073,036 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2011/10/13 10:56:04 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/10/13 10:23:16 | 087,132,222 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/10/12 17:02:58 | 000,316,170 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\_MG_8544.jpg
[2011/10/12 17:00:44 | 001,502,898 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\Henry_Burris_-_CFL_PHOTO_-_Peter_McCabe.jpg
[2011/10/11 11:46:01 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-536494136-2410558530-2963846775-1008.job
[2011/10/07 10:21:26 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Mimi II\My Documents\HijackThis.exe
[2011/10/06 17:12:39 | 000,000,985 | ---- | M] () -- C:\WINDOWS\dellstat.ini
[2011/10/04 20:05:55 | 000,014,250 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\fi.jpg
[2011/10/04 19:33:39 | 000,014,998 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF2219.jpg
[2011/10/04 19:20:53 | 000,021,908 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\nor.jpg
[2011/09/28 12:10:02 | 000,001,776 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/09/28 12:06:48 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\Mimi II\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/09/26 12:04:41 | 000,063,487 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\ss.jpg
[2011/09/25 10:22:01 | 000,000,211 | RHS- | M] () -- C:\BOOT.INI
[2011/09/16 18:30:43 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\switchShakeIcon.job
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[18 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/13 10:55:36 | 000,001,393 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/10/12 17:02:57 | 000,316,170 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\_MG_8544.jpg
[2011/10/12 17:00:41 | 001,502,898 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\Henry_Burris_-_CFL_PHOTO_-_Peter_McCabe.jpg
[2011/10/04 20:01:48 | 000,014,250 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\fi.jpg
[2011/10/04 19:30:12 | 000,014,998 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF2219.jpg
[2011/10/04 19:20:53 | 000,021,908 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\nor.jpg
[2011/09/28 12:06:47 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/09/26 12:03:00 | 000,063,487 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\ss.jpg
[2011/09/25 10:21:56 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL 9.0 Tray Icon.lnk
[2011/09/16 18:30:42 | 000,000,282 | ---- | C] () -- C:\WINDOWS\tasks\switchShakeIcon.job
[2011/07/06 19:09:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2011/07/06 18:58:54 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2011/02/27 15:50:22 | 000,000,003 | ---- | C] () -- C:\WINDOWS\treeskp.sys
[2011/02/27 15:50:22 | 000,000,003 | ---- | C] () -- C:\WINDOWS\sbacknt.bin
[2010/02/11 00:12:00 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2010/02/11 00:12:00 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2009/12/17 04:33:56 | 003,190,784 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2009/12/17 04:33:56 | 000,405,504 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2009/12/17 04:33:56 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2009/12/17 04:33:56 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2009/12/17 04:33:56 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2009/12/17 04:33:56 | 000,097,280 | ---- | C] () -- C:\WINDOWS\System32\ff_realaac.dll
[2009/12/17 04:33:56 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2009/12/17 04:33:56 | 000,038,400 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2009/12/17 04:33:54 | 000,741,376 | ---- | C] () -- C:\WINDOWS\System32\audxlib.dll
[2009/12/17 04:33:54 | 000,662,016 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/12/17 04:33:54 | 000,511,488 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2009/12/17 04:33:54 | 000,245,760 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2009/12/17 04:33:54 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2009/12/17 04:33:54 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2009/12/17 04:33:54 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2009/12/17 04:33:54 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2009/12/17 04:33:54 | 000,079,872 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2009/12/17 04:33:54 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2009/12/17 04:33:54 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/05/01 16:03:56 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mimi II\Local Settings\Application Data\prvlcl.dat
[2009/04/23 18:29:16 | 000,189,051 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2009/04/16 11:24:06 | 008,892,928 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\atscie.msi
[2008/12/26 20:03:10 | 000,281,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008/12/26 20:03:03 | 000,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/05/28 10:22:26 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Mimi II\Application Data\inst.exe
[2008/05/28 10:22:26 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Mimi II\Application Data\pcouffin.cat
[2008/05/28 10:22:26 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Mimi II\Application Data\pcouffin.inf
[2008/04/29 11:36:06 | 000,000,001 | ---- | C] () -- C:\WINDOWS\dedlat2.dll
[2008/04/29 11:35:51 | 000,613,897 | -H-- | C] () -- C:\WINDOWS\System32\drivers\klog.dat
[2008/01/30 17:10:46 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\libcurl.dll
[2007/12/14 15:52:38 | 000,000,005 | ---- | C] () -- C:\WINDOWS\System32\SySVid.dat
[2007/12/14 15:51:39 | 000,003,082 | ---- | C] () -- C:\WINDOWS\System32\affv11300p4now.sys
[2007/12/13 15:15:14 | 000,000,206 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/12/05 18:06:04 | 000,000,335 | ---- | C] () -- C:\WINDOWS\mozregistry.dat
[2007/11/29 11:31:11 | 000,915,488 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2007/11/29 11:31:11 | 000,058,144 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2007/11/17 19:53:56 | 000,001,578 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Mp4 Codec.dat
[2007/11/17 19:52:02 | 000,002,154 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Ogg Vorbis Codec.dat
[2007/11/17 19:51:08 | 000,002,467 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dMC mp3PRO (CLI) Encoder.dat
[2007/11/17 19:49:16 | 000,002,286 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Monkeys Audio Codec.dat
[2007/10/31 10:39:54 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2007/07/24 16:22:50 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2007/07/24 16:22:49 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2007/07/24 16:22:49 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2007/07/24 16:22:49 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2007/07/24 16:22:49 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2007/07/24 16:22:49 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2007/07/24 16:22:49 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2007/07/24 16:22:49 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2007/07/24 16:22:49 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2007/07/24 16:22:49 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2007/07/24 16:22:49 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2007/07/24 16:22:49 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2007/07/24 16:22:49 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2007/07/24 16:22:49 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2007/07/24 16:22:49 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2007/07/24 16:22:49 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2007/07/24 16:22:49 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2007/07/24 16:22:49 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2007/07/24 16:22:49 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2007/07/06 18:06:24 | 000,001,160 | ---- | C] () -- C:\WINDOWS\ARCHPR.INI
[2007/06/07 18:20:02 | 000,003,452 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Musepack Codec.dat
[2007/06/01 15:17:27 | 000,000,227 | ---- | C] () -- C:\WINDOWS\PowerReg.dat
[2007/06/01 15:17:21 | 000,045,568 | ---- | C] () -- C:\WINDOWS\UniFish3.exe
[2007/05/17 13:58:10 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\libexpatw.dll
[2007/03/28 15:25:37 | 000,000,050 | ---- | C] () -- C:\WINDOWS\MegaManager.INI
[2007/03/22 16:47:35 | 000,046,344 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.EXE
[2007/02/20 18:14:20 | 000,194,133 | ---- | C] () -- C:\WINDOWS\patcher.exe
[2007/02/05 21:34:05 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\MP2enc.dll
[2007/01/19 12:34:39 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2007/01/19 12:34:39 | 000,000,341 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2007/01/19 12:33:58 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2007/01/19 12:33:58 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2007/01/19 12:33:58 | 000,000,073 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2007/01/19 12:33:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nsprs.dll
[2006/11/20 12:04:59 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2006/11/06 15:30:38 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2006/06/18 19:47:49 | 000,161,280 | ---- | C] () -- C:\Documents and Settings\Mimi II\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/06/18 19:47:49 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Mimi II\Local Settings\Application Data\fusioncache.dat
[2006/06/17 13:32:06 | 001,019,094 | RHS- | C] () -- C:\Program Files\serial.zip
[2006/06/17 13:32:06 | 001,019,094 | RHS- | C] () -- C:\Program Files\serial.tde
[2006/05/28 12:45:47 | 000,397,306 | RHS- | C] () -- C:\Program Files\wunauclt.zip
[2006/05/28 12:45:47 | 000,397,306 | RHS- | C] () -- C:\Program Files\wunauclt.tbe
[2006/05/01 19:19:24 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2006/04/15 10:38:42 | 000,001,067 | ---- | C] () -- C:\WINDOWS\ARPR.INI
[2006/02/11 21:14:57 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\micr0st.dll
[2006/02/11 21:01:13 | 000,000,067 | ---- | C] () -- C:\WINDOWS\A1 DVD Ripper.INI
[2006/01/13 18:28:11 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/12/12 20:57:59 | 000,033,012 | ---- | C] () -- C:\WINDOWS\System32\tpuninstall.exe
[2005/12/07 10:56:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\TempName.dll
[2005/12/06 21:05:32 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\drivers\netfltConfig.dat
[2005/11/24 17:46:19 | 000,370,000 | RHS- | C] () -- C:\WINDOWS\aiiaacc.exe
[2005/11/24 17:46:19 | 000,000,007 | ---- | C] () -- C:\WINDOWS\wocnm.dat
[2005/11/24 17:46:19 | 000,000,001 | ---- | C] () -- C:\WINDOWS\isf.dat
[2005/11/22 13:24:32 | 000,666,240 | ---- | C] () -- C:\WINDOWS\System32\aswBoot.exe
[2005/11/01 13:51:23 | 000,001,290 | ---- | C] () -- C:\WINDOWS\AZPR3.INI
[2005/10/01 18:01:50 | 000,000,066 | ---- | C] () -- C:\WINDOWS\Aurora Video VCD_SVCD_DVD Creator.INI
[2005/10/01 17:33:25 | 000,000,067 | ---- | C] () -- C:\WINDOWS\VideoConvert.INI
[2005/10/01 17:31:01 | 000,000,066 | ---- | C] () -- C:\WINDOWS\#1 Video Converter.INI
[2005/09/11 18:06:16 | 000,000,287 | ---- | C] () -- C:\WINDOWS\EReg072.dat
[2005/06/22 21:37:51 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\FileOps.exe
[2005/05/13 12:41:24 | 000,167,424 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe
[2005/05/13 12:14:11 | 000,000,005 | ---- | C] () -- C:\WINDOWS\System32\wincon.dat
[2005/03/10 14:40:28 | 000,000,339 | ---- | C] () -- C:\WINDOWS\ULEAD32.INI
[2005/03/07 12:25:55 | 000,099,965 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2005/03/02 18:36:38 | 000,105,168 | ---- | C] () -- C:\WINDOWS\NSUninst.exe
[2005/03/02 18:36:18 | 000,105,168 | ---- | C] () -- C:\WINDOWS\GREUninstall.exe
[2005/03/02 18:36:16 | 000,013,605 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2005/03/01 21:58:36 | 000,004,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2005/02/27 10:56:58 | 000,000,819 | ---- | C] () -- C:\WINDOWS\jamkeys.ini
[2005/02/27 10:56:58 | 000,000,024 | ---- | C] () -- C:\WINDOWS\jam.ini
[2005/02/27 10:56:46 | 000,000,055 | ---- | C] () -- C:\WINDOWS\mediachk.ini
[2005/02/27 10:56:46 | 000,000,040 | ---- | C] () -- C:\WINDOWS\sndcheck.ini
[2005/02/27 10:56:42 | 000,025,440 | ---- | C] () -- C:\WINDOWS\VUNINSTL.DLL
[2005/02/27 10:56:38 | 000,304,128 | ---- | C] () -- C:\WINDOWS\VUNINSTL.EXE
[2005/02/27 10:55:33 | 000,000,395 | ---- | C] () -- C:\WINDOWS\VUNINSTL.INI
[2005/02/14 13:53:19 | 000,000,402 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2005/01/12 14:17:03 | 000,000,338 | ---- | C] () -- C:\WINDOWS\fontssg.ini
[2005/01/12 14:17:03 | 000,000,097 | ---- | C] () -- C:\WINDOWS\LMICD.INI
[2005/01/04 12:30:46 | 000,059,419 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2005/01/01 14:11:10 | 000,000,644 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2004/12/29 14:30:34 | 000,001,125 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2004/12/29 13:56:55 | 000,000,985 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2004/12/29 13:55:59 | 000,143,360 | R--- | C] () -- C:\WINDOWS\System32\dlbtcoin.dll
[2004/12/29 13:55:59 | 000,126,976 | R--- | C] () -- C:\WINDOWS\System32\dlbtsnls.dll
[2004/12/29 13:55:43 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbtvs.dll
[2004/12/29 13:55:42 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\dlbtih.exe
[2004/12/29 13:55:39 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\dlbtcur.dll
[2004/12/29 13:55:39 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\dlbtcu.dll
[2004/12/29 13:55:34 | 000,557,056 | ---- | C] () -- C:\WINDOWS\System32\dlbtjswr.dll
[2004/12/29 13:55:26 | 000,401,408 | ---- | C] () -- C:\WINDOWS\System32\dlbtutil.dll
[2004/12/29 13:25:06 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2004/12/03 19:59:44 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/12/03 19:57:05 | 000,000,324 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/12/03 19:52:41 | 000,000,590 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/12/03 19:50:14 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2004/12/03 19:41:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\BOOTSTAT.DAT
[2004/12/03 19:40:54 | 000,445,830 | ---- | C] () -- C:\WINDOWS\System32\PERFH009.DAT
[2004/12/03 19:40:54 | 000,073,036 | ---- | C] () -- C:\WINDOWS\System32\PERFC009.DAT
[2004/12/03 19:27:50 | 000,000,519 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/10/26 18:39:05 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2004/09/28 07:38:30 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\wmatimer.dll
[2004/09/16 00:03:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 15:13:12 | 000,000,882 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/08/10 15:08:08 | 000,397,552 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 15:03:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 15:02:16 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 12:08:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 12:08:26 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\MIB.BIN
[2004/08/04 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 07:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 07:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 18:01:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\SETPWRCG.EXE
[2004/07/03 22:08:04 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2003/12/13 22:40:42 | 001,003,520 | ---- | C] () -- C:\WINDOWS\System32\ltmm_n.dll
[2003/07/31 19:16:46 | 000,000,017 | -H-- | C] () -- C:\WINDOWS\System32\drivers\DVEMODEM.DAT
[2003/01/07 17:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/15 18:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[1997/08/23 12:33:24 | 000,022,064 | ---- | C] () -- C:\WINDOWS\System32\tntlvr.dll
[1997/06/13 21:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[1980/01/01 02:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2011/09/23 10:11:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2004/12/03 19:49:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/03/14 10:24:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2008/12/26 19:37:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/05/08 12:11:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy-PizzaParty
[2007/09/08 10:45:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Internet debug mess great
[2007/12/03 22:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/02/27 14:33:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2010/10/01 18:23:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008/05/04 15:32:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PrevxCSI
[2010/09/08 11:45:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\River Past G5
[2008/08/28 12:12:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SimCity Societies
[2011/07/02 17:45:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Solidshield
[2010/06/19 10:36:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/02/01 18:39:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2007/07/28 11:33:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Storm
[2009/06/18 18:47:08 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\System Restore
[2010/01/01 14:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tages
[2005/01/08 11:46:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tavultesoft
[2009/05/08 12:11:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/11 11:53:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2007/05/16 19:56:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\.BitTornado
[2009/11/30 12:05:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\AVG9
[2008/12/26 19:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\DAEMON Tools
[2008/12/26 19:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\DAEMON Tools Lite
[2008/12/26 19:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\DAEMON Tools Pro
[2008/02/06 16:02:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Design Science
[2011/02/15 19:15:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Dropbox
[2006/06/18 19:40:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\FIFA2003CC
[2006/06/18 19:40:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\GlobalSCAPE
[2007/11/23 20:40:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Grammatica
[2010/03/12 15:24:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\gtk-2.0
[2006/06/18 19:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Leadertech
[2011/06/08 19:06:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Mael
[2008/09/15 13:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Maple
[2008/10/06 18:11:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\My Games
[2010/10/01 18:23:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\NCH Swift Sound
[2009/05/26 18:44:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Netscape
[2011/06/08 19:09:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Notepad++
[2009/03/16 20:11:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\OpenOffice.org
[2007/07/24 16:23:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Panasonic
[2007/07/31 15:56:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\ppstream
[2011/01/09 14:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\RenPy
[2008/04/04 20:08:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\River Past G5
[2009/02/13 19:09:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\SendSpace Wizard
[2006/06/18 19:35:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Seven Zip
[2010/06/19 10:35:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Sports Interactive
[2006/06/18 19:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\STOIK
[2011/09/11 18:51:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Ubisoft
[2007/11/30 21:58:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Uniblue
[2011/01/09 14:43:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Utherverse
[2006/06/18 19:34:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Visicom Media
[2010/08/18 12:00:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Vivox
[2006/06/18 19:34:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\VP-Software
[2008/06/10 20:43:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Vso
[2011/09/16 18:30:43 | 000,000,282 | ---- | M] () -- C:\WINDOWS\Tasks\switchShakeIcon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 07:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 20:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\SYSTEM32\svchost.exe
[2004/08/04 07:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\I386\SVCHOST.EXE
[2004/08/04 07:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 07:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\I386\USERINIT.EXE
[2004/08/04 07:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\SYSTEM32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 07:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\I386\WINLOGON.EXE
[2004/08/04 07:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\SYSTEM32\winlogon.exe

< %systemroot%\*. /mp /s >

< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\aol.exe\InstallInfo\\ReinstallCommand: C:\PROGRA~1\AOL9~1.0\accdef.exe -rb [2004/04/08 13:09:16 | 000,016,496 | ---- | M] (America Online, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\aol.exe\InstallInfo\\HideIconsCommand: C:\PROGRA~1\AOL9~1.0\accdef.exe -hb [2004/04/08 13:09:16 | 000,016,496 | ---- | M] (America Online, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\aol.exe\InstallInfo\\ShowIconsCommand: C:\PROGRA~1\AOL9~1.0\accdef.exe -sb [2004/04/08 13:09:16 | 000,016,496 | ---- | M] (America Online, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\aol.exe\shell\open\command\\: C:\PROGRA~1\AOL9~1.0\aol.exe [2004/04/08 13:09:58 | 000,038,000 | ---- | M] (America Online, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/09/23 00:28:29 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/09/23 00:28:29 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/09/23 00:28:29 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/09/23 00:28:29 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/09/23 00:28:29 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/09/23 00:28:29 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/08/22 07:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/08/22 07:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/08/22 07:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\InstallInfo\\HideIconsCommand: "" /HideShortcuts
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\InstallInfo\\ShowIconsCommand: "" /ShowShortcuts
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\InstallInfo\\ReinstallCommand: "" /SetAsDefaultAppGlobal
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\shell\open\command\\: C:\Program Files\Netscape\Navigator 9\navigator.exe
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\shell\properties\command\\: "C:\Program Files\Netscape\Navigator 9\navigator.exe" -preferences
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\shell\safemode\command\\: "C:\Program Files\Netscape\Navigator 9\navigator.exe" -safe-mode
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Netscp.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Netscape\Netscape\uninstall\NSUninst.exe" /ua "7.2 (en)" /hs browser [2005/03/02 18:36:38 | 000,105,168 | ---- | M] ()
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Netscp.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Netscape\Netscape\Netscp.exe" -silent -nosplash -setDefaultBrowser [2004/08/04 18:41:00 | 000,526,224 | ---- | M] (Mozilla, Netscape)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Netscp.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Netscape\Netscape\uninstall\NSUninst.exe" /ua "7.2 (en)" /ss browser [2005/03/02 18:36:38 | 000,105,168 | ---- | M] ()
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Netscp.exe\shell\open\command\\: C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE [2004/08/04 18:41:00 | 000,526,224 | ---- | M] (Mozilla, Netscape)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Netscp.exe\shell\properties\command\\: C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE -chrome "chrome://communicator/content/pref/pref.xul" [2004/08/04 18:41:00 | 000,526,224 | ---- | M] (Mozilla, Netscape)

< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\aol.exe\InstallInfo\\ReinstallCommand: C:\PROGRA~1\AOL9~1.0\accdef.exe -rb [2004/04/08 13:09:16 | 000,016,496 | ---- | M] (America Online, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\aol.exe\InstallInfo\\HideIconsCommand: C:\PROGRA~1\AOL9~1.0\accdef.exe -hb [2004/04/08 13:09:16 | 000,016,496 | ---- | M] (America Online, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\aol.exe\InstallInfo\\ShowIconsCommand: C:\PROGRA~1\AOL9~1.0\accdef.exe -sb [2004/04/08 13:09:16 | 000,016,496 | ---- | M] (America Online, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\aol.exe\shell\open\command\\: C:\PROGRA~1\AOL9~1.0\aol.exe [2004/04/08 13:09:58 | 000,038,000 | ---- | M] (America Online, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/09/23 00:28:29 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/09/23 00:28:29 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/09/23 00:28:29 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/09/23 00:28:29 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/09/23 00:28:29 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/09/23 00:28:29 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/08/22 07:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/08/22 07:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/08/22 07:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\InstallInfo\\HideIconsCommand: "" /HideShortcuts
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\InstallInfo\\ShowIconsCommand: "" /ShowShortcuts
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\InstallInfo\\ReinstallCommand: "" /SetAsDefaultAppGlobal
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\shell\open\command\\: C:\Program Files\Netscape\Navigator 9\navigator.exe
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\shell\properties\command\\: "C:\Program Files\Netscape\Navigator 9\navigator.exe" -preferences
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\NAVIGATOR.EXE\shell\safemode\command\\: "C:\Program Files\Netscape\Navigator 9\navigator.exe" -safe-mode
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Netscp.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Netscape\Netscape\uninstall\NSUninst.exe" /ua "7.2 (en)" /hs browser [2005/03/02 18:36:38 | 000,105,168 | ---- | M] ()
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Netscp.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Netscape\Netscape\Netscp.exe" -silent -nosplash -setDefaultBrowser [2004/08/04 18:41:00 | 000,526,224 | ---- | M] (Mozilla, Netscape)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Netscp.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Netscape\Netscape\uninstall\NSUninst.exe" /ua "7.2 (en)" /ss browser [2005/03/02 18:36:38 | 000,105,168 | ---- | M] ()
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Netscp.exe\shell\open\command\\: C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE [2004/08/04 18:41:00 | 000,526,224 | ---- | M] (Mozilla, Netscape)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Netscp.exe\shell\properties\command\\: C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE -chrome "chrome://communicator/content/pref/pref.xul" [2004/08/04 18:41:00 | 000,526,224 | ---- | M] (Mozilla, Netscape)

========== Alternate Data Streams ==========

@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A5227364
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A73B0434

< End of report >

Edited by princessmimi, 13 October 2011 - 06:23 PM.

  • 0

#4
princessmimi

princessmimi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Unfortunately, I have to get off the computer now, so the second step will be done tomorrow morning, if that's alright.

Extras.txt:

OTL Extras logfile created on: 10/13/2011 7:36:14 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Mimi II\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.07 Mb Total Physical Memory | 641.79 Mb Available Physical Memory | 62.79% Memory free
2.40 Gb Paging File | 1.78 Gb Available in Paging File | 73.95% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.68 Gb Total Space | 8.31 Gb Free Space | 11.59% Space Free | Partition Type: NTFS

Computer Name: D3T0R661 | User Name: Mimi II | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.reg [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.scr [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [open] -- Reg Error: Invalid data type.
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"4662:TCP" = 4662:TCP:*:Enabled:eMule port
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service
"4672:UDP" = 4672:UDP:*:Enabled:eMule port

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\WinMX\WinMX.exe" = C:\Program Files\WinMX\WinMX.exe:*:Enabled:WinMX Application
"C:\Program Files\Soulseek\slsk.exe" = C:\Program Files\Soulseek\slsk.exe:*:Enabled:SoulSeek Client
"C:\Program Files\RhinoSoft.com\FTP Voyager\FTPVoyager.exe" = C:\Program Files\RhinoSoft.com\FTP Voyager\FTPVoyager.exe:*:Enabled:FTP Voyager, an FTP Client for Windows
"C:\Program Files\Cerberus\Cerberus.exe" = C:\Program Files\Cerberus\Cerberus.exe:*:Enabled:Cerberus FTP Server Application
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire 4.9.28
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
"C:\Program Files\Netscape\Netscape\Netscp.exe" = C:\Program Files\Netscape\Netscape\Netscp.exe:*:Enabled:Netscape -- (Mozilla, Netscape)
"C:\StubInstaller.exe" = C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"C:\Program Files\BitTornado\btdownloadgui.exe" = C:\Program Files\BitTornado\btdownloadgui.exe:*:Enabled:btdownloadgui -- ()
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\Program Files\PPStream\PPStream.exe" = C:\Program Files\PPStream\PPStream.exe:*:Enabled:PPStream
"C:\Program Files\TVAnts\Tvants.exe" = C:\Program Files\TVAnts\Tvants.exe:*:Enabled:TVAnts
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application
"C:\Program Files\Global Star Software\Airport Tycoon 3\at3.exe" = C:\Program Files\Global Star Software\Airport Tycoon 3\at3.exe:*:Enabled:at3
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Documents and Settings\Mimi II\My Documents\Michal's Documents\Gabi's Stuff\Soccer Songs\gabi\SopCast\adv\SopAdver.exe" = C:\Documents and Settings\Mimi II\My Documents\Michal's Documents\Gabi's Stuff\Soccer Songs\gabi\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver
"C:\Program Files\Ubisoft\Blue Byte\The Settlers - Dziedzictwo Królów\bin\settlershok.exe" = C:\Program Files\Ubisoft\Blue Byte\The Settlers - Dziedzictwo Królów\bin\settlershok.exe:*:Enabled:THE SETTLERS - Heritage of Kings
"C:\Program Files\Maple 12\jre\bin\maple.exe" = C:\Program Files\Maple 12\jre\bin\maple.exe:*:Enabled:Maple 12
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Documents and Settings\Mimi II\My Documents\football + soccer\Soccer CD\SopCast\adv\SopAdver.exe" = C:\Documents and Settings\Mimi II\My Documents\football + soccer\Soccer CD\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver
"C:\Program Files\Anno 1701\Anno1701.exe" = C:\Program Files\Anno 1701\Anno1701.exe:*:Enabled:Anno 1701
"C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule -- (http://www.emule-project.net)
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver
"C:\Documents and Settings\Mimi II\Application Data\SopCast\adv\SopAdver.exe" = C:\Documents and Settings\Mimi II\Application Data\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver -- (www.sopcast.com)
"C:\Program Files\Mozilla Firefox\FirefoxPortable\App\Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\FirefoxPortable\App\Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\River Past\Audio Converter\AudioConverter.exe" = C:\Program Files\River Past\Audio Converter\AudioConverter.exe:*:Enabled:River Past Audio Converter
"C:\Documents and Settings\Mimi II\Application Data\IMVUClient\1VivoxVoice.exe" = C:\Documents and Settings\Mimi II\Application Data\IMVUClient\1VivoxVoice.exe:*:Enabled:1VivoxVoice
"C:\Program Files\Utherverse Digital Inc\Utherverse VWW Client\Utherverse.exe" = C:\Program Files\Utherverse Digital Inc\Utherverse VWW Client\Utherverse.exe:*:Disabled:Utherverse
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Documents and Settings\Mimi II\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Mimi II\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)
"C:\Program Files\SecondLifeViewer2\SLVoice.exe" = C:\Program Files\SecondLifeViewer2\SLVoice.exe:*:Enabled:SLVoice
"C:\Program Files\Ubisoft\Related Designs\ANNO 1404\Anno4.exe" = C:\Program Files\Ubisoft\Related Designs\ANNO 1404\Anno4.exe:*:Enabled:ANNO 1404 -- (Related Designs)
"C:\Program Files\Ubisoft\Related Designs\ANNO 1404\tools\Anno4Web.exe" = C:\Program Files\Ubisoft\Related Designs\ANNO 1404\tools\Anno4Web.exe:*:Enabled:ANNO 1404 Web -- ()
"C:\Program Files\Sports Interactive\Football Manager 2010\fm.exe" = C:\Program Files\Sports Interactive\Football Manager 2010\fm.exe:*:Disabled:Football Manager 2010
"C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe" = C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet,0.0.0.0/255.255.255.255:Enabled:Pure Networks Platform Service -- (Cisco Systems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03ADC8AB-C130-0C3D-1FF9-2C385DF25689}" = CCC Help Czech
"{053A7E07-3D44-4CDB-B79C-EE8755BFD7D6}" = Class_50_Content_Update
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07021185-008D-ABF9-7716-475AC035F8B3}" = CCC Help Spanish
"{09CF6AF5-9206-4FD7-9B08-BA6819FB47E3}" = Anno 1404
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F8D0406-7755-AC37-6529-73AD649DBE32}" = Catalyst Control Center Graphics Previews Common
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1B2DBF55-05D4-4072-87D8-689141E262BD}" = Creative ZEN
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22072CC8-7230-96F8-52F4-05EAF3F906B6}" = CCC Help Polish
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2368ADBD-6FDF-4B9F-FE41-E20B4D78E79E}" = CCC Help Chinese Standard
"{25EF0DC4-B072-2E04-4581-A13C91423CE6}" = CCC Help Portuguese
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 26
"{26F7855C-443B-00A6-F7B8-A97A5403F617}" = CCC Help Danish
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2CB4A925-48A7-DA65-DCEE-D4DE224B7D84}" = CCC Help English
"{2CDCCE7E-55D5-40CC-AEA0-ABA54713501F}" = LUMIX Simple Viewer
"{306D75B9-7FFF-FF65-0C76-57F2FE4FE1D6}" = Catalyst Control Center Core Implementation
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{32B12FE4-5A51-751A-1FB6-A14E97EBDD5C}" = CCC Help German
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{351512E5-01BD-E878-6F57-AA3E517D9ECE}" = Skins
"{354A387E-0374-21A3-6832-335674A6D7D1}" = CCC Help French
"{3C00BEE9-26D0-D9E0-A2D1-62F70D412A12}" = CCC Help Turkish
"{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}" = ANNO 1404
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4346F7AA-3D56-0941-424C-4454E04D37F6}" = CCC Help Italian
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CAE2F2C-75CD-A0DE-7520-449BCBBCC833}" = CCC Help Korean
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57F7F0A5-8F22-8E63-E819-803B5C9CA3A5}" = CCC Help Dutch
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5EA437D2-7A57-B60E-E8F2-76BFAC0895A5}" = CCC Help Chinese Traditional
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61AF4E75-050E-0304-3417-8BC16417FEB1}" = CCC Help Greek
"{632005DA-C291-5275-284C-5EE96B05C714}" = Catalyst Control Center HydraVision Full
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.3
"{6C72BE0C-3E25-CACD-0070-2FD9C02ABA14}" = ccc-core-preinstall
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7148F0A8-6813-11D6-A77B-00B0D0142060}" = Java 2 Runtime Environment, SE v1.4.2_06
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7AC0886A-CE48-4EB6-9CC3-4C56D427F2E1}" = Cisco Network Magic
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{7E6066E6-8B5B-4100-B0FA-1D9E9B663CBA}" = iTunes
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{7FCC4EDC-6EE2-4309-ABD7-85F2667A7B90}" = WebEx Support Manager for Internet Explorer
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{880BB617-914E-17E8-D877-A96BAC5794D2}" = Catalyst Control Center Graphics Full New
"{8897CF22-DB6C-8248-895C-12BFA2677F51}" = CCC Help Hungarian
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{998D6972-F58E-479D-9248-8F179E55AE38}" = Java DB 10.4.1.3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AC76BA86-7AD7-5670-0000-800000000003}" = Korean Fonts Support For Adobe Reader 8
"{AC76BA86-7AD7-5760-0000-800000000003}" = Japanese Fonts Support For Adobe Reader 8
"{AF710FDE-2815-8C8D-5281-8004C2654AA6}" = CCC Help Russian
"{AFF2D965-C6F2-A210-FBF7-532612AA1D23}" = CCC Help Swedish
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B21336EE-4AEF-9940-4AC7-EDB89854B8D3}" = CCC Help Thai
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BBA69346-61A1-BD34-E75A-4D81232DB1FE}" = Catalyst Control Center Localization All
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BF7C1B99-A250-45EF-B186-0C33B7308F95}" = SD40-2_Content_Update
"{BFD5ED08-F066-92D5-BE67-3B9AE5DCFF0C}" = CCC Help Japanese
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4609F15-FB3C-D97E-BAA1-4F10815039C2}" = Catalyst Control Center Graphics Full Existing
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D01FAC3D-86B4-3A19-9D10-9156A0EB3EBE}" = CCC Help Finnish
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint Plus
"{D73722C8-3F65-C75B-A631-5D36894DAB92}" = ccc-core-static
"{DB5F474C-B584-417F-810B-DEBBC1893C2A}" = TBS WMP Plug-in
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DDAD33B6-8C00-428D-087B-A7088355B9BE}" = Catalyst Control Center Graphics Light
"{E333F074-FC7F-596D-3D61-44F0EC28E8C0}" = ccc-utility
"{E3436EE2-D5CB-4249-840B-3A0140CC34C3}" = Classic PhoneTools
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F71C0208-1D32-439D-9257-F90F0BAACE6A}" = CM 03-04
"{FA38F9E4-BED7-E021-B660-8FDFF7EC6E1A}" = CCC Help Norwegian
"{FC467B61-F890-4E29-8585-365DAB66F13E}" = Pure Networks Platform
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"All ATI Software" = ATI - Software Uninstall Utility
"America Online ca" = AOL (Choose which version to remove)
"AOL Connectivity Services" = AOL Connectivity Services
"ATI Display Driver" = ATI Display Driver
"AVG9Uninstall" = AVG 9.0
"BitTornado" = BitTornado 0.3.17
"CCleaner" = CCleaner (remove only)
"Crossword Weaver 7.0" = Crossword Weaver 7.0
"dBpowerAMP Monkeys Audio Codec" = dBpowerAMP Monkeys Audio Codec
"dBpowerAMP Mp4 Codec" = dBpowerAMP Mp4 Codec
"dBpowerAMP Musepack Codec" = dBpowerAMP Musepack Codec
"dBpowerAMP Ogg Vorbis Codec" = dBpowerAMP Ogg Vorbis Codec
"Dell Photo AIO Printer 922" = Dell Photo AIO Printer 922
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"dMC mp3PRO (CLI) Encoder" = dMC mp3PRO (CLI) Encoder
"DSMT6" = MathType 6
"eMule" = eMule
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{DB5F474C-B584-417F-810B-DEBBC1893C2A}" = TBS WMP Plug-in
"InstallShield_{F71C0208-1D32-439D-9257-F90F0BAACE6A}" = CM 03-04
"Intel® 537EP V9x DFV PCI Modem" = Intel® 537EP V9x DFV PCI Modem
"JDownloader" = JDownloader
"Keyman Package blackfoot" = Keyman Package - Blackfoot Practical Unicode
"Keyman Package cree_east_u" = Keyman Package - East Cree Unicode
"Keyman Package dakelh1_u" = Keyman Package - Dakelh I Unicode
"Keyman Package inuktitut_u" = Keyman Package - Inuktitut Unicode
"Keyman Package kmtip" = Keyman Package - Add-in for Text Services Framework
"Keyman Package naskapi_u" = Keyman Package - Naskapi Unicode
"Keyman Package ojibway_af_ww" = Keyman Package - Ojibway a-final West-w
"Keyman Package richedit" = Keyman Package - Add-in for Richedit Control
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 7.0 (x86 en-US)" = Mozilla Firefox 7.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Netscape (7.2)" = Netscape (7.2)
"Network MagicUninstall" = Network Magic
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"ProTrain 1.1 US 1.1" = ProTrain 1.1 US 1.1
"PSSENSOR_ab977ca22ef595e0c55853eb3fbfffd950acc82c" = Windows Driver Package - PASCO Scientific (PASCO) USB 01/17/2004 1.9.0.0
"RadLight APE DirectShow filter" = RadLight APE DirectShow filter (remove only)
"RadLight TTA DirectShow filter" = RadLight TTA DirectShow filter (remove only)
"RealPlayer 12.0" = RealPlayer
"Switch" = Switch Sound File Converter
"SysInfo" = Creative System Information
"Tavultesoft Keyman 6.0" = Tavultesoft Keyman 6.0
"VLC media player" = VideoLAN VLC media player 0.8.6b
"VobSub" = VobSub v2.23 (Remove Only)
"vPod" = vPod (Remove Only)
"Winamp" = Winamp (remove only)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"ZENcast Organizer" = ZENcast Organizer

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Video4iPod Converter" = Video4iPod Converter

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/13/2011 10:40:57 AM | Computer Name = D3T0R661 | Source = ESENT | ID = 490
Description = svchost (1220) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 10/13/2011 10:40:57 AM | Computer Name = D3T0R661 | Source = ESENT | ID = 470
Description = Catalog Database (1220) Database C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
is partially attached. Attachment stage: 3. Error: -1032.

Error - 10/13/2011 10:52:04 AM | Computer Name = D3T0R661 | Source = ESENT | ID = 494
Description = Catalog Database (1220) Database recovery failed with error -1216
because it encountered references to a database, 'C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb',
which is no longer present. The database was not brought to a consistent state
before it was removed (or possibly moved or renamed). The database engine will not
permit recovery to complete for this instance until the missing database is re-instated.
If the database is truly no longer available and no longer required, please contact
PSS for further instructions regarding the steps required in order to allow recovery
to proceed without this database.

Error - 10/13/2011 10:52:04 AM | Computer Name = D3T0R661 | Source = ESENT | ID = 454
Description = Catalog Database (1220) Database recovery/restore failed with unexpected
error -1216.

Error - 10/13/2011 11:16:58 AM | Computer Name = D3T0R661 | Source = ESENT | ID = 490
Description = svchost (1220) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 10/13/2011 11:16:58 AM | Computer Name = D3T0R661 | Source = ESENT | ID = 439
Description = Catalog Database (1220) Unable to write a shadowed header for file
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb. Error
-1032.

Error - 10/13/2011 11:16:58 AM | Computer Name = D3T0R661 | Source = ESENT | ID = 473
Description = Catalog Database (1220) Database C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
was partially detached. Error -1032 encountered updating database headers.

Error - 10/13/2011 12:40:36 PM | Computer Name = D3T0R661 | Source = ESENT | ID = 490
Description = svchost (1224) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 10/13/2011 12:40:36 PM | Computer Name = D3T0R661 | Source = ESENT | ID = 439
Description = Catalog Database (1224) Unable to write a shadowed header for file
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb. Error
-1032.

Error - 10/13/2011 12:40:37 PM | Computer Name = D3T0R661 | Source = ESENT | ID = 473
Description = Catalog Database (1224) Database C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
was partially detached. Error -1032 encountered updating database headers.

[ System Events ]
Error - 10/13/2011 10:18:51 AM | Computer Name = D3T0R661 | Source = Service Control Manager | ID = 7001
Description = The Wireless Zero Configuration service depends on the NDIS Usermode
I/O Protocol service which failed to start because of the following error: %%1058

Error - 10/13/2011 10:18:51 AM | Computer Name = D3T0R661 | Source = Service Control Manager | ID = 7000
Description = The bsaspi32 service failed to start due to the following error: %%2

Error - 10/13/2011 10:18:51 AM | Computer Name = D3T0R661 | Source = Service Control Manager | ID = 7000
Description = The RPC Security service failed to start due to the following error:
%%2

Error - 10/13/2011 12:32:35 PM | Computer Name = D3T0R661 | Source = Service Control Manager | ID = 7001
Description = The Wireless Zero Configuration service depends on the NDIS Usermode
I/O Protocol service which failed to start because of the following error: %%1058

Error - 10/13/2011 12:32:35 PM | Computer Name = D3T0R661 | Source = Service Control Manager | ID = 7000
Description = The bsaspi32 service failed to start due to the following error: %%2

Error - 10/13/2011 12:32:35 PM | Computer Name = D3T0R661 | Source = Service Control Manager | ID = 7000
Description = The RPC Security service failed to start due to the following error:
%%2

Error - 10/13/2011 4:42:48 PM | Computer Name = D3T0R661 | Source = Service Control Manager | ID = 7001
Description = The Wireless Zero Configuration service depends on the NDIS Usermode
I/O Protocol service which failed to start because of the following error: %%1058

Error - 10/13/2011 4:42:48 PM | Computer Name = D3T0R661 | Source = Service Control Manager | ID = 7000
Description = The bsaspi32 service failed to start due to the following error: %%2

Error - 10/13/2011 4:42:48 PM | Computer Name = D3T0R661 | Source = Service Control Manager | ID = 7000
Description = The RPC Security service failed to start due to the following error:
%%2

Error - 10/13/2011 7:38:42 PM | Computer Name = D3T0R661 | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume C:.


< End of report >
  • 0

#5
princessmimi

princessmimi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Hello again! Here's the GMER log:

((PS. I'm not sure if it's important with the results, but when I started up my computer this morning, I got a CHKDSK which said my volune C:\ was dirty and did some repairs. Just so it's clear, the OTL was done before the CHKDSK and the GMER was done after))

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-14 11:48:29
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 WDC_WD800JD-75JNA0 rev.05.01C05
Running: sbruso00.exe; Driver: C:\DOCUME~1\MIMIII~1\LOCALS~1\Temp\kwlyapog.sys


---- System - GMER 1.0.15 ----

SSDT spbh.sys ZwCreateKey [0xF77450E0]
SSDT spbh.sys ZwEnumerateKey [0xF7763CA2]
SSDT spbh.sys ZwEnumerateValueKey [0xF7764030]
SSDT spbh.sys ZwOpenKey [0xF77450C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xEBE87670]
SSDT spbh.sys ZwQueryKey [0xF7764108]
SSDT spbh.sys ZwQueryValueKey [0xF7763F88]
SSDT spbh.sys ZwSetValueKey [0xF776419A]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xEBE87720]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xEBE877C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xEBE87860]

INT 0x62 ? 8735FBF8
INT 0x63 ? 871BFE70
INT 0x73 ? 8735FBF8
INT 0x94 ? 871BFE70
INT 0xA4 ? 871BFE70
INT 0xB4 ? 871BFE70

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!ZwYieldExecution + 47A 804E4CD4 8 Bytes [20, 77, E8, EB, C0, 77, E8, ...]
? spbh.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF69C6000, 0x1C5D38, 0xE8000020]
.text USBPORT.SYS!DllUnload F69A58AC 5 Bytes JMP 871BF450
init C:\WINDOWS\system32\DRIVERS\mohfilt.sys entry point in "init" section [0xF7C60760]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xEB3FA300, 0x3B6D8, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xF7C05300, 0x1BEE, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text C:\program files\real\realplayer\update\realsched.exe[448] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 873D22D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F7776C4C] spbh.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7776CA0] spbh.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7746040] spbh.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F774613C] spbh.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F77460BE] spbh.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F77467FC] spbh.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F77466D2] spbh.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 871BF550
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F7756048] spbh.sys

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 8734A1F8

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBPDO-0 8704E500
Device \Driver\usbuhci \Device\USBPDO-1 8704E500
Device \Driver\usbuhci \Device\USBPDO-2 8704E500
Device \Driver\usbuhci \Device\USBPDO-3 8704E500
Device \Driver\usbehci \Device\USBPDO-4 871F5408

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Ftdisk \Device\HarddiskVolume1 873601F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 873601F8
Device \Driver\Cdrom \Device\CdRom0 871B7368
Device \Driver\Cdrom \Device\CdRom1 871B7368
Device \Driver\atapi \Device\Ide\IdePort0 [F76BFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F76BFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F76BFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F76BFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 [F76BFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Ftdisk \Device\HarddiskVolume3 873601F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 87100500
Device \Driver\NetBT \Device\NetbiosSmb 87100500

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBFDO-0 8704E500
Device \Driver\usbuhci \Device\USBFDO-1 8704E500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8719D500
Device \Driver\usbuhci \Device\USBFDO-2 8704E500
Device \Driver\NetBT \Device\NetBT_Tcpip_{08B6E02A-BBEA-450C-A110-EED00DD6157E} 87100500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8719D500
Device \Driver\usbuhci \Device\USBFDO-3 8704E500
Device \Driver\usbehci \Device\USBFDO-4 871F5408
Device \Driver\Ftdisk \Device\FtControl 873601F8
Device \FileSystem\Fastfat \Fat 8704F500
Device \FileSystem\Fastfat \Fat BA5D1297

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs 87092480
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\[email protected] 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\[email protected] 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 0x9B 0x2E 0x41 0x9E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\[email protected] 0x9B 0x2E 0x41 0x9E ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] 0x9B 0x2E 0x41 0x9E ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\[email protected] 0x9B 0x2E 0x41 0x9E ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\[email protected] 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\[email protected] 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\[email protected] yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\[email protected]
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\[email protected] 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\[email protected] 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\[email protected]_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\[email protected]_DLLs 1
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\[email protected] C:\Program Files\Common Files\System\ado\msado15.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\[email protected] Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\[email protected] ADODB.StreamClass
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\[email protected] ADODB, Version=7.0.3300.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\[email protected] v1.0.3705
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\InprocServer32\7.0.3300.0
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\InprocServer32\[email protected] ADODB.StreamClass
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\InprocServer32\[email protected] ADODB, Version=7.0.3300.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\InprocServer32\[email protected] v1.0.3705
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\[email protected] ADODB.Stream.2.8
Reg HKLM\SOFTWARE\Classes\CLSID\{54F7E20E-E585-D8F5-72FC-4456429E0881}\[email protected] ADODB.Stream
Reg HKLM\SOFTWARE\Classes\CLSID\{6C68E3C2-87CF-9D19-4BCF-EE4F0E8B2FA6}\[email protected] C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\ITIRCL52.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{6C68E3C2-87CF-9D19-4BCF-EE4F0E8B2FA6}\[email protected] *r=^Vn-}f(ZXfeAR6.jiTranslationHidden>BbxH8x=!g(3?!!!_GX=b?
Reg HKLM\SOFTWARE\Classes\CLSID\{6C68E3C2-87CF-9D19-4BCF-EE4F0E8B2FA6}\[email protected] both
Reg HKLM\SOFTWARE\Classes\CLSID\{6C68E3C2-87CF-9D19-4BCF-EE4F0E8B2FA6}\[email protected] ITIR.DefWordSink.5.2
Reg HKLM\SOFTWARE\Classes\CLSID\{EA07B874-F404-0975-0E56-7458120EC520}\[email protected] C:\WINDOWS\system32\msi.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{EA07B874-F404-0975-0E56-7458120EC520}\[email protected] Apartment
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b\[email protected]\ö\x90|aö\x90|

---- EOF - GMER 1.0.15 ----
  • 0

#6
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hi princessmimi,

Step 1

NOTE: This fix is custom made for this system only and for current system state! Don't try to run it on another system!

Please close all running programs and Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    SRV - File not found [Auto | Stopped] -- -- (Winsys32)
    DRV - [2004/02/22 00:27:05 | 000,015,872 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\Mimi II\Local Settings\Temp\krdpdre.sys -- (krdpdre)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKCU..\Run: [UtilEventVdm] rundll32.exe "C:\Documents and Settings\Mimi II\Local Settings\Application Data\xpAuthenticationRpl\UtilEventVdm.dll",oleMobileTray MSNcfgNotifier File not found
    O33 - MountPoints2\{038ec433-a4f2-11e0-96a2-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{038ec433-a4f2-11e0-96a2-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{038ec433-a4f2-11e0-96a2-00038a000015}\Shell\AutoRun\command - "" = F:\Autorun.exe
    O33 - MountPoints2\{2615f4ef-7bac-11df-9342-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{2615f4ef-7bac-11df-9342-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{2615f4ef-7bac-11df-9342-00038a000015}\Shell\AutoRun\command - "" = F:\autorun.exe
    O33 - MountPoints2\{6fc80b2e-3b23-11de-8f74-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{6fc80b2e-3b23-11de-8f74-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{6fc80b2e-3b23-11de-8f74-00038a000015}\Shell\AutoRun\command - "" = F:\S3\Autorun.exe
    O33 - MountPoints2\{b4e67a7e-4463-11dd-8de2-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{b4e67a7e-4463-11dd-8de2-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{b4e67a7e-4463-11dd-8de2-00038a000015}\Shell\AutoRun\command - "" = F:\autorun.exe
    O33 - MountPoints2\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\Shell\AutoRun\command - "" = F:\Autorun.exe
    O33 - MountPoints2\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\Shell\AutoRun\command - "" = F:\_AUTORUN\AUTORUN.EXE
    O33 - MountPoints2\{ebf1aea6-3e45-11de-8f7b-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{ebf1aea6-3e45-11de-8f7b-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{ebf1aea6-3e45-11de-8f7b-00038a000015}\Shell\AutoRun\command - "" = F:\Autorun.exe

    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post the fix log it produces in your next reply or you can find it in C:\_OTL\MovedFiles

Step 2

Update Malwarebytes and run Quick Scan. Post log after the scan.

Step 3

Please don't forget to include these items in your reply:

  • OTL fix log
  • Malwarebytes log
It would be helpful if you could post each log in separate post
  • 0

#7
princessmimi

princessmimi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Hello! Looks like the startup message has vanished and the infection hasn't...
OTL log first:

All processes killed
========== OTL ==========
Service Winsys32 stopped successfully!
Service Winsys32 deleted successfully!
Service krdpdre stopped successfully!
Service krdpdre deleted successfully!
C:\Documents and Settings\Mimi II\Local Settings\Temp\krdpdre.sys moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\UtilEventVdm deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{038ec433-a4f2-11e0-96a2-00038a000015}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{038ec433-a4f2-11e0-96a2-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{038ec433-a4f2-11e0-96a2-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{038ec433-a4f2-11e0-96a2-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{038ec433-a4f2-11e0-96a2-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{038ec433-a4f2-11e0-96a2-00038a000015}\ not found.
File F:\Autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2615f4ef-7bac-11df-9342-00038a000015}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2615f4ef-7bac-11df-9342-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2615f4ef-7bac-11df-9342-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2615f4ef-7bac-11df-9342-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2615f4ef-7bac-11df-9342-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2615f4ef-7bac-11df-9342-00038a000015}\ not found.
File F:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6fc80b2e-3b23-11de-8f74-00038a000015}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6fc80b2e-3b23-11de-8f74-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6fc80b2e-3b23-11de-8f74-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6fc80b2e-3b23-11de-8f74-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6fc80b2e-3b23-11de-8f74-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6fc80b2e-3b23-11de-8f74-00038a000015}\ not found.
File F:\S3\Autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b4e67a7e-4463-11dd-8de2-00038a000015}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b4e67a7e-4463-11dd-8de2-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b4e67a7e-4463-11dd-8de2-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b4e67a7e-4463-11dd-8de2-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b4e67a7e-4463-11dd-8de2-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b4e67a7e-4463-11dd-8de2-00038a000015}\ not found.
File F:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf4bd92a-a4ba-11e0-96a1-00038a000015}\ not found.
File F:\Autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ccaf5a9e-3ceb-11de-8f78-00038a000015}\ not found.
File F:\_AUTORUN\AUTORUN.EXE not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ebf1aea6-3e45-11de-8f7b-00038a000015}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ebf1aea6-3e45-11de-8f7b-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ebf1aea6-3e45-11de-8f7b-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ebf1aea6-3e45-11de-8f7b-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ebf1aea6-3e45-11de-8f7b-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ebf1aea6-3e45-11de-8f7b-00038a000015}\ not found.
File F:\Autorun.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 599761 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 41 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 4578389 bytes
->Flash cache emptied: 348 bytes

User: Mimi
->Temp folder emptied: 869122176 bytes
->Java cache emptied: 11447240 bytes
->Flash cache emptied: 109843 bytes

User: Mimi II
->Temp folder emptied: 25596038 bytes
->Temporary Internet Files folder emptied: 239202 bytes
->Java cache emptied: 10804 bytes
->FireFox cache emptied: 23738681 bytes
->Flash cache emptied: 7134 bytes

User: NetworkService
->Temp folder emptied: 7900 bytes
->Temporary Internet Files folder emptied: 581192 bytes

User: Owner

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 39138 bytes
%systemroot%\System32 .tmp files removed: 18522695 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4026808 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 224459507 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34398 bytes
RecycleBin emptied: 187813542 bytes

Total Files Cleaned = 1,308.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: Mimi
->Flash cache emptied: 0 bytes

User: Mimi II
->Flash cache emptied: 0 bytes

User: NetworkService

User: Owner

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.29.1 log created on 10152011_104820

Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\0EH1FCA52XJ1UCA5GAES6CA93MAJ2CA6J7IM9CAK67HI1CAK8WC0ZCA4NPYHHCAYZJY5XCA8VSCHGCA134RNTCAHX1LJRCAVAZDTOCA9IR0VXCAH97F5NCAQZPGRDCABI4XM6CA4RUZI8CAHCFASQCA9HED9WCAPGIO2XCAM67XN8 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\3JRWNCA7PMR5QCADDO5TFCA32LENCCAHBSW0CCAA7HWORCAFP92XBCA8CFACBCA50QJA6CA3ET03RCAOKD5G2CAV56OCMCA2J50P0CALZMFPRCATSOT2RCAZ3VDDDCAU8OQMHCAJ0T7RYCAX3P7VFCAG0LMZPCAE59OU4CA9G0ARK not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\541RACAQVYUMXCAE48STTCAA7IS53CA73QS8GCA70DMOWCAA2VQ8KCA61S3U8CALW2WKQCADBWDDWCAVPGB1BCA20Y4LKCAPTRVZ6CAB5CZG3CAP6ERTECA4E34K8CAN91V7HCA9YWOA8CAV9RKDFCAWW5TPSCAJZNKGGCAGWAWMO not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\64A5ZCAN3R8FPCAG0HEBKCAUV87GPCAV8B35LCAAM8EFNCAJPACWBCA11DR60CA4PZ01ZCA5G2SHPCAGL8MNACAFK485OCA48YVYTCAEABYY2CA3KQI00CAFW1JO5CADW0UC8CAGJM2YXCAAFMZZCCA145T4ACAQEHOAHCAW5URG4 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\6CAPA9Y1UCANSLDNLCAELUI6ZCATL2V1ICAGA3DCRCA76I43VCAVVW25FCA744SJQCAX5YG24CAH22NPJCAJTKISBCA4YEI2PCAT1IQ6DCAPAJ0C9CA0D5GI7CA737339CAH47XGQCA37QE6YCA75YRW5CAVOL3X5CAX0GAKA.htm not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\7CAHDGWDACABWQYIGCA0847C1CA385V2ICARQ3EUACAIW0N1NCA795C4ECA08RVDFCACI3E72CAPSS7XVCA3OFFX1CA2CEMWLCAZMO7IRCAUFX7PVCACR1HDSCAY6M8KGCAUHQ4PYCAFUUZ7HCA9TTLQACAZKTC0DCATTC038.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\7I8OUCA3YE2E0CAXECZ0ICA822TY5CAO6GKF3CAFUJFMACAYEAPSXCAF750DJCAPDIT2XCA1FCBVCCA0STJEICAT0697HCA9QTM3KCARA4GY6CAWXY4VHCAROTFIQCAEA00LUCA9QGGK3CAIGH5MACAUQRKT2CA6XFQ1VCASP164X not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\7OP5LCA1C0G7YCA1L4SK6CAS2WD5ACAKL3MKUCA9D4P1JCAYZQ915CAQGFB3FCA2O1WWDCAO3Y4HTCA9CZIB8CAYB2NJ6CA1AR93CCA1H87K0CAPD6U05CAZ78B3DCA5VMJGQCAHB1ZRRCA73H73PCANZ5XGICAIN3CVLCAV81CQL not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\BCAHMSJAVCAKNXSO3CA8R6DIMCAWRA0Q5CAGPTS9ZCAJ5DYAHCAXB8481CAH8R74XCAEXQT9SCALHB9HMCA51MPI1CA6FQU3XCAD33JS3CAU5LIB6CAAY5LJFCAFSV5SSCAUAHIU0CA1ZNPJ4CAQH9CH5CA1CNZM8CA2M7EFW.htm not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\BCS6HCADD0GJ3CAXIQSJBCAIOJGO2CA891B9TCAJWO55XCAQTIWXICA5Y6PVFCAQVQGNFCAF05178CAWYU18SCAA5SIZ0CANL60G0CAOXLNAXCA60CDNACA934WSVCA9CF2KCCAQ1TCNSCAAHOI48CAJ5B1HMCAB0OS6JCANNPY38 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\BKWTOCAHO0BX7CAZDOV41CAMMT416CAPF6C6SCA9Q103YCAQCI4CKCANTU9J4CA0LO88CCA3HS1WOCA23VMPFCALCL52QCAYYRP5NCAYBFD05CACNN1L1CATK3WLECA3LIZB8CA6AR0J7CA7CHZHFCA9UXKNJCAESYMJICARVG1P2 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\DCA33IGE4CAHOEQASCA33LSZRCATZP2R8CAU3VRRQCACUFMRLCAWOLWS8CA5RUGHJCANFMPV5CAE4I4PUCAXP1UE3CAGZABVNCAUITK5PCAC8RVR9CAJDAKKFCAHNK75ECA6CEYKFCA21EDQPCADEZ5O4CA19Y490CA1LF4K5.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\GCAG0VANDCASYAE49CAWI4O3ZCACN8VJXCATS9T1PCAM1NL7MCA90TDGNCA1TCYLJCACGJL3VCASBO4TMCAITFQONCA25VZ0VCAIP988QCAYPKE68CADMZNH3CACR3Q64CAJ041O3CA08YVRGCA3XU1CTCAYOPWJZCARSY7J5.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\H1NL8CA2ZLNFQCAUXY6UMCA0B83JTCAB4YRPRCA0UT4OZCAI19PCZCA6P1IDRCA0Q1E5XCAP43PCXCA3CV7BTCARZMI0PCARRWSCGCAI11X7PCAV0QSEKCA6XULMVCATHKIUYCAZUJ5KMCAWLNZVDCALF3Z7YCAT1JDP6CA1TRW4F not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\IQ5F8CAYW24K2CA3U2BFPCAW4KH19CAUT8XQICADPHQNYCAU50DZYCA4XXF3CCATUUWR0CAII7JW2CAN56X8SCAZO59YYCAJ3WOJBCAY0RQT8CALV5ZJGCAVVBW2BCACLRAC6CAIVZGO6CAX9LEF5CA6Y78BTCAK4WB0WCA54CMUY not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\J4HWDCA5W7K26CA8MPYJ7CABTKMOJCARK5NFFCANLJ34ICAKR6OIPCA3H1PEUCAMNQQTKCAF8A9TZCAA0SJWWCABB3OW1CA4PDZSZCASSG8IACAY1JX4ACA9TZE6TCAU38UVPCAFL79XDCACGIV54CACP15QNCAW3OG3ZCA027Y7S not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\J7YWZCANKAS85CA5FNEZICAAEGYK3CA5KMIOBCAHGAGURCAPMET3CCA7Q6JG8CAA2PHFPCA31SS3PCA7PSE6OCAOG092TCA44RB0VCAQPJIT8CAJ7PUOYCAV03I2TCAS90SLXCADKXIT3CAU0FFOACAZ6LUMQCA6HPLFTCA4RR5TL not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\JHYDJCAMX1DGXCATB8YM3CA9B50N4CAP0SFTLCA4832XYCA449SWVCATGWWN3CAS798EACA1JGFUZCA76NNH1CA6X9Q1NCA87KWTZCANSKX56CAF0DBX1CAMFOB8TCA4DMPKPCAUP0X7XCA1ER980CAOI1TODCAVTFEQUCAA2XXK8 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\KCA6LYES4CAYPVCK7CA7OMJQSCAEL5AKWCAGXDSGICAIZSQWRCAEKJATACAHW1L4ZCAQ33L74CALDTVTCCAK67GE5CAXQTXZMCAQEDHFHCA46TSILCAF997MVCAO4W11TCA3XP4V6CAHKEVPGCAH3DIDXCA2OE2K8CAAVW30Y.htm not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\SCAP2D3S4CADUICY5CALWGQARCAE7WBSRCAEEUO82CA01P3QBCANM21YFCA67NARQCAH1PBOHCACZJJE4CA4N696BCA82OBX9CAEK2RENCAWYGE6QCAZPPU3PCAZWQ1WNCAZD8596CAH3BLSXCAM18762CAXV78NICAD0BFG8.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\WU0QBCAPDRUTNCAA4MKC4CA00K6G0CAJ7AJYICA1PFE05CAB4BVBPCAFLJF1CCA53P04NCAK69F01CA1QVUY2CAC1799CCAX3DG3UCA3JWQ7SCABOQWINCADG54WICAB58D0ICAM5YEF2CA7Y2EKMCA95P3KICAJJD5RFCA4Z35ES not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\RIVI8N79\YCA6FRJ01CAQ1XC1ACA0VNXK9CAGPEYUQCAH0NQN8CABNTSKACA3D8KLHCARUB8Q5CAQ8AV1VCAJFK5HQCAT474M0CA6WFSJICAQLGXU9CAD573C4CAM1QIUICAUJDC4BCAU5AZHLCAH84I6HCAT3ZD6XCAIVTNHJCAJIS9SV.htm not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\2TZX5CAIY240GCA3NEMCKCASM8H3XCAUZHQA2CAZ91E1LCAQBIYPQCA2NL57WCAME0RZ9CATJOPOOCAUIQMJ8CA60GHO4CAKQKN7YCABWO3X1CAQ79RA8CAU4GNQ8CANSTRVBCAVDGK4WCAPJ2N1CCAA0FA99CA7RR906CA9REV3N not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\4Y09XCAWQURW7CANAX4MDCAKMB47BCA87DIH9CAFTXQ4UCAC4PDY8CA77HFXDCAH1TFSPCADOB9OSCALHSQQNCADKBXS7CAJFB60MCAR0ZYXZCASS9GD9CAK4IH04CAP5F8QZCABIJR3QCAOO2YU3CAL0RZOLCAU9L0W7CA2HH5MD not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\58G85CAJH8HIUCA2EC9QHCAYWDQ8FCAWFXDI0CAQ616EZCAV9GYZ5CAOZUCFECAW3NZZSCA07C8F6CAJXR425CAE7D6AQCA16BP2PCAM5HKESCABQR4UJCAPYR2T7CAL73W8ECA78130ICA0CC03PCAPFCIHECA7579PPCAOU08SS not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\6G2R8CALU8ANOCAPRMB6KCA9MYTMACA8YRS7TCAMPN03KCAE3RT9MCAT20Z5ECAI0S5U1CA065ZOUCA0L276UCAUXQAMRCA0P5Z3TCA3I70HJCA44GMRBCA0W65UBCAA05WSQCAH3FQN0CALPXI65CAO95KW7CASYB7C8CA0E7VQG not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\7E57NCA9R4462CAMZ8M5QCAAXZMDCCARHVCLECAZN84JBCAA4PM1OCAQG7HU5CADE1PEJCAD8CZLDCAA3JZFOCAZGG0N6CAWUF2HICAAMG2TYCAF5NF7UCAZ6SNOSCADYN4AHCAL938SLCACCBIG3CA9SUV8YCADFMN7ICAQXPBIQ not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\EOHV1CAOV3PA1CACKRROHCAAGT50DCAYST4ETCAJQU4BOCAJL6ICFCAANCUR8CAOC0SHGCAWLRWI0CANQTXWFCA81HVPLCAQUMUI3CAYKST9KCATLWWJZCAG4S0A0CAB3OMPACA99ZHZGCASO5XPVCAHZSEMFCAUNPVJHCA3RLQPQ not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\H2EPBCAZ059RBCADFDOMBCASD8CWWCAQBFNVMCA7X9B2RCAKEAFU8CAKW4NFTCANFA8AXCA93P31TCA4CDW6HCA7V7YMNCADLF7QRCAVCFI33CAJER4D3CAHZBPIXCASUSQ53CA00HW33CA7GCQEQCAM350ETCATTRDPPCATSIGSG not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\HON01CAUORDIWCAV6TX3HCAEWT429CATH5P2KCA2893M2CA3WY3R8CAHW32XRCA6GYJZVCAIM6C1RCAZLB9JBCA7M0T1GCAOZ66YICA1Q2O9FCABNNLQGCA233ET6CAGOG58PCAGWTAGZCAPF0JBFCATHOQH6CAVR7U12CAT4SYPH not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\KCA7RTYRBCA8IHZMLCA2I1YYYCA7B46FKCAOLEGSTCAJPCH8ACA4ELNL7CA23MW95CABIUNQACAGHMAPSCA9AXAC7CAMLKMN0CANTEGRZCASRSJ63CAAYHTDHCAUIWCLCCA25JF35CAK19L1ICA4L6NVPCAG1QIS6CACI3E5J.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\LZSEDCALF79DVCAKQ4FZWCA8U0XMHCABWIPUQCAX3QBN0CAS0KDB8CAVRN19YCAL13UHCCAFXORTBCAXAIFLHCAOLQTAACACCMMKSCAATB8OXCAJEPN5ACA266ML1CA1ERHESCA73JXG0CALKCIJACAZQ5WRVCA0SZSDECA2GLSYL not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\M5QAZCASXZQM9CAAABD8BCAOGSO5PCAN28AYRCAJW8QBFCA096CXNCAKOVM5SCA9ONQ6KCAFIROWLCAC5PUS7CAUDUDO1CADFN1H0CAX254UWCA465SLDCAK71MWUCAN2K6V5CA8TET5ECAWY55KLCAXS81OVCAYCXWG1CA6LHKU2 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\MW9BUCAC5V9AXCA8GLBKRCACPGHXTCAFFA9LFCAW6D3ZCCAO8QMPPCAEJ22MMCA3WAYA1CAOU09D0CABAS01ICA13QW93CA7X9Z2XCAXQ36QQCA6ST731CAX2R6TACA3FZYH3CAEMQLVDCA3XMCLICAJMUULOCAX90S17CAUYX5IV not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\OPNCXCAAVSD33CAPWRZX4CA9HQJ8XCAIM9MTLCA6D842UCA2OL0HICACYYJP5CASD58IOCAVF2ZD2CA4G8ULXCAOXB8SKCA4JEOVCCAUGZCHHCA1HAA2ECAX9UFPOCAS66MQ0CAWZZWTRCA158WJYCA5EV11YCAJ6AKIWCA9QQWGU not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\P8SQRCAIBM0LZCA2LSJZMCAVBKUT1CA26SHTUCA071RQDCAUNJOTMCAFY92NNCATP9OC0CAUVBQFNCACXTV8VCAGIDWM1CALMD640CA2ZEITNCA4AMVT6CA10MCIUCA1TRZU0CAEW0I1QCAAPXLBACA4AR5UJCA38HC6YCAXKPF26 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\QM5AXCAI13MC8CA22FB7TCAPT92G0CAHP2U22CA6YUK17CACA4MLQCAM52EULCADUK21KCAP119ACCAGZFHFACARKDWJ7CAXB2T71CAO1IGL4CAE18BKWCALXJDNYCAGEKS1PCALTO8N6CAVTJK1ICAZHFHSRCAW02CBDCAWY0RSK not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\SHKOHCAEHDY9WCAE9DRJGCAPROW4YCAFF66FJCA0YXST0CA4Y9GZ9CAE1VTTNCATFQHH9CAVDSOFWCAU8HWCSCAAIAFROCAN5QPK9CAR2Y19ECABVS8AFCAB1YV63CA6U69ZHCA5G7BRACA4U4NW6CADEUQO7CAKSBZESCAD0YR7D not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\T6FW8CAFDZ2A9CA8SKOKDCALCJIXOCA23Q0ALCA3S9ILPCAWVHL0ZCA54PLTECAOPIU0UCA1I4YGGCAYVYWUHCA6TAQBRCAQYQX6NCAR880XFCAFP25Q0CARPXF02CASJ9VMVCANU1UVCCA3XSOCACAEB22X6CAQI96E3CAW0NGT1 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\VSG49CADIGZ9TCAGJFO1RCAXYIGS8CA70QVTNCAY15LA9CAIAPB6LCAPJIE56CAIKM0XDCAN8QFNRCAK6AKCHCAUCG43UCAIDMCY6CAKRKAS1CAXLZ44SCASVX033CA0KZ90QCAG8Q8UACACQU6BFCAPYON90CA5OXXLZCAT5VOJX not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\X18TRCAW9LRPWCAM0MWNRCAMRDAGICA4NUWTMCATO0XV1CA16I1BHCA5XUIPQCA1D55EQCASA7M2HCANA52Q3CAEA6M1FCAJ6419OCAIZU3ZGCAWAOZHBCATO8CH5CAH70V1LCAC805TOCADH6AA7CAQDHEK8CA1QE0A7CA2ODNMR not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\YVZ40CA7EISQXCAOS2TASCA1J4AFPCAGL24MACAJ8RYYQCAN41H17CAOOKCY8CATZHRHECABSUY9NCA0MER5WCANVND6YCAOSACCICAV0RNMMCACCFJOKCAA5QI21CA14AEIBCAOGBG0ZCAVCKY1TCAT4U6FFCAV5ZLG0CA2BUJW3 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\LWNNWLGF\ZH1G3CAZU21G4CAWKLYROCALVIQX8CAHRYW33CA1M09OHCAWEHE4NCAOTS091CAWEX9Y7CAEBXBQCCAJAVQWMCAVSIDU8CA500ZUMCA512Q0SCANBHPVGCAI2BHA7CAGMHGJTCAFKA59JCASHL3AICA1SPH16CA2IFDCYCA4ZBWDN not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\05AIMCA8EM57ICAOS6P1ACA6VPND7CARZH3TECA3IP55PCAFP82SZCAIGPLX7CAB6O1LMCALZYDCLCA95Z9VOCAVB4J1QCAC3EF0CCA0DDFY3CAXWUCYLCAHHMEGQCA6HYDC5CAWWHRMUCA29X2RICAD7FBOOCAFSRXURCA710EBY not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\0CAOA8I7MCASI9T6ICA09LUT7CAO9SA3BCAHANV2QCA55R5TGCA78YOHXCAVPT5DCCA8KC30YCA6K0OH6CA20PV1RCAQZXKHICA6EM8CMCA1U5ISOCALNZ6VNCAHY2R35CA69X7CCCAL63QYUCADIETIFCAU218T2CAU52IS8.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\0XM1FCADWG9ZXCALKIYA6CAMXWHD7CA0P2DWACAY8MHMHCA0PLKH4CA735CWMCAOWB4G2CA0YBD3ACAH670D3CA9Z5YRFCAGVHDLPCAD4ZF9VCAGTIYLTCA1LGLH9CATLSHNWCANSXMGWCA0GB0D7CADQESB3CAWNPRDPCA9GZY5K not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\11MA1CAVSGJVVCAW0ZAA4CAI7SLDECABEY6K3CAHMU17XCAOJE41BCAWZ4XCECAYZII3QCA921PGVCAMK1KT7CAQ9QFHACAR4Y4XVCA25RVSOCAG7IKTECAXCGY06CAM4KKN8CAU28U6ACAP0CD0UCA7T0HORCAMWB0IICAX7GYRC not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\5MPBBCA1A71ICCAEWP4IJCAAZT5YYCAWWZJCFCAHW52QECAM80FFTCA72AEKICAKJK7BHCA3Z4QN8CAT1ADLUCAOEZK2VCALOTPGSCA8L3LVRCA9OE3QJCAYGQ4GOCA6C3A1XCAWBZ15ACAPHKDLHCASHEGPDCAXCWLCDCATGTJWH not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\7J44DCARKQ8HSCA5RN9RECAE1B3JRCA73X0YECAOCVM8ECA0XGG5PCAL51TVJCA0ZTXV5CAH3QTUFCAOUX3M5CAOVIMY6CAFB2OTFCAPBB7NICA46MX0WCATBIQVNCABEI4E8CAWS8D3KCAXEA63SCAMMD2JFCAAWPZAHCAR88Z6I not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\BASTECAMVM89CCAQ3RGHPCA2173ITCAK3MB4NCAJSKFUGCARYFTK1CAE8EIENCAHYZ39UCA6C4JAJCAKSUIG3CADFY1M9CADVZYKWCA33P0AJCAYDQC1TCALWK2U4CAK68OGACAM10SD9CA7QGWQQCAUCORMFCAOO4QS4CA3BOWS9 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\E2UEMCA965EXQCARSVS1ZCA842NCLCAXG3UGICAGCIY4MCAXU897HCA2N4KHACA6NV034CA6KJGJYCACRZ5OVCAS7J8K7CAVYEIH3CA5HLJ0NCAP2Z0G4CANNVKVUCAUYY0CSCA9THMW5CAM4D3JYCA8LXT7CCA1ZOOCNCAU0W0P3 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\EEYPOCAYNCCT9CADE8Q4ACAC3HQP2CAVLW22QCAO11C58CAOBP3F3CAO0A8YKCAYL0YRQCA7F5U93CARQEZ75CAEE7F91CAF6PBW4CAKXA0I9CAUVPDMRCA408LN3CATDHV6FCA8ANXKQCAWGEOHZCAYVV2KECAT4O3YYCAALVKTE not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\HCA0FG92DCA8F0VKGCAQ4191ECACAQZBMCA2LA8E4CANBMJM6CA0V4YLRCAZ7TKPRCAT3J3B6CASOS7GLCA48M4KGCAJE743GCAP0UJN7CA7KWUOYCAPJK93JCA6XJHPXCADKD87ECAYFG2YHCA6726EJCAOPQ1GZCA25N2T9.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\K2FV3CACT1H72CA9UVLPTCAVMO9KYCAOBY54XCA7EPAB6CAI7B6WCCAGSEH6KCAQIDMQ8CAP7ZFB2CAZ4BMR6CAAMXW3ICAY4L74YCASZIWUCCAIOJJMUCAZ5OCAWCAQ3VOEUCA3MW3JGCAN1Y8Q3CAF41QMRCA7DZA0LCAO2D1LN not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\MCA3DNXS6CAZUHA8PCA9NSC4YCA5DUT2NCAN2HB31CA9JBRYBCAH5UITDCAITO09BCAG93HFPCA81HDYVCA1NDBY9CAJX9H2DCADDBYNYCA748NZUCAQRRF3CCAVA4Y8KCAG3294UCAVXJHMACAIV285RCAH9L7JDCAGYRO95.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\NCAFI8MWUCA7HIFN6CA55VGUNCA00VQ8DCACIAA8KCA1TV4XECAJU90RJCAJK8QECCA6JSN20CA113Q0HCAF8GG1SCAMD6Z43CAAWFY3YCA01G8O5CABKJWJECAB2D9DQCARNCMYCCAK5IT2HCAB4S48ACAGPI384CA8LDW5T.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\ND6Y8CAC2GKC8CAWDQ0YECA6ZBCHKCA42Y07UCAQ0TSOFCAUPVZYBCA262EK4CAPHF4SBCA70IKE9CA0I2FXTCALL9EP8CA7UXG9RCAA406AJCA8QY7Q3CAC6ZA3WCAGPS859CAFWOPXUCA9N74VWCA99ACDCCA5X3V5RCAQU53AY not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\PCAGTH8BXCAZNBK5OCA3GB801CAONBLTLCAWD10BACAO5WNUHCAOW5XS5CAKO92LFCAXY9R97CA3S5BN4CAGRKHFCCA8UCKJBCA6MHKXSCAUZPL5VCAWA17QFCAC6HNPACAOQYT69CAL4OGTWCAQLV0KVCAXPAZFOCAOW8YTA.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\SCA24F2SLCA0Y8919CA159SUZCAJL99JVCAS50P7CCATXO51XCA5S09FNCA7ZBI4LCAQ0A0QXCAN11PMHCARLAJ14CAOG272LCAJ1F3WACA3QK3N1CA0PFBCUCAYRYSM2CAMTX5LNCAE7UR83CA1AGEY9CAIBPL5BCAFY643Z.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\U1DP2CAFHVYJZCA0LB7BZCA80Z0EICAHSNHNTCA609YHQCA04X901CAOEJQ75CA3HBX9ECA2P4TGRCAKZK36QCA8FE6C6CA4I1O8VCASP5PL7CAEORWQCCA6OUQ22CA9XHQ94CAYWM23TCA3J47SKCAEG287VCAK78VZLCAVC3GO8 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\U7ZCPCAKHE7Y5CAC4IOIQCAXQDJP7CAW29V2XCATE4PTLCA5YXE63CAKTEECSCA0UFHSUCA8TES22CASN2BVZCALFIOH2CA10K5JZCAKMPFPJCAAWQ0M1CA4KL707CAUFVJCJCAJX7AYBCA0DRYCICAUN8J4ZCAJPZ8H5CAFLRCEH not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\Y684VCAVALG26CA8NNO0JCASEKY5NCAL8MHQ4CA264J1GCAQAUE2PCA3F5TF2CA0GOLYSCAP966L5CAZZZWOBCATUO3Q6CAZL0CXJCAE7O9SOCA49WFR7CAKT62X9CAGGTLQQCA08HO44CAELGDXVCAUP8W7GCAVZATSUCAWI10AN not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\6XUR11CO\YZW7YCAOASRTHCABKCTUICA5Y313CCA6CIEYNCAPRIX28CA7TEM8ZCAGTXVS1CAZKT1QYCAM2ZWGNCARDRNXXCAKRSSZ9CAUP3ZUDCAFGODLTCA1RHDG0CA78E80CCASDQ9IECAXI29GZCAX3BACFCAMMKDXCCASDBH9VCA9RDCSI not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\0Z8ZKLB9\37IXFCA5202YTCANICZXZCABDYSXVCAVIZ172CAP1EVD7CABK9D12CAW6CFGYCASZ19GGCAK6J83LCA6OYFL0CAZN4NWGCAKEHP9ZCAG1FQXTCAX54QA9CAEC5B39CABCXIVZCAAWH1BSCACWQHIFCAO26DQFCA1BGMKVCA2J8RK3 not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\0Z8ZKLB9\3CA7HDEYRCAPJFEBDCAGIQ6HLCAX6NZBHCAJW8JDQCABM8MMDCAUZBC6NCA0GKUH0CASMXWHUCAADD01SCAAMVK95CA3FKDR0CAJ72GEMCAUI4VRVCA9S02S8CAULKDVQCAH4F1GECA0QD0CACAUIWMJUCAIRZRNCCA2RC0EZ.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\0Z8ZKLB9\4UQX7CAU87DN3CAC8TE8OCA8X0J56CANJ4PHUCA54IG0LCA6S1I5VCASF2A4GCAFJNKU7CA4TYBATCA2M9CVICAOO0T04CADGIT3VCA2XI76ACAH9NK8HCAGIY07DCA36OR2HCAWMYESCCAQVAOOFCAUWPBHXCA6JUXTVCA475RUP not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\0Z8ZKLB9\5EY67CA1660NKCA2WTNCTCABHGQBZCAGPQYZYCACEBXI6CA3S8BIDCAXNRHV7CA6VAJVMCA4J2XM2CA8O7KWSCAOY8XNACAQZDRRACAVAPEUOCA6L1DX6CA007SC6CA05NOGXCAJDK179CA4JRZGLCABJQWFICAGZOV2NCAN704RD not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\0Z8ZKLB9\HCA6RDVW7CAN7H460CAND1B2OCAA7TG7MCAWQ35FICAFBBNO0CASCW4UNCAFLTL2JCAXAH62CCAQT79RLCAKJSJ9BCA7M9AEMCA391VF5CAB9WVDKCAS4417VCAEEOPE9CAZO6G9CCA0B4QDRCAC6RCHNCABUG6HLCAXADHWN.jpg not found!
File\Folder C:\Documents and Settings\Mimi II\Local Settings\Temp\Temporary Internet Files\Content.IE5\0Z8ZKLB9\PWAVZCACMV75ZCAEL1WTJCAO66Q0BCAWZD8L5CA24PJ4TCAX0FR3DCA406934CA81IQTHCA3W1MC0CAESYA6BCAX3CIIJCAJYFQ4TCAJ5CRGICASVG2GACA5EB4WTCAXV3JP1CAHU8YYMCA5M7OR7CAR2F8UJCA74ZXQBCA7GXXKZ not found!

Registry entries deleted on Reboot...
  • 0

#8
princessmimi

princessmimi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Malware Bytes log (in the original program, the Registry Data has Chinese instead of question marks... log didn't note it, but I did remove it successfully, that is for that time, since it's probably back upon restart; thought I'd throw that in just in case) :

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7929

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

10/15/2011 11:15:38 AM
mbam-log-2011-10-15 (11-15-30).txt

Scan type: Quick scan
Objects scanned: 209336
Time elapsed: 18 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (????????) Good: (regedit.exe "%1") -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Edited by princessmimi, 15 October 2011 - 03:34 PM.

  • 0

#9
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hi princessmimi,

How is your system now? Problems?

  • Run OTL.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open notepad window. OTL.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file, and post it with your next reply.

  • 0

#10
princessmimi

princessmimi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Hello!
The startup message is gone for sure, but my computer is still coming back infected upon startup/restart and every time it scans and removes the infection, I get CHKDSK upon restart, which is a little annoying. Otherwise, the computer is running fine (and I think I gained a good 1.5GB with that temp folder deletion. :) Here's the OTL log:

OTL logfile created on: 10/16/2011 10:24:56 AM - Run 2
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Mimi II\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.07 Mb Total Physical Memory | 131.08 Mb Available Physical Memory | 12.82% Memory free
2.40 Gb Paging File | 1.52 Gb Available in Paging File | 63.47% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.68 Gb Total Space | 9.81 Gb Free Space | 13.68% Space Free | Partition Type: NTFS

Computer Name: D3T0R661 | User Name: Mimi II | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/10/16 10:21:34 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
PRC - [2011/10/13 19:35:52 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mimi II\Desktop\OTL.exe
PRC - [2011/09/28 12:02:13 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\App\Firefox\firefox.exe
PRC - [2011/09/13 10:12:06 | 002,076,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2011/05/21 16:46:58 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2011/03/21 14:56:16 | 001,230,704 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/11/24 10:40:25 | 000,725,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/09/20 10:28:11 | 000,621,920 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/06/22 10:27:59 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/06/22 10:27:55 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/06/22 10:27:44 | 005,897,808 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/06/22 10:27:44 | 000,596,560 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2010/06/22 10:27:00 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/06/22 10:26:59 | 000,842,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2009/09/14 11:07:30 | 000,472,112 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Pure Networks\Network Magic\nmapp.exe
PRC - [2009/07/07 14:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
PRC - [2009/03/28 11:34:20 | 000,153,352 | ---- | M] (PortableApps.com) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\FirefoxPortable.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/11/06 11:08:10 | 000,397,312 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
PRC - [2006/09/29 11:55:14 | 000,057,344 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
PRC - [2004/02/25 10:04:16 | 001,123,440 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
PRC - [2001/11/27 09:10:00 | 000,106,560 | ---- | M] (WinZip Computing, Inc.) -- C:\Program Files\WinZip\WZQKPICK.EXE


========== Modules (No Company Name) ==========

MOD - [2011/10/13 19:32:06 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll
MOD - [2011/10/13 19:31:56 | 011,800,576 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll
MOD - [2011/10/13 11:14:27 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
MOD - [2011/10/13 11:13:28 | 000,025,600 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
MOD - [2011/10/13 11:12:03 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
MOD - [2011/10/13 11:11:55 | 012,430,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
MOD - [2011/10/13 11:11:37 | 001,587,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll
MOD - [2011/10/13 11:08:33 | 007,950,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
MOD - [2011/10/13 11:08:06 | 011,490,816 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011/09/28 12:02:14 | 001,015,256 | ---- | M] () -- C:\Program Files\Mozilla Firefox\FirefoxPortable\App\Firefox\js3250.dll
MOD - [2011/07/06 19:01:53 | 000,011,776 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Runtime\2.0.3693.42552__90ba9c70f846762e\CLI.Caste.HydraVision.Runtime.dll
MOD - [2011/07/06 19:01:53 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Shared\2.0.3693.42552__90ba9c70f846762e\CLI.Caste.HydraVision.Shared.dll
MOD - [2011/07/06 19:01:53 | 000,007,680 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Wizard\2.0.3693.42556__90ba9c70f846762e\CLI.Caste.HydraVision.Wizard.dll
MOD - [2011/07/06 19:01:53 | 000,007,680 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Dashboard\2.0.3693.42552__90ba9c70f846762e\CLI.Caste.HydraVision.Dashboard.dll
MOD - [2011/07/06 19:01:52 | 000,290,816 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3693.42442__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:52 | 000,204,800 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3693.42461__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:52 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3693.42456__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:52 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3693.42451__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:51 | 001,728,512 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3693.42460__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:51 | 000,692,224 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3693.42508__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:51 | 000,491,520 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3693.42537__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:51 | 000,364,544 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3693.42522__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:51 | 000,077,824 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3693.42517__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:51 | 000,069,632 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3693.42499__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:51 | 000,036,864 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3693.42486__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:50 | 000,139,264 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3693.42537__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:50 | 000,106,496 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3693.42461__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:50 | 000,073,728 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3693.42450__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:49 | 000,364,544 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3693.42504__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:49 | 000,094,208 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3693.42504__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:49 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3693.42460__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:48 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3693.42503__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:45 | 000,811,008 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3693.42488__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:45 | 000,405,504 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3693.42512__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2011/07/06 19:01:45 | 000,081,920 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3693.42487__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:44 | 000,712,704 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3693.42452__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:44 | 000,589,824 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3693.42462__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:44 | 000,225,280 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3693.42462__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:44 | 000,126,976 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3693.42496__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:44 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3693.42466__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:44 | 000,036,864 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3693.42496__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:43 | 000,798,720 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3693.42518__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:43 | 000,450,560 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3693.42482__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:43 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3693.42497__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:42 | 000,675,840 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3693.42500__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:42 | 000,438,272 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3693.42487__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2011/07/06 19:01:42 | 000,065,536 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3693.42486__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:42 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3693.42487__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2011/07/06 19:01:41 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3309.28617__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3309.28608__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3309.28629__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3309.28645__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3309.28647__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3309.28627__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2011/07/06 19:01:41 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3309.28647__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2011/07/06 19:01:40 | 000,007,168 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2011/07/06 19:01:39 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3309.28601__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2011/07/06 19:01:39 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3309.28603__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2011/07/06 19:01:39 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3309.28630__90ba9c70f846762e\DEM.OS.I0602.dll
MOD - [2011/07/06 19:01:39 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3309.28626__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2011/07/06 19:01:39 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.OS\2.0.3309.28645__90ba9c70f846762e\DEM.OS.dll
MOD - [2011/07/06 19:01:39 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll
MOD - [2011/07/06 19:01:38 | 000,073,728 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3309.28604__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2011/07/06 19:01:38 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2011/07/06 19:01:38 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3309.28669__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2011/07/06 19:01:38 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3309.28620__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2011/07/06 19:01:38 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3309.28617__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2011/07/06 19:01:38 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3309.28611__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2011/07/06 19:01:38 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.3309.28630__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2011/07/06 19:01:38 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2011/07/06 19:01:38 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3309.28617__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2011/07/06 19:01:37 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3309.28618__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2011/07/06 19:01:37 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.3309.28631__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll
MOD - [2011/07/06 19:01:37 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3309.28631__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2011/07/06 19:01:37 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3309.28630__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2011/07/06 19:01:36 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3309.28644__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2011/07/06 19:01:35 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3309.28636__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,065,536 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3309.28636__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3309.28634__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,049,152 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3309.28634__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3309.28636__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3309.28624__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3309.28632__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3309.28630__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3309.28635__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2011/07/06 19:01:33 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3309.28630__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2011/07/06 19:01:32 | 000,503,808 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ResourceManagement.Foundation.Implementation\2.0.3693.42564__90ba9c70f846762e\ResourceManagement.Foundation.Implementation.dll
MOD - [2011/07/06 19:01:32 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3309.28634__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2011/07/06 19:01:32 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3693.42545__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2011/07/06 19:01:32 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3309.28627__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2011/07/06 19:01:32 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll
MOD - [2011/07/06 19:01:32 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.3309.28626__90ba9c70f846762e\APM.Foundation.dll
MOD - [2011/07/06 19:01:32 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3309.28617__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2011/07/06 19:01:31 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3309.28612__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll
MOD - [2011/07/06 19:01:31 | 000,014,848 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll
MOD - [2011/07/06 19:01:31 | 000,013,312 | ---- | M] () -- C:\WINDOWS\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll
MOD - [2011/07/06 19:01:31 | 000,007,168 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3693.42437__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2011/07/06 19:01:30 | 000,544,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3693.42525__90ba9c70f846762e\CLI.Component.Systemtray.dll
MOD - [2011/07/06 19:01:30 | 000,405,504 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3693.42455__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2011/07/06 19:01:30 | 000,106,496 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3693.42531__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2011/07/06 19:01:30 | 000,081,920 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3693.42440__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2011/07/06 19:01:30 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3693.42530__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2011/07/06 19:01:30 | 000,057,344 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3693.42441__90ba9c70f846762e\CLI.Component.SkinFactory.dll
MOD - [2011/07/06 19:01:30 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3309.28628__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2011/07/06 19:01:30 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3309.28608__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2011/07/06 19:01:30 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3309.28614__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2011/07/06 19:01:30 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3309.28627__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2011/07/06 19:01:30 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3309.28626__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2011/07/06 19:01:28 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3309.28624__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2011/07/06 19:01:26 | 001,142,784 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3693.42446__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2011/07/06 19:01:25 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3309.28621__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2011/07/06 19:01:25 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3309.28637__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2011/07/06 19:01:24 | 000,081,920 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ATIDEMOS\2.0.3693.42440__90ba9c70f846762e\ATIDEMOS.dll
MOD - [2011/07/06 19:01:24 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2011/07/06 19:01:24 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3693.42531__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2011/07/06 19:01:23 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3693.42439__90ba9c70f846762e\APM.Server.dll
MOD - [2011/07/06 19:01:23 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3693.42438__90ba9c70f846762e\AEM.Server.dll
MOD - [2011/03/21 14:57:34 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/03/21 14:56:16 | 001,230,704 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/02/20 17:21:08 | 000,327,680 | ---- | M] () -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]\voikko\WINNT_x86-msvc\libvoikko-1.dll
MOD - [2010/08/10 00:01:06 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2009/11/24 13:36:36 | 000,016,384 | R--- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2009/11/04 11:57:14 | 000,057,344 | ---- | M] () -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\boost_thread-vc71-mt-1_32.dll
MOD - [2009/11/04 11:57:13 | 000,077,824 | ---- | M] () -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\boost_log-vc71-mt-1_32.dll
MOD - [2009/07/13 17:37:04 | 000,152,112 | ---- | M] () -- C:\Program Files\Common Files\Pure Networks Shared\Platform\CAntiVirusCOM.dll
MOD - [2009/07/13 17:37:04 | 000,098,304 | ---- | M] () -- C:\Program Files\Common Files\Pure Networks Shared\Platform\CFirewallCOM.dll
MOD - [2004/06/18 11:29:44 | 000,007,680 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\dlbtmcro.dll
MOD - [2004/06/18 11:27:50 | 000,065,536 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\JetScan.dll
MOD - [2004/06/18 11:26:42 | 000,065,536 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\JetImage.dll
MOD - [2004/06/18 11:26:18 | 000,028,672 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\JetPDF.dll
MOD - [2004/06/18 11:25:56 | 000,036,864 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\JetFunc.dll
MOD - [2004/03/29 12:45:52 | 000,075,264 | ---- | M] () -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBTPP5C.DLL
MOD - [2004/03/10 10:36:24 | 000,061,440 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 922\ConvDIB.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (winsocket)
SRV - File not found [Auto | Stopped] -- -- (RPC Security)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/10/16 10:21:34 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
SRV - [2010/06/22 10:27:55 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/06/22 10:27:44 | 005,897,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2008/04/13 20:12:02 | 000,105,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\p2pgasvc.dll -- (p2pgasvc)
SRV - [2008/04/13 20:11:55 | 000,035,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\SYSTEM32\iprip.dll -- (Iprip)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2004/03/16 16:33:24 | 000,421,888 | ---- | M] (Dell) [On_Demand | Stopped] -- C:\WINDOWS\System32\dlbtcoms.exe -- (dlbt_device)
SRV - [2004/02/25 10:04:16 | 001,123,440 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe -- (AOL ACS)


========== Driver Services (SafeList) ==========

DRV - [2011/09/13 10:11:56 | 000,029,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2011/05/05 10:28:03 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/06/22 10:27:48 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys -- (AVGIDSFilterxpx)
DRV - [2010/06/22 10:27:48 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys -- (AVGIDSShimxpx)
DRV - [2010/06/22 10:27:48 | 000,025,168 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\AVGIDSxx.sys -- (AVGIDSErHrxpx)
DRV - [2010/06/22 10:27:47 | 000,122,448 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys -- (AVGIDSDriverxpx)
DRV - [2010/06/22 10:27:02 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/03/05 11:13:41 | 000,052,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\System32\Drivers\avgrkx86.sys -- (AvgRkx86)
DRV - [2010/02/11 08:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys -- (Tcpip6)
DRV - [2010/02/11 03:38:10 | 003,565,056 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2010/01/01 14:07:51 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\atksgt.sys -- (atksgt)
DRV - [2010/01/01 14:07:50 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\lirsgt.sys -- (lirsgt)
DRV - [2009/07/07 14:48:44 | 000,026,672 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\purendis.sys -- (purendis)
DRV - [2009/07/07 14:48:44 | 000,025,392 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\pnarp.sys -- (pnarp)
DRV - [2008/06/27 12:09:32 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2007/08/01 22:47:26 | 000,102,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys -- (tmcomm)
DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/09/05 12:03:16 | 000,003,968 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys -- (AvgAsCln)
DRV - [2005/11/21 01:48:21 | 000,016,512 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ASPI32.SYS -- (ASPI32)
DRV - [2004/06/16 00:52:40 | 000,061,157 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys -- (IntelC53)
DRV - [2004/03/06 00:15:34 | 000,647,929 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys -- (IntelC52)
DRV - [2004/03/06 00:14:42 | 001,233,525 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys -- (IntelC51)
DRV - [2004/03/06 00:13:38 | 000,037,048 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys -- (mohfilt)
DRV - [2003/08/28 20:58:40 | 000,004,272 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\bvrp_pci.sys -- (bvrp_pci)
DRV - [2003/06/13 10:53:06 | 000,015,232 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdrbsvsd.sys -- (cdrbsvsd)
DRV - [2003/01/10 18:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2002/11/08 15:45:06 | 000,017,217 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.hotmail.com"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.647: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.647: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2011/09/13 10:19:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/05/21 16:47:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/23 00:28:29 | 000,134,104 | ---- | M] (Mozilla Foundation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/28 12:06:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape 7.2\Extensions\\Components: C:\Program Files\Netscape\Netscape\Components [2011/07/27 18:16:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape 7.2\Extensions\\Plugins: C:\Program Files\Netscape\Netscape\Plugins [2011/07/01 10:28:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape Navigator 9.0.0.6\extensions\\Components: C:\Program Files\Netscape\Navigator 9\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape Navigator 9.0.0.6\extensions\\Plugins: C:\Program Files\Netscape\Navigator 9\plugins [2011/03/08 19:33:17 | 000,000,000 | ---D | M]

[2011/10/14 11:45:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mimi II\Application Data\Mozilla\Extensions
[2011/09/28 12:06:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/10 18:17:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/11 18:08:55 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/14 11:33:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/11 11:27:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/11 11:24:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/10 18:19:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2009/04/17 10:22:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\App\Firefox\extensions
[2011/09/28 12:02:19 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\App\Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/10/13 19:32:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions
[2010/07/13 11:27:20 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/30 21:38:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\{b80f591e-fe9a-46cf-a13e-180377240586}
[2010/11/17 19:05:10 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/10/12 19:12:29 | 000,000,000 | ---D | M] (Canadian English Dictionary) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2010/12/30 21:38:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/03/04 11:10:35 | 000,000,000 | ---D | M] (Suomen kielen oikoluku) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/10/12 11:30:57 | 000,000,000 | ---D | M] (Dictionnaire français «Moderne») -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/04/28 20:47:12 | 000,000,000 | ---D | M] (Icelandic Dictionary) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/04/28 20:47:11 | 000,000,000 | ---D | M] (Dizionario italiano) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/06/28 21:08:22 | 000,000,000 | ---D | M] (Norsk bokmÃ¥l ordliste) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/07/01 11:16:54 | 000,000,000 | ---D | M] (Polski slownik poprawnej pisowni) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2010/09/15 18:05:52 | 000,000,000 | ---D | M] (Russian spellchecking dictionary) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2011/07/01 11:16:54 | 000,000,000 | ---D | M] (Svensk ordlista) -- C:\Program Files\Mozilla Firefox\FirefoxPortable\Data\profile\extensions\[email protected]
[2010/04/10 18:17:39 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/01 18:07:07 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/22 21:16:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2009/08/12 18:19:22 | 000,000,813 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LUMIX Simple Viewer.lnk = C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMovingBands = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCloseDragDropBands = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmat...enWebRadio.html File not found
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Mimi II\Start Menu\Programs\IMVU\Run IMVU.lnk File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.t...ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} http://cameracanadap...PUploader57.cab (Image Uploader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{08B6E02A-BBEA-450C-A110-EED00DD6157E}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Mimi II\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mimi II\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/10/15 10:48:20 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/10/13 19:35:50 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mimi II\Desktop\OTL.exe
[2011/10/13 11:03:34 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/10/07 10:21:12 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Mimi II\My Documents\HijackThis.exe
[2011/10/01 19:14:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/10/01 19:14:37 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/10/01 19:14:00 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/09/26 11:44:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NCH Software
[2011/09/26 11:44:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mimi II\Application Data\NCH Software
[2011/09/24 17:28:33 | 000,000,000 | ---D | C] -- C:\Program Files\MALWAREBYTES ANTI-MALWARE
[2008/05/28 10:22:26 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Mimi II\Application Data\pcouffin.sys
[1980/01/01 02:00:00 | 000,151,552 | ---- | C] ( ) -- C:\WINDOWS\System32\ATIDEMGR.dll

========== Files - Modified Within 30 Days ==========

[2011/10/16 10:38:11 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/16 10:21:49 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2011/10/16 10:19:42 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-536494136-2410558530-2963846775-1008.job
[2011/10/16 10:19:30 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/16 10:19:18 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2011/10/16 10:19:15 | 1071,796,224 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/15 18:46:26 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Mimi II\Local Settings\Application Data\prvlcl.dat
[2011/10/15 18:00:32 | 000,014,198 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\fra.jpg
[2011/10/15 17:56:54 | 000,088,937 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\P1050761.jpg
[2011/10/15 17:56:17 | 000,106,359 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\P1050699.jpg
[2011/10/14 16:13:35 | 000,000,986 | ---- | M] () -- C:\WINDOWS\dellstat.ini
[2011/10/14 16:02:41 | 003,245,726 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF3212.jpg
[2011/10/14 16:02:24 | 003,943,057 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF3196.jpg
[2011/10/14 16:02:02 | 004,596,960 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF3110.jpg
[2011/10/14 16:01:48 | 004,469,231 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF3088.jpg
[2011/10/13 20:26:30 | 000,302,592 | ---- | M] () -- C:\sbruso00.exe
[2011/10/13 19:35:52 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mimi II\Desktop\OTL.exe
[2011/10/13 13:46:46 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/13 12:30:31 | 000,397,552 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/13 11:07:07 | 000,445,830 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2011/10/13 11:07:07 | 000,073,036 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2011/10/13 10:56:04 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/10/13 10:23:16 | 087,132,222 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/10/12 17:02:58 | 000,316,170 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\_MG_8544.jpg
[2011/10/12 17:00:44 | 001,502,898 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\Henry_Burris_-_CFL_PHOTO_-_Peter_McCabe.jpg
[2011/10/11 11:46:01 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-536494136-2410558530-2963846775-1008.job
[2011/10/07 10:21:26 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Mimi II\My Documents\HijackThis.exe
[2011/10/04 20:05:55 | 000,014,250 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\fi.jpg
[2011/10/04 19:33:39 | 000,014,998 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF2219.jpg
[2011/10/04 19:20:53 | 000,021,908 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\nor.jpg
[2011/09/28 12:10:02 | 000,001,776 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/09/28 12:06:48 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\Mimi II\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/09/26 12:04:41 | 000,063,487 | ---- | M] () -- C:\Documents and Settings\Mimi II\My Documents\ss.jpg
[2011/09/25 10:22:01 | 000,000,211 | RHS- | M] () -- C:\BOOT.INI
[2011/09/16 18:30:43 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\switchShakeIcon.job

========== Files Created - No Company Name ==========

[2011/10/15 18:00:32 | 000,014,198 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\fra.jpg
[2011/10/15 17:56:53 | 000,088,937 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\P1050761.jpg
[2011/10/15 17:56:13 | 000,106,359 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\P1050699.jpg
[2011/10/13 20:26:29 | 000,302,592 | ---- | C] () -- C:\sbruso00.exe
[2011/10/13 10:55:36 | 000,001,393 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/10/12 17:02:57 | 000,316,170 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\_MG_8544.jpg
[2011/10/12 17:00:41 | 001,502,898 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\Henry_Burris_-_CFL_PHOTO_-_Peter_McCabe.jpg
[2011/10/04 20:01:48 | 000,014,250 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\fi.jpg
[2011/10/04 19:30:12 | 000,014,998 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF2219.jpg
[2011/10/04 19:20:53 | 000,021,908 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\nor.jpg
[2011/09/30 11:09:40 | 003,245,726 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF3212.jpg
[2011/09/30 11:04:22 | 003,943,057 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF3196.jpg
[2011/09/30 10:20:20 | 004,596,960 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF3110.jpg
[2011/09/30 10:08:30 | 004,469,231 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\DSCF3088.jpg
[2011/09/28 12:06:47 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/09/26 12:03:00 | 000,063,487 | ---- | C] () -- C:\Documents and Settings\Mimi II\My Documents\ss.jpg
[2011/09/25 10:21:56 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL 9.0 Tray Icon.lnk
[2011/09/16 18:30:42 | 000,000,282 | ---- | C] () -- C:\WINDOWS\tasks\switchShakeIcon.job
[2011/07/06 19:09:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2011/07/06 18:58:54 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2011/02/27 15:50:22 | 000,000,003 | ---- | C] () -- C:\WINDOWS\treeskp.sys
[2011/02/27 15:50:22 | 000,000,003 | ---- | C] () -- C:\WINDOWS\sbacknt.bin
[2010/02/11 00:12:00 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2010/02/11 00:12:00 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2009/12/17 04:33:56 | 003,190,784 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2009/12/17 04:33:56 | 000,405,504 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2009/12/17 04:33:56 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2009/12/17 04:33:56 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2009/12/17 04:33:56 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2009/12/17 04:33:56 | 000,097,280 | ---- | C] () -- C:\WINDOWS\System32\ff_realaac.dll
[2009/12/17 04:33:56 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2009/12/17 04:33:56 | 000,038,400 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2009/12/17 04:33:54 | 000,741,376 | ---- | C] () -- C:\WINDOWS\System32\audxlib.dll
[2009/12/17 04:33:54 | 000,662,016 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/12/17 04:33:54 | 000,511,488 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2009/12/17 04:33:54 | 000,245,760 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2009/12/17 04:33:54 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2009/12/17 04:33:54 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2009/12/17 04:33:54 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2009/12/17 04:33:54 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2009/12/17 04:33:54 | 000,079,872 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2009/12/17 04:33:54 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2009/12/17 04:33:54 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/05/01 16:03:56 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mimi II\Local Settings\Application Data\prvlcl.dat
[2009/04/23 18:29:16 | 000,189,051 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2009/04/16 11:24:06 | 008,892,928 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\atscie.msi
[2008/12/26 20:03:10 | 000,281,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008/12/26 20:03:03 | 000,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/05/28 10:22:26 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Mimi II\Application Data\inst.exe
[2008/05/28 10:22:26 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Mimi II\Application Data\pcouffin.cat
[2008/05/28 10:22:26 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Mimi II\Application Data\pcouffin.inf
[2008/04/29 11:36:06 | 000,000,001 | ---- | C] () -- C:\WINDOWS\dedlat2.dll
[2008/04/29 11:35:51 | 000,613,897 | -H-- | C] () -- C:\WINDOWS\System32\drivers\klog.dat
[2008/01/30 17:10:46 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\libcurl.dll
[2007/12/14 15:52:38 | 000,000,005 | ---- | C] () -- C:\WINDOWS\System32\SySVid.dat
[2007/12/14 15:51:39 | 000,003,082 | ---- | C] () -- C:\WINDOWS\System32\affv11300p4now.sys
[2007/12/13 15:15:14 | 000,000,206 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/12/05 18:06:04 | 000,000,335 | ---- | C] () -- C:\WINDOWS\mozregistry.dat
[2007/11/29 11:31:11 | 000,915,488 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2007/11/29 11:31:11 | 000,058,144 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2007/11/17 19:53:56 | 000,001,578 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Mp4 Codec.dat
[2007/11/17 19:52:02 | 000,002,154 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Ogg Vorbis Codec.dat
[2007/11/17 19:51:08 | 000,002,467 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dMC mp3PRO (CLI) Encoder.dat
[2007/11/17 19:49:16 | 000,002,286 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Monkeys Audio Codec.dat
[2007/10/31 10:39:54 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2007/07/24 16:22:50 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2007/07/24 16:22:49 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2007/07/24 16:22:49 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2007/07/24 16:22:49 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2007/07/24 16:22:49 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2007/07/24 16:22:49 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2007/07/24 16:22:49 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2007/07/24 16:22:49 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2007/07/24 16:22:49 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2007/07/24 16:22:49 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2007/07/24 16:22:49 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2007/07/24 16:22:49 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2007/07/24 16:22:49 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2007/07/24 16:22:49 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2007/07/24 16:22:49 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2007/07/24 16:22:49 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2007/07/24 16:22:49 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2007/07/24 16:22:49 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2007/07/24 16:22:49 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2007/07/06 18:06:24 | 000,001,160 | ---- | C] () -- C:\WINDOWS\ARCHPR.INI
[2007/06/07 18:20:02 | 000,003,452 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Musepack Codec.dat
[2007/06/01 15:17:27 | 000,000,227 | ---- | C] () -- C:\WINDOWS\PowerReg.dat
[2007/06/01 15:17:21 | 000,045,568 | ---- | C] () -- C:\WINDOWS\UniFish3.exe
[2007/05/17 13:58:10 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\libexpatw.dll
[2007/03/28 15:25:37 | 000,000,050 | ---- | C] () -- C:\WINDOWS\MegaManager.INI
[2007/03/22 16:47:35 | 000,046,344 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.EXE
[2007/02/20 18:14:20 | 000,194,133 | ---- | C] () -- C:\WINDOWS\patcher.exe
[2007/02/05 21:34:05 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\MP2enc.dll
[2007/01/19 12:34:39 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2007/01/19 12:34:39 | 000,000,341 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2007/01/19 12:33:58 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2007/01/19 12:33:58 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2007/01/19 12:33:58 | 000,000,073 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2007/01/19 12:33:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nsprs.dll
[2006/11/20 12:04:59 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2006/11/06 15:30:38 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2006/06/18 19:47:49 | 000,161,280 | ---- | C] () -- C:\Documents and Settings\Mimi II\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/06/18 19:47:49 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Mimi II\Local Settings\Application Data\fusioncache.dat
[2006/06/17 13:32:06 | 001,019,094 | RHS- | C] () -- C:\Program Files\serial.zip
[2006/06/17 13:32:06 | 001,019,094 | RHS- | C] () -- C:\Program Files\serial.tde
[2006/05/28 12:45:47 | 000,397,306 | RHS- | C] () -- C:\Program Files\wunauclt.zip
[2006/05/28 12:45:47 | 000,397,306 | RHS- | C] () -- C:\Program Files\wunauclt.tbe
[2006/05/01 19:19:24 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2006/04/15 10:38:42 | 000,001,067 | ---- | C] () -- C:\WINDOWS\ARPR.INI
[2006/02/11 21:14:57 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\micr0st.dll
[2006/02/11 21:01:13 | 000,000,067 | ---- | C] () -- C:\WINDOWS\A1 DVD Ripper.INI
[2006/01/13 18:28:11 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/12/12 20:57:59 | 000,033,012 | ---- | C] () -- C:\WINDOWS\System32\tpuninstall.exe
[2005/12/07 10:56:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\TempName.dll
[2005/12/06 21:05:32 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\drivers\netfltConfig.dat
[2005/11/24 17:46:19 | 000,370,000 | RHS- | C] () -- C:\WINDOWS\aiiaacc.exe
[2005/11/24 17:46:19 | 000,000,007 | ---- | C] () -- C:\WINDOWS\wocnm.dat
[2005/11/24 17:46:19 | 000,000,001 | ---- | C] () -- C:\WINDOWS\isf.dat
[2005/11/22 13:24:32 | 000,666,240 | ---- | C] () -- C:\WINDOWS\System32\aswBoot.exe
[2005/11/01 13:51:23 | 000,001,290 | ---- | C] () -- C:\WINDOWS\AZPR3.INI
[2005/10/01 18:01:50 | 000,000,066 | ---- | C] () -- C:\WINDOWS\Aurora Video VCD_SVCD_DVD Creator.INI
[2005/10/01 17:33:25 | 000,000,067 | ---- | C] () -- C:\WINDOWS\VideoConvert.INI
[2005/10/01 17:31:01 | 000,000,066 | ---- | C] () -- C:\WINDOWS\#1 Video Converter.INI
[2005/09/11 18:06:16 | 000,000,287 | ---- | C] () -- C:\WINDOWS\EReg072.dat
[2005/06/22 21:37:51 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\FileOps.exe
[2005/05/13 12:41:24 | 000,167,424 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe
[2005/05/13 12:14:11 | 000,000,005 | ---- | C] () -- C:\WINDOWS\System32\wincon.dat
[2005/03/10 14:40:28 | 000,000,339 | ---- | C] () -- C:\WINDOWS\ULEAD32.INI
[2005/03/07 12:25:55 | 000,099,965 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2005/03/02 18:36:38 | 000,105,168 | ---- | C] () -- C:\WINDOWS\NSUninst.exe
[2005/03/02 18:36:18 | 000,105,168 | ---- | C] () -- C:\WINDOWS\GREUninstall.exe
[2005/03/02 18:36:16 | 000,013,605 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2005/03/01 21:58:36 | 000,004,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2005/02/27 10:56:58 | 000,000,819 | ---- | C] () -- C:\WINDOWS\jamkeys.ini
[2005/02/27 10:56:58 | 000,000,024 | ---- | C] () -- C:\WINDOWS\jam.ini
[2005/02/27 10:56:46 | 000,000,055 | ---- | C] () -- C:\WINDOWS\mediachk.ini
[2005/02/27 10:56:46 | 000,000,040 | ---- | C] () -- C:\WINDOWS\sndcheck.ini
[2005/02/27 10:56:42 | 000,025,440 | ---- | C] () -- C:\WINDOWS\VUNINSTL.DLL
[2005/02/27 10:56:38 | 000,304,128 | ---- | C] () -- C:\WINDOWS\VUNINSTL.EXE
[2005/02/27 10:55:33 | 000,000,395 | ---- | C] () -- C:\WINDOWS\VUNINSTL.INI
[2005/02/14 13:53:19 | 000,000,402 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2005/01/12 14:17:03 | 000,000,338 | ---- | C] () -- C:\WINDOWS\fontssg.ini
[2005/01/12 14:17:03 | 000,000,097 | ---- | C] () -- C:\WINDOWS\LMICD.INI
[2005/01/04 12:30:46 | 000,059,419 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2005/01/01 14:11:10 | 000,000,644 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2004/12/29 14:30:34 | 000,001,125 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2004/12/29 13:56:55 | 000,000,986 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2004/12/29 13:55:59 | 000,143,360 | R--- | C] () -- C:\WINDOWS\System32\dlbtcoin.dll
[2004/12/29 13:55:59 | 000,126,976 | R--- | C] () -- C:\WINDOWS\System32\dlbtsnls.dll
[2004/12/29 13:55:43 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbtvs.dll
[2004/12/29 13:55:42 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\dlbtih.exe
[2004/12/29 13:55:39 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\dlbtcur.dll
[2004/12/29 13:55:39 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\dlbtcu.dll
[2004/12/29 13:55:34 | 000,557,056 | ---- | C] () -- C:\WINDOWS\System32\dlbtjswr.dll
[2004/12/29 13:55:26 | 000,401,408 | ---- | C] () -- C:\WINDOWS\System32\dlbtutil.dll
[2004/12/29 13:25:06 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2004/12/03 19:59:44 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/12/03 19:57:05 | 000,000,324 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/12/03 19:52:41 | 000,000,590 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/12/03 19:50:14 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2004/12/03 19:41:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\BOOTSTAT.DAT
[2004/12/03 19:40:54 | 000,445,830 | ---- | C] () -- C:\WINDOWS\System32\PERFH009.DAT
[2004/12/03 19:40:54 | 000,073,036 | ---- | C] () -- C:\WINDOWS\System32\PERFC009.DAT
[2004/12/03 19:27:50 | 000,000,519 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/10/26 18:39:05 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2004/09/28 07:38:30 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\wmatimer.dll
[2004/09/16 00:03:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 15:13:12 | 000,000,882 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/08/10 15:08:08 | 000,397,552 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 15:03:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 15:02:16 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 12:08:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 12:08:26 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\MIB.BIN
[2004/08/04 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 07:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 07:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 18:01:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\SETPWRCG.EXE
[2004/07/03 22:08:04 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2003/12/13 22:40:42 | 001,003,520 | ---- | C] () -- C:\WINDOWS\System32\ltmm_n.dll
[2003/07/31 19:16:46 | 000,000,017 | -H-- | C] () -- C:\WINDOWS\System32\drivers\DVEMODEM.DAT
[2003/01/07 17:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/15 18:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[1997/08/23 12:33:24 | 000,022,064 | ---- | C] () -- C:\WINDOWS\System32\tntlvr.dll
[1997/06/13 21:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[1980/01/01 02:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2011/09/23 10:11:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2004/12/03 19:49:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/03/14 10:24:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2008/12/26 19:37:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/05/08 12:11:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy-PizzaParty
[2007/09/08 10:45:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Internet debug mess great
[2007/12/03 22:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/02/27 14:33:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2010/10/01 18:23:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008/05/04 15:32:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PrevxCSI
[2010/09/08 11:45:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\River Past G5
[2008/08/28 12:12:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SimCity Societies
[2011/07/02 17:45:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Solidshield
[2010/06/19 10:36:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/02/01 18:39:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2007/07/28 11:33:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Storm
[2009/06/18 18:47:08 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\System Restore
[2010/01/01 14:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tages
[2005/01/08 11:46:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tavultesoft
[2009/05/08 12:11:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/11 11:53:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2007/05/16 19:56:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\.BitTornado
[2009/11/30 12:05:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\AVG9
[2008/12/26 19:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\DAEMON Tools
[2008/12/26 19:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\DAEMON Tools Lite
[2008/12/26 19:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\DAEMON Tools Pro
[2008/02/06 16:02:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Design Science
[2011/02/15 19:15:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Dropbox
[2006/06/18 19:40:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\FIFA2003CC
[2006/06/18 19:40:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\GlobalSCAPE
[2007/11/23 20:40:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Grammatica
[2010/03/12 15:24:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\gtk-2.0
[2006/06/18 19:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Leadertech
[2011/06/08 19:06:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Mael
[2008/09/15 13:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Maple
[2008/10/06 18:11:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\My Games
[2010/10/01 18:23:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\NCH Swift Sound
[2009/05/26 18:44:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Netscape
[2011/06/08 19:09:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Notepad++
[2009/03/16 20:11:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\OpenOffice.org
[2007/07/24 16:23:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Panasonic
[2007/07/31 15:56:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\ppstream
[2011/01/09 14:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\RenPy
[2008/04/04 20:08:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\River Past G5
[2009/02/13 19:09:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\SendSpace Wizard
[2006/06/18 19:35:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Seven Zip
[2010/06/19 10:35:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Sports Interactive
[2006/06/18 19:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\STOIK
[2011/09/11 18:51:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Ubisoft
[2007/11/30 21:58:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Uniblue
[2011/01/09 14:43:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Utherverse
[2006/06/18 19:34:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Visicom Media
[2010/08/18 12:00:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Vivox
[2006/06/18 19:34:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\VP-Software
[2008/06/10 20:43:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mimi II\Application Data\Vso
[2011/09/16 18:30:43 | 000,000,282 | ---- | M] () -- C:\WINDOWS\Tasks\switchShakeIcon.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A5227364
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A73B0434

< End of report >
  • 0

Advertisements


#11
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Let's see what we have there:

Download and Install Combofix

Download ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop *

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
  • 0

#12
princessmimi

princessmimi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Hello again,

I seem to have two problems before running Combofix:

#1. I seem to have the bad fortune of having AVG 9.0 internet security on my computer and have spent nearly half an hour trying to find any useful hints on how to disable it (the link you gave for this forum has AVG 9.0 go to the official site, but the page is gone). I've searched it online and have only come up with people complaining it can't be disabled or that you do it through the Resident Shield (just like with doing GMER). Do you know if this is enough to disable or it, or is there some other trick?

#2. Combofix is detecting Avast! on my computer. I used it for a few months more than five years ago and properly uninstalled it. I did a search through my computer and it detected an old shortcut, but that's it. I deleted this, but it still keeps detecting it.

Considering the warnings, I thought I'd let you know first what's going on before going ahead and screwing something up. :)
  • 0

#13
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hi princessmimi,

You did good thing and ask me for advice. After this two steps try to run Combofix again.

Step 1

We need to remove AVG from your system. Please download AVG Remover and run it in order to remove AVG.

Step 2

Lets remove Avast! leftovers from your system. Download Avast removal tool from This site and run it in order to remove Avast files from your system.
  • 0

#14
princessmimi

princessmimi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
I removed both antivirus files and ran Combofix. I'm not sure what happened, but my computer's running like before. There's no difference in speed or performance (this old computer can't handle much of either anymore). When I reinstalled AVG before posting this reply, the computer restarted and ran CHKDSK. I'm not sure if this is a good, bad or unimportant thing, but I thought I'd mention it. Hoping everything is coming out clean...

Combofix log:

ComboFix 11-10-16.02 - Mimi II 10/18/2011 16:04:17.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.469 [GMT -4:00]
Running from: c:\documents and settings\Mimi II\Desktop\ComboFix.exe
AV: AVG Internet Security *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Storm
c:\documents and settings\All Users\Application Data\Storm\Update\aac_ps.ax
c:\documents and settings\All Users\Application Data\Storm\update\aasc32.dll
c:\documents and settings\All Users\Application Data\Storm\Update\ac3filter.ax
c:\documents and settings\All Users\Application Data\Storm\update\asusasv1.dll
c:\documents and settings\All Users\Application Data\Storm\Update\asusasv2.dll
c:\documents and settings\All Users\Application Data\Storm\Update\atidvdv.ax
c:\documents and settings\All Users\Application Data\Storm\update\ativcr2.dll
c:\documents and settings\All Users\Application Data\Storm\update\avidavicodec.dll
c:\documents and settings\All Users\Application Data\Storm\update\AviSplitter.ax
c:\documents and settings\All Users\Application Data\Storm\Update\binkw32.dll
c:\documents and settings\All Users\Application Data\Storm\update\cddareader.ax
c:\documents and settings\All Users\Application Data\Storm\update\cdxareader.ax
c:\documents and settings\All Users\Application Data\Storm\update\CLRVIDDC.DLL
c:\documents and settings\All Users\Application Data\Storm\Update\clrviddd.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Codec\RadGtSplitter.ax
c:\documents and settings\All Users\Application Data\Storm\Update\com.apple.QuickTime.plist
c:\documents and settings\All Users\Application Data\Storm\update\CoreAVC.ax
c:\documents and settings\All Users\Application Data\Storm\Update\DECVW_32.DLL
c:\documents and settings\All Users\Application Data\Storm\update\DmoDec.dll
c:\documents and settings\All Users\Application Data\Storm\update\dxr.dll
c:\documents and settings\All Users\Application Data\Storm\update\ff_kerneldeint.dll
c:\documents and settings\All Users\Application Data\Storm\update\ff_liba52.dll
c:\documents and settings\All Users\Application Data\Storm\update\ff_libdts.dll
c:\documents and settings\All Users\Application Data\Storm\update\ff_realaac.dll
c:\documents and settings\All Users\Application Data\Storm\update\ff_samplerate.dll
c:\documents and settings\All Users\Application Data\Storm\update\ff_tremor.dll
c:\documents and settings\All Users\Application Data\Storm\update\ff_vfw.dll
c:\documents and settings\All Users\Application Data\Storm\update\ff_vfw.dll.manifest
c:\documents and settings\All Users\Application Data\Storm\update\ffdshow.ax
c:\documents and settings\All Users\Application Data\Storm\Update\ffdshow.ax.manifest
c:\documents and settings\All Users\Application Data\Storm\update\FLAC.ax
c:\documents and settings\All Users\Application Data\Storm\Update\FLVSplitter.ax
c:\documents and settings\All Users\Application Data\Storm\update\frapsvid.dll
c:\documents and settings\All Users\Application Data\Storm\Update\i263_32.drv
c:\documents and settings\All Users\Application Data\Storm\update\icmw_32.dll
c:\documents and settings\All Users\Application Data\Storm\update\keys.dat
c:\documents and settings\All Users\Application Data\Storm\update\l3codeca.acm
c:\documents and settings\All Users\Application Data\Storm\update\l3codecp.acm
c:\documents and settings\All Users\Application Data\Storm\update\l3codecx.ax
c:\documents and settings\All Users\Application Data\Storm\Update\languages\ffdshow.1033.en
c:\documents and settings\All Users\Application Data\Storm\Update\languages\ffdshow.2052.sc
c:\documents and settings\All Users\Application Data\Storm\Update\LCodcCMP.dll
c:\documents and settings\All Users\Application Data\Storm\Update\libavcodec.dll
c:\documents and settings\All Users\Application Data\Storm\update\libmplayer.dll
c:\documents and settings\All Users\Application Data\Storm\Update\MACDec.dll
c:\documents and settings\All Users\Application Data\Storm\Update\MASource.ax
c:\documents and settings\All Users\Application Data\Storm\Update\mkunicode.dll
c:\documents and settings\All Users\Application Data\Storm\Update\mkx.dll
c:\documents and settings\All Users\Application Data\Storm\update\mkzlib.dll
c:\documents and settings\All Users\Application Data\Storm\update\mp4.dll
c:\documents and settings\All Users\Application Data\Storm\Update\MP4Splitter.ax
c:\documents and settings\All Users\Application Data\Storm\Update\mpg2splt.ax
c:\documents and settings\All Users\Application Data\Storm\update\msvcr71.dll
c:\documents and settings\All Users\Application Data\Storm\update\MZP4_DEC.DLL
c:\documents and settings\All Users\Application Data\Storm\update\ogm.dll
c:\documents and settings\All Users\Application Data\Storm\update\Plugins\nppl3260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\nppl3260.xpt
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\npqtplugin.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\nprpjplug.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\nsIQTScriptablePlugin.xpt
c:\documents and settings\All Users\Application Data\Storm\update\Plugins\nsJSRealPlayerPlugin.xpt
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\QuickTimePlugin.class
c:\documents and settings\All Users\Application Data\Storm\update\PmpSplt.ax
c:\documents and settings\All Users\Application Data\Storm\update\pncrt.dll
c:\documents and settings\All Users\Application Data\Storm\update\pndx5016.dll
c:\documents and settings\All Users\Application Data\Storm\Update\pndx5032.dll
c:\documents and settings\All Users\Application Data\Storm\update\qt.p2p
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\CFCharacterSetBitmaps.bitmap
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\CoreVideo.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\CoreVideo.Resources\CoreVideo.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\CoreVideo.Resources\en.lproj\CoreVideoLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\CoreVideo.Resources\zh_CN.lproj\CoreVideoLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QTCheck.ocx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QTPlugin.ocx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime.cpl
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime.qts
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime.Resources\en.lproj\QuickTimeLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime.Resources\en.lproj\QuickTimeLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime.Resources\QuickTime.dll
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime.Resources\QuickTime.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime.Resources\zh_CN.lproj\QuickTimeLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime.Resources\zh_CN.lproj\QuickTimeLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime3GPP.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime3GPP.Resources\en.lproj\QuickTime3GPPLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime3GPP.Resources\QuickTime3GPP.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime3GPP.Resources\zh_CN.lproj\QuickTime3GPPLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeAudioSupport.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeAudioSupport.Resources\en.lproj\QuickTimeAudioSupportLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeAudioSupport.Resources\en.lproj\QuickTimeAudioSupportLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeAudioSupport.Resources\QuickTimeAudioSupport.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeAudioSupport.Resources\zh_CN.lproj\QuickTimeAudioSupportLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeAudioSupport.Resources\zh_CN.lproj\QuickTimeAudioSupportLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeEssentials.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeEssentials.Resources\en.lproj\QuickTimeEssentialsLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeEssentials.Resources\QuickTimeEssentials.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeEssentials.Resources\zh_CN.lproj\QuickTimeEssentialsLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeH264.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeH264.Resources\en.lproj\QuickTimeH264Localized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeH264.Resources\QuickTimeH264.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeH264.Resources\zh_CN.lproj\QuickTimeH264Localized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeInternetExtras.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeInternetExtras.Resources\en.lproj\QuickTimeInternetExtrasLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeInternetExtras.Resources\QuickTimeInternetExtras.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeInternetExtras.Resources\zh_CN.lproj\QuickTimeInternetExtrasLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeMPEG4.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeMPEG4.Resources\en.lproj\QuickTimeMPEG4Localized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeMPEG4.Resources\QuickTimeMPEG4.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeMPEG4.Resources\zh_CN.lproj\QuickTimeMPEG4Localized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeStreaming.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreaming.Resources\en.lproj\QuickTimeStreamingLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeStreaming.Resources\en.lproj\QuickTimeStreamingLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreaming.Resources\QuickTimeStreaming.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeStreaming.Resources\zh_CN.lproj\QuickTimeStreamingLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeStreaming.Resources\zh_CN.lproj\QuickTimeStreamingLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreamingExtras.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeStreamingExtras.Resources\en.lproj\QuickTimeStreamingExtrasLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeStreamingExtras.Resources\QuickTimeStreamingExtras.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreamingExtras.Resources\zh_CN.lproj\QuickTimeStreamingExtrasLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeVR.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeVR.Resources\en.lproj\QuickTimeVRLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeVR.Resources\QuickTimeVR.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeVR.Resources\zh_CN.lproj\QuickTimeVRLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeWebHelper.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeWebHelper.Resources\en.lproj\QuickTimeWebHelperLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeWebHelper.Resources\en.lproj\QuickTimeWebHelperLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeWebHelper.Resources\QuickTimeWebHelper.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeWebHelper.Resources\QuickTimeWebHelper.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeWebHelper.Resources\zh_CN.lproj\QuickTimeWebHelperLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeWebHelper.Resources\zh_CN.lproj\QuickTimeWebHelperLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QuickTime.qts
c:\documents and settings\All Users\Application Data\Storm\update\QuickTimeVR.qtx
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\14_43260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\28_83260.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\atrc.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\cook.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\ddnt3260.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\dnet3260.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\drv1.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\drv2.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\drvc.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\hxltcolor.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\raac.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\ralf.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\rv10.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\rv20.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\rv30.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\rv40.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\sipr.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Common\objb3201.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Common\pnen3260.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Common\pngu3267.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Common\pnrs3260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Common\rppr3260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\audplin.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\authmgr.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\clbascauth.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\clntxres.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\ExtResources\coreres.xrs
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\fpsechnd.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\httpfsys.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\hxsdp.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\hxxml.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\imgrender.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\memfsys.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\mp3fformat.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\mp3render.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\mp4arender.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\ntlmauth.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\oggfformat.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\pacplin.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\plusplin.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\pxcb3210.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\ramfformat.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\ramrender.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rarender.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rmfformat.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rmxfpln.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\rmxrend.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rn5auth.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rtfformat.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rtrender.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rvrender.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\sdpplin.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\security.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\smlfformat.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\smlrender.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\smmrender.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\smplfsys.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\stubdrm.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\tfilesys.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\vidplin.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\vidsite.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\vorbisrend.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\vsrlocal.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\rpplugins\cn\embed_cn.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\rpplugins\cn\rpclsvc_cn.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\rpplugins\embd3260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\rpplugins\rpcl3260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\rpplugins\rput3260.dll
c:\documents and settings\All Users\Application Data\Storm\update\RLMPCDec.ax
c:\documents and settings\All Users\Application Data\Storm\update\rmoc3260.dll
c:\documents and settings\All Users\Application Data\Storm\update\RMSplt.ax
c:\documents and settings\All Users\Application Data\Storm\Update\scsource.ax
c:\documents and settings\All Users\Application Data\Storm\Update\SHNTrans.ax
c:\documents and settings\All Users\Application Data\Storm\update\smackw32.dll
c:\documents and settings\All Users\Application Data\Storm\Update\splitter.ax
c:\documents and settings\All Users\Application Data\Storm\Update\tomsmocomp_ff.dll
c:\documents and settings\All Users\Application Data\Storm\Update\ts.dll
c:\documents and settings\All Users\Application Data\Storm\Update\tsccvid.dll
c:\documents and settings\All Users\Application Data\Storm\Update\TTASplt.ax
c:\documents and settings\All Users\Application Data\Storm\Update\TTL2Dec.dll
c:\documents and settings\All Users\Application Data\Storm\Update\v2k2_dec.dll
c:\documents and settings\All Users\Application Data\Storm\Update\v2kdspde.dll
c:\documents and settings\All Users\Application Data\Storm\update\VDODEC32.dll
c:\documents and settings\All Users\Application Data\Storm\Update\vdowave.drv
c:\documents and settings\All Users\Application Data\Storm\update\VgmAudio.ax
c:\documents and settings\All Users\Application Data\Storm\Update\vgmbgr.ax
c:\documents and settings\All Users\Application Data\Storm\Update\VgmSplt.ax
c:\documents and settings\All Users\Application Data\Storm\update\vgmv2k2.ax
c:\documents and settings\All Users\Application Data\Storm\update\Vid1Dec.dll
c:\documents and settings\All Users\Application Data\Storm\Update\vmnc.dll
c:\documents and settings\All Users\Application Data\Storm\Update\vp6vfw.dll
c:\documents and settings\All Users\Application Data\Storm\Update\vp7vfw.dll
c:\documents and settings\All Users\Application Data\Storm\update\VSFilter.dll
c:\documents and settings\All Users\Application Data\Storm\update\xvid.ax
c:\documents and settings\All Users\Application Data\Storm\Update\xvidcore.dll
c:\documents and settings\All Users\Application Data\Storm\Update\xvidvfw.dll
c:\documents and settings\All Users\Application Data\Tages
c:\documents and settings\All Users\Application Data\Tages\16784711\Serial.txt
c:\documents and settings\All Users\Application Data\Tages\Priv.xey
c:\documents and settings\Mimi II\Application Data\inst.exe
c:\documents and settings\Mimi II\WINDOWS
c:\documents and settings\Mimi\Favorites\.url
c:\documents and settings\Mimi\WINDOWS
C:\Documents
c:\program files\INSTALL.LOG
C:\readme.txt
c:\windows\exefld
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\7474777576737
c:\windows\system32\7474777576737\A8A8ABA9AAA7A
c:\windows\system32\7474777576737\B4B4B7B5B6B3B
c:\windows\system32\7474777576737\B6B6B9B7B8B5B
c:\windows\system32\7474777576737\D1D1D4D2D3D0D
c:\windows\system32\7474777576737\DADADDDBDCD9D
c:\windows\system32\ban_list.txt
c:\windows\system32\drivers\klog.dat
c:\windows\system32\Thumbs.db
c:\windows\system32\tpuninstall.exe
c:\windows\WindowsXP-KB894391-x86-ENU.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ASC3550P
-------\Legacy_SROSA
.
.
((((((((((((((((((((((((( Files Created from 2011-09-18 to 2011-10-18 )))))))))))))))))))))))))))))))
.
.
2011-10-15 14:48 . 2011-10-15 14:48 -------- d-----w- C:\_OTL
2011-10-14 00:26 . 2011-10-14 00:26 302592 ----a-w- C:\sbruso00.exe
2011-09-28 16:06 . 2011-09-23 04:28 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-09-28 16:06 . 2011-09-23 04:28 773080 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-09-28 16:06 . 2011-09-23 04:28 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2011-09-28 16:06 . 2011-09-23 04:28 478168 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-09-28 16:06 . 2011-09-23 04:28 1833944 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-09-28 16:06 . 2011-09-23 04:28 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2011-09-28 16:06 . 2011-09-23 04:28 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-09-28 16:06 . 2011-09-23 01:16 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-09-28 16:06 . 2011-09-23 01:16 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-09-26 15:44 . 2011-09-26 15:44 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2011-09-26 15:44 . 2011-09-26 15:44 -------- d-----w- c:\documents and settings\Mimi II\Application Data\NCH Software
2011-09-24 21:28 . 2011-10-18 14:05 -------- d-----w- c:\program files\MALWAREBYTES ANTI-MALWARE
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-28 16:05 . 2011-05-28 14:32 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-26 15:41 . 2008-07-29 23:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 11:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 11:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12 . 2004-08-04 11:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2004-08-04 11:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-31 21:00 . 2009-11-11 17:47 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 23:48 . 2004-08-04 11:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2004-08-04 11:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2004-08-04 11:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-04 11:00 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2004-08-04 11:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-03 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-07-07 647216]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2009-09-14 472112]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
"CTCheck"="c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-05-21 273544]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-11 61440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-6-23 113664]
AOL 9.0 Tray Icon.lnk - c:\program files\AOL 9.0\aoltray.exe [2004-12-3 156784]
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2007-7-24 57344]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2005-3-8 106560]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Netscape\\Netscape\\Netscp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Documents and Settings\\Mimi II\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Mozilla Firefox\\FirefoxPortable\\App\\Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404\\Anno4.exe"=
"c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404\\tools\\Anno4Web.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe"= c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet,0.0.0.0/255.255.255.255:Enabled:Pure Networks Platform Service
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"4662:TCP"= 4662:TCP:eMule port
"67:UDP"= 67:UDP:DHCP Discovery Service
"4672:UDP"= 4672:UDP:eMule port
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 sptd;sptd;c:\windows\SYSTEM32\DRIVERS\sptd.sys [6/27/2008 12:00 PM 717296]
R2 Iprip;RIP Listener;c:\windows\System32\svchost.exe -k netsvcs [8/4/2004 7:00 AM 14336]
S0 sgkt;sgkt;c:\windows\system32\drivers\jrdn.sys --> c:\windows\system32\drivers\jrdn.sys [?]
S2 bsaspi32;bsaspi32; [x]
S2 gupdate1c9bee52bba4c2c;Google Update Service (gupdate1c9bee52bba4c2c);c:\program files\Google\Update\GoogleUpdate.exe [4/16/2009 6:46 PM 133104]
S2 RPC Security;RPC Security;c:\windows\svchost.exe --> c:\windows\svchost.exe [?]
S2 winsocket;winsocket;c:\windows\system32\winsocket.exe --> c:\windows\system32\winsocket.exe [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/16/2009 6:46 PM 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\SYSTEM32\DRIVERS\pcouffin.sys [5/28/2008 10:22 AM 47360]
S4 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys --> c:\windows\system32\drivers\av5flt.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
.
2011-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-16 22:46]
.
2011-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-16 22:46]
.
2011-10-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-536494136-2410558530-2963846775-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2011-10-18 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-536494136-2410558530-2963846775-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2011-09-16 c:\windows\Tasks\switchShakeIcon.job
- c:\program files\NCH Swift Sound\Switch\switch.exe [2010-10-01 22:39]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.bbc.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Mimi II\Start Menu\Programs\IMVU\Run IMVU.lnk
TCP: DhcpNameServer = 192.168.0.1
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\Mimi II\Application Data\Mozilla\Firefox\Profiles\fye2bq6f.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.hotmail.com
.
.
------- File Associations -------
.
.scr=
.reg=
.
- - - - ORPHANS REMOVED - - - -
.
Notify-avgrsstarter - avgrsstx.dll
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-18 16:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-536494136-2410558530-2963846775-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-536494136-2410558530-2963846775-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-536494136-2410558530-2963846775-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*8nPN]*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-536494136-2410558530-2963846775-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*8nPN]*\OpenWithList]
@Class="Shell"
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell]
@="Play"
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\Enqueue]
@="&Enqueue in Winamp"
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\Enqueue\command]
@="\"c:\\Program Files\\Winamp\\winamp.exe\" /ADD \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\Enqueue\DropTarget]
"Clsid"="{77A366BA-2BE4-4a1e-9263-7734AA3E99A2}"
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\ListBookmark]
@="Add to Winamp's &Bookmark list"
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\ListBookmark\command]
@="\"c:\\Program Files\\Winamp\\winamp.exe\" /BOOKMARK \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\open]
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\open\command]
@="\"c:\\Program Files\\Winamp\\winamp.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\open\DropTarget]
"Clsid"="{46986115-84D6-459c-8F95-52DD653E532E}"
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\Play]
@="&Play in Winamp"
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\Play\command]
@="\"c:\\Program Files\\Winamp\\winamp.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ *0.m'**X¸§* *_*a*u*t*o*_*f*i*l*e*\shell\Play\DropTarget]
"Clsid"="{46986115-84D6-459c-8F95-52DD653E532E}"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(784)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3120)
c:\windows\system32\WININET.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\PENUSA.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2011-10-18 16:31:50 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-18 20:31
.
Pre-Run: 11,842,752,512 bytes free
Post-Run: 11,667,804,160 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=,1,2,3,4
- - End Of File - - B149C1337ABF2157A4CFA2907D070E24
  • 0

#15
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hi princessmimi,

Looking good. Combofix did great job. Do you have any problems now?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP