Anyway my pc suddenly started redirecting google pages .I believe it may have come from a gaming site or facebook.
Also malware bytes found problems but couldn't remove them as they kept generating.
Also upon rebooting everything would freeze ,and the only way i could get back on was to start in safe mode and remove malwarebytes program,along with google chrome
i am using zonealarm as a firewall and vipre as my antivirus .Vipre found the rootkit problem but could not quaratine or remove it .
Many thanks in advance
OTL FILE
OTL logfile created on: 10/01/2012 12:52:14 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\ollie\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.33% Memory free
3.35 Gb Paging File | 2.81 Gb Available in Paging File | 83.98% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.11 Gb Total Space | 142.27 Gb Free Space | 62.37% Space Free | Partition Type: NTFS
Drive D: | 232.83 Gb Total Space | 166.47 Gb Free Space | 71.50% Space Free | Partition Type: FAT32
Computer Name: OLLIE-E53879FC3 | User Name: ollie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/10 11:24:27 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ollie\Desktop\OTL.exe
PRC - [2011/12/18 21:08:42 | 002,420,616 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2011/11/03 14:44:28 | 000,497,280 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
PRC - [2011/11/03 14:44:24 | 000,738,944 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
PRC - [2011/11/01 00:55:08 | 003,045,744 | ---- | M] (GFI Software) -- C:\Program Files\GFI Software\VIPRE\SBAMTray.exe
PRC - [2011/11/01 00:41:20 | 003,287,472 | ---- | M] (GFI Software) -- C:\Program Files\GFI Software\VIPRE\SBAMSvc.exe
PRC - [2011/11/01 00:41:00 | 000,173,424 | ---- | M] (GFI Software) -- C:\Program Files\GFI Software\VIPRE\SBPIMSvc.exe
PRC - [2010/07/07 15:00:22 | 007,667,970 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
PRC - [2009/07/27 22:39:59 | 001,676,776 | ---- | M] (HistoryKill.com) -- C:\Program Files\HistoryKill 2010\histkill.exe
PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/04/04 17:58:30 | 000,856,064 | ---- | M] (Adobe Sytems Incorporated) -- C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
PRC - [2005/03/22 16:20:44 | 000,339,968 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2003/06/28 15:10:18 | 001,658,965 | ---- | M] (GlobespanVirata, Inc.) -- C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
========== Modules (No Company Name) ==========
MOD - [2012/01/10 11:49:46 | 000,193,904 | ---- | M] () -- C:\Program Files\GFI Software\VIPRE\Definitions\libMachoUniv.dll
MOD - [2012/01/10 11:49:45 | 000,210,288 | ---- | M] () -- C:\Program Files\GFI Software\VIPRE\Definitions\libBase64.dll
MOD - [2011/07/31 18:47:46 | 003,577,856 | ---- | M] () -- C:\WINDOWS\system32\ffdshow.ax
MOD - [2011/02/04 17:48:32 | 000,456,192 | ---- | M] () -- C:\WINDOWS\system32\encdec.dll
MOD - [2011/02/04 17:48:30 | 000,291,840 | ---- | M] () -- C:\WINDOWS\system32\sbe.dll
MOD - [2010/07/07 15:00:22 | 007,667,970 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
MOD - [2010/07/07 15:00:22 | 000,868,352 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility Libs\RBScript.dll
MOD - [2010/07/07 15:00:22 | 000,762,368 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility Libs\XML.dll
MOD - [2010/07/07 15:00:22 | 000,266,240 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility Libs\CGamma.dll
MOD - [2010/07/07 15:00:22 | 000,147,456 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility Libs\RegEx.dll
MOD - [2010/07/07 15:00:22 | 000,139,264 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility Libs\Appearance Pak.dll
MOD - [2010/07/07 15:00:22 | 000,098,304 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility Libs\Shell.dll
MOD - [2010/07/07 15:00:22 | 000,065,536 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility Libs\CSensor.dll
MOD - [2010/07/07 15:00:22 | 000,028,672 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility Libs\MBSRegistrationPlugin16042.dll
MOD - [2010/07/07 15:00:22 | 000,025,600 | ---- | M] () -- C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility Libs\MBSPluginVersionPlugin16042.dll
MOD - [2010/02/05 18:27:45 | 001,291,776 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2009/08/11 21:21:20 | 001,021,440 | ---- | M] () -- C:\WINDOWS\system32\ac3filter_intl.dll
MOD - [2009/08/11 21:19:04 | 000,797,184 | ---- | M] () -- C:\WINDOWS\system32\ac3filter.ax
MOD - [2008/04/14 00:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 00:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2008/01/06 16:35:51 | 000,036,864 | ---- | M] () -- C:\Program Files\My Hidden Folders\MHFshellmenu.dll
MOD - [2007/05/22 09:59:22 | 000,128,512 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2006/07/21 12:50:32 | 000,066,048 | R--- | M] () -- C:\WINDOWS\system32\hcwXDS.dll
MOD - [2006/05/14 04:23:40 | 000,138,752 | ---- | M] () -- C:\Program Files\7-Zip\7-zip.dll
MOD - [2005/12/22 17:28:40 | 000,160,768 | ---- | M] () -- C:\Program Files\GFI Software\VIPRE\unrar.dll
MOD - [2005/08/05 13:01:54 | 000,167,936 | ---- | M] () -- C:\WINDOWS\system32\wstpager.ax
MOD - [2005/08/05 13:01:54 | 000,159,744 | ---- | M] () -- C:\WINDOWS\system32\VBICodec.ax
MOD - [2005/08/05 12:06:50 | 000,165,376 | ---- | M] () -- C:\WINDOWS\system32\mpg2splt.ax
MOD - [2003/06/28 15:07:58 | 001,757,278 | ---- | M] () -- C:\Program Files\BT Voyager 105 ADSL Modem\dbgmode.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - File not found [Disabled | Stopped] -- -- (PCPitstop Scheduling)
SRV - File not found [Auto | Stopped] -- -- (AdvancedSystemCareService)
SRV - [2011/12/30 17:22:03 | 000,163,840 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe -- (Adobe Version Cue CS2)
SRV - [2011/12/18 21:08:42 | 002,420,616 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon)
SRV - [2011/11/03 14:44:28 | 000,497,280 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe -- (IswSvc)
SRV - [2011/11/01 00:41:20 | 003,287,472 | ---- | M] (GFI Software) [Auto | Running] -- C:\Program Files\GFI Software\VIPRE\SBAMSvc.exe -- (SBAMSvc)
SRV - [2011/11/01 00:41:00 | 000,173,424 | ---- | M] (GFI Software) [Auto | Running] -- C:\Program Files\GFI Software\VIPRE\SBPIMSvc.exe -- (SBPIMSvc)
SRV - [2008/08/13 23:04:44 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Disabled | Stopped] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2008/04/14 00:12:35 | 000,026,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\skeys.exe -- (SerialKeys)
========== Driver Services (SafeList) ==========
DRV - [2011/12/18 21:04:24 | 000,525,840 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (Vsdatant)
DRV - [2011/11/03 14:44:20 | 000,027,016 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV - [2011/11/01 00:08:12 | 000,217,976 | ---- | M] (GFI Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sbtis.sys -- (sbtis)
DRV - [2011/09/09 10:10:40 | 000,077,816 | ---- | M] (GFI Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\sbapifs.sys -- (sbapifs)
DRV - [2011/09/09 10:10:40 | 000,021,240 | ---- | M] (GFI Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sbaphd.sys -- (sbaphd)
DRV - [2010/04/02 02:38:59 | 000,022,304 | ---- | M] (Eltima Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\HMFAxCore0ad0c39557b13aeb3585f857b85005af.sys -- (HMFAxCore0ad0c39557b13aeb3585f857b85005af)
DRV - [2010/03/30 21:27:40 | 000,012,288 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Spyder3.sys -- (Spyder3)
DRV - [2009/08/29 17:13:43 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/08/05 15:58:40 | 000,093,872 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SBREDrv.sys -- (SBRE)
DRV - [2009/05/18 10:49:16 | 000,023,808 | ---- | M] (Phase One A/S) [Kernel | Auto | Running] -- C:\WINDOWS\System32\Drivers\p1c1394.sys -- (P1C1394)
DRV - [2009/03/02 14:00:46 | 000,095,592 | ---- | M] (Rocket Division Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\StarPortLite.sys -- (StarPortLite) StarPort Storage Controller (Lite)
DRV - [2008/04/13 18:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008/04/13 18:40:27 | 000,057,600 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\redbook.sys -- (redbook)
DRV - [2007/02/06 10:27:02 | 000,185,728 | R--- | M] (Hauppauge Computer Works, Inc.) [23|25|26]xxx) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hcwPP2.sys -- (hcwPP2)
DRV - [2006/08/23 15:16:07 | 000,006,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sysid.sys -- (sysid)
DRV - [2006/07/14 00:02:22 | 000,013,696 | ---- | M] (SingleClick Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wsp_pkt.sys -- (wsppkt)
DRV - [2006/07/14 00:01:16 | 000,013,824 | ---- | M] (SingleClick Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hnm_wrls_pkt.sys -- (hnmwrlspkt)
DRV - [2006/07/14 00:00:58 | 000,013,440 | ---- | M] (SingleClick Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\packet.sys -- (Packet)
DRV - [2005/11/18 11:02:50 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/11/18 11:02:10 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005/11/16 14:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2005/11/07 04:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/11/07 04:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/11/07 04:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/11/07 04:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/11/07 04:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2004/08/18 03:25:28 | 000,014,080 | ---- | M] (Roxio) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\MRFilter.sys -- (MrFilter)
DRV - [2004/08/18 03:25:20 | 000,200,704 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\udfreadr.sys -- (UdfReadr)
DRV - [2003/11/17 14:59:20 | 000,212,224 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2003/11/17 14:58:02 | 000,680,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2003/11/17 14:56:26 | 001,042,432 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2003/08/15 12:59:12 | 000,148,338 | ---- | M] (GlobespanVirata Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gwausb.sys -- (wanusb)
DRV - [1999/09/10 12:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (ASPI32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.live.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\ollie\Local Settings\Application Data\Google\Update\1.3.21.93\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\ollie\Local Settings\Application Data\Google\Update\1.3.21.93\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\FlashCatch\firefox [2011/10/21 16:47:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012/01/06 16:50:28 | 000,000,000 | ---D | M]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\ollie\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin8.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\ollie\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\ollie\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 4.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\ollie\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1487.6512\npCIDetect13.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\ollie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\ollie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Gmail = C:\Documents and Settings\ollie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
O1 HOSTS File: ([2011/12/31 00:47:23 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (FlashCatch) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - C:\Program Files\FlashCatch\flashcatch.dll (Level 9 Technology, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (no name) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (FlashCatch) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - C:\Program Files\FlashCatch\flashcatch.dll (Level 9 Technology, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe (Adobe Sytems Incorporated)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe (GlobespanVirata, Inc.)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\GFI Software\VIPRE\SBAMTray.exe (GFI Software)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Spyder3Utility.lnk = C:\Program Files\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: GreyMSIAds = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Internet)
O15 - HKCU\..Trusted Domains: sunbeltsoftware.com ([www] https in Trusted sites)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9DD82859-DBB4-4AD4-8987-0CD542E2D2A6}: NameServer = 194.72.9.34 217.32.171.22
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\ollie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\ollie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/27 22:06:43 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/10 11:36:41 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\ollie\Recent
[2012/01/10 11:24:22 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ollie\Desktop\OTL.exe
[2012/01/10 03:37:09 | 000,000,000 | ---D | C] -- C:\ERDNT
[2012/01/10 03:37:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2012/01/10 03:37:02 | 000,000,000 | ---D | C] -- C:\!FixIEDef
[2012/01/10 03:35:57 | 001,093,459 | ---- | C] (Zoll Technologies) -- C:\Documents and Settings\ollie\Desktop\FixIEDef.exe
[2012/01/09 14:02:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ollie\My Documents\ForceField Shared Files
[2012/01/09 13:43:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ollie\Application Data\Malwarebytes
[2012/01/09 13:43:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/01/06 16:50:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Check Point
[2012/01/03 16:07:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\CheckPoint
[2011/12/31 13:16:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/12/31 04:39:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GFI Software
[2011/12/31 04:39:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\VDD
[2011/12/31 04:29:37 | 011,520,880 | ---- | C] (GFI Software) -- C:\Documents and Settings\ollie\Desktop\setup-vipre-antivirus-en-us.exe
[2011/12/31 01:38:32 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/12/31 00:54:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/12/31 00:17:01 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/12/30 22:07:07 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2011/12/25 23:25:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{BD8912D9-3040-46C4-B96A-4C3AC7E43486}
[2011/12/25 23:24:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ollie\Local Settings\Application Data\PackageAware
[2011/12/25 07:36:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ollie\My Documents\kurtnilsen
[2004/12/13 07:57:36 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\RCCOLLAB.DLL
[2002/01/14 17:30:34 | 021,823,560 | ---- | C] (Microsoft) -- C:\Program Files\dotnetfx.exe
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/10 12:56:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/10 12:54:00 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2012/01/10 12:32:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-861567501-682003330-1003UA.job
[2012/01/10 11:24:27 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ollie\Desktop\OTL.exe
[2012/01/10 11:10:55 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/10 03:36:08 | 001,093,459 | ---- | M] (Zoll Technologies) -- C:\Documents and Settings\ollie\Desktop\FixIEDef.exe
[2012/01/09 18:47:32 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/09 18:46:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/08 23:32:00 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-861567501-682003330-1003Core.job
[2012/01/04 22:32:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/03 16:13:00 | 000,415,915 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2012/01/01 19:30:51 | 000,187,526 | ---- | M] () -- C:\Documents and Settings\ollie\My Documents\cc_20120101_193010.reg
[2011/12/31 04:49:32 | 002,127,560 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/31 04:39:14 | 000,001,752 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VIPRE.lnk
[2011/12/31 04:29:37 | 011,520,880 | ---- | M] (GFI Software) -- C:\Documents and Settings\ollie\Desktop\setup-vipre-antivirus-en-us.exe
[2011/12/31 00:47:23 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/31 00:17:08 | 000,000,325 | RHS- | M] () -- C:\boot.ini
[2011/12/30 17:22:13 | 000,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\WINDOWS\System32\IoctlSvc(2).exe
[2011/12/28 20:43:56 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/03 16:09:40 | 000,415,915 | ---- | C] () -- C:\WINDOWS\System32\vsconfig.xml
[2012/01/01 19:30:15 | 000,187,526 | ---- | C] () -- C:\Documents and Settings\ollie\My Documents\cc_20120101_193010.reg
[2011/12/31 04:39:14 | 000,001,752 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VIPRE.lnk
[2011/12/31 00:17:08 | 000,000,279 | ---- | C] () -- C:\Boot.bak
[2011/11/13 14:05:49 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2011/07/31 18:31:38 | 003,854,848 | ---- | C] () -- C:\WINDOWS\System32\ffmpeg.dll
[2011/07/19 19:08:04 | 000,074,752 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2011/07/19 19:06:48 | 000,259,584 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2011/07/19 19:06:36 | 000,158,208 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2011/07/19 19:06:34 | 001,524,224 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2011/07/19 19:06:34 | 000,096,768 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2011/07/19 19:06:32 | 000,145,920 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2011/07/19 19:06:30 | 000,136,704 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2011/07/19 19:06:30 | 000,113,664 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2011/07/19 19:06:28 | 000,327,680 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2011/07/19 19:06:28 | 000,211,456 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2011/05/30 13:42:50 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/05/23 07:46:30 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/03/03 11:40:08 | 000,150,528 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
[2011/03/03 11:39:56 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
[2011/03/03 11:39:46 | 000,141,824 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
[2011/03/03 11:39:34 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
[2011/03/03 11:39:02 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\dsmux.exe
[2011/03/03 11:38:54 | 000,154,112 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2011/03/03 11:38:40 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
[2011/03/03 11:38:10 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
[2011/03/03 11:38:04 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\mkv2vfr.exe
[2011/03/03 11:37:50 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
[2011/03/03 11:37:40 | 000,358,400 | ---- | C] () -- C:\WINDOWS\System32\gdsmux.exe
[2011/03/03 11:35:32 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
[2011/03/03 11:35:26 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
[2010/08/18 19:56:38 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini
[2010/04/12 08:12:24 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\Spyder3.sys
[2009/12/02 18:58:59 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2009/12/02 18:58:53 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/12/02 18:58:52 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/12/02 18:58:52 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/12/02 18:58:52 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/11/07 02:11:39 | 000,782,336 | ---- | C] () -- C:\WINDOWS\System32\IlmImf.dll
[2009/11/07 02:11:39 | 000,353,280 | ---- | C] () -- C:\WINDOWS\System32\pmtf2.dll
[2009/11/07 02:11:39 | 000,229,376 | ---- | C] () -- C:\WINDOWS\System32\PhotomatixLib2.dll
[2009/11/07 02:11:39 | 000,216,064 | ---- | C] () -- C:\WINDOWS\System32\pmjp.dll
[2009/11/07 02:11:39 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\pmtf1.dll
[2009/11/07 02:11:39 | 000,204,288 | ---- | C] () -- C:\WINDOWS\System32\pmtf3.dll
[2009/11/07 02:11:39 | 000,112,128 | ---- | C] () -- C:\WINDOWS\System32\PhotomatixLib3.dll
[2009/11/07 02:11:39 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\pmexr.dll
[2009/11/07 02:11:39 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmbm.dll
[2009/11/07 02:11:38 | 000,271,872 | ---- | C] () -- C:\WINDOWS\System32\PhotomatixLib.dll
[2009/10/02 22:18:05 | 000,000,140 | ---- | C] () -- C:\Documents and Settings\ollie\Application Data\default.pls
[2009/10/01 00:51:07 | 000,004,767 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2009/08/11 21:21:26 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\ac3config.exe
[2009/08/11 21:21:20 | 001,021,440 | ---- | C] () -- C:\WINDOWS\System32\ac3filter_intl.dll
[2009/07/12 02:39:37 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\AVERM.dll
[2009/07/12 02:39:36 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll
[2009/07/08 10:16:38 | 000,066,048 | R--- | C] () -- C:\WINDOWS\System32\hcwXDS.dll
[2009/05/25 04:08:38 | 000,009,728 | ---- | C] () -- C:\WINDOWS\System32\Native.exe
[2009/05/18 21:45:58 | 000,000,264 | ---- | C] () -- C:\WINDOWS\reimage.ini
[2009/05/02 22:03:48 | 001,380,403 | ---- | C] () -- C:\WINDOWS\System32\avgsdk.dll
[2009/04/03 13:10:04 | 007,262,208 | ---- | C] () -- C:\WINDOWS\System32\tliadjust32.dll
[2008/11/06 15:37:32 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/05/26 20:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/01/03 16:30:49 | 000,000,223 | ---- | C] () -- C:\WINDOWS\HP PrecisionScan Pro.INI
[2008/01/03 14:40:33 | 000,000,113 | ---- | C] () -- C:\WINDOWS\PhotoImpression.ini
[2007/12/14 12:20:18 | 000,000,023 | ---- | C] () -- C:\WINDOWS\DownloadStudio.INI
[2007/10/03 01:35:07 | 000,178,870 | ---- | C] () -- C:\Program Files\detours.lib
[2007/10/03 01:35:07 | 000,110,592 | ---- | C] () -- C:\Program Files\detours.pdb
[2007/10/03 01:35:07 | 000,098,551 | ---- | C] () -- C:\Program Files\libmpeg2.cpp
[2007/10/03 01:35:07 | 000,055,512 | ---- | C] () -- C:\Program Files\Mpeg2DecFilter.cpp
[2007/10/03 01:35:07 | 000,051,263 | ---- | C] () -- C:\Program Files\DSUtil.cpp
[2007/10/03 01:35:07 | 000,042,382 | ---- | C] () -- C:\Program Files\a_yuv2rgb.asm
[2007/10/03 01:35:07 | 000,025,367 | ---- | C] () -- C:\Program Files\vd.cpp
[2007/10/03 01:35:07 | 000,011,675 | ---- | C] () -- C:\Program Files\libmpeg2.h
[2007/10/03 01:35:07 | 000,011,046 | ---- | C] () -- C:\Program Files\MediaTypes.cpp
[2007/10/03 01:35:07 | 000,010,091 | ---- | C] () -- C:\Program Files\idct_mmx.obj
[2007/10/03 01:35:07 | 000,008,998 | ---- | C] () -- C:\Program Files\motion_comp_mmx.obj
[2007/10/03 01:35:07 | 000,008,870 | ---- | C] () -- C:\Program Files\PropertyPageSettings.cpp
[2007/10/03 01:35:07 | 000,007,342 | ---- | C] () -- C:\Program Files\Mpeg2DecFilter.h
[2007/10/03 01:35:07 | 000,007,071 | ---- | C] () -- C:\Program Files\DSUtil.h
[2007/10/03 01:35:07 | 000,006,723 | ---- | C] () -- C:\Program Files\GPL MPEG Decoder.vcproj
[2007/10/03 01:35:07 | 000,005,974 | ---- | C] () -- C:\Program Files\Mpeg2DecFilter.rc
[2007/10/03 01:35:07 | 000,004,327 | ---- | C] () -- C:\Program Files\moreuuids.h
[2007/10/03 01:35:07 | 000,002,923 | ---- | C] () -- C:\Program Files\Mpeg2DecFilterInterface.h
[2007/10/03 01:35:07 | 000,002,623 | ---- | C] () -- C:\Program Files\PropertyPageAbout.cpp
[2007/10/03 01:35:07 | 000,002,499 | ---- | C] () -- C:\Program Files\vd.h
[2007/10/03 01:35:07 | 000,002,022 | ---- | C] () -- C:\Program Files\NoDeCSSInputPin.cpp
[2007/10/03 01:35:07 | 000,002,019 | ---- | C] () -- C:\Program Files\PropertyPage.h
[2007/10/03 01:35:07 | 000,001,380 | ---- | C] () -- C:\Program Files\Mpeg2DecFilterUids.h
[2007/10/03 01:35:07 | 000,001,274 | ---- | C] () -- C:\Program Files\MediaTypes.h
[2007/10/03 01:35:07 | 000,001,145 | ---- | C] () -- C:\Program Files\stdafx.cpp
[2007/10/03 01:35:07 | 000,001,097 | ---- | C] () -- C:\Program Files\resource.h
[2007/10/03 01:35:07 | 000,000,153 | ---- | C] () -- C:\Program Files\Mpeg2DecFilter.def
[2007/10/03 01:35:06 | 000,021,251 | ---- | C] () -- C:\Program Files\detours.h
[2007/10/03 01:35:06 | 000,018,699 | ---- | C] () -- C:\Program Files\a_yuvtable.asm
[2007/10/03 01:35:06 | 000,001,527 | ---- | C] () -- C:\Program Files\stdafx.h
[2007/10/03 01:35:06 | 000,001,053 | ---- | C] () -- C:\Program Files\DeCSSInputPin.h
[2007/04/04 16:10:14 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\CNMVS3m.DLL
[2007/01/22 08:11:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\ArmAccess.dll
[2006/12/13 01:32:01 | 000,001,759 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/11/07 20:39:21 | 005,115,780 | ---- | C] () -- C:\Program Files\RawShooterEssentials.exe
[2006/11/01 05:05:53 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/11/01 00:38:42 | 000,160,951 | ---- | C] () -- C:\WINDOWS\System32\drivers\gtipdsp_.bin
[2006/10/30 10:30:30 | 000,010,032 | ---- | C] () -- C:\WINDOWS\System32\drivers\SBTEDrv.sys
[2006/10/05 20:04:22 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/09/25 19:47:04 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2006/09/08 09:03:22 | 000,000,040 | ---- | C] () -- C:\WINDOWS\nero.INI
[2006/08/23 15:16:07 | 000,006,336 | ---- | C] () -- C:\WINDOWS\System32\drivers\sysid.sys
[2006/08/23 15:12:40 | 000,000,509 | ---- | C] () -- C:\WINDOWS\HistoryEradicator.ini
[2006/08/23 00:22:39 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
[2006/08/20 16:23:19 | 000,001,100 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2006/08/08 14:22:15 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2006/08/04 14:38:00 | 000,000,859 | ---- | C] () -- C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2006/08/03 11:52:28 | 000,096,768 | ---- | C] () -- C:\WINDOWS\SlantAdj.dll
[2006/08/03 11:52:28 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\epDPE.ini
[2006/08/03 11:52:00 | 000,000,022 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2006/08/03 11:51:59 | 000,030,605 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2006/08/03 11:51:59 | 000,027,030 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2006/08/03 11:50:43 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE CX3600E.ini
[2006/07/31 14:02:28 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2006/07/28 23:54:13 | 000,022,528 | ---- | C] () -- C:\Documents and Settings\ollie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/07/28 14:36:05 | 000,000,338 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2006/07/28 02:08:12 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\ollie\Local Settings\Application Data\fusioncache.dat
[2006/07/28 02:08:04 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2006/07/27 22:54:05 | 000,057,600 | ---- | C] () -- C:\WINDOWS\System32\drivers\redbook.sys
[2006/07/27 22:52:27 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/07/27 22:51:26 | 002,127,560 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/07/27 22:44:31 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2006/07/27 22:42:50 | 000,160,963 | ---- | C] () -- C:\WINDOWS\System32\drivers\gtipdsp.bin
[2006/07/27 22:42:50 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\CoInst.dll
[2006/07/27 22:42:45 | 000,016,926 | ---- | C] () -- C:\WINDOWS\wwdslcfg.ini
[2006/07/27 22:09:45 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/07/27 22:02:58 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/03/04 04:52:00 | 000,088,576 | ---- | C] () -- C:\WINDOWS\System32\OptimFROG.dll
[2005/11/02 10:39:16 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\SDelete.dll
[2005/11/02 10:39:16 | 000,024,924 | ---- | C] () -- C:\WINDOWS\System32\openports.dll
[2005/08/05 13:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/03/22 22:38:24 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005/03/22 22:38:24 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/11/29 15:43:20 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\sherlock2.exe
[2004/10/12 06:40:58 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2004/10/12 06:39:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2004/10/09 06:40:16 | 000,454,144 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2004/10/05 08:16:08 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2004/10/03 17:50:54 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/08/10 11:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 11:00:00 | 000,416,880 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 11:00:00 | 000,291,840 | ---- | C] () -- C:\WINDOWS\System32\sbe(2).dll
[2004/08/10 11:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 11:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 11:00:00 | 000,060,360 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 11:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 11:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 11:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 11:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/10 11:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/01/07 14:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/15 22:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2001/01/24 05:31:18 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\prntfix.exe
[2000/04/14 16:50:02 | 000,343,040 | ---- | C] () -- C:\WINDOWS\System32\Lffpx7.dll
[1998/06/11 14:08:06 | 000,095,232 | ---- | C] () -- C:\WINDOWS\System32\Lfkodak.dll
========== LOP Check ==========
[2011/10/29 15:46:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2011/03/04 19:04:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bFkEpPc06300
[2012/01/03 16:07:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CheckPoint
[2011/11/17 03:55:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GFI Software
[2011/10/29 13:44:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/11/29 12:41:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2009/03/17 23:11:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/06/28 13:30:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/06/11 11:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/08/13 04:54:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Phase One
[2011/10/29 13:43:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Premium
[2009/07/05 13:38:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegCure
[2008/09/06 19:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2012/01/05 11:32:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2006/12/02 02:14:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2006/08/03 11:54:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2009/10/22 15:27:36 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2010/02/17 03:24:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/12/25 23:25:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{BD8912D9-3040-46C4-B96A-4C3AC7E43486}
[2008/06/16 19:20:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Autodesk
[2011/10/29 15:46:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Babylon
[2011/10/29 21:21:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\BabylonToolbar
[2011/05/21 16:52:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2006/07/30 13:33:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Business Logic
[2006/07/29 00:26:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Canon
[2010/07/02 17:39:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\CheckPoint
[2007/12/22 11:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\DMCache
[2010/09/06 17:24:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\ePaperPress
[2009/03/20 17:25:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\FM Settings
[2011/11/17 03:56:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\GFI Software
[2008/12/27 16:19:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\GrabPro
[2008/10/02 16:41:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\HDRsoft
[2011/11/29 12:40:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\IObit
[2010/11/19 18:05:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Nik Software
[2006/08/05 16:31:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Opera
[2009/06/27 21:06:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Orbit
[2006/11/07 20:47:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Pixmantec
[2006/08/17 11:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Sereniti
[2007/04/14 01:54:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Smart Panel
[2009/08/29 17:17:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\StarBurn
[2008/09/08 21:10:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\Template
[2006/08/20 22:11:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ollie\Application Data\TuneUp Software
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 174 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D2F2F703
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >