I'm getting 3 error messages:
memory errors for svchost.exe
unable to create MoHlog.txt file
generic host process for Win32 Services encountered a problem and needs to close
There are no new icons in my taskbar.
I tried doing a system restore by going into safe mode with command prompt. I got a message saying that system restore cannot make your computer safe.
I was able to download and run SuperAntiSpyware (I do get icons for anything new I download). It found 452 cookies, trojans, viruses, etc. After that, I ran AVG, which found nothing.
I was able to run Malwarebytes by uninstalling the old one from program access in the start menu and downloading a new version. It found, I think, 68 problem files. I ran it again in safe mode and it found nothing. But when I restarted, my files were still hidden.
In the AVG vault (all from the WINDOWS\TEMP and temp file):
Trojan horse Generic26.BTDG
Trojan horse Generic_r.AHQ
some unknowns
some old stuff I thought I had deleted
In the Malwarebytes quarantine is one thing: Trojan.FakeAV from C:\System Volume Information\_restore{(long string of letters, numbers, and dashes)
After I ran OTL, transparent versions of all the previously hidden files appeared on my desktop, as well as icons for the files that are supposed to be hidden. I'm able to open them. I still can't go anywhere from the start menu.
Any help would be greatly appreciated.
OTL logfile created on: 1/19/2012 7:11:21 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Vinny\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.74 Gb Available Physical Memory | 37.24% Memory free
5.84 Gb Paging File | 3.32 Gb Available in Paging File | 56.85% Paging File free
Paging file location(s): C:\pagefile.sys 4092 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 441.96 Gb Total Space | 22.76 Gb Free Space | 5.15% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Computer Name: BANJO | User Name: Vinny | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/18 23:49:53 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vinny\Desktop\OTL.exe
PRC - [2011/12/24 17:50:16 | 000,981,680 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2011/12/19 00:27:43 | 000,869,216 | -H-- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe
PRC - [2011/12/19 00:27:41 | 000,892,768 | -H-- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2011/12/08 18:44:22 | 004,616,064 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2011/12/03 01:22:12 | 002,415,456 | -H-- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | -H-- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/11/03 12:06:56 | 002,152,152 | -H-- | M] (Lavasoft Limited) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/11/03 12:06:56 | 001,187,072 | -H-- | M] (Lavasoft Limited) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/10/12 05:25:22 | 004,433,248 | -H-- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/09/08 19:53:26 | 000,743,264 | -H-- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/15 05:21:40 | 000,337,760 | -H-- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/11 17:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2011/08/02 05:09:08 | 000,192,776 | -H-- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/04/14 10:25:41 | 000,924,632 | -H-- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/01/20 03:20:12 | 001,305,408 | -H-- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2010/09/10 13:52:06 | 002,326,920 | -H-- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
PRC - [2009/09/12 15:31:36 | 000,357,384 | -H-- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2009/09/12 15:30:48 | 005,048,488 | -H-- | M] (Acronis) -- C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
PRC - [2008/09/12 10:45:48 | 000,036,352 | -H-- | M] () -- C:\Program Files\Winamp\winampa.exe
PRC - [2008/05/07 16:13:00 | 004,314,464 | -H-- | M] (Symantec Corporation) -- C:\Program Files\Norton Ghost\Agent\VProSvc.exe
PRC - [2008/05/07 16:13:00 | 002,245,984 | -H-- | M] (Symantec Corporation) -- C:\Program Files\Norton Ghost\Agent\VProTray.exe
PRC - [2008/05/07 11:30:48 | 001,558,000 | -H-- | M] (Symantec) -- C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
PRC - [2006/05/16 22:15:10 | 000,071,288 | -H-- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
PRC - [2006/04/06 13:58:52 | 001,032,192 | -H-- | M] (Dell Inc) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2006/04/06 13:57:54 | 000,380,928 | -H-- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2006/03/22 23:13:46 | 001,591,808 | -H-- | M] (YourWare Solutions ) -- C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
PRC - [2006/01/02 16:41:22 | 000,045,056 | -H-- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2004/08/10 05:00:00 | 001,032,192 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/03/04 08:46:24 | 000,172,032 | -H-- | M] (HP) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
PRC - [2003/09/10 01:24:00 | 000,020,480 | -H-- | M] () -- C:\Program Files\NetWaiting\netwaiting.exe
========== Modules (No Company Name) ==========
MOD - [2012/01/19 16:58:11 | 000,052,736 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll
MOD - [2012/01/19 16:58:10 | 000,063,488 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
MOD - [2012/01/18 19:14:26 | 000,117,760 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
MOD - [2012/01/18 19:14:26 | 000,052,224 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
MOD - [2012/01/05 23:29:54 | 002,076,672 | -H-- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_749594a3\system.xml.dll
MOD - [2012/01/05 23:29:46 | 002,994,176 | -H-- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_76365581\system.windows.forms.dll
MOD - [2012/01/05 23:29:37 | 000,835,584 | -H-- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_cb18fa41\system.drawing.dll
MOD - [2012/01/05 23:29:33 | 001,929,216 | -H-- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_b5719552\system.dll
MOD - [2012/01/05 23:29:06 | 003,289,088 | -H-- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_b6c6067f\mscorlib.dll
MOD - [2012/01/05 23:27:39 | 001,335,296 | -H-- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2012/01/05 23:27:38 | 002,039,808 | -H-- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2012/01/05 23:27:36 | 001,245,184 | -H-- | M] () -- c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
MOD - [2012/01/05 23:27:34 | 000,323,584 | -H-- | M] () -- c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
MOD - [2012/01/05 23:27:33 | 000,368,640 | -H-- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
MOD - [2012/01/05 23:27:32 | 000,466,944 | -H-- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2012/01/05 23:27:31 | 001,216,512 | -H-- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2011/12/19 00:27:43 | 000,869,216 | -H-- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe
MOD - [2011/12/19 00:27:41 | 000,892,768 | -H-- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2011/11/03 12:06:56 | 000,591,232 | -H-- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\RPAPI.dll
MOD - [2011/11/03 12:06:56 | 000,430,568 | -H-- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\Viprebridge.dll
MOD - [2011/11/03 12:06:56 | 000,308,560 | -H-- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\Vipre.dll
MOD - [2011/05/24 16:21:24 | 006,271,136 | -H-- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/04/14 10:25:47 | 001,874,904 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2010/11/17 13:16:56 | 000,067,872 | -H-- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2009/06/15 09:50:44 | 000,093,696 | -H-- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2008/09/12 10:45:48 | 000,036,352 | -H-- | M] () -- C:\Program Files\Winamp\winampa.exe
MOD - [2006/04/06 13:59:08 | 000,073,728 | -H-- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
MOD - [2005/12/19 07:08:42 | 000,086,016 | -H-- | M] () -- C:\WINDOWS\system32\preflib.dll
MOD - [2005/12/19 07:08:30 | 000,757,760 | -H-- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
MOD - [2005/10/13 12:53:36 | 000,090,223 | -H-- | M] () -- C:\Program Files\Dell\QuickSet\preflibcl.dll
MOD - [2003/09/10 01:24:00 | 000,020,480 | -H-- | M] () -- C:\Program Files\NetWaiting\netwaiting.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/12/19 00:27:43 | 000,869,216 | -H-- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe -- (vToolbarUpdater)
SRV - [2011/11/03 12:06:56 | 002,152,152 | -H-- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2011/10/12 05:25:22 | 004,433,248 | -H-- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/08/11 17:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2011/08/02 05:09:08 | 000,192,776 | -H-- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011/04/20 23:52:44 | 000,655,624 | -H-- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/09/10 13:52:06 | 002,326,920 | -H-- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2009/09/12 15:31:30 | 000,660,520 | -H-- | M] (Acronis) [Auto | Stopped] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2008/05/07 16:13:00 | 004,314,464 | -H-- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Ghost\Agent\VProSvc.exe -- (Norton Ghost)
SRV - [2008/05/07 11:30:48 | 001,558,000 | -H-- | M] (Symantec) [On_Demand | Running] -- C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe -- (SymSnapService)
SRV - [2007/09/12 17:27:24 | 002,999,664 | -H-- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate)
SRV - [2007/03/07 14:47:46 | 000,076,848 | -H-- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2006/04/06 13:57:54 | 000,380,928 | -H-- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)
SRV - [2002/12/17 17:26:22 | 007,520,337 | -H-- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002/12/17 17:23:30 | 000,311,872 | -H-- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (MBAMSwissArmy)
DRV - [2011/11/03 12:06:56 | 000,064,512 | -H-- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2011/11/03 12:06:56 | 000,015,232 | -H-- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys -- (Lavasoft Kernexplorer)
DRV - [2011/10/07 05:23:48 | 000,230,608 | -H-- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011/10/04 05:21:42 | 000,016,720 | -H-- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/09/13 05:30:10 | 000,032,592 | -H-- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/08/08 05:08:58 | 000,040,016 | -H-- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/07/22 10:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011/07/12 15:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/07/11 00:14:38 | 000,295,248 | -H-- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/07/11 00:14:28 | 000,024,272 | -H-- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/07/11 00:14:28 | 000,023,120 | -H-- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/07/11 00:14:26 | 000,134,608 | -H-- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/05/04 23:31:47 | 000,218,688 | -H-- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2010/09/10 13:52:11 | 000,159,168 | -H-- | M] (Acronis) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afcdp.sys -- (afcdp)
DRV - [2010/09/10 13:51:59 | 000,902,432 | -H-- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\tdrpm251.sys -- (tdrpman251) Acronis Try&Decide and Restore Points filter (build 251)
DRV - [2010/09/10 13:51:56 | 000,570,016 | -H-- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2010/09/10 13:51:38 | 000,157,248 | -H-- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\snapman.sys -- (snapman)
DRV - [2010/03/30 23:00:00 | 000,027,760 | -H-- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt -- (EverestDriver)
DRV - [2008/05/07 11:30:54 | 000,137,952 | -H-- | M] (StorageCraft) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\symsnap.sys -- (symsnap)
DRV - [2008/01/19 19:12:42 | 000,128,104 | -H-- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2008/01/19 18:45:40 | 000,038,112 | -H-- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\v2imount.sys -- (v2imount)
DRV - [2008/01/19 18:40:16 | 000,015,088 | -H-- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vproeventmonitor.sys -- (VProEventMonitor)
DRV - [2007/02/25 11:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 15:07:28 | 000,004,736 | -H-- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/05/23 06:06:36 | 001,578,496 | -H-- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/03/24 15:34:30 | 001,156,648 | -H-- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2005/11/02 11:24:34 | 000,424,320 | -H-- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005/08/12 16:50:46 | 000,016,128 | -H-- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/08/05 08:32:16 | 000,045,312 | -H-- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/14 15:58:14 | 000,028,544 | -H-- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/07/14 14:28:38 | 000,307,968 | -H-- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/07/12 16:00:30 | 000,051,328 | -H-- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2004/09/20 11:44:48 | 000,005,652 | -H-- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bvrp_pci.sys -- (bvrp_pci)
DRV - [2004/08/10 05:00:00 | 000,040,320 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2004/08/10 05:00:00 | 000,012,160 | -H-- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\fsvga.sys -- (FsVga)
DRV - [2004/02/13 08:46:00 | 000,017,153 | -H-- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1060908
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1060908
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1060908
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "Bing"
FF - prefs.js..browser.search.order.1: "Bing"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1374
FF - prefs.js..extensions.enabledItems: [email protected]:2.0
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..keyword.URL: "http://isearch.avg.c...2:16&sap=ku&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/12/23 22:05:44 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\9.0.0.22\ [2011/12/19 00:27:57 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/04 02:24:44 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/04 02:25:01 | 000,000,000 | -H-D | M]
[2008/09/03 06:05:54 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Extensions
[2011/10/21 22:30:52 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Firefox\Profiles\3vdf3rxd.default\extensions
[2010/05/01 16:07:16 | 000,000,000 | -H-D | M] (Screengrab) -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Firefox\Profiles\3vdf3rxd.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2011/10/21 22:30:52 | 000,000,000 | -H-D | M] (Rikaichan) -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Firefox\Profiles\3vdf3rxd.default\extensions\{0AA9101C-D3C1-4129-A9B7-D778C6A17F82}
[2011/09/14 00:58:51 | 000,000,000 | -H-D | M] (StartNow Toolbar) -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Firefox\Profiles\3vdf3rxd.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2011/09/14 00:57:01 | 000,000,000 | -H-D | M] (Searchqu Toolbar) -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Firefox\Profiles\3vdf3rxd.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011/09/14 00:58:51 | 000,000,000 | -H-D | M] (DealPly) -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Firefox\Profiles\3vdf3rxd.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
[2011/09/17 01:52:39 | 000,000,000 | -H-D | M] (Rikaichan Japanese-English Dictionary File) -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Firefox\Profiles\3vdf3rxd.default\extensions\[email protected]
[2011/09/13 22:40:05 | 000,001,945 | -H-- | M] () -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Firefox\Profiles\3vdf3rxd.default\searchplugins\bing-zugo.xml
[2011/05/28 17:16:32 | 000,001,635 | -H-- | M] () -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Firefox\Profiles\3vdf3rxd.default\searchplugins\firefox-add-ons.xml
[2011/09/14 00:39:07 | 000,002,497 | -H-- | M] () -- C:\Documents and Settings\Vinny\Application Data\Mozilla\Firefox\Profiles\3vdf3rxd.default\searchplugins\SearchResults.xml
[2011/09/14 00:48:02 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2006/09/24 15:00:27 | 000,000,000 | -H-D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/07/04 00:19:34 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/12/19 00:27:57 | 000,000,000 | -H-D | M] (AVG Security Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\9.0.0.22
[2007/08/26 10:54:34 | 000,000,000 | -H-D | M] (Java Console) -- C:\PROGRA~1\MOZILL~1\EXTENSIONS\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2008/02/25 21:02:04 | 000,000,000 | -H-D | M] (Java Console) -- C:\PROGRA~1\MOZILL~1\EXTENSIONS\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/04/27 06:38:21 | 000,000,000 | -H-D | M] (Java Console) -- C:\PROGRA~1\MOZILL~1\EXTENSIONS\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/09/25 19:12:53 | 000,000,000 | -H-D | M] (Java Console) -- C:\PROGRA~1\MOZILL~1\EXTENSIONS\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2011/07/04 00:19:34 | 000,000,000 | -H-D | M] (Java Console) -- C:\PROGRA~1\MOZILL~1\EXTENSIONS\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/12/23 22:05:44 | 000,000,000 | -H-D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2011/07/04 00:19:16 | 000,000,000 | -H-D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/09/14 00:57:01 | 000,000,000 | -H-D | M] (DataMngr) -- C:\PROGRAM FILES\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/04/14 10:26:02 | 000,142,296 | -H-- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/06 10:37:19 | 000,091,552 | -H-- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/07/04 00:19:15 | 000,476,904 | -H-- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/12/19 06:57:38 | 000,310,272 | -H-- | M] () -- C:\Program Files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
[2009/11/06 10:37:20 | 000,091,552 | -H-- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/12/19 00:27:39 | 000,003,766 | -H-- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2009/01/08 11:22:08 | 000,004,212 | -H-- | M] () -- C:\Program Files\mozilla firefox\searchplugins\orbitsearch.xml
[2011/09/14 00:39:07 | 000,002,497 | -H-- | M] () -- C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
O1 HOSTS File: ([2004/08/10 04:00:00 | 000,000,734 | -H-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\9.0.0.22\AVG Secure Search_toolbar.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\9.0.0.22\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Norton Ghost 14.0] C:\Program Files\Norton Ghost\Agent\VProTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [ZoneAlarm Installer] C:\Program Files\CheckPoint\Install\Launcher.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [FreeRAM XP] C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions )
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netwaiting.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\Vinny\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: NoActiveDesktopChanges = [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: NoActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: NoSaveSettings = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: ClassicShell = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKCU\..Trusted Domains: erightsoft.net ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: free.fr ([gpl.download] * in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.3.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A49256A0-8EAE-4327-8DAA-A08019055890}: DhcpNameServer = 192.168.0.1 205.171.3.25
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\dimsntfy: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Vinny\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Vinny\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 03:43:04 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{7b0b78f1-0cbb-11dd-9ccb-0015c5494866}\Shell\Decrypt using DVD Decrypter\Command - "" = C:\Program Files\DVD Decrypter\DVDDecrypter.exe -- [2005/03/20 19:55:47 | 000,772,608 | -H-- | M] (LIGHTNING UK!)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: autotvol - (C:\WINDOWS\system32\autonet1.dll) - File not found
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/19 02:21:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/19 02:21:20 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/01/18 23:49:54 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Vinny\Desktop\OTL.exe
[2012/01/18 23:24:32 | 000,000,000 | ---D | C] -- C:\Program Files\CheckPoint
[2012/01/18 22:55:09 | 010,847,608 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Vinny\Desktop\mbam-setup-1.60.0.1800.com
[2012/01/18 19:14:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vinny\Application Data\SUPERAntiSpyware.com
[2012/01/18 19:12:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2012/01/18 19:12:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2012/01/18 19:12:08 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012/01/18 19:03:25 | 014,131,560 | ---- | C] (SUPERAntiSpyware.com) -- C:\Documents and Settings\Vinny\Desktop\SUPERAntiSpyware.exe
[2012/01/18 04:57:56 | 000,064,512 | -H-- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2012/01/18 04:57:29 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lavasoft
[2012/01/18 03:59:11 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/17 19:05:35 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2012/01/17 19:04:34 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2012/01/17 19:04:33 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/01/17 18:58:46 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2012/01/15 22:29:14 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Vinny\Desktop\Amok Time Fanmix
[2012/01/09 03:27:56 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Vinny\Desktop\Versus Video Games
[2012/01/09 03:27:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Vinny\Desktop\Dual Dragons
[2012/01/09 03:12:11 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Vinny\Desktop\VG Rocks
[2012/01/09 03:11:55 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Vinny\Desktop\Leg Vacuum
[2012/01/09 03:11:42 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Vinny\Desktop\CarboHydroM
[2012/01/08 05:49:18 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Vinny\Desktop\[Game - Soundtrack] Genso Suikoden Piano Collection ~Avertunerio Antes Lance Mao~
[2012/01/08 05:05:40 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Vinny\Desktop\[Game - Soundtrack] Genso Suikoden Orgel Collection
[2012/01/05 23:11:42 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Vinny\Desktop\dontletthemfoolyou
[2011/04/15 01:55:46 | 000,047,360 | -H-- | C] (VSO Software) -- C:\Documents and Settings\Vinny\Application Data\pcouffin.sys
[2007/05/20 05:31:42 | 000,061,440 | -H-- | C] (Freeware licensed under GPL) -- C:\Program Files\DGVfapi.vfp
[2007/03/15 23:29:16 | 000,781,992 | -H-- | C] (Beepa P/L) -- C:\Program Files\fraps.exe
[2007/03/15 23:27:30 | 000,118,784 | -H-- | C] (Beepa P/L) -- C:\Program Files\fraps.dll
[2007/03/15 23:27:16 | 000,122,880 | -H-- | C] (Beepa P/L) -- C:\Program Files\frapslcd.dll
[2006/12/21 23:01:46 | 000,057,856 | -H-- | C] (Beepa P/L) -- C:\Program Files\fraps64.dll
[2006/12/21 23:01:36 | 000,293,376 | -H-- | C] (Beepa P/L) -- C:\Program Files\fraps64.dat
[2006/11/17 16:18:00 | 000,120,320 | -H-- | C] ( ) -- C:\WINDOWS\System32\lagarith.dll
[7 C:\Documents and Settings\Vinny\My Documents\*.tmp files -> C:\Documents and Settings\Vinny\My Documents\*.tmp -> ]
[5 C:\Documents and Settings\Vinny\Desktop\*.tmp files -> C:\Documents and Settings\Vinny\Desktop\*.tmp -> ]
[42 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[1525 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/19 18:51:00 | 000,358,315 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/01/19 16:56:14 | 000,000,278 | -H-- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-46722641-3523488381-3589522040-1006.job
[2012/01/19 16:56:13 | 000,000,378 | -H-- | M] () -- C:\WINDOWS\tasks\Registry Reviver-Vinny-Startup.job
[2012/01/19 16:56:12 | 087,064,782 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/01/19 16:53:57 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/19 16:49:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/19 06:28:49 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat
[2012/01/19 06:28:49 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat
[2012/01/19 06:28:40 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/01/19 02:21:22 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\Vinny\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/01/19 02:21:22 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/19 00:04:53 | 000,002,855 | ---- | M] () -- C:\Documents and Settings\Vinny\Desktop\Shortcut to mbam-setup-1.60.0.1800.com.pif
[2012/01/18 23:49:53 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vinny\Desktop\OTL.exe
[2012/01/18 22:56:11 | 010,847,608 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Vinny\Desktop\mbam-setup-1.60.0.1800.com
[2012/01/18 19:12:13 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/01/18 19:11:14 | 014,131,560 | ---- | M] (SUPERAntiSpyware.com) -- C:\Documents and Settings\Vinny\Desktop\SUPERAntiSpyware.exe
[2012/01/18 04:45:41 | 012,021,760 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\Ad-Aware96Install.msi
[2012/01/17 20:02:34 | 000,000,397 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\51c5c6a8
[2012/01/17 19:20:40 | 000,030,022 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\tumblr_lxke96fCtb1qf9gcq.jpg
[2012/01/13 23:04:01 | 079,836,741 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\No Path.zip
[2012/01/13 00:30:03 | 000,000,776 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\settings.config
[2012/01/12 00:06:42 | 000,194,086 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\TurboVote (Rachel Marie Anderson).pdf
[2012/01/10 01:10:34 | 066,727,368 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\prem1.avi
[2012/01/09 04:21:40 | 069,822,165 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\Genso Suikoden Piano Collection 2.rar
[2012/01/09 03:50:13 | 098,588,278 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\ET-SET.rar
[2012/01/09 03:46:09 | 057,393,968 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\ES-TCAC.rar
[2012/01/09 03:38:54 | 096,519,528 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\DWATRM-ITFR...LAA!.rar
[2012/01/09 03:31:29 | 023,870,054 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\DOE-BTM.rar
[2012/01/09 01:29:30 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/08 05:01:47 | 000,001,492 | -HS- | M] () -- C:\Documents and Settings\Vinny\Local Settings\Application Data\ld7057sr6ces33o40m367as3u5j3vxnxa721onvr0e57di
[2012/01/08 05:01:47 | 000,001,492 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\ld7057sr6ces33o40m367as3u5j3vxnxa721onvr0e57di
[2012/01/06 03:24:00 | 000,000,286 | -H-- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-46722641-3523488381-3589522040-1006.job
[2012/01/05 23:28:43 | 000,483,224 | -H-- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/05 23:28:43 | 000,089,446 | -H-- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/01/05 01:29:27 | 000,081,408 | -H-- | M] () -- C:\Documents and Settings\Vinny\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/05 00:19:17 | 000,000,077 | -H-- | M] () -- C:\WINDOWS\huffyuv.ini
[2011/12/31 04:06:46 | 000,000,114 | -H-- | M] () -- C:\WINDOWS\CIV.INI
[2011/12/27 01:29:25 | 036,464,060 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\comeon-divx.zip
[2011/12/23 22:28:03 | 085,207,351 | -H-- | M] () -- C:\Documents and Settings\Vinny\Desktop\Dream Within v2.wmv
[7 C:\Documents and Settings\Vinny\My Documents\*.tmp files -> C:\Documents and Settings\Vinny\My Documents\*.tmp -> ]
[5 C:\Documents and Settings\Vinny\Desktop\*.tmp files -> C:\Documents and Settings\Vinny\Desktop\*.tmp -> ]
[1525 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/19 02:21:22 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\Vinny\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/01/19 02:21:22 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/19 00:04:53 | 000,002,855 | ---- | C] () -- C:\Documents and Settings\Vinny\Desktop\Shortcut to mbam-setup-1.60.0.1800.com.pif
[2012/01/18 22:13:38 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2012/01/18 22:13:38 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2012/01/18 19:12:13 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/01/18 04:44:54 | 012,021,760 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\Ad-Aware96Install.msi
[2012/01/17 20:02:33 | 000,000,422 | -H-- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\1ee5aec9
[2012/01/17 20:02:33 | 000,000,406 | -H-- | C] () -- C:\Documents and Settings\NetworkService\Application Data\c0a48891
[2012/01/17 20:02:33 | 000,000,397 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\51c5c6a8
[2012/01/17 19:20:40 | 000,030,022 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\tumblr_lxke96fCtb1qf9gcq.jpg
[2012/01/13 22:55:07 | 079,836,741 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\No Path.zip
[2012/01/12 00:06:45 | 000,194,086 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\TurboVote (Rachel Marie Anderson).pdf
[2012/01/10 00:56:56 | 066,727,368 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\prem1.avi
[2012/01/09 04:09:11 | 069,822,165 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\Genso Suikoden Piano Collection 2.rar
[2012/01/09 03:40:24 | 098,588,278 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\ET-SET.rar
[2012/01/09 03:40:09 | 057,393,968 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\ES-TCAC.rar
[2012/01/09 03:29:22 | 096,519,528 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\DWATRM-ITFR...LAA!.rar
[2012/01/09 03:28:56 | 023,870,054 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\DOE-BTM.rar
[2012/01/08 05:01:40 | 000,001,492 | -HS- | C] () -- C:\Documents and Settings\Vinny\Local Settings\Application Data\ld7057sr6ces33o40m367as3u5j3vxnxa721onvr0e57di
[2012/01/08 05:01:40 | 000,001,492 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\ld7057sr6ces33o40m367as3u5j3vxnxa721onvr0e57di
[2012/01/08 01:55:11 | 000,227,328 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\MTPAxe.exe
[2012/01/08 01:44:03 | 000,000,776 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\settings.config
[2012/01/05 22:56:41 | 033,105,844 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\clearthearea-astarte.avi
[2011/12/27 01:11:41 | 036,464,060 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\comeon-divx.zip
[2011/12/23 22:11:14 | 085,207,351 | -H-- | C] () -- C:\Documents and Settings\Vinny\Desktop\Dream Within v2.wmv
[2011/04/15 01:55:46 | 000,087,608 | -H-- | C] () -- C:\Documents and Settings\Vinny\Application Data\inst.exe
[2011/04/15 01:55:46 | 000,007,887 | -H-- | C] () -- C:\Documents and Settings\Vinny\Application Data\pcouffin.cat
[2011/04/15 01:55:46 | 000,001,144 | -H-- | C] () -- C:\Documents and Settings\Vinny\Application Data\pcouffin.inf
[2010/11/11 00:02:23 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\PowerReg.dat
[2010/11/01 22:50:17 | 000,000,114 | -H-- | C] () -- C:\WINDOWS\CIV.INI
[2010/10/29 02:30:36 | 000,791,112 | -H-- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/09/19 02:33:39 | 000,695,642 | -H-- | C] () -- C:\WINDOWS\unins001.exe
[2010/09/19 02:33:39 | 000,001,783 | -H-- | C] () -- C:\WINDOWS\unins001.dat
[2010/09/19 02:33:15 | 000,695,642 | -H-- | C] () -- C:\WINDOWS\unins000.exe
[2010/09/19 02:33:15 | 000,001,142 | -H-- | C] () -- C:\WINDOWS\unins000.dat
[2010/09/09 18:34:36 | 000,215,144 | RH-- | C] () -- C:\WINDOWS\patchw32.dll
[2010/09/09 18:32:50 | 000,215,144 | RH-- | C] () -- C:\WINDOWS\pw32a.dll
[2010/09/05 14:17:12 | 000,139,264 | -H-- | C] () -- C:\WINDOWS\System32\utvideo.dll
[2010/06/19 03:00:00 | 000,000,279 | -H-- | C] () -- C:\Documents and Settings\Vinny\Application Data\.thetimelineproj.cfg
[2010/05/27 21:24:03 | 000,028,624 | -H-- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2010/05/25 22:53:49 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\Vinny\Application Data\czyiwa.dat
[2010/05/25 18:31:48 | 000,000,104 | -HS- | C] () -- C:\WINDOWS\WSYS049.SYS
[2010/04/01 01:31:27 | 001,866,670 | -H-- | C] () -- C:\WINDOWS\System32\libfftw3f-3.dll
[2010/04/01 00:35:41 | 002,371,760 | -H-- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe
[2010/04/01 00:35:41 | 000,002,190 | -H-- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpoweramp Renaissance uPlayer.dat
[2010/02/09 19:37:31 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Vinny\Local Settings\Application Data\prvlcl.dat
[2009/11/30 14:51:19 | 000,001,572 | -H-- | C] () -- C:\Documents and Settings\Vinny\Application Data\home_budget_lite.ini
[2009/08/25 22:43:24 | 000,005,652 | -H-- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2009/08/17 17:16:10 | 000,122,880 | -H-- | C] () -- C:\WINDOWS\System32\avsfilter.dll
[2009/08/17 17:16:10 | 000,061,440 | -H-- | C] () -- C:\WINDOWS\System32\LoadPluginEx.dll
[2009/08/17 17:16:09 | 000,188,416 | -H-- | C] () -- C:\WINDOWS\System32\warpsharp.dll
[2009/08/17 16:46:52 | 001,627,136 | -H-- | C] () -- C:\WINDOWS\System32\fftw3.dll
[2009/07/23 23:43:45 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/06/26 05:55:39 | 000,000,600 | -H-- | C] () -- C:\Documents and Settings\Vinny\Local Settings\Application Data\PUTTY.RND
[2008/09/30 22:05:54 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\Irremote.ini
[2008/09/26 19:58:57 | 000,000,069 | -H-- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/09/04 14:48:53 | 000,000,024 | -H-- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/09/03 16:04:12 | 000,237,568 | -H-- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
[2008/08/06 19:52:58 | 000,000,048 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008/06/27 20:44:18 | 000,035,365 | -H-- | C] () -- C:\WINDOWS\System32\uninstHelixYUV.exe
[2008/06/27 20:42:00 | 000,815,104 | -H-- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/06/27 20:42:00 | 000,180,224 | -H-- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/01/15 19:44:58 | 000,002,296 | -H-- | C] () -- C:\WINDOWS\hpdj5700.ini
[2008/01/15 19:44:12 | 000,000,414 | -H-- | C] () -- C:\WINDOWS\hpbvspst.ini
[2008/01/10 22:54:32 | 000,000,038 | -H-- | C] () -- C:\WINDOWS\AviSplitter.INI
[2008/01/10 21:22:13 | 000,004,159 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\jexqjxsy.dne
[2007/05/28 13:22:42 | 000,022,701 | -H-- | C] () -- C:\Program Files\uninstall.exe
[2007/05/17 21:42:11 | 000,000,552 | -H-- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2007/03/27 16:39:20 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\Vinny\Local Settings\Application Data\CF0F9240.DAT
[2007/03/27 16:39:20 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\CF0F9240.DAT
[2006/12/19 06:59:42 | 000,001,860 | -H-- | C] () -- C:\Program Files\README.HTM
[2006/10/22 21:30:26 | 000,057,856 | -H-- | C] () -- C:\WINDOWS\TADSUINS.EXE
[2006/10/22 16:16:56 | 000,000,067 | -H-- | C] () -- C:\WINDOWS\IDMan.INI
[2006/10/01 15:07:36 | 000,003,766 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/10/01 15:07:36 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\C67A36DCD6.sys
[2006/09/26 22:56:27 | 000,000,002 | -H-- | C] () -- C:\WINDOWS\msoffice.ini
[2006/09/26 03:00:22 | 000,000,039 | -H-- | C] () -- C:\WINDOWS\lagarith.ini
[2006/09/24 23:07:31 | 000,081,408 | -H-- | C] () -- C:\Documents and Settings\Vinny\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/24 15:00:17 | 000,003,691 | -H-- | C] () -- C:\WINDOWS\mozver.dat
[2006/09/14 00:32:21 | 000,000,128 | -H-- | C] () -- C:\Documents and Settings\Vinny\Local Settings\Application Data\fusioncache.dat
[2006/09/08 13:30:38 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2006/09/08 13:18:20 | 000,129,024 | -H-- | C] () -- C:\WINDOWS\UNWISE.EXE
[2006/09/08 13:17:18 | 000,053,248 | -H-- | C] () -- C:\WINDOWS\System32\pxhpinst.exe
[2006/09/08 13:15:32 | 000,000,402 | -H-- | C] () -- C:\WINDOWS\wininit.ini
[2006/09/08 13:14:16 | 000,000,335 | -H-- | C] () -- C:\WINDOWS\nsreg.dat
[2006/09/08 13:12:10 | 000,000,376 | -H-- | C] () -- C:\WINDOWS\ODBC.INI
[2006/09/08 13:09:05 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/09/08 12:42:26 | 000,049,152 | -H-- | C] () -- C:\WINDOWS\setpwrcg.exe
[2006/09/08 12:42:20 | 000,016,480 | -H-- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2006/09/08 12:42:17 | 000,127,614 | -H-- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/09/08 12:41:58 | 000,086,016 | -H-- | C] () -- C:\WINDOWS\System32\preflib.dll
[2006/09/08 12:41:58 | 000,018,944 | -H-- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2006/09/08 12:41:53 | 000,757,760 | -H-- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2006/09/08 12:40:47 | 000,000,390 | -H-- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/02/23 00:06:42 | 000,006,739 | -H-- | C] () -- C:\Program Files\QuickStart.html
[2005/09/15 16:40:22 | 000,160,768 | -H-- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005/08/16 03:48:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/08/16 03:38:45 | 000,034,380 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 03:37:24 | 000,001,793 | -H-- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 03:33:38 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/08/16 03:27:59 | 000,294,072 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/16 03:18:37 | 000,022,040 | -H-- | C] () -- C:\WINDOWS\System32\_004501_.tmp.dll
[2005/08/16 03:18:37 | 000,022,040 | -H-- | C] () -- C:\WINDOWS\System32\_004381_.tmp.dll
[2005/08/16 03:18:33 | 000,483,224 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005/08/16 03:18:33 | 000,089,446 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005/08/16 03:18:28 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
[2005/08/16 03:18:22 | 000,249,270 | -H-- | C] () -- C:\WINDOWS\System32\_004552_.tmp.dll
[2005/08/16 03:18:22 | 000,249,270 | -H-- | C] () -- C:\WINDOWS\System32\_004413_.tmp.dll
[2005/05/12 08:25:24 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\px.ini
[2005/03/22 16:38:24 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005/03/22 16:38:24 | 000,004,627 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/10 05:00:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 05:00:00 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 05:00:00 | 000,249,270 | -H-- | C] () -- C:\WINDOWS\System32\_005057_.tmp.dll
[2004/08/10 05:00:00 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 05:00:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 05:00:00 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 05:00:00 | 000,022,040 | -H-- | C] () -- C:\WINDOWS\System32\_005025_.tmp.dll
[2004/08/10 05:00:00 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 05:00:00 | 000,001,788 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/09 22:11:42 | 000,185,856 | -H-- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/01/27 06:13:54 | 000,421,888 | -H-- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2004/01/27 06:13:14 | 000,061,440 | -H-- | C] () -- C:\WINDOWS\System32\libfaac.dll
[2004/01/05 22:50:40 | 000,245,760 | -H-- | C] () -- C:\WINDOWS\System32\ImxEx.dll
[2003/01/07 14:05:08 | 000,002,695 | -H-- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/16 07:32:12 | 000,000,077 | -H-- | C] () -- C:\WINDOWS\huffyuv.ini
[2002/06/17 18:36:00 | 000,482,816 | -H-- | C] () -- C:\WINDOWS\System32\VFCodec.dll
========== LOP Check ==========
[2010/09/10 14:07:01 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Acronis
[2012/01/19 05:45:09 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012/01/18 23:06:20 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/04/25 17:19:20 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2011/09/14 00:39:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/03/14 17:49:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/21 01:16:23 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2005/08/16 19:54:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\DIGStream
[2009/04/08 00:46:54 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Maestro
[2012/01/19 16:57:21 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/10/14 03:05:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2008/03/07 20:16:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Otto
[2011/04/25 17:39:01 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Rosetta Stone
[2008/03/10 15:01:10 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2011/03/28 00:04:38 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2006/09/08 13:15:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/12/28 20:49:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/04/25 01:03:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/09/14 00:57:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{ACFC9F59-F1AE-43D2-8CFE-E2F1E0F82ABA}
[2011/12/06 23:19:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\.anki
[2010/01/06 18:54:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\.matplotlib
[2010/09/10 14:38:54 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Acronis
[2009/05/07 15:25:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Amazon
[2011/03/01 17:34:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\AnvSoft
[2011/09/24 17:22:17 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\AVG Secure Search
[2011/09/24 17:20:31 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\AVG2012
[2006/11/06 01:04:11 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\cYo
[2011/04/21 02:00:03 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\DAEMON Tools Lite
[2011/05/04 00:44:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\DeviceDoctorSoftware
[2007/06/04 16:48:37 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\DMCache
[2011/02/22 22:27:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\EurekaLog
[2010/04/24 21:42:41 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\FileZilla
[2010/06/22 01:47:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\FreeFLVConverter
[2011/02/16 23:35:20 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\GetRightToGo
[2008/07/23 16:22:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\GrabPro
[2012/01/10 03:58:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\gtk-2.0
[2009/10/29 03:17:33 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\ImgBurn
[2007/03/04 23:20:40 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Leadertech
[2008/06/16 10:20:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\LimeWire
[2009/09/23 04:31:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\MilkShape 3D 1.x.x
[2006/09/25 23:32:20 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\MPEG Streamclip
[2011/04/25 16:13:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\mplayer
[2006/09/26 23:27:37 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Opera
[2011/04/19 17:06:41 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Orbit
[2008/03/07 20:16:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Otto
[2010/12/27 17:10:00 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\ProgSense
[2006/11/30 20:27:49 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Publish Providers
[2011/04/09 00:31:56 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\RenPy
[2011/02/22 22:28:34 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\RiffTrax
[2011/09/14 00:57:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\searchqutoolbar
[2007/03/20 23:35:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Softplicity
[2008/01/01 15:55:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Sony
[2008/01/01 14:21:05 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Sony Setup
[2008/09/29 23:00:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\STOIK
[2008/04/17 11:22:27 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\TERMINAL Studio
[2011/12/09 06:16:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\uTorrent
[2006/10/01 17:20:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\VersionTracker Pro
[2011/09/17 01:20:41 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Vinny\Application Data\Vso
[2012/01/19 06:28:40 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2012/01/19 16:56:13 | 000,000,378 | -H-- | M] () -- C:\WINDOWS\Tasks\Registry Reviver-Vinny-Startup.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 362 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2C595FF3
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >