have been infected with Google redirect.
Used the guide on earlier threads and here is my Logs. Please advise if I need to go ahead with FixMBR on asmMBR or not, because when it comes up with a Warning that partition may become inaccessible.
Appreciate any help.
aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software
Run date: 2012-02-05 20:07:00
-----------------------------
20:07:00.453 OS Version: Windows 5.1.2600 Service Pack 3
20:07:00.453 Number of processors: 2 586 0xF06
20:07:00.453 ComputerName: YOUR-830BE02797 UserName: Alex
20:07:02.718 Initialize success
20:11:41.312 AVAST engine defs: 12020401
20:11:48.468 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
20:11:48.468 Disk 0 Vendor: Hitachi_HTS542512K9SA00 BB2OC31P Size: 114473MB BusType: 3
20:11:48.703 Disk 0 MBR read successfully
20:11:48.703 Disk 0 MBR scan
20:11:49.234 Disk 0 Windows XP default MBR code
20:11:49.250 Disk 0 Partition 1 80 (A) 0C FAT32 LBA MSDOS5.0 68684 MB offset 63
20:11:50.218 Disk 0 Partition - 00 0F Extended LBA 45786 MB offset 140665140
20:11:50.250 Disk 0 Partition 2 00 0B FAT32 MSWIN4.1 45786 MB offset 140665203
20:11:50.484 Disk 0 scanning sectors +234436545
20:11:50.515 Disk 0 scanning C:\WINDOWS\system32\drivers
20:14:05.656 Service scanning
20:14:14.750 Modules scanning
20:14:23.750 Disk 0 trace - called modules:
20:14:23.765 ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
20:14:23.765 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a75bab8]
20:14:23.765 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> [0x8a75c920]
20:14:23.765 5 PCTCore.sys[b9ead099] -> nt!IofCallDriver -> \Device\0000007e[0x8a7669e8]
20:14:23.765 7 ACPI.sys[b9f5f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a767940]
20:14:24.781 AVAST engine scan C:\WINDOWS
20:15:07.421 AVAST engine scan C:\WINDOWS\system32
20:20:09.921 File: C:\WINDOWS\system32\wmidx6.dll **INFECTED** Win32:Diller-E [Trj]
20:28:47.406 AVAST engine scan C:\WINDOWS\system32\drivers
20:30:17.390 AVAST engine scan C:\Documents and Settings\Alex
21:57:12.750 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Alex\My Documents\MBR.dat"
21:57:12.750 The log file has been saved successfully to "C:\Documents and Settings\Alex\My Documents\aswMBR.txt"
OTL log:
OTL logfile created on: 5/02/2012 8:11:39 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Alex\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 0.47 Gb Available Physical Memory | 23.63% Memory free
3.85 Gb Paging File | 2.04 Gb Available in Paging File | 53.04% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 67.06 Gb Total Space | 16.73 Gb Free Space | 24.95% Space Free | Partition Type: FAT32
Drive D: | 44.70 Gb Total Space | 14.60 Gb Free Space | 32.65% Space Free | Partition Type: FAT32
Computer Name: YOUR-830BE02797 | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/02/05 20:07:46 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Alex\My Documents\Downloads\OTL.exe
PRC - [2012/02/05 20:06:26 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Alex\My Documents\Downloads\aswMBR.exe
PRC - [2012/02/02 17:19:16 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/02/02 07:14:48 | 000,180,648 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.21.99\GoogleCrashHandler.exe
PRC - [2012/01/30 14:39:34 | 000,909,152 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
PRC - [2012/01/30 14:39:14 | 000,939,872 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2012/01/03 16:31:34 | 001,391,272 | ---- | M] (Ask) -- C:\Program Files\Ask.com\Updater\Updater.exe
PRC - [2011/12/04 13:28:36 | 000,246,112 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\ouc.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/10/10 06:23:34 | 000,973,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011/09/08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/24 20:04:14 | 013,830,960 | ---- | M] (JustVoip) -- C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe
PRC - [2011/08/15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/04/22 23:21:10 | 000,247,728 | ---- | M] (TomTom) -- D:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2011/03/15 02:27:28 | 000,271,712 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe
PRC - [2011/01/13 15:17:26 | 001,589,208 | ---- | M] (PC Tools) -- d:\Program Files\PC Tools Security\pctsGui.exe
PRC - [2010/11/19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) -- d:\Program Files\PC Tools Security\pctsSvc.exe
PRC - [2010/03/15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) -- d:\Program Files\PC Tools Security\pctsAuxs.exe
PRC - [2010/02/09 14:35:54 | 000,061,440 | ---- | M] () -- C:\Program Files\Crazy John's\Crazy John's Broadband\DetectWireless.exe
PRC - [2009/09/08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/14 10:12:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/14 10:12:14 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2008/02/19 15:33:16 | 000,033,136 | ---- | M] () -- C:\WINDOWS\ASScrPro.exe
PRC - [2008/01/29 17:38:32 | 000,583,048 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2007/09/10 15:12:44 | 000,069,632 | ---- | M] (Software 2000 Limited) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE
PRC - [2007/02/06 10:30:00 | 000,065,536 | R--- | M] (Cognizance Corporation) -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe
PRC - [2006/10/18 18:04:28 | 000,802,816 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2006/09/07 17:58:32 | 000,778,240 | ---- | M] () -- C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
PRC - [2006/08/23 07:22:14 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe
PRC - [2006/08/10 07:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
PRC - [2006/08/06 22:11:00 | 000,573,440 | ---- | M] (Motorola Inc.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
PRC - [2006/06/08 20:33:02 | 000,053,248 | ---- | M] (ASUSTeK Computer INC.) -- C:\Program Files\ASUS\ATK Media\DMedia.exe
PRC - [2006/06/01 14:02:54 | 000,491,520 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
PRC - [2006/05/30 10:28:20 | 000,811,008 | ---- | M] (ATK) -- C:\Program Files\ASUS\Splendid\ACMON.exe
PRC - [2006/05/16 11:42:52 | 001,777,664 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2006/04/07 17:36:46 | 000,290,816 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2006/03/13 23:30:16 | 000,593,920 | ---- | M] (Infineon Technologies AG) -- c:\Program Files\Infineon\Security Platform Software\SpTNA.exe
PRC - [2006/03/10 00:41:42 | 000,131,072 | ---- | M] (Infineon Technologies AG) -- c:\Program Files\Infineon\Security Platform Software\PSDrt.exe
PRC - [2006/02/21 15:20:54 | 000,180,224 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe
PRC - [2006/01/27 18:17:50 | 000,221,184 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
PRC - [2006/01/23 21:47:32 | 000,073,728 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
PRC - [2006/01/02 16:41:22 | 000,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2005/11/29 03:51:04 | 000,099,872 | ---- | M] (Infineon Technologies AG) -- c:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE
PRC - [2005/10/17 17:09:34 | 000,987,136 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe
PRC - [2005/07/06 15:43:42 | 000,155,648 | ---- | M] (ASUSTeK) -- C:\WINDOWS\system32\ACEngSvr.exe
========== Modules (No Company Name) ==========
MOD - [2012/02/02 17:19:14 | 001,911,768 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/01/30 14:39:34 | 000,909,152 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
MOD - [2012/01/30 14:39:14 | 000,939,872 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2011/12/04 13:28:40 | 002,415,104 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QtCore4.dll
MOD - [2011/12/04 13:28:40 | 001,148,416 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QtNetwork4.dll
MOD - [2011/12/04 13:28:40 | 000,398,336 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QtXml4.dll
MOD - [2011/12/04 13:28:40 | 000,384,512 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QueryStrategy.dll
MOD - [2011/12/04 13:28:38 | 000,043,008 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\libgcc_s_dw2-1.dll
MOD - [2011/12/04 13:28:38 | 000,011,362 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\mingwm10.dll
MOD - [2011/12/04 13:28:36 | 000,246,112 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\ouc.exe
MOD - [2011/10/14 07:03:04 | 008,522,400 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/03/15 02:27:28 | 000,271,712 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe
MOD - [2010/10/02 13:38:30 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_0a0bfb1b\mscorlib.dll
MOD - [2010/10/02 13:38:28 | 000,835,584 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_584b4caf\system.drawing.dll
MOD - [2010/10/02 13:38:24 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_d4e6da61\system.xml.dll
MOD - [2010/10/02 13:38:20 | 003,018,752 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_64abb3df\system.windows.forms.dll
MOD - [2010/10/02 13:38:14 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_9d87ef9c\system.dll
MOD - [2010/10/02 13:38:04 | 001,265,664 | ---- | M] () -- c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
MOD - [2010/10/02 13:38:04 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2010/08/30 16:05:52 | 000,157,656 | ---- | M] () -- d:\Program Files\PC Tools Security\NetworkLayer\PCTCFHook.dll
MOD - [2010/08/10 17:59:26 | 001,263,576 | ---- | M] () -- d:\Program Files\PC Tools Security\UserModeFileCache.dll
MOD - [2010/08/10 17:58:38 | 000,091,608 | ---- | M] () -- d:\Program Files\PC Tools Security\avengine\sdkBSCtrl.dll
MOD - [2010/02/09 14:35:54 | 000,061,440 | ---- | M] () -- C:\Program Files\Crazy John's\Crazy John's Broadband\DetectWireless.exe
MOD - [2008/02/19 15:33:16 | 000,033,136 | ---- | M] () -- C:\WINDOWS\ASScrPro.exe
MOD - [2008/02/19 14:49:48 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2008/02/19 14:49:48 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
MOD - [2008/02/19 14:49:46 | 002,052,096 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2008/02/19 14:49:46 | 000,466,944 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2008/02/19 14:49:46 | 000,323,584 | ---- | M] () -- c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
MOD - [2006/10/18 17:51:48 | 000,118,784 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2006/10/18 17:50:22 | 000,348,160 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\IntStngs.dll
MOD - [2006/09/07 17:58:32 | 000,778,240 | ---- | M] () -- C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
MOD - [2006/08/23 07:22:14 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe
MOD - [2006/08/10 07:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
MOD - [2006/05/17 16:39:26 | 000,028,672 | ---- | M] () -- C:\Program Files\ASUS\Asus MultiFrame\HookTitle.dll
MOD - [2006/02/21 15:20:54 | 000,180,224 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe
MOD - [2005/10/17 17:09:34 | 000,987,136 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe
MOD - [2005/07/29 11:05:16 | 000,049,152 | ---- | M] () -- C:\Program Files\ASUS\Splendid\GLCDdll.dll
MOD - [2005/07/22 21:30:20 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\TosCommAPI.dll
MOD - [2004/07/20 17:04:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\TosBtHcrpAPI.dll
MOD - [2004/05/27 19:13:10 | 000,057,344 | ---- | M] () -- C:\WINDOWS\ATK0100\CMSSC.dll
MOD - [1998/05/05 21:10:00 | 000,069,632 | R--- | M] () -- C:\WINDOWS\system32\ODMA32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (LiveUpdate Notice Ex)
SRV - File not found [Auto | Running] -- -- (HWDeviceService.exe)
SRV - [2012/01/30 14:39:34 | 000,909,152 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe -- (vToolbarUpdater)
SRV - [2011/12/04 13:28:36 | 000,246,112 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Crazy Johns Broadband\UpdateDog\ouc.exe -- (Crazy Johns Broadband. RunOuc)
SRV - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2010/11/19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) [Auto | Running] -- d:\Program Files\PC Tools Security\pctsSvc.exe -- (sdCoreService)
SRV - [2010/03/15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) [Auto | Running] -- d:\Program Files\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/09/08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2008/01/29 17:38:32 | 000,583,048 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -- (LiveUpdate Notice Service)
SRV - [2007/02/06 10:30:00 | 000,074,240 | R--- | M] (Cognizance Corporation) [Auto | Running] -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll -- (ASBroker)
SRV - [2006/06/21 03:14:00 | 000,131,584 | R--- | M] (Cognizance Corporation) [Auto | Running] -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASChnl.dll -- (ASChannel)
SRV - [2005/11/29 03:51:04 | 000,099,872 | ---- | M] (Infineon Technologies AG) [Auto | Running] -- c:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE -- (PersonalSecureDriveService)
========== Driver Services (SafeList) ==========
DRV - [2012/01/26 10:51:54 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/12/04 13:28:40 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2011/12/04 13:28:40 | 000,090,368 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - [2011/12/04 13:28:40 | 000,073,216 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2011/10/07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011/10/04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/09/13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/08/08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/07/11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/07/11 01:14:28 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/07/11 01:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/07/11 01:14:26 | 000,134,608 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/12/10 13:24:12 | 000,239,168 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2010/07/16 14:59:54 | 000,656,320 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pctEFA.sys -- (pctEFA)
DRV - [2010/07/16 14:59:54 | 000,338,880 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\pctDS.sys -- (pctDS)
DRV - [2009/02/17 12:19:44 | 000,057,672 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2008/04/14 04:56:50 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008/02/11 10:12:04 | 000,015,360 | R--- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NetMotCM.sys -- (ndiscm)
DRV - [2008/01/23 17:08:58 | 000,099,456 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bsusbser.sys -- (bsusbser)
DRV - [2006/10/24 06:28:46 | 001,777,664 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/10/19 09:29:22 | 000,012,544 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/08/08 23:15:14 | 001,116,544 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynMini.sys -- (SynMini)
DRV - [2006/08/08 23:15:14 | 000,007,808 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynScan.sys -- (SynScan)
DRV - [2006/08/06 22:13:50 | 000,980,608 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smserial.sys -- (smserial)
DRV - [2006/07/24 01:15:04 | 004,353,024 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/05/18 21:46:16 | 000,110,976 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (Tosrfbd)
DRV - [2006/05/16 10:14:00 | 000,023,496 | R--- | M] (Cognizance Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\itsdisk.sys -- (ItSDisk)
DRV - [2006/05/09 11:21:54 | 000,040,192 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2006/05/09 10:33:54 | 000,062,848 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfhid.sys -- (Tosrfhid)
DRV - [2006/04/19 13:57:44 | 000,047,488 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte)
DRV - [2006/03/16 10:45:12 | 000,037,632 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (Tosrfbnp)
DRV - [2006/03/15 10:52:40 | 000,052,864 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfsnd.sys -- (TosRfSnd) Bluetooth Audio Device (WDM)
DRV - [2006/01/24 10:45:56 | 000,034,944 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipswuio.sys -- (ipswuio)
DRV - [2005/11/29 03:50:58 | 000,036,768 | ---- | M] (Infineon Technologies AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\psd.sys -- (PersonalSecureDrive)
DRV - [2005/11/16 20:28:32 | 000,028,928 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/11/16 01:08:16 | 000,078,976 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTL8023xp)
DRV - [2005/11/01 17:54:50 | 000,051,584 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/10/20 20:19:34 | 000,036,352 | ---- | M] (Infineon Technologies AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ifxtpm.sys -- (IFXTPM)
DRV - [2005/08/01 16:45:08 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005/07/11 18:58:56 | 000,003,712 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\toshidpt.sys -- (toshidpt)
DRV - [2005/02/17 08:07:48 | 000,005,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)
DRV - [2005/01/06 13:42:42 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://my.ebay.com.a...MyeBay&guest=1"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: [email protected]:3.11.3.15590
FF - prefs.js..keyword.URL: "http://www.google.co...b=adawaretb&q="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@csi.business.gov.au/CsiPlugin: D:\Program Files\Common-Use Signing Interface\bin\npCsiPlugin.dll (Commonwealth Government of Australia)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/01/29 11:54:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\10.0.0.7\ [2012/01/30 14:39:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2008/02/23 14:04:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2008/02/23 14:04:44 | 000,000,000 | ---D | M]
[2008/08/28 19:38:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Extensions
[2009/11/23 20:26:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Extensions\[email protected]
[2008/02/23 14:04:56 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions
[2012/01/26 07:20:14 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/09 21:44:44 | 000,000,000 | ---D | M] (F5 Networks Host Plugin) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions\{DBBB3167-6E81-400f-BBFD-BD8921726F52}
[2012/01/26 20:01:18 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions\[email protected]
[2012/02/01 13:24:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-1.xml
[2011/11/24 20:18:58 | 000,002,571 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\askcom.xml
[2011/05/24 12:17:44 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-3.xml
[2011/05/25 18:54:38 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-4.xml
[2011/05/26 15:08:50 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-2.xml
[2011/05/29 09:22:04 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin.xml
[2008/02/23 14:04:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/01/30 14:39:48 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\10.0.0.7
[2012/01/29 11:54:52 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2012/02/02 17:19:16 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/07 03:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2009/11/07 03:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/18 05:14:28 | 000,002,149 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\adawaretb.xml
[2012/01/22 07:13:08 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
[2012/01/22 07:13:08 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/01/22 07:13:08 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/01/22 07:13:08 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/22 07:13:10 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/01/30 14:38:44 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
========== Chrome ==========
CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
O1 HOSTS File: ([2006/02/28 20:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (ASUS Security Protect Manager) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe (ATK)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ASUS Camera ScreenSaver] C:\WINDOWS\ASScrProlog.exe ()
O4 - HKLM..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe ()
O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\ASScrPro.exe ()
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe ()
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISTray] d:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe ()
O4 - HKLM..\Run: [ROC_roc_dec12] C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe ()
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe ()
O4 - HKCU..\Run: [JustVoip] C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe (JustVoip)
O4 - HKCU..\Run: [MyDetectWireless] C:\Program Files\Crazy John's\Crazy John's Broadband\DetectWireless.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [TomTomHOME.exe] d:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiFrame.lnk = C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe (ASUSTek Computer Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\Alex\Start Menu\Programs\Startup\fliptoast.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKCU\..Trusted Domains: servicestream.com.au ([secure] http in Trusted sites)
O15 - HKCU\..Trusted Domains: servicestream.com.au ([secure] https in Trusted sites)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} https://secure.servi...,2009,0514,2204 (F5 Networks Policy Agent Host Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 61.9.133.193 61.9.134.49
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95AF6966-FC6E-4CC2-8AA8-249EA40C37AF}: DhcpNameServer = 61.9.133.193 61.9.134.49
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll ()
O20 - AppInit_DLLs: (APSHook.dll) -C:\WINDOWS\System32\APSHook.dll (Cognizance Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IfxWlxEN: DllName - (IfxWlxEN.dll) - C:\WINDOWS\System32\IfxWlxEN.dll (Infineon Technologies AG)
O20 - Winlogon\Notify\OneCard: DllName - (c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll) - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll (Cognizance Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - (TPSvc.dll) - File not found
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/Alex/LOCALS~1/Temp/msohtml1/02/clip_image002.jpg
O24 - Desktop Components:1 () - file:///C:/DOCUME~1/Alex/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg
O24 - Desktop Components:2 () - file:///C:/DOCUME~1/Alex/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Components:3 (My Current Home Page) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/14 18:08:18 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2008/02/19 14:36:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2008/10/13 15:48:14 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{37bf6e5c-1e1f-11e1-babb-0019d2b2ccfb}\Shell - "" = AutoRun
O33 - MountPoints2\{37bf6e5c-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{37bf6e5c-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{37bf6e5e-1e1f-11e1-babb-0019d2b2ccfb}\Shell - "" = AutoRun
O33 - MountPoints2\{37bf6e5e-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{37bf6e5e-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{582e2a48-d812-11de-b52e-0019d2b2ccfb}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O33 - MountPoints2\{8715fb76-f5cf-11de-b572-001e2a609d39}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/05 10:16:32 | 000,656,320 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctEFA.sys
[2012/02/05 10:16:32 | 000,338,880 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctDS.sys
[2012/02/05 10:16:30 | 000,251,560 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2012/02/05 10:16:22 | 000,239,168 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2012/02/05 10:16:22 | 000,160,448 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2012/02/05 10:16:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2012/02/05 10:16:13 | 000,070,536 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2012/02/05 10:16:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\PC Tools
[2012/02/04 21:35:56 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/02/04 21:35:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2012/02/04 21:31:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Desktop\TDSSKiller
[2012/01/30 22:31:50 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/01/30 22:26:05 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/01/30 22:06:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/30 22:05:33 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Alex\Start Menu\Programs\Administrative Tools
[2012/01/30 14:39:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cache
[2012/01/29 14:49:22 | 000,000,000 | -HSD | C] -- C:\FOUND.024
[2012/01/29 12:26:38 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012/01/29 11:57:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\AVG2012
[2012/01/29 11:56:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2012/01/29 11:56:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\AVG Secure Search
[2012/01/29 11:56:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012/01/29 11:56:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search
[2012/01/29 11:56:01 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search
[2012/01/29 11:55:57 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/01/29 11:54:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/01/29 11:54:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2012/01/29 11:52:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2012/01/26 10:51:53 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/01/26 10:29:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\ZoomBrowser EX
[2012/01/26 10:27:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\My Documents\Canon Utilities
[2012/01/26 10:26:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\CANON INC
[2012/01/26 10:25:00 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2012/01/26 10:24:47 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2012/01/26 07:21:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Canon MyCameraFiles
[2012/01/26 07:20:28 | 000,000,000 | ---D | C] -- C:\Program Files\Canon
[2012/01/26 07:20:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2012/01/26 07:20:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2012/01/26 07:19:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC
[2012/01/26 07:17:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Canon
[2012/01/23 14:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2012/01/20 22:09:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\com.w3i.FlipToast
[2012/01/20 22:09:11 | 000,000,000 | ---D | C] -- C:\Program Files\fliptoast
[2012/01/20 22:09:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
========== Files - Modified Within 30 Days ==========
[2012/02/05 22:01:02 | 000,000,232 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/02/05 21:57:14 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Alex\My Documents\MBR.dat
[2012/02/05 20:20:02 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/05 16:09:48 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/05 16:09:42 | 000,000,302 | ---- | M] () -- C:\WINDOWS\tasks\BRNDHJI.job
[2012/02/05 16:09:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/05 16:09:34 | 2146,717,696 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/05 11:04:02 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2012/02/05 10:16:44 | 000,731,688 | ---- | M] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2012/02/05 09:18:56 | 088,181,301 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/05 08:39:22 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/02/05 08:39:06 | 000,000,440 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
[2012/02/04 21:34:56 | 000,512,992 | ---- | M] () -- C:\Documents and Settings\Alex\Desktop\sdasetup_revwire207(1).exe
[2012/02/04 16:45:06 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/02/02 22:12:16 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat
[2012/02/02 22:12:16 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat
[2012/02/01 12:01:30 | 000,000,606 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/01/30 22:24:58 | 000,119,296 | ---- | M] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/29 16:57:56 | 000,001,609 | ---- | M] () -- C:\WINDOWS\pstudio.ini
[2012/01/29 10:07:10 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\pixillionShakeIcon.job
[2012/01/28 23:58:44 | 000,071,634 | ---- | M] () -- C:\Documents and Settings\Alex\My Documents\ISO1.nri
[2012/01/26 10:51:54 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/01/26 07:22:06 | 000,000,543 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\DCSD Software Guide.lnk
[2012/01/26 07:22:00 | 000,000,555 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PowerShot S100 Camera User Guide.lnk
[2012/01/26 07:21:20 | 000,000,549 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Digital Photo Professional.lnk
[2012/01/26 07:20:24 | 000,000,679 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012/01/23 22:06:00 | 000,126,976 | RHS- | M] () -- C:\WINDOWS\System32\wmidx6.dll
[2012/01/23 14:18:22 | 000,000,523 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2012/01/23 14:17:04 | 021,073,936 | ---- | M] () -- C:\Documents and Settings\Alex\My Documents\vlc-1.1.11-win32.exe
[2012/01/21 17:41:22 | 000,000,556 | ---- | M] () -- C:\Documents and Settings\Alex\Start Menu\Programs\Startup\fliptoast.lnk
[2012/01/20 22:14:20 | 008,261,192 | ---- | M] () -- C:\Documents and Settings\Alex\Desktop\DSC_2570.jpeg
[2012/01/10 22:16:08 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
========== Files Created - No Company Name ==========
[2012/02/05 10:16:33 | 000,731,688 | ---- | C] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2012/02/05 09:18:54 | 088,181,301 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/04 21:35:14 | 000,512,992 | ---- | C] () -- C:\Documents and Settings\Alex\Desktop\sdasetup_revwire207(1).exe
[2012/01/29 11:56:19 | 000,000,606 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/01/26 11:37:41 | 000,091,584 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/01/26 07:22:04 | 000,000,543 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\DCSD Software Guide.lnk
[2012/01/26 07:22:00 | 000,000,555 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PowerShot S100 Camera User Guide.lnk
[2012/01/26 07:21:18 | 000,000,549 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Digital Photo Professional.lnk
[2012/01/26 07:20:22 | 000,000,679 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012/01/23 22:05:59 | 000,000,302 | ---- | C] () -- C:\WINDOWS\tasks\BRNDHJI.job
[2012/01/23 22:05:58 | 000,126,976 | RHS- | C] () -- C:\WINDOWS\System32\wmidx6.dll
[2012/01/23 14:18:20 | 000,000,523 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2012/01/23 14:16:45 | 021,073,936 | ---- | C] () -- C:\Documents and Settings\Alex\My Documents\vlc-1.1.11-win32.exe
[2012/01/20 22:29:11 | 000,000,282 | ---- | C] () -- C:\WINDOWS\tasks\pixillionShakeIcon.job
[2012/01/20 22:14:14 | 008,261,192 | ---- | C] () -- C:\Documents and Settings\Alex\Desktop\DSC_2570.jpeg
[2012/01/20 22:12:53 | 013,914,414 | ---- | C] () -- C:\Documents and Settings\Alex\Desktop\DSC_2570.NEF
[2012/01/20 22:09:40 | 000,000,556 | ---- | C] () -- C:\Documents and Settings\Alex\Start Menu\Programs\Startup\fliptoast.lnk
[2011/05/29 22:15:40 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2011/05/29 22:15:40 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2011/04/17 21:14:49 | 000,001,240 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\6082cmkajv5q4bt0
[2011/04/17 21:14:49 | 000,001,240 | -HS- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\6082cmkajv5q4bt0
[2011/04/13 22:24:17 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\housecall.guid.cache
[2011/04/10 10:07:36 | 000,008,744 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\o553q566703t0w537
[2011/04/10 10:07:36 | 000,008,744 | -HS- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\o553q566703t0w537
[2010/10/12 20:41:33 | 000,171,695 | ---- | C] () -- C:\WINDOWS\hphins34.dat
[2010/10/12 20:41:33 | 000,000,532 | ---- | C] () -- C:\WINDOWS\hphmdl34.dat
[2010/09/19 08:44:06 | 000,000,943 | ---- | C] () -- C:\WINDOWS\WirelessCard.INI
[2010/06/06 17:35:51 | 000,172,130 | ---- | C] () -- C:\WINDOWS\hphins34.dat.temp
[2010/06/06 17:35:50 | 000,000,532 | ---- | C] () -- C:\WINDOWS\hphmdl34.dat.temp
[2009/05/06 10:45:44 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\acovcnt.exe
[2009/02/19 21:42:02 | 000,000,208 | ---- | C] () -- C:\WINDOWS\EliteCentral.ini
[2008/10/14 08:26:06 | 000,003,839 | ---- | C] () -- C:\WINDOWS\System32\drivers\GETPADD.sys
[2008/07/26 23:19:44 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008/06/26 20:15:05 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\HPPLVS.dll
[2008/06/16 23:50:11 | 000,000,098 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI
[2008/06/16 23:36:14 | 000,000,024 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008/05/09 22:04:21 | 000,000,204 | ---- | C] () -- C:\WINDOWS\MYOBP.INI
[2008/05/09 22:04:21 | 000,000,119 | ---- | C] () -- C:\WINDOWS\SwDrvs.ini
[2008/05/09 22:04:21 | 000,000,041 | ---- | C] () -- C:\WINDOWS\MYOB.INI
[2008/05/09 22:04:08 | 000,000,343 | ---- | C] () -- C:\WINDOWS\10ed.ini
[2008/05/09 22:02:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\drvxl32.INI
[2008/05/09 22:02:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\drvwd32.INI
[2008/05/08 14:53:54 | 000,001,609 | ---- | C] () -- C:\WINDOWS\pstudio.ini
[2008/05/08 14:53:54 | 000,000,028 | ---- | C] () -- C:\WINDOWS\album.ini
[2008/05/08 14:53:54 | 000,000,021 | ---- | C] () -- C:\WINDOWS\Ps_setup.ini
[2008/03/22 06:30:08 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/03/04 14:11:00 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/03/01 19:44:51 | 000,119,296 | ---- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/26 12:08:42 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/02/23 18:49:17 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/02/23 18:37:07 | 000,001,597 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2008/02/23 14:04:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/02/23 12:54:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\tosOBEX.INI
[2008/02/23 12:53:33 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\fusioncache.dat
[2008/02/23 12:53:21 | 000,000,546 | ---- | C] () -- C:\WINDOWS\System32\ABF3JR.DAT
[2008/02/19 15:36:07 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/02/19 15:33:14 | 000,033,136 | ---- | C] () -- C:\WINDOWS\ASScrPro.exe
[2008/02/19 15:33:04 | 000,037,232 | ---- | C] () -- C:\WINDOWS\ASScrProlog.exe
[2008/02/19 15:33:02 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2008/02/19 15:05:05 | 000,987,136 | ---- | C] () -- C:\WINDOWS\System32\wcourier.exe
[2008/02/19 14:58:07 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008/02/19 14:58:07 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008/02/19 14:39:54 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2008/02/19 14:39:11 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/02/19 14:34:25 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/02/19 14:30:56 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/02/19 14:30:23 | 000,139,648 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/02/19 14:14:44 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2008/02/19 14:14:38 | 000,136,650 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2008/02/19 14:06:04 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\SynSvc_.exe
[2008/02/19 14:06:04 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynSam.sys
[2008/02/19 14:06:04 | 000,007,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynScan.sys
[2008/02/19 14:05:56 | 000,498,688 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynPin.sys
[2008/02/19 14:05:55 | 001,116,544 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynMini.sys
[2008/02/19 14:05:55 | 000,045,056 | ---- | C] () -- C:\WINDOWS\StkUnist.exe
[2008/02/19 14:05:55 | 000,028,800 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynCamd.sys
[2008/02/19 14:04:01 | 000,000,010 | ---- | C] () -- C:\WINDOWS\System32\ABLKSR.INI
[2008/02/19 14:03:53 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\ATKACPI.sys
[2007/11/28 04:26:10 | 000,438,272 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2007/07/26 12:01:50 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\hppatusg01.dll
[2006/08/17 10:55:17 | 000,007,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\MMIOPORT.SYS
[2006/08/17 10:55:17 | 000,002,538 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/08/17 10:54:47 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/08/17 10:54:45 | 000,442,896 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/08/17 10:54:45 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/08/17 10:54:45 | 000,072,308 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/08/17 10:54:45 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/08/17 10:54:43 | 000,004,487 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/08/17 10:54:39 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/08/17 10:54:38 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/08/17 10:54:35 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/08/17 10:54:35 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/08/17 10:54:32 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/08/17 10:54:21 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2005/09/02 14:44:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/22 21:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2005/04/02 16:30:00 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\scardsyn.dll
[2004/07/20 17:04:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 14:43:28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TBTMonUI.dll
[2000/01/31 08:02:00 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\Wh2Robo.dll
[1998/05/05 21:10:00 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\ODMA32.dll
< End of report >