Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Google redirect virus, plse help [Closed]


  • This topic is locked This topic is locked

#1
Sidor

Sidor

    New Member

  • Member
  • Pip
  • 2 posts
hi,

have been infected with Google redirect.

Used the guide on earlier threads and here is my Logs. Please advise if I need to go ahead with FixMBR on asmMBR or not, because when it comes up with a Warning that partition may become inaccessible.

Appreciate any help.


aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software
Run date: 2012-02-05 20:07:00
-----------------------------
20:07:00.453 OS Version: Windows 5.1.2600 Service Pack 3
20:07:00.453 Number of processors: 2 586 0xF06
20:07:00.453 ComputerName: YOUR-830BE02797 UserName: Alex
20:07:02.718 Initialize success
20:11:41.312 AVAST engine defs: 12020401
20:11:48.468 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
20:11:48.468 Disk 0 Vendor: Hitachi_HTS542512K9SA00 BB2OC31P Size: 114473MB BusType: 3
20:11:48.703 Disk 0 MBR read successfully
20:11:48.703 Disk 0 MBR scan
20:11:49.234 Disk 0 Windows XP default MBR code
20:11:49.250 Disk 0 Partition 1 80 (A) 0C FAT32 LBA MSDOS5.0 68684 MB offset 63
20:11:50.218 Disk 0 Partition - 00 0F Extended LBA 45786 MB offset 140665140
20:11:50.250 Disk 0 Partition 2 00 0B FAT32 MSWIN4.1 45786 MB offset 140665203
20:11:50.484 Disk 0 scanning sectors +234436545
20:11:50.515 Disk 0 scanning C:\WINDOWS\system32\drivers
20:14:05.656 Service scanning
20:14:14.750 Modules scanning
20:14:23.750 Disk 0 trace - called modules:
20:14:23.765 ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
20:14:23.765 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a75bab8]
20:14:23.765 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> [0x8a75c920]
20:14:23.765 5 PCTCore.sys[b9ead099] -> nt!IofCallDriver -> \Device\0000007e[0x8a7669e8]
20:14:23.765 7 ACPI.sys[b9f5f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a767940]
20:14:24.781 AVAST engine scan C:\WINDOWS
20:15:07.421 AVAST engine scan C:\WINDOWS\system32
20:20:09.921 File: C:\WINDOWS\system32\wmidx6.dll **INFECTED** Win32:Diller-E [Trj]
20:28:47.406 AVAST engine scan C:\WINDOWS\system32\drivers
20:30:17.390 AVAST engine scan C:\Documents and Settings\Alex
21:57:12.750 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Alex\My Documents\MBR.dat"
21:57:12.750 The log file has been saved successfully to "C:\Documents and Settings\Alex\My Documents\aswMBR.txt"


OTL log:

OTL logfile created on: 5/02/2012 8:11:39 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Alex\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 0.47 Gb Available Physical Memory | 23.63% Memory free
3.85 Gb Paging File | 2.04 Gb Available in Paging File | 53.04% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 67.06 Gb Total Space | 16.73 Gb Free Space | 24.95% Space Free | Partition Type: FAT32
Drive D: | 44.70 Gb Total Space | 14.60 Gb Free Space | 32.65% Space Free | Partition Type: FAT32

Computer Name: YOUR-830BE02797 | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/02/05 20:07:46 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Alex\My Documents\Downloads\OTL.exe
PRC - [2012/02/05 20:06:26 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Alex\My Documents\Downloads\aswMBR.exe
PRC - [2012/02/02 17:19:16 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/02/02 07:14:48 | 000,180,648 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.21.99\GoogleCrashHandler.exe
PRC - [2012/01/30 14:39:34 | 000,909,152 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
PRC - [2012/01/30 14:39:14 | 000,939,872 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2012/01/03 16:31:34 | 001,391,272 | ---- | M] (Ask) -- C:\Program Files\Ask.com\Updater\Updater.exe
PRC - [2011/12/04 13:28:36 | 000,246,112 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\ouc.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/10/10 06:23:34 | 000,973,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011/09/08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/24 20:04:14 | 013,830,960 | ---- | M] (JustVoip) -- C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe
PRC - [2011/08/15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/04/22 23:21:10 | 000,247,728 | ---- | M] (TomTom) -- D:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2011/03/15 02:27:28 | 000,271,712 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe
PRC - [2011/01/13 15:17:26 | 001,589,208 | ---- | M] (PC Tools) -- d:\Program Files\PC Tools Security\pctsGui.exe
PRC - [2010/11/19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) -- d:\Program Files\PC Tools Security\pctsSvc.exe
PRC - [2010/03/15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) -- d:\Program Files\PC Tools Security\pctsAuxs.exe
PRC - [2010/02/09 14:35:54 | 000,061,440 | ---- | M] () -- C:\Program Files\Crazy John's\Crazy John's Broadband\DetectWireless.exe
PRC - [2009/09/08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/14 10:12:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/14 10:12:14 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2008/02/19 15:33:16 | 000,033,136 | ---- | M] () -- C:\WINDOWS\ASScrPro.exe
PRC - [2008/01/29 17:38:32 | 000,583,048 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2007/09/10 15:12:44 | 000,069,632 | ---- | M] (Software 2000 Limited) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE
PRC - [2007/02/06 10:30:00 | 000,065,536 | R--- | M] (Cognizance Corporation) -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe
PRC - [2006/10/18 18:04:28 | 000,802,816 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2006/09/07 17:58:32 | 000,778,240 | ---- | M] () -- C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
PRC - [2006/08/23 07:22:14 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe
PRC - [2006/08/10 07:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
PRC - [2006/08/06 22:11:00 | 000,573,440 | ---- | M] (Motorola Inc.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
PRC - [2006/06/08 20:33:02 | 000,053,248 | ---- | M] (ASUSTeK Computer INC.) -- C:\Program Files\ASUS\ATK Media\DMedia.exe
PRC - [2006/06/01 14:02:54 | 000,491,520 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
PRC - [2006/05/30 10:28:20 | 000,811,008 | ---- | M] (ATK) -- C:\Program Files\ASUS\Splendid\ACMON.exe
PRC - [2006/05/16 11:42:52 | 001,777,664 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2006/04/07 17:36:46 | 000,290,816 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2006/03/13 23:30:16 | 000,593,920 | ---- | M] (Infineon Technologies AG) -- c:\Program Files\Infineon\Security Platform Software\SpTNA.exe
PRC - [2006/03/10 00:41:42 | 000,131,072 | ---- | M] (Infineon Technologies AG) -- c:\Program Files\Infineon\Security Platform Software\PSDrt.exe
PRC - [2006/02/21 15:20:54 | 000,180,224 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe
PRC - [2006/01/27 18:17:50 | 000,221,184 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
PRC - [2006/01/23 21:47:32 | 000,073,728 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
PRC - [2006/01/02 16:41:22 | 000,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2005/11/29 03:51:04 | 000,099,872 | ---- | M] (Infineon Technologies AG) -- c:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE
PRC - [2005/10/17 17:09:34 | 000,987,136 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe
PRC - [2005/07/06 15:43:42 | 000,155,648 | ---- | M] (ASUSTeK) -- C:\WINDOWS\system32\ACEngSvr.exe


========== Modules (No Company Name) ==========

MOD - [2012/02/02 17:19:14 | 001,911,768 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/01/30 14:39:34 | 000,909,152 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
MOD - [2012/01/30 14:39:14 | 000,939,872 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2011/12/04 13:28:40 | 002,415,104 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QtCore4.dll
MOD - [2011/12/04 13:28:40 | 001,148,416 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QtNetwork4.dll
MOD - [2011/12/04 13:28:40 | 000,398,336 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QtXml4.dll
MOD - [2011/12/04 13:28:40 | 000,384,512 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QueryStrategy.dll
MOD - [2011/12/04 13:28:38 | 000,043,008 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\libgcc_s_dw2-1.dll
MOD - [2011/12/04 13:28:38 | 000,011,362 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\mingwm10.dll
MOD - [2011/12/04 13:28:36 | 000,246,112 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\ouc.exe
MOD - [2011/10/14 07:03:04 | 008,522,400 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/03/15 02:27:28 | 000,271,712 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe
MOD - [2010/10/02 13:38:30 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_0a0bfb1b\mscorlib.dll
MOD - [2010/10/02 13:38:28 | 000,835,584 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_584b4caf\system.drawing.dll
MOD - [2010/10/02 13:38:24 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_d4e6da61\system.xml.dll
MOD - [2010/10/02 13:38:20 | 003,018,752 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_64abb3df\system.windows.forms.dll
MOD - [2010/10/02 13:38:14 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_9d87ef9c\system.dll
MOD - [2010/10/02 13:38:04 | 001,265,664 | ---- | M] () -- c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
MOD - [2010/10/02 13:38:04 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2010/08/30 16:05:52 | 000,157,656 | ---- | M] () -- d:\Program Files\PC Tools Security\NetworkLayer\PCTCFHook.dll
MOD - [2010/08/10 17:59:26 | 001,263,576 | ---- | M] () -- d:\Program Files\PC Tools Security\UserModeFileCache.dll
MOD - [2010/08/10 17:58:38 | 000,091,608 | ---- | M] () -- d:\Program Files\PC Tools Security\avengine\sdkBSCtrl.dll
MOD - [2010/02/09 14:35:54 | 000,061,440 | ---- | M] () -- C:\Program Files\Crazy John's\Crazy John's Broadband\DetectWireless.exe
MOD - [2008/02/19 15:33:16 | 000,033,136 | ---- | M] () -- C:\WINDOWS\ASScrPro.exe
MOD - [2008/02/19 14:49:48 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2008/02/19 14:49:48 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
MOD - [2008/02/19 14:49:46 | 002,052,096 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2008/02/19 14:49:46 | 000,466,944 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2008/02/19 14:49:46 | 000,323,584 | ---- | M] () -- c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
MOD - [2006/10/18 17:51:48 | 000,118,784 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2006/10/18 17:50:22 | 000,348,160 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\IntStngs.dll
MOD - [2006/09/07 17:58:32 | 000,778,240 | ---- | M] () -- C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
MOD - [2006/08/23 07:22:14 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe
MOD - [2006/08/10 07:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
MOD - [2006/05/17 16:39:26 | 000,028,672 | ---- | M] () -- C:\Program Files\ASUS\Asus MultiFrame\HookTitle.dll
MOD - [2006/02/21 15:20:54 | 000,180,224 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe
MOD - [2005/10/17 17:09:34 | 000,987,136 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe
MOD - [2005/07/29 11:05:16 | 000,049,152 | ---- | M] () -- C:\Program Files\ASUS\Splendid\GLCDdll.dll
MOD - [2005/07/22 21:30:20 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\TosCommAPI.dll
MOD - [2004/07/20 17:04:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\TosBtHcrpAPI.dll
MOD - [2004/05/27 19:13:10 | 000,057,344 | ---- | M] () -- C:\WINDOWS\ATK0100\CMSSC.dll
MOD - [1998/05/05 21:10:00 | 000,069,632 | R--- | M] () -- C:\WINDOWS\system32\ODMA32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (LiveUpdate Notice Ex)
SRV - File not found [Auto | Running] -- -- (HWDeviceService.exe)
SRV - [2012/01/30 14:39:34 | 000,909,152 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe -- (vToolbarUpdater)
SRV - [2011/12/04 13:28:36 | 000,246,112 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Crazy Johns Broadband\UpdateDog\ouc.exe -- (Crazy Johns Broadband. RunOuc)
SRV - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2010/11/19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) [Auto | Running] -- d:\Program Files\PC Tools Security\pctsSvc.exe -- (sdCoreService)
SRV - [2010/03/15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) [Auto | Running] -- d:\Program Files\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/09/08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2008/01/29 17:38:32 | 000,583,048 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -- (LiveUpdate Notice Service)
SRV - [2007/02/06 10:30:00 | 000,074,240 | R--- | M] (Cognizance Corporation) [Auto | Running] -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll -- (ASBroker)
SRV - [2006/06/21 03:14:00 | 000,131,584 | R--- | M] (Cognizance Corporation) [Auto | Running] -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASChnl.dll -- (ASChannel)
SRV - [2005/11/29 03:51:04 | 000,099,872 | ---- | M] (Infineon Technologies AG) [Auto | Running] -- c:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE -- (PersonalSecureDriveService)


========== Driver Services (SafeList) ==========

DRV - [2012/01/26 10:51:54 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/12/04 13:28:40 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2011/12/04 13:28:40 | 000,090,368 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - [2011/12/04 13:28:40 | 000,073,216 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2011/10/07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011/10/04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/09/13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/08/08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/07/11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/07/11 01:14:28 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/07/11 01:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/07/11 01:14:26 | 000,134,608 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/12/10 13:24:12 | 000,239,168 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2010/07/16 14:59:54 | 000,656,320 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pctEFA.sys -- (pctEFA)
DRV - [2010/07/16 14:59:54 | 000,338,880 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\pctDS.sys -- (pctDS)
DRV - [2009/02/17 12:19:44 | 000,057,672 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2008/04/14 04:56:50 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008/02/11 10:12:04 | 000,015,360 | R--- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NetMotCM.sys -- (ndiscm)
DRV - [2008/01/23 17:08:58 | 000,099,456 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bsusbser.sys -- (bsusbser)
DRV - [2006/10/24 06:28:46 | 001,777,664 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/10/19 09:29:22 | 000,012,544 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/08/08 23:15:14 | 001,116,544 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynMini.sys -- (SynMini)
DRV - [2006/08/08 23:15:14 | 000,007,808 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynScan.sys -- (SynScan)
DRV - [2006/08/06 22:13:50 | 000,980,608 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smserial.sys -- (smserial)
DRV - [2006/07/24 01:15:04 | 004,353,024 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/05/18 21:46:16 | 000,110,976 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (Tosrfbd)
DRV - [2006/05/16 10:14:00 | 000,023,496 | R--- | M] (Cognizance Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\itsdisk.sys -- (ItSDisk)
DRV - [2006/05/09 11:21:54 | 000,040,192 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2006/05/09 10:33:54 | 000,062,848 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfhid.sys -- (Tosrfhid)
DRV - [2006/04/19 13:57:44 | 000,047,488 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte)
DRV - [2006/03/16 10:45:12 | 000,037,632 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (Tosrfbnp)
DRV - [2006/03/15 10:52:40 | 000,052,864 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfsnd.sys -- (TosRfSnd) Bluetooth Audio Device (WDM)
DRV - [2006/01/24 10:45:56 | 000,034,944 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipswuio.sys -- (ipswuio)
DRV - [2005/11/29 03:50:58 | 000,036,768 | ---- | M] (Infineon Technologies AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\psd.sys -- (PersonalSecureDrive)
DRV - [2005/11/16 20:28:32 | 000,028,928 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/11/16 01:08:16 | 000,078,976 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTL8023xp)
DRV - [2005/11/01 17:54:50 | 000,051,584 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/10/20 20:19:34 | 000,036,352 | ---- | M] (Infineon Technologies AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ifxtpm.sys -- (IFXTPM)
DRV - [2005/08/01 16:45:08 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005/07/11 18:58:56 | 000,003,712 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\toshidpt.sys -- (toshidpt)
DRV - [2005/02/17 08:07:48 | 000,005,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)
DRV - [2005/01/06 13:42:42 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://my.ebay.com.a...MyeBay&guest=1"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: [email protected]:3.11.3.15590
FF - prefs.js..keyword.URL: "http://www.google.co...b=adawaretb&q="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@csi.business.gov.au/CsiPlugin: D:\Program Files\Common-Use Signing Interface\bin\npCsiPlugin.dll (Commonwealth Government of Australia)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/01/29 11:54:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\10.0.0.7\ [2012/01/30 14:39:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2008/02/23 14:04:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2008/02/23 14:04:44 | 000,000,000 | ---D | M]

[2008/08/28 19:38:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Extensions
[2009/11/23 20:26:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Extensions\[email protected]
[2008/02/23 14:04:56 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions
[2012/01/26 07:20:14 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/09 21:44:44 | 000,000,000 | ---D | M] (F5 Networks Host Plugin) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions\{DBBB3167-6E81-400f-BBFD-BD8921726F52}
[2012/01/26 20:01:18 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions\[email protected]
[2012/02/01 13:24:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-1.xml
[2011/11/24 20:18:58 | 000,002,571 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\askcom.xml
[2011/05/24 12:17:44 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-3.xml
[2011/05/25 18:54:38 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-4.xml
[2011/05/26 15:08:50 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-2.xml
[2011/05/29 09:22:04 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin.xml
[2008/02/23 14:04:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/01/30 14:39:48 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\10.0.0.7
[2012/01/29 11:54:52 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2012/02/02 17:19:16 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/07 03:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2009/11/07 03:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/18 05:14:28 | 000,002,149 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\adawaretb.xml
[2012/01/22 07:13:08 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
[2012/01/22 07:13:08 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/01/22 07:13:08 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/01/22 07:13:08 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/22 07:13:10 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/01/30 14:38:44 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml

========== Chrome ==========

CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}

O1 HOSTS File: ([2006/02/28 20:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (ASUS Security Protect Manager) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe (ATK)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ASUS Camera ScreenSaver] C:\WINDOWS\ASScrProlog.exe ()
O4 - HKLM..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe ()
O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\ASScrPro.exe ()
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe ()
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISTray] d:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe ()
O4 - HKLM..\Run: [ROC_roc_dec12] C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe ()
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe ()
O4 - HKCU..\Run: [JustVoip] C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe (JustVoip)
O4 - HKCU..\Run: [MyDetectWireless] C:\Program Files\Crazy John's\Crazy John's Broadband\DetectWireless.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [TomTomHOME.exe] d:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiFrame.lnk = C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe (ASUSTek Computer Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\Alex\Start Menu\Programs\Startup\fliptoast.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKCU\..Trusted Domains: servicestream.com.au ([secure] http in Trusted sites)
O15 - HKCU\..Trusted Domains: servicestream.com.au ([secure] https in Trusted sites)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} https://secure.servi...,2009,0514,2204 (F5 Networks Policy Agent Host Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 61.9.133.193 61.9.134.49
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95AF6966-FC6E-4CC2-8AA8-249EA40C37AF}: DhcpNameServer = 61.9.133.193 61.9.134.49
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll ()
O20 - AppInit_DLLs: (APSHook.dll) -C:\WINDOWS\System32\APSHook.dll (Cognizance Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IfxWlxEN: DllName - (IfxWlxEN.dll) - C:\WINDOWS\System32\IfxWlxEN.dll (Infineon Technologies AG)
O20 - Winlogon\Notify\OneCard: DllName - (c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll) - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll (Cognizance Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - (TPSvc.dll) - File not found
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/Alex/LOCALS~1/Temp/msohtml1/02/clip_image002.jpg
O24 - Desktop Components:1 () - file:///C:/DOCUME~1/Alex/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg
O24 - Desktop Components:2 () - file:///C:/DOCUME~1/Alex/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Components:3 (My Current Home Page) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/14 18:08:18 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2008/02/19 14:36:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2008/10/13 15:48:14 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{37bf6e5c-1e1f-11e1-babb-0019d2b2ccfb}\Shell - "" = AutoRun
O33 - MountPoints2\{37bf6e5c-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{37bf6e5c-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{37bf6e5e-1e1f-11e1-babb-0019d2b2ccfb}\Shell - "" = AutoRun
O33 - MountPoints2\{37bf6e5e-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{37bf6e5e-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{582e2a48-d812-11de-b52e-0019d2b2ccfb}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O33 - MountPoints2\{8715fb76-f5cf-11de-b572-001e2a609d39}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/02/05 10:16:32 | 000,656,320 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctEFA.sys
[2012/02/05 10:16:32 | 000,338,880 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctDS.sys
[2012/02/05 10:16:30 | 000,251,560 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2012/02/05 10:16:22 | 000,239,168 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2012/02/05 10:16:22 | 000,160,448 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2012/02/05 10:16:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2012/02/05 10:16:13 | 000,070,536 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2012/02/05 10:16:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\PC Tools
[2012/02/04 21:35:56 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/02/04 21:35:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2012/02/04 21:31:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Desktop\TDSSKiller
[2012/01/30 22:31:50 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/01/30 22:26:05 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/01/30 22:06:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/30 22:05:33 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Alex\Start Menu\Programs\Administrative Tools
[2012/01/30 14:39:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cache
[2012/01/29 14:49:22 | 000,000,000 | -HSD | C] -- C:\FOUND.024
[2012/01/29 12:26:38 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012/01/29 11:57:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\AVG2012
[2012/01/29 11:56:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2012/01/29 11:56:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\AVG Secure Search
[2012/01/29 11:56:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012/01/29 11:56:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search
[2012/01/29 11:56:01 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search
[2012/01/29 11:55:57 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/01/29 11:54:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/01/29 11:54:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2012/01/29 11:52:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2012/01/26 10:51:53 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/01/26 10:29:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\ZoomBrowser EX
[2012/01/26 10:27:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\My Documents\Canon Utilities
[2012/01/26 10:26:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\CANON INC
[2012/01/26 10:25:00 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2012/01/26 10:24:47 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2012/01/26 07:21:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Canon MyCameraFiles
[2012/01/26 07:20:28 | 000,000,000 | ---D | C] -- C:\Program Files\Canon
[2012/01/26 07:20:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2012/01/26 07:20:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2012/01/26 07:19:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC
[2012/01/26 07:17:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Canon
[2012/01/23 14:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2012/01/20 22:09:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\com.w3i.FlipToast
[2012/01/20 22:09:11 | 000,000,000 | ---D | C] -- C:\Program Files\fliptoast
[2012/01/20 22:09:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR

========== Files - Modified Within 30 Days ==========

[2012/02/05 22:01:02 | 000,000,232 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/02/05 21:57:14 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Alex\My Documents\MBR.dat
[2012/02/05 20:20:02 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/05 16:09:48 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/05 16:09:42 | 000,000,302 | ---- | M] () -- C:\WINDOWS\tasks\BRNDHJI.job
[2012/02/05 16:09:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/05 16:09:34 | 2146,717,696 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/05 11:04:02 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2012/02/05 10:16:44 | 000,731,688 | ---- | M] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2012/02/05 09:18:56 | 088,181,301 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/05 08:39:22 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/02/05 08:39:06 | 000,000,440 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
[2012/02/04 21:34:56 | 000,512,992 | ---- | M] () -- C:\Documents and Settings\Alex\Desktop\sdasetup_revwire207(1).exe
[2012/02/04 16:45:06 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/02/02 22:12:16 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat
[2012/02/02 22:12:16 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat
[2012/02/01 12:01:30 | 000,000,606 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/01/30 22:24:58 | 000,119,296 | ---- | M] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/29 16:57:56 | 000,001,609 | ---- | M] () -- C:\WINDOWS\pstudio.ini
[2012/01/29 10:07:10 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\pixillionShakeIcon.job
[2012/01/28 23:58:44 | 000,071,634 | ---- | M] () -- C:\Documents and Settings\Alex\My Documents\ISO1.nri
[2012/01/26 10:51:54 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/01/26 07:22:06 | 000,000,543 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\DCSD Software Guide.lnk
[2012/01/26 07:22:00 | 000,000,555 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PowerShot S100 Camera User Guide.lnk
[2012/01/26 07:21:20 | 000,000,549 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Digital Photo Professional.lnk
[2012/01/26 07:20:24 | 000,000,679 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012/01/23 22:06:00 | 000,126,976 | RHS- | M] () -- C:\WINDOWS\System32\wmidx6.dll
[2012/01/23 14:18:22 | 000,000,523 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2012/01/23 14:17:04 | 021,073,936 | ---- | M] () -- C:\Documents and Settings\Alex\My Documents\vlc-1.1.11-win32.exe
[2012/01/21 17:41:22 | 000,000,556 | ---- | M] () -- C:\Documents and Settings\Alex\Start Menu\Programs\Startup\fliptoast.lnk
[2012/01/20 22:14:20 | 008,261,192 | ---- | M] () -- C:\Documents and Settings\Alex\Desktop\DSC_2570.jpeg
[2012/01/10 22:16:08 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

========== Files Created - No Company Name ==========

[2012/02/05 10:16:33 | 000,731,688 | ---- | C] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2012/02/05 09:18:54 | 088,181,301 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/04 21:35:14 | 000,512,992 | ---- | C] () -- C:\Documents and Settings\Alex\Desktop\sdasetup_revwire207(1).exe
[2012/01/29 11:56:19 | 000,000,606 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/01/26 11:37:41 | 000,091,584 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/01/26 07:22:04 | 000,000,543 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\DCSD Software Guide.lnk
[2012/01/26 07:22:00 | 000,000,555 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PowerShot S100 Camera User Guide.lnk
[2012/01/26 07:21:18 | 000,000,549 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Digital Photo Professional.lnk
[2012/01/26 07:20:22 | 000,000,679 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012/01/23 22:05:59 | 000,000,302 | ---- | C] () -- C:\WINDOWS\tasks\BRNDHJI.job
[2012/01/23 22:05:58 | 000,126,976 | RHS- | C] () -- C:\WINDOWS\System32\wmidx6.dll
[2012/01/23 14:18:20 | 000,000,523 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2012/01/23 14:16:45 | 021,073,936 | ---- | C] () -- C:\Documents and Settings\Alex\My Documents\vlc-1.1.11-win32.exe
[2012/01/20 22:29:11 | 000,000,282 | ---- | C] () -- C:\WINDOWS\tasks\pixillionShakeIcon.job
[2012/01/20 22:14:14 | 008,261,192 | ---- | C] () -- C:\Documents and Settings\Alex\Desktop\DSC_2570.jpeg
[2012/01/20 22:12:53 | 013,914,414 | ---- | C] () -- C:\Documents and Settings\Alex\Desktop\DSC_2570.NEF
[2012/01/20 22:09:40 | 000,000,556 | ---- | C] () -- C:\Documents and Settings\Alex\Start Menu\Programs\Startup\fliptoast.lnk
[2011/05/29 22:15:40 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2011/05/29 22:15:40 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2011/04/17 21:14:49 | 000,001,240 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\6082cmkajv5q4bt0
[2011/04/17 21:14:49 | 000,001,240 | -HS- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\6082cmkajv5q4bt0
[2011/04/13 22:24:17 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\housecall.guid.cache
[2011/04/10 10:07:36 | 000,008,744 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\o553q566703t0w537
[2011/04/10 10:07:36 | 000,008,744 | -HS- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\o553q566703t0w537
[2010/10/12 20:41:33 | 000,171,695 | ---- | C] () -- C:\WINDOWS\hphins34.dat
[2010/10/12 20:41:33 | 000,000,532 | ---- | C] () -- C:\WINDOWS\hphmdl34.dat
[2010/09/19 08:44:06 | 000,000,943 | ---- | C] () -- C:\WINDOWS\WirelessCard.INI
[2010/06/06 17:35:51 | 000,172,130 | ---- | C] () -- C:\WINDOWS\hphins34.dat.temp
[2010/06/06 17:35:50 | 000,000,532 | ---- | C] () -- C:\WINDOWS\hphmdl34.dat.temp
[2009/05/06 10:45:44 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\acovcnt.exe
[2009/02/19 21:42:02 | 000,000,208 | ---- | C] () -- C:\WINDOWS\EliteCentral.ini
[2008/10/14 08:26:06 | 000,003,839 | ---- | C] () -- C:\WINDOWS\System32\drivers\GETPADD.sys
[2008/07/26 23:19:44 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008/06/26 20:15:05 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\HPPLVS.dll
[2008/06/16 23:50:11 | 000,000,098 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI
[2008/06/16 23:36:14 | 000,000,024 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008/05/09 22:04:21 | 000,000,204 | ---- | C] () -- C:\WINDOWS\MYOBP.INI
[2008/05/09 22:04:21 | 000,000,119 | ---- | C] () -- C:\WINDOWS\SwDrvs.ini
[2008/05/09 22:04:21 | 000,000,041 | ---- | C] () -- C:\WINDOWS\MYOB.INI
[2008/05/09 22:04:08 | 000,000,343 | ---- | C] () -- C:\WINDOWS\10ed.ini
[2008/05/09 22:02:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\drvxl32.INI
[2008/05/09 22:02:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\drvwd32.INI
[2008/05/08 14:53:54 | 000,001,609 | ---- | C] () -- C:\WINDOWS\pstudio.ini
[2008/05/08 14:53:54 | 000,000,028 | ---- | C] () -- C:\WINDOWS\album.ini
[2008/05/08 14:53:54 | 000,000,021 | ---- | C] () -- C:\WINDOWS\Ps_setup.ini
[2008/03/22 06:30:08 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/03/04 14:11:00 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/03/01 19:44:51 | 000,119,296 | ---- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/26 12:08:42 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/02/23 18:49:17 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/02/23 18:37:07 | 000,001,597 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2008/02/23 14:04:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/02/23 12:54:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\tosOBEX.INI
[2008/02/23 12:53:33 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\fusioncache.dat
[2008/02/23 12:53:21 | 000,000,546 | ---- | C] () -- C:\WINDOWS\System32\ABF3JR.DAT
[2008/02/19 15:36:07 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/02/19 15:33:14 | 000,033,136 | ---- | C] () -- C:\WINDOWS\ASScrPro.exe
[2008/02/19 15:33:04 | 000,037,232 | ---- | C] () -- C:\WINDOWS\ASScrProlog.exe
[2008/02/19 15:33:02 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2008/02/19 15:05:05 | 000,987,136 | ---- | C] () -- C:\WINDOWS\System32\wcourier.exe
[2008/02/19 14:58:07 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008/02/19 14:58:07 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008/02/19 14:39:54 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2008/02/19 14:39:11 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/02/19 14:34:25 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/02/19 14:30:56 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/02/19 14:30:23 | 000,139,648 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/02/19 14:14:44 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2008/02/19 14:14:38 | 000,136,650 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2008/02/19 14:06:04 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\SynSvc_.exe
[2008/02/19 14:06:04 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynSam.sys
[2008/02/19 14:06:04 | 000,007,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynScan.sys
[2008/02/19 14:05:56 | 000,498,688 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynPin.sys
[2008/02/19 14:05:55 | 001,116,544 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynMini.sys
[2008/02/19 14:05:55 | 000,045,056 | ---- | C] () -- C:\WINDOWS\StkUnist.exe
[2008/02/19 14:05:55 | 000,028,800 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynCamd.sys
[2008/02/19 14:04:01 | 000,000,010 | ---- | C] () -- C:\WINDOWS\System32\ABLKSR.INI
[2008/02/19 14:03:53 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\ATKACPI.sys
[2007/11/28 04:26:10 | 000,438,272 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2007/07/26 12:01:50 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\hppatusg01.dll
[2006/08/17 10:55:17 | 000,007,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\MMIOPORT.SYS
[2006/08/17 10:55:17 | 000,002,538 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/08/17 10:54:47 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/08/17 10:54:45 | 000,442,896 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/08/17 10:54:45 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/08/17 10:54:45 | 000,072,308 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/08/17 10:54:45 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/08/17 10:54:43 | 000,004,487 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/08/17 10:54:39 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/08/17 10:54:38 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/08/17 10:54:35 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/08/17 10:54:35 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/08/17 10:54:32 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/08/17 10:54:21 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2005/09/02 14:44:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/22 21:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2005/04/02 16:30:00 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\scardsyn.dll
[2004/07/20 17:04:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 14:43:28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TBTMonUI.dll
[2000/01/31 08:02:00 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\Wh2Robo.dll
[1998/05/05 21:10:00 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\ODMA32.dll

< End of report >
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi your MBR is OK so there is no need to touch it.. On completion of this run could you check for redirects please

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    [2011/04/10 10:07:36 | 000,008,744 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\o553q566703t0w537
    [2011/04/10 10:07:36 | 000,008,744 | -HS- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\o553q566703t0w537
    [2011/04/17 21:14:49 | 000,001,240 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\6082cmkajv5q4bt0
    [2011/04/17 21:14:49 | 000,001,240 | -HS- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\6082cmkajv5q4bt0
    [2012/01/23 22:05:59 | 000,000,302 | ---- | C] () -- C:\WINDOWS\tasks\BRNDHJI.job
    [2012/01/23 22:06:00 | 000,126,976 | RHS- | M] () -- C:\WINDOWS\System32\wmidx6.dll

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

#3
Sidor

Sidor

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
thanks for the advice. Here is by new OTL log.
Google Redirect Looks like has been fixed.
Does the log look OK now ?
thanks


OTL logfile created on: 6/02/2012 5:18:48 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Alex\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 0.95 Gb Available Physical Memory | 47.66% Memory free
3.85 Gb Paging File | 2.73 Gb Available in Paging File | 70.89% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 67.06 Gb Total Space | 17.20 Gb Free Space | 25.65% Space Free | Partition Type: FAT32
Drive D: | 44.70 Gb Total Space | 14.64 Gb Free Space | 32.75% Space Free | Partition Type: FAT32

Computer Name: YOUR-830BE02797 | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/02/06 07:02:58 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Alex\My Documents\Downloads\OTL.exe
PRC - [2012/02/02 17:19:16 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/02/02 07:14:48 | 000,180,648 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.21.99\GoogleCrashHandler.exe
PRC - [2012/01/30 14:39:34 | 000,909,152 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
PRC - [2012/01/30 14:39:14 | 000,939,872 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2012/01/03 16:31:34 | 001,391,272 | ---- | M] (Ask) -- C:\Program Files\Ask.com\Updater\Updater.exe
PRC - [2011/12/04 13:28:36 | 000,246,112 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\ouc.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/10/10 06:23:34 | 000,973,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011/09/08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/24 20:04:14 | 013,830,960 | ---- | M] (JustVoip) -- C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe
PRC - [2011/08/15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/04/22 23:21:10 | 000,247,728 | ---- | M] (TomTom) -- D:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2011/03/15 02:27:28 | 000,271,712 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe
PRC - [2010/02/09 14:35:54 | 000,061,440 | ---- | M] () -- C:\Program Files\Crazy John's\Crazy John's Broadband\DetectWireless.exe
PRC - [2009/09/08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/14 10:12:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/19 15:33:16 | 000,033,136 | ---- | M] () -- C:\WINDOWS\ASScrPro.exe
PRC - [2008/01/29 17:38:32 | 000,583,048 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2007/09/10 15:12:44 | 000,069,632 | ---- | M] (Software 2000 Limited) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE
PRC - [2007/02/06 10:30:00 | 000,065,536 | R--- | M] (Cognizance Corporation) -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe
PRC - [2006/10/18 18:04:28 | 000,802,816 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2006/09/07 17:58:32 | 000,778,240 | ---- | M] () -- C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
PRC - [2006/08/23 07:22:14 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe
PRC - [2006/08/10 07:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
PRC - [2006/08/06 22:11:00 | 000,573,440 | ---- | M] (Motorola Inc.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
PRC - [2006/06/08 20:33:02 | 000,053,248 | ---- | M] (ASUSTeK Computer INC.) -- C:\Program Files\ASUS\ATK Media\DMedia.exe
PRC - [2006/06/01 14:02:54 | 000,491,520 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
PRC - [2006/05/30 10:28:20 | 000,811,008 | ---- | M] (ATK) -- C:\Program Files\ASUS\Splendid\ACMON.exe
PRC - [2006/05/16 11:42:52 | 001,777,664 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2006/04/07 17:36:46 | 000,290,816 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2006/03/13 23:30:16 | 000,593,920 | ---- | M] (Infineon Technologies AG) -- c:\Program Files\Infineon\Security Platform Software\SpTNA.exe
PRC - [2006/03/10 00:41:42 | 000,131,072 | ---- | M] (Infineon Technologies AG) -- c:\Program Files\Infineon\Security Platform Software\PSDrt.exe
PRC - [2006/02/21 15:20:54 | 000,180,224 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe
PRC - [2006/01/27 18:17:50 | 000,221,184 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
PRC - [2006/01/23 21:47:32 | 000,073,728 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
PRC - [2006/01/02 16:41:22 | 000,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2005/11/29 03:51:04 | 000,099,872 | ---- | M] (Infineon Technologies AG) -- c:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE
PRC - [2005/10/17 17:09:34 | 000,987,136 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe
PRC - [2005/07/06 15:43:42 | 000,155,648 | ---- | M] (ASUSTeK) -- C:\WINDOWS\system32\ACEngSvr.exe


========== Modules (No Company Name) ==========

MOD - [2012/02/02 17:19:14 | 001,911,768 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/01/30 14:39:34 | 000,909,152 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
MOD - [2012/01/30 14:39:14 | 000,939,872 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2011/12/04 13:28:40 | 002,415,104 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QtCore4.dll
MOD - [2011/12/04 13:28:40 | 001,148,416 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QtNetwork4.dll
MOD - [2011/12/04 13:28:40 | 000,398,336 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QtXml4.dll
MOD - [2011/12/04 13:28:40 | 000,384,512 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\QueryStrategy.dll
MOD - [2011/12/04 13:28:38 | 000,043,008 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\libgcc_s_dw2-1.dll
MOD - [2011/12/04 13:28:38 | 000,011,362 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\mingwm10.dll
MOD - [2011/12/04 13:28:36 | 000,246,112 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband\OnlineUpdate\ouc.exe
MOD - [2011/10/14 07:03:04 | 008,522,400 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/08/31 08:25:44 | 000,016,832 | ---- | M] () -- C:\Program Files\Adobe\Reader 8.0\Reader\ViewerPS.dll
MOD - [2011/03/15 02:27:28 | 000,271,712 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe
MOD - [2010/10/02 13:38:30 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_0a0bfb1b\mscorlib.dll
MOD - [2010/10/02 13:38:28 | 000,835,584 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_584b4caf\system.drawing.dll
MOD - [2010/10/02 13:38:24 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_d4e6da61\system.xml.dll
MOD - [2010/10/02 13:38:20 | 003,018,752 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_64abb3df\system.windows.forms.dll
MOD - [2010/10/02 13:38:14 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_9d87ef9c\system.dll
MOD - [2010/10/02 13:38:04 | 001,265,664 | ---- | M] () -- c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
MOD - [2010/10/02 13:38:04 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2010/02/09 14:35:54 | 000,061,440 | ---- | M] () -- C:\Program Files\Crazy John's\Crazy John's Broadband\DetectWireless.exe
MOD - [2010/02/06 04:27:46 | 001,291,776 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2008/04/14 10:12:04 | 000,562,176 | ---- | M] () -- C:\WINDOWS\system32\qedit.dll
MOD - [2008/04/14 10:12:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 10:11:52 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2008/02/19 15:33:16 | 000,033,136 | ---- | M] () -- C:\WINDOWS\ASScrPro.exe
MOD - [2008/02/19 14:49:48 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2008/02/19 14:49:48 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
MOD - [2008/02/19 14:49:46 | 002,052,096 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2008/02/19 14:49:46 | 000,466,944 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2008/02/19 14:49:46 | 000,323,584 | ---- | M] () -- c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
MOD - [2006/10/18 17:51:48 | 000,118,784 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2006/10/18 17:50:22 | 000,348,160 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\IntStngs.dll
MOD - [2006/09/07 17:58:32 | 000,778,240 | ---- | M] () -- C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
MOD - [2006/08/23 07:22:14 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe
MOD - [2006/08/10 07:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
MOD - [2006/05/17 16:39:26 | 000,028,672 | ---- | M] () -- C:\Program Files\ASUS\Asus MultiFrame\HookTitle.dll
MOD - [2006/02/21 15:20:54 | 000,180,224 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe
MOD - [2005/10/19 09:17:58 | 000,073,728 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll
MOD - [2005/10/17 17:09:34 | 000,987,136 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe
MOD - [2005/07/29 11:05:16 | 000,049,152 | ---- | M] () -- C:\Program Files\ASUS\Splendid\GLCDdll.dll
MOD - [2005/07/22 21:30:20 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\TosCommAPI.dll
MOD - [2004/07/20 17:04:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\TosBtHcrpAPI.dll
MOD - [2004/05/27 19:13:10 | 000,057,344 | ---- | M] () -- C:\WINDOWS\ATK0100\CMSSC.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (LiveUpdate Notice Ex)
SRV - File not found [Auto | Running] -- -- (HWDeviceService.exe)
SRV - [2012/01/30 14:39:34 | 000,909,152 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe -- (vToolbarUpdater)
SRV - [2011/12/04 13:28:36 | 000,246,112 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Crazy Johns Broadband\UpdateDog\ouc.exe -- (Crazy Johns Broadband. RunOuc)
SRV - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2010/11/19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) [On_Demand | Stopped] -- d:\Program Files\PC Tools Security\pctsSvc.exe -- (sdCoreService)
SRV - [2010/03/15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) [On_Demand | Stopped] -- d:\Program Files\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/09/08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2008/01/29 17:38:32 | 000,583,048 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -- (LiveUpdate Notice Service)
SRV - [2007/02/06 10:30:00 | 000,074,240 | R--- | M] (Cognizance Corporation) [Auto | Running] -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll -- (ASBroker)
SRV - [2006/06/21 03:14:00 | 000,131,584 | R--- | M] (Cognizance Corporation) [Auto | Running] -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASChnl.dll -- (ASChannel)
SRV - [2005/11/29 03:51:04 | 000,099,872 | ---- | M] (Infineon Technologies AG) [Auto | Running] -- c:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE -- (PersonalSecureDriveService)


========== Driver Services (SafeList) ==========

DRV - [2011/12/04 13:28:40 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2011/12/04 13:28:40 | 000,090,368 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - [2011/12/04 13:28:40 | 000,073,216 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2011/10/07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011/10/04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/09/13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/08/08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/07/11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/07/11 01:14:28 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/07/11 01:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/07/11 01:14:26 | 000,134,608 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/12/10 13:24:12 | 000,239,168 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2010/07/16 14:59:54 | 000,656,320 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pctEFA.sys -- (pctEFA)
DRV - [2010/07/16 14:59:54 | 000,338,880 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\pctDS.sys -- (pctDS)
DRV - [2009/02/17 12:19:44 | 000,057,672 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2008/04/14 04:56:50 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008/02/11 10:12:04 | 000,015,360 | R--- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NetMotCM.sys -- (ndiscm)
DRV - [2008/01/23 17:08:58 | 000,099,456 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bsusbser.sys -- (bsusbser)
DRV - [2006/10/24 06:28:46 | 001,777,664 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/10/19 09:29:22 | 000,012,544 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/08/08 23:15:14 | 001,116,544 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynMini.sys -- (SynMini)
DRV - [2006/08/08 23:15:14 | 000,007,808 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynScan.sys -- (SynScan)
DRV - [2006/08/06 22:13:50 | 000,980,608 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smserial.sys -- (smserial)
DRV - [2006/07/24 01:15:04 | 004,353,024 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/05/18 21:46:16 | 000,110,976 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (Tosrfbd)
DRV - [2006/05/16 10:14:00 | 000,023,496 | R--- | M] (Cognizance Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\itsdisk.sys -- (ItSDisk)
DRV - [2006/05/09 11:21:54 | 000,040,192 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2006/05/09 10:33:54 | 000,062,848 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfhid.sys -- (Tosrfhid)
DRV - [2006/04/19 13:57:44 | 000,047,488 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte)
DRV - [2006/03/16 10:45:12 | 000,037,632 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (Tosrfbnp)
DRV - [2006/03/15 10:52:40 | 000,052,864 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfsnd.sys -- (TosRfSnd) Bluetooth Audio Device (WDM)
DRV - [2006/01/24 10:45:56 | 000,034,944 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipswuio.sys -- (ipswuio)
DRV - [2005/11/29 03:50:58 | 000,036,768 | ---- | M] (Infineon Technologies AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\psd.sys -- (PersonalSecureDrive)
DRV - [2005/11/16 20:28:32 | 000,028,928 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/11/16 01:08:16 | 000,078,976 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTL8023xp)
DRV - [2005/11/01 17:54:50 | 000,051,584 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/10/20 20:19:34 | 000,036,352 | ---- | M] (Infineon Technologies AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ifxtpm.sys -- (IFXTPM)
DRV - [2005/08/01 16:45:08 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005/07/11 18:58:56 | 000,003,712 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\toshidpt.sys -- (toshidpt)
DRV - [2005/02/17 08:07:48 | 000,005,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)
DRV - [2005/01/06 13:42:42 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://my.ebay.com.a...MyeBay&guest=1"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: [email protected]:3.11.3.15590
FF - prefs.js..keyword.URL: "http://www.google.co...b=adawaretb&q="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@csi.business.gov.au/CsiPlugin: D:\Program Files\Common-Use Signing Interface\bin\npCsiPlugin.dll (Commonwealth Government of Australia)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/01/29 11:54:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\10.0.0.7\ [2012/01/30 14:39:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2008/02/23 14:04:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2008/02/23 14:04:44 | 000,000,000 | ---D | M]

[2008/08/28 19:38:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Extensions
[2009/11/23 20:26:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Extensions\[email protected]
[2008/02/23 14:04:56 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions
[2012/01/26 07:20:14 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/09 21:44:44 | 000,000,000 | ---D | M] (F5 Networks Host Plugin) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions\{DBBB3167-6E81-400f-BBFD-BD8921726F52}
[2012/01/26 20:01:18 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\extensions\[email protected]
[2012/02/01 13:24:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-1.xml
[2011/11/24 20:18:58 | 000,002,571 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\askcom.xml
[2011/05/24 12:17:44 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-3.xml
[2011/05/25 18:54:38 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-4.xml
[2011/05/26 15:08:50 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin-2.xml
[2011/05/29 09:22:04 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\7kvzy268.default\searchplugins\icqplugin.xml
[2008/02/23 14:04:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/01/30 14:39:48 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\10.0.0.7
[2012/01/29 11:54:52 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2012/02/02 17:19:16 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/07 03:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2009/11/07 03:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/18 05:14:28 | 000,002,149 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\adawaretb.xml
[2012/01/22 07:13:08 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
[2012/01/22 07:13:08 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/01/22 07:13:08 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/01/22 07:13:08 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/22 07:13:10 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/01/30 14:38:44 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml

========== Chrome ==========

CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}

O1 HOSTS File: ([2012/02/06 07:06:02 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (ASUS Security Protect Manager) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe (ATK)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ASUS Camera ScreenSaver] C:\WINDOWS\ASScrProlog.exe ()
O4 - HKLM..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe ()
O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\ASScrPro.exe ()
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe ()
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe ()
O4 - HKLM..\Run: [ROC_roc_dec12] C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe ()
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe ()
O4 - HKCU..\Run: [JustVoip] C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe (JustVoip)
O4 - HKCU..\Run: [MyDetectWireless] C:\Program Files\Crazy John's\Crazy John's Broadband\DetectWireless.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [TomTomHOME.exe] d:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiFrame.lnk = C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe (ASUSTek Computer Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\Alex\Start Menu\Programs\Startup\fliptoast.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKCU\..Trusted Domains: servicestream.com.au ([secure] http in Trusted sites)
O15 - HKCU\..Trusted Domains: servicestream.com.au ([secure] https in Trusted sites)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} https://secure.servi...,2009,0514,2204 (F5 Networks Policy Agent Host Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 61.9.133.193 61.9.134.49
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95AF6966-FC6E-4CC2-8AA8-249EA40C37AF}: DhcpNameServer = 61.9.133.193 61.9.134.49
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll ()
O20 - AppInit_DLLs: (APSHook.dll) -C:\WINDOWS\System32\APSHook.dll (Cognizance Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IfxWlxEN: DllName - (IfxWlxEN.dll) - C:\WINDOWS\System32\IfxWlxEN.dll (Infineon Technologies AG)
O20 - Winlogon\Notify\OneCard: DllName - (c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll) - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll (Cognizance Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - (TPSvc.dll) - File not found
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/Alex/LOCALS~1/Temp/msohtml1/02/clip_image002.jpg
O24 - Desktop Components:1 () - file:///C:/DOCUME~1/Alex/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg
O24 - Desktop Components:2 () - file:///C:/DOCUME~1/Alex/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Components:3 (My Current Home Page) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/14 18:08:18 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2008/02/19 14:36:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2008/10/13 15:48:14 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{37bf6e5c-1e1f-11e1-babb-0019d2b2ccfb}\Shell - "" = AutoRun
O33 - MountPoints2\{37bf6e5c-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{37bf6e5c-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{37bf6e5e-1e1f-11e1-babb-0019d2b2ccfb}\Shell - "" = AutoRun
O33 - MountPoints2\{37bf6e5e-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{37bf6e5e-1e1f-11e1-babb-0019d2b2ccfb}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{582e2a48-d812-11de-b52e-0019d2b2ccfb}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O33 - MountPoints2\{8715fb76-f5cf-11de-b572-001e2a609d39}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/02/06 07:05:51 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/02/05 10:16:32 | 000,656,320 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctEFA.sys
[2012/02/05 10:16:32 | 000,338,880 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctDS.sys
[2012/02/05 10:16:30 | 000,251,560 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2012/02/05 10:16:22 | 000,239,168 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2012/02/05 10:16:22 | 000,160,448 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2012/02/05 10:16:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2012/02/05 10:16:13 | 000,070,536 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2012/02/05 10:16:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\PC Tools
[2012/02/04 21:35:56 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/02/04 21:35:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2012/01/30 22:31:50 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/01/30 22:05:33 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Alex\Start Menu\Programs\Administrative Tools
[2012/01/30 14:39:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cache
[2012/01/29 14:49:22 | 000,000,000 | -HSD | C] -- C:\FOUND.024
[2012/01/29 12:26:38 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012/01/29 11:57:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\AVG2012
[2012/01/29 11:56:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2012/01/29 11:56:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\AVG Secure Search
[2012/01/29 11:56:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012/01/29 11:56:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search
[2012/01/29 11:56:01 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search
[2012/01/29 11:55:57 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/01/29 11:54:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/01/29 11:54:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2012/01/29 11:52:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2012/01/26 10:29:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\ZoomBrowser EX
[2012/01/26 10:27:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\My Documents\Canon Utilities
[2012/01/26 10:26:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\CANON INC
[2012/01/26 07:21:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Canon MyCameraFiles
[2012/01/26 07:20:28 | 000,000,000 | ---D | C] -- C:\Program Files\Canon
[2012/01/26 07:20:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2012/01/26 07:20:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2012/01/26 07:19:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC
[2012/01/26 07:17:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Canon
[2012/01/23 14:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2012/01/20 22:09:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alex\Application Data\com.w3i.FlipToast
[2012/01/20 22:09:11 | 000,000,000 | ---D | C] -- C:\Program Files\fliptoast
[2012/01/20 22:09:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR

========== Files - Modified Within 30 Days ==========

[2012/02/06 17:36:02 | 000,000,232 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/02/06 17:20:04 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/06 17:17:30 | 000,122,368 | ---- | M] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/06 16:36:40 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/06 16:36:28 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/06 16:36:24 | 2146,717,696 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/06 11:04:02 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2012/02/06 09:59:10 | 088,282,867 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/05 22:38:14 | 000,139,648 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/05 22:11:02 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/02/05 21:57:14 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Alex\My Documents\MBR.dat
[2012/02/05 10:16:44 | 000,731,688 | ---- | M] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2012/02/05 08:39:22 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/02/05 08:39:06 | 000,000,440 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
[2012/02/02 22:12:16 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat
[2012/02/02 22:12:16 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat
[2012/02/01 12:01:30 | 000,000,606 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/01/29 16:57:56 | 000,001,609 | ---- | M] () -- C:\WINDOWS\pstudio.ini
[2012/01/29 10:07:10 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\pixillionShakeIcon.job
[2012/01/28 23:58:44 | 000,071,634 | ---- | M] () -- C:\Documents and Settings\Alex\My Documents\ISO1.nri
[2012/01/26 07:22:06 | 000,000,543 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\DCSD Software Guide.lnk
[2012/01/26 07:22:00 | 000,000,555 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PowerShot S100 Camera User Guide.lnk
[2012/01/26 07:21:20 | 000,000,549 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Digital Photo Professional.lnk
[2012/01/26 07:20:24 | 000,000,679 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012/01/23 14:18:22 | 000,000,523 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2012/01/23 14:17:04 | 021,073,936 | ---- | M] () -- C:\Documents and Settings\Alex\My Documents\vlc-1.1.11-win32.exe
[2012/01/21 17:41:22 | 000,000,556 | ---- | M] () -- C:\Documents and Settings\Alex\Start Menu\Programs\Startup\fliptoast.lnk
[2012/01/20 22:14:20 | 008,261,192 | ---- | M] () -- C:\Documents and Settings\Alex\Desktop\DSC_2570.jpeg
[2012/01/10 22:16:08 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

========== Files Created - No Company Name ==========

[2012/02/06 09:59:09 | 088,282,867 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/05 21:57:12 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Alex\My Documents\MBR.dat
[2012/02/05 10:16:33 | 000,731,688 | ---- | C] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2012/01/29 11:56:19 | 000,000,606 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/01/26 11:37:41 | 000,091,584 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/01/26 07:22:04 | 000,000,543 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\DCSD Software Guide.lnk
[2012/01/26 07:22:00 | 000,000,555 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PowerShot S100 Camera User Guide.lnk
[2012/01/26 07:21:18 | 000,000,549 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Digital Photo Professional.lnk
[2012/01/26 07:20:22 | 000,000,679 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012/01/23 14:18:20 | 000,000,523 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2012/01/23 14:16:45 | 021,073,936 | ---- | C] () -- C:\Documents and Settings\Alex\My Documents\vlc-1.1.11-win32.exe
[2012/01/20 22:29:11 | 000,000,282 | ---- | C] () -- C:\WINDOWS\tasks\pixillionShakeIcon.job
[2012/01/20 22:14:14 | 008,261,192 | ---- | C] () -- C:\Documents and Settings\Alex\Desktop\DSC_2570.jpeg
[2012/01/20 22:12:53 | 013,914,414 | ---- | C] () -- C:\Documents and Settings\Alex\Desktop\DSC_2570.NEF
[2012/01/20 22:09:40 | 000,000,556 | ---- | C] () -- C:\Documents and Settings\Alex\Start Menu\Programs\Startup\fliptoast.lnk
[2011/05/29 22:15:40 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2011/05/29 22:15:40 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2011/04/13 22:24:17 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\housecall.guid.cache
[2010/10/12 20:41:33 | 000,171,695 | ---- | C] () -- C:\WINDOWS\hphins34.dat
[2010/10/12 20:41:33 | 000,000,532 | ---- | C] () -- C:\WINDOWS\hphmdl34.dat
[2010/09/19 08:44:06 | 000,000,943 | ---- | C] () -- C:\WINDOWS\WirelessCard.INI
[2010/06/06 17:35:51 | 000,172,130 | ---- | C] () -- C:\WINDOWS\hphins34.dat.temp
[2010/06/06 17:35:50 | 000,000,532 | ---- | C] () -- C:\WINDOWS\hphmdl34.dat.temp
[2009/05/06 10:45:44 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\acovcnt.exe
[2009/02/19 21:42:02 | 000,000,208 | ---- | C] () -- C:\WINDOWS\EliteCentral.ini
[2008/10/14 08:26:06 | 000,003,839 | ---- | C] () -- C:\WINDOWS\System32\drivers\GETPADD.sys
[2008/07/26 23:19:44 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008/06/26 20:15:05 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\HPPLVS.dll
[2008/06/16 23:50:11 | 000,000,098 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI
[2008/06/16 23:36:14 | 000,000,024 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008/05/09 22:04:21 | 000,000,204 | ---- | C] () -- C:\WINDOWS\MYOBP.INI
[2008/05/09 22:04:21 | 000,000,119 | ---- | C] () -- C:\WINDOWS\SwDrvs.ini
[2008/05/09 22:04:21 | 000,000,041 | ---- | C] () -- C:\WINDOWS\MYOB.INI
[2008/05/09 22:04:08 | 000,000,343 | ---- | C] () -- C:\WINDOWS\10ed.ini
[2008/05/09 22:02:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\drvxl32.INI
[2008/05/09 22:02:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\drvwd32.INI
[2008/05/08 14:53:54 | 000,001,609 | ---- | C] () -- C:\WINDOWS\pstudio.ini
[2008/05/08 14:53:54 | 000,000,028 | ---- | C] () -- C:\WINDOWS\album.ini
[2008/05/08 14:53:54 | 000,000,021 | ---- | C] () -- C:\WINDOWS\Ps_setup.ini
[2008/03/22 06:30:08 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/03/04 14:11:00 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/03/01 19:44:51 | 000,122,368 | ---- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/26 12:08:42 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/02/23 18:49:17 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/02/23 18:37:07 | 000,001,597 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2008/02/23 14:04:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/02/23 12:54:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\tosOBEX.INI
[2008/02/23 12:53:33 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Alex\Local Settings\Application Data\fusioncache.dat
[2008/02/23 12:53:21 | 000,000,546 | ---- | C] () -- C:\WINDOWS\System32\ABF3JR.DAT
[2008/02/19 15:36:07 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/02/19 15:33:14 | 000,033,136 | ---- | C] () -- C:\WINDOWS\ASScrPro.exe
[2008/02/19 15:33:04 | 000,037,232 | ---- | C] () -- C:\WINDOWS\ASScrProlog.exe
[2008/02/19 15:33:02 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2008/02/19 15:05:05 | 000,987,136 | ---- | C] () -- C:\WINDOWS\System32\wcourier.exe
[2008/02/19 14:58:07 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008/02/19 14:58:07 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008/02/19 14:39:54 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2008/02/19 14:39:11 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/02/19 14:34:25 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/02/19 14:30:56 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/02/19 14:30:23 | 000,139,648 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/02/19 14:14:44 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2008/02/19 14:14:38 | 000,136,650 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2008/02/19 14:06:04 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\SynSvc_.exe
[2008/02/19 14:06:04 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynSam.sys
[2008/02/19 14:06:04 | 000,007,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynScan.sys
[2008/02/19 14:05:56 | 000,498,688 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynPin.sys
[2008/02/19 14:05:55 | 001,116,544 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynMini.sys
[2008/02/19 14:05:55 | 000,045,056 | ---- | C] () -- C:\WINDOWS\StkUnist.exe
[2008/02/19 14:05:55 | 000,028,800 | ---- | C] () -- C:\WINDOWS\System32\drivers\SynCamd.sys
[2008/02/19 14:04:01 | 000,000,010 | ---- | C] () -- C:\WINDOWS\System32\ABLKSR.INI
[2008/02/19 14:03:53 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\ATKACPI.sys
[2007/11/28 04:26:10 | 000,438,272 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2007/07/26 12:01:50 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\hppatusg01.dll
[2006/08/17 10:55:17 | 000,007,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\MMIOPORT.SYS
[2006/08/17 10:55:17 | 000,002,538 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/08/17 10:54:47 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/08/17 10:54:45 | 000,442,896 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/08/17 10:54:45 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/08/17 10:54:45 | 000,072,308 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/08/17 10:54:45 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/08/17 10:54:43 | 000,004,487 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/08/17 10:54:39 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/08/17 10:54:38 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/08/17 10:54:35 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/08/17 10:54:35 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/08/17 10:54:32 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/08/17 10:54:21 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2005/09/02 14:44:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/22 21:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2005/04/02 16:30:00 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\scardsyn.dll
[2004/07/20 17:04:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 14:43:28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TBTMonUI.dll
[2000/01/31 08:02:00 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\Wh2Robo.dll
[1998/05/05 21:10:00 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\ODMA32.dll

========== LOP Check ==========

[2008/02/19 15:23:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Infineon
[2008/02/23 21:56:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2008/08/10 12:08:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008/10/13 12:51:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/10/13 18:55:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7
[2008/10/21 10:25:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Clipsal Australia
[2008/11/09 15:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{AD2241B4-DF72-4418-A91C-A27146879636}
[2009/02/19 21:02:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Quicken Elite
[2009/04/17 19:47:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/07/02 17:30:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GARMIN
[2009/11/23 20:27:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2009/12/28 18:44:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9(2)
[2011/04/10 22:37:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/10/26 15:06:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2011/12/04 13:28:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DatacardService
[2011/12/04 13:29:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Crazy Johns Broadband
[2012/01/26 07:19:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC
[2012/01/29 11:52:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2012/01/29 11:54:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/01/29 11:55:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/01/29 11:56:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2008/02/19 15:23:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\Infineon
[2008/02/29 19:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\JustVoip
[2008/05/09 11:31:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\Canon
[2008/07/28 20:16:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\ICQ
[2008/08/07 21:46:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\ICQ Toolbar
[2008/08/10 12:08:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\NCH Swift Sound
[2008/10/13 20:55:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\Asus
[2009/02/19 21:02:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\Quicken Elite
[2009/07/02 17:14:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\GARMIN
[2009/07/15 22:52:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\EuroTalk
[2009/11/23 20:26:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\TomTom
[2011/05/01 11:12:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\Umli
[2011/05/01 11:12:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\Lumax
[2011/05/01 18:34:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\TeamViewer
[2011/09/22 19:03:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\BitZipper
[2011/09/22 19:33:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\RegistryKeys
[2011/10/26 14:20:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\ImgBurn
[2012/01/20 22:09:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\com.w3i.FlipToast
[2012/01/29 11:56:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\AVG Secure Search
[2012/01/29 11:57:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alex\Application Data\AVG2012
[2012/02/05 22:11:02 | 000,000,486 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2012/02/06 17:36:02 | 000,000,232 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2012/01/29 10:07:10 | 000,000,282 | ---- | M] () -- C:\WINDOWS\Tasks\pixillionShakeIcon.job
[2011/10/06 18:19:02 | 000,000,278 | ---- | M] () -- C:\WINDOWS\Tasks\photopadShakeIcon.job
[2011/10/03 18:16:18 | 000,000,278 | ---- | M] () -- C:\WINDOWS\Tasks\photopadSevenDays.job

========== Purity Check ==========



< End of report >
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
A bit of housekeeping and a scan for orphans now I feel

Are you experiencing any further problems ?

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
    [2012/02/05 21:57:14 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Alex\My Documents\MBR.dat

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

THEN

Please download Malwarebytes' Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
  • 0

#5
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP