Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trojan horse hider, win32 lebag win32 heur I'm riddled HELP [Close


  • This topic is locked This topic is locked

#61
nobbyburton

nobbyburton

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 173 posts
OTL logfile created on: 3/11/2012 10:31:54 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 86.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): H:\pagefile.sys 1024 2048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 11.46 Gb Free Space | 4.92% Space Free | Partition Type: NTFS
Drive D: | 6.57 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 970.53 Mb Total Space | 841.95 Mb Free Space | 86.75% Space Free | Partition Type: FAT32
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet002

========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand] -- -- (WmdmPmSN)
SRV - File not found [On_Demand] -- -- (HTTPFilter)
SRV - File not found [Auto] -- -- (helpsvc)
SRV - [2012/01/31 11:02:52 | 007,391,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2012/01/16 17:03:55 | 000,909,152 | ---- | M] () [Auto] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe -- (vToolbarUpdater)
SRV - [2011/11/10 09:17:31 | 000,167,264 | ---- | M] () [On_Demand] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2011/02/08 00:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2009/09/08 12:25:52 | 000,096,334 | ---- | M] (Canon Inc.) [Auto] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2009/01/28 03:39:02 | 000,185,640 | ---- | M] (TeamViewer GmbH) [Auto] -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe -- (TeamViewer4)
SRV - [2006/10/13 13:01:06 | 000,207,664 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - File not found [Kernel | On_Demand] -- -- (catchme)
DRV - [2012/03/10 21:08:10 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2012/03/09 13:09:36 | 000,475,736 | ---- | M] (Kaspersky Lab) [File_System | System] -- C:\WINDOWS\system32\drivers\2278046drv.sys -- (2278046drv)
DRV - [2012/03/09 13:09:36 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\54823927.sys -- (54823927)
DRV - [2011/05/27 14:05:44 | 000,134,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/04/04 19:59:56 | 000,297,168 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/03/16 11:03:20 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/03/01 09:25:18 | 000,034,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/02/22 03:13:02 | 000,022,992 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV - [2011/02/10 02:53:54 | 000,027,216 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/02/10 02:53:52 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/01/07 01:41:46 | 000,248,656 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/03/10 04:18:20 | 000,024,216 | ---- | M] (Initio Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ivusb.sys -- (ivusb)
DRV - [2010/02/26 09:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010/02/26 09:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010/02/26 09:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/02/26 09:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009/10/30 18:59:02 | 000,064,000 | ---- | M] () [Kernel | System] -- C:\Program Files\Clarus\Samsung SecretZone\mvd20.sys -- (mvd20)
DRV - [2009/08/05 17:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009/04/21 09:25:30 | 000,012,800 | ---- | M] () [Kernel | System] -- C:\Program Files\Clarus\Samsung SecretZone\mdf15.sys -- (mdf15)
DRV - [2008/08/26 05:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/04/13 14:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2007/03/16 06:11:38 | 000,012,256 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto] -- C:\WINDOWS\System32\drivers\TBPanel.sys -- (TBPanel)
DRV - [2007/03/16 06:11:38 | 000,012,256 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\TBPanel.sys -- (Cardex)
DRV - [2006/10/13 13:04:30 | 001,966,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\VX3000.sys -- (VX3000)
DRV - [2006/05/01 08:50:40 | 000,086,560 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\SE26obex.sys -- (SE26obex)
DRV - [2006/05/01 08:49:50 | 000,088,688 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\SE26mgmt.sys -- (SE26mgmt) Sony Ericsson Device 038 USB WMC Device Management Drivers (WDM)
DRV - [2006/05/01 08:49:00 | 000,097,184 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\SE26mdm.sys -- (SE26mdm)
DRV - [2006/05/01 08:48:56 | 000,009,360 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\SE26mdfl.sys -- (SE26mdfl)
DRV - [2006/05/01 08:48:04 | 000,061,600 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\SE26bus.sys -- (SE26bus) Sony Ericsson Device 038 Driver driver (WDM)
DRV - [2006/05/01 08:47:30 | 000,018,704 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\se26nd5.sys -- (se26nd5) Sony Ericsson Device 038 USB Ethernet Emulation SEMC38 (NDIS)
DRV - [2006/05/01 08:47:24 | 000,090,768 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\se26unic.sys -- (se26unic) Sony Ericsson Device 038 USB Ethernet Emulation SEMC38 (WDM)
DRV - [2006/03/13 23:23:26 | 000,082,048 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2006/02/20 14:59:36 | 000,083,344 | R--- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\w810obex.sys -- (w810obex)
DRV - [2006/02/20 14:59:34 | 000,094,064 | R--- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\w810mdm.sys -- (w810mdm)
DRV - [2006/02/20 14:59:34 | 000,085,408 | R--- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\w810mgmt.sys -- (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM)
DRV - [2006/02/20 14:59:32 | 000,008,336 | R--- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\w810mdfl.sys -- (w810mdfl)
DRV - [2006/02/20 14:59:28 | 000,058,288 | R--- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\w810bus.sys -- (w810bus) Sony Ericsson W810 Driver driver (WDM)
DRV - [2006/01/18 22:01:00 | 000,017,280 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ctpdusb.sys -- (Jukebox3)
DRV - [2005/08/11 01:49:28 | 000,393,088 | R--- | M] (Sensaura) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2005/02/11 17:46:22 | 000,371,712 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2004/10/27 11:21:30 | 000,145,920 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService)
DRV - [2004/08/12 22:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004/06/08 18:13:49 | 000,003,968 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2004/06/03 08:10:00 | 000,071,596 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\PfModNT.sys -- (PfModNT)
DRV - [2002/09/09 15:54:06 | 000,016,269 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand] -- C:\WINDOWS\system32\ASNDIS5.sys -- (ASNDIS5)
DRV - [2001/08/17 10:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Andy_&_Joanna_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sky.com
IE - HKU\Andy_&_Joanna_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.newsnow.c...pur/All Sources
IE - HKU\Andy_&_Joanna_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Andy_&_Joanna_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local



FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{B73DC3E6-5AA7-4F69-A6DA-F8F00F7AEE36}: H:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\{B73DC3E6-5AA7-4F69-A6DA-F8F00F7AEE36} [2010/07/19 13:38:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: H:\Program Files\AVG\AVG10\Firefox4\ [2012/02/02 18:30:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: H:\Documents and Settings\All Users\Application Data\AVG Secure Search\10.0.0.7\ [2012/01/16 17:04:21 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}: H:\Program Files\PriceGong\2.1.0\FF [2010/05/11 17:13:13 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2012/03/09 18:17:33 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ALOT Toolbar Helper) - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\alot.dll (Vertro)
O2 - BHO: (no name) - {1631550F-191D-4826-B069-D9439253D926} - No CLSID value found.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Vertro)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKU\Andy_&_Joanna_ON_C\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Gainward] C:\Program Files\XpertVision\TBPanel.exe (Xpertvision, Inc.)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [ROC_roc_dec12] C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe ()
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [VX3000] C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [HorAtbfq] C:\Documents and Settings\NetworkService\Local Settings\Application Data\yiangwkb\horatbfq.exe ()
O4 - HKU\Andy_&_Joanna_ON_C..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Audible, Inc.)
O4 - Startup: C:\Documents and Settings\Andy & Joanna\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Andy & Joanna\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\Andy & Joanna\Start Menu\Programs\Startup\_uninst_11160100.lnk = C:\Documents and Settings\Andy & Joanna\Local Settings\Temp\_uninst_11160100.bat ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Andy_&_Joanna_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\Andy_&_Joanna_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_15.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - File not found
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.aka...vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} https://moneymanager...unttracking.cab (Egg Money Manager Digital Safe)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1199526417500 (WUWebControl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {7ECB1A47-6647-4B2C-A8DA-675569C9FF15} http://services.soft...geUploader7.cab (Image Uploader Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebo...Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} https://www.plaxo.co...upldr-2k-xp.cab (Plaxo Auto-Import Utility)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 90.207.238.97 90.207.238.99
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - File not found
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (H:\Documents and Settings\NetworkService\Local Settings\Application Data\yiangwkb\horatbfq.exe) - C:\Documents and Settings\NetworkService\Local Settings\Application Data\yiangwkb\horatbfq.exe ()
O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/23 03:22:58 | 000,000,285 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{0fcca0c9-1439-11e0-9900-001d6030268b}\Shell - "" = AutoRun
O33 - MountPoints2\{0fcca0c9-1439-11e0-9900-001d6030268b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0fcca0c9-1439-11e0-9900-001d6030268b}\Shell\AutoRun\command - "" = J:\DPFMate.exe
O33 - MountPoints2\{433a36a8-9f5b-11e0-9986-001d6030268b}\Shell - "" = AutoRun
O33 - MountPoints2\{433a36a8-9f5b-11e0-9986-001d6030268b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{433a36a8-9f5b-11e0-9986-001d6030268b}\Shell\AutoRun\command - "" = K:\laucher.exe
O33 - MountPoints2\{a30bc684-7709-11de-8693-001d6030268b}\Shell - "" = AutoRun
O33 - MountPoints2\{a30bc684-7709-11de-8693-001d6030268b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a30bc684-7709-11de-8693-001d6030268b}\Shell\AutoRun\command - "" = L:\SafeStick.exe
O33 - MountPoints2\{cf3ef115-07c9-11dd-9bda-001d6030268b}\Shell - "" = AutoRun
O33 - MountPoints2\{cf3ef115-07c9-11dd-9bda-001d6030268b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cf3ef115-07c9-11dd-9bda-001d6030268b}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- [2007/10/23 07:45:40 | 001,336,632 | R--- | M] ()
O33 - MountPoints2\{dc787f38-8a52-11de-86b1-001d6030268b}\Shell - "" = AutoRun
O33 - MountPoints2\{dc787f38-8a52-11de-86b1-001d6030268b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{dc787f38-8a52-11de-86b1-001d6030268b}\Shell\AutoRun\command - "" = J:\SafeStick.exe
O33 - MountPoints2\{e2a00ee0-bb7d-11dc-9b70-001d6030268b}\Shell\AutoRun\command - "" = J:\Blackwell.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (H:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (H:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: helpsvc - File not found
NetSvcs: WmdmPmSN - File not found

========== Files/Folders - Created Within 30 Days ==========

[2012/03/11 04:46:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andy & Joanna\Start Menu\Programs\CyberLink PowerDVD
[2012/03/10 21:07:41 | 000,475,736 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\2278046drv.sys
[2012/03/10 21:07:41 | 000,133,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\54823927.sys
[2012/03/10 21:00:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\yiangwkb
[2012/03/10 16:51:23 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/03/10 16:48:17 | 000,000,000 | --SD | C] -- C:\ComboFix
[2012/03/10 16:39:47 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/03/10 16:38:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/03/10 16:38:09 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/03/09 18:33:46 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/03/09 18:16:57 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/03/09 16:41:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Google
[2012/03/09 16:41:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\AskToolbar
[2012/03/09 16:41:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2012/03/09 16:41:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2012/03/09 16:39:51 | 000,000,000 | R--D | C] -- C:\Documents and Settings\LocalService\Favorites
[2012/03/07 19:31:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2012/03/07 15:49:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\yiangwkb

========== Files - Modified Within 30 Days ==========

[2012/03/11 17:17:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/03/11 17:14:32 | 000,098,368 | -H-- | M] () -- C:\WINDOWS\System32\4Ex8PA3
[2012/03/11 14:02:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/11 14:01:00 | 000,000,250 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/03/11 14:00:07 | 000,000,458 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Registration.job
[2012/03/11 13:58:19 | 000,000,364 | RHS- | M] () -- C:\boot.ini
[2012/03/11 13:47:26 | 000,319,103 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/03/11 12:46:19 | 091,431,967 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/03/11 05:16:38 | 000,000,000 | R--D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2012/03/11 05:12:01 | 000,000,558 | ---- | M] () -- C:\WINDOWS\DFC.INI
[2012/03/11 04:55:15 | 000,098,368 | -H-- | M] () -- C:\Documents and Settings\Andy & Joanna\Desktop\4Ex8PA3
[2012/03/11 04:54:48 | 000,098,368 | -H-- | M] () -- C:\Documents and Settings\Andy & Joanna\4Ex8PA3
[2012/03/11 04:46:33 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/03/11 04:46:24 | 000,098,368 | -H-- | M] () -- C:\WINDOWS\System32\idLl3SAc
[2012/03/11 04:46:23 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/11 04:46:14 | 000,098,368 | --S- | M] () -- C:\horatbfq.exe
[2012/03/10 21:08:10 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/03/10 19:11:09 | 000,000,838 | ---- | M] () -- C:\Documents and Settings\Andy & Joanna\Start Menu\Programs\Startup\_uninst_11160100.lnk
[2012/03/10 18:45:17 | 000,098,368 | -H-- | M] () -- C:\WINDOWS\System32\a7nkjz3
[2012/03/10 18:45:15 | 000,098,368 | -H-- | M] () -- C:\WINDOWS\System32\cRrO623
[2012/03/10 18:45:12 | 000,098,368 | -H-- | M] () -- C:\WINDOWS\System32\a2JGu23
[2012/03/10 13:06:23 | 000,445,144 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/03/10 13:06:23 | 000,072,910 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/03/09 18:17:33 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2012/03/09 15:26:41 | 000,002,187 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2012/03/09 13:09:36 | 000,475,736 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\2278046drv.sys
[2012/03/09 13:09:36 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\54823927.sys
[2012/03/08 18:39:55 | 000,277,352 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/08 18:06:36 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/03/07 18:27:10 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/07 18:27:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/05 16:32:36 | 000,032,256 | ---- | M] () -- C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/29 16:15:01 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/02/23 14:40:29 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/17 14:13:46 | 000,002,193 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Safari.lnk
[2012/02/16 18:40:15 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/02/16 18:39:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2012/02/16 15:55:28 | 000,001,052 | ---- | M] () -- C:\Documents and Settings\Andy & Joanna\Start Menu\Programs\Startup\Dropbox.lnk
[2012/02/16 15:55:28 | 000,001,052 | ---- | M] () -- C:\Documents and Settings\Andy & Joanna\Desktop\Dropbox.lnk

========== Files Created - No Company Name ==========

[2012/03/11 04:55:15 | 000,098,368 | -H-- | C] () -- C:\Documents and Settings\Andy & Joanna\Desktop\4Ex8PA3
[2012/03/11 04:54:46 | 000,098,368 | -H-- | C] () -- C:\Documents and Settings\Andy & Joanna\4Ex8PA3
[2012/03/11 04:46:24 | 000,098,368 | -H-- | C] () -- C:\WINDOWS\System32\idLl3SAc
[2012/03/11 04:46:19 | 000,098,368 | --S- | C] () -- C:\horatbfq.exe
[2012/03/11 04:46:09 | 000,098,368 | -H-- | C] () -- C:\WINDOWS\System32\4Ex8PA3
[2012/03/10 19:11:09 | 000,000,838 | ---- | C] () -- C:\Documents and Settings\Andy & Joanna\Start Menu\Programs\Startup\_uninst_11160100.lnk
[2012/03/10 16:51:28 | 000,000,210 | ---- | C] () -- C:\Boot.bak
[2012/03/10 16:51:26 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/03/09 18:28:00 | 000,098,368 | -H-- | C] () -- C:\WINDOWS\System32\a7nkjz3
[2012/03/09 18:27:55 | 000,098,368 | -H-- | C] () -- C:\WINDOWS\System32\cRrO623
[2012/03/09 18:27:50 | 000,098,368 | -H-- | C] () -- C:\WINDOWS\System32\a2JGu23
[2012/03/07 18:27:10 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/16 15:55:09 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/16 15:55:09 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2011/08/07 08:25:11 | 000,000,020 | ---- | C] () -- C:\WINDOWS\System32\MSWYXTND.DLL
[2010/08/16 14:32:27 | 000,590,816 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/13 17:28:39 | 000,000,186 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2010/03/12 13:01:09 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/09/14 10:06:27 | 000,058,644 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/08/03 10:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 10:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/23 17:23:51 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2009/07/04 07:10:32 | 003,525,811 | ---- | C] () -- C:\Documents and Settings\Andy & Joanna\Application Data\NMM-MetaData.db
[2009/06/30 15:45:40 | 000,000,332 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/06/25 11:52:10 | 000,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/06/25 11:52:10 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2009/06/25 11:52:08 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009/06/25 11:52:08 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/06/24 05:16:34 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Andy & Joanna\Application Data\$_hpcst$.hpc
[2009/04/16 15:30:34 | 000,034,981 | ---- | C] () -- C:\Documents and Settings\Andy & Joanna\Start Menu.rar
[2009/02/16 08:33:02 | 000,000,091 | ---- | C] () -- C:\WINDOWS\quadriga.ini
[2008/03/21 14:25:02 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\PdeSrvps.dll
[2008/03/21 14:24:30 | 000,250,368 | ---- | C] () -- C:\WINDOWS\UNWISE.EXE
[2008/03/21 13:51:34 | 000,139,786 | ---- | C] () -- C:\WINDOWS\hpoins15.dat
[2008/03/21 13:51:34 | 000,001,039 | ---- | C] () -- C:\WINDOWS\hpomdl15.dat
[2008/01/29 16:53:04 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDER300Euro.ini
[2008/01/29 16:52:52 | 000,000,182 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT4.DAT
[2008/01/29 15:59:52 | 002,357,248 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/01/29 15:59:52 | 000,497,152 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008/01/29 15:59:52 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008/01/29 15:59:52 | 000,214,016 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/01/27 16:29:39 | 000,000,517 | ---- | C] () -- C:\WINDOWS\MP3trt.ini
[2008/01/26 09:14:50 | 000,380,928 | ---- | C] () -- C:\WINDOWS\System32\ammpp.dll
[2008/01/26 09:14:50 | 000,193,536 | ---- | C] () -- C:\WINDOWS\System32\atomid.exe
[2008/01/26 09:14:50 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\a1.dll
[2008/01/26 06:58:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2008/01/26 05:53:36 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/01/05 07:06:36 | 000,032,256 | ---- | C] () -- C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/05 05:10:18 | 000,525,824 | ---- | C] () -- C:\WINDOWS\System32\ASWL2K.exe
[2008/01/05 05:10:18 | 000,496,640 | ---- | C] () -- C:\WINDOWS\System32\ASWLSVC.exe
[2008/01/05 05:10:18 | 000,159,827 | ---- | C] () -- C:\WINDOWS\System32\RemSvc.exe
[2008/01/04 19:07:02 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/01/03 19:59:02 | 000,000,558 | ---- | C] () -- C:\WINDOWS\DFC.INI
[2008/01/03 19:53:40 | 000,015,891 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008/01/03 19:53:38 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/01/03 19:53:35 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/01/03 19:46:14 | 001,437,696 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2008/01/03 19:46:14 | 000,544,768 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2008/01/03 19:46:14 | 000,528,384 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2008/01/03 19:46:13 | 001,806,336 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/01/03 19:46:13 | 001,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/01/03 19:46:13 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/01/03 19:46:13 | 000,385,024 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/01/03 19:33:32 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/01/03 19:28:56 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/01/03 18:17:26 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/01/03 18:14:26 | 000,277,352 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/04/14 22:30:47 | 000,015,498 | ---- | C] () -- C:\WINDOWS\VX3000.ini
[2006/02/28 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/02/28 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/02/28 08:00:00 | 000,445,144 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/02/28 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/02/28 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/02/28 08:00:00 | 000,072,910 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/02/28 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/02/28 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/02/28 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/02/28 08:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/02/28 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/02/28 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/12/21 06:13:56 | 000,191,136 | ---- | C] () -- C:\WINDOWS\System32\plx_upldr.dll

========== LOP Check ==========

[2010/07/27 13:28:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\4C5A5FEE6EA00812DBE8AB71C400E3A0
[2010/05/11 17:13:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\alot
[2011/12/16 05:50:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\AVG Secure Search
[2010/12/06 16:46:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\AVG10
[2012/03/11 04:48:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\Dropbox
[2009/07/23 17:41:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\ICAClient
[2008/01/04 20:23:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\muvee Technologies
[2010/12/29 10:48:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\Nokia
[2009/07/04 06:54:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\Nseries
[2009/07/04 06:38:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\PC Suite
[2012/03/07 18:45:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\PriceGong
[2009/12/13 12:49:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\Printer Info Cache
[2011/07/28 15:07:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\Red Kawa
[2009/02/13 04:20:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\TeamViewer
[2008/01/26 05:21:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\Teleca
[2012/03/05 18:30:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\uTorrent
[2009/09/19 06:15:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andy & Joanna\Application Data\YouSendIt
[2012/01/16 17:04:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2010/12/06 16:45:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2012/03/10 21:02:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/12/06 16:38:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2009/01/20 20:17:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cached Installations
[2011/02/17 18:48:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Clarus
[2010/12/06 16:45:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/08/04 15:27:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2011/02/27 15:33:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kAmNoBc06308
[2008/02/03 10:09:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/05/07 12:06:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2008/01/03 19:48:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/09/28 13:42:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2009/01/20 20:17:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/07/04 06:53:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2008/01/04 20:22:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/01/29 16:54:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2010/05/29 07:47:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/14 08:56:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/11 07:58:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2012/03/11 14:00:07 | 000,000,458 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Registration.job
[2012/03/11 14:01:00 | 000,000,250 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2012/03/11 04:46:14 | 000,098,368 | --S- | M] () -- C:\horatbfq.exe


< MD5 for: EXPLORER.EXE >
[2007/06/13 06:23:07 | 001,134,080 | ---- | M] (Microsoft Corporation) MD5=0525D08F6213090563C9EBC3FD3A6BAA -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,134,592 | ---- | M] (Microsoft Corporation) MD5=9C0A2F103215B79F8317E11514387AD6 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,134,080 | ---- | M] (Microsoft Corporation) MD5=D8FD9684C8D42F1F5F83DA257686263C -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2006/02/28 08:00:00 | 001,133,056 | ---- | M] (Microsoft Corporation) MD5=E6C04B753303B8E919A7FE3273DB990E -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2008/04/13 20:12:19 | 001,134,592 | ---- | M] (Microsoft Corporation) MD5=EC3758A2D91FB1F5D7A9ABB7BF87DBD9 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 20:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2006/02/28 08:00:00 | 000,115,200 | ---- | M] (Microsoft Corporation) MD5=2DAA071FE574323318FD3D819D401B30 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2012/01/13 10:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/04/13 20:12:36 | 000,115,200 | ---- | M] (Microsoft Corporation) MD5=B58E6FEE09052321E402AD15B4366862 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe

< MD5 for: USERINIT.EXE >
[2006/02/28 08:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008/04/13 20:12:39 | 000,608,768 | ---- | M] (Microsoft Corporation) MD5=21BAE44C7C146715473E4C9BEEFB7498 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2006/02/28 08:00:00 | 000,603,136 | ---- | M] (Microsoft Corporation) MD5=60AF954E20F59EEDF71DF85B65A2FC41 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/01/13 10:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT /s >
"Type" = 1
"Start" = 1
"ErrorControl" = 1
"Tag" = 6
"ImagePath" = system32\DRIVERS\netbt.sys -- [2008/04/13 15:21:00 | 000,162,816 | ---- | M] (Microsoft Corporation)
"DisplayName" = NetBios over Tcpip
"Group" = PNP_TDI
"DependOnService" = Tcpip [binary data]
"DependOnGroup" = [binary data]
"Description" = NetBios over Tcpip
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Linkage]
"OtherDependencies" = Tcpip [binary data]
"Bind" = [Binary data over 100 bytes]
"Route" = [Binary data over 100 bytes]
"Export" = [Binary data over 100 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters]
"NbProvider" = _tcp
"NameServerPort" = 137
"CacheTimeout" = 600000
"BcastNameQueryCount" = 3
"BcastQueryTimeout" = 750
"NameSrvQueryCount" = 3
"NameSrvQueryTimeout" = 1500
"Size/Small/Medium/Large" = 1
"SessionKeepAlive" = 3600000
"TransportBindName" = \Device\
"EnableLMHOSTS" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{4598F7AE-1A5B-4B72-8903-3E685FFE2FE9}]
"NameServerList" = [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{6BDC5713-9FCB-4158-A5AA-EC724B3D3F47}]
"NameServerList" = [binary data]
"NetbiosOptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{6EFCB436-CE30-4096-96DC-190682815772}]
"NameServerList" = [binary data]
"NetbiosOptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{DC0999A4-425F-402F-9156-FD1D20292D19}]
"NameServerList" = [binary data]
"NetbiosOptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{DF4B3AC5-15D4-4328-9E55-47F62CFD92A1}]
"NameServerList" = [binary data]
"NetbiosOptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{F9DB83B2-8293-4CB4-AAB4-558DC381A356}]
"NameServerList" = [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{FFB5F31A-4F91-4CB8-AC50-9035B5319D86}]
"NameServerList" = [binary data]
"NetbiosOptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Security]
"Security" = [Binary data over 100 bytes]

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS /s >
"Type" = 2
"Start" = 1
"ErrorControl" = 1
"Tag" = 1
"ImagePath" = system32\DRIVERS\netbios.sys -- [2008/04/13 14:56:02 | 000,034,688 | ---- | M] (Microsoft Corporation)
"DisplayName" = NetBIOS Interface
"Group" = NetBIOSGroup
"Description" = NetBIOS Interface
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage]
"LanaMap" = 01 06 01 05 01 04 01 03 01 00 00 01 00 02 [binary data]
"Bind" = [Binary data over 100 bytes]
"Route" = [Binary data over 100 bytes]
"Export" = [Binary data over 100 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS\Parameters]
"MaxLana" = 6
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS\Parameters\Winsock]
"HelperDllName" = %SystemRoot%\System32\wshnetbs.dll -- [2006/02/28 08:00:00 | 000,007,168 | ---- | M] (Microsoft Corporation)
"MaxSockAddrLength" = 20
"MinSockAddrLength" = 20
"Mapping" = 02 00 00 00 03 00 00 00 11 00 00 00 05 00 00 00 00 00 00 00 11 00 00 00 02 00 00 00 00 00 00 00 [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS\Security]
"Security" = [Binary data over 100 bytes]

< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command\\: "H:\Program Files\Google\Chrome\Application\chrome.exe" [2012/03/08 10:28:54 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "H:\Program Files\Google\Chrome\Application\chrome.exe" --show-icons [2012/03/08 10:28:54 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "H:\Program Files\Google\Chrome\Application\chrome.exe" --hide-icons [2012/03/08 10:28:54 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "H:\Program Files\Google\Chrome\Application\chrome.exe" --make-default-browser [2012/03/08 10:28:54 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "H:\Program Files\Google\Chrome\Application\chrome.exe" [2012/03/08 10:28:54 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "H:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/12/16 08:22:03 | 000,171,520 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "H:\WINDOWS\system32\ie4uinit.exe" -hide [2011/12/16 08:22:03 | 000,171,520 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "H:\WINDOWS\system32\ie4uinit.exe" -show [2011/12/16 08:22:03 | 000,171,520 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: H:\Program Files\Internet Explorer\iexplore.exe [2011/12/16 07:00:16 | 000,634,680 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "H:\Program Files\Safari\Safari.exe" /reinstall [2011/11/10 13:19:40 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "H:\Program Files\Safari\Safari.exe" /hideicons [2011/11/10 13:19:40 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "H:\Program Files\Safari\Safari.exe" /showicons [2011/11/10 13:19:40 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "H:\Program Files\Safari\Safari.exe" [2011/11/10 13:19:40 | 002,388,848 | ---- | M] (Apple Inc.)

< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command\\: "H:\Program Files\Google\Chrome\Application\chrome.exe" [2012/03/08 10:28:54 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "H:\Program Files\Google\Chrome\Application\chrome.exe" --show-icons [2012/03/08 10:28:54 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "H:\Program Files\Google\Chrome\Application\chrome.exe" --hide-icons [2012/03/08 10:28:54 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "H:\Program Files\Google\Chrome\Application\chrome.exe" --make-default-browser [2012/03/08 10:28:54 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "H:\Program Files\Google\Chrome\Application\chrome.exe" [2012/03/08 10:28:54 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "H:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/12/16 08:22:03 | 000,171,520 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "H:\WINDOWS\system32\ie4uinit.exe" -hide [2011/12/16 08:22:03 | 000,171,520 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "H:\WINDOWS\system32\ie4uinit.exe" -show [2011/12/16 08:22:03 | 000,171,520 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: H:\Program Files\Internet Explorer\iexplore.exe [2011/12/16 07:00:16 | 000,634,680 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "H:\Program Files\Safari\Safari.exe" /reinstall [2011/11/10 13:19:40 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "H:\Program Files\Safari\Safari.exe" /hideicons [2011/11/10 13:19:40 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "H:\Program Files\Safari\Safari.exe" /showicons [2011/11/10 13:19:40 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "H:\Program Files\Safari\Safari.exe" [2011/11/10 13:19:40 | 002,388,848 | ---- | M] (Apple Inc.)

< C:\Windows\assembly\tmp\U\*.* /s >

< C:\Program Files\Common Files\ComObjects\*.* /s >

Invalid Environment Variable: %Temp%\smtmp\1\*.*

Invalid Environment Variable: %Temp%\smtmp\2\*.*

Invalid Environment Variable: %Temp%\smtmp\3\*.*

Invalid Environment Variable: %Temp%\smtmp\4\*.*
< End of report >
  • 0

Advertisements


#62
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Restart Reatogo (unless still running )

Download the attached fix.txt to the USB drive
[attachment=56557:fix.txt]
Run OTL and press the Run Fix button
OTL will then ask for the location of Fix.txt
Locate it on your USB drive and select it
Press Run Fix again
Once completed reboot and see if you can achieve normal mode
  • 0

#63
nobbyburton

nobbyburton

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 173 posts
Just to check presumably reboot minus the reatogo disk
  • 0

#64
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Not really necessary.. When the press any key to boot from CD appears if you ignore it it should go direct to windows
  • 0

#65
nobbyburton

nobbyburton

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 173 posts
Ok appreciate it's Late on a Sunday, can't believe this but it's still coming up with that stupid box like on my earlier twitter pic, I can't do anything but enter or escape and it immediately logs off the Andy & Joanna user I don't think I've done anything wrong, should I try running the run fix again
  • 0

#66
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Do you have additional users on the computer ?
  • 0

#67
nobbyburton

nobbyburton

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 173 posts
No but when I did scan from otlpe, andy & Joanna was first in the list, then local and network machine were the other 2 listed, but I checked the box as you said
  • 0

#68
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Start the computer to the Reatogo desktop
  • Using Explorer locate the USB drive
  • Run frst.exe
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

  • 0

#69
nobbyburton

nobbyburton

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 173 posts
How do I know if my system is 32 pr 64 bit

  • 0

#70
nobbyburton

nobbyburton

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 173 posts
Will download both
  • 0

Advertisements


#71
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Oops sorry you are 32bit :blush:
  • 0

#72
nobbyburton

nobbyburton

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 173 posts
Scan result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 11-03-2012
Ran by SYSTEM at 12-03-2012 01:46:56
Running from E:\
Microsoft Windows XP (X86) OS Language: English(US)
The current controlset is ControlSet002

========================== Registry (Whitelisted) =============

HKLM\...\Run: [Gainward] H:\Program Files\XpertVision\TBPanel.exe /A [2165256 2007-11-01] (Xpertvision, Inc.)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup [8491008 2007-09-16] (NVIDIA Corporation)
HKLM\...\Run: [NeroFilterCheck] H:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [161328 2007-05-04] (Nero AG)
HKLM\...\Run: [RemoteControl] "H:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [56928 2006-11-23] (Cyberlink Corp.)
HKLM\...\Run: [LanguageShortcut] "H:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [54832 2006-12-05] ()
HKLM\...\Run: [VX3000] H:\WINDOWS\vVX3000.exe [707376 2006-10-13] (Microsoft Corporation)
HKLM\...\Run: [LifeCam] "H:\Program Files\Microsoft LifeCam\LifeExp.exe" [277296 2006-10-13] (Microsoft Corporation)
HKLM\...\Run: [AppleSyncNotifier] H:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.)
HKLM\...\Run: [GrooveMonitor] "H:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [AVG_TRAY] H:\Program Files\AVG\AVG10\avgtray.exe [2339168 2012-01-17] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "H:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [40368 2011-08-30] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "H:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-29] (Adobe Systems Incorporated)
HKLM\...\Run: [DivXUpdate] "H:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1230704 2011-03-21] ()
HKLM\...\Run: [vProt] "H:\Program Files\AVG Secure Search\vprot.exe" [939872 2012-01-16] ()
HKLM\...\Run: [APSDaemon] "H:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM\...\Run: [ROC_roc_dec12] "H:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 [928096 2012-01-16] ()
HKLM\...\Run: [iTunesHelper] "H:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM\...\Run: [MSConfig] H:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto [169984 2008-04-13] (Microsoft Corporation)
HKU\Andy & Joanna\...\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe [15360 2008-04-13] (Microsoft Corporation)
HKU\Andy & Joanna\...\Run: [H/PC Connection Agent] "H:\Program Files\Microsoft ActiveSync\wcescomm.exe" [1289000 2006-11-13] (Microsoft Corporation)
HKU\Andy & Joanna\...\Run: [SpybotSD TeaTimer] H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\Andy & Joanna\...\Run: [swg] "H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [68856 2008-01-27] (Google Inc.)
HKU\Andy & Joanna\...\Run: [HorAtbfq] H:\Documents and Settings\NetworkService\Local Settings\Application Data\yiangwkb\horatbfq.exe [98368 2012-03-11] ()
HKU\Andy & Joanna\...\Policies\system: [disableregistrytools] 0
HKLM\...\Winlogon: [Userinit] H:\WINDOWS\system32\userinit.exe,,H:\Documents and Settings\NetworkService\Local Settings\Application Data\yiangwkb\horatbfq.exe [98368 2012-03-11] ()
Winlogon\Notify\crypt32chain: crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet: cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll: cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy: %SystemRoot%\System32\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp: wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\Schedule: wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\sclgntfy: sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SensLogn: WlNotify.dll (Microsoft Corporation)
Winlogon\Notify\termsrv: wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
Winlogon\Notify\wlballoon: wlnotify.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 90.207.238.97 90.207.238.99
Tcpip\..\Interfaces\{DF4B3AC5-15D4-4328-9E55-47F62CFD92A1}: [NameServer]192.168.0.1

================================ Services (Whitelisted) ==================

4 Alerter; C:\Windows\System32\svchost.exe -k LocalService [14336 2008-04-13] (Microsoft Corporation)
3 AppMgmt; C:\Windows\System32\svchost.exe -k netsvcs [14336 2008-04-13] (Microsoft Corporation)
3 AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [167264 2011-11-10] ()
2 AVGIDSAgent; "C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe" [7391072 2012-01-31] (AVG Technologies CZ, s.r.o.)
2 avgwd; "C:\Program Files\AVG\AVG10\avgwdsvc.exe" [269520 2011-02-08] (AVG Technologies CZ, s.r.o.)
3 BITS; C:\Windows\System32\svchost.exe -k netsvcs [14336 2008-04-13] (Microsoft Corporation)
2 CCALib8; C:\Program Files\Canon\CAL\CALMAIN.exe [96334 2009-09-08] (Canon Inc.)
2 Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.EXE [44032 1999-12-12] (Creative Technology Ltd)
3 EapHost; C:\Windows\System32\svchost.exe -k eapsvcs [14336 2008-04-13] (Microsoft Corporation)
2 Eventlog; C:\Windows\System32\services.exe [110592 2009-02-06] (Microsoft Corporation)
2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [135664 2010-02-02] (Google Inc.)
3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [135664 2010-02-02] (Google Inc.)
3 hkmsvc; C:\Windows\System32\svchost.exe -k netsvcs [14336 2008-04-13] (Microsoft Corporation)
2 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" [322120 2003-06-19] (Microsoft Corporation)
4 Messenger; C:\Windows\System32\svchost.exe -k netsvcs [14336 2008-04-13] (Microsoft Corporation)
3 napagent; C:\Windows\System32\svchost.exe -k netsvcs [14336 2008-04-13] (Microsoft Corporation)
3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [267824 2007-05-04] (Nero AG)
2 TeamViewer4; "C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe" -service [185640 2009-01-28] (TeamViewer GmbH)
3 upnphost; C:\Windows\System32\svchost.exe -k LocalService [14336 2008-04-13] (Microsoft Corporation)
2 vToolbarUpdater; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe [909152 2012-01-16] ()
3 WmdmPmSN; C:\Windows\System32\svchost.exe -k netsvcs [14336 2008-04-13] (Microsoft Corporation)
3 xmlprov; C:\Windows\System32\svchost.exe -k netsvcs [14336 2008-04-13] (Microsoft Corporation)
2 helpsvc; C:\Windows\PCHealth\HelpCtr\Binaries\pchsvc.dlles\pchsvc.dll [x]
3 HTTPFilter; C:\Windows\System32\w3ssl.dll [x]
2 JavaQuickStarterService; "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" [x]

========================== Drivers (Whitelisted) =============

1 2278046drv; C:\Windows\System32\DRIVERS\2278046drv.sys [475736 2012-03-09] (Kaspersky Lab)
0 54823927; C:\Windows\System32\DRIVERS\54823927.sys [133208 2012-03-09] (Kaspersky Lab ZAO)
3 ADIHdAudAddService; C:\Windows\System32\drivers\ADIHdAud.sys [141312 2005-10-05] (Analog Devices, Inc.)
3 AEAudioService; C:\Windows\System32\drivers\AEAudio.sys [127872 2005-03-04] (Andrea Electronics Corporation)
2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [20747 2008-01-05] (Meetinghouse Data Communications)
3 AVGIDSDriver; C:\Windows\System32\DRIVERS\AVGIDSDriver.Sys [134480 2011-05-27] (AVG Technologies CZ, s.r.o. )
0 AVGIDSEH; C:\Windows\System32\DRIVERS\AVGIDSEH.Sys [22992 2011-02-22] (AVG Technologies CZ, s.r.o. )
3 AVGIDSFilter; C:\Windows\System32\DRIVERS\AVGIDSFilter.Sys [24144 2011-02-10] (AVG Technologies CZ, s.r.o. )
3 AVGIDSShim; C:\Windows\System32\DRIVERS\AVGIDSShim.Sys [27216 2011-02-10] (AVG Technologies CZ, s.r.o. )
1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [248656 2011-01-07] (AVG Technologies CZ, s.r.o.)
1 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [34896 2011-03-01] (AVG Technologies CZ, s.r.o.)
0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [32592 2011-03-16] (AVG Technologies CZ, s.r.o.)
1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [297168 2011-04-04] (AVG Technologies CZ, s.r.o.)
3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl5.sys [371712 2005-02-11] (Broadcom Corporation)
3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
2 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [9856 2004-07-28] (Elaborate Bytes AG)
3 ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [3968 2004-06-08] (Elaborate Bytes AG)
2 fssfltr; C:\Windows\System32\DRIVERS\fssfltr_tdi.sys [54752 2009-08-05] (Microsoft Corporation)
3 gameenum; C:\Windows\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [145920 2004-10-27] (Windows ® Server 2003 DDK provider)
3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows ® Server 2003 DDK provider)
3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2007-03-08] (HP)
3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2007-03-08] (HP)
3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2007-03-08] (HP)
3 ivusb; C:\Windows\System32\DRIVERS\ivusb.sys [24216 2010-03-10] (Initio Corporation)
3 Jukebox3; C:\Windows\System32\DRIVERS\ctpdusb.sys [17280 2006-01-18] (Creative Technology Ltd.)
3 ms_mpu401; C:\Windows\System32\drivers\msmpu401.sys [2944 2001-08-17] (Microsoft Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-12] ()
3 NABTSFEC; C:\Windows\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-13] (Microsoft Corporation)
3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
3 pccsmcfd; C:\Windows\System32\DRIVERS\pccsmcfd.sys [18816 2008-08-26] (Nokia)
3 PSched; C:\Windows\System32\DRIVERS\psched.sys [69120 2008-04-13] (Microsoft Corporation)
3 Ptilink; C:\Windows\System32\DRIVERS\ptilink.sys [17792 2006-02-28] (Parallel Technologies, Inc.)
3 RTLE8023xp; C:\Windows\System32\DRIVERS\Rtenicxp.sys [82048 2006-03-13] (Realtek Semiconductor Corporation )
3 SE26bus; C:\Windows\System32\DRIVERS\SE26bus.sys [61600 2006-05-01] (MCCI)
3 SE26mdfl; C:\Windows\System32\DRIVERS\SE26mdfl.sys [9360 2006-05-01] (MCCI)
3 SE26mdm; C:\Windows\System32\DRIVERS\SE26mdm.sys [97184 2006-05-01] (MCCI)
3 SE26mgmt; C:\Windows\System32\DRIVERS\SE26mgmt.sys [88688 2006-05-01] (MCCI)
3 se26nd5; C:\Windows\System32\DRIVERS\se26nd5.sys [18704 2006-05-01] (MCCI)
3 SE26obex; C:\Windows\System32\DRIVERS\SE26obex.sys [86560 2006-05-01] (MCCI)
3 se26unic; C:\Windows\System32\DRIVERS\se26unic.sys [90768 2006-05-01] (MCCI)
3 SenFiltService; C:\Windows\System32\drivers\Senfilt.sys [393088 2005-08-11] (Sensaura)
3 SLIP; C:\Windows\System32\DRIVERS\SLIP.sys [11136 2008-04-13] (Microsoft Corporation)
3 SONYPVU1; C:\Windows\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation)
3 streamip; C:\Windows\System32\DRIVERS\StreamIP.sys [15232 2008-04-13] (Microsoft Corporation)
2 TBPanel; C:\Windows\System32\Drivers\TBPanel.sys [12256 2007-03-16] (Windows ® 2000 DDK provider)
3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltj.sys [8192 2010-02-26] (Nokia)
3 usb_rndisx; C:\Windows\System32\DRIVERS\usb8023x.sys [12800 2008-04-13] (Microsoft Corporation)
3 VX3000; C:\Windows\System32\DRIVERS\VX3000.sys [1966384 2006-10-13] (Microsoft Corporation)
3 w810bus; C:\Windows\System32\DRIVERS\w810bus.sys [58288 2006-02-20] (MCCI)
3 w810mdfl; C:\Windows\System32\DRIVERS\w810mdfl.sys [8336 2006-02-20] (MCCI)
3 w810mdm; C:\Windows\System32\DRIVERS\w810mdm.sys [94064 2006-02-20] (MCCI)
3 w810mgmt; C:\Windows\System32\DRIVERS\w810mgmt.sys [85408 2006-02-20] (MCCI)
3 w810obex; C:\Windows\System32\DRIVERS\w810obex.sys [83344 2006-02-20] (MCCI)
3 wceusbsh; C:\Windows\System32\DRIVERS\wceusbsh.sys [28672 2006-11-06] (Microsoft Corporation)
3 WSTCODEC; C:\Windows\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-13] (Microsoft Corporation)
4 Abiosdsk; [x]
4 abp480n5; [x]
4 adpu160m; [x]
4 Aha154x; [x]
4 aic78u2; [x]
4 aic78xx; [x]
4 AliIde; [x]
4 amsint; [x]
4 asc; [x]
4 asc3350p; [x]
4 asc3550; [x]
3 ASNDIS5; \??\H:\WINDOWS\system32\ASNDIS5.SYS [x]
4 Atdisk; [x]
3 Cardex; \??\H:\WINDOWS\system32\drivers\TBPANEL.SYS [x]
3 catchme; \??\H:\DOCUME~1\ANDY&J~1\LOCALS~1\Temp\catchme.sys [x]
4 cd20xrnt; [x]
1 Changer; [x]
4 CmdIde; [x]
4 Cpqarray; [x]
4 dac2w2k; [x]
4 dac960nt; [x]
4 dpti2o; [x]
4 hpn; [x]
1 i2omgmt; [x]
4 i2omp; [x]
4 ini910u; [x]
4 IntelIde; [x]
1 lbrtfdc; [x]
3 MBAMSwissArmy; \??\H:\WINDOWS\system32\drivers\mbamswissarmy.sys [x]
1 mdf15; \??\H:\Program Files\Clarus\Samsung SecretZone\mdf15.sys [x]
4 mraid35x; [x]
1 mvd20; \??\H:\Program Files\Clarus\Samsung SecretZone\mvd20.sys [x]
1 PCIDump; [x]
3 PDCOMP; [x]
3 PDFRAME; [x]
3 PDRELI; [x]
3 PDRFRAME; [x]
4 perc2; [x]
4 perc2hib; [x]
2 PfModNT; \??\H:\WINDOWS\system32\drivers\PfModNT.sys [x]
4 ql1080; [x]
4 Ql10wnt; [x]
4 ql12160; [x]
4 ql1240; [x]
4 ql1280; [x]
4 Simbad; [x]
4 Sparrow; [x]
4 symc810; [x]
4 symc8xx; [x]
4 sym_hi; [x]
4 sym_u3; [x]
4 TosIde; [x]
4 ultra; [x]
4 ViaIde; [x]
3 WDICA; [x]

========================== NetSvcs (Whitelisted) ===========

============ One Month Created Files and Folders ==============

2012-03-12 01:46 - 2012-03-12 01:46 - 0000000 ____D C:\FRST
2012-03-11 22:40 - 2012-03-11 22:40 - 0098368 ___AH C:\4Ex8PA3
2012-03-11 22:39 - 2012-03-12 00:35 - 0118428 ____A C:\OTL.Txt
2012-03-11 04:55 - 2012-03-12 00:36 - 0098368 ___AH C:\Documents and Settings\Andy & Joanna\Desktop\4Ex8PA3
2012-03-11 04:54 - 2012-03-11 04:54 - 0098368 ___AH C:\Documents and Settings\Andy & Joanna\4Ex8PA3
2012-03-11 04:46 - 2012-03-11 20:38 - 0098368 ___AH C:\Windows\System32\4Ex8PA3
2012-03-11 04:46 - 2012-03-11 04:46 - 0098368 ___AH C:\Windows\System32\idLl3SAc
2012-03-11 04:46 - 2012-03-11 04:46 - 0098368 ____S C:\horatbfq.exe
2012-03-10 21:07 - 2012-03-09 13:09 - 0475736 ____A (Kaspersky Lab) C:\Windows\System32\Drivers\2278046drv.sys
2012-03-10 21:07 - 2012-03-09 13:09 - 0133208 ____A (Kaspersky Lab ZAO) C:\Windows\System32\Drivers\54823927.sys
2012-03-10 21:05 - 2012-03-10 21:05 - 0113155 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\wbjpxoag.log
2012-03-10 21:05 - 2012-03-10 21:05 - 0003265 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\bpcfdxwe.log
2012-03-10 21:05 - 2012-03-10 21:05 - 0001572 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\uisvlpvd.log
2012-03-10 21:04 - 2012-03-10 21:04 - 0004011 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\nypmwsbh.log
2012-03-10 21:04 - 2012-03-10 21:04 - 0000239 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\kgoulhud.log
2012-03-10 21:04 - 2012-03-10 21:04 - 0000000 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\esuqgaqj.log
2012-03-10 21:00 - 2012-03-10 21:10 - 0000024 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\ipurrakp.log
2012-03-10 21:00 - 2012-03-10 21:04 - 0405696 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\jgyfnwrm.log
2012-03-10 21:00 - 2012-03-10 21:00 - 0000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\yiangwkb
2012-03-10 19:11 - 2012-03-10 19:11 - 0000838 ____A C:\Documents and Settings\Andy & Joanna\Start Menu\Programs\Startup\_uninst_11160100.lnk
2012-03-10 16:51 - 2012-03-10 16:51 - 0000000 RASHD C:\cmdcons
2012-03-10 16:51 - 2008-01-03 18:13 - 0000210 ____A C:\Boot.bak
2012-03-10 16:51 - 2004-08-03 19:00 - 0260272 _RASH C:\cmldr
2012-03-10 16:50 - 2012-03-11 05:23 - 0000000 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\dahfnjdl.log
2012-03-10 16:48 - 2012-03-10 19:17 - 0000000 ___SD C:\ComboFix
2012-03-10 16:39 - 2012-03-10 18:21 - 0000000 ___SD C:\32788R22FWJFW
2012-03-10 16:38 - 2012-03-10 16:38 - 0000000 ____D C:\Windows\ERDNT
2012-03-10 16:38 - 2012-03-10 16:38 - 0000000 ____D C:\Qoobox
2012-03-10 13:18 - 2012-03-10 13:19 - 0070248 ____A C:\TDSSKiller.2.7.19.0_10.03.2012_17.18.00_log.txt
2012-03-10 13:08 - 2012-03-10 13:09 - 0063642 ____A C:\TDSSKiller.2.7.19.0_10.03.2012_17.08.32_log.txt
2012-03-09 20:07 - 2012-03-09 20:09 - 0070580 ____A C:\TDSSKiller.2.7.19.0_10.03.2012_00.07.38_log.txt
2012-03-09 18:33 - 2012-03-09 18:33 - 0000000 ____D C:\TDSSKiller_Quarantine
2012-03-09 18:31 - 2012-03-09 18:33 - 0070580 ____A C:\TDSSKiller.2.7.19.0_09.03.2012_22.31.44_log.txt
2012-03-09 18:28 - 2012-03-10 18:45 - 0098368 ___AH C:\Windows\System32\a7nkjz3
2012-03-09 18:27 - 2012-03-10 18:45 - 0098368 ___AH C:\Windows\System32\cRrO623
2012-03-09 18:27 - 2012-03-10 18:45 - 0098368 ___AH C:\Windows\System32\a2JGu23
2012-03-09 18:16 - 2012-03-09 18:16 - 0000000 ____D C:\_OTL
2012-03-09 16:41 - 2012-03-09 16:42 - 0000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\AskToolbar
2012-03-09 16:41 - 2012-03-09 16:41 - 0000000 ____D C:\Documents and Settings\LocalService\Application Data\Macromedia
2012-03-09 16:41 - 2012-03-09 16:41 - 0000000 ____D C:\Documents and Settings\LocalService\Application Data\Google
2012-03-09 16:41 - 2012-03-09 16:41 - 0000000 ____D C:\Documents and Settings\LocalService\Application Data\Adobe
2012-03-09 15:55 - 2012-03-09 15:57 - 0004144 ____A C:\TDSSKiller.2.7.19.0_09.03.2012_19.55.35_log.txt
2012-03-09 15:54 - 2012-03-09 15:55 - 0062406 ____A C:\TDSSKiller.2.7.19.0_09.03.2012_19.54.31_log.txt
2012-03-08 18:02 - 2012-03-10 16:48 - 0000000 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\ghengwic.log
2012-03-08 18:01 - 2012-03-09 15:12 - 0113155 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\wbjpxoag.log
2012-03-08 18:01 - 2012-03-09 15:12 - 0001572 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\uisvlpvd.log
2012-03-08 18:01 - 2012-03-08 18:01 - 0003265 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\bpcfdxwe.log
2012-03-08 18:00 - 2012-03-10 16:48 - 0000024 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\ipurrakp.log
2012-03-08 18:00 - 2012-03-10 16:43 - 0003028 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\kgoulhud.log
2012-03-08 18:00 - 2012-03-10 16:38 - 0405696 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\jgyfnwrm.log
2012-03-08 18:00 - 2012-03-08 18:00 - 0004011 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\nypmwsbh.log
2012-03-08 18:00 - 2012-03-08 18:00 - 0000000 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\esuqgaqj.log
2012-03-07 19:31 - 2012-03-07 19:31 - 0000000 ____D C:\Program Files\Common Files\Wise Installation Wizard
2012-03-07 18:59 - 2012-03-07 18:59 - 0020003 ____A C:\Documents and Settings\Andy & Joanna\My Documents\hijackthis.log
2012-03-07 18:27 - 2012-03-07 18:27 - 0000784 ____A C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-03-07 15:57 - 2012-03-07 19:33 - 3429236 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\kgoulhud.log
2012-03-07 15:53 - 2012-03-07 15:53 - 0112483 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\wbjpxoag.log
2012-03-07 15:53 - 2012-03-07 15:53 - 0003265 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\bpcfdxwe.log
2012-03-07 15:53 - 2012-03-07 15:53 - 0001572 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\uisvlpvd.log
2012-03-07 15:49 - 2012-03-12 00:37 - 0000024 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\ipurrakp.log
2012-03-07 15:49 - 2012-03-11 04:46 - 0405696 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\jgyfnwrm.log
2012-03-07 15:49 - 2012-03-10 20:59 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\yiangwkb
2012-03-07 15:49 - 2012-03-07 15:49 - 0004011 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\nypmwsbh.log
2012-03-07 15:49 - 2012-03-07 15:49 - 0000000 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\esuqgaqj.log
2012-02-16 18:40 - 2012-02-16 18:40 - 0000000 __HDC C:\Windows\$NtUninstallKB2660465$
2012-02-16 18:37 - 2012-02-16 18:38 - 0006654 ____A C:\Windows\KB2661637.log
2012-02-16 18:37 - 2012-02-16 18:37 - 0000000 __HDC C:\Windows\$NtUninstallKB2661637$
2012-02-16 15:57 - 2012-02-16 18:40 - 0212330 ____A C:\Windows\KB2647516-IE7.log
2012-02-16 15:57 - 2012-02-16 18:40 - 0131362 ____A C:\Windows\KB2660465.log
2012-02-16 15:55 - 2012-01-11 15:06 - 0003072 ____N C:\Windows\System32\iacenc.dll
2012-02-16 15:55 - 2012-01-11 15:06 - 0003072 ____C C:\Windows\System32\dllcache\iacenc.dll

============ 3 Months Modified Files and Folders ===============

2012-03-12 01:46 - 2012-03-12 01:46 - 0000000 ____D C:\FRST
2012-03-12 00:37 - 2012-03-07 15:49 - 0000024 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\ipurrakp.log
2012-03-12 00:36 - 2012-03-11 04:55 - 0098368 ___AH C:\Documents and Settings\Andy & Joanna\Desktop\4Ex8PA3
2012-03-12 00:35 - 2012-03-11 22:39 - 0118428 ____A C:\OTL.Txt
2012-03-11 22:40 - 2012-03-11 22:40 - 0098368 ___AH C:\4Ex8PA3
2012-03-11 20:38 - 2012-03-11 04:46 - 0098368 ___AH C:\Windows\System32\4Ex8PA3
2012-03-11 20:38 - 2008-01-03 19:39 - 0000278 __ASH C:\Documents and Settings\Andy & Joanna\ntuser.ini
2012-03-11 20:38 - 2008-01-03 19:39 - 0000062 __ASH C:\Documents and Settings\Andy & Joanna\Local Settings\desktop.ini
2012-03-11 20:38 - 2008-01-03 19:38 - 0032528 ____A C:\Windows\SchedLgU.Txt
2012-03-11 20:38 - 2008-01-03 19:38 - 0000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2012-03-11 20:38 - 2008-01-03 19:38 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2012-03-11 20:38 - 2008-01-03 19:34 - 0000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2012-03-11 20:38 - 2008-01-03 19:30 - 1626118 ____A C:\Windows\WindowsUpdate.log
2012-03-11 20:38 - 2008-01-03 18:19 - 0000275 ____A C:\Windows\wiadebug.log
2012-03-11 20:38 - 2008-01-03 18:19 - 0000049 ____A C:\Windows\wiaservc.log
2012-03-11 17:14 - 2010-07-19 16:48 - 0199926 ___AC C:\Windows\ntbtlog.txt
2012-03-11 14:02 - 2010-02-02 17:17 - 0000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-03-11 14:01 - 2009-07-23 17:23 - 0000250 ____A C:\Windows\Tasks\Scheduled Update for Ask Toolbar.job
2012-03-11 14:00 - 2009-01-20 20:17 - 0000458 ____A C:\Windows\Tasks\ParetoLogic Registration.job
2012-03-11 13:58 - 2008-01-03 18:13 - 0000364 _RASH C:\boot.ini
2012-03-11 13:47 - 2010-12-06 16:43 - 0000000 ____D C:\Windows\System32\Drivers\AVG
2012-03-11 05:23 - 2012-03-10 16:50 - 0000000 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\dahfnjdl.log
2012-03-11 05:16 - 2006-02-28 08:00 - 0000663 ____A C:\Windows\win.ini
2012-03-11 05:16 - 2006-02-28 08:00 - 0000227 ____A C:\Windows\system.ini
2012-03-11 05:12 - 2008-01-03 19:59 - 0000558 ____A C:\Windows\DFC.INI
2012-03-11 04:54 - 2012-03-11 04:54 - 0098368 ___AH C:\Documents and Settings\Andy & Joanna\4Ex8PA3
2012-03-11 04:54 - 2008-03-04 16:57 - 0000000 ___HD C:\Config.Msi
2012-03-11 04:48 - 2011-07-10 14:02 - 0000000 ___RD C:\Documents and Settings\Andy & Joanna\My Documents\Dropbox
2012-03-11 04:48 - 2011-07-10 14:00 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Application Data\Dropbox
2012-03-11 04:47 - 2009-11-04 10:15 - 0574842 ____A C:\Windows\setupapi.log
2012-03-11 04:46 - 2012-03-11 04:46 - 0098368 ___AH C:\Windows\System32\idLl3SAc
2012-03-11 04:46 - 2012-03-11 04:46 - 0098368 ____S C:\horatbfq.exe
2012-03-11 04:46 - 2012-03-07 15:49 - 0405696 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\jgyfnwrm.log
2012-03-11 04:46 - 2010-02-02 17:17 - 0000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-03-11 04:46 - 2006-02-28 08:00 - 0013646 ____A C:\Windows\System32\wpa.dbl
2012-03-10 21:10 - 2012-03-10 21:00 - 0000024 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\ipurrakp.log
2012-03-10 21:08 - 2010-07-19 16:54 - 0040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-03-10 21:05 - 2012-03-10 21:05 - 0113155 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\wbjpxoag.log
2012-03-10 21:05 - 2012-03-10 21:05 - 0003265 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\bpcfdxwe.log
2012-03-10 21:05 - 2012-03-10 21:05 - 0001572 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\uisvlpvd.log
2012-03-10 21:04 - 2012-03-10 21:04 - 0004011 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\nypmwsbh.log
2012-03-10 21:04 - 2012-03-10 21:04 - 0000239 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\kgoulhud.log
2012-03-10 21:04 - 2012-03-10 21:04 - 0000000 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\esuqgaqj.log
2012-03-10 21:04 - 2012-03-10 21:00 - 0405696 ____A C:\Documents and Settings\NetworkService\Local Settings\Application Data\jgyfnwrm.log
2012-03-10 21:02 - 2010-12-06 16:43 - 0000000 ____D C:\Documents and Settings\All Users\Application Data\AVG10
2012-03-10 21:00 - 2012-03-10 21:00 - 0000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\yiangwkb
2012-03-10 20:59 - 2012-03-07 15:49 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\yiangwkb
2012-03-10 20:59 - 2010-08-04 15:26 - 0000000 ____D C:\Program Files\PC Connectivity Solution
2012-03-10 20:59 - 2009-12-20 16:13 - 0000000 ____D C:\Program Files\QuickTime
2012-03-10 20:59 - 2008-09-10 15:26 - 0000000 ____D C:\Program Files\Championship Manager 01-02
2012-03-10 20:59 - 2008-01-29 16:53 - 0000000 ____D C:\Program Files\EPSON Print CD
2012-03-10 20:59 - 2008-01-25 17:54 - 0000000 ____D C:\Program Files\Common Files\LightScribe
2012-03-10 20:59 - 2008-01-03 19:44 - 0000000 ____D C:\Program Files\XpertVision
2012-03-10 20:59 - 2008-01-03 19:28 - 0000000 ____D C:\Program Files\Messenger
2012-03-10 20:59 - 2008-01-03 18:07 - 0000000 ____D C:\Windows\System32\usmt
2012-03-10 19:40 - 2011-04-14 06:21 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\Bonusprint
2012-03-10 19:35 - 2008-03-21 13:57 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Application Data\HPAppData
2012-03-10 19:17 - 2012-03-10 16:48 - 0000000 ___SD C:\ComboFix
2012-03-10 19:15 - 2008-01-26 08:48 - 0000000 ____D C:\USB Key
2012-03-10 19:11 - 2012-03-10 19:11 - 0000838 ____A C:\Documents and Settings\Andy & Joanna\Start Menu\Programs\Startup\_uninst_11160100.lnk
2012-03-10 18:45 - 2012-03-09 18:28 - 0098368 ___AH C:\Windows\System32\a7nkjz3
2012-03-10 18:45 - 2012-03-09 18:27 - 0098368 ___AH C:\Windows\System32\cRrO623
2012-03-10 18:45 - 2012-03-09 18:27 - 0098368 ___AH C:\Windows\System32\a2JGu23
2012-03-10 18:39 - 2010-11-01 11:55 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\My Documents\Leila
2012-03-10 18:21 - 2012-03-10 16:39 - 0000000 ___SD C:\32788R22FWJFW
2012-03-10 18:21 - 2008-01-25 19:19 - 0000000 ____D C:\Old PC
2012-03-10 18:21 - 2008-01-03 19:34 - 0000000 ___HD C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files
2012-03-10 16:51 - 2012-03-10 16:51 - 0000000 RASHD C:\cmdcons
2012-03-10 16:48 - 2012-03-08 18:02 - 0000000 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\ghengwic.log
2012-03-10 16:48 - 2012-03-08 18:00 - 0000024 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\ipurrakp.log
2012-03-10 16:43 - 2012-03-08 18:00 - 0003028 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\kgoulhud.log
2012-03-10 16:38 - 2012-03-10 16:38 - 0000000 ____D C:\Windows\ERDNT
2012-03-10 16:38 - 2012-03-10 16:38 - 0000000 ____D C:\Qoobox
2012-03-10 16:38 - 2012-03-08 18:00 - 0405696 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\jgyfnwrm.log
2012-03-10 16:35 - 2008-04-11 09:28 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Application Data\U3
2012-03-10 13:32 - 2008-01-26 09:21 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\My Documents\Torrents
2012-03-10 13:19 - 2012-03-10 13:18 - 0070248 ____A C:\TDSSKiller.2.7.19.0_10.03.2012_17.18.00_log.txt
2012-03-10 13:09 - 2012-03-10 13:08 - 0063642 ____A C:\TDSSKiller.2.7.19.0_10.03.2012_17.08.32_log.txt
2012-03-10 13:08 - 2009-04-15 07:39 - 0018956 ___AC C:\Windows\KB952004.log
2012-03-10 13:06 - 2008-01-03 18:17 - 0526818 ____A C:\Windows\System32\PerfStringBackup.INI
2012-03-10 13:04 - 2008-09-25 15:37 - 0000000 __HDC C:\Windows\$NtServicePackUninstall$
2012-03-10 13:00 - 2008-01-03 18:07 - 0000000 ____D C:\Windows\msagent
2012-03-10 13:00 - 2008-01-03 18:07 - 0000000 ____D C:\Windows\ime
2012-03-09 20:09 - 2012-03-09 20:07 - 0070580 ____A C:\TDSSKiller.2.7.19.0_10.03.2012_00.07.38_log.txt
2012-03-09 19:51 - 2008-01-25 19:04 - 0000000 ____D C:\Windows\System32\URTTemp
2012-03-09 19:50 - 2008-01-03 19:29 - 0000000 ____D C:\Windows\System32\Restore
2012-03-09 19:49 - 2008-01-03 18:07 - 0000000 ____D C:\Windows\System32\npp
2012-03-09 19:44 - 2008-01-03 19:27 - 0000000 ____D C:\Windows\System32\Com
2012-03-09 19:43 - 2008-09-25 15:44 - 0000000 ____D C:\Windows\System32\bits
2012-03-09 19:43 - 2008-01-03 19:29 - 0000000 ____D C:\Windows\srchasst
2012-03-09 19:39 - 2008-01-03 18:07 - 0000000 ____D C:\Windows\PeerNet
2012-03-09 19:32 - 2008-01-03 18:07 - 0000000 ____D C:\Windows\Help
2012-03-09 19:11 - 2008-01-03 19:27 - 0000000 ____D C:\Program Files\Windows NT
2012-03-09 19:10 - 2009-07-08 16:41 - 0000000 ____D C:\Program Files\WinAVI Video Converter
2012-03-09 19:10 - 2008-01-29 16:01 - 0000000 ____D C:\Program Files\WinAVIVideoConverter
2012-03-09 19:08 - 2008-01-03 19:29 - 0000000 ____D C:\Program Files\Outlook Express
2012-03-09 19:08 - 2008-01-03 19:29 - 0000000 ____D C:\Program Files\NetMeeting
2012-03-09 19:07 - 2011-08-26 15:26 - 0000000 ____D C:\Program Files\MP3 My MP3 3.1
2012-03-09 19:07 - 2008-01-03 19:29 - 0000000 ____D C:\Program Files\Movie Maker
2012-03-09 18:58 - 2008-01-03 19:29 - 0000000 ____D C:\Program Files\Common Files\System
2012-03-09 18:33 - 2012-03-09 18:33 - 0000000 ____D C:\TDSSKiller_Quarantine
2012-03-09 18:33 - 2012-03-09 18:31 - 0070580 ____A C:\TDSSKiller.2.7.19.0_09.03.2012_22.31.44_log.txt
2012-03-09 18:27 - 2008-01-03 19:39 - 0000000 ___HD C:\Documents and Settings\Andy & Joanna\Local Settings\Temporary Internet Files
2012-03-09 18:27 - 2008-01-03 19:38 - 0000000 __SHD C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files
2012-03-09 18:24 - 2008-01-03 18:17 - 0000000 __SHD C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files
2012-03-09 18:22 - 2008-01-05 06:59 - 0000000 __HDC C:\Windows\ie7
2012-03-09 18:21 - 2009-07-04 06:54 - 0000000 __HDC C:\Windows\$NtUninstallWudf01005$
2012-03-09 18:21 - 2008-01-25 17:43 - 0000000 __HDC C:\Windows\$NtUninstallwmp11$
2012-03-09 18:20 - 2011-03-20 08:15 - 0000000 __HDC C:\Windows\$NtUninstallKB971029$
2012-03-09 18:20 - 2010-10-12 17:25 - 0000000 __HDC C:\Windows\$NtUninstallKB982132$
2012-03-09 18:20 - 2010-10-12 17:24 - 0000000 __HDC C:\Windows\$NtUninstallKB979687$
2012-03-09 18:20 - 2010-09-15 15:13 - 0000000 __HDC C:\Windows\$NtUninstallKB975558_WM8$
2012-03-09 18:20 - 2010-09-15 15:12 - 0000000 __HDC C:\Windows\$NtUninstallKB982802$
2012-03-09 18:20 - 2010-09-15 15:11 - 0000000 __HDC C:\Windows\$NtUninstallKB981322$
2012-03-09 18:20 - 2010-08-13 17:23 - 0000000 __HDC C:\Windows\$NtUninstallKB982665$
2012-03-09 18:20 - 2010-08-13 17:23 - 0000000 __HDC C:\Windows\$NtUninstallKB981997$
2012-03-09 18:20 - 2010-06-14 04:14 - 0000000 __HDC C:\Windows\$NtUninstallKB978695_WM9$
2012-03-09 18:20 - 2010-06-14 04:13 - 0000000 __HDC C:\Windows\$NtUninstallKB975562$
2012-03-09 18:20 - 2010-05-11 16:53 - 0000000 __HDC C:\Windows\$NtUninstallKB978542$
2012-03-09 18:20 - 2010-04-16 04:25 - 0000000 __HDC C:\Windows\$NtUninstallKB981349$
2012-03-09 18:20 - 2010-04-13 17:55 - 0000000 __HDC C:\Windows\$NtUninstallKB979309$
2012-03-09 18:20 - 2010-04-13 17:55 - 0000000 __HDC C:\Windows\$NtUninstallKB978601$
2012-03-09 18:20 - 2010-03-11 17:05 - 0000000 __HDC C:\Windows\$NtUninstallKB975561$
2012-03-09 18:20 - 2010-02-10 19:25 - 0000000 __HDC C:\Windows\$NtUninstallKB975713$
2012-03-09 18:20 - 2010-02-10 19:25 - 0000000 __HDC C:\Windows\$NtUninstallKB975560$
2012-03-09 18:20 - 2010-02-10 19:23 - 0000000 __HDC C:\Windows\$NtUninstallKB978706$
2012-03-09 18:20 - 2010-01-12 19:23 - 0000000 __HDC C:\Windows\$NtUninstallKB972270$
2012-03-09 18:20 - 2010-01-12 19:23 - 0000000 __HDC C:\Windows\$NtUninstallKB955759$
2012-03-09 18:20 - 2009-12-25 08:35 - 0000000 __HDC C:\Windows\$NtUninstallKB954708$
2012-03-09 18:20 - 2009-12-13 13:06 - 0000000 __HDC C:\Windows\$NtUninstallKB974318$
2012-03-09 18:20 - 2009-12-13 13:06 - 0000000 __HDC C:\Windows\$NtUninstallKB970430$
2012-03-09 18:20 - 2009-12-13 12:54 - 0000000 __HDC C:\Windows\$NtUninstallKB974392$
2012-03-09 18:20 - 2009-12-13 12:54 - 0000000 __HDC C:\Windows\$NtUninstallKB971737$
2012-03-09 18:20 - 2009-11-26 19:34 - 0000000 __HDC C:\Windows\$NtUninstallKB973687$
2012-03-09 18:20 - 2009-10-15 17:22 - 0000000 __HDC C:\Windows\$NtUninstallKB969059$
2012-03-09 18:20 - 2009-10-15 17:21 - 0000000 __HDC C:\Windows\$NtUninstallKB954155_WM9$
2012-03-09 18:20 - 2009-10-15 17:20 - 0000000 __HDC C:\Windows\$NtUninstallKB974571$
2012-03-09 18:20 - 2009-10-15 17:18 - 0000000 __HDC C:\Windows\$NtUninstallKB975467$
2012-03-09 18:20 - 2009-09-09 10:52 - 0000000 __HDC C:\Windows\$NtUninstallKB968816_WM9$
2012-03-09 18:20 - 2009-09-09 10:51 - 0000000 __HDC C:\Windows\$NtUninstallKB971961$
2012-03-09 18:20 - 2009-08-26 03:05 - 0000000 __HDC C:\Windows\$NtUninstallKB970653-v3$
2012-03-09 18:20 - 2009-08-16 07:12 - 0000000 __HDC C:\Windows\$NtUninstallKB968389$
2012-03-09 18:20 - 2009-08-13 18:36 - 0000000 __HDC C:\Windows\$NtUninstallKB960859$
2012-03-09 18:20 - 2009-08-13 18:35 - 0000000 __HDC C:\Windows\$NtUninstallKB971657$
2012-03-09 18:20 - 2009-08-13 18:35 - 0000000 __HDC C:\Windows\$NtUninstallKB956744$
2012-03-09 18:20 - 2009-08-13 18:34 - 0000000 __HDC C:\Windows\$NtUninstallKB973540_WM9$
2012-03-09 18:20 - 2009-08-13 18:34 - 0000000 __HDC C:\Windows\$NtUninstallKB973354$
2012-03-09 18:20 - 2009-08-13 18:32 - 0000000 __HDC C:\Windows\$NtUninstallKB973815$
2012-03-09 18:20 - 2009-07-15 16:04 - 0000000 __HDC C:\Windows\$NtUninstallKB971633$
2012-03-09 18:20 - 2009-07-15 16:00 - 0000000 __HDC C:\Windows\$NtUninstallKB961371$
2012-03-09 18:20 - 2009-06-23 11:47 - 0000000 __HDC C:\Windows\$NtUninstallKB961501$
2012-03-09 18:20 - 2009-06-23 11:43 - 0000000 __HDC C:\Windows\$NtUninstallKB970238$
2012-03-09 18:20 - 2009-04-15 17:42 - 0000000 __HDC C:\Windows\$NtUninstallKB961373$
2012-03-09 18:20 - 2009-04-15 17:42 - 0000000 __HDC C:\Windows\$NtUninstallKB959426$
2012-03-09 18:20 - 2009-04-15 17:39 - 0000000 __HDC C:\Windows\$NtUninstallKB960803$
2012-03-09 18:20 - 2009-04-15 17:39 - 0000000 __HDC C:\Windows\$NtUninstallKB956572$
2012-03-09 18:20 - 2009-04-15 17:39 - 0000000 __HDC C:\Windows\$NtUninstallKB952004$
2012-03-09 18:20 - 2009-03-11 19:44 - 0000000 __HDC C:\Windows\$NtUninstallKB959772_WM11$
2012-03-09 18:20 - 2008-12-12 19:37 - 0000000 __HDC C:\Windows\$NtUninstallKB955839$
2012-03-09 18:20 - 2008-12-12 19:34 - 0000000 __HDC C:\Windows\$NtUninstallKB952069_WM9$
2012-03-09 18:20 - 2008-12-12 19:33 - 0000000 __HDC C:\Windows\$NtUninstallKB956802$
2012-03-09 18:20 - 2008-11-12 19:12 - 0000000 __HDC C:\Windows\$NtUninstallKB954459$
2012-03-09 18:20 - 2008-11-12 19:11 - 0000000 __HDC C:\Windows\$NtUninstallKB955069$
2012-03-09 18:20 - 2008-10-24 19:07 - 0000000 __HDC C:\Windows\$NtUninstallKB958644$
2012-03-09 18:20 - 2008-09-25 15:48 - 0000000 __HDC C:\Windows\$NtUninstallKB952954$
2012-03-09 18:20 - 2008-09-25 15:48 - 0000000 __HDC C:\Windows\$NtUninstallKB952287$
2012-03-09 18:20 - 2008-09-10 11:42 - 0000000 __HDC C:\Windows\$NtUninstallKB954154_WM11$
2012-03-09 18:20 - 2008-08-12 17:53 - 0000000 __HDC C:\Windows\$NtUninstallKB952954_0$
2012-03-09 18:20 - 2008-08-12 17:51 - 0000000 __HDC C:\Windows\$NtUninstallKB952287_0$
2012-03-09 18:20 - 2008-01-25 17:42 - 0000000 __HDC C:\Windows\$NtUninstallWMFDist11$
2012-03-09 18:19 - 2009-04-15 17:37 - 0000000 __HDC C:\Windows\$NtUninstallKB923561$
2012-03-09 18:19 - 2008-09-27 07:26 - 0000000 __HDC C:\Windows\$NtUninstallKB951978$
2012-03-09 18:19 - 2008-09-25 15:48 - 0000000 __HDC C:\Windows\$NtUninstallKB951748$
2012-03-09 18:19 - 2008-09-25 15:48 - 0000000 __HDC C:\Windows\$NtUninstallKB951698$
2012-03-09 18:19 - 2008-09-25 15:48 - 0000000 __HDC C:\Windows\$NtUninstallKB951066$
2012-03-09 18:19 - 2008-09-25 15:48 - 0000000 __HDC C:\Windows\$NtUninstallKB950974$
2012-03-09 18:19 - 2008-09-25 15:47 - 0000000 __HDC C:\Windows\$NtUninstallKB946648$
2012-03-09 18:19 - 2008-08-12 17:53 - 0000000 __HDC C:\Windows\$NtUninstallKB946648_0$
2012-03-09 18:19 - 2008-08-12 17:51 - 0000000 __HDC C:\Windows\$NtUninstallKB951072-v2$
2012-03-09 18:19 - 2008-08-12 17:51 - 0000000 __HDC C:\Windows\$NtUninstallKB951066_0$
2012-03-09 18:19 - 2008-07-09 08:17 - 0000000 __HDC C:\Windows\$NtUninstallKB951748_0$
2012-03-09 18:19 - 2008-06-10 18:07 - 0000000 __HDC C:\Windows\$NtUninstallKB951698_0$
2012-03-09 18:19 - 2008-04-09 22:02 - 0000000 __HDC C:\Windows\$NtUninstallKB948590$
2012-03-09 18:19 - 2008-04-09 22:00 - 0000000 __HDC C:\Windows\$NtUninstallKB945553$
2012-03-09 18:19 - 2008-02-12 18:07 - 0000000 __HDC C:\Windows\$NtUninstallKB943055$
2012-03-09 18:19 - 2008-01-26 12:01 - 0000000 __HDC C:\Windows\$NtUninstallKB943485$
2012-03-09 18:19 - 2008-01-26 12:01 - 0000000 __HDC C:\Windows\$NtUninstallKB939683$
2012-03-09 18:19 - 2008-01-26 12:01 - 0000000 __HDC C:\Windows\$NtUninstallKB929399$
2012-03-09 18:19 - 2008-01-26 12:00 - 0000000 __HDC C:\Windows\$NtUninstallKB936782_WMP11$
2012-03-09 18:19 - 2008-01-05 07:02 - 0000000 __HDC C:\Windows\$NtUninstallKB942615$
2012-03-09 18:19 - 2008-01-05 07:02 - 0000000 __HDC C:\Windows\$NtUninstallKB937894$
2012-03-09 18:19 - 2008-01-05 07:01 - 0000000 __HDC C:\Windows\$NtUninstallKB941569$
2012-03-09 18:19 - 2008-01-05 06:58 - 0000000 __HDC C:\Windows\$NtUninstallKB943460$
2012-03-09 18:19 - 2008-01-05 06:52 - 0000000 __HDC C:\Windows\$NtUninstallKB943460_0$
2012-03-09 18:19 - 2008-01-05 06:52 - 0000000 __HDC C:\Windows\$NtUninstallKB941202$
2012-03-09 18:19 - 2008-01-05 06:52 - 0000000 __HDC C:\Windows\$NtUninstallKB938127$
2012-03-09 18:19 - 2008-01-05 06:52 - 0000000 __HDC C:\Windows\$NtUninstallKB936782_WMP9$
2012-03-09 18:19 - 2008-01-05 06:52 - 0000000 __HDC C:\Windows\$NtUninstallKB936021$
2012-03-09 18:19 - 2008-01-05 06:52 - 0000000 __HDC C:\Windows\$NtUninstallKB933729$
2012-03-09 18:19 - 2008-01-05 06:51 - 0000000 __HDC C:\Windows\$NtUninstallKB938829$
2012-03-09 18:19 - 2008-01-05 06:51 - 0000000 __HDC C:\Windows\$NtUninstallKB938828$
2012-03-09 18:19 - 2008-01-05 06:51 - 0000000 __HDC C:\Windows\$NtUninstallKB929123$
2012-03-09 18:19 - 2008-01-05 06:50 - 0000000 __HDC C:\Windows\$NtUninstallKB931261$
2012-03-09 18:19 - 2008-01-05 06:50 - 0000000 __HDC C:\Windows\$NtUninstallKB930178$
2012-03-09 18:19 - 2008-01-05 06:50 - 0000000 __HDC C:\Windows\$NtUninstallKB927779$
2012-03-09 18:19 - 2008-01-05 06:50 - 0000000 __HDC C:\Windows\$NtUninstallKB926436$
2012-03-09 18:19 - 2008-01-05 06:50 - 0000000 __HDC C:\Windows\$NtUninstallKB925902$
2012-03-09 18:19 - 2008-01-05 06:50 - 0000000 __HDC C:\Windows\$NtUninstallKB924667$
2012-03-09 18:19 - 2008-01-05 06:49 - 0000000 __HDC C:\Windows\$NtUninstallKB928255$
2012-03-09 18:19 - 2008-01-05 06:49 - 0000000 __HDC C:\Windows\$NtUninstallKB927802$
2012-03-09 18:19 - 2008-01-05 06:49 - 0000000 __HDC C:\Windows\$NtUninstallKB926255$
2012-03-09 18:19 - 2008-01-05 06:49 - 0000000 __HDC C:\Windows\$NtUninstallKB924496$
2012-03-09 18:19 - 2008-01-05 06:49 - 0000000 __HDC C:\Windows\$NtUninstallKB924270$
2012-03-09 18:19 - 2008-01-05 06:49 - 0000000 __HDC C:\Windows\$NtUninstallKB923980$
2012-03-09 18:19 - 2008-01-05 06:49 - 0000000 __HDC C:\Windows\$NtUninstallKB923191$
2012-03-09 18:18 - 2012-01-25 19:21 - 0000000 __HDC C:\Windows\$NtUninstallKB2585542$
2012-03-09 18:18 - 2012-01-11 16:04 - 0000000 __HDC C:\Windows\$NtUninstallKB2646524$
2012-03-09 18:18 - 2012-01-11 16:04 - 0000000 __HDC C:\Windows\$NtUninstallKB2631813$
2012-03-09 18:18 - 2012-01-11 16:00 - 0000000 __HDC C:\Windows\$NtUninstallKB2598479$
2012-03-09 18:18 - 2011-12-16 16:38 - 0000000 __HDC C:\Windows\$NtUninstallKB2624667$
2012-03-09 18:18 - 2011-12-16 16:33 - 0000000 __HDC C:\Windows\$NtUninstallKB2619339$
2012-03-09 18:18 - 2011-11-13 23:05 - 0000000 __HDC C:\Windows\$NtUninstallKB2544893-v2$
2012-03-09 18:18 - 2011-10-13 12:08 - 0000000 __HDC C:\Windows\$NtUninstallKB2564958$
2012-03-09 18:18 - 2011-08-12 17:54 - 0000000 __HDC C:\Windows\$NtUninstallKB2567680$
2012-03-09 18:18 - 2011-07-18 15:45 - 0000000 __HDC C:\Windows\$NtUninstallKB2507938$
2012-03-09 18:18 - 2011-06-15 18:13 - 0000000 __HDC C:\Windows\$NtUninstallKB2544893$
2012-03-09 18:18 - 2011-04-14 18:03 - 0000000 __HDC C:\Windows\$NtUninstallKB2510581$
2012-03-09 18:18 - 2011-04-14 17:52 - 0000000 __HDC C:\Windows\$NtUninstallKB2503658$
2012-03-09 18:18 - 2011-04-14 17:51 - 0000000 __HDC C:\Windows\$NtUninstallKB2506212$
2012-03-09 18:18 - 2011-04-14 17:47 - 0000000 __HDC C:\Windows\$NtUninstallKB2509553$
2012-03-09 18:18 - 2011-02-10 19:22 - 0000000 __HDC C:\Windows\$NtUninstallKB2483185$
2012-03-09 18:18 - 2008-01-05 06:58 - 0000000 __HDC C:\Windows\$NtUninstallKB914440$
2012-03-09 18:18 - 2008-01-05 06:51 - 0000000 __HDC C:\Windows\$NtUninstallKB921503$
2012-03-09 18:18 - 2008-01-05 06:50 - 0000000 __HDC C:\Windows\$NtUninstallKB918118$
2012-03-09 18:18 - 2008-01-05 06:49 - 0000000 __HDC C:\Windows\$NtUninstallKB920685$
2012-03-09 18:18 - 2008-01-05 06:48 - 0000000 __HDC C:\Windows\$NtUninstallKB920683$
2012-03-09 18:18 - 2008-01-05 06:48 - 0000000 __HDC C:\Windows\$NtUninstallKB918439$
2012-03-09 18:18 - 2008-01-05 06:48 - 0000000 __HDC C:\Windows\$NtUninstallKB914388$
2012-03-09 18:18 - 2008-01-05 06:48 - 0000000 __HDC C:\Windows\$NtUninstallKB913580$
2012-03-09 18:18 - 2008-01-05 06:48 - 0000000 __HDC C:\Windows\$NtUninstallKB911927$
2012-03-09 18:18 - 2008-01-05 06:48 - 0000000 __HDC C:\Windows\$NtUninstallKB911564$
2012-03-09 18:18 - 2008-01-05 06:48 - 0000000 __HDC C:\Windows\$NtUninstallKB911562$
2012-03-09 18:18 - 2008-01-05 06:48 - 0000000 __HDC C:\Windows\$NtUninstallKB911280$
2012-03-09 18:18 - 2008-01-05 06:48 - 0000000 __HDC C:\Windows\$NtUninstallKB908531$
2012-03-09 18:18 - 2008-01-05 06:47 - 0000000 __HDC C:\Windows\$NtUninstallKB910437$
2012-03-09 18:18 - 2008-01-05 06:47 - 0000000 __HDC C:\Windows\$NtUninstallKB908519$
2012-03-09 18:18 - 2008-01-05 06:47 - 0000000 __HDC C:\Windows\$NtUninstallKB905414$
2012-03-09 18:18 - 2008-01-05 06:47 - 0000000 __HDC C:\Windows\$NtUninstallKB902400$
2012-03-09 18:18 - 2008-01-05 06:47 - 0000000 __HDC C:\Windows\$NtUninstallKB901017$
2012-03-09 18:18 - 2008-01-05 06:47 - 0000000 __HDC C:\Windows\$NtUninstallKB900725$
2012-03-09 18:18 - 2008-01-05 06:45 - 0000000 __HDC C:\Windows\$NtUninstallKB901214$
2012-03-09 18:18 - 2008-01-05 06:45 - 0000000 __HDC C:\Windows\$NtUninstallKB899587$
2012-03-09 18:18 - 2008-01-05 06:45 - 0000000 __HDC C:\Windows\$NtUninstallKB896423$
2012-03-09 18:18 - 2008-01-05 06:45 - 0000000 __HDC C:\Windows\$NtUninstallKB896358$
2012-03-09 18:18 - 2008-01-05 06:45 - 0000000 __HDC C:\Windows\$NtUninstallKB894391$
2012-03-09 18:18 - 2008-01-05 06:45 - 0000000 __HDC C:\Windows\$NtUninstallKB893756$
2012-03-09 18:18 - 2008-01-05 06:45 - 0000000 __HDC C:\Windows\$NtUninstallKB890859$
2012-03-09 18:18 - 2008-01-05 06:45 - 0000000 __HDC C:\Windows\$NtUninstallKB888302$
2012-03-09 18:18 - 2008-01-05 06:45 - 0000000 __HDC C:\Windows\$NtUninstallKB887472$
2012-03-09 18:18 - 2008-01-05 06:45 - 0000000 __HDC C:\Windows\$NtUninstallKB885835$
2012-03-09 18:18 - 2008-01-05 06:44 - 0000000 __HDC C:\Windows\$NtUninstallKB873339$
2012-03-09 18:17 - 2011-06-15 18:23 - 0000000 __HDC C:\Windows\$NtUninstallKB2476490$
2012-03-09 18:17 - 2011-03-11 19:26 - 0000000 __HDC C:\Windows\$NtUninstallKB2479943$
2012-03-09 18:17 - 2011-03-11 19:22 - 0000000 __HDC C:\Windows\$NtUninstallKB2481109$
2012-03-09 18:17 - 2011-02-10 19:23 - 0000000 __HDC C:\Windows\$NtUninstallKB2478971$
2012-03-09 18:17 - 2011-01-12 14:44 - 0000000 __HDC C:\Windows\$NtUninstallKB2419632$
2012-03-09 18:17 - 2010-12-16 15:29 - 0000000 __HDC C:\Windows\$NtUninstallKB2423089$
2012-03-09 18:17 - 2010-10-12 17:26 - 0000000 __HDC C:\Windows\$NtUninstallKB2387149$
2012-03-09 18:17 - 2010-10-12 17:26 - 0000000 __HDC C:\Windows\$NtUninstallKB2345886$
2012-03-09 18:17 - 2010-10-12 17:26 - 0000000 __HDC C:\Windows\$NtUninstallKB2296011$
2012-03-09 18:17 - 2010-10-12 17:25 - 0000000 __HDC C:\Windows\$NtUninstallKB2378111_WM9$
2012-03-09 18:17 - 2010-10-12 17:18 - 0000000 __HDC C:\Windows\$NtUninstallKB2360937$
2012-03-09 18:17 - 2010-09-15 15:12 - 0000000 __HDC C:\Windows\$NtUninstallKB2347290$
2012-03-09 18:17 - 2010-09-15 15:12 - 0000000 __HDC C:\Windows\$NtUninstallKB2121546$
2012-03-09 18:17 - 2010-09-15 15:07 - 0000000 __HDC C:\Windows\$NtUninstallKB2141007$
2012-03-09 18:17 - 2010-08-13 17:32 - 0000000 __HDC C:\Windows\$NtUninstallKB2079403$
2012-03-09 18:17 - 2010-08-03 14:01 - 0000000 __HDC C:\Windows\$NtUninstallKB2286198$
2012-03-09 18:17 - 2010-07-14 05:58 - 0000000 __HDC C:\Windows\$NtUninstallKB2229593$
2012-03-09 18:17 - 2006-02-28 08:00 - 0000098 ____A C:\Windows\System32\Drivers\etc\Hosts
2012-03-09 18:16 - 2012-03-09 18:16 - 0000000 ____D C:\_OTL
2012-03-09 18:15 - 2009-03-12 04:14 - 0000000 ____D C:\Program Files\Photo Viewer
2012-03-09 18:14 - 2008-01-03 19:49 - 0000000 __HDC C:\Windows\$MSI31Uninstall_KB893803v2$
2012-03-09 17:21 - 2008-01-29 16:15 - 0003787 ___AC C:\Windows\System32\TVersityMediaServer.log
2012-03-09 16:42 - 2012-03-09 16:41 - 0000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\AskToolbar
2012-03-09 16:42 - 2012-01-16 17:03 - 0000000 ____D C:\Windows\System32\cache
2012-03-09 16:42 - 2010-02-02 17:17 - 0000000 ____D C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
2012-03-09 16:41 - 2012-03-09 16:41 - 0000000 ____D C:\Documents and Settings\LocalService\Application Data\Macromedia
2012-03-09 16:41 - 2012-03-09 16:41 - 0000000 ____D C:\Documents and Settings\LocalService\Application Data\Google
2012-03-09 16:41 - 2012-03-09 16:41 - 0000000 ____D C:\Documents and Settings\LocalService\Application Data\Adobe
2012-03-09 15:58 - 2008-01-03 19:43 - 0073928 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2012-03-09 15:57 - 2012-03-09 15:55 - 0004144 ____A C:\TDSSKiller.2.7.19.0_09.03.2012_19.55.35_log.txt
2012-03-09 15:55 - 2012-03-09 15:54 - 0062406 ____A C:\TDSSKiller.2.7.19.0_09.03.2012_19.54.31_log.txt
2012-03-09 15:26 - 2011-09-12 13:51 - 0002187 ____A C:\Documents and Settings\All Users\Desktop\Safari.lnk
2012-03-09 15:26 - 2008-12-24 10:00 - 0000000 ____D C:\Program Files\Safari
2012-03-09 15:12 - 2012-03-08 18:01 - 0113155 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\wbjpxoag.log
2012-03-09 15:12 - 2012-03-08 18:01 - 0001572 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\uisvlpvd.log
2012-03-09 13:09 - 2012-03-10 21:07 - 0475736 ____A (Kaspersky Lab) C:\Windows\System32\Drivers\2278046drv.sys
2012-03-09 13:09 - 2012-03-10 21:07 - 0133208 ____A (Kaspersky Lab ZAO) C:\Windows\System32\Drivers\54823927.sys
2012-03-08 18:39 - 2008-01-03 18:14 - 0277352 ____A C:\Windows\System32\FNTCACHE.DAT
2012-03-08 18:06 - 2011-08-25 07:37 - 0001813 ____A C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2012-03-08 18:01 - 2012-03-08 18:01 - 0003265 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\bpcfdxwe.log
2012-03-08 18:00 - 2012-03-08 18:00 - 0004011 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\nypmwsbh.log
2012-03-08 18:00 - 2012-03-08 18:00 - 0000000 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\esuqgaqj.log
2012-03-07 19:37 - 2008-01-25 17:43 - 0000000 ____D C:\Program Files\Windows Media Connect 2
2012-03-07 19:33 - 2012-03-07 15:57 - 3429236 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\kgoulhud.log
2012-03-07 19:31 - 2012-03-07 19:31 - 0000000 ____D C:\Program Files\Common Files\Wise Installation Wizard
2012-03-07 19:28 - 2009-12-25 08:38 - 0000000 ____D C:\Program Files\Microsoft Office Outlook Connector
2012-03-07 19:24 - 2009-06-25 11:52 - 0000000 ____D C:\Program Files\K-Lite Codec Pack
2012-03-07 19:24 - 2008-01-29 16:09 - 0000000 ____D C:\Program Files\Media Player Classic
2012-03-07 19:24 - 2008-01-04 19:06 - 0000000 ____D C:\Program Files\Microsoft ActiveSync
2012-03-07 19:22 - 2008-03-04 16:58 - 0000000 ____D C:\Program Files\HP
2012-03-07 19:21 - 2009-07-23 17:27 - 0000000 ____D C:\Program Files\GPLGS
2012-03-07 19:16 - 2008-01-25 17:57 - 0000000 ____D C:\Program Files\coverXP
2012-03-07 19:09 - 2011-12-16 05:14 - 0000000 ____D C:\Program Files\AVG Secure Search
2012-03-07 19:09 - 2011-02-17 14:56 - 0000000 ____D C:\Program Files\Audacity
2012-03-07 19:09 - 2008-01-26 09:14 - 0000000 ____D C:\Program Files\AnMing
2012-03-07 18:59 - 2012-03-07 18:59 - 0020003 ____A C:\Documents and Settings\Andy & Joanna\My Documents\hijackthis.log
2012-03-07 18:59 - 2008-01-03 19:39 - 0000000 ___RD C:\Documents and Settings\Andy & Joanna\My Documents
2012-03-07 18:45 - 2010-05-11 17:13 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Application Data\PriceGong
2012-03-07 18:27 - 2012-03-07 18:27 - 0000784 ____A C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-03-07 18:27 - 2010-07-19 16:54 - 0000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-03-07 15:53 - 2012-03-07 15:53 - 0112483 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\wbjpxoag.log
2012-03-07 15:53 - 2012-03-07 15:53 - 0003265 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\bpcfdxwe.log
2012-03-07 15:53 - 2012-03-07 15:53 - 0001572 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\uisvlpvd.log
2012-03-07 15:49 - 2012-03-07 15:49 - 0004011 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\nypmwsbh.log
2012-03-07 15:49 - 2012-03-07 15:49 - 0000000 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\esuqgaqj.log
2012-03-05 18:30 - 2008-01-26 09:16 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Application Data\uTorrent
2012-03-05 16:32 - 2008-01-05 07:06 - 0032256 ____A C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-02-29 16:15 - 2008-01-26 05:53 - 0000069 ____A C:\Windows\NeroDigital.ini
2012-02-23 19:17 - 2008-01-26 09:16 - 0000000 ____D C:\Program Files\uTorrent
2012-02-23 14:43 - 2009-07-22 17:50 - 0000000 __SHD C:\Documents and Settings\Andy & Joanna\Local Settings\Application Data\.#
2012-02-23 14:40 - 2011-06-24 13:23 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-02-22 18:28 - 2008-01-04 19:04 - 0000000 ____D C:\Program Files\Microsoft Office
2012-02-22 18:27 - 2009-12-02 19:28 - 0000000 ____D C:\Documents and Settings\All Users\Application Data\Microsoft Help
2012-02-22 18:24 - 2008-01-03 18:17 - 0000000 ____D C:\Program Files\Common Files\Microsoft Shared
2012-02-17 09:29 - 2008-04-01 09:56 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\My Documents\Driving Range Idea
2012-02-17 08:41 - 2008-01-25 19:04 - 0000000 ____D C:\Windows\Microsoft.NET
2012-02-17 08:34 - 2009-12-25 08:38 - 0000000 ____D C:\Program Files\Microsoft Silverlight
2012-02-16 18:40 - 2012-02-16 18:40 - 0000000 __HDC C:\Windows\$NtUninstallKB2660465$
2012-02-16 18:40 - 2012-02-16 15:57 - 0212330 ____A C:\Windows\KB2647516-IE7.log
2012-02-16 18:40 - 2012-02-16 15:57 - 0131362 ____A C:\Windows\KB2660465.log
2012-02-16 18:40 - 2008-01-05 06:50 - 52550552 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-02-16 18:40 - 2008-01-05 06:45 - 0315545 ____A C:\Windows\updspapi.log
2012-02-16 18:40 - 2008-01-03 18:17 - 2285525 ____A C:\Windows\FaxSetup.log
2012-02-16 18:40 - 2008-01-03 18:17 - 1105515 ____A C:\Windows\ocgen.log
2012-02-16 18:40 - 2008-01-03 18:17 - 1049903 ____A C:\Windows\tsoc.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0753791 ____A C:\Windows\comsetup.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0710966 ____A C:\Windows\msmqinst.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0534032 ____A C:\Windows\iis6.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0455410 ____A C:\Windows\ntdtcsetup.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0401003 ____A C:\Windows\netfxocm.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0158190 ____A C:\Windows\MedCtrOC.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0122657 ____A C:\Windows\ocmsn.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0115545 ____A C:\Windows\tabletoc.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0114686 ____A C:\Windows\msgsocm.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0001374 ____A C:\Windows\imsins.log
2012-02-16 18:40 - 2008-01-03 18:17 - 0001374 ____A C:\Windows\imsins.BAK
2012-02-16 18:39 - 2008-01-05 07:00 - 0000000 ____D C:\Windows\ie7updates
2012-02-16 18:38 - 2012-02-16 18:37 - 0006654 ____A C:\Windows\KB2661637.log
2012-02-16 18:37 - 2012-02-16 18:37 - 0000000 __HDC C:\Windows\$NtUninstallKB2661637$
2012-02-16 18:37 - 2008-01-03 19:31 - 0000000 ___HD C:\Windows\$hf_mig$
2012-02-16 15:55 - 2011-07-10 14:02 - 0001052 ____A C:\Documents and Settings\Andy & Joanna\Desktop\Dropbox.lnk
2012-02-16 15:55 - 2011-07-10 14:00 - 0001052 ____A C:\Documents and Settings\Andy & Joanna\Start Menu\Programs\Startup\Dropbox.lnk
2012-02-02 18:30 - 2010-12-06 16:45 - 0000690 ____A C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
2012-01-31 10:09 - 2010-08-16 14:32 - 0590816 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2012-01-31 07:37 - 2009-01-19 14:56 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Application Data\ZoomBrowser EX
2012-01-31 06:24 - 2009-09-06 05:32 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\My Documents\Jo Stuff
2012-01-31 06:24 - 2008-01-03 19:39 - 0000000 ___RD C:\Documents and Settings\Andy & Joanna\My Documents\My Pictures
2012-01-30 16:08 - 2008-01-03 18:14 - 0190053 ____A C:\Windows\setupact.log
2012-01-30 14:56 - 2011-02-17 18:48 - 0000000 ____D C:\Log
2012-01-30 14:53 - 2008-01-03 19:50 - 0000000 ___RD C:\Documents and Settings\Andy & Joanna\My Documents\My Videos
2012-01-30 14:51 - 2008-01-25 19:39 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\My Documents\My Received Files
2012-01-30 14:29 - 2010-11-21 16:13 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\My Documents\30yrs of Jo!
2012-01-29 15:25 - 2012-01-26 13:31 - 0017200 ____A C:\Documents and Settings\Andy & Joanna\My Documents\Mum Fletcher's Tribute 26 January 2012.docx
2012-01-29 13:46 - 2012-01-29 13:46 - 0012265 ____A C:\Documents and Settings\Andy & Joanna\My Documents\Mum Fletcher Poem 29 Jan 2012.docx
2012-01-28 08:06 - 2012-01-26 17:58 - 0154624 ____A C:\Documents and Settings\Andy & Joanna\My Documents\Hilda_Fletcher_-_Funeral_Service[1].doc
2012-01-25 19:21 - 2012-01-25 13:34 - 0012433 ____A C:\Windows\KB2585542.log
2012-01-25 14:43 - 2012-01-25 14:43 - 0001542 ____A C:\Documents and Settings\All Users\Desktop\iTunes.lnk
2012-01-25 14:43 - 2009-09-14 08:55 - 0000000 ____D C:\Program Files\iTunes
2012-01-25 14:42 - 2012-01-25 14:42 - 0000000 ____D C:\Program Files\iPod
2012-01-25 14:42 - 2008-01-25 18:18 - 0000000 ____D C:\Program Files\Common Files\Apple
2012-01-24 20:00 - 2008-01-29 16:22 - 0000805 ____A C:\Windows\System32\tversity.cookies
2012-01-16 17:17 - 2008-04-04 15:29 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\My Documents\My Scans
2012-01-16 17:04 - 2011-12-16 05:14 - 0000000 ____D C:\Documents and Settings\All Users\Application Data\AVG Secure Search
2012-01-14 13:43 - 2012-01-14 13:43 - 0133649 ____A C:\Documents and Settings\Andy & Joanna\My Documents\zizzi.xps
2012-01-12 12:53 - 2008-10-16 08:48 - 1859968 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\win32k.sys
2012-01-12 12:53 - 2006-02-28 08:00 - 1859968 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-01-11 16:04 - 2012-01-11 13:53 - 0012135 ____A C:\Windows\KB2646524.log
2012-01-11 16:04 - 2012-01-11 13:53 - 0011502 ____A C:\Windows\KB2631813.log
2012-01-11 16:00 - 2012-01-11 13:53 - 0012096 ____A C:\Windows\KB2598479.log
2012-01-11 15:42 - 2012-01-11 15:42 - 0006540 ____A C:\Windows\KB2603381.log
2012-01-11 15:42 - 2012-01-11 15:42 - 0000000 __HDC C:\Windows\$NtUninstallKB2603381$
2012-01-11 15:41 - 2012-01-11 15:41 - 0000000 __HDC C:\Windows\$NtUninstallKB2584146$
2012-01-11 15:41 - 2012-01-11 13:53 - 0010902 ____A C:\Windows\KB2584146.log
2012-01-11 15:06 - 2012-02-16 15:55 - 0003072 ____N C:\Windows\System32\iacenc.dll
2012-01-11 15:06 - 2012-02-16 15:55 - 0003072 ____C C:\Windows\System32\dllcache\iacenc.dll
2012-01-07 12:12 - 2012-01-07 12:12 - 0011446 ____A C:\Documents and Settings\Andy & Joanna\My Documents\PRAYERS.docx
2012-01-01 13:18 - 2008-01-25 18:19 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Application Data\Apple Computer
2012-01-01 12:43 - 2012-01-01 12:43 - 0001604 ____A C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
2012-01-01 12:39 - 2012-01-01 12:39 - 0000000 ____D C:\Program Files\Bonjour
2011-12-19 04:13 - 2008-01-05 07:00 - 0569856 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msfeeds.dll
2011-12-19 04:13 - 2008-01-05 07:00 - 0482304 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ieapfltr.dll
2011-12-19 04:13 - 2008-01-05 07:00 - 0268288 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iertutil.dll
2011-12-19 04:13 - 2008-01-05 07:00 - 0164352 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\icardie.dll
2011-12-19 04:13 - 2008-01-05 07:00 - 0153600 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msfeedsbs.dll
2011-12-19 04:13 - 2007-08-13 14:54 - 6076416 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2011-12-19 04:13 - 2007-08-13 14:54 - 0468480 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2011-12-19 04:13 - 2007-08-13 14:54 - 0153600 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2011-12-19 04:13 - 2007-08-13 14:36 - 0164352 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2011-12-19 04:13 - 2007-08-13 14:34 - 0268288 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2011-12-19 04:13 - 2007-07-11 08:27 - 0482304 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 3717632 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\mshtml.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 3616768 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 1830912 ____N (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2011-12-19 04:13 - 2006-02-28 08:00 - 1830912 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\inetcpl.cpl
2011-12-19 04:13 - 2006-02-28 08:00 - 1168896 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\urlmon.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 1168896 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0832512 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wininet.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0832512 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0772608 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\mstime.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0772608 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0580096 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\mshtmled.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0485888 ____N (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0485888 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iedkcs32.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0478720 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0448000 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\dxtmsft.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0347136 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0334336 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\webcheck.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0331264 ____N (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0331264 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ieaksie.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0315904 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\dxtrans.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0294400 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msrating.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0294400 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0293376 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\iepeers.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0254464 ____N (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0254464 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ieakeng.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0234496 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\extmgr.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0233472 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0226304 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\advpack.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0214528 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0207360 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\url.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0192512 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0145920 ____N (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0145920 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iernonce.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0145408 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\pngfilt.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0129024 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\jsproxy.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0124928 ____A (Microsoft Corporation) C:\Windows\System32\advpack.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0118272 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\corpol.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0106496 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0102912 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\occache.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0102912 ____N (Microsoft Corporation) C:\Windows\System32\occache.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0078336 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\ieencode.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0078336 ____A (Microsoft Corporation) C:\Windows\System32\ieencode.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0044544 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0027648 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2011-12-19 04:13 - 2006-02-28 08:00 - 0017408 ____A (Microsoft Corporation) C:\Windows\System32\corpol.dll
2011-12-16 16:40 - 2011-12-16 05:15 - 0099171 ____A C:\Windows\KB2618444-IE7.log
2011-12-16 16:39 - 2011-12-16 05:15 - 0013163 ____A C:\Windows\KB2639417.log
2011-12-16 16:38 - 2011-12-16 16:38 - 0000000 __HDC C:\Windows\$NtUninstallKB2639417$
2011-12-16 16:38 - 2011-12-16 05:15 - 0012151 ____A C:\Windows\KB2624667.log
2011-12-16 16:33 - 2011-12-16 16:33 - 0004131 ____A C:\Windows\KB2633952.log
2011-12-16 16:33 - 2011-12-16 16:33 - 0000000 __HDC C:\Windows\$NtUninstallKB2633952$
2011-12-16 16:33 - 2011-12-16 05:14 - 0011327 ____A C:\Windows\KB2619339.log
2011-12-16 16:33 - 2008-01-05 07:01 - 0617170 ____A C:\Windows\System32\TZLog.log
2011-12-16 16:32 - 2011-12-16 16:32 - 0006816 ____A C:\Windows\KB2618451.log
2011-12-16 16:32 - 2011-12-16 16:32 - 0000000 __HDC C:\Windows\$NtUninstallKB2620712$
2011-12-16 16:32 - 2011-12-16 16:32 - 0000000 __HDC C:\Windows\$NtUninstallKB2618451$
2011-12-16 16:32 - 2011-12-16 05:14 - 0011406 ____A C:\Windows\KB2620712.log
2011-12-16 16:32 - 2011-12-16 05:13 - 0014288 ____A C:\Windows\KB2633171.log
2011-12-16 16:31 - 2011-12-16 16:31 - 0000000 __HDC C:\Windows\$NtUninstallKB2633171$
2011-12-16 08:22 - 2008-01-05 07:00 - 0114688 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ieudinit.exe
2011-12-16 08:22 - 2006-02-28 08:00 - 0171520 ____N (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2011-12-16 08:22 - 2006-02-28 08:00 - 0171520 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ie4uinit.exe
2011-12-16 07:00 - 2008-01-03 19:29 - 0634680 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iexplore.exe
2011-12-16 06:58 - 2006-02-28 08:00 - 0161792 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\ieakui.dll
2011-12-16 06:58 - 2006-02-28 08:00 - 0161792 ____N (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2011-12-16 05:50 - 2011-12-16 05:50 - 0000000 ____D C:\Documents and Settings\Andy & Joanna\Application Data\AVG Secure Search
2011-12-16 05:14 - 2011-12-16 05:14 - 0000000 ____D C:\Program Files\Common Files\AVG Secure Search

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points (XP) =====================

RP: -> 2012-03-10 13:37 - 028672 _restore{BE19214C-0968-4AF8-9B16-06D5279C8F65}\RP1049

RP: -> 2012-03-09 18:24 - 028672 _restore{BE19214C-0968-4AF8-9B16-06D5279C8F65}\RP1048

RP: -> 2012-03-09 17:35 - 028672 _restore{BE19214C-0968-4AF8-9B16-06D5279C8F65}\RP1047


========================= Memory info ======================

Percentage of memory in use: 13%
Total physical RAM: 2046.48 MB
Available physical RAM: 1763.41 MB
Total Pagefile: 1877.14 MB
Available Pagefile: 1809.41 MB
Total Virtual: 2047.88 MB
Available Virtual: 2002.18 MB

======================= Partitions =========================
  • 0

#73
nobbyburton

nobbyburton

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 173 posts
btw, no need to apologise, will wacth out for your replies, but am at work tomorrow and daughters birthday, but thanks again

i feel slightly more positive the end is in sight
  • 0

#74
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
I can see the problem but I am surprised that OTLPE did no clear it

What is drive H as that is where the userinit points to, so if this fails I may need to rewrite that reg key

Lets see if FSRT can do the job

What I will also do is stop teatimer in case that is replacing the entry I am trying to delete, so spybot may need to be re-installed

I have 3 restore points to play with if this does not work



Download the attached Fixlist.txt to the usb drive that has FRST on it

[attachment=56569:fixlist.txt]
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system .


Now please boot into the Reatogo Desktop.
Insert the USB drive with FSRT and Fixlist.txt on it
Run FSRT and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
  • 0

#75
nobbyburton

nobbyburton

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 173 posts
Ok will be home in an hour and will try, the h drive is in effect my c drive as I don't have a c drive, happy to remove spybot if that helps
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP