maliprog
and finally the OTL.Txt log
OTL logfile created on: 22/05/2012 09:56:26 - Run 1
OTL by OldTimer - Version 3.2.43.1 Folder = C:\Documents and Settings\richard\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.99 Gb Total Physical Memory | 2.06 Gb Available Physical Memory | 68.91% Memory free
4.32 Gb Paging File | 3.33 Gb Available in Paging File | 77.15% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 53.19 Gb Total Space | 16.99 Gb Free Space | 31.94% Space Free | Partition Type: NTFS
Drive D: | 53.70 Gb Total Space | 53.64 Gb Free Space | 99.89% Space Free | Partition Type: FAT32
Computer Name: PROMAN | User Name: richard | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/05/22 09:54:52 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\richard\My Documents\Downloads\OTL.scr
PRC - [2012/05/08 00:31:08 | 003,331,872 | ---- | M] (Akamai Technologies, Inc) -- C:\Documents and Settings\richard\Local Settings\Application Data\Akamai\netsession_win.exe
PRC - [2012/05/04 07:17:12 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/04/17 01:23:42 | 001,652,536 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
PRC - [2012/04/17 01:23:42 | 000,931,640 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2011/12/20 13:32:00 | 000,634,880 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
PRC - [2011/12/19 17:32:26 | 000,394,672 | ---- | M] (Eastman Kodak Company) -- C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
PRC - [2011/12/10 11:25:36 | 002,756,608 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\EKAiO2MUI.exe
PRC - [2011/09/15 12:06:04 | 000,088,576 | ---- | M] () -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2011/07/22 00:07:38 | 000,718,720 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
PRC - [2011/02/01 07:45:55 | 000,208,896 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Documents and Settings\richard\Local Settings\Temp\RtkBtMnt.exe
PRC - [2010/10/07 01:54:07 | 000,225,280 | ---- | M] (BUFFALO INC.) -- C:\Program Files\BUFFALO\Backup_Utility\BUVSSServiceXp.exe
PRC - [2010/10/07 01:54:05 | 001,822,720 | ---- | M] (BUFFALO INC.) -- C:\Program Files\BUFFALO\Backup_Utility\BUTray.exe
PRC - [2010/10/07 01:54:03 | 000,315,392 | ---- | M] (BUFFALO INC.) -- C:\Program Files\BUFFALO\Backup_Utility\BUService.exe
PRC - [2010/01/28 14:47:44 | 001,737,464 | ---- | M] () -- C:\Program Files\3\3Connect\BecHelperService.exe
PRC - [2009/02/06 15:23:36 | 000,727,720 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2009/02/06 15:23:12 | 002,021,400 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/04 18:10:26 | 000,030,152 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2007/06/14 21:40:04 | 000,850,704 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe
PRC - [2007/05/24 13:18:06 | 000,475,136 | ---- | M] () -- C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
PRC - [2007/03/30 13:52:24 | 000,342,528 | ---- | M] (HiTRUST) -- C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
PRC - [2007/03/21 21:00:04 | 000,355,096 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/03/21 21:00:00 | 000,174,872 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007/03/08 11:49:34 | 000,045,056 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
PRC - [2007/03/01 19:21:52 | 000,024,576 | ---- | M] ( ) -- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
PRC - [2006/12/17 21:32:16 | 000,143,360 | ---- | M] (Evoluent) -- C:\Program Files\Evoluent\VMouse\EvoMouExec.exe
PRC - [2006/06/01 15:40:54 | 000,413,696 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
========== Modules (No Company Name) ========== MOD - [2012/05/11 07:58:20 | 000,169,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Automation\f00a45464b25cfc9c5c5e8fb5f4c65b8\Inkjet.Automation.ni.dll
MOD - [2012/05/11 07:58:14 | 000,098,304 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.DeviceSettin#\aa9e5b16e62fd9074582fac9b222ccad\Inkjet.DeviceSettings.ni.dll
MOD - [2012/05/11 07:57:54 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\92d58f840f549f9bd880783d43db7e3c\System.Runtime.Remoting.ni.dll
MOD - [2012/05/11 07:57:44 | 000,237,056 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Localization\a867deed9e531e58a95d0e22c8c3b382\Inkjet.Localization.ni.dll
MOD - [2012/05/11 07:57:44 | 000,105,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Diagnostics\549e9236099ca3eac9c3f10099019459\Inkjet.Diagnostics.ni.dll
MOD - [2012/05/11 07:57:42 | 000,283,648 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Utilities\528120d87a5bbe3d0709d97017fb3217\Inkjet.Utilities.ni.dll
MOD - [2012/05/11 07:57:39 | 000,824,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Hardware\dacff62b95a3c6a4c4792e7743787777\Inkjet.Hardware.ni.dll
MOD - [2012/05/11 07:57:39 | 000,080,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Configuration\8a113d17ac02d8e4285ea1db21a3f286\Inkjet.Configuration.ni.dll
MOD - [2012/05/11 07:57:38 | 000,180,736 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Statistics\683ccae865dd1941a8ec53c781a01bdc\Inkjet.Statistics.ni.dll
MOD - [2012/05/11 07:57:33 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll
MOD - [2012/05/10 23:44:22 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll
MOD - [2012/05/10 23:44:12 | 012,430,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\995fcf39ead2c2a53e084505c2c67d49\System.Windows.Forms.ni.dll
MOD - [2012/05/10 23:43:56 | 001,591,808 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\8ca00132a08c69697adf1cda32ebd835\System.Drawing.ni.dll
MOD - [2012/05/10 23:42:00 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012/05/10 23:41:42 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2012/05/10 23:40:59 | 003,186,688 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2012/05/10 23:40:58 | 002,933,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2012/05/10 23:40:58 | 000,425,984 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
MOD - [2012/05/10 23:40:52 | 002,048,000 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
MOD - [2012/05/04 07:17:12 | 001,952,696 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/04/11 16:13:11 | 000,843,776 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_d0954948\system.drawing.dll
MOD - [2012/04/11 16:13:05 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_5cb2673c\system.windows.forms.dll
MOD - [2012/04/11 16:12:50 | 000,471,040 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2012/03/28 08:18:39 | 003,417,376 | ---- | M] () -- c:\Program Files\Common Files\Akamai\netsession_win_6c825ce.dll
MOD - [2012/01/02 04:01:49 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_922cb585\mscorlib.dll
MOD - [2012/01/02 04:01:37 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_432ecd3f\system.xml.dll
MOD - [2012/01/02 04:01:22 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_b1889730\system.dll
MOD - [2012/01/02 04:01:14 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2012/01/02 04:01:13 | 001,269,760 | ---- | M] () -- c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
MOD - [2012/01/02 04:01:12 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2011/12/20 13:32:00 | 001,515,520 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\Maps\R66Api.dll
MOD - [2011/12/20 13:32:00 | 000,634,880 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
MOD - [2011/12/20 13:32:00 | 000,559,244 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\sqlite3.7.dll
MOD - [2011/12/20 13:32:00 | 000,516,599 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\sqlite3.dll
MOD - [2011/12/20 13:32:00 | 000,389,120 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcDetect.dll
MOD - [2011/12/20 13:32:00 | 000,172,032 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcDetectLegend.dll
MOD - [2011/12/20 13:32:00 | 000,143,360 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcDisk.dll
MOD - [2011/12/20 13:32:00 | 000,103,936 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\OutputLog.dll
MOD - [2011/12/20 13:32:00 | 000,094,208 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\fdHttpd.dll
MOD - [2011/11/10 17:11:00 | 000,557,056 | ---- | M] () -- C:\Program Files\Trusteer\Rapport\bin\js32.dll
MOD - [2011/09/15 12:06:04 | 000,088,576 | ---- | M] () -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
MOD - [2011/08/07 21:25:21 | 000,516,368 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportMS.dll
MOD - [2011/03/17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 16:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2010/01/28 14:47:44 | 001,737,464 | ---- | M] () -- C:\Program Files\3\3Connect\BecHelperService.exe
MOD - [2007/07/12 23:33:58 | 000,087,552 | ---- | M] () -- C:\WINDOWS\system32\cpwmon2k.dll
MOD - [2007/06/16 04:05:20 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2007/06/16 04:05:20 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
MOD - [2007/06/16 04:05:20 | 000,323,584 | ---- | M] () -- c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
MOD - [2007/06/16 04:05:20 | 000,126,976 | ---- | M] () -- c:\windows\assembly\gac\system.serviceprocess\1.0.5000.0__b03f5f7f11d50a3a\system.serviceprocess.dll
MOD - [2007/06/14 21:40:06 | 000,057,344 | ---- | M] () -- C:\Program Files\Launch Manager\PowerUtl.dll
MOD - [2007/05/24 13:18:06 | 000,475,136 | ---- | M] () -- C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
MOD - [2007/04/27 18:12:02 | 001,368,064 | ---- | M] () -- c:\Acer\Empowering Technology\eNet\eNet.dll
MOD - [2007/04/06 02:56:30 | 000,356,352 | ---- | M] () -- C:\Acer\Empowering Technology\eRecovery\it41.dll
MOD - [2007/03/29 12:29:34 | 000,188,416 | ---- | M] () -- C:\Acer\Empowering Technology\eSettings\CPUID.dll
MOD - [2007/02/21 12:13:02 | 000,118,784 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2006/03/16 13:03:24 | 000,032,768 | ---- | M] () -- c:\Acer\Empowering Technology\eDataSecurity\eDSCS2CClassLib.dll
MOD - [2006/01/12 10:33:34 | 000,212,992 | ---- | M] () -- C:\Acer\Empowering Technology\eRecovery\imagefile.dll
MOD - [2005/10/20 18:20:24 | 000,208,896 | ---- | M] () -- C:\Acer\Empowering Technology\ePower\DialogDLL.dll
MOD - [2005/10/11 14:18:54 | 000,028,672 | ---- | M] () -- C:\Acer\Empowering Technology\ePower\SysHook.dll
MOD - [2002/11/26 14:43:18 | 000,106,496 | ---- | M] () -- C:\WINDOWS\system32\BrMuSNMP.dll
========== Win32 Services (SafeList) ========== SRV - [2012/05/04 07:17:13 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/04/17 01:23:42 | 000,931,640 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2012/03/28 08:18:39 | 003,417,376 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_6c825ce.dll -- (Akamai)
SRV - [2011/12/19 17:32:26 | 000,394,672 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe -- (Kodak AiO Network Discovery Service)
SRV - [2011/09/15 12:06:04 | 000,088,576 | ---- | M] () [Auto | Running] -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2011/06/12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010/10/07 01:54:07 | 000,225,280 | ---- | M] (BUFFALO INC.) [Auto | Running] -- C:\Program Files\BUFFALO\Backup_Utility\BUVSSServiceXp.exe -- (BFBackupUtilityVSSService)
SRV - [2010/10/07 01:54:03 | 000,315,392 | ---- | M] (BUFFALO INC.) [Auto | Running] -- C:\Program Files\BUFFALO\Backup_Utility\BUService.exe -- (BFBackupUtilityService)
SRV - [2010/01/28 14:47:44 | 001,737,464 | ---- | M] () [Auto | Running] -- C:\Program Files\3\3Connect\BecHelperService.exe -- (BecHelperService)
SRV - [2009/02/06 15:27:06 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009/02/06 15:23:36 | 000,727,720 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2008/11/11 10:38:06 | 000,620,544 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008/04/04 18:10:26 | 000,030,152 | ---- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Service)
SRV - [2007/03/21 21:00:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2007/03/01 19:21:52 | 000,024,576 | ---- | M] ( ) [Auto | Running] -- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe -- (eLockService)
SRV - [2005/11/02 15:32:02 | 000,086,016 | ---- | M] (CACE Technologies) [On_Demand | Unknown] -- C:\Program Files\WinPCap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\usbser_lowerflt.sys -- (upperdev)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\npf.sys -- (NPF)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS -- (MRESP50)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS -- (MRENDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS -- (MREMPR5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS -- (MREMP50)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\1D6.tmp -- (MEMSWEEP2)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/04/17 01:23:58 | 000,164,112 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2012/04/17 01:23:58 | 000,071,440 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys -- (RapportEI)
DRV - [2012/04/17 01:23:58 | 000,056,208 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2011/12/15 17:53:08 | 000,228,208 | ---- | M] () [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys -- (RapportCerberus_34302)
DRV - [2011/08/07 21:25:21 | 000,021,520 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Running] -- c:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportIaso.sys -- (RapportIaso)
DRV - [2010/06/22 18:01:52 | 000,021,248 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\htcnprot.sys -- (htcnprot)
DRV - [2010/02/28 14:17:06 | 000,390,528 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\RapportBuka.sys -- (RapportBuka)
DRV - [2010/01/28 14:35:24 | 000,010,240 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdvrmng.sys -- (mdvrmng)
DRV - [2010/01/28 13:34:32 | 000,102,528 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009/07/21 15:02:20 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/07/21 15:02:20 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/07/21 15:02:20 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009/07/21 10:15:42 | 000,114,688 | ---- | M] (ZTE Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnet.sys -- (ZTEusbnet)
DRV - [2009/06/10 15:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2009/04/27 15:00:54 | 000,009,728 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter.sys -- (massfilter)
DRV - [2009/02/06 15:24:22 | 000,056,280 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi)
DRV - [2009/02/06 15:24:22 | 000,033,096 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2009/02/06 15:24:18 | 000,130,952 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epfw.sys -- (epfw)
DRV - [2009/02/06 15:23:18 | 000,106,208 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009/02/06 15:19:52 | 000,113,448 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/11/14 09:00:15 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2007/07/16 22:29:33 | 000,017,432 | ---- | M] (Hewlett Packard) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hpfxbulk.sys -- (HPFXBULK)
DRV - [2007/05/31 04:04:56 | 004,424,192 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/03/29 12:27:42 | 000,014,544 | ---- | M] (EnTech Taiwan) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\TVicPort.sys -- (tvicport)
DRV - [2007/03/29 12:27:40 | 000,069,632 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\int15.sys -- (int15)
DRV - [2007/03/29 12:27:40 | 000,006,080 | ---- | M] (Zeal SoftStudio) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\zntport.sys -- (zntport)
DRV - [2007/02/25 07:05:24 | 002,203,520 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Intel®
DRV - [2007/02/22 11:15:56 | 000,137,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (nmwcd)
DRV - [2007/02/22 11:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (nmwcdcm)
DRV - [2007/02/22 11:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (nmwcdcj)
DRV - [2007/02/22 11:15:14 | 000,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (nmwcdc)
DRV - [2007/02/21 12:16:12 | 000,012,416 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2007/01/24 22:44:06 | 000,290,304 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2006/12/22 19:56:44 | 000,988,800 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2006/12/22 19:56:00 | 000,209,664 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2006/12/22 19:55:56 | 000,730,112 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2006/12/12 00:32:20 | 000,012,288 | ---- | M] (Evoluent) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\evomouflt.sys -- (evomouflt)
DRV - [2005/04/07 19:08:46 | 000,078,208 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-shd.sys -- (EpmShd)
DRV - [2005/01/13 15:46:16 | 000,069,632 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys)
DRV - [2004/07/19 14:10:00 | 000,004,096 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-psd.sys -- (EpmPsd)
DRV - [2003/01/10 17:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 13:11:30 | 000,096,640 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...ferrer:source?} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.yahoo....=utf-8&fr=b1ie7IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk/ig
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.co...urceid=ie7&rlz=IE - HKCU\..\SearchScopes\{C75C5CBF-E2CA-40F0-B1EA-D4A034FA7C69}: "URL" =
http://search.yahoo....=utf-8&fr=b1ie7IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;<local>
========== FireFox ========== FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..extensions.enabledItems: {4D144BC3-23FB-47de-90C5-63CCB0139CCF}:1.0
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.9: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll (Viewpoint Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/05/04 07:17:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/30 16:54:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
[email protected]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2009/03/12 22:42:39 | 000,000,000 | ---D | M]
[2011/07/18 08:57:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\richard\Application Data\Mozilla\Extensions
[2011/07/18 08:57:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\richard\Application Data\Mozilla\Extensions\
[email protected][2012/05/17 00:49:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\richard\Application Data\Mozilla\Firefox\Profiles\wq29r0lb.default\extensions
[2010/09/08 23:02:56 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\richard\Application Data\Mozilla\Firefox\Profiles\wq29r0lb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/27 09:51:14 | 000,000,000 | ---D | M] (TradeManager-Plugin) -- C:\Documents and Settings\richard\Application Data\Mozilla\Firefox\Profiles\wq29r0lb.default\extensions\{4D144BC3-23FB-47de-90C5-63CCB0139CCF}
[2012/05/16 23:25:51 | 000,000,000 | ---D | M] (Page Speed) -- C:\Documents and Settings\richard\Application Data\Mozilla\Firefox\Profiles\wq29r0lb.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2012/01/03 00:06:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/05/17 00:49:27 | 001,335,949 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\RICHARD\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\WQ29R0LB.DEFAULT\EXTENSIONS\
[email protected][2011/06/13 10:59:05 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/05/04 07:17:13 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/12/28 23:17:46 | 000,289,592 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
[2011/12/28 23:17:33 | 000,172,344 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\mozilla firefox\plugins\npatgpc.dll
[2011/06/13 10:59:04 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/05/04 07:17:09 | 000,001,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/12/21 06:02:40 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/05/04 07:17:09 | 000,000,935 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/05/04 07:17:09 | 000,001,166 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/05/04 07:17:13 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/05/04 07:17:09 | 000,001,121 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2008/12/30 01:59:48 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll (HiTRUST)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll (HiTRUST)
O4 - HKLM..\Run: [Backup Utility TaskTray Tool] C:\Program Files\BUFFALO\Backup_Utility\BUTray.exe (BUFFALO INC.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe ()
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe (HiTRUST)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [EKAIO2StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe ()
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Documents and Settings\richard\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk = C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe (Acer Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Evoluent Mouse Manager.lnk = C:\WINDOWS\Installer\{D4FE08FD-C342-4A50-AE8B-3E9236DC20ED}\_3490A01862136E4A51872C.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71}
http://download.micr...01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B}
http://aolcc.aolsvc....kup/qdiagcc.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C984BF1-7106-4DC0-80D1-B898EB0A775B}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\richard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\richard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{10ef1caa-96f0-11dd-9aaa-0019d2c63553}\Shell - "" = AutoRun
O33 - MountPoints2\{10ef1caa-96f0-11dd-9aaa-0019d2c63553}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{10ef1caa-96f0-11dd-9aaa-0019d2c63553}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{10ef1cac-96f0-11dd-9aaa-0019d2c63553}\Shell - "" = AutoRun
O33 - MountPoints2\{10ef1cac-96f0-11dd-9aaa-0019d2c63553}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{10ef1cac-96f0-11dd-9aaa-0019d2c63553}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{10ef1cae-96f0-11dd-9aaa-0019d2c63553}\Shell - "" = AutoRun
O33 - MountPoints2\{10ef1cae-96f0-11dd-9aaa-0019d2c63553}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{10ef1cae-96f0-11dd-9aaa-0019d2c63553}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{10ef1caf-96f0-11dd-9aaa-0019d2c63553}\Shell - "" = AutoRun
O33 - MountPoints2\{10ef1caf-96f0-11dd-9aaa-0019d2c63553}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{10ef1caf-96f0-11dd-9aaa-0019d2c63553}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{45b09a6a-94f8-11df-9ed6-0019d2c63553}\Shell - "" = AutoRun
O33 - MountPoints2\{45b09a6a-94f8-11df-9ed6-0019d2c63553}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{45b09a6a-94f8-11df-9ed6-0019d2c63553}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{9f696a9e-096c-11e0-9fa4-0019d2c63553}\Shell - "" = AutoRun
O33 - MountPoints2\{9f696a9e-096c-11e0-9fa4-0019d2c63553}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9f696a9e-096c-11e0-9fa4-0019d2c63553}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{a0ecc462-4f58-11de-9c56-0019d2c63553}\Shell - "" = AutoRun
O33 - MountPoints2\{a0ecc462-4f58-11de-9c56-0019d2c63553}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a0ecc462-4f58-11de-9c56-0019d2c63553}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{b156cea6-0924-11e0-9f9f-0019d2c63553}\Shell - "" = AutoRun
O33 - MountPoints2\{b156cea6-0924-11e0-9f9f-0019d2c63553}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b156cea6-0924-11e0-9f9f-0019d2c63553}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{b156cea9-0924-11e0-9f9f-0019d2c63553}\Shell - "" = AutoRun
O33 - MountPoints2\{b156cea9-0924-11e0-9f9f-0019d2c63553}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b156cea9-0924-11e0-9f9f-0019d2c63553}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ========== [2012/05/22 08:45:27 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\richard\Recent
[2012/05/22 05:11:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\richard\My Documents\hijackthis
[2012/05/22 04:47:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\richard\Start Menu\Programs\HiJackThis
[2012/05/21 22:28:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sophos
[2012/05/21 22:28:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\richard\Start Menu\Programs\Sophos
[2012/05/21 22:04:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\ESET
[2012/05/21 15:51:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\richard\Application Data\Malwarebytes
[2012/05/21 15:50:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/05/21 15:50:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/05/21 15:50:46 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/05/21 15:50:46 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/05/21 06:59:10 | 000,000,000 | -HSD | C] -- C:\found.000
[2012/05/18 15:15:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\richard\My Documents\pictures of steele
[2012/05/12 21:23:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\richard\My Documents\Steele builderdispute
[2012/05/12 21:20:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\richard\My Documents\dpa
[2012/05/12 21:16:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\richard\My Documents\Steele ciob twitter
[2012/05/12 21:14:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\richard\My Documents\Steele twitter Mr Survey
[2012/05/12 21:13:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\richard\My Documents\Steele dampproofingblog.com
[2012/05/04 07:17:23 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012/05/04 07:17:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\Documents and Settings\richard\My Documents\*.tmp files -> C:\Documents and Settings\richard\My Documents\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/05/22 09:55:00 | 000,000,888 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/22 09:27:58 | 000,002,345 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Evoluent Mouse Manager.lnk
[2012/05/22 09:27:21 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/05/22 09:27:19 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/22 09:27:17 | 000,000,442 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2012/05/22 09:20:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/05/22 09:20:36 | 3210,924,032 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/22 04:47:52 | 000,002,451 | ---- | M] () -- C:\Documents and Settings\richard\Desktop\HiJackThis.lnk
[2012/05/21 22:28:19 | 000,002,078 | ---- | M] () -- C:\Documents and Settings\richard\Desktop\Sophos Virus Removal Tool.lnk
[2012/05/21 15:50:49 | 000,000,788 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/20 13:18:00 | 000,000,820 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2012/05/19 21:04:21 | 000,311,785 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\ryan quote page 1.JPG
[2012/05/17 16:03:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/05/17 13:49:40 | 000,001,338 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\sam spade sleuth favicon.png
[2012/05/17 01:43:42 | 000,146,228 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\17 may dpa news.JPG
[2012/05/15 22:41:33 | 000,323,679 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\Louis J Updated Report.pdf
[2012/05/15 12:31:05 | 000,141,571 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\dpa 15 may.JPG
[2012/05/15 09:31:15 | 000,008,604 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\image protectacoat.JPG
[2012/05/15 09:10:03 | 000,138,007 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\yahoo account.JPG
[2012/05/15 08:57:21 | 000,164,678 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\CIOB protectacoat.JPG
[2012/05/12 23:09:38 | 000,169,054 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\wykamol gpi help.JPG
[2012/05/11 16:51:35 | 000,163,378 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\new bogart.JPG
[2012/05/11 07:39:31 | 000,439,736 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/05/10 23:41:08 | 000,752,008 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/05/10 23:41:08 | 000,201,440 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/05/10 00:02:42 | 000,219,997 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\tradesmen4u.JPG
[2012/05/06 18:04:49 | 000,121,397 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\c_buying_at_auction.pdf
[2012/05/03 01:23:00 | 000,167,949 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\lifecote prop ladder.JPG
[2012/04/30 17:08:17 | 000,165,340 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\blog defamation 4.JPG
[2012/04/30 17:07:36 | 000,181,894 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\blog defamation3.JPG
[2012/04/30 17:06:25 | 000,159,819 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\blog defamation 2.JPG
[2012/04/30 17:05:50 | 000,181,893 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\blog defamation 1.JPG
[2012/04/30 17:03:29 | 000,178,662 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\blog defamation rgj.JPG
[2012/04/29 14:36:12 | 001,525,812 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\Cafcass Younger MFC low res.pdf
[2012/04/29 13:48:38 | 000,237,653 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\d008-notes-eng.pdf
[2012/04/29 13:40:24 | 002,223,510 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\children seperation.pdf
[2012/04/26 12:19:30 | 000,201,395 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\ciob steele blog.JPG
[2012/04/23 06:48:59 | 000,013,215 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\ultimateplugins.com-smart-update-pinger.zip
[2012/04/23 03:26:00 | 000,008,704 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\DPC IMAGE.JPG
[2012/04/23 03:15:52 | 000,031,220 | ---- | M] () -- C:\Documents and Settings\richard\My Documents\news_dpc_too_2.jpg
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\Documents and Settings\richard\My Documents\*.tmp files -> C:\Documents and Settings\richard\My Documents\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/05/22 04:47:07 | 000,002,451 | ---- | C] () -- C:\Documents and Settings\richard\Desktop\HiJackThis.lnk
[2012/05/21 22:28:19 | 000,002,078 | ---- | C] () -- C:\Documents and Settings\richard\Desktop\Sophos Virus Removal Tool.lnk
[2012/05/21 15:50:49 | 000,000,788 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/19 21:04:21 | 000,311,785 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\ryan quote page 1.JPG
[2012/05/17 13:49:40 | 000,001,338 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\sam spade sleuth favicon.png
[2012/05/17 01:43:42 | 000,146,228 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\17 may dpa news.JPG
[2012/05/15 22:41:33 | 000,323,679 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\Louis J Updated Report.pdf
[2012/05/15 12:31:05 | 000,141,571 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\dpa 15 may.JPG
[2012/05/15 09:31:15 | 000,008,604 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\image protectacoat.JPG
[2012/05/15 09:10:03 | 000,138,007 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\yahoo account.JPG
[2012/05/15 08:57:20 | 000,164,678 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\CIOB protectacoat.JPG
[2012/05/12 23:09:37 | 000,169,054 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\wykamol gpi help.JPG
[2012/05/11 16:51:35 | 000,163,378 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\new bogart.JPG
[2012/05/10 00:02:41 | 000,219,997 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\tradesmen4u.JPG
[2012/05/06 18:04:43 | 000,121,397 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\c_buying_at_auction.pdf
[2012/05/03 01:23:00 | 000,167,949 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\lifecote prop ladder.JPG
[2012/04/30 17:08:16 | 000,165,340 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\blog defamation 4.JPG
[2012/04/30 17:07:36 | 000,181,894 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\blog defamation3.JPG
[2012/04/30 17:06:25 | 000,159,819 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\blog defamation 2.JPG
[2012/04/30 17:05:50 | 000,181,893 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\blog defamation 1.JPG
[2012/04/30 17:03:28 | 000,178,662 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\blog defamation rgj.JPG
[2012/04/29 14:36:12 | 001,525,812 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\Cafcass Younger MFC low res.pdf
[2012/04/29 13:48:38 | 000,237,653 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\d008-notes-eng.pdf
[2012/04/29 13:40:24 | 002,223,510 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\children seperation.pdf
[2012/04/26 12:19:30 | 000,201,395 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\ciob steele blog.JPG
[2012/04/23 06:48:58 | 000,013,215 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\ultimateplugins.com-smart-update-pinger.zip
[2012/04/23 03:26:00 | 000,008,704 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\DPC IMAGE.JPG
[2012/04/23 03:15:51 | 000,031,220 | ---- | C] () -- C:\Documents and Settings\richard\My Documents\news_dpc_too_2.jpg
[2012/02/15 14:51:37 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/11/17 08:43:11 | 000,172,843 | ---- | C] () -- C:\WINDOWS\hppins13.dat.temp
[2011/11/16 21:56:04 | 000,000,619 | ---- | C] () -- C:\WINDOWS\System32\hppapr13.dat
[2011/09/17 21:08:52 | 000,081,106 | ---- | C] () -- C:\WINDOWS\HPHins08.dat
[2011/09/17 21:08:52 | 000,004,011 | ---- | C] () -- C:\WINDOWS\hphmdl08.dat
[2011/09/17 21:08:42 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2011/08/05 15:35:30 | 000,001,056 | ---- | C] () -- C:\WINDOWS\System32\EKaio2WiaCoInst.ini
[2011/03/05 10:11:52 | 000,108,504 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/10/07 01:54:29 | 000,015,725 | ---- | C] () -- C:\WINDOWS\UN091222.INI
========== LOP Check ========== [2008/10/10 18:24:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Birdstep Technology
[2009/03/12 22:42:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2009/02/12 20:10:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2009/08/01 10:45:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/09/15 20:52:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2011/03/21 23:19:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\O2CM-CE
[2009/02/10 18:34:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2008/12/27 17:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2012/05/21 22:28:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sophos
[2009/06/04 09:32:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2010/01/04 01:09:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/09/21 21:27:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viper
[2011/03/03 12:31:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/05/14 09:27:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/10/10 18:24:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Birdstep Technology
[2008/10/10 18:17:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Birdstep Technology(2)
[2008/10/10 18:17:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Birdstep Technology(3)
[2008/10/10 18:17:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Birdstep Technology(4)
[2009/03/12 22:43:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\ESET
[2010/05/23 13:15:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\FUJIFILM
[2012/03/27 08:54:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\HTC
[2012/03/27 08:53:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2009/02/12 21:50:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Nokia
[2011/06/22 22:36:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Nokia Multimedia Player
[2012/03/27 09:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Outlook
[2009/06/10 22:17:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\PC Suite
[2008/09/26 16:51:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Rokario
[2007/12/22 22:39:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\ScanSoft
[2011/04/11 22:50:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Serif
[2010/09/28 15:32:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\SmartDraw
[2011/03/21 23:30:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Tatara Systems
[2011/12/03 10:38:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Temp
[2011/07/18 08:57:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\TomTom
[2009/03/01 23:56:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\richard\Application Data\Trusteer
[2012/05/22 09:27:17 | 000,000,442 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Program Check.job
[2012/03/22 04:00:00 | 000,000,376 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: EXPLORER.EXE >[2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 12:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 11:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: SVCHOST.EXE >[2012/04/04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/04/14 01:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 01:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2004/08/05 04:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: USERINIT.EXE >[2004/08/05 04:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 01:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 01:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 01:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2004/08/05 04:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/04/04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /mp /s > < hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/05/04 07:17:09 | 000,866,992 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/05/04 07:17:09 | 000,866,992 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/05/04 07:17:09 | 000,866,992 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/05/04 07:17:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/05/04 07:17:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/05/04 07:17:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2012/02/29 13:16:50 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2012/02/29 13:16:50 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2012/02/29 13:16:50 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" [2012/02/29 12:01:00 | 000,634,680 | ---- | M] (Microsoft Corporation)
< hklm\software\clients\startmenuinternet|command /64 /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/05/04 07:17:09 | 000,866,992 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/05/04 07:17:09 | 000,866,992 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/05/04 07:17:09 | 000,866,992 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/05/04 07:17:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/05/04 07:17:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/05/04 07:17:12 | 000,924,600 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2012/02/29 13:16:50 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2012/02/29 13:16:50 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2012/02/29 13:16:50 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" [2012/02/29 12:01:00 | 000,634,680 | ---- | M] (Microsoft Corporation)
< > < > < >< End of report >