ComboFix 10-05-01.01 - Graham 05/01/2010 13:02:06.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2988 [GMT -5:00]
Running from: c:\documents and settings\Graham\Desktop\Alureon.G\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\WindowsUpdate
c:\windows\system32\Data
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((( Files Created from 2010-04-01 to 2010-05-01 )))))))))))))))))))))))))))))))
.
2010-04-28 22:26 . 2008-04-14 00:12 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-04-28 22:26 . 2001-08-18 03:36 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-04-28 22:26 . 2008-04-14 00:12 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-04-28 22:26 . 2001-08-18 03:37 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-04-28 22:26 . 2001-08-18 03:37 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-04-28 22:25 . 2001-08-18 03:37 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
2010-04-28 22:25 . 2001-08-17 17:11 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-04-28 22:25 . 2004-08-04 03:29 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-04-28 22:25 . 2008-04-13 18:46 19200 ----a-w- c:\windows\system32\dllcache\wstcodec.sys
2010-04-28 22:25 . 2004-08-04 03:29 12063 ----a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-04-28 22:25 . 2008-04-14 00:12 8192 ----a-w- c:\windows\system32\dllcache\wshirda.dll
2010-04-28 22:25 . 2008-04-13 18:36 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-04-28 22:25 . 2004-08-04 03:31 154624 ----a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-04-28 22:25 . 2001-08-17 17:12 34890 ----a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-04-28 22:25 . 2001-08-17 18:28 771581 ----a-w- c:\windows\system32\dllcache\winacisa.sys
2010-04-28 22:23 . 2001-08-17 18:49 24576 ----a-w- c:\windows\system32\dllcache\viairda.sys
2010-04-28 22:22 . 2001-08-18 03:36 50688 ----a-w- c:\windows\system32\dllcache\umaxscan.dll
2010-04-28 22:21 . 2001-08-17 17:12 34375 ----a-w- c:\windows\system32\dllcache\tpro4.sys
2010-04-28 22:20 . 2001-08-17 17:50 36640 ----a-w- c:\windows\system32\dllcache\t2r4mini.sys
2010-04-28 22:19 . 2001-08-18 03:36 24660 ----a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-04-28 22:18 . 2001-08-17 17:12 24576 ----a-w- c:\windows\system32\dllcache\smc8000n.sys
2010-04-28 22:17 . 2001-08-17 17:50 68608 ----a-w- c:\windows\system32\dllcache\sis6306p.sys
2010-04-28 22:16 . 2008-04-13 18:40 43904 ----a-w- c:\windows\system32\dllcache\sbp2port.sys
2010-04-28 22:15 . 2001-08-17 17:12 19017 ----a-w- c:\windows\system32\dllcache\rtl8029.sys
2010-04-28 22:14 . 2001-08-18 03:36 5632 ----a-w- c:\windows\system32\dllcache\ptpusb.dll
2010-04-28 22:13 . 2001-08-17 17:11 30282 ----a-w- c:\windows\system32\dllcache\pcntn5hl.sys
2010-04-28 22:12 . 2001-08-17 17:12 27209 ----a-w- c:\windows\system32\dllcache\otc06x5.sys
2010-04-28 22:11 . 2001-08-17 17:50 39264 ----a-w- c:\windows\system32\dllcache\neo20xx.sys
2010-04-28 22:10 . 2008-04-13 18:39 5504 ----a-w- c:\windows\system32\dllcache\mstee.sys
2010-04-28 22:10 . 2008-04-13 18:46 49024 ----a-w- c:\windows\system32\dllcache\mstape.sys
2010-04-28 22:10 . 2001-08-17 18:48 12416 ----a-w- c:\windows\system32\dllcache\msriffwv.sys
2010-04-28 22:10 . 2001-08-17 19:00 2944 ----a-w- c:\windows\system32\dllcache\msmpu401.sys
2010-04-28 22:10 . 2008-04-13 18:54 22016 ----a-w- c:\windows\system32\dllcache\msircomm.sys
2010-04-28 22:10 . 2004-08-10 10:00 98304 ----a-w- c:\windows\system32\dllcache\msir3jp.dll
2010-04-28 22:10 . 2001-08-17 19:02 35200 ----a-w- c:\windows\system32\dllcache\msgame.sys
2010-04-28 22:10 . 2001-08-17 18:48 6016 ----a-w- c:\windows\system32\dllcache\msfsio.sys
2010-04-28 22:10 . 2008-04-13 18:46 51200 ----a-w- c:\windows\system32\dllcache\msdv.sys
2010-04-28 22:10 . 2008-04-13 18:46 15232 ----a-w- c:\windows\system32\dllcache\mpe.sys
2010-04-28 22:08 . 2004-08-04 03:41 420992 ----a-w- c:\windows\system32\dllcache\ltmdmntt.sys
2010-04-28 22:07 . 2008-04-14 00:09 6144 ----a-w- c:\windows\system32\dllcache\kbd106.dll
2010-04-28 22:06 . 2001-08-18 03:36 372824 ----a-w- c:\windows\system32\dllcache\iconf32.dll
2010-04-28 22:05 . 2001-08-17 18:28 488383 ----a-w- c:\windows\system32\dllcache\hsf_v124.sys
2010-04-28 22:04 . 2001-08-18 03:36 93696 ----a-w- c:\windows\system32\dllcache\hpgt42.dll
2010-04-28 22:03 . 2001-08-17 17:15 455296 ----a-w- c:\windows\system32\dllcache\fusbbase.sys
2010-04-28 22:02 . 2001-08-17 18:28 594238 ----a-w- c:\windows\system32\dllcache\es56hpi.sys
2010-04-28 22:01 . 2001-08-17 17:10 55999 ----a-w- c:\windows\system32\dllcache\el556nd5.sys
2010-04-28 22:00 . 2001-08-18 03:36 419357 ----a-w- c:\windows\system32\dllcache\dgconfig.dll
2010-04-28 21:59 . 2004-08-10 10:00 18944 ----a-w- c:\windows\system32\dllcache\cprofile.exe
2010-04-28 21:58 . 2004-08-10 10:00 6656 ----a-w- c:\windows\system32\dllcache\c_is2022.dll
2010-04-28 21:57 . 2001-08-17 17:11 54271 ----a-w- c:\windows\system32\dllcache\bcm42xx5.sys
2010-04-28 21:56 . 2001-08-17 17:19 553984 ----a-w- c:\windows\system32\dllcache\adm8820.sys
2010-04-28 21:55 . 2001-08-17 19:56 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-04-28 21:03 . 2010-04-28 21:03 -------- d-----w- c:\documents and settings\Graham\AdobeLicensingFilesBackup
2010-04-28 06:04 . 2010-04-28 06:04 -------- d-----w- c:\program files\BitTorrent
2010-04-28 05:33 . 2010-03-26 15:33 1496064 ----a-w- c:\documents and settings\Graham\Application Data\Mozilla\Firefox\Profiles\nw5edqef.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-04-28 05:33 . 2010-03-26 15:33 43008 ----a-w- c:\documents and settings\Graham\Application Data\Mozilla\Firefox\Profiles\nw5edqef.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-04-28 05:33 . 2010-03-26 15:33 339456 ----a-w- c:\documents and settings\Graham\Application Data\Mozilla\Firefox\Profiles\nw5edqef.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-04-28 05:33 . 2010-03-26 15:32 346112 ----a-w- c:\documents and settings\Graham\Application Data\Mozilla\Firefox\Profiles\nw5edqef.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-04-28 02:04 . 2010-04-28 02:05 -------- d-----w- c:\program files\iTunes
2010-04-28 01:58 . 2010-04-28 01:58 -------- d-----w- c:\program files\Bonjour
2010-04-28 01:56 . 2010-04-28 01:56 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.11\SetupAdmin.exe
2010-04-24 07:40 . 2010-04-24 07:40 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2010-04-20 23:40 . 2010-04-20 23:40 3584 ----a-r- c:\documents and settings\Graham\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-04-20 23:40 . 2010-04-20 23:40 -------- d-----w- c:\program files\Windows Installer Clean Up
2010-04-19 21:24 . 2010-04-19 21:24 84480 ----a-w- c:\documents and settings\Graham\Application Data\SystemRequirementsLab\srlproxy_intel_4.1.66.0A.dll
2010-04-18 17:54 . 2010-04-27 12:31 -------- d-----w- c:\documents and settings\Graham\Application Data\GHISLER
2010-04-18 17:54 . 2009-09-24 12:50 545 ----a-w- c:\windows\UC.PIF
2010-04-18 17:54 . 2009-09-24 12:50 545 ----a-w- c:\windows\RAR.PIF
2010-04-18 17:54 . 2009-09-24 12:50 545 ----a-w- c:\windows\PKZIP.PIF
2010-04-18 17:54 . 2009-09-24 12:50 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-04-18 17:54 . 2009-09-24 12:50 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-04-18 17:54 . 2009-09-24 12:50 545 ----a-w- c:\windows\LHA.PIF
2010-04-18 17:54 . 2009-09-24 12:50 545 ----a-w- c:\windows\ARJ.PIF
2010-04-18 17:46 . 2010-02-04 15:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-04-18 17:46 . 2010-02-04 15:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-04-18 17:46 . 2010-02-04 15:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-04-18 17:46 . 2010-02-04 15:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-04-16 01:02 . 2010-04-16 01:14 -------- d-----w- c:\program files\NirSoft
2010-04-13 22:52 . 2010-04-13 22:52 -------- d-----w- C:\Python31
2010-04-13 22:49 . 2010-04-13 22:49 -------- d-----w- C:\Python27
2010-04-13 20:44 . 2010-04-07 20:28 253952 ----a-w- c:\documents and settings\Graham\Application Data\Mozilla\Firefox\Profiles\nw5edqef.default\extensions\
[email protected]\plugins\npCoralIETab.dll
2010-04-12 20:33 . 2010-04-12 20:33 -------- d-----w- c:\program files\WhoCrashed
2010-04-12 18:26 . 2010-04-12 18:26 237320 ----a-w- c:\windows\system32\PDBoot.exe
2010-04-12 05:13 . 2010-03-29 20:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-12 05:13 . 2010-03-29 20:24 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-11 07:11 . 2010-04-12 05:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-11 03:44 . 2010-04-11 03:44 2291200 ----a-w- c:\windows\system32\python27.dll
2010-04-08 18:20 . 2010-04-08 18:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 18:20 . 2010-04-08 18:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-02 05:18 . 2010-04-02 05:12 754984 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-04-02 05:18 . 2010-04-02 05:11 986904 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-04-02 05:18 . 2009-09-01 11:38 529200 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivX7\DivX Plus DirectShow Filters\DivXDSFiltersUninstall.exe
2010-04-02 05:18 . 2009-09-01 11:37 529200 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe
2010-04-02 05:18 . 2010-04-02 05:18 56766 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-04-02 05:18 . 2010-04-02 05:18 56978 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-04-02 05:18 . 2010-04-02 05:18 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-04-02 05:18 . 2010-04-02 05:18 57677 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-04-02 05:17 . 2010-04-02 05:17 84035 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-04-02 05:17 . 2010-04-02 05:17 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-04-02 05:17 . 2010-04-02 05:17 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-04-02 05:17 . 2010-04-02 05:17 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-04-02 05:17 . 2010-04-02 05:17 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-04-02 05:17 . 2010-04-02 05:17 54174 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-04-02 05:17 . 2010-04-02 05:17 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-04-02 05:17 . 2010-04-02 05:17 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-04-02 05:17 . 2010-04-02 05:17 54629 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-04-02 05:17 . 2010-04-02 05:17 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-04-02 05:16 . 2010-04-02 05:16 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-04-02 05:16 . 2010-04-02 05:16 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-04-02 05:15 . 2010-04-02 05:15 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-04-02 05:15 . 2010-04-02 05:15 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-04-02 05:12 . 2010-04-02 05:18 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-04-01 21:25 . 2010-04-01 21:25 -------- d-----w- C:\_OTL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-01 17:58 . 2010-03-29 01:09 -------- d-----w- c:\program files\PeerBlock
2010-05-01 04:10 . 2005-10-26 18:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-01 04:08 . 2005-10-26 19:00 -------- d-----w- c:\program files\Creative
2010-05-01 04:07 . 2007-11-18 06:48 409600 ----a-w- c:\windows\system32\wrap_oal.dll
2010-05-01 04:07 . 2005-10-26 19:01 114688 ----a-w- c:\windows\system32\OpenAL32.dll
2010-05-01 03:55 . 2007-10-13 04:23 -------- d-----w- c:\program files\Live for Speed S2 Modified
2010-04-30 03:28 . 2007-05-15 04:13 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-04-29 12:34 . 2005-11-01 03:26 37274 ----a-w- c:\documents and settings\Graham\Application Data\wklnhst.dat
2010-04-28 21:03 . 2006-12-28 00:20 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2010-04-28 02:04 . 2006-11-17 23:04 -------- d-----w- c:\program files\iPod
2010-04-28 02:04 . 2007-06-30 20:12 -------- d-----w- c:\program files\Common Files\Apple
2010-04-24 02:47 . 2006-12-06 22:51 -------- d-----w- c:\documents and settings\Graham\Application Data\BitTorrent
2010-04-23 06:49 . 2005-10-26 19:00 -------- d-----w- c:\program files\ATI Technologies
2010-04-21 02:07 . 2007-01-02 03:15 -------- d-----w- c:\documents and settings\Graham\Application Data\DivX
2010-04-20 23:40 . 2009-11-13 01:23 -------- d-----w- c:\program files\MSECACHE
2010-04-19 21:25 . 2009-10-15 22:22 -------- d-----w- c:\program files\SystemRequirementsLab
2010-04-19 21:24 . 2009-10-15 22:22 -------- d-----w- c:\documents and settings\Graham\Application Data\SystemRequirementsLab
2010-04-18 14:55 . 2005-11-10 03:15 -------- d-----w- c:\program files\NovaLogic
2010-04-13 20:53 . 2007-03-28 00:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-02 05:18 . 2007-01-02 02:54 -------- d-----w- c:\program files\DivX
2010-04-02 05:15 . 2009-09-01 11:34 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-03-31 03:00 . 2010-03-31 03:00 -------- d-----w- c:\program files\Common Files\Java
2010-03-31 02:59 . 2008-11-22 01:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-30 23:30 . 2010-03-30 23:30 11024 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp DSP Effects.dat
2010-03-30 23:30 . 2007-01-15 01:33 3494576 ----a-w- c:\windows\system32\SpoonUninstall.exe
2010-03-30 23:29 . 2010-03-30 23:29 15607 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2010-03-30 22:37 . 2010-03-30 22:36 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-03-30 22:33 . 2006-01-27 03:53 -------- d-----w- c:\program files\QuickTime
2010-03-30 07:28 . 2010-03-06 20:19 -------- d-----w- c:\program files\CCleaner
2010-03-29 01:33 . 2010-03-29 01:33 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-03-29 01:32 . 2006-03-03 02:43 -------- d-----w- c:\program files\Google
2010-03-29 01:09 . 2008-10-25 22:44 -------- d-----w- c:\program files\PeerGuardian2
2010-03-27 17:57 . 2007-10-08 23:36 -------- d-----w- c:\program files\Live for Speed S2
2010-03-21 05:43 . 2010-03-21 05:43 2137600 ----a-w- c:\windows\system32\python31.dll
2010-03-10 05:07 . 2009-10-22 23:57 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-03-10 00:27 . 2010-03-10 00:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco
2010-03-10 00:27 . 2010-01-27 02:58 -------- d-----w- c:\program files\Raxco
2010-03-09 11:09 . 2004-08-19 20:49 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-02-26 05:43 . 2004-08-19 20:49 667136 ------w- c:\windows\system32\wininet.dll
2010-02-26 05:43 . 2004-08-19 20:49 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-02-24 15:16 . 2009-10-03 19:56 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-24 13:11 . 2005-10-26 18:34 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-19 19:27 . 2010-02-19 19:27 720384 ----a-w- c:\windows\system32\DivX.dll
2010-02-19 19:27 . 2010-02-19 19:27 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2010-02-19 19:27 . 2010-02-19 19:27 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2010-02-19 19:27 . 2010-02-19 19:27 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2010-02-19 19:27 . 2010-02-19 19:27 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2010-02-19 19:27 . 2010-02-19 19:27 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2010-02-16 14:08 . 2004-08-19 20:49 2146304 ------w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-04 03:59 2024448 ------w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2004-08-19 20:49 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-19 20:49 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-11 07:38 . 2010-04-30 23:37 3565056 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-02-11 05:17 . 2010-04-30 23:37 11845632 ----a-w- c:\windows\system32\atioglxx.dll
2010-02-11 05:07 . 2010-04-30 23:37 307200 ----a-w- c:\windows\system32\atiiiexx.dll
2010-02-11 04:46 . 2007-03-15 01:58 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-02-11 04:45 . 2010-04-30 23:37 325120 ----a-w- c:\windows\system32\ati2dvag.dll
2010-02-11 04:45 . 2007-07-28 03:30 325120 ----a-w- c:\windows\system32\ati2dvag.dll.tmp
2010-02-11 04:37 . 2007-09-29 02:47 290816 ----a-w- c:\windows\system32\atiok3x2.dll
2010-02-11 04:36 . 2010-04-30 23:37 204800 ----a-w- c:\windows\system32\atipdlxx.dll
2010-02-11 04:35 . 2010-04-30 23:37 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-02-11 04:35 . 2010-04-30 23:37 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-02-11 04:35 . 2010-04-30 23:37 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-02-11 04:35 . 2010-04-30 23:37 155648 ----a-w- c:\windows\system32\ati2evxx.dll
2010-02-11 04:33 . 2010-04-30 23:37 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2010-02-11 04:32 . 2010-04-30 23:37 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-02-11 04:25 . 2010-04-30 23:37 3818144 ----a-w- c:\windows\system32\ati3duag.dll
2010-02-11 04:25 . 2005-10-26 18:35 3818144 ----a-w- c:\windows\system32\ati3duag.dll.tmp
2010-02-11 04:23 . 2010-02-11 04:23 45056 ----a-w- c:\windows\system32\aticalrt.dll
2010-02-11 04:22 . 2010-02-11 04:22 45056 ----a-w- c:\windows\system32\aticalcl.dll
2010-02-11 04:21 . 2010-02-11 04:21 3227648 ----a-w- c:\windows\system32\aticaldd.dll
2010-02-11 04:19 . 2010-04-30 23:37 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-02-11 04:12 . 2010-04-30 23:37 2670592 ----a-w- c:\windows\system32\ativvaxx.dll
2010-02-11 04:12 . 2005-10-26 18:35 2670592 ----a-w- c:\windows\system32\ativvaxx.dll.tmp
2010-02-11 04:12 . 2007-09-29 02:36 887724 ----a-w- c:\windows\system32\ativva6x.dat
2010-02-11 04:12 . 2007-09-29 02:36 3107788 ----a-w- c:\windows\system32\ativva5x.dat
2010-02-11 03:59 . 2010-02-11 03:59 49664 ----a-w- c:\windows\system32\amdpcom32.dll
2010-02-11 03:55 . 2010-04-30 23:37 475136 ----a-w- c:\windows\system32\atikvmag.dll
2010-02-11 03:54 . 2010-02-11 03:54 126976 ----a-w- c:\windows\system32\atiadlxx.dll
2010-02-11 03:53 . 2010-04-30 23:37 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-02-11 03:47 . 2010-04-30 23:37 626688 ----a-w- c:\windows\system32\ati2cqag.dll
2010-02-11 03:47 . 2005-10-26 18:35 626688 ----a-w- c:\windows\system32\ati2cqag.dll.tmp
2010-02-11 02:20 . 2007-11-14 05:12 593920 ------w- c:\windows\system32\ati2sgag.exe
2008-03-29 20:18 . 2005-10-28 04:27 3558 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerBlock"="c:\program files\PeerBlock\peerblock.exe" [2010-03-09 1738352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-24 142120]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-11-22 842584]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"P17Helper"="P17.dll" [2005-05-04 64512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Auto Detect.lnk - c:\program files\iConcepts Music Express\MEAutoDetect.exe [2007-9-22 270336]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-10-26 24576]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2009-06-10 08:57 136472 ----a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2009-06-10 09:02 904840 ----a-w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
2006-10-23 12:50 71216 ----a-r- c:\program files\Common Files\AOL\acs\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2003-09-17 15:43 57344 ----a-w- c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-03-05 15:32 1135912 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2007-04-02 10:24 113400 ----a-w- c:\program files\Sonic\Product\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 19:56 64512 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2009-07-20 19:52 41264 ----a-w- c:\program files\Common Files\AOL\1130467576\EE\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 15:44 249856 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 15:44 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
2005-05-04 00:38 64512 ----a-w- c:\windows\system32\P17.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 02:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2010-02-11 04:32 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 16:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2009-06-10 08:55 1326080 ----a-w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 06:00 90112 ------w- c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=2 (0x2)
"usnjsvc"=3 (0x3)
"WUSB54GCSVC"=3 (0x3)
"wlidsvc"=2 (0x2)
"Roxio Upnp Server 9"=3 (0x3)
"Roxio UPnP Renderer 9"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"idsvc"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"DSBrokerService"=3 (0x3)
"Creative Service for CDROM Access"=3 (0x3)
"BcmSqlStartupSvc"=2 (0x2)
"AOL ACS"=3 (0x3)
"AcrSch2Svc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1130467576\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\AOL\\1130467576\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1130467576\\EE\\aim6.exe"=
"c:\\WINDOWS\\kdx\\khost.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Terminal Reality\\4x4 Evo2\\4x42.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\thrones.exe"=
"c:\\Program Files\\Motorola\\RSD Lite\\SDL.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Live for Speed S2\\LFS.exe"=
"c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"= c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:192.168.1.1/255.255.255.255:Disabled:Adobe CSI CS4
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"f:\\Program Files\\NovaLogic\\Delta Force Black Hawk Down\\UPDATE.EXE"=
"c:\\Program Files\\AOL 9.6\\waol.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"3689:TCP"= 3689:TCP:iPhone 3G Remote
"5353:TCP"= 5353:TCP:iPhone 3G Remote
"8889:TCP"= 8889:TCP:iPhone
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [12/6/2005 10:11 AM 35328]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/21/2007 8:45 PM 682232]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [12/18/2009 10:58 AM 11336]
S3 cpuz126;cpuz126;\??\c:\docume~1\Graham\LOCALS~1\Temp\cpuz.sys --> c:\docume~1\Graham\LOCALS~1\Temp\cpuz.sys [?]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [10/19/2006 10:45 AM 10664]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [4/12/2010 12:13 AM 38224]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Graham\Desktop\Alureon.G\SysProt\SysProtDrv.sys [4/10/2010 6:27 PM 44288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
2010-04-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]
2007-04-05 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2006-11-22 01:09]
2010-04-30 c:\windows\Tasks\{5A946781-7F50-46F7-B9B9-3B43599481E3}_XPS400_Graham.job
- c:\windows\system32\mobsync.exe [2004-08-19 00:12]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://www.dell4me.com/myway
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 64.34.161.90:80
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites -
http://favorites.liv...m/quickadd.aspxIE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Save with Download Manager... - c:\program files\J River\Media Jukebox\DMDownload.htm
Trusted Zone: musicmatch.com\online
TCP: {2F69DF63-90DE-4818-A569-A6BCFA5464FD} = 24.177.176.38,24.197.160.18
FF - ProfilePath - c:\documents and settings\Graham\Application Data\Mozilla\Firefox\Profiles\nw5edqef.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - prefs.js: network.proxy.ftp - 64.90.179.108
FF - prefs.js: network.proxy.gopher - 64.90.179.108
FF - prefs.js: network.proxy.socks - 64.90.179.108
FF - prefs.js: network.proxy.ssl - 64.90.179.108
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Graham\Application Data\Mozilla\Firefox\Profiles\nw5edqef.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\Graham\Application Data\Mozilla\Firefox\Profiles\nw5edqef.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: c:\documents and settings\Graham\Application Data\Mozilla\Firefox\Profiles\nw5edqef.default\extensions\
[email protected]\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
FF - plugin: c:\documents and settings\Graham\Application Data\Mozilla\Firefox\Profiles\nw5edqef.default\extensions\
[email protected]\plugins\npCoralIETab.dll
FF - plugin: c:\documents and settings\Graham\Application Data\Mozilla\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-855771979-2752217130-3050068086-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1236)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(1292)
c:\windows\system32\relog_ap.dll
.
Completion time: 2010-05-01 13:14:14
ComboFix-quarantined-files.txt 2010-05-01 18:14
ComboFix2.txt 2010-04-02 11:36
ComboFix3.txt 2010-04-01 22:07
Pre-Run: 11,234,562,048 bytes free
Post-Run: 11,481,518,080 bytes free
- - End Of File - - B68DB688B07002175661E4F693EC9814
+++++++++++++++++++++++++++
+ File Lister Version 1.1.4 +
+ +
+ By bamajim / SpywareHammer.com +
+++++++++++++++++++++++++++
Report ran on --->>> 5/1/2010 1:21:10 PM
====== Running Processes ======
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\ctfmon.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Internet Explorer\iexplore.exe
====== BHO's ======
BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}\ - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
BHO: (NO NAME) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: (NO NAME) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
====== System Keys (some whitelisted items will not be shown)======
Winlogon\Userinit = C:\WINDOWS\system32\userinit.exe,
Winlogon\Shell = Explorer.exe
====== HKLM\~\Run Keys ======
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[iTunesHelper] = "C:\Program Files\iTunes\iTunesHelper.exe"
[XboxStat] = "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
[MSSE] = "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
[IntelliPoint] = "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
[IAAnotif] = C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
[ATIPTA] = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
[P17Helper] = Rundll32 P17.dll,P17Helper
====== HKCU\~\Run Keys ======
[PeerBlock] = C:\Program Files\PeerBlock\peerblock.exe
====== DNS Info (List may be empty) ======
HKEY_LOCAL_MACHINE\CCS\~\{2F69DF63-90DE-4818-A569-A6BCFA5464FD}\ NameServer= 24.177.176.38,24.197.160.18
NV Hostname = XPS400
DataBasePath = %SystemRoot%\System32\drivers\etc
ForwardBroadcasts = 0
IPEnableRouter = 0
Hostname = XPS400
UseDomainNameDevolution = 1
DeadGWDetectDefault = 1
DontAddDefaultGatewayDefault = 0
TcpMaxDataRetransmissions = 5
====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======
4/1/2010 4:44:49 PM 8140197 C:\cmdcons
4/1/2010 4:44:55 PM 860672 C:\cmdcons\SYSTEM32
5/1/2010 12:58:45 PM 467056 C:\ComboFix
4/13/2010 5:49:14 PM 43835625 C:\Python27
4/13/2010 5:49:33 PM 6161564 C:\Python27\DLLs
4/13/2010 5:49:43 PM 5661447 C:\Python27\Doc
4/13/2010 5:49:34 PM 447234 C:\Python27\include
4/13/2010 5:49:15 PM 22637232 C:\Python27\Lib
4/13/2010 5:49:33 PM 317852 C:\Python27\Lib\bsddb
4/13/2010 5:49:33 PM 234082 C:\Python27\Lib\bsddb\test
4/13/2010 5:49:33 PM 193782 C:\Python27\Lib\compiler
4/13/2010 5:49:32 PM 255862 C:\Python27\Lib\ctypes
4/13/2010 5:49:33 PM 10478 C:\Python27\Lib\ctypes\macholib
4/13/2010 5:49:32 PM 210530 C:\Python27\Lib\ctypes\test
4/13/2010 5:49:32 PM 19843 C:\Python27\Lib\curses
4/13/2010 5:49:31 PM 1445648 C:\Python27\Lib\distutils
4/13/2010 5:49:31 PM 866932 C:\Python27\Lib\distutils\command
4/13/2010 5:49:31 PM 173015 C:\Python27\Lib\distutils\tests
4/13/2010 5:49:30 PM 516515 C:\Python27\Lib\email
4/13/2010 5:49:31 PM 11365 C:\Python27\Lib\email\mime
4/13/2010 5:49:30 PM 344632 C:\Python27\Lib\email\test
4/13/2010 5:49:30 PM 86861 C:\Python27\Lib\email\test\data
4/13/2010 5:49:29 PM 1338389 C:\Python27\Lib\encodings
4/13/2010 5:49:29 PM 12550 C:\Python27\Lib\hotshot
4/13/2010 5:49:29 PM 716375 C:\Python27\Lib\idlelib
4/13/2010 5:49:29 PM 58065 C:\Python27\Lib\idlelib\Icons
4/13/2010 5:49:29 PM 1365 C:\Python27\Lib\importlib
4/13/2010 5:49:28 PM 70678 C:\Python27\Lib\json
4/13/2010 5:49:29 PM 24918 C:\Python27\Lib\json\tests
4/13/2010 5:49:28 PM 582895 C:\Python27\Lib\lib-tk
4/13/2010 5:49:28 PM 75056 C:\Python27\Lib\lib-tk\test
4/13/2010 5:49:28 PM 2675 C:\Python27\Lib\lib-tk\test\test_tkinter
4/13/2010 5:49:28 PM 70020 C:\Python27\Lib\lib-tk\test\test_ttk
4/13/2010 5:49:27 PM 603493 C:\Python27\Lib\lib2to3
4/13/2010 5:49:28 PM 101439 C:\Python27\Lib\lib2to3\fixes
4/13/2010 5:49:28 PM 65475 C:\Python27\Lib\lib2to3\pgen2
4/13/2010 5:49:27 PM 339554 C:\Python27\Lib\lib2to3\tests
4/13/2010 5:49:27 PM 160383 C:\Python27\Lib\lib2to3\tests\data
4/13/2010 5:49:28 PM 1079 C:\Python27\Lib\lib2to3\tests\data\fixers
4/13/2010 5:49:28 PM 884 C:\Python27\Lib\lib2to3\tests\data\fixers\myfixes
4/13/2010 5:49:27 PM 140597 C:\Python27\Lib\logging
4/13/2010 5:49:27 PM 115981 C:\Python27\Lib\msilib
4/13/2010 5:49:27 PM 152617 C:\Python27\Lib\multiprocessing
4/13/2010 5:49:27 PM 4508 C:\Python27\Lib\multiprocessing\dummy
4/13/2010 5:49:27 PM 424010 C:\Python27\Lib\pydoc_data
4/13/2010 5:49:27 PM 121 C:\Python27\Lib\site-packages
4/13/2010 5:49:27 PM 103041 C:\Python27\Lib\sqlite3
4/13/2010 5:49:27 PM 96864 C:\Python27\Lib\sqlite3\test
4/13/2010 5:49:18 PM 11117422 C:\Python27\Lib\test
4/13/2010 5:49:27 PM 7774 C:\Python27\Lib\test\crashers
4/13/2010 5:49:25 PM 4445817 C:\Python27\Lib\test\decimaltestdata
4/13/2010 5:49:25 PM 2140 C:\Python27\Lib\test\leakers
4/13/2010 5:49:25 PM 3267 C:\Python27\Lib\test\xmltestdata
4/13/2010 5:49:18 PM 274120 C:\Python27\Lib\unittest
4/13/2010 5:49:18 PM 182602 C:\Python27\Lib\unittest\test
4/13/2010 5:49:18 PM 48671 C:\Python27\Lib\wsgiref
4/13/2010 5:49:18 PM 278610 C:\Python27\Lib\xml
4/13/2010 5:49:18 PM 142414 C:\Python27\Lib\xml\dom
4/13/2010 5:49:18 PM 74224 C:\Python27\Lib\xml\etree
4/13/2010 5:49:18 PM 293 C:\Python27\Lib\xml\parsers
4/13/2010 5:49:18 PM 60658 C:\Python27\Lib\xml\sax
4/13/2010 5:49:35 PM 1097890 C:\Python27\libs
4/13/2010 5:49:35 PM 6846173 C:\Python27\tcl
4/13/2010 5:49:43 PM 19278 C:\Python27\tcl\dde1.3
4/13/2010 5:49:42 PM 18814 C:\Python27\tcl\reg1.2
4/13/2010 5:49:42 PM 165466 C:\Python27\tcl\tcl8
4/13/2010 5:49:42 PM 52156 C:\Python27\tcl\tcl8\8.4
4/13/2010 5:49:42 PM 5838 C:\Python27\tcl\tcl8\8.4\platform
4/13/2010 5:49:42 PM 113310 C:\Python27\tcl\tcl8\8.5
4/13/2010 5:49:38 PM 3278068 C:\Python27\tcl\tcl8.5
4/13/2010 5:49:42 PM 1413736 C:\Python27\tcl\tcl8.5\encoding
4/13/2010 5:49:42 PM 10494 C:\Python27\tcl\tcl8.5\http1.0
4/13/2010 5:49:41 PM 112332 C:\Python27\tcl\tcl8.5\msgs
4/13/2010 5:49:41 PM 33620 C:\Python27\tcl\tcl8.5\opt0.4
4/13/2010 5:49:38 PM 1451874 C:\Python27\tcl\tcl8.5\tzdata
4/13/2010 5:49:41 PM 41089 C:\Python27\tcl\tcl8.5\tzdata\Africa
4/13/2010 5:49:40 PM 645699 C:\Python27\tcl\tcl8.5\tzdata\America
4/13/2010 5:49:41 PM 77165 C:\Python27\tcl\tcl8.5\tzdata\America\Argentina
4/13/2010 5:49:41 PM 57371 C:\Python27\tcl\tcl8.5\tzdata\America\Indiana
4/13/2010 5:49:41 PM 17611 C:\Python27\tcl\tcl8.5\tzdata\America\Kentucky
4/13/2010 5:49:41 PM 16559 C:\Python27\tcl\tcl8.5\tzdata\America\North_Dakota
4/13/2010 5:49:40 PM 16607 C:\Python27\tcl\tcl8.5\tzdata\Antarctica
4/13/2010 5:49:40 PM 176 C:\Python27\tcl\tcl8.5\tzdata\Arctic
4/13/2010 5:49:39 PM 181163 C:\Python27\tcl\tcl8.5\tzdata\Asia
4/13/2010 5:49:39 PM 51011 C:\Python27\tcl\tcl8.5\tzdata\Atlantic
4/13/2010 5:49:39 PM 59789 C:\Python27\tcl\tcl8.5\tzdata\Australia
4/13/2010 5:49:39 PM 737 C:\Python27\tcl\tcl8.5\tzdata\Brazil
4/13/2010 5:49:39 PM 1685 C:\Python27\tcl\tcl8.5\tzdata\Canada
4/13/2010 5:49:39 PM 373 C:\Python27\tcl\tcl8.5\tzdata\Chile
4/13/2010 5:49:39 PM 4207 C:\Python27\tcl\tcl8.5\tzdata\Etc
4/13/2010 5:49:38 PM 341361 C:\Python27\tcl\tcl8.5\tzdata\Europe
4/13/2010 5:49:38 PM 1722 C:\Python27\tcl\tcl8.5\tzdata\Indian
4/13/2010 5:49:38 PM 566 C:\Python27\tcl\tcl8.5\tzdata\Mexico
4/13/2010 5:49:38 PM 33436 C:\Python27\tcl\tcl8.5\tzdata\Pacific
4/13/2010 5:49:38 PM 2459 C:\Python27\tcl\tcl8.5\tzdata\SystemV
4/13/2010 5:49:38 PM 2426 C:\Python27\tcl\tcl8.5\tzdata\US
4/13/2010 5:49:36 PM 1264677 C:\Python27\tcl\tix8.4.3
4/13/2010 5:49:37 PM 18303 C:\Python27\tcl\tix8.4.3\bitmaps
4/13/2010 5:49:36 PM 246247 C:\Python27\tcl\tix8.4.3\demos
4/13/2010 5:49:37 PM 38718 C:\Python27\tcl\tix8.4.3\demos\bitmaps
4/13/2010 5:49:36 PM 157421 C:\Python27\tcl\tix8.4.3\demos\samples
4/13/2010 5:49:36 PM 230453 C:\Python27\tcl\tix8.4.3\pref
4/13/2010 5:49:35 PM 1399693 C:\Python27\tcl\tk8.5
4/13/2010 5:49:35 PM 684237 C:\Python27\tcl\tk8.5\demos
4/13/2010 5:49:36 PM 277824 C:\Python27\tcl\tk8.5\demos\images
4/13/2010 5:49:35 PM 97217 C:\Python27\tcl\tk8.5\images
4/13/2010 5:49:35 PM 69298 C:\Python27\tcl\tk8.5\msgs
4/13/2010 5:49:35 PM 99406 C:\Python27\tcl\tk8.5\ttk
4/13/2010 5:49:43 PM 563409 C:\Python27\Tools
4/13/2010 5:49:43 PM 30557 C:\Python27\Tools\i18n
4/13/2010 5:49:43 PM 134262 C:\Python27\Tools\pynche
4/13/2010 5:49:43 PM 19509 C:\Python27\Tools\pynche\X
4/13/2010 5:49:43 PM 320587 C:\Python27\Tools\Scripts
4/13/2010 5:49:43 PM 8249 C:\Python27\Tools\versioncheck
4/13/2010 5:49:43 PM 69754 C:\Python27\Tools\webchecker
4/13/2010 5:52:36 PM 39588252 C:\Python31
4/13/2010 5:52:49 PM 5009564 C:\Python31\DLLs
4/13/2010 5:52:58 PM 5108933 C:\Python31\Doc
4/13/2010 5:52:50 PM 423256 C:\Python31\include
4/13/2010 5:52:36 PM 20324499 C:\Python31\Lib
4/13/2010 5:52:49 PM 254297 C:\Python31\Lib\ctypes
4/13/2010 5:52:49 PM 9385 C:\Python31\Lib\ctypes\macholib
4/13/2010 5:52:49 PM 211110 C:\Python31\Lib\ctypes\test
4/13/2010 5:52:49 PM 19852 C:\Python31\Lib\curses
4/13/2010 5:52:49 PM 16177 C:\Python31\Lib\dbm
4/13/2010 5:52:47 PM 1467149 C:\Python31\Lib\distutils
4/13/2010 5:52:48 PM 867895 C:\Python31\Lib\distutils\command
4/13/2010 5:52:48 PM 162297 C:\Python31\Lib\distutils\tests
4/13/2010 5:52:47 PM 391105 C:\Python31\Lib\email
4/13/2010 5:52:47 PM 11356 C:\Python31\Lib\email\mime
4/13/2010 5:52:47 PM 222088 C:\Python31\Lib\email\test
4/13/2010 5:52:47 PM 86564 C:\Python31\Lib\email\test\data
4/13/2010 5:52:46 PM 1290187 C:\Python31\Lib\encodings
4/13/2010 5:52:46 PM 32089 C:\Python31\Lib\html
4/13/2010 5:52:46 PM 183874 C:\Python31\Lib\http
4/13/2010 5:52:45 PM 715752 C:\Python31\Lib\idlelib
4/13/2010 5:52:45 PM 58065 C:\Python31\Lib\idlelib\Icons
4/13/2010 5:52:45 PM 147214 C:\Python31\Lib\importlib
4/13/2010 5:52:45 PM 108434 C:\Python31\Lib\importlib\test
4/13/2010 5:52:45 PM 5059 C:\Python31\Lib\importlib\test\builtin
4/13/2010 5:52:45 PM 5591 C:\Python31\Lib\importlib\test\extension
4/13/2010 5:52:45 PM 5200 C:\Python31\Lib\importlib\test\frozen
4/13/2010 5:52:45 PM 31461 C:\Python31\Lib\importlib\test\import_
4/13/2010 5:52:45 PM 42158 C:\Python31\Lib\importlib\test\source
4/13/2010 5:52:45 PM 66184 C:\Python31\Lib\json
4/13/2010 5:52:45 PM 23562 C:\Python31\Lib\json\tests
4/13/2010 5:52:44 PM 598209 C:\Python31\Lib\lib2to3
4/13/2010 5:52:44 PM 98684 C:\Python31\Lib\lib2to3\fixes
4/13/2010 5:52:44 PM 65530 C:\Python31\Lib\lib2to3\pgen2
4/13/2010 5:52:44 PM 337077 C:\Python31\Lib\lib2to3\tests
4/13/2010 5:52:44 PM 160383 C:\Python31\Lib\lib2to3\tests\data
4/13/2010 5:52:44 PM 1079 C:\Python31\Lib\lib2to3\tests\data\fixers
4/13/2010 5:52:44 PM 884 C:\Python31\Lib\lib2to3\tests\data\fixers\myfixes
4/13/2010 5:52:44 PM 115875 C:\Python31\Lib\logging
4/13/2010 5:52:44 PM 113413 C:\Python31\Lib\msilib
4/13/2010 5:52:44 PM 149766 C:\Python31\Lib\multiprocessing
4/13/2010 5:52:44 PM 4630 C:\Python31\Lib\multiprocessing\dummy
4/13/2010 5:52:44 PM 380582 C:\Python31\Lib\pydoc_data
4/13/2010 5:52:44 PM 121 C:\Python31\Lib\site-packages
4/13/2010 5:52:43 PM 94453 C:\Python31\Lib\sqlite3
4/13/2010 5:52:43 PM 88259 C:\Python31\Lib\sqlite3\test
4/13/2010 5:52:38 PM 10240950 C:\Python31\Lib\test
4/13/2010 5:52:43 PM 7786 C:\Python31\Lib\test\crashers
4/13/2010 5:52:42 PM 4445817 C:\Python31\Lib\test\decimaltestdata
4/13/2010 5:52:42 PM 2140 C:\Python31\Lib\test\leakers
4/13/2010 5:52:38 PM 430764 C:\Python31\Lib\tkinter
4/13/2010 5:52:38 PM 74954 C:\Python31\Lib\tkinter\test
4/13/2010 5:52:38 PM 2684 C:\Python31\Lib\tkinter\test\test_tkinter
4/13/2010 5:52:38 PM 68952 C:\Python31\Lib\tkinter\test\test_ttk
4/13/2010 5:52:38 PM 125521 C:\Python31\Lib\urllib
4/13/2010 5:52:38 PM 50622 C:\Python31\Lib\wsgiref
4/13/2010 5:52:38 PM 259043 C:\Python31\Lib\xml
4/13/2010 5:52:38 PM 142576 C:\Python31\Lib\xml\dom
4/13/2010 5:52:38 PM 54691 C:\Python31\Lib\xml\etree
4/13/2010 5:52:38 PM 293 C:\Python31\Lib\xml\parsers
4/13/2010 5:52:38 PM 60462 C:\Python31\Lib\xml\sax
4/13/2010 5:52:38 PM 75966 C:\Python31\Lib\xmlrpc
4/13/2010 5:52:50 PM 1094670 C:\Python31\libs
4/13/2010 5:52:50 PM 6846173 C:\Python31\tcl
4/13/2010 5:52:57 PM 19278 C:\Python31\tcl\dde1.3
4/13/2010 5:52:56 PM 18814 C:\Python31\tcl\reg1.2
4/13/2010 5:52:56 PM 165466 C:\Python31\tcl\tcl8
4/13/2010 5:52:56 PM 52156 C:\Python31\tcl\tcl8\8.4
4/13/2010 5:52:56 PM 5838 C:\Python31\tcl\tcl8\8.4\platform
4/13/2010 5:52:56 PM 113310 C:\Python31\tcl\tcl8\8.5
4/13/2010 5:52:52 PM 3278068 C:\Python31\tcl\tcl8.5
4/13/2010 5:52:56 PM 1413736 C:\Python31\tcl\tcl8.5\encoding
4/13/2010 5:52:56 PM 10494 C:\Python31\tcl\tcl8.5\http1.0
4/13/2010 5:52:55 PM 112332 C:\Python31\tcl\tcl8.5\msgs
4/13/2010 5:52:55 PM 33620 C:\Python31\tcl\tcl8.5\opt0.4
4/13/2010 5:52:52 PM 1451874 C:\Python31\tcl\tcl8.5\tzdata
4/13/2010 5:52:55 PM 41089 C:\Python31\tcl\tcl8.5\tzdata\Africa
4/13/2010 5:52:54 PM 645699 C:\Python31\tcl\tcl8.5\tzdata\America
4/13/2010 5:52:55 PM 77165 C:\Python31\tcl\tcl8.5\tzdata\America\Argentina
4/13/2010 5:52:55 PM 57371 C:\Python31\tcl\tcl8.5\tzdata\America\Indiana
4/13/2010 5:52:55 PM 17611 C:\Python31\tcl\tcl8.5\tzdata\America\Kentucky
4/13/2010 5:52:55 PM 16559 C:\Python31\tcl\tcl8.5\tzdata\America\North_Dakota
4/13/2010 5:52:54 PM 16607 C:\Python31\tcl\tcl8.5\tzdata\Antarctica
4/13/2010 5:52:54 PM 176 C:\Python31\tcl\tcl8.5\tzdata\Arctic
4/13/2010 5:52:54 PM 181163 C:\Python31\tcl\tcl8.5\tzdata\Asia
4/13/2010 5:52:54 PM 51011 C:\Python31\tcl\tcl8.5\tzdata\Atlantic
4/13/2010 5:52:54 PM 59789 C:\Python31\tcl\tcl8.5\tzdata\Australia
4/13/2010 5:52:53 PM 737 C:\Python31\tcl\tcl8.5\tzdata\Brazil
4/13/2010 5:52:53 PM 1685 C:\Python31\tcl\tcl8.5\tzdata\Canada
4/13/2010 5:52:53 PM 373 C:\Python31\tcl\tcl8.5\tzdata\Chile
4/13/2010 5:52:53 PM 4207 C:\Python31\tcl\tcl8.5\tzdata\Etc
4/13/2010 5:52:53 PM 341361 C:\Python31\tcl\tcl8.5\tzdata\Europe
4/13/2010 5:52:53 PM 1722 C:\Python31\tcl\tcl8.5\tzdata\Indian
4/13/2010 5:52:53 PM 566 C:\Python31\tcl\tcl8.5\tzdata\Mexico
4/13/2010 5:52:53 PM 33436 C:\Python31\tcl\tcl8.5\tzdata\Pacific
4/13/2010 5:52:53 PM 2459 C:\Python31\tcl\tcl8.5\tzdata\SystemV
4/13/2010 5:52:53 PM 2426 C:\Python31\tcl\tcl8.5\tzdata\US
4/13/2010 5:52:51 PM 1264677 C:\Python31\tcl\tix8.4.3
4/13/2010 5:52:52 PM 18303 C:\Python31\tcl\tix8.4.3\bitmaps
4/13/2010 5:52:52 PM 246247 C:\Python31\tcl\tix8.4.3\demos
4/13/2010 5:52:52 PM 38718 C:\Python31\tcl\tix8.4.3\demos\bitmaps
4/13/2010 5:52:52 PM 157421 C:\Python31\tcl\tix8.4.3\demos\samples
4/13/2010 5:52:52 PM 230453 C:\Python31\tcl\tix8.4.3\pref
4/13/2010 5:52:50 PM 1399693 C:\Python31\tcl\tk8.5
4/13/2010 5:52:51 PM 684237 C:\Python31\tcl\tk8.5\demos
4/13/2010 5:52:51 PM 277824 C:\Python31\tcl\tk8.5\demos\images
4/13/2010 5:52:51 PM 97217 C:\Python31\tcl\tk8.5\images
4/13/2010 5:52:50 PM 69298 C:\Python31\tcl\tk8.5\msgs
4/13/2010 5:52:50 PM 99406 C:\Python31\tcl\tk8.5\ttk
4/13/2010 5:52:57 PM 554799 C:\Python31\Tools
4/13/2010 5:52:57 PM 30554 C:\Python31\Tools\i18n
4/13/2010 5:52:57 PM 134156 C:\Python31\Tools\pynche
4/13/2010 5:52:57 PM 19509 C:\Python31\Tools\pynche\X
4/13/2010 5:52:57 PM 312005 C:\Python31\Tools\Scripts
4/13/2010 5:52:58 PM 8264 C:\Python31\Tools\versioncheck
4/13/2010 5:52:58 PM 69820 C:\Python31\Tools\webchecker
4/1/2010 4:37:31 PM 15806402 C:\Qoobox
5/1/2010 1:01:24 PM 12483 C:\Qoobox\BackEnv
4/1/2010 4:37:31 PM 13992846 C:\Qoobox\Quarantine
4/1/2010 4:48:51 PM 13909425 C:\Qoobox\Quarantine\C
4/1/2010 4:55:36 PM 1037 C:\Qoobox\Quarantine\C\Documents and Settings
4/1/2010 4:55:36 PM 1037 C:\Qoobox\Quarantine\C\Documents and Settings\Graham
4/1/2010 4:55:36 PM 1037 C:\Qoobox\Quarantine\C\Documents and Settings\Graham\Start Menu
4/1/2010 4:55:36 PM 1037 C:\Qoobox\Quarantine\C\Documents and Settings\Graham\Start Menu\Programs
4/1/2010 4:55:36 PM 1037 C:\Qoobox\Quarantine\C\Documents and Settings\Graham\Start Menu\Programs\AVI Codec Pack +
4/1/2010 4:55:36 PM 4138279 C:\Qoobox\Quarantine\C\Program Files
4/1/2010 4:55:36 PM 4138279 C:\Qoobox\Quarantine\C\Program Files\AVI Codec Pack
4/1/2010 4:55:36 PM 1667153 C:\Qoobox\Quarantine\C\Program Files\AVI Codec Pack\DivX 3.11
4/1/2010 4:55:38 PM 1916963 C:\Qoobox\Quarantine\C\Program Files\AVI Codec Pack\ffdhow
4/1/2010 4:55:39 PM 321536 C:\Qoobox\Quarantine\C\Program Files\AVI Codec Pack\LAYER-3
4/1/2010 4:55:40 PM 9770109 C:\Qoobox\Quarantine\C\WINDOWS
4/2/2010 6:25:14 AM 39424 C:\Qoobox\Quarantine\C\WINDOWS\AppPatch
4/1/2010 4:55:40 PM 241 C:\Qoobox\Quarantine\C\WINDOWS\Downloaded Program Files
4/1/2010 4:55:40 PM 9374092 C:\Qoobox\Quarantine\C\WINDOWS\system32
4/2/2010 6:25:14 AM 123136 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers
4/1/2010 4:37:31 PM 18780 C:\Qoobox\Quarantine\Registry_backups
4/1/2010 4:25:40 PM 67243663 C:\_OTL
4/1/2010 4:25:40 PM 67243663 C:\_OTL\MovedFiles
4/1/2010 4:25:40 PM 17337614 C:\_OTL\MovedFiles\04012010_162540
4/1/2010 4:25:43 PM 0 C:\_OTL\MovedFiles\04012010_162540\C_Documents and Settings
4/1/2010 4:25:43 PM 0 C:\_OTL\MovedFiles\04012010_162540\C_Documents and Settings\Graham
4/1/2010 4:25:43 PM 0 C:\_OTL\MovedFiles\04012010_162540\C_Documents and Settings\Graham\Application Data
4/1/2010 4:25:43 PM 0 4/1/2010 4:45:00 PM 209 32 C:\Boot.bak
4/1/2010 4:44:55 PM 260272 32 C:\cmldr
5/1/2010 1:14:15 PM 38230 32 C:\ComboFix.txt
4/30/2010 6:53:18 PM 3756167168 38 C:\hiberfil.sys
4/2/2010 6:37:47 AM 34526 32 C:\TDSSKiller.2.2.8.1_02.04.2010_06.37.47_log.txt
4/12/2010 8:31:44 PM 1218 32 C:\VEW.txt
4/1/2010 4:43:06 PM 196633830 C:\WINDOWS\ERDNT
4/1/2010 5:05:47 PM 21430768 C:\WINDOWS\ERDNT\cache
4/1/2010 4:43:06 PM 88087876 C:\WINDOWS\ERDNT\Hiv-backup
5/1/2010 1:01:21 PM 17379328 C:\WINDOWS\ERDNT\Hiv-backup\Users
5/1/2010 1:01:21 PM 241664 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000001
5/1/2010 1:01:21 PM 8192 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000002
5/1/2010 1:01:21 PM 237568 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000003
5/1/2010 1:01:21 PM 8192 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000004
5/1/2010 1:01:21 PM 16560128 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000005
5/1/2010 1:01:21 PM 323584 C:\WINDOWS\ERDNT\Hiv-backup\Users\00000006
4/2/2010 6:25:38 AM 87115076 C:\WINDOWS\ERDNT\subs
4/2/2010 6:25:41 AM 16392192 C:\WINDOWS\ERDNT\subs\Users
4/2/2010 6:25:41 AM 241664 C:\WINDOWS\ERDNT\subs\Users\00000001
4/2/2010 6:25:41 AM 8192 C:\WINDOWS\ERDNT\subs\Users\00000002
4/2/2010 6:25:41 AM 237568 C:\WINDOWS\ERDNT\subs\Users\00000003
4/2/2010 6:25:41 AM 8192 C:\WINDOWS\ERDNT\subs\Users\00000004
4/2/2010 6:25:41 AM 15572992 C:\WINDOWS\ERDNT\subs\Users\00000005
4/2/2010 6:25:42 AM 323584 C:\WINDOWS\ERDNT\subs\Users\00000006
4/2/2010 6:25:32 AM 32768 C:\WINDOWS\temp
5/1/2010 12:35:43 PM 0 32 C:\WINDOWS\0.log
4/18/2010 12:54:00 PM 545 32 C:\WINDOWS\ARJ.PIF
4/1/2010 4:43:31 PM 80412 32 C:\WINDOWS\grep.exe
4/18/2010 12:54:00 PM 545 32 C:\WINDOWS\LHA.PIF
4/1/2010 4:43:32 PM 77312 32 C:\WINDOWS\MBR.exe
4/1/2010 4:43:31 PM 31232 32 C:\WINDOWS\NIRCMD.exe
4/18/2010 12:54:00 PM 545 32 C:\WINDOWS\NOCLOSE.PIF
5/1/2010 1:00:58 PM 256512 32 C:\WINDOWS\PEV.exe
3/30/2010 9:51:31 PM 1091826 32 C:\WINDOWS\pfirewall.log
3/30/2010 9:51:31 PM 4194840 32 C:\WINDOWS\pfirewall.log.old
4/18/2010 12:54:00 PM 545 32 C:\WINDOWS\PKUNZIP.PIF
4/18/2010 12:54:00 PM 545 32 C:\WINDOWS\PKZIP.PIF
4/18/2010 12:54:00 PM 545 32 C:\WINDOWS\RAR.PIF
3/30/2010 9:51:05 PM 32048 32 C:\WINDOWS\SchedLgU.Txt
4/1/2010 4:43:31 PM 98816 32 C:\WINDOWS\sed.exe
4/30/2010 10:33:14 PM 6095 32 C:\WINDOWS\setupapi.log
4/24/2010 12:25:00 PM 0 0 C:\WINDOWS\Sti_Trace.log
4/1/2010 4:43:31 PM 161792 32 C:\WINDOWS\SWREG.exe
4/1/2010 4:43:31 PM 136704 32 C:\WINDOWS\SWSC.exe
4/1/2010 4:43:30 PM 212480 32 C:\WINDOWS\SWXCACLS.exe
4/18/2010 12:54:00 PM 545 32 C:\WINDOWS\UC.PIF
4/24/2010 12:25:01 PM 216 32 C:\WINDOWS\wiadebug.log
4/24/2010 12:25:00 PM 48 32 C:\WINDOWS\wiaservc.log
3/30/2010 9:50:01 PM 1461695 32 C:\WINDOWS\WindowsUpdate.log
4/1/2010 4:43:31 PM 68096 32 C:\WINDOWS\zip.exe
4/30/2010 6:37:09 PM 626688 32 C:\WINDOWS\system32\ati2cqag.dll
4/30/2010 6:37:19 PM 325120 32 C:\WINDOWS\system32\ati2dvag.dll
4/30/2010 6:37:14 PM 43520 32 C:\WINDOWS\system32\ati2edxx.dll
4/30/2010 6:37:12 PM 155648 32 C:\WINDOWS\system32\ati2evxx.dll
4/30/2010 6:37:11 PM 602112 32 C:\WINDOWS\system32\ati2evxx.exe
4/30/2010 6:37:10 PM 26112 32 C:\WINDOWS\system32\Ati2mdxx.exe
4/30/2010 6:37:10 PM 3818144 32 C:\WINDOWS\system32\ati3duag.dll
4/30/2010 6:37:11 PM 53248 32 C:\WINDOWS\system32\ATIDDC.DLL
4/30/2010 6:37:15 PM 303104 32 C:\WINDOWS\system32\ATIDEMGR.dll
4/30/2010 6:37:15 PM 7167 32 C:\WINDOWS\system32\atifglpf.xml
4/30/2010 6:37:11 PM 189051 32 C:\WINDOWS\system32\atiicdxx.dat
4/30/2010 6:37:19 PM 307200 32 C:\WINDOWS\system32\atiiiexx.dll
4/30/2010 6:37:15 PM 475136 32 C:\WINDOWS\system32\atikvmag.dll
4/30/2010 6:37:15 PM 6684672 32 C:\WINDOWS\system32\atioglx1.dll
4/30/2010 6:37:15 PM 11845632 32 C:\WINDOWS\system32\atioglxx.dll
4/30/2010 6:37:14 PM 204800 32 C:\WINDOWS\system32\atipdlxx.dll
4/30/2010 6:37:11 PM 17408 32 C:\WINDOWS\system32\atitvo32.dll
4/30/2010 6:37:10 PM 2670592 32 C:\WINDOWS\system32\ativvaxx.dll
3/2/2010 1:16:04 PM 353592 32 C:\WINDOWS\system32\DivXControlPanelApplet.cpl
4/8/2010 1:20:02 PM 107808 32 C:\WINDOWS\system32\dns-sd.exe
4/8/2010 1:20:02 PM 91424 32 C:\WINDOWS\system32\dnssd.dll
3/8/2010 12:59:18 PM 94208 32 C:\WINDOWS\system32\dpl100.dll
3/30/2010 10:00:09 PM 145184 32 C:\WINDOWS\system32\java.exe
3/30/2010 10:00:09 PM 73728 32 C:\WINDOWS\system32\javacpl.cpl
3/30/2010 10:00:09 PM 145184 32 C:\WINDOWS\system32\javaw.exe
3/30/2010 10:00:09 PM 153376 32 C:\WINDOWS\system32\javaws.exe
4/30/2010 6:37:14 PM 155648 32 C:\WINDOWS\system32\Oemdspif.dll
4/12/2010 1:26:02 PM 237320 32 C:\WINDOWS\system32\PDBoot.exe
4/10/2010 10:44:10 PM 2291200 32 C:\WINDOWS\system32\python27.dll
3/21/2010 12:43:00 AM 2137600 32 C:\WINDOWS\system32\python31.dll
3/17/2010 9:53:42 PM 69632 32 C:\WINDOWS\system32\QuickTime.qts
3/17/2010 9:53:42 PM 94208 32 C:\WINDOWS\system32\QuickTimeVR.qtx
3/30/2010 6:30:06 PM 33846 32 C:\WINDOWS\system32\SpoonUninstall-dBpoweramp DSP Effects.bmp
3/30/2010 6:30:06 PM 11024 32 C:\WINDOWS\system32\SpoonUninstall-dBpoweramp DSP Effects.dat
3/30/2010 6:29:59 PM 33846 32 C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.bmp
3/30/2010 6:29:59 PM 15607 32 C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
4/18/2010 12:46:48 PM 22360 32 C:\WINDOWS\system32\X3DAudio1_7.dll
4/18/2010 12:46:48 PM 238936 32 C:\WINDOWS\system32\xactengine3_6.dll
4/18/2010 12:46:49 PM 74072 32 C:\WINDOWS\system32\XAPOFX1_4.dll
4/18/2010 12:46:49 PM 528216 32 C:\WINDOWS\system32\XAudio2_6.dll
====== "\Administrator & All Users\Startup" Last 60 Days======
4/28/2010 4:54:49 PM 1741 32 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Auto Detect.lnk
4/28/2010 4:54:49 PM 493 32 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
4/28/2010 4:54:49 PM 1787 32 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
====== "\Program Files" Last 60 Days======
4/28/2010 1:04:42 AM 1111409 C:\Program Files\BitTorrent
4/27/2010 8:58:30 PM 599827 C:\Program Files\Bonjour
3/6/2010 3:19:24 PM 2812120 C:\Program Files\CCleaner
4/27/2010 9:04:01 PM 126470055 C:\Program Files\iTunes
4/11/2010 2:11:59 AM 3947668 C:\Program Files\Malwarebytes' Anti-Malware
4/15/2010 8:02:21 PM 0 C:\Program Files\NirSoft
3/28/2010 8:09:07 PM 30668956 C:\Program Files\PeerBlock
4/12/2010 3:33:43 PM 2155705 C:\Program Files\WhoCrashed
4/20/2010 6:40:20 PM 142742 C:\Program Files\Windows Installer Clean Up
======"Drivers" Modified Last 60 Days======
4/12/2010 12:13:53 AM 20824 32 C:\WINDOWS\system32\drivers\mbam.sys
4/12/2010 12:13:56 AM 38224 32 C:\WINDOWS\system32\drivers\mbamswissarmy.sys
====== Files Deleted under "%Temp%" ======
0 Files deleted
======"All Users\Application Data" Last 60 Days======
4/24/2010 2:40:13 AM 188 C:\Documents and Settings\All Users\Application Data\ATI
4/24/2010 2:40:13 AM 188 C:\Documents and Settings\All Users\Application Data\ATI\ACE
4/2/2010 12:12:05 AM 4090359 C:\Documents and Settings\All Users\Application Data\DivX
4/2/2010 12:15:13 AM 56969 C:\Documents and Settings\All Users\Application Data\DivX\ASPEncoder
4/2/2010 12:16:57 AM 57409 C:\Documents and Settings\All Users\Application Data\DivX\ControlPanel
4/2/2010 12:17:13 AM 54128 C:\Documents and Settings\All Users\Application Data\DivX\Converter
4/2/2010 12:17:15 AM 54153 C:\Documents and Settings\All Users\Application Data\DivX\DFXPlugin
4/2/2010 12:18:37 AM 1058400 C:\Documents and Settings\All Users\Application Data\DivX\DivX7
4/2/2010 12:18:37 AM 529200 C:\Documents and Settings\All Users\Application Data\DivX\DivX7\DivX Converter
4/2/2010 12:18:37 AM 529200 C:\Documents and Settings\All Users\Application Data\DivX\DivX7\DivX Plus DirectShow Filters
4/2/2010 12:17:19 AM 56458 C:\Documents and Settings\All Users\Application Data\DivX\DivXDecoderShortcut
4/2/2010 12:18:34 AM 56766 C:\Documents and Settings\All Users\Application Data\DivX\DivXPlusShortcuts
4/2/2010 12:17:18 AM 54174 C:\Documents and Settings\All Users\Application Data\DivX\DSAACDecoder
4/2/2010 12:17:22 AM 57532 C:\Documents and Settings\All Users\Application Data\DivX\DSASPDecoder
4/2/2010 12:17:25 AM 54166 C:\Documents and Settings\All Users\Application Data\DivX\DSAVCDecoder
4/2/2010 12:17:26 AM 57054 C:\Documents and Settings\All Users\Application Data\DivX\DSDesktopComponents
4/2/2010 12:17:00 AM 54101 C:\Documents and Settings\All Users\Application Data\DivX\MPEG2Plugin
4/2/2010 12:16:55 AM 52963 C:\Documents and Settings\All Users\Application Data\DivX\MSVC80CRTRedist
4/2/2010 12:18:16 AM 57677 C:\Documents and Settings\All Users\Application Data\DivX\Player
4/2/2010 12:15:25 AM 54073 C:\Documents and Settings\All Users\Application Data\DivX\Qt4.5
4/2/2010 12:12:05 AM 2005094 C:\Documents and Settings\All Users\Application Data\DivX\Setup
4/2/2010 12:12:14 AM 73637 C:\Documents and Settings\All Users\Application Data\DivX\Setup\DefaultBanner
4/2/2010 12:12:16 AM 21000 C:\Documents and Settings\All Users\Application Data\DivX\Setup\EULAs
4/2/2010 12:12:16 AM 21000 C:\Documents and Settings\All Users\Application Data\DivX\Setup\EULAs\consumer
4/2/2010 12:17:10 AM 54629 C:\Documents and Settings\All Users\Application Data\DivX\TranscodeEngine
4/2/2010 12:17:35 AM 84035 C:\Documents and Settings\All Users\Application Data\DivX\TransferWizard
4/2/2010 12:18:18 AM 53600 C:\Documents and Settings\All Users\Application Data\DivX\Update
4/2/2010 12:18:28 AM 56978 C:\Documents and Settings\All Users\Application Data\DivX\WebPlayer
3/9/2010 7:27:56 PM 2704210 C:\Documents and Settings\All Users\Application Data\Raxco
3/9/2010 7:27:56 PM 2704210 C:\Documents and Settings\All Users\Application Data\Raxco\PerfectDisk
3/9/2010 7:27:56 PM 2704210 C:\Documents and Settings\All Users\Application Data\Raxco\PerfectDisk\11.0
3/30/2010 5:36:41 PM 541387 C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
3/30/2010 5:37:54 PM 541387 C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86
4/27/2010 9:05:03 PM 133968 C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\x86
====== HKLM\~\ShellServiceObjectDelayLoad======
PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\shell32.dll
CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - %Systemroot%\system32\webcheck.dll
SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - %systemroot%\system32\stobject.dll
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll
====== HKLM\~\SharedTaskScheduler======
Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - %SystemRoot%\system32\browseui.dll
Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll
======HKLM\~\msconfig\startupreg======
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service
HKLM\Software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKLM\Software\microsoft\shared tools\msconfig\startupreg\AOLDialer
HKLM\Software\microsoft\shared tools\msconfig\startupreg\CTSysVol
HKLM\Software\microsoft\shared tools\msconfig\startupreg\DivXUpdate
HKLM\Software\microsoft\shared tools\msconfig\startupreg\DMXLauncher
HKLM\Software\microsoft\shared tools\msconfig\startupreg\ehTray
HKLM\Software\microsoft\shared tools\msconfig\startupreg\HostManager
HKLM\Software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
HKLM\Software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler
HKLM\Software\microsoft\shared tools\msconfig\startupreg\P17Helper
HKLM\Software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKLM\Software\microsoft\shared tools\msconfig\startupreg\StartCCC
HKLM\Software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKLM\Software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe
HKLM\Software\microsoft\shared tools\msconfig\startupreg\UpdReg
====== Services ( Services that are Whitelisted are not shown) ======
adfs (adfs)- C:\WINDOWS\system32\drivers\adfs.sys - Auto/Running
bvrp_pci (bvrp_pci)- - Manual/Stopped
cpudrv (cpudrv)- \??\C:\Program Files\SystemRequirementsLab\cpudrv.sys - Manual/Stopped
cpuz126 (cpuz126)- \??\C:\DOCUME~1\Graham\LOCALS~1\Temp\cpuz.sys - Manual/Stopped
ctsfm2k (Creative SoundFont Management Device Driver)- C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys - Manual/Running
DLABOIOM (DLABOIOM)- C:\WINDOWS\system32\DLA\DLABOIOM.SYS - Auto/Running
DLACDBHM (DLACDBHM)- C:\WINDOWS\system32\Drivers\DLACDBHM.SYS - System/Running
DLADResN (DLADResN)- C:\WINDOWS\system32\DLA\DLADResN.SYS - Auto/Running
DLAIFS_M (DLAIFS_M)- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS - Auto/Running
DLAOPIOM (DLAOPIOM)- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS - Auto/Running
DLAPoolM (DLAPoolM)- C:\WINDOWS\system32\DLA\DLAPoolM.SYS - Auto/Running
DLARTL_N (DLARTL_N)- C:\WINDOWS\system32\Drivers\DLARTL_N.SYS - System/Running
DLAUDFAM (DLAUDFAM)- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS - Auto/Running
DLAUDF_M (DLAUDF_M)- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS - Auto/Running
drvmcdb (drvmcdb)- C:\WINDOWS\system32\Drivers\DRVMCDB.SYS - Boot/Running
drvnddm (drvnddm)- C:\WINDOWS\system32\Drivers\DRVNDDM.SYS - Auto/Running
DSproct (DSproct)- \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys - Manual/Stopped
dsunidrv (DellSupport UniDriver)- C:\WINDOWS\system32\DRIVERS\dsunidrv.sys - Auto/Running
E100B (Intel® PRO Adapter Driver)- C:\WINDOWS\system32\DRIVERS\e100b325.sys - Manual/Stopped
e1express (Intel® PRO/1000 PCI Express Network Connection Driver)- C:\WINDOWS\system32\DRIVERS\e1e5132.sys - Manual/Running
GcKernel (Microsoft SideWinder Value Add - Filter Driver)- C:\WINDOWS\system32\DRIVERS\GcKernel.sys - Manual/Stopped
GTNDIS5 (GTNDIS5 NDIS Protocol Driver)- \??\C:\WINDOWS\system32\GTNDIS5.SYS - Manual/Stopped
hamachi_oem (PlayLinc Adapter)- C:\WINDOWS\system32\DRIVERS\gan_adapter.sys - Manual/Stopped
HIDSwvd (Microsoft SideWinder Virtual HID Device Mini-Driver)- C:\WINDOWS\system32\DRIVERS\HIDSwvd.sys - Manual/Stopped
iastor (Intel AHCI Controller)- C:\WINDOWS\system32\drivers\iastor.sys - Boot/Running
MBAMSwissArmy (MBAMSwissArmy)- \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys - Manual/Stopped
MHNDRV (MHN driver)- C:\WINDOWS\system32\DRIVERS\mhndrv.sys - Manual/Stopped
motmodem (Motorola USB CDC ACM Driver)- C:\WINDOWS\system32\DRIVERS\motmodem.sys - Manual/Stopped
MpFilter (Microsoft Malware Protection Driver)- C:\WINDOWS\system32\DRIVERS\MpFilter.sys - System/Running
ndiscm (Motorola SURFboard USB Cable Modem Windows Driver)- C:\WINDOWS\system32\DRIVERS\NetMotCM.sys - Manual/Stopped
ossrv (Creative OS Services Driver)- C:\WINDOWS\system32\DRIVERS\ctoss2k.sys - Manual/Running
P2k (Motorola USB Device)- C:\WINDOWS\system32\DRIVERS\P2k.sys - Manual/Stopped
RT73 (Linksys Home Wireless-G USB Adapter Driver)- C:\WINDOWS\system32\DRIVERS\rt73.sys - Manual/Running
sfdrv01 (StarForce Protection Environment Driver (version 1.x))- C:\WINDOWS\system32\drivers\sfdrv01.sys - Boot/Running
sfhlp02 (StarForce Protection Helper Driver (version 2.x))- C:\WINDOWS\system32\drivers\sfhlp02.sys - Boot/Running
sfsync02 (StarForce Protection Synchronization Driver (version 2.x))- C:\WINDOWS\system32\drivers\sfsync02.sys - Boot/Running
sfsync03 (StarForce Protection Synchronization Driver (version 3.x))- C:\WINDOWS\system32\drivers\sfsync03.sys - Boot/Running
sfvfs02 (StarForce Protection VFS Driver (version 2.x))- C:\WINDOWS\system32\drivers\sfvfs02.sys - Boot/Running
snapman (Acronis Snapshots Manager)- C:\WINDOWS\system32\DRIVERS\snapman.sys - Boot/Running
SysProtDrv.sys (SysProtDrv.sys)- \??\C:\Documents and Settings\Graham\Desktop\Alureon.G\SysProt\SysProtDrv.sys - Manual/Stopped
Tcpip6 (Microsoft IPv6 Protocol Driver)- C:\WINDOWS\system32\DRIVERS\tcpip6.sys - System/Running
tdrpman (Acronis Try&Decide and Restore Points filter)- C:\WINDOWS\system32\DRIVERS\tdrpman.sys - Boot/Running
TIEHDUSB (TIEHDUSB)- C:\WINDOWS\system32\drivers\tiehdusb.sys - Manual/Stopped
tifsfilter (Acronis True Image FS Filter)- C:\WINDOWS\system32\DRIVERS\tifsfilt.sys - Auto/Running
timounter (Acronis True Image Backup Archive Explorer)- C:\WINDOWS\system32\DRIVERS\timntr.sys - Boot/Running
tunmp (Microsoft Tun Miniport Adapter Driver)- C:\WINDOWS\system32\DRIVERS\tunmp.sys - Manual/Running
TVICHW32 (TVICHW32)- \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS - Manual/Stopped
USBAAPL (Apple Mobile USB Driver)- C:\WINDOWS\system32\Drivers\usbaapl.sys - Manual/Stopped
usbser (Motorola USB Modem Driver)- C:\WINDOWS\system32\DRIVERS\usbser.sys - Manual/Stopped
USB_RNDIS (USB Remote NDIS Network Device Driver)- C:\WINDOWS\system32\DRIVERS\usb8023.sys - Manual/Stopped
wanatw (WAN Miniport (ATW))- C:\WINDOWS\system32\DRIVERS\wanatw4.sys - Manual/Running
Wdf01000 (Wdf01000)- C:\WINDOWS\system32\DRIVERS\Wdf01000.sys - Manual/Running
xusb21 (Xbox 360 Wireless Receiver Driver Service 21)- C:\WINDOWS\system32\DRIVERS\xusb21.sys - Manual/Running
====== Uninstall List ======
A file named 'UNI.txt' was created and saved to
FileListers default location. Post the results if requested.
======== Other Info ========
TOTAL PHYSICAL RAM: 3756 MB
Boot Info
[boot loader]
timeout=3
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
OS Type: Microsoft Windows XP Professional
Build: 5.1.2600
Service Pack: 3.0
====== Files with Hidden Attributes======
A file named 'Hidden.txt' was created and saved to
FileListers default location. Post the results if requested.
==End of Report==
I am unable to logon to the Recovery Console, I get the error 0x0000007B, as pictured below: