Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

google redirect virus


  • This topic is locked This topic is locked

#1
gentlecarlos

gentlecarlos

    New Member

  • Member
  • Pip
  • 6 posts
Hi there.
I have had the google redirect virus for about three weeks now and its really doing my head in. I have tried many removal methods including a guide on this site but with no success. Any help would be much apreciated.
Regards Carl.

Edited by gentlecarlos, 09 December 2010 - 03:54 PM.

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there I will need a little information first

Posted Image GMER Rootkit Scanner - Download - Homepage
[*] Download GMER
[*] Extract the contents of the zipped file to desktop.
[*] Double click GMER.exe.
Posted Image
[*] If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
[*] In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
  • IAT/EAT
  • Drives/Partition other than Systemdrive (typically C:\)
  • Show All (don't miss this one)
    Posted Image
    Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries
Please copy and paste the report into your Post.

THEN

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Click on Scan all users
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic

  • 0

#3
gentlecarlos

gentlecarlos

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi there.
Thanks for your prompt reply. Here are the logs from the scans.
Regards Carl.




GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-12 22:41:52
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 FUJITSU_MHV2080AT_PL rev.000000A0
Running: gmer.exe; Driver: C:\DOCUME~1\CARLGE~1\LOCALS~1\Temp\pgwyrkog.sys


---- System - GMER 1.0.15 ----

SSDT 8A048AC8 ZwAlertResumeThread
SSDT 8A048BA8 ZwAlertThread
SSDT 89F91E48 ZwAllocateVirtualMemory
SSDT 89DDBFD0 ZwAssignProcessToJobObject
SSDT 8A0DC288 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA7EFD720]
SSDT 8A0E4370 ZwCreateMutant
SSDT 8A01FCE8 ZwCreateSymbolicLinkObject
SSDT 8A367740 ZwCreateThread
SSDT 89EA0EB0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA7EFD9A0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA7EFDF00]
SSDT 89F91FC0 ZwDuplicateObject
SSDT 8A0CCE68 ZwFreeVirtualMemory
SSDT 8A073E90 ZwImpersonateAnonymousToken
SSDT 8A073F70 ZwImpersonateThread
SSDT 8A03C050 ZwLoadDriver
SSDT 89F8DAC0 ZwMapViewOfSection
SSDT 8A0E42B0 ZwOpenEvent
SSDT 89FB6008 ZwOpenProcess
SSDT 89DA8620 ZwOpenProcessToken
SSDT 89E8F4B8 ZwOpenSection
SSDT 89FB6130 ZwOpenThread
SSDT 89DDBEE0 ZwProtectVirtualMemory
SSDT 89E971C0 ZwResumeThread
SSDT 8A0F4658 ZwSetContextThread
SSDT 8A0F4738 ZwSetInformationProcess
SSDT 89EA0F90 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA7EFE150]
SSDT 89E8F598 ZwSuspendProcess
SSDT 89E972A0 ZwSuspendThread
SSDT 89FAF2C8 ZwTerminateProcess
SSDT 89E97360 ZwTerminateThread
SSDT 8A056818 ZwUnmapViewOfSection
SSDT 8A0CCF38 ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwCallbackReturn + 2454 80501C8C 8 Bytes CALL C0DA1E8D
.text ntkrnlpa.exe!ZwCallbackReturn + 2778 80501FB0 8 Bytes CALL 69C2C03E
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
? C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101211.006\NAVEX15.SYS The system cannot find the file specified. !
? C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101211.006\NAVENG.SYS The system cannot find the file specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3396] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]

---- Devices - GMER 1.0.15 ----

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

---- EOF - GMER 1.0.15 ----


OTL logfile created on: 12/12/2010 23:04:05 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\carl gentleman\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 17.11 Gb Free Space | 45.91% Space Free | Partition Type: NTFS
Drive D: | 30.28 Gb Total Space | 30.00 Gb Free Space | 99.08% Space Free | Partition Type: NTFS

Computer Name: YOUR-F42298D1A0 | User Name: carl gentleman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\carl gentleman\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe (Sony Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\SonicStage\SSAAD.exe ()
PRC - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe (Utimaco Safeware AG)
PRC - C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\ico.exe (Primax Electronics Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\carl gentleman\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\asoehook.dll (Symantec Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\WMVCore.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\winsta.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\shgina.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\odbc32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\netui1.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\netui0.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\ntlanman.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\netrap.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msgina.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\drprov.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\davclnt.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\odbcint.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wmasf.dll (Microsoft Corporation)
MOD - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\pdfshell.dll (Adobe Systems, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) -- C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) -- C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (NIS) -- C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe (Symantec Corporation)
SRV - (VUAgent) -- C:\Program Files\Sony\VAIO Update 5\VUAgent.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) -- C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (SSScsiSV) -- C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (AdobeActiveFileMonitor4.0) -- C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe ()
SRV - (VzCdbSvc) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (VzFw) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (Vcsw) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (MSCSPTISRV) -- C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) -- C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (S24EventMonitor) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (VAIO Event Service) -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101212.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101212.002\NAVENG.SYS (Symantec Corporation)
DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\NIS\1205000.07D\SYMTDI.SYS (Symantec Corporation)
DRV - (SRTSP) -- C:\WINDOWS\System32\Drivers\NIS\1205000.07D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\WINDOWS\system32\drivers\NIS\1205000.07D\SRTSPX.SYS (Symantec Corporation)
DRV - (BHDrvx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101123.003\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) -- C:\WINDOWS\system32\drivers\NIS\1205000.07D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymIRON) -- C:\WINDOWS\system32\drivers\NIS\1205000.07D\Ironx86.SYS (Symantec Corporation)
DRV - (IDSxpx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101210.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SymDS) -- C:\WINDOWS\system32\drivers\NIS\1205000.07D\SYMDS.SYS (Symantec Corporation)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (tifmsony) -- C:\WINDOWS\system32\drivers\tifmsony.sys (Texas Instruments)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w29n51) Intel® -- C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (LEX_AS_NIC_SERVICE_YNOS) -- C:\WINDOWS\system32\drivers\ExpasAG.sys (Atheros Communications, Inc.)
DRV - (PrivateDisk) -- C:\WINDOWS\system32\drivers\privatediskm.sys (Utimaco Safeware AG)
DRV - (ApfiltrService) -- C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (DMICall) -- C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (SNC) -- C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.c...aspx?TbId=60475
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.c...spx?tb_id=60475


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.club-vaio.com/en/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.club-vaio.com/en/
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.club-vaio.com/en/

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.club-vaio.com/en/

IE - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\..\URLSearchHook: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2010/12/09 22:20:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2010/12/09 20:39:22 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2010/12/03 18:43:17 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coieplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\WINDOWS\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PDService.exe] C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe (Utimaco Safeware AG)
O4 - HKLM..\Run: [PrepareYourVAIO] C:\Program Files\Sony\Prepare your VAIO\PYVAlert.exe (Sony Corporation)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe ()
O4 - HKLM..\Run: [VAIO Update 5] C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe (Sony Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O15 - HKU\.DEFAULT\..Trusted Domains: sony-europe.com ([] in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: sony-europe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sonystyle-europe.com ([] in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: sonystyle-europe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: vaio-link.com ([] in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: vaio-link.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony-europe.com ([] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: sony-europe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sonystyle-europe.com ([] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: sonystyle-europe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: vaio-link.com ([] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: vaio-link.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\..Trusted Domains: sony-europe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\..Trusted Domains: sonystyle-europe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-639572236-1284316945-3395171387-1007\..Trusted Domains: vaio-link.com ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/17 15:27:29 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.dvsd - C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll (Sony Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)


SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: hitmanpro35 - Reg Error: Value error.
SafeBootNet: hitmanpro35.sys - Reg Error: Value error.
SafeBootNet: HitmanPro35Crusader - Reg Error: Value error.
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Service
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2F6EFCE6-10DF-49F9-9E64-9AE3775B2588} - Microsoft .NET Framework 1.1 Security Update (KB2416447)
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Flash Player 8
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

========== Files/Folders - Created Within 30 Days ==========

[2010/12/12 21:32:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Desktop\New Folder
[2010/12/10 00:57:14 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010/12/10 00:44:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\PriceGong
[2010/12/10 00:34:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Apple Computer
[2010/12/10 00:34:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Apple Computer
[2010/12/10 00:34:20 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
[2010/12/10 00:34:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/12/10 00:33:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Apple
[2010/12/10 00:21:51 | 000,000,000 | ---D | C] -- C:\Program Files\Abexo
[2010/12/10 00:05:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Registry Mechanic
[2010/12/09 23:42:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Uniblue
[2010/12/09 23:42:14 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2010/12/09 23:42:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\PackageAware
[2010/12/09 20:41:30 | 000,368,248 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symtdi.sys
[2010/12/09 20:41:30 | 000,330,360 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symtdiv.sys
[2010/12/09 20:41:30 | 000,295,032 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symnets.sys
[2010/12/09 20:41:29 | 000,652,336 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symefa.sys
[2010/12/09 20:41:29 | 000,509,560 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtsp.sys
[2010/12/09 20:41:29 | 000,340,016 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symds.sys
[2010/12/09 20:41:29 | 000,136,312 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\ironx86.sys
[2010/12/09 20:41:29 | 000,050,168 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtspx.sys
[2010/12/09 20:39:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NIS\1205000.07D
[2010/12/04 03:33:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Desktop\photos
[2010/12/04 03:09:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Desktop\desktop music
[2010/12/02 14:33:46 | 000,000,000 | ---D | C] -- C:\Program Files\Dream Aquarium
[2010/12/02 13:21:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\WinRAR
[2010/12/02 13:20:56 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2010/12/02 11:03:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2010/12/01 22:13:17 | 000,000,000 | ---D | C] -- C:\Program Files\Atlantis3D
[2010/12/01 20:04:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Malwarebytes
[2010/12/01 20:03:56 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/01 20:03:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/12/01 20:03:53 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/01 20:03:53 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/01 19:50:35 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/12/01 19:50:35 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/12/01 19:50:35 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/12/01 19:50:35 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/12/01 19:48:25 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/12/01 18:13:48 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/12/01 01:07:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Sonic
[2010/12/01 01:07:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Leadertech
[2010/12/01 00:22:19 | 000,000,000 | ---D | C] -- C:\Program Files\VirtualDJ
[2010/11/30 22:17:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\Small Block Screensaver
[2010/11/30 21:53:38 | 000,337,056 | ---- | C] (Axialis Software) -- C:\WINDOWS\System32\ENTER.scr
[2010/11/30 21:27:17 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/11/30 21:22:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/11/30 01:10:24 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\WINDOWS\System32\bootdelete.exe
[2010/11/29 22:18:42 | 000,000,000 | ---D | C] -- C:\Program Files\Hitman Pro 3.5
[2010/11/29 22:17:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/11/28 22:25:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Threat Expert
[2010/11/28 22:03:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/11/27 14:42:35 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2010/11/23 20:04:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/11/23 20:03:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2010/11/23 20:02:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Sun
[2010/11/23 19:15:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Help
[2010/11/23 19:15:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Help
[2010/11/21 01:17:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\vlc
[2010/11/21 01:16:10 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2010/11/21 00:20:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2010/11/20 23:41:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2010/11/20 23:41:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2010/11/20 23:41:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2010/11/20 23:41:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2010/11/20 23:34:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic
[2010/11/20 23:29:28 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2010/11/20 23:29:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\EHome
[2010/11/20 22:53:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Opera
[2010/11/20 22:53:06 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2010/11/20 20:25:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\IObit
[2010/11/20 20:25:48 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2010/11/20 20:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\Eusing Free Registry Cleaner
[2010/11/20 19:57:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\RegGenie
[2010/11/20 19:45:00 | 000,000,000 | ---D | C] -- C:\Program Files\RegGenie
[2010/11/20 19:33:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\AdobeUM
[2010/11/19 16:13:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\My Documents\Symantec
[2010/11/19 00:23:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2010/11/19 00:22:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\InstallShield
[2010/11/18 23:15:48 | 000,126,512 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/11/18 23:15:48 | 000,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2010/11/18 23:14:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NIS
[2010/11/18 23:14:33 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Internet Security
[2010/11/18 23:14:32 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2010/11/18 23:14:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2010/11/18 23:13:49 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2010/11/18 23:13:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/11/18 22:39:53 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2010/11/18 22:39:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Conduit
[2010/11/18 22:39:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\uTorrentBar
[2010/11/18 22:39:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\ConduitEngine
[2010/11/18 22:39:50 | 000,000,000 | ---D | C] -- C:\Program Files\ConduitEngine
[2010/11/18 22:39:48 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentBar
[2010/11/18 22:39:46 | 000,000,000 | ---D | C] -- C:\extensions
[2010/11/18 22:39:37 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2010/11/18 22:38:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\uTorrent
[2010/11/18 22:31:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Opera
[2010/11/18 22:24:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\My Documents\Downloads
[2010/11/17 20:40:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Temp
[2010/11/17 20:36:18 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\carl gentleman\IECompatCache
[2010/11/17 20:33:50 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\carl gentleman\PrivacIE
[2010/11/17 20:32:03 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\carl gentleman\IETldCache
[2010/11/17 20:26:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010/11/17 20:26:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2010/11/17 20:24:54 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/11/17 20:24:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2010/11/17 19:59:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2010/11/17 19:57:01 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010/11/17 18:08:27 | 000,000,000 | ---D | C] -- C:\Update
[2010/11/17 18:06:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2010/11/17 18:04:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\sony
[2010/11/17 18:04:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SWF Studio
[2010/11/17 18:02:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\carl gentleman\My Documents\My Videos
[2010/11/17 18:02:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2010/11/17 17:54:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Macromedia
[2010/11/17 17:54:25 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\carl gentleman\UserData
[2010/11/17 17:52:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2010/11/17 17:46:15 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2010/11/17 17:45:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2010/11/17 17:45:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2010/11/17 17:45:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2010/11/17 17:45:15 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010/11/17 17:44:20 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010/11/17 17:43:00 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2010/11/17 17:41:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Adobe
[2010/11/17 17:38:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
[2010/11/17 17:37:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\VAIO Media Platform
[2010/11/17 17:37:04 | 000,068,608 | ---- | C] (QSound Labs, Inc.) -- C:\WINDOWS\System32\SonyAIwo.dll
[2010/11/17 17:37:04 | 000,061,952 | ---- | C] (QSound Labs, Inc.) -- C:\WINDOWS\System32\SonyAIds.dll
[2010/11/17 17:37:04 | 000,038,400 | ---- | C] (QSound Labs, Inc.) -- C:\WINDOWS\System32\SonyAIwd.dll
[2010/11/17 17:36:39 | 000,565,248 | ---- | C] (Gracenote) -- C:\WINDOWS\System32\CddbMusicIDSony.dll
[2010/11/17 17:36:20 | 000,765,952 | ---- | C] (Gracenote) -- C:\WINDOWS\System32\CDDBUISony.dll
[2010/11/17 17:36:19 | 000,598,016 | ---- | C] (Gracenote (formerly CDDB, Inc.)) -- C:\WINDOWS\System32\CDDBControlSony.dll
[2010/11/17 17:36:19 | 000,073,728 | ---- | C] (Gracenote) -- C:\WINDOWS\System32\CddbLinkSony.dll
[2010/11/17 17:35:50 | 000,000,000 | ---D | C] -- C:\Program Files\Skype
[2010/11/17 17:34:40 | 000,000,000 | ---D | C] -- C:\Program Files\Roxio
[2010/11/17 17:34:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sonic Shared
[2010/11/17 17:34:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\ImageConverter2
[2010/11/17 17:32:20 | 000,000,000 | --SD | C] -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft
[2010/11/17 17:32:20 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\carl gentleman\SendTo
[2010/11/17 17:32:20 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\carl gentleman\Recent
[2010/11/17 17:32:20 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\carl gentleman\Application Data
[2010/11/17 17:32:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\carl gentleman\Start Menu
[2010/11/17 17:32:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\carl gentleman\My Documents\My Pictures
[2010/11/17 17:32:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\carl gentleman\My Documents\My Music
[2010/11/17 17:32:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\carl gentleman\My Documents
[2010/11/17 17:32:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\carl gentleman\Favorites
[2010/11/17 17:32:20 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\carl gentleman\Cookies
[2010/11/17 17:32:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\carl gentleman\Templates
[2010/11/17 17:32:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\carl gentleman\PrintHood
[2010/11/17 17:32:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\carl gentleman\NetHood
[2010/11/17 17:32:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\carl gentleman\Local Settings
[2010/11/17 17:32:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Symantec
[2010/11/17 17:32:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Sony Corporation
[2010/11/17 17:32:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Microsoft
[2010/11/17 17:32:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Identities
[2010/11/17 17:32:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\Google
[2010/11/17 17:32:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Desktop
[2010/11/17 17:32:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\ApplicationHistory
[2010/11/17 17:32:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Application Data\Adobe
[2010/11/17 17:32:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150050}
[2010/11/17 17:29:01 | 000,000,000 | ---D | C] -- C:\Program Files\Program Shortcuts

========== Files - Modified Within 30 Days ==========

[2010/12/12 22:39:44 | 000,002,567 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Office 2003 Edition 60 Day Trial.lnk
[2010/12/12 22:13:04 | 000,001,014 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-639572236-1284316945-3395171387-1007UA.job
[2010/12/12 21:12:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/12/12 21:12:54 | 1600,638,976 | -HS- | M] () -- C:\hiberfil.sys
[2010/12/12 19:00:00 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\RMSchedule.job
[2010/12/12 11:13:00 | 000,000,962 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-639572236-1284316945-3395171387-1007Core.job
[2010/12/10 00:35:15 | 000,051,360 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/12/10 00:34:29 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/12/10 00:21:52 | 000,000,732 | ---- | M] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Abexo Free Registry Cleaner.lnk
[2010/12/10 00:21:52 | 000,000,714 | ---- | M] () -- C:\Documents and Settings\carl gentleman\Desktop\Abexo Free Registry Cleaner.lnk
[2010/12/09 22:29:35 | 000,012,872 | ---- | M] (SurfRight B.V.) -- C:\WINDOWS\System32\bootdelete.exe
[2010/12/09 22:27:07 | 000,016,968 | ---- | M] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/12/09 22:20:37 | 000,001,988 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2010/12/09 22:20:17 | 000,614,470 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\Cat.DB
[2010/12/08 16:47:53 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/12/04 10:53:10 | 000,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\isolate.ini
[2010/12/04 04:01:21 | 000,009,840 | ---- | M] () -- C:\{AC14C231-DAB2-4839-A6B2-28794DD8C732}
[2010/12/03 19:15:15 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/12/03 19:15:14 | 000,002,355 | ---- | M] () -- C:\Documents and Settings\carl gentleman\Desktop\Google Chrome.lnk
[2010/12/03 18:43:17 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2010/12/02 09:49:15 | 000,004,566 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/12/02 09:49:08 | 000,398,748 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/12/02 09:49:08 | 000,060,714 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/12/02 09:25:23 | 000,000,819 | ---- | M] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/12/02 03:15:10 | 000,007,877 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symnetv.cat
[2010/12/02 03:15:10 | 000,007,458 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symnet.cat
[2010/12/01 20:03:58 | 000,000,788 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/01 19:02:54 | 000,281,336 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/01 05:24:00 | 000,368,248 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symtdi.sys
[2010/12/01 05:24:00 | 000,295,032 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symnets.sys
[2010/12/01 05:23:59 | 000,330,360 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symtdiv.sys
[2010/12/01 05:23:53 | 000,001,474 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symnetv.inf
[2010/12/01 05:23:53 | 000,001,446 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symnet.inf
[2010/12/01 00:22:29 | 000,000,644 | ---- | M] () -- C:\Documents and Settings\carl gentleman\Desktop\Virtual DJ.lnk
[2010/11/30 21:53:38 | 000,337,056 | ---- | M] (Axialis Software) -- C:\WINDOWS\System32\ENTER.scr
[2010/11/29 22:21:49 | 000,000,618 | ---- | M] () -- C:\WINDOWS\System32\.crusader
[2010/11/29 22:18:42 | 000,001,667 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Hitman Pro 3.5.lnk
[2010/11/29 17:42:18 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/23 04:59:06 | 000,007,456 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symefa.cat
[2010/11/23 04:58:56 | 000,007,450 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symds.cat
[2010/11/23 04:27:39 | 000,007,528 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\iron.cat
[2010/11/23 04:08:31 | 000,509,560 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtsp.sys
[2010/11/23 04:08:31 | 000,050,168 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtspx.sys
[2010/11/23 04:08:31 | 000,007,454 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtspx.cat
[2010/11/23 04:08:31 | 000,007,450 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtsp.cat
[2010/11/23 04:08:31 | 000,001,389 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtspx.inf
[2010/11/23 04:08:31 | 000,001,383 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtsp.inf
[2010/11/21 01:16:56 | 000,000,723 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2010/11/21 01:12:41 | 000,011,264 | ---- | M] () -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/21 00:21:44 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2010/11/20 23:33:36 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/11/18 23:15:48 | 000,126,512 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/11/18 23:15:48 | 000,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2010/11/18 23:15:48 | 000,007,456 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/11/18 23:15:48 | 000,000,805 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/11/18 22:39:37 | 000,000,652 | ---- | M] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2010/11/18 22:39:37 | 000,000,634 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/11/18 02:59:55 | 000,652,336 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symefa.sys
[2010/11/18 02:59:54 | 000,003,374 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symefa.inf
[2010/11/17 20:32:06 | 000,001,507 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Browser Choice.lnk
[2010/11/17 18:02:07 | 000,000,808 | ---- | M] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/11/17 17:51:01 | 000,029,322 | ---- | M] () -- C:\WINDOWS\System32\Snyres.oem
[2010/11/17 17:51:00 | 000,000,266 | ---- | M] () -- C:\WINDOWS\System32\Snysplst.oem
[2010/11/17 17:51:00 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\SNYINST.OEM
[2010/11/17 17:47:03 | 000,000,376 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2010/11/17 17:35:10 | 000,000,059 | ---- | M] () -- C:\WINDOWS\WININIT.INI
[2010/11/17 17:29:16 | 000,000,099 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2010/11/17 17:29:11 | 000,000,000 | RH-- | M] () -- C:\WINDOWS\System32\drivers\Sony_VGN-FS485B.mrk
[2010/11/17 17:29:10 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2010/11/16 01:45:33 | 000,136,312 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\ironx86.sys
[2010/11/16 01:45:33 | 000,000,742 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\iron.inf

========== Files Created - No Company Name ==========

[2010/12/10 00:35:15 | 000,051,360 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/12/10 00:34:29 | 000,001,854 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/12/10 00:21:52 | 000,000,732 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Abexo Free Registry Cleaner.lnk
[2010/12/10 00:21:51 | 000,000,714 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Desktop\Abexo Free Registry Cleaner.lnk
[2010/12/10 00:03:54 | 000,000,272 | ---- | C] () -- C:\WINDOWS\tasks\RMSchedule.job
[2010/12/09 22:19:44 | 000,614,470 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\Cat.DB
[2010/12/09 20:41:30 | 000,007,877 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symnetv.cat
[2010/12/09 20:41:30 | 000,007,458 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symnet.cat
[2010/12/09 20:41:30 | 000,001,474 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symnetv.inf
[2010/12/09 20:41:30 | 000,001,446 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symnet.inf
[2010/12/09 20:41:29 | 000,007,528 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\iron.cat
[2010/12/09 20:41:29 | 000,007,456 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symefa.cat
[2010/12/09 20:41:29 | 000,007,454 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtspx.cat
[2010/12/09 20:41:29 | 000,007,450 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symds.cat
[2010/12/09 20:41:29 | 000,007,450 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtsp.cat
[2010/12/09 20:41:29 | 000,003,374 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symefa.inf
[2010/12/09 20:41:29 | 000,002,792 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\symds.inf
[2010/12/09 20:41:29 | 000,001,389 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtspx.inf
[2010/12/09 20:41:29 | 000,001,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\srtsp.inf
[2010/12/09 20:41:29 | 000,000,742 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\iron.inf
[2010/12/09 20:39:22 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1205000.07D\isolate.ini
[2010/12/04 04:01:21 | 000,009,840 | ---- | C] () -- C:\{AC14C231-DAB2-4839-A6B2-28794DD8C732}
[2010/12/02 11:11:19 | 000,002,333 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/12/02 11:11:18 | 000,002,355 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Desktop\Google Chrome.lnk
[2010/12/02 11:08:21 | 000,001,014 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-639572236-1284316945-3395171387-1007UA.job
[2010/12/02 11:08:20 | 000,000,962 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-639572236-1284316945-3395171387-1007Core.job
[2010/12/01 20:03:58 | 000,000,788 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/01 19:50:35 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/12/01 19:50:35 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/12/01 19:50:35 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/12/01 19:50:35 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/12/01 19:50:35 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/12/01 00:22:28 | 000,000,644 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Desktop\Virtual DJ.lnk
[2010/11/29 22:21:49 | 000,000,618 | ---- | C] () -- C:\WINDOWS\System32\.crusader
[2010/11/29 22:18:43 | 000,016,968 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/11/29 22:18:42 | 000,001,667 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Hitman Pro 3.5.lnk
[2010/11/21 01:16:55 | 000,000,723 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2010/11/20 23:34:39 | 000,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
[2010/11/20 23:34:37 | 000,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2010/11/20 23:34:28 | 000,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
[2010/11/20 23:32:37 | 000,004,566 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010/11/19 16:18:24 | 000,215,144 | R--- | C] () -- C:\WINDOWS\patchw32.dll
[2010/11/19 16:17:46 | 000,215,144 | R--- | C] () -- C:\WINDOWS\pw32a.dll
[2010/11/18 23:15:48 | 000,007,456 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/11/18 23:15:48 | 000,000,805 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/11/18 23:15:30 | 000,001,988 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2010/11/18 23:03:14 | 000,000,075 | ---- | C] () -- C:\Documents and Settings\carl gentleman\LuResult.txt
[2010/11/18 22:39:37 | 000,000,652 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2010/11/18 22:39:37 | 000,000,634 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/11/17 20:52:54 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/17 20:32:06 | 000,001,507 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Browser Choice.lnk
[2010/11/17 18:02:07 | 000,000,808 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/11/17 17:47:06 | 000,002,567 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Office 2003 Edition 60 Day Trial.lnk
[2010/11/17 17:47:02 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/11/17 17:37:55 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\Cpuinf32.dll
[2010/11/17 17:35:10 | 000,000,059 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2010/11/17 17:32:22 | 000,000,819 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/11/17 17:32:22 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/11/17 17:32:22 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\carl gentleman\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2010/11/17 17:29:11 | 000,000,000 | RH-- | C] () -- C:\WINDOWS\System32\drivers\Sony_VGN-FS485B.mrk
[2005/11/18 17:34:39 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/11/18 13:33:18 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2005/11/18 13:33:18 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2005/11/18 13:33:18 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2005/11/18 13:33:18 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2005/11/18 13:33:18 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2005/11/18 13:33:18 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2005/11/18 10:28:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VAIOUpdt.INI
[2005/11/17 16:40:10 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\WLANDLL.DLL
[2005/11/17 16:02:58 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2005/11/17 15:19:48 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/11/17 06:13:39 | 000,003,822 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/11/01 08:53:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2010/11/29 22:21:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/12/10 00:06:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/11/20 20:25:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\carl gentleman\Application Data\IObit
[2010/12/01 01:07:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\carl gentleman\Application Data\Leadertech
[2010/11/20 22:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\carl gentleman\Application Data\Opera
[2010/12/10 00:44:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\carl gentleman\Application Data\PriceGong
[2010/11/20 19:57:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\carl gentleman\Application Data\RegGenie
[2010/12/10 00:05:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\carl gentleman\Application Data\Registry Mechanic
[2010/11/17 18:04:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\carl gentleman\Application Data\sony
[2010/12/09 23:42:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\carl gentleman\Application Data\Uniblue
[2010/12/02 16:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\carl gentleman\Application Data\uTorrent
[2010/12/12 19:00:00 | 000,000,272 | ---- | M] () -- C:\WINDOWS\Tasks\RMSchedule.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >



OTL Extras logfile created on: 12/12/2010 23:04:05 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\carl gentleman\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 17.11 Gb Free Space | 45.91% Space Free | Partition Type: NTFS
Drive D: | 30.28 Gb Total Space | 30.00 Gb Free Space | 99.08% Space Free | Partition Type: NTFS

Computer Name: YOUR-F42298D1A0 | User Name: carl gentleman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_USERS\S-1-5-21-639572236-1284316945-3395171387-1007\SOFTWARE\Classes\<extension>]
.html [@ = SafariHTML] -- C:\Program Files\Safari\Safari.exe (Apple Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00F8608F-BA6A-4B32-843A-1A568ACD1198}" = VAIO Sea Wallpaper
"{013E1BA8-C815-4E27-BCB9-D6B1B2E24094}" = SonicStage Mastering Studio Audio Filter Custom Preset
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio DigitalMedia Data
"{11C98E1A-EC91-4B38-B44C-C562292D8453}" = Adobe Premiere Elements 2.0
"{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{20ACB2F8-3BCA-45A8-80A2-9D3CB5C25F43}" = Safari
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{28DA872A-0848-48CF-B749-19A198157A2A}" = mDriver
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{48E9DE14-39D1-4974-91A6-D4E1836F648D}" = SafeGuard® PrivateDisk 1.00.6 - Try and Buy Version
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{5BEE8F1F-BD32-4553-8107-500439E43BD7}" = VAIO Update
"{61D6E4FB-1A62-4EB1-BE56-929B00C155CF}" = Wireless LAN Starter
"{63B8FB69-A1B6-425D-B67D-5257B7A1F663}" = Image Converter 2 Plus
"{668B1BD6-4593-4959-970E-249AFFE6F35C}" = VOR
"{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6DE14BE4-6F04-4935-8ABD-A0A19FE2E55A}" = mCore
"{767E3E57-D183-48F2-B25F-1AA5CBC98F5E}" = VAIO Edit Components
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 5.0
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{9080C5D2-82FA-452A-87FA-CBB4B05D67A5}" = VPS
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{9E407618-D9CD-4F39-9490-9ED45294073D}" = Click to DVD 2.0.03 Menu Data
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 3.3
"{A4D77A09-10EA-4574-8C09-9B6E1A21C95F}" = Virus Guard - powered by BitDefender
"{AB467B85-4F52-48C2-AEED-0673D00417B0}" = SonicStage Mastering Studio Audio Filter
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio DigitalMedia Audio
"{ABBD2A2E-2424-4078-966F-F319A88D5F21}" = VAIO Starfish Wallpaper
"{AC76BA86-0000-7EC8-7489-000000000702}" = Adobe Acrobat 7.0.1 and Reader 7.0.1 Update
"{AC76BA86-0000-7EC8-7489-000000000703}" = Adobe Acrobat 7.0.2 and Reader 7.0.2 Update
"{AC76BA86-0000-7EC8-7489-000000000704}" = Adobe Acrobat 7.0.3 and Reader 7.0.3 Update
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 5.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio DigitalMedia Copy
"{B7C03E84-AF46-42F4-809D-D4127D9086D0}" = VAIO Edit Components 6.6
"{BBFFB027-7D53-4E1B-95BC-35A2216D1D60}" = VAIO Long Battery Life Wallpaper
"{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library
"{BF3B304B-8A18-452D-A19F-6012CA8418D7}" = SonicStage Mastering Studio 2.1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (VAIO_VEDB)
"{E5E6E687-1033-0000-0000-000000000002}" = Adobe Acrobat 7.0 Elements
"{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.5.32
"{EBB7C1C1-D439-4D9B-9FDC-954C10F266B0}" = Adobe Photoshop Elements 4.0
"{EE7EB179-5AA2-4B28-AC92-5CBAAF82BA7F}" = SonicStage Mastering Studio Plugins
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"{FB714F13-10C9-48DB-91C9-DDBCCCBF9370}" = VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
"{FC37C108-821D-4EDE-8F40-D5B497586805}" = VAIO Control Center
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FCCB0B43-7A6D-49A4-A5B3-B10F592F4EB6}" = LAN-Express AS IEEE 802.11 Wireless LAN
"Abexo Free Registry Cleaner" = Abexo Free Registry Cleaner
"Adobe Acrobat 7.0 Elements" = Adobe Acrobat 7.0 Elements
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop Elements 4" = Adobe Photoshop Elements 4.0
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_20030003" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"conduitEngine" = Conduit Engine
"HitmanPro35" = Hitman Pro 3.5
"ie8" = Windows Internet Explorer 8
"InstallShield_{668B1BD6-4593-4959-970E-249AFFE6F35C}" = VAIO Online Registration (English)
"InstallShield_{9080C5D2-82FA-452A-87FA-CBB4B05D67A5}" = VAIO Product Survey
"InstallShield_{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MouseSuite98" = Sony USB Mouse
"NIS" = Norton Internet Security
"NVIDIA Drivers" = NVIDIA Drivers
"OpenMG HotFix4.3-05-09-14-01" = OpenMG Limited Patch 4.3-05-10-05-01
"PremElem20" = Adobe Premiere Elements 2.0
"ProInst" = Intel® PROSet/Wireless Software
"PROSet" = Intel® PRO Network Connections Drivers
"Skype_is1" = Skype 1.4
"Small Block Engine Assembly" = Small Block Engine Assembly
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"VLC media player" = VLC media player 1.1.5
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-639572236-1284316945-3395171387-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 09/12/2010 20:30:37 | Computer Name = YOUR-F42298D1A0 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.

Error - 09/12/2010 20:41:11 | Computer Name = YOUR-F42298D1A0 | Source = Bonjour Service | ID = 100
Description =

Error - 09/12/2010 20:54:52 | Computer Name = YOUR-F42298D1A0 | Source = Bonjour Service | ID = 100
Description =

Error - 10/12/2010 10:32:23 | Computer Name = YOUR-F42298D1A0 | Source = Application Hang | ID = 1002
Description = Hanging application ahc.exe, version 2.0.480.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/12/2010 10:32:46 | Computer Name = YOUR-F42298D1A0 | Source = Application Hang | ID = 1002
Description = Hanging application ahc.exe, version 2.0.480.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 12/12/2010 19:00:07 | Computer Name = YOUR-F42298D1A0 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.17.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 12/12/2010 19:01:42 | Computer Name = YOUR-F42298D1A0 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.17.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 12/12/2010 19:03:16 | Computer Name = YOUR-F42298D1A0 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.17.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 12/12/2010 19:03:21 | Computer Name = YOUR-F42298D1A0 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.17.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 12/12/2010 19:03:30 | Computer Name = YOUR-F42298D1A0 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.17.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 09/12/2010 21:01:22 | Computer Name = YOUR-F42298D1A0 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 09/12/2010 21:01:22 | Computer Name = YOUR-F42298D1A0 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.CRT. Reference error
message: The referenced assembly is not installed on your system. .

Error - 09/12/2010 21:01:22 | Computer Name = YOUR-F42298D1A0 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Safari\Safari.exe.
Reference
error message: The operation completed successfully. .

Error - 09/12/2010 21:01:39 | Computer Name = YOUR-F42298D1A0 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 09/12/2010 21:01:39 | Computer Name = YOUR-F42298D1A0 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.CRT. Reference error
message: The referenced assembly is not installed on your system. .

Error - 09/12/2010 21:01:39 | Computer Name = YOUR-F42298D1A0 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Safari\Safari.exe.
Reference
error message: The operation completed successfully. .

Error - 12/12/2010 17:57:11 | Computer Name = YOUR-F42298D1A0 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 12/12/2010 18:47:46 | Computer Name = YOUR-F42298D1A0 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 12/12/2010 18:47:46 | Computer Name = YOUR-F42298D1A0 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.CRT. Reference error
message: The referenced assembly is not installed on your system. .

Error - 12/12/2010 18:47:46 | Computer Name = YOUR-F42298D1A0 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Safari\Safari.exe.
Reference
error message: The operation completed successfully. .


< End of report >
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hmm OK lets get the big guns on the job.. Do you use a router ?

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    Posted Image

  • If an infected file is detected, the default action will be Cure, click on Continue.


    Posted Image

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    Posted Image

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    Posted Image

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

THEN

Download ComboFix from one of these locations:


Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • 0

#5
gentlecarlos

gentlecarlos

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi again.
sorry have been away from the computer and have just run the scans you asked for.
TDSkiller has nothing to report. I will attach the report for combofix.
In reply to your question about the router yes i am using a router via my wifi on my laptop.
Thanks again. Carl
ComboFix 10-12-13.02 - carl gentleman 14/12/2010 17:29:38.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1526.818 [GMT 0:00]
Running from: c:\documents and settings\carl gentleman\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\carl gentleman\Application Data\PriceGong
c:\documents and settings\carl gentleman\Application Data\PriceGong\Data\mru.xml
c:\program files\RegGenie
c:\program files\RegGenie\Backups\40502.8239666435
c:\program files\RegGenie\Backups\40502.8301992824
c:\program files\RegGenie\RegGenie.ini

.
((((((((((((((((((((((((( Files Created from 2010-11-14 to 2010-12-14 )))))))))))))))))))))))))))))))
.

2010-12-13 22:24 . 2010-12-13 22:24 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2010-12-13 22:15 . 2010-12-13 22:15 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-12-13 22:12 . 2010-12-13 22:15 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2010-12-13 22:06 . 2001-08-17 13:53 6784 -c--a-w- c:\windows\system32\dllcache\serscan.sys
2010-12-13 22:06 . 2001-08-17 13:53 6784 ----a-w- c:\windows\system32\drivers\serscan.sys
2010-12-13 22:04 . 2008-10-24 02:34 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-12-13 22:04 . 2008-10-24 02:34 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2010-12-13 22:03 . 2008-10-24 11:48 321536 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp696.dll
2010-12-13 22:03 . 2008-10-24 11:48 118272 ----a-w- c:\windows\system32\hpz3l696.dll
2010-12-13 22:03 . 2008-10-24 02:35 271704 ----a-r- c:\windows\system32\hpzids01.dll
2010-12-13 22:03 . 2008-10-24 02:34 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2010-12-13 22:03 . 2008-10-24 02:34 372736 ----a-r- c:\windows\system32\hppldcoi.dll
2010-12-13 22:03 . 2008-10-24 02:34 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-12-13 22:03 . 2008-10-24 02:34 737280 ----a-r- c:\windows\system32\hposwia_p01a.dll
2010-12-13 22:03 . 2008-10-24 02:34 974848 ----a-r- c:\windows\system32\hpost_p01a.dll
2010-12-13 22:03 . 2008-10-24 02:34 307200 ----a-r- c:\windows\system32\hposc_p01a.dll
2010-12-13 22:00 . 2010-12-13 22:03 -------- d-----w- c:\windows\LastGood
2010-12-13 21:59 . 2010-12-13 21:59 -------- d-----w- c:\program files\Common Files\HP
2010-12-13 21:59 . 2010-12-13 21:59 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-12-13 21:59 . 2010-12-13 21:59 -------- d-----w- c:\program files\Hewlett-Packard
2010-12-13 21:58 . 2010-12-13 22:20 -------- d-----w- c:\program files\HP
2010-12-13 21:58 . 2008-04-14 00:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-12-13 21:58 . 2008-04-14 00:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-12-13 21:58 . 2008-04-14 00:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-12-13 21:58 . 2008-04-14 00:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-12-13 21:58 . 2008-04-14 00:15 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-12-13 21:58 . 2008-04-14 00:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-12-10 00:34 . 2010-12-10 00:34 -------- d-----w- c:\program files\Safari
2010-12-10 00:34 . 2010-12-10 00:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-12-10 00:21 . 2010-12-10 00:21 -------- d-----w- c:\program files\Abexo
2010-12-09 23:42 . 2010-12-09 23:42 -------- d-----w- c:\program files\Uniblue
2010-12-02 14:33 . 2010-12-08 18:09 -------- d-----w- c:\program files\Dream Aquarium
2010-12-02 11:03 . 2010-12-02 11:03 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-12-01 22:13 . 2010-12-01 22:15 -------- d-----w- c:\program files\Atlantis3D
2010-12-01 20:03 . 2010-12-01 20:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-12-01 20:03 . 2010-11-29 17:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-01 20:03 . 2010-12-01 20:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-01 20:03 . 2010-11-29 17:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-01 18:13 . 2010-12-01 18:13 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-12-01 00:22 . 2010-12-09 22:50 -------- d-----w- c:\program files\VirtualDJ
2010-11-30 22:52 . 2010-09-18 06:53 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2010-11-30 22:52 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-11-30 22:52 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-11-30 22:52 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-11-30 22:38 . 2009-08-06 19:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-11-30 22:38 . 2009-08-06 19:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-11-30 22:17 . 2010-11-30 22:17 -------- d-----w- c:\windows\Small Block Screensaver
2010-11-30 21:53 . 2010-11-30 21:53 337056 ----a-w- c:\windows\system32\ENTER.scr
2010-11-30 21:27 . 2010-11-30 21:27 -------- d-----w- C:\_OTM
2010-11-30 01:10 . 2010-12-09 22:29 12872 ----a-w- c:\windows\system32\bootdelete.exe
2010-11-29 22:18 . 2010-12-09 22:27 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-11-29 22:18 . 2010-11-29 22:18 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-11-29 22:17 . 2010-11-29 22:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-11-28 22:03 . 2010-12-10 00:06 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-11-27 14:42 . 2010-11-27 14:42 -------- d-----w- c:\program files\Microsoft Silverlight
2010-11-23 20:03 . 2010-11-23 20:03 -------- d-----w- c:\windows\Sun
2010-11-23 20:03 . 2010-11-23 20:03 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-23 20:03 . 2010-11-23 20:03 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-21 01:16 . 2010-11-21 01:16 -------- d-----w- c:\program files\VideoLAN
2010-11-20 23:34 . 2008-04-14 05:41 4255 ------w- c:\windows\system32\drivers\adv01nt5.dll
2010-11-20 23:29 . 2010-11-20 23:29 -------- d-----w- c:\windows\EHome
2010-11-20 22:53 . 2010-12-02 09:57 -------- d-----w- c:\program files\Opera
2010-11-20 20:25 . 2010-11-20 20:25 -------- d-----w- c:\program files\IObit
2010-11-20 20:03 . 2010-11-20 20:06 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2010-11-20 18:57 . 2010-11-20 18:57 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-11-19 16:18 . 2007-03-22 13:38 215144 ----a-r- c:\windows\patchw32.dll
2010-11-19 16:17 . 2007-03-22 13:38 215144 ----a-r- c:\windows\pw32a.dll
2010-11-19 00:25 . 2006-02-07 15:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2010-11-19 00:25 . 2006-02-07 15:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2010-11-19 00:25 . 2006-02-07 15:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2010-11-19 00:25 . 2006-02-07 15:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2010-11-19 00:25 . 2005-11-13 23:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2010-11-19 00:25 . 2010-11-19 00:25 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2010-11-19 00:25 . 2010-11-19 00:25 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2010-11-19 00:23 . 2010-12-13 22:00 -------- dc----w- c:\windows\system32\DRVSTORE
2010-11-19 00:23 . 2006-11-28 14:15 35704 ----a-w- c:\windows\system32\NicInst.dll
2010-11-19 00:23 . 2006-11-28 14:15 28536 ----a-w- c:\windows\system32\NicCo.dll
2010-11-18 23:15 . 2010-11-18 23:15 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-11-18 23:15 . 2010-11-18 23:15 126512 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-11-18 23:14 . 2010-12-09 22:20 -------- d-----w- c:\windows\system32\drivers\NIS
2010-11-18 23:14 . 2010-11-18 23:14 -------- d-----w- c:\program files\Norton Internet Security
2010-11-18 23:14 . 2010-11-18 23:14 -------- d-----w- c:\program files\Windows Sidebar
2010-11-18 23:14 . 2010-11-18 23:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-11-18 23:13 . 2010-11-18 23:13 -------- d-----w- c:\program files\NortonInstaller
2010-11-18 22:55 . 2010-11-18 22:55 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-11-18 22:39 . 2010-11-18 22:39 -------- d-----w- c:\program files\Conduit
2010-11-18 22:39 . 2010-11-18 22:39 -------- d-----w- C:\extensions
2010-11-18 22:39 . 2010-11-18 22:39 -------- d-----w- c:\program files\uTorrent
2010-11-17 20:26 . 2010-09-10 05:58 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-11-17 20:26 . 2010-09-10 05:58 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-11-17 20:26 . 2010-09-10 05:58 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-11-17 20:26 . 2010-09-10 05:58 1986560 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-11-17 20:26 . 2010-09-10 05:58 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-11-17 20:26 . 2010-09-10 05:58 11080192 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-11-17 20:26 . 2010-09-10 05:58 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-11-17 20:24 . 2010-11-17 20:26 -------- dc-h--w- c:\windows\ie8
2010-11-17 19:59 . 2010-11-20 23:38 -------- d-----w- c:\windows\ServicePackFiles
2010-11-17 19:57 . 2010-11-17 19:57 -------- d-----w- c:\program files\MSXML 4.0
2010-11-17 18:21 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-11-17 18:21 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-11-17 18:21 . 2010-08-26 13:39 357248 -c----w- c:\windows\system32\dllcache\srv.sys
2010-11-17 18:20 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-11-17 18:20 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-11-17 18:20 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-11-17 18:19 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-11-17 18:19 . 2010-08-27 08:02 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-11-17 18:19 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-11-17 18:18 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-11-17 18:18 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-11-17 18:18 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2010-11-17 18:18 . 2010-06-14 07:41 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2010-11-17 18:18 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-11-17 18:11 . 2009-06-10 09:19 2066432 -c----w- c:\windows\system32\dllcache\mstscax.dll
2010-11-17 18:11 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-11-17 18:08 . 2010-08-26 12:52 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-11-17 18:08 . 2010-07-12 12:55 218112 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-11-17 18:08 . 2010-11-26 00:46 -------- d-----w- C:\Update
2010-11-17 18:04 . 2010-11-17 18:04 -------- d-----w- c:\program files\Common Files\SWF Studio
2010-11-17 17:50 . 2010-11-17 17:50 -------- d-----w- c:\documents and settings\Owner
2010-11-17 17:46 . 2007-04-09 13:23 28552 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-11-17 17:46 . 2007-04-09 13:23 28040 ----a-w- c:\windows\system32\mdimon.dll
2010-11-17 17:46 . 2010-11-17 17:46 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-11-17 17:45 . 2010-11-17 17:46 -------- d-----w- c:\windows\SHELLNEW
2010-11-17 17:45 . 2010-11-17 17:45 -------- d-----w- c:\program files\Microsoft.NET
2010-11-17 17:45 . 2010-11-17 17:45 -------- d-----r- C:\MSOCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 12:23 . 2005-11-17 06:12 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2005-11-17 06:12 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2005-11-17 06:12 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2005-11-17 06:12 953856 ----a-w- c:\windows\system32\mfc40u.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\tbuTor.dll" [2010-10-18 3908192]

[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 12:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-10-18 12:26 3908192 ----a-w- c:\program files\uTorrentBar\tbuTor.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTor.dll" [2010-10-18 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-10-18 3908192]

[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\tbuTor.dll" [2010-10-18 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-10-18 3908192]

[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\carl gentleman\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-12-02 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-11-07 114688]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-06-09 6746112]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-29 14720000]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-04-29 45056]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 45056]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-29 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-29 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-29 114688]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-10-19 184320]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"PDService.exe"="c:\program files\Utimaco\SafeGuard PrivateDisk\pdservice.exe" [2004-07-06 40960]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 483328]
"VAIO Update 5"="c:\program files\Sony\VAIO Update 5\VAIOUpdt.exe" [2010-04-09 1459568]
"PrepareYourVAIO"="c:\program files\Sony\Prepare your VAIO\PYVAlert.exe" [2005-01-21 118784]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-09-27 81920]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 17:42 73728 ----a-w- c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1205000.07D\symds.sys [09/12/2010 20:41 340016]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1205000.07D\symefa.sys [09/12/2010 20:41 652336]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101123.003\BHDrvx86.sys [23/11/2010 02:20 691248]
R1 PrivateDisk;PrivateDisk;c:\windows\system32\drivers\privatediskm.sys [06/07/2004 14:07 45627]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1205000.07D\ironx86.sys [09/12/2010 20:41 136312]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\18.5.0.125\ccsvchst.exe [09/12/2010 20:39 130000]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [18/11/2010 23:39 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101210.001\IDSXpx86.sys [11/12/2010 06:49 341944]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe [17/11/2010 18:10 722288]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - HPQCXS08
*NewlyCreated* - HPQDDSVC
*NewlyCreated* - HPSLPSVC
*NewlyCreated* - NET_DRIVER_HPZ12
*NewlyCreated* - PGWYRKOG
*NewlyCreated* - PML_DRIVER_HPZ12
*Deregistered* - klmd25
*Deregistered* - pgwyrkog

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-639572236-1284316945-3395171387-1007Core.job
- c:\documents and settings\carl gentleman\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-02 11:08]

2010-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-639572236-1284316945-3395171387-1007UA.job
- c:\documents and settings\carl gentleman\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-02 11:08]

2005-11-18 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-11-18 12:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = hxxp://vcl.vaio.sony.co.jp/eu/PforVAIO.htm
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\18.5.0.125\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\VESWinlogon.dll
.
Completion time: 2010-12-14 17:37:24
ComboFix-quarantined-files.txt 2010-12-14 17:37

Pre-Run: 17,822,507,008 bytes free
Post-Run: 17,786,445,824 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - B42618226D60D4F5E60A888C083D63A3
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
If you are still getting re-directed that would suggest a router infection - On completion of these runs can you let me know whether you are still getting redirects

Next you must reset the router to its default configuration. This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).

THEN

Posted Image Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
  • 0

#7
gentlecarlos

gentlecarlos

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi again.
will have to say these procedures seem very familiar from the tutorials that i have followed before. what do have to do to sort the router problem. I do a google search an then select the site i want an then it redirects to some adult chat site or price comparison site. Are u happy its not my computer then?.
thanks Carl.
  • 0

#8
gentlecarlos

gentlecarlos

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi again.
every thing you have said is right. I have reset the router and now don't have the right passwords to access it. I have gained access on an unsecured network in range of my computer and no redirects. my computer works perfectly. how do i make my router work again coz all the settings have changed.
soz for being thick. carl
  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
When your ISP gave you the router you should also have been given a card with the access key, although resetting the router should not have affected that at all

What is your router type? As the password will have been set to default (this is how the infection got in)
  • 0

#10
gentlecarlos

gentlecarlos

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Thank you very very much for your help. I managed to contact my provider on the phone and together we managed to get the right code.
my computer accesses the net and does google searches no probs now. Cant thank you enough I wouldn't have even considered the router to be the problem.
Regards a very happy Carl.
  • 0

#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
These malware writers are getting sneaky

Looking at that I am a happy bunny ;)

I will remove my tools now and give some recommendations, but I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :D

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

Posted Image Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 23.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u23-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u23-windows-i586-p.exe and select "Run as an Administrator.")


SPRING CLEAN

Download and run Puran Disc Defragmenter

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes: It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe ;)
  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :D

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP