after recently having some malware activity on one PC detected and solved I decided to switch from AVG to MSE and scanned my other home PCs with MWBAM for any infections. the results are positive and not in a good way!
there are at least two trojans detected on my Dell desktop running W7. I believe they have not been removed successfully so far.
Main symptoms I have seen are a recent spate of low BB speeds and on pinging my internal router IP, it was forwarding to an external IP. resetting the modem solved the problem temporarily.
here are the last 3 MWB logs and the OTL log. Let me know what you advise. Thanks in advance! - Kdokeeffe
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8152
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
13/11/2011 23:01:19
mbam-log-2011-11-13 (23-01-19).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 503012
Time elapsed: 3 hour(s), 25 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Qoobox\quarantine\C\Windows\System32\dlof759.dll.vir (Trojan.Boaxxe) -> Quarantined and deleted successfully.
c:\Users\Kieran\AppData\Roaming\microsoft\Windows\templates\memory.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Users\Kieran\templates\memory.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Public\documents\Server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Public\documents\Server\server.dat (Malware.Trace) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8156
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
14/11/2011 03:29:59
mbam-log-2011-11-14 (03-29-59).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 502028
Time elapsed: 3 hour(s), 14 minute(s), 39 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8156
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
15/11/2011 02:30:19
mbam-log-2011-11-15 (02-30-19).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|M:\|Y:\|Z:\|)
Objects scanned: 637694
Time elapsed: 3 hour(s), 4 minute(s), 34 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL logfile created on: 15/11/2011 13:17:45 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Kieran\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001809 | Country: Ireland | Language: ENI | Date Format: dd/MM/yyyy
3.25 Gb Total Physical Memory | 1.38 Gb Available Physical Memory | 42.58% Memory free
6.49 Gb Paging File | 4.48 Gb Available in Paging File | 68.97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 217.78 Gb Total Space | 17.96 Gb Free Space | 8.25% Space Free | Partition Type: NTFS
Drive D: | 232.83 Gb Total Space | 3.29 Gb Free Space | 1.41% Space Free | Partition Type: NTFS
Drive E: | 15.00 Gb Total Space | 10.60 Gb Free Space | 70.67% Space Free | Partition Type: NTFS
Drive Y: | 465.76 Gb Total Space | 0.23 Gb Free Space | 0.05% Space Free | Partition Type: NTFS
Drive Z: | 465.76 Gb Total Space | 52.06 Gb Free Space | 11.18% Space Free | Partition Type: NTFS
Computer Name: DELLPC | User Name: Kieran | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Kieran\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Nokia)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\POWERISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mindjet\MindManager 9\MmReminderService.exe (Mindjet)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\cmd.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InstallShield Shared\Service\InstallShield Licensing Service.exe (Macrovision )
PRC - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
PRC - C:\Windows\System32\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Ikanos Consulting\SideTunes\itunessideshowgadget.exe ()
PRC - C:\Windows\System32\Crypserv.exe (CrypKey (Canada) Ltd.)
PRC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe (Seagate Technology LLC)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe ()
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\QualityManager.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
PRC - C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\Users\Kieran\AppData\Local\Google\Chrome\Application\15.0.874.106\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Kieran\AppData\Local\Google\Chrome\Application\15.0.874.106\pdf.dll ()
MOD - C:\Users\Kieran\AppData\Local\Google\Chrome\Application\15.0.874.106\avutil-51.dll ()
MOD - C:\Users\Kieran\AppData\Local\Google\Chrome\Application\15.0.874.106\avformat-53.dll ()
MOD - C:\Users\Kieran\AppData\Local\Google\Chrome\Application\15.0.874.106\avcodec-53.dll ()
MOD - C:\Users\Kieran\AppData\Local\Google\Chrome\Application\15.0.874.106\gcswf32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\66a5094e521e34aecd51e4bae30ac266\System.Configuration.Install.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Program Files\Google\Quick Search Box\bin\1.2.1151.245\rlz.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Mindjet\MindManager 9\zlib.dll ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Microsoft.SideShow\1.0.2.0__31bf3856ad364e35\Microsoft.SideShow.dll ()
MOD - C:\Windows\CTXFIRES.DLL ()
MOD - C:\Windows\System32\APOMngr.DLL ()
MOD - C:\Program Files\Ikanos Consulting\SideTunes\itunessideshowgadget.exe ()
MOD - C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe ()
MOD - C:\Program Files\TotalAudioConverter\axTotalConverter.dll ()
========== Win32 Services (SafeList) ==========
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) -- File not found
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) -- File not found
SRV - (Belkin High-Speed Mode Wireless G USB Network Adapter Service) -- File not found
SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (nvUpdatusService) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (NisSrv) -- C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (InstallShield Licensing Service) -- C:\Program Files\Common Files\InstallShield Shared\Service\InstallShield Licensing Service.exe (Macrovision )
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Creative ALchemy AL6 Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (CTAudSvcService) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Crypkey License) -- C:\Windows\System32\Crypserv.exe (CrypKey (Canada) Ltd.)
SRV - (GoToAssist) -- C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (Basics Service) -- C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe (Seagate Technology LLC)
SRV - (IAANTMON) Intel® -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (AcrSch2Svc) -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Acronis)
SRV - (AlertService) Intel® -- C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
SRV - (QualityManager) Intel® -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe (Intel® Corporation)
SRV - (Remote UI Service) Intel® -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe (Intel® Corporation)
SRV - (MCLServiceATL) Intel® -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (Intel® Corporation)
SRV - (DHTRACE) Intel® -- C:\Program Files\Common Files\Intel\IntelDH\bin\DHTraceController.exe (Intel® Corporation)
SRV - (ISSM) Intel® -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe (Intel® Corporation)
SRV - (NMSCore) Intel® -- C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe (Intel® Corporation)
SRV - (M1 Server) Intel® Viiv™ -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe ()
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (TOSHIBA Bluetooth Service) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (DQLWinService) -- C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
========== Driver Services (SafeList) ==========
DRV - (Avgtdix) -- File not found
DRV - (Avgrkx86) -- File not found
DRV - (AVGIDSShim) -- File not found
DRV - (AVGIDSFilter) -- File not found
DRV - (AVGIDSEH) -- File not found
DRV - (AVGIDSDriver) -- File not found
DRV - (MpKslca3b42fb) -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1F7DCC01-F227-4579-B2C6-5C64E7D99DE8}\MpKslca3b42fb.sys (Microsoft Corporation)
DRV - (SCDEmu) -- C:\Windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdnsu) -- C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (NisDrv) -- C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (vmbus) -- C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (taphss) -- C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (RTL8192su) -- C:\Windows\System32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (appliandMP) -- C:\Windows\System32\drivers\appliand.sys (Applian Technologies Inc.)
DRV - (appliand) -- C:\Windows\System32\drivers\appliand.sys (Applian Technologies Inc.)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (ha20x2k) -- C:\Windows\System32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (emupia) -- C:\Windows\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) -- C:\Windows\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) -- C:\Windows\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) -- C:\Windows\System32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\Windows\System32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) -- C:\Windows\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTEXFIFX.SYS) -- C:\Windows\System32\drivers\CTEXFIFX.SYS (Creative Technology Ltd.)
DRV - (CTEXFIFX) -- C:\Windows\System32\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV - (CTHWIUT.SYS) -- C:\Windows\System32\drivers\CTHWIUT.SYS (Creative Technology Ltd.)
DRV - (CTHWIUT) -- C:\Windows\System32\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV - (CT20XUT.SYS) -- C:\Windows\System32\drivers\CT20XUT.SYS (Creative Technology Ltd.)
DRV - (CT20XUT) -- C:\Windows\System32\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV - (ssm_mdm) -- C:\Windows\System32\drivers\ssm_mdm.sys (MCCI Corporation)
DRV - (ssm_bus) SAMSUNG Mobile USB Device II 1.0 driver (WDM) -- C:\Windows\System32\drivers\ssm_bus.sys (MCCI Corporation)
DRV - (ssm_mdfl) -- C:\Windows\System32\drivers\ssm_mdfl.sys (MCCI Corporation)
DRV - (USB_RNDIS) -- C:\Windows\System32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (e1express) Intel® -- C:\Windows\System32\drivers\e1e6232.sys (Intel Corporation)
DRV - (sptd) -- C:\Windows\System32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (NetworkX) -- C:\Windows\system32\ckldrv.sys ()
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (TSHWMDTCP) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys ()
DRV - (Tosrfusb) -- C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (pmxmouse) -- C:\Windows\System32\drivers\pmxmouse.sys (Primax Electronics Ltd.)
DRV - (pmxusblf) -- C:\Windows\System32\drivers\pmxusblf.sys (Primax Electronics Ltd.)
DRV - (nmsunidr) -- C:\Windows\System32\drivers\nmsunidr.sys (Gteko Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll File not found
FF - HKLM\Software\MozillaPlugins\@emusic.com/dlm-plugin: C:\Program Files\eMusic Download Manager\plugin\npemusic.dll (eMusic.com)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.669: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.669: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.669: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.669: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\@zylom.com/ZylomGamesPlayer: C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom)
FF - HKCU\Software\MozillaPlugins\@emusic.com/dlm-plugin: C:\Program Files\eMusic Download Manager\plugin\npemusic.dll (eMusic.com)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Kieran\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Kieran\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\Program Files\eMusic Download Manager\xulrunner\components [2011/11/10 22:02:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\Program Files\eMusic Download Manager\xulrunner\plugins [2011/11/10 22:02:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/28 09:30:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\msntoolbar@msn.com: C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\Firefox [2011/07/26 16:58:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/07/27 01:16:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/10/25 08:21:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/10 22:02:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/10 22:02:10 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/28 09:30:00 | 000,000,000 | ---D | M]
[2009/10/30 15:22:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kieran\AppData\Roaming\Mozilla\Extensions
[2009/10/30 15:22:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kieran\AppData\Roaming\Mozilla\Extensions\songbird@songbirdnest.com
[2011/10/26 01:21:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kieran\AppData\Roaming\Mozilla\Firefox\Profiles\pqgl9gps.default\extensions
[2011/10/26 01:21:40 | 000,000,000 | ---D | M] (Vuze Remote Community Toolbar) -- C:\Users\Kieran\AppData\Roaming\Mozilla\Firefox\Profiles\pqgl9gps.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/10/24 18:24:41 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/02 15:22:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/30 14:23:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/24 11:42:55 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/25 16:05:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/23 14:04:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/24 18:24:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2009/10/19 23:52:13 | 000,000,000 | ---D | M] (eMusic - Apple iTunes Support) -- C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\EXTENSIONS\DLM_ITUNES@EMUSIC.COM
[2009/10/19 23:52:13 | 000,000,000 | ---D | M] (eMusic - Nullsoft Winamp Support) -- C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\EXTENSIONS\DLM_WINAMP@EMUSIC.COM
[2009/10/19 23:52:13 | 000,000,000 | ---D | M] (eMusic - Microsoft Media Player Support) -- C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\EXTENSIONS\DLM_WMP@EMUSIC.COM
[2011/07/19 00:36:52 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2008/04/25 12:41:55 | 000,024,576 | ---- | M] (Avantstar, Inc.) -- C:\Program Files\mozilla firefox\plugins\NPQ00032.DLL
[2010/07/12 16:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2006/03/22 02:27:56 | 000,098,304 | ---- | M] (Zylom) -- C:\Program Files\mozilla firefox\plugins\npzylomgamesplayer.dll
[2010/07/20 10:00:00 | 000,086,016 | ---- | M] (Avantstar, Inc.) -- C:\Program Files\mozilla firefox\plugins\QVPLUG32.DLL
[2010/01/01 08:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Kieran\AppData\Local\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Kieran\AppData\Local\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Kieran\AppData\Local\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Quick View Plus for Windows XP and Windows 2000 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPQ00032.DLL
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Zylom Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: eMusic Remote Plugin (Enabled) = C:\Program Files\eMusic Download Manager\plugin\npemusic.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: RubbishBooks = C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\gklfihmmokekepifllhpdlkobiplpklj\2.3_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AVG Safe Search = C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1857_0\
CHR - Extension: Vuze Remote = C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\2.0.1.4_0\
CHR - Extension: Vuze Remote = C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\2.3.1.12_0\
O1 HOSTS File: ([2011/11/15 13:11:10 | 000,000,822 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 9\Mm8InternetExplorer.dll (Mindjet)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (Intel® Corporation)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DVD or CD Sharing] C:\Program Files\DVD or CD Sharing\ODSAgent.exe (Apple Inc.)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 9\MmReminderService.exe (Mindjet)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NMSSupport] C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe (Intel Corporation)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [googletalk] C:\Users\Kieran\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/532.5 (KHTML, like Gecko) Chrome/4.1.249.1036 Safari/532.5" -"http://www.atom.co.j...ge/Zinter.html" File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 9\Mm8InternetExplorer.dll (Mindjet)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6E4B2DE6-0546-49F3-8113-23325632B8A5}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FE08E2C0-E98D-4D6C-8122-8DDD076F2572}: NameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O28 - HKLM ShellExecuteHooks: {0cab0400-7395-11d0-a5e5-0020afe2fdd9} - C:\Windows\qvphook.dll (Avantstar, Inc.)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/29 08:57:26 | 000,000,032 | ---- | M] () - Y:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2005/09/29 08:57:26 | 000,000,032 | ---- | M] () - Z:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/15 08:49:25 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/11/14 12:07:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/11/13 11:48:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/11/13 11:37:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/13 11:36:59 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/11/11 02:02:41 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\PFStaticIP
[2011/11/11 01:59:51 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\APN
[2011/11/11 01:59:22 | 000,000,000 | ---D | C] -- C:\Program Files\PFStaticIP
[2011/11/10 22:02:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/11/10 22:01:55 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/11/08 22:00:32 | 000,000,000 | ---D | C] -- C:\Users\Kieran\Desktop\Tz
[2011/11/06 23:26:01 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\GRETECH
[2011/11/06 23:25:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player
[2011/11/06 23:25:23 | 000,000,000 | ---D | C] -- C:\Program Files\GRETECH
[2011/11/01 21:32:40 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{91EC8B17-9707-4024-9663-FBE3CEF86113}
[2011/11/01 21:32:29 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{9FA0390E-0D72-42CB-911D-418A4F339B8E}
[2011/11/01 20:35:30 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{F93F111E-39E4-42F2-B450-B7BD89E34D3D}
[2011/11/01 20:35:19 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{09509684-0CAE-4054-B29C-405C69B69286}
[2011/11/01 19:48:08 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{50DE5B47-3163-433B-B3A8-81584D2C1705}
[2011/11/01 19:47:53 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{FA995BBF-26E5-409F-ADD6-BB1D4E979585}
[2011/11/01 18:19:59 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\AVG2012
[2011/11/01 18:19:33 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012
[2011/10/30 11:00:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
[2011/10/30 11:00:18 | 000,000,000 | ---D | C] -- C:\Program Files\POWERISO
[2011/10/30 09:33:37 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TransMac
[2011/10/30 09:33:37 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\TransMac
[2011/10/30 09:33:37 | 000,000,000 | ---D | C] -- C:\Program Files\TransMac
[2011/10/30 09:33:01 | 000,000,000 | ---D | C] -- C:\Program Files\Pixbyte
[2011/10/30 09:20:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD or CD Sharing
[2011/10/30 09:20:33 | 000,000,000 | ---D | C] -- C:\Program Files\DVD or CD Sharing
[2011/10/30 02:14:48 | 000,000,000 | ---D | C] -- C:\Users\Kieran\Desktop\from nokia mem card
[2011/10/30 02:05:40 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\ImgBurn
[2011/10/30 01:39:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2011/10/30 01:38:56 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn
[2011/10/30 01:03:10 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicISO
[2011/10/30 01:03:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicISO
[2011/10/30 01:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\MagicISO
[2011/10/26 01:25:58 | 000,000,000 | ---D | C] -- C:\Users\Kieran\.swt
[2011/10/22 15:31:30 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{24915404-A806-4111-BBCE-1AB528CE7B3E}
[2011/10/22 15:31:19 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{19A7084C-9393-4F4B-8439-0B6C51AAEE4B}
[2011/10/21 17:39:50 | 000,000,000 | ---D | C] -- C:\Users\Kieran\Desktop\Music
[2011/10/20 14:46:50 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{DB615542-A20A-41DD-A6BC-31754765C19B}
[2011/10/20 14:46:38 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{C434913A-A1CC-4902-A8A1-C40654A00031}
[2011/10/20 12:46:30 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{F6274A0C-5DE3-4CF5-A437-9130502E445E}
[2011/10/20 12:44:38 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{AFEF832D-D07A-4E49-BC22-D3C0F99624B0}
[2011/10/20 12:44:27 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{3E03C469-8778-4189-BCF8-C39E958A0C95}
[2011/10/20 12:34:56 | 000,000,000 | ---D | C] -- C:\Users\Kieran\AppData\Local\{F329998B-9B26-4B92-9C62-CD01626BB30C}
[2011/10/18 09:27:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/18 09:26:15 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/10/18 09:22:29 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/10/18 08:05:03 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Support Center
[2010/05/05 15:53:36 | 000,060,928 | ---- | C] ( ) -- C:\Windows\System32\a3d.dll
[2010/05/05 15:32:22 | 000,012,800 | ---- | C] ( ) -- C:\Windows\System32\killapps.exe
========== Files - Modified Within 30 Days ==========
[2011/11/15 13:11:10 | 000,000,822 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/11/15 13:01:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1119982138-2822077597-1950866782-1001UA.job
[2011/11/15 12:34:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/15 10:00:11 | 000,000,506 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2011/11/15 09:00:00 | 000,000,436 | ---- | M] () -- C:\Windows\tasks\SyncBack Music Backup.job
[2011/11/15 08:53:53 | 000,011,424 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/15 08:53:53 | 000,011,424 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/15 08:49:25 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/11/15 00:34:01 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/14 19:01:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1119982138-2822077597-1950866782-1001Core.job
[2011/11/14 12:08:26 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011/11/14 12:07:42 | 000,702,142 | ---- | M] () -- C:\Windows\System32\perfh019.dat
[2011/11/14 12:07:42 | 000,666,210 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2011/11/14 12:07:42 | 000,641,796 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/11/14 12:07:42 | 000,460,018 | ---- | M] () -- C:\Windows\System32\perfh001.dat
[2011/11/14 12:07:42 | 000,377,912 | ---- | M] () -- C:\Windows\System32\perfh00D.dat
[2011/11/14 12:07:42 | 000,142,960 | ---- | M] () -- C:\Windows\System32\perfc019.dat
[2011/11/14 12:07:42 | 000,121,318 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2011/11/14 12:07:42 | 000,116,078 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/11/14 12:07:42 | 000,088,674 | ---- | M] () -- C:\Windows\System32\perfc001.dat
[2011/11/14 12:07:42 | 000,078,784 | ---- | M] () -- C:\Windows\System32\perfc00D.dat
[2011/11/14 11:42:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/14 11:42:07 | 2615,611,392 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/14 09:41:45 | 000,055,756 | ---- | M] () -- C:\Windows\System32\BMXStateBkp-{00000004-00000000-00000004-00001102-00000005-60021102}.rfx
[2011/11/14 09:41:45 | 000,055,756 | ---- | M] () -- C:\Windows\System32\BMXState-{00000004-00000000-00000004-00001102-00000005-60021102}.rfx
[2011/11/14 09:41:45 | 000,000,788 | ---- | M] () -- C:\Windows\System32\DVCState-{00000004-00000000-00000004-00001102-00000005-60021102}.rfx
[2011/11/13 11:37:03 | 000,001,033 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/11 01:59:23 | 000,000,955 | ---- | M] () -- C:\Users\Kieran\Desktop\Portforward Setup Static IP Address.lnk
[2011/11/09 18:31:49 | 003,511,976 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/11/06 23:25:36 | 000,001,075 | ---- | M] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2011/11/01 09:04:06 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/10/30 11:00:19 | 000,000,931 | ---- | M] () -- C:\Users\Public\Desktop\PowerISO.lnk
[2011/10/30 09:33:38 | 000,000,931 | ---- | M] () -- C:\Users\Kieran\Desktop\TransMac.lnk
[2011/10/30 02:11:33 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
[2011/10/30 01:39:01 | 000,001,777 | ---- | M] () -- C:\Users\Public\Desktop\ImgBurn.lnk
[2011/10/30 01:03:10 | 000,001,735 | ---- | M] () -- C:\Users\Kieran\Desktop\MagicISO.lnk
[2011/10/29 21:18:11 | 000,001,117 | ---- | M] () -- C:\Users\Kieran\Desktop\Recent Downloads.lnk
[2011/10/26 01:22:11 | 000,001,789 | ---- | M] () -- C:\Users\Public\Desktop\Vuze.lnk
[2011/10/25 08:21:02 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2011/10/22 15:16:58 | 000,000,756 | ---- | M] () -- C:\Users\Kieran\Desktop\Hazel.lnk
[2011/10/21 17:53:24 | 000,002,377 | ---- | M] () -- C:\Users\Kieran\Desktop\Sunset.Blvd.1950.480x352.25fps.817kbs.96mps.MultiSub.WunSeeDee.avi - Shortcut.lnk
[2011/10/21 17:42:32 | 000,000,650 | ---- | M] () -- C:\Users\Kieran\Desktop\Movies.lnk
[2011/10/18 09:28:08 | 000,002,503 | ---- | M] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
========== Files Created - No Company Name ==========
[2011/11/14 12:08:26 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011/11/14 12:07:35 | 000,001,859 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/11/13 11:37:03 | 000,001,033 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/11 01:59:23 | 000,000,955 | ---- | C] () -- C:\Users\Kieran\Desktop\Portforward Setup Static IP Address.lnk
[2011/11/06 23:25:36 | 000,001,075 | ---- | C] () -- C:\Users\Kieran\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2011/10/30 11:00:19 | 000,000,931 | ---- | C] () -- C:\Users\Public\Desktop\PowerISO.lnk
[2011/10/30 09:33:38 | 000,000,931 | ---- | C] () -- C:\Users\Kieran\Desktop\TransMac.lnk
[2011/10/30 02:11:33 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
[2011/10/30 01:39:01 | 000,001,777 | ---- | C] () -- C:\Users\Public\Desktop\ImgBurn.lnk
[2011/10/30 01:39:00 | 000,001,789 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
[2011/10/30 01:03:10 | 000,001,735 | ---- | C] () -- C:\Users\Kieran\Desktop\MagicISO.lnk
[2011/10/29 21:18:11 | 000,001,117 | ---- | C] () -- C:\Users\Kieran\Desktop\Recent Downloads.lnk
[2011/10/26 01:22:11 | 000,001,789 | ---- | C] () -- C:\Users\Public\Desktop\Vuze.lnk
[2011/10/22 15:16:58 | 000,000,756 | ---- | C] () -- C:\Users\Kieran\Desktop\Hazel.lnk
[2011/10/21 17:53:24 | 000,002,377 | ---- | C] () -- C:\Users\Kieran\Desktop\Sunset.Blvd.1950.480x352.25fps.817kbs.96mps.MultiSub.WunSeeDee.avi - Shortcut.lnk
[2011/10/21 17:42:32 | 000,000,650 | ---- | C] () -- C:\Users\Kieran\Desktop\Movies.lnk
[2011/10/18 08:05:13 | 000,000,564 | ---- | C] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/10/18 08:05:11 | 000,000,506 | ---- | C] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2011/07/26 16:38:35 | 000,231,210 | ---- | C] () -- C:\Windows\hpwins23.dat.temp
[2011/04/19 09:54:03 | 000,000,094 | ---- | C] () -- C:\Users\Kieran\AppData\Local\fusioncache.dat
[2011/03/04 15:01:56 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/03/04 15:01:54 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/02/25 15:29:17 | 002,529,622 | ---- | C] () -- C:\Users\Kieran\AppData\Local\[j0005]-[p02].bmp
[2011/02/25 15:29:14 | 002,529,622 | ---- | C] () -- C:\Users\Kieran\AppData\Local\[j0005]-[p01].bmp
[2011/01/24 23:00:33 | 000,272,392 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2011/01/24 22:25:06 | 000,061,909 | ---- | C] () -- C:\Users\Kieran\AppData\Roaming\Comma Separated Values (Windows).ADR
[2011/01/13 03:37:13 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011/01/13 03:37:12 | 000,810,496 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011/01/13 03:37:12 | 000,183,808 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/01/13 03:37:12 | 000,080,896 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/01/13 03:37:12 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/01/05 01:42:22 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011/01/05 01:42:22 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011/01/05 01:18:17 | 000,000,004 | ---- | C] () -- C:\Windows\vx86036.dat
[2011/01/04 12:04:28 | 000,000,071 | ---- | C] () -- C:\Windows\Crypkey.ini
[2011/01/04 12:03:37 | 000,019,584 | ---- | C] () -- C:\Windows\System32\Ckldrv.sys
[2011/01/04 12:03:36 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe
[2011/01/04 12:03:36 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll
[2011/01/04 12:03:36 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe
[2010/10/20 13:43:45 | 000,000,010 | ---- | C] () -- C:\Users\Kieran\AppData\Roaming\install
[2010/10/07 13:46:13 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/10/07 13:46:13 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/10/07 13:46:13 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/10/07 13:46:13 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/10/07 13:46:13 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/07/14 02:45:03 | 005,653,224 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2010/05/12 22:16:31 | 000,000,000 | ---- | C] () -- C:\Users\Kieran\AppData\Local\prvlcl.dat
[2010/05/05 16:34:20 | 000,027,039 | ---- | C] () -- C:\Windows\System32\instwdm.ini
[2010/05/05 16:34:16 | 000,000,054 | ---- | C] () -- C:\Windows\System32\ctzapxx.ini
[2010/05/05 15:51:04 | 000,002,560 | ---- | C] () -- C:\Windows\System32\CtxfiRes.dll
[2010/05/05 15:40:40 | 000,321,512 | ---- | C] () -- C:\Windows\System32\ctdlang.dat
[2010/05/05 15:40:40 | 000,056,509 | ---- | C] () -- C:\Windows\System32\ctdnlstr.dat
[2010/05/05 15:35:34 | 000,016,384 | ---- | C] () -- C:\Windows\System32\regplib.exe
[2010/05/05 15:32:26 | 000,007,680 | ---- | C] () -- C:\Windows\System32\enlocstr.exe
[2010/04/28 09:29:35 | 000,023,113 | ---- | C] () -- C:\Windows\hpqins15.dat
[2010/04/20 21:08:31 | 000,001,843 | ---- | C] () -- C:\Windows\hpwmdl23.dat.temp
[2010/04/20 17:20:46 | 000,228,882 | ---- | C] () -- C:\Windows\hpwins23.dat
[2010/01/11 03:16:24 | 000,040,960 | ---- | C] () -- C:\Windows\DelPiv.exe
[2010/01/06 02:27:32 | 000,000,028 | ---- | C] () -- C:\Windows\v2d.INI
[2009/12/03 01:19:28 | 000,460,018 | ---- | C] () -- C:\Windows\System32\perfh001.dat
[2009/12/03 01:19:28 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2009/12/03 01:19:28 | 000,289,060 | ---- | C] () -- C:\Windows\System32\perfi001.dat
[2009/12/03 01:19:28 | 000,088,674 | ---- | C] () -- C:\Windows\System32\perfc001.dat
[2009/12/03 01:19:28 | 000,042,056 | ---- | C] () -- C:\Windows\System32\perfd001.dat
[2009/12/03 01:19:27 | 000,666,210 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2009/12/03 01:19:27 | 000,121,318 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2009/12/03 01:19:27 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
[2009/12/03 01:12:54 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat
[2009/12/03 01:12:53 | 000,702,142 | ---- | C] () -- C:\Windows\System32\perfh019.dat
[2009/12/03 01:12:53 | 000,142,960 | ---- | C] () -- C:\Windows\System32\perfc019.dat
[2009/12/03 01:12:53 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat
[2009/12/03 01:06:35 | 000,229,316 | ---- | C] () -- C:\Windows\System32\perfi00D.dat
[2009/12/03 01:06:34 | 000,377,912 | ---- | C] () -- C:\Windows\System32\perfh00D.dat
[2009/12/03 01:06:34 | 000,078,784 | ---- | C] () -- C:\Windows\System32\perfc00D.dat
[2009/12/03 01:06:34 | 000,032,166 | ---- | C] () -- C:\Windows\System32\perfd00D.dat
[2009/11/25 12:08:37 | 000,000,029 | ---- | C] () -- C:\Windows\sfbm.INI
[2009/11/19 01:28:42 | 000,000,017 | ---- | C] () -- C:\Users\Kieran\AppData\Local\resmon.resmoncfg
[2009/11/06 09:17:18 | 000,002,075 | ---- | C] () -- C:\Windows\hpwmdl23.dat
[2009/10/16 02:32:25 | 000,028,160 | ---- | C] () -- C:\Users\Kieran\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/14 16:49:29 | 000,000,000 | ---- | C] () -- C:\Users\Kieran\AppData\Roaming\wklnhst.dat
[2009/10/11 04:32:18 | 000,021,924 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2009/10/11 03:48:16 | 000,148,480 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL
[2009/10/11 03:48:16 | 000,073,728 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/14 04:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 04:33:53 | 003,511,976 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 02:05:48 | 000,641,796 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 02:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 02:05:48 | 000,116,078 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 02:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 02:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 02:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 23:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 23:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 23:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/07/13 23:11:12 | 001,659,648 | ---- | C] () -- C:\Windows\System32\nywfvpov.dat
[2009/07/13 23:11:12 | 000,633,600 | ---- | C] () -- C:\Windows\System32\vipixuov.dat
[2009/07/13 23:11:12 | 000,149,248 | ---- | C] () -- C:\Windows\System32\xhgataiq.dat
[2009/07/13 23:11:12 | 000,149,248 | ---- | C] () -- C:\Windows\System32\cqhesjbg.dat
[2009/07/13 23:11:12 | 000,145,152 | ---- | C] () -- C:\Windows\System32\dputlcsx.dat
[2009/07/13 23:11:12 | 000,050,432 | ---- | C] () -- C:\Windows\System32\chjacfud.dat
[2009/07/13 23:11:12 | 000,039,680 | ---- | C] () -- C:\Windows\System32\nrhdxyju.dat
[2009/07/06 11:05:26 | 000,059,791 | ---- | C] () -- C:\Users\Kieran\AppData\Roaming\Artwork.jpg
[2009/06/18 03:34:49 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/06/10 21:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/06/03 11:19:42 | 000,002,560 | ---- | C] () -- C:\Windows\CTXFIRES.DLL
[2009/05/26 09:56:08 | 000,000,297 | ---- | C] () -- C:\Windows\System32\kill.ini
[2008/10/07 00:09:13 | 000,066,560 | ---- | C] () -- C:\Windows\MOTA113.exe
[2008/10/07 00:09:12 | 000,502,784 | ---- | C] () -- C:\Windows\x2.64.exe
[2008/10/07 00:09:12 | 000,240,128 | ---- | C] () -- C:\Windows\System32\x.264.exe
[2008/10/07 00:09:12 | 000,217,073 | ---- | C] () -- C:\Windows\meta4.exe
[2008/10/07 00:09:12 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2008/09/14 22:42:28 | 000,001,076 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2008/09/14 22:17:35 | 000,000,000 | ---- | C] () -- C:\Windows\PROTOCOL.INI
[2008/09/14 21:37:22 | 000,000,000 | ---- | C] () -- C:\Windows\tosOBEX.INI
[2008/02/29 03:12:36 | 000,000,672 | ---- | C] () -- C:\Windows\mozver.dat
[2008/02/22 17:22:25 | 000,024,206 | ---- | C] () -- C:\Users\Kieran\AppData\Roaming\UserTile.png
[2008/02/21 11:34:49 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2008/02/16 07:46:49 | 000,876,544 | ---- | C] () -- C:\Windows\System32\TEACico2.dll
[2008/02/16 00:00:12 | 000,303,104 | ---- | C] () -- C:\Windows\System32\FontZoom.exe
[2008/02/16 00:00:12 | 000,131,062 | ---- | C] () -- C:\Windows\System32\DellPM.ini
[2007/10/25 17:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2007/06/21 09:49:24 | 000,118,784 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2006/06/23 10:09:34 | 000,019,968 | R--- | C] () -- C:\Windows\System32\cpuinf32.dll
[2005/07/22 20:30:18 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
[2002/09/17 23:45:00 | 000,119,808 | ---- | C] () -- C:\Windows\lsb_un20.exe
========== LOP Check ==========
[2011/02/17 15:34:03 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\.minecraft
[2010/09/07 23:52:35 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\.oit
[2009/12/15 10:22:42 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\.purple
[2010/08/26 11:31:45 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Apowersoft
[2010/02/22 20:15:42 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Audacity
[2011/11/01 18:19:59 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\AVG2012
[2010/10/07 13:32:10 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\AVG9
[2011/11/14 23:25:23 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Azureus
[2010/05/20 16:34:41 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Blitware
[2009/05/26 02:40:12 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\DAEMON Tools
[2009/10/11 04:18:36 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\DAEMON Tools Lite
[2010/07/17 19:02:23 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\dBpoweramp
[2009/10/11 04:18:36 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\eMusic
[2010/08/25 20:32:48 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\GrabPro
[2009/10/11 04:18:37 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\gtk-2.0
[2011/10/30 02:05:40 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\ImgBurn
[2009/12/07 14:37:47 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Intermedia Software
[2011/04/19 09:53:01 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\iPodSoft
[2009/10/11 04:18:37 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Leadertech
[2011/01/29 17:33:42 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\ML
[2011/11/15 08:54:54 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Nokia
[2009/10/11 04:19:02 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\NSeries
[2011/01/27 23:20:29 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Orbit
[2011/10/30 02:11:42 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\PC Suite
[2010/12/14 11:50:59 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\PCDr
[2008/02/22 17:22:25 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\PeerNetworking
[2011/11/12 01:28:42 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\PFStaticIP
[2010/08/25 20:34:47 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\ProgSense
[2009/05/19 20:26:42 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Publish Providers
[2011/04/19 09:54:03 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Purple Ghost Software, Inc
[2011/01/25 10:23:15 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Raptr
[2011/04/19 02:07:26 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\rockbox.org
[2011/01/05 01:41:45 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Samsung
[2011/06/18 14:25:18 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Softplicity
[2010/10/09 02:32:41 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Songbird2
[2009/10/11 04:19:04 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Sony
[2009/02/24 23:02:19 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\TeamViewer
[2011/01/03 11:50:08 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Template
[2009/10/11 04:19:04 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/12/03 16:53:56 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/10/11 04:19:06 | 000,000,000 | ---D | M] -- C:\Users\Kieran\AppData\Roaming\Wizards of the Coast
[2011/11/01 09:04:06 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/09/01 08:50:21 | 000,032,620 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/11/15 09:00:00 | 000,000,436 | ---- | M] () -- C:\Windows\Tasks\SyncBack Music Backup.job
[2011/11/15 10:00:11 | 000,000,506 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
< End of report >