I'm hoping one of you is up for a challenge, three weeks to the day I have been battling with this one and my white flag is definitely up.
I now know I need help.
It all started with an unexpected crash of my kaspersky while doing an upgrade from 2011 to 2013.
I guess the virus had been sitting there waiting for the opportunity.
progressively the virus over the next few days turned off mouse support cd/dvd and networking of any kind including ftp
it doesn't seem to care about usb 3.0 so I do have the ability to use usb stick and usb drives to pass files and programs back and forwards.
so far I have tried malware bytes, msse, combofix, gmer, drweb, and numerous others.
it will not let me do a restore.
I have replaced earlier versions of the hive to no avail.
I have tried to do a repair install which so far has not been possible indeed at 4 am one morning I ended up installing a completely separate version of windows instead of doing a repair install , that will teach me not to mess with computers at ridiculous hours of the morning.
Here is my log hopefully you guys can help.
OTL logfile created on: 15/12/2012 10:18:54 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.37 Gb Total Physical Memory | 2.77 Gb Available Physical Memory | 82.23% Memory free
7.24 Gb Paging File | 6.72 Gb Available in Paging File | 92.78% Paging File free
Paging file location(s): C:\pagefile.sys 4096 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.51 Gb Total Space | 588.18 Gb Free Space | 63.14% Space Free | Partition Type: NTFS
Drive E: | 59.63 Gb Total Space | 57.05 Gb Free Space | 95.67% Space Free | Partition Type: NTFS
Computer Name: USER-24DEB876B6 | User Name: paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/12/15 10:14:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\OTL.exe
PRC - [2012/11/20 21:29:38 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/10/20 05:25:58 | 010,122,112 | ---- | M] (HLW Software Development GmbH) -- C:\Program Files\iTap mobile\Connect\iTapMobileConnect.exe
PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/09/12 17:19:44 | 000,947,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/07/27 17:57:12 | 002,163,064 | ---- | M] (Condusiv Technologies) -- C:\Program Files\Condusiv Technologies\Diskeeper\DkService.exe
PRC - [2011/09/20 14:37:36 | 000,582,656 | ---- | M] () -- C:\Program Files\Common Files\Materialise\LicenseFiles6\LicSrv60.exe
PRC - [2011/09/02 09:42:34 | 000,028,672 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\nwtray.exe
PRC - [2011/05/30 22:09:00 | 000,581,120 | ---- | M] () -- C:\Program Files\Autodesk\Moldflow Adviser 2012\bin\amajm.exe
PRC - [2011/05/04 13:14:38 | 000,081,408 | ---- | M] () -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2010/12/07 15:28:06 | 000,579,384 | ---- | M] (Autodesk, Inc.) -- C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe
PRC - [2010/07/09 11:40:24 | 000,065,856 | ---- | M] (Nalpeiron Ltd.) -- C:\WINDOWS\system32\NLSSRV32.EXE
PRC - [2010/07/09 11:40:14 | 000,196,928 | ---- | M] (Nitro PDF Software) -- C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
PRC - [2010/06/09 11:41:30 | 001,726,976 | ---- | M] () -- C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
PRC - [2010/03/10 13:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2009/10/09 04:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
PRC - [2009/09/17 00:03:00 | 000,369,952 | ---- | M] (SafeNet, Inc.) -- C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
PRC - [2009/09/17 00:00:02 | 000,292,128 | ---- | M] (SafeNet, Inc.) -- C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe
PRC - [2009/03/12 17:36:24 | 000,086,016 | ---- | M] () -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2011/09/20 14:37:36 | 000,582,656 | ---- | M] () -- C:\Program Files\Common Files\Materialise\LicenseFiles6\LicSrv60.exe
MOD - [2011/09/02 09:42:26 | 000,262,227 | ---- | M] () -- C:\WINDOWS\system32\nwshlxnt.dll
MOD - [2011/09/02 09:39:42 | 000,110,592 | ---- | M] () -- C:\WINDOWS\system32\nls\ENGLISH\nwshlxnr.dll
MOD - [2011/06/24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/05/30 22:09:00 | 000,581,120 | ---- | M] () -- C:\Program Files\Autodesk\Moldflow Adviser 2012\bin\amajm.exe
MOD - [2011/05/04 13:14:38 | 000,081,408 | ---- | M] () -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
MOD - [2011/03/02 11:40:51 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2010/07/29 17:19:04 | 000,234,496 | ---- | M] () -- C:\Program Files\Portable\Total Video Converter - HD version 3.71\TVCShellExt.dll
MOD - [2010/07/09 11:40:28 | 000,115,008 | ---- | M] () -- C:\Program Files\Nitro PDF\Professional\NPShellExtension.dll
MOD - [2010/07/04 21:32:38 | 000,010,752 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerCOM.dll
MOD - [2010/06/09 11:41:30 | 001,726,976 | ---- | M] () -- C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
MOD - [2009/03/12 17:36:24 | 000,086,016 | ---- | M] () -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
MOD - [2008/08/26 12:07:18 | 000,133,632 | ---- | M] () -- C:\Program Files\Atomic Alarm Clock\Clock.dll
MOD - [2005/06/24 15:13:48 | 000,407,552 | ---- | M] () -- C:\Program Files\Extension Changer\extcontext.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe -- (AVP)
SRV - [2012/11/20 21:29:38 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/11/18 01:54:37 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/10/27 17:05:50 | 000,081,696 | ---- | M] () [Auto | Stopped] -- C:\Program Files\HDD Regenerator\hrsrv.exe -- (hddrsrv)
SRV - [2012/10/24 17:50:38 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/20 05:25:58 | 010,122,112 | ---- | M] (HLW Software Development GmbH) [Auto | Running] -- C:\Program Files\iTap mobile\Connect\iTapMobileConnect.exe -- (itap-mobile-connect)
SRV - [2012/09/20 13:28:48 | 030,785,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/07/27 17:57:12 | 002,163,064 | ---- | M] (Condusiv Technologies) [Auto | Running] -- C:\Program Files\Condusiv Technologies\Diskeeper\DkService.exe -- (Diskeeper)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/05/15 10:18:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2011/10/09 08:30:57 | 000,079,360 | ---- | M] (SolidWorks) [On_Demand | Stopped] -- C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service)
SRV - [2011/10/09 08:30:56 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/09/27 03:00:24 | 000,089,160 | ---- | M] (Dassault Systèmes SolidWorks Corp.) [On_Demand | Stopped] -- C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe -- (CoordinatorServiceHost)
SRV - [2011/09/20 14:37:36 | 000,582,656 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\Materialise\LicenseFiles6\LicSrv60.exe -- (MatLocalLicenceServer60)
SRV - [2011/09/02 09:42:30 | 000,053,339 | ---- | M] (Novell, Inc.) [On_Demand | Stopped] -- C:\WINDOWS\system32\cusrvc.exe -- (cusrvc)
SRV - [2011/09/01 23:10:08 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\srvany.exe -- (KMService)
SRV - [2011/08/17 18:42:58 | 000,090,168 | ---- | M] (Mentor Graphics Corporation) [On_Demand | Stopped] -- C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe -- (Remote Solver for Flow Simulation 2012)
SRV - [2011/05/30 22:09:00 | 000,581,120 | ---- | M] () [Auto | Running] -- C:\Program Files\Autodesk\Moldflow Adviser 2012\bin\amajm.exe -- (amajm2012)
SRV - [2011/05/04 13:14:38 | 000,081,408 | ---- | M] () [Auto | Running] -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2010/12/07 15:28:06 | 000,579,384 | ---- | M] (Autodesk, Inc.) [Auto | Running] -- C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe -- (mitsijm2012)
SRV - [2010/07/09 11:40:24 | 000,065,856 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\WINDOWS\system32\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2010/07/09 11:40:14 | 000,196,928 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe -- (NitroDriverReadSpool)
SRV - [2010/06/25 17:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd)
SRV - [2010/03/10 13:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/10/09 04:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0)
SRV - [2009/09/17 06:06:00 | 001,246,496 | ---- | M] (SafeNet, Inc) [Disabled | Stopped] -- C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe -- (SentinelProtectionServer)
SRV - [2009/09/17 00:03:00 | 000,369,952 | ---- | M] (SafeNet, Inc.) [Auto | Running] -- C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe -- (SentinelKeysServer)
SRV - [2009/09/17 00:00:02 | 000,292,128 | ---- | M] (SafeNet, Inc.) [Auto | Running] -- C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe -- (SentinelSecurityRuntime)
SRV - [2009/03/12 17:36:24 | 000,086,016 | ---- | M] () [Auto | Running] -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe -- (mi-raysat_3dsmax2010_32)
SRV - [2005/09/23 06:01:16 | 002,799,808 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon80)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (SANDRA)
DRV - File not found [Kernel | Boot | Stopped] -- System32\Drivers\PxHelp20.sys -- (PxHelp20)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\PciCon.sys -- (PciCon)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\klmouflt.sys -- (klmouflt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\klim5.sys -- (klim5)
DRV - File not found [File_System | System | Stopped] -- system32\DRIVERS\klif.sys -- (KLIF)
DRV - File not found [Kernel | System | Stopped] -- system32\DRIVERS\kl2.sys -- (kl2)
DRV - File not found [Kernel | Boot | Stopped] -- system32\DRIVERS\kl1.sys -- (KL1)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (FNETURPX)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\user\LOCALS~1\Temp\HBCD\PCWizard\pcwiz_x32.sys -- (cpuz134)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | Boot | Stopped] -- system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2012/12/15 10:16:59 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C18D307C-83F3-4A99-9C0F-7F8DCD5BB8D7}\MpKsl9f1cdc81.sys -- (MpKsl9f1cdc81)
DRV - [2012/08/22 22:15:54 | 000,231,760 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2012/07/09 14:54:56 | 000,085,328 | ---- | M] (Condusiv Technologies) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\DKTLFSMF.sys -- (DKTLFSMF)
DRV - [2012/07/03 19:55:18 | 000,124,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvhda32.sys -- (NVHDA)
DRV - [2012/06/26 17:44:02 | 000,041,008 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dsu2cam.sys -- (DSU2CAM)
DRV - [2012/06/18 19:14:42 | 000,044,496 | ---- | M] (Condusiv Technologies) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKRtWrt.sys -- (DKRtWrt)
DRV - [2012/05/23 15:36:50 | 000,275,760 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\mv91xx.sys -- (mv91xx)
DRV - [2012/04/09 15:27:34 | 000,299,024 | ---- | M] (EldoS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cbfs3.sys -- (cbfs3)
DRV - [2011/11/10 03:42:12 | 007,493,120 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2011/09/08 22:47:18 | 000,460,800 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (hardlock)
DRV - [2011/09/08 22:47:17 | 000,047,616 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Haspnt.sys -- (Haspnt)
DRV - [2011/09/02 09:42:36 | 000,006,128 | ---- | M] (Novell, Inc.) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\NetWare\nwsns.sys -- (NWSNS)
DRV - [2011/09/02 09:42:34 | 000,023,232 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\NetWare\nwsap.sys -- (NWSAP)
DRV - [2011/09/02 09:42:34 | 000,020,208 | ---- | M] (Novell, Inc.) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\NetWare\nwslp.sys -- (NWSLP)
DRV - [2011/09/02 09:42:34 | 000,018,353 | ---- | M] (Novell, Inc.) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\NetWare\nwdhcp.sys -- (NWDHCP)
DRV - [2011/09/02 09:42:34 | 000,017,664 | ---- | M] (Novell, Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\NetWare\nwfilter.sys -- (NWFILTER)
DRV - [2011/09/02 09:42:34 | 000,009,297 | ---- | M] (Novell, Inc.) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\NetWare\nwhost.sys -- (NWHOST)
DRV - [2011/09/02 09:42:32 | 000,045,824 | ---- | M] (Novell, Inc.) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\NetWare\nwdns.sys -- (NWDNS)
DRV - [2011/09/02 09:42:32 | 000,038,603 | ---- | M] (Novell, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nicm.sys -- (NICM)
DRV - [2011/09/02 09:42:32 | 000,029,440 | ---- | M] (Novell, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\NetWare\resmgr.sys -- (RESMGR)
DRV - [2011/09/02 09:42:30 | 000,058,496 | ---- | M] (Novell, Inc.) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\NetWare\nwsipx32.sys -- (NWSIPX32)
DRV - [2011/09/02 09:42:28 | 000,185,216 | ---- | M] (Novell, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\NetWare\srvloc.sys -- (SRVLOC)
DRV - [2011/09/02 09:42:26 | 000,553,216 | ---- | M] (Novell, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\NetWare\nwfs.sys -- (NetwareWorkstation)
DRV - [2011/07/29 13:54:56 | 000,013,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\epmntdrv.sys -- (epmntdrv)
DRV - [2011/07/29 13:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2011/07/06 18:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/06/15 08:23:56 | 000,060,156 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2011/05/21 20:33:10 | 000,192,128 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\xhcdrv.sys -- (xhcdrv)
DRV - [2010/09/30 12:59:16 | 000,141,568 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV - [2010/09/30 12:59:16 | 000,061,824 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nusb3hub.sys -- (nusb3hub)
DRV - [2010/06/22 17:01:52 | 000,021,248 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\htcnprot.sys -- (htcnprot)
DRV - [2010/02/09 04:56:10 | 000,222,248 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2009/11/19 13:33:20 | 000,051,200 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2009/09/17 16:01:18 | 000,579,840 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\emBDA.sys -- (USB28xxBGA)
DRV - [2009/09/17 16:00:38 | 000,543,744 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\emOEM.sys -- (USB28xxOEM)
DRV - [2009/08/19 12:05:56 | 000,100,368 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2009/07/27 00:49:22 | 000,019,456 | ---- | M] (BUFFALO INC.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bfturbov.sys -- (bfturbov)
DRV - [2009/06/18 17:04:20 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2009/06/09 23:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2008/04/14 00:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE)
DRV - [2008/04/13 18:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2006/04/01 05:33:32 | 000,163,712 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vinyl97.sys -- (VIAudio)
DRV - [2005/01/25 15:45:50 | 000,035,107 | ---- | M] (Winternals) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VDiskBus.sys -- (vdiskbus)
DRV - [2003/04/30 15:59:40 | 000,259,528 | ---- | M] (Hauppauge Computer Works) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Nuvision.sys -- (NuVision)
DRV - [2002/12/16 18:11:02 | 000,026,120 | ---- | M] (Rainbow Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SNTNLUSB.SYS -- (Sntnlusb)
DRV - [2002/12/16 18:11:02 | 000,009,949 | ---- | M] () [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\SENTINEL.HLP -- (Sentinel)
DRV - [2002/01/12 16:30:34 | 000,003,567 | ---- | M] (Beyond Logic http://www.beyondlogic.org) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PortTalk.sys -- (PortTalk)
DRV - [2001/08/17 13:05:48 | 000,314,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CamDrO21.sys -- (PhilCam8116)
DRV - [2001/08/17 12:49:42 | 000,322,432 | ---- | M] (Matrox Graphics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\G400m.sys -- (G400)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.google.co.uk/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..CT2481032.browser.search.defaultthis.engineName: true
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk"
FF - prefs.js..extensions.enabledAddons: [email protected]:1.0.0.1227P.314153
FF - prefs.js..extensions.enabledAddons: [email protected]:1.1.22
FF - prefs.js..extensions.enabledAddons: [email protected]:3.8.0
FF - prefs.js..extensions.enabledAddons: [email protected]:4.58
FF - prefs.js..keyword.URL: "http://search.yahoo...._1-ya-bs-rp&q="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[email protected]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2011/09/22 07:16:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files\SPEEDbit Video Downloader\SPFireFox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/17 11:29:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/09/07 13:02:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2012/12/09 06:51:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ctkasml.default\extensions
[2012/01/10 09:48:05 | 000,000,000 | ---D | M] (Adobe BrowserLab for Firebug) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ctkasml.default\extensions\[email protected]
[2012/12/09 06:51:54 | 000,000,000 | ---D | M] (FlashFirebug) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ctkasml.default\extensions\[email protected]
[2012/11/21 04:52:33 | 000,234,741 | ---- | M] () (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ctkasml.default\extensions\[email protected]
[2012/11/17 12:21:38 | 002,042,908 | ---- | M] () (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ctkasml.default\extensions\[email protected]
[2012/11/17 12:21:48 | 000,251,282 | ---- | M] () (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ctkasml.default\extensions\[email protected]
[2012/11/17 11:42:18 | 000,000,915 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ctkasml.default\searchplugins\conduit.xml
[2012/12/01 10:26:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/09/08 22:13:54 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]_bak
[2011/09/08 22:13:51 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]_bak
[2010/09/30 12:28:49 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/10/24 17:50:58 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/24 17:50:17 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/17 12:21:26 | 000,128,264 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\testlog.txt
[2012/10/24 17:50:17 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/07/11 18:26:14 | 000,001,068 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahootc.xml
========== Chrome ==========
CHR - homepage: http://www.google.co.uk/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.co.uk/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.95\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.95\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll
CHR - plugin: Java Deployment Toolkit 7.0.90.5 (Enabled) = C:\WINDOWS\system32\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google Drive = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: New Tab Redirect = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ffnkmhhiondoojnmkkpebhfmeeloahpe\1.1_0\
CHR - Extension: Gmail = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/12/08 08:17:12 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" File not found
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NWTRAY] C:\WINDOWS\System32\nwtray.exe (Novell, Inc.)
O4 - HKLM..\Run: [StartupFaster] "C:\Program Files\Startup Faster\startuploader.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP File not found
O4 - HKCU..\Run: [SkinClock] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\StartupFaster [2012/11/10 17:48:52 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\StartupFaster [2012/11/10 17:48:52 | 000,000,000 | -H-D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: CompatibleRUPSecurity = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to WebSite-Watcher - C:\Documents and Settings\user\Application Data\aignes\WebSite-Watcher\config\settings\wswie.htm ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - Reg Error: Key error. File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - Reg Error: Key error. File not found
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\NetWare\nwws2nds.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\system32\NetWare\nwws2sap.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\WINDOWS\system32\NetWare\nwws2slp.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {042134DD-BB44-43FC-A74F-B80FBD465925} http://210.68.70.226...e/xWebView4.cab (xWebView4 Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1285837009015 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1341098091181 (MUWebControl Class)
O16 - DPF: {99477088-D541-4C7E-945D-9E8854469CF5} http://192.168.100.200/Topica.cab (Topica Control)
O16 - DPF: {B29FFE46-EFA5-41A7-95B3-21E6182CC5BE} http://210.68.70.226.../TOPICACamV.cab (TOPICA IPCamera Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C1E4FE21-20A5-4D65-866D-E7C2BEF15CA1}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E553B255-2CAE-4281-8B0D-09A7F55A2F37}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E553B255-2CAE-4281-8B0D-09A7F55A2F37}: NameServer = 158.152.1.43,158.152.1.58
O18 - Protocol\Handler\dae {A6781FA9-C199-4FF3-803D-C181484BB4E0} - C:\Program Files\Right Hemisphere\Deep Access Explorer\PreviewHandler32.dll (Right Hemisphere)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (NWGINA.DLL) - C:\WINDOWS\System32\nwgina.dll (Novell, Inc.)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\WINDOWS\system32\CbFsMntNtf3.dll (EldoS Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (nwv1_0) - C:\WINDOWS\System32\nwv1_0.dll (Novell, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/09 11:00:29 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/12/15 17:39:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft Antimalware
[2012/12/15 09:26:45 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\user\Recent
[2012/12/14 10:51:56 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/12/14 10:49:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/12/14 08:40:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/12/14 08:20:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\MFAData
[2012/12/14 08:20:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\Avg2013
[2012/12/14 07:36:00 | 000,019,456 | ---- | C] (BUFFALO INC.) -- C:\WINDOWS\System32\drivers\bfturbov.sys
[2012/12/14 07:00:14 | 000,000,000 | ---D | C] -- C:\WINDOWS.2
[2012/12/13 20:50:14 | 000,000,000 | ---D | C] -- C:\WINDOWS.1
[2012/12/10 13:00:02 | 000,000,000 | ---D | C] -- C:\WINDOWS.0
[2012/12/02 10:43:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Start Menu\Programs\MICE
[2012/12/02 10:43:13 | 000,000,000 | ---D | C] -- C:\Program Files\MICE
[2012/12/02 00:55:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Mouse
[2012/12/01 16:54:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2012/12/01 11:02:55 | 000,000,000 | ---D | C] -- C:\kavremover
[2012/12/01 09:34:00 | 000,074,072 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klflt.sys
[2012/12/01 09:33:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Kaspersky Lab Setup Files
[2012/11/27 09:35:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\My Documents\Transcend 4GB (2x2GB) DDR2-667 PC2-5300 ECC Registered Memory (RAM) 240-pin eBay-cached_files
[2012/11/27 01:20:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\GlarySoft
[2012/11/23 08:26:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\NetSetMan
[2012/11/23 08:26:22 | 000,000,000 | ---D | C] -- C:\Program Files\NetSetMan
[2012/11/22 17:17:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Registry Finder
[2012/11/22 17:17:37 | 000,000,000 | ---D | C] -- C:\Program Files\AceLogix
[2012/11/22 17:07:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Start Menu\Programs\DCSoft
[2012/11/22 17:07:07 | 000,000,000 | ---D | C] -- C:\Program Files\DCSoft
[2012/11/20 21:30:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/11/20 21:14:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[2012/11/19 23:38:45 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/11/19 23:34:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/11/19 23:33:29 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/11/18 01:06:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\driverview
[2012/11/17 23:31:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Powertoys for Windows XP
[2012/11/17 18:07:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\Registry Toolkit
[2012/11/17 18:07:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Tools
[2012/11/17 18:07:09 | 000,000,000 | ---D | C] -- C:\Program Files\RegTkt
[2012/11/17 12:18:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\toolbarcleaner
[2012/11/17 12:18:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor
[2012/11/17 12:18:23 | 000,000,000 | ---D | C] -- C:\Program Files\Toolbar Cleaner
[2012/11/17 12:18:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Start Menu\Programs\Toolbar Cleaner
[2012/11/15 22:40:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\FixCleaner
[2012/11/15 22:40:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\FixCleaner
[2012/11/15 22:40:08 | 000,000,000 | ---D | C] -- C:\Program Files\FixCleaner
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/12/15 10:22:47 | 000,000,808 | ---- | M] () -- C:\Documents and Settings\user\Application Data\AtomicAlarmClock.ini
[2012/12/15 10:18:10 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/15 10:10:54 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/12/15 10:04:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/12/15 10:01:11 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/12/15 10:01:01 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/15 10:00:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/12/15 10:00:15 | 3623,428,096 | -HS- | M] () -- C:\hiberfil.sys
[2012/12/14 22:50:03 | 000,000,498 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Outlook 2010.job
[2012/12/14 09:48:13 | 000,001,917 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/12/14 07:32:14 | 000,002,860 | ---- | M] () -- C:\config.xml
[2012/12/14 07:32:14 | 000,001,176 | ---- | M] () -- C:\WINDOWS\System32\RW_{D7B257AE-D3A5-11E0-A956-806D6172696F}.dat
[2012/12/14 07:32:14 | 000,000,024 | ---- | M] () -- C:\WINDOWS\System32\RW_AppData.dat
[2012/12/14 05:07:46 | 000,000,401 | -HS- | M] () -- C:\boot.ini
[2012/12/11 09:49:17 | 000,526,792 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/12/11 09:49:17 | 000,096,648 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/12/11 08:13:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/12/08 18:12:35 | 000,096,208 | ---- | M] () -- C:\WINDOWS\System32\RW_FileType.dat
[2012/12/08 18:12:35 | 000,000,636 | ---- | M] () -- C:\WINDOWS\System32\RW_FileFlag.dat
[2012/12/08 18:12:35 | 000,000,056 | ---- | M] () -- C:\WINDOWS\System32\RW_{A7B93EC5-4153-11E2-81A6-0004763B69CB}.dat
[2012/12/08 18:12:35 | 000,000,056 | ---- | M] () -- C:\WINDOWS\System32\RW_{A7B93EC4-4153-11E2-81A6-0004763B69CB}.dat
[2012/12/08 18:12:35 | 000,000,056 | ---- | M] () -- C:\WINDOWS\System32\RW_{6A51049F-4A58-11E1-8101-0004763B69CB}.dat
[2012/12/08 12:10:42 | 003,851,592 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/12/08 10:37:28 | 000,000,112 | ---- | M] () -- C:\WINDOWS\System32\RW_{181E0F2E-286A-11E2-8181-0004763B69CB}.dat
[2012/12/08 10:37:28 | 000,000,016 | ---- | M] () -- C:\WINDOWS\System32\EvGr_Data{D7B257AE-D3A5-11E0-A956-806D6172696F}.dat
[2012/12/08 10:37:28 | 000,000,016 | ---- | M] () -- C:\WINDOWS\System32\EvGr_Data{181E0F2E-286A-11E2-8181-0004763B69CB}.dat
[2012/12/08 08:17:12 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/12/02 10:43:19 | 000,001,511 | ---- | M] () -- C:\Documents and Settings\user\Desktop\MICE.lnk
[2012/12/01 17:15:48 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01009.Wdf
[2012/12/01 17:15:33 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_dc3d_01009.Wdf
[2012/12/01 16:38:19 | 001,610,520 | ---- | M] () -- C:\Documents and Settings\user\Desktop\INFCACHE.1
[2012/12/01 11:08:32 | 000,000,000 | -HS- | M] () -- C:\DkHyperbootSync
[2012/12/01 11:01:25 | 000,000,024 | ---- | M] () -- C:\Documents and Settings\user\random.dat
[2012/12/01 10:40:06 | 000,000,363 | ---- | M] () -- C:\Documents and Settings\user\SciTE.session
[2012/12/01 10:35:29 | 000,000,040 | ---- | M] () -- C:\Documents and Settings\user\jagex_cl_runescape_LIVE.dat
[2012/12/01 10:26:49 | 000,115,465 | ---- | M] () -- C:\WINDOWS\System32\drivers\klin.dat
[2012/12/01 10:26:49 | 000,097,545 | ---- | M] () -- C:\WINDOWS\System32\drivers\klick.dat
[2012/11/27 09:35:45 | 000,238,433 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Transcend 4GB (2x2GB) DDR2-667 PC2-5300 ECC Registered Memory (RAM) 240-pin eBay-cached.htm
[2012/11/27 09:31:10 | 000,109,117 | ---- | M] () -- C:\Documents and Settings\user\My Documents\4GB(2x2GB) DDR2-667 PC2-5300 ECC Registered CL5 240-pin DIMM Memory RAM eBay.htm
[2012/11/27 09:04:16 | 001,779,322 | ---- | M] () -- C:\Documents and Settings\user\My Documents\dr memory.jpg
[2012/11/22 17:17:38 | 000,000,863 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Registry Finder.lnk
[2012/11/22 17:17:38 | 000,000,845 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Registry Finder.lnk
[2012/11/20 21:14:50 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Google Chrome.lnk
[2012/11/20 21:14:50 | 000,001,791 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/20 08:35:46 | 000,001,024 | ---- | M] () -- C:\.rnd
[2012/11/20 08:34:36 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Irremote.ini
[2012/11/19 19:40:59 | 000,279,245 | ---- | M] () -- C:\Documents and Settings\user\My Documents\19-11-2012 07-39.jpg
[2012/11/19 19:21:00 | 000,009,874 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Shipping Labels (927198141970).pdf
[2012/11/17 18:07:33 | 000,000,035 | ---- | M] () -- C:\WINDOWS\VB.MNM
[2012/11/17 17:13:47 | 000,000,023 | ---- | M] () -- C:\Documents and Settings\user\Desktop\ip.bat
[2012/11/17 16:05:42 | 000,000,376 | ---- | M] () -- C:\Documents and Settings\user\Desktop\DEMON.bat
[2012/11/17 15:41:36 | 000,000,126 | ---- | M] () -- C:\Documents and Settings\user\Desktop\TALK.bat
[2012/11/17 13:40:43 | 000,000,891 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Sothink SWF Editor.lnk
[2012/11/17 13:40:43 | 000,000,873 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Sothink SWF Editor.lnk
[2012/11/17 12:18:23 | 000,000,761 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Toolbar Cleaner.lnk
[2012/11/17 11:46:50 | 000,020,249 | ---- | M] () -- C:\Documents and Settings\user\Desktop\SoundPlayerHater.swf
[2012/11/17 11:30:11 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/11/17 11:30:11 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/11/16 00:05:56 | 000,007,170 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Movie3.swf
[2012/11/16 00:05:24 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Movie3.avi
[2012/11/15 23:59:18 | 017,126,419 | ---- | M] () -- C:\Documents and Settings\user\My Documents\error.swi
[2012/11/15 23:39:08 | 001,824,568 | ---- | M] () -- C:\Documents and Settings\user\My Documents\tsb_additive manufacturing comp final.pdf
[2012/11/15 22:40:10 | 000,001,852 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\FixCleaner.lnk
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/12/14 08:50:58 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/12/14 08:46:27 | 000,001,917 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012/12/14 08:41:00 | 000,001,698 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/12/13 20:56:28 | 000,335,029 | ---- | C] () -- C:\DPsFnshr.exe
[2012/12/11 23:14:03 | 3623,428,096 | -HS- | C] () -- C:\hiberfil.sys
[2012/12/08 18:12:35 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\RW_{A7B93EC5-4153-11E2-81A6-0004763B69CB}.dat
[2012/12/08 18:12:35 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\RW_{A7B93EC4-4153-11E2-81A6-0004763B69CB}.dat
[2012/12/08 18:12:35 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\RW_{6A51049F-4A58-11E1-8101-0004763B69CB}.dat
[2012/12/02 10:43:19 | 000,001,511 | ---- | C] () -- C:\Documents and Settings\user\Desktop\MICE.lnk
[2012/12/01 17:15:48 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01009.Wdf
[2012/12/01 17:15:33 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_dc3d_01009.Wdf
[2012/12/01 17:00:49 | 000,000,667 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\AtomicAlarmClock.ini
[2012/12/01 11:52:43 | 000,000,112 | ---- | C] () -- C:\WINDOWS\System32\RW_{181E0F2E-286A-11E2-8181-0004763B69CB}.dat
[2012/12/01 11:52:43 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\EvGr_Data{D7B257AE-D3A5-11E0-A956-806D6172696F}.dat
[2012/12/01 11:52:43 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\EvGr_Data{181E0F2E-286A-11E2-8181-0004763B69CB}.dat
[2012/12/01 11:42:28 | 000,002,860 | ---- | C] () -- C:\config.xml
[2012/12/01 11:42:28 | 000,001,176 | ---- | C] () -- C:\WINDOWS\System32\RW_{D7B257AE-D3A5-11E0-A956-806D6172696F}.dat
[2012/12/01 10:32:21 | 000,000,000 | -HS- | C] () -- C:\DkHyperbootSync
[2012/11/27 09:35:42 | 000,238,433 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Transcend 4GB (2x2GB) DDR2-667 PC2-5300 ECC Registered Memory (RAM) 240-pin eBay-cached.htm
[2012/11/27 09:31:09 | 000,109,117 | ---- | C] () -- C:\Documents and Settings\user\My Documents\4GB(2x2GB) DDR2-667 PC2-5300 ECC Registered CL5 240-pin DIMM Memory RAM eBay.htm
[2012/11/27 09:03:46 | 001,779,322 | ---- | C] () -- C:\Documents and Settings\user\My Documents\dr memory.jpg
[2012/11/22 17:17:38 | 000,000,863 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Registry Finder.lnk
[2012/11/22 17:17:38 | 000,000,845 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Registry Finder.lnk
[2012/11/20 21:14:50 | 000,001,813 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Google Chrome.lnk
[2012/11/20 21:14:50 | 000,001,791 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/20 21:13:20 | 000,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/20 21:13:19 | 000,000,878 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/20 08:36:07 | 000,774,144 | ---- | C] () -- C:\WINDOWS\System32\NEROINSTAEC43759.DB
[2012/11/20 08:34:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2012/11/19 23:38:47 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/11/19 19:39:55 | 000,279,245 | ---- | C] () -- C:\Documents and Settings\user\My Documents\19-11-2012 07-39.jpg
[2012/11/19 19:21:00 | 000,009,874 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Shipping Labels (927198141970).pdf
[2012/11/18 01:54:41 | 000,000,830 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/11/17 23:31:31 | 000,160,217 | ---- | C] () -- C:\WINDOWS\System32\PowerToysLicense.rtf
[2012/11/17 18:07:33 | 000,000,035 | ---- | C] () -- C:\WINDOWS\VB.MNM
[2012/11/17 16:44:56 | 000,000,023 | ---- | C] () -- C:\Documents and Settings\user\Desktop\ip.bat
[2012/11/17 16:05:59 | 000,000,376 | ---- | C] () -- C:\Documents and Settings\user\Desktop\DEMON.bat
[2012/11/17 16:05:59 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\user\Desktop\TALK.bat
[2012/11/17 13:40:43 | 000,000,891 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Sothink SWF Editor.lnk
[2012/11/17 13:40:43 | 000,000,873 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Sothink SWF Editor.lnk
[2012/11/17 12:18:23 | 000,000,761 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Toolbar Cleaner.lnk
[2012/11/17 11:46:48 | 000,020,249 | ---- | C] () -- C:\Documents and Settings\user\Desktop\SoundPlayerHater.swf
[2012/11/17 11:30:10 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/11/16 00:05:56 | 000,007,170 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Movie3.swf
[2012/11/16 00:05:24 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Movie3.avi
[2012/11/15 23:59:09 | 017,126,419 | ---- | C] () -- C:\Documents and Settings\user\My Documents\error.swi
[2012/11/15 23:39:07 | 001,824,568 | ---- | C] () -- C:\Documents and Settings\user\My Documents\tsb_additive manufacturing comp final.pdf
[2012/11/15 22:40:10 | 000,001,852 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\FixCleaner.lnk
[2012/11/14 08:46:46 | 000,000,023 | ---- | C] () -- C:\WINDOWS\SWFDecompiler.INI
[2012/11/07 22:52:33 | 000,000,500 | ---- | C] () -- C:\WINDOWS\TUCSEN.ini
[2012/11/06 23:33:38 | 002,469,760 | ---- | C] () -- C:\WINDOWS\System32\BootMan.exe
[2012/11/06 23:33:38 | 000,086,408 | ---- | C] () -- C:\WINDOWS\System32\setupempdrv03.exe
[2012/11/06 23:33:38 | 000,019,840 | ---- | C] () -- C:\WINDOWS\System32\EuEpmGdi.dll
[2012/11/06 23:33:38 | 000,013,192 | ---- | C] () -- C:\WINDOWS\System32\epmntdrv.sys
[2012/11/06 23:33:38 | 000,008,456 | ---- | C] () -- C:\WINDOWS\System32\EuGdiDrv.sys
[2012/10/29 22:28:44 | 000,322,424 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/10/16 22:56:33 | 000,000,024 | ---- | C] () -- C:\WINDOWS\System32\RW_AppData.dat
[2012/10/12 18:10:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX2.INI
[2012/10/12 17:17:07 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Booms
[2012/10/12 17:17:07 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\user\Application Data\Bass
[2012/10/12 17:17:07 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
[2012/10/12 17:17:07 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Classical
[2012/10/12 17:15:55 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Breath Pad
[2012/10/12 17:15:55 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\user\Application Data\Bass Amp
[2012/10/12 17:15:55 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
[2012/10/12 17:15:55 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Clips
[2012/10/12 17:15:54 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\BookService
[2012/10/12 17:15:54 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\user\Application Data\Basics
[2012/10/12 17:15:54 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
[2012/10/12 17:15:20 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\user\Application Data\Calibrators
[2012/10/12 17:15:20 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLeo.DAT
[2012/10/12 17:15:20 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Desktop Pictures
[2012/10/12 17:15:20 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Chorus
[2012/10/12 07:04:24 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\avisynth.dll
[2012/09/20 17:57:22 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\user\Application Data\winscp.rnd
[2012/08/26 17:16:14 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\user\.deskmetrics
[2012/07/27 12:01:08 | 000,009,341 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft Excel 97-2003.EML
[2012/07/20 16:17:42 | 000,446,464 | ---- | C] () -- C:\WINDOWS\System32\NVH264Decoder.dll
[2012/07/20 16:17:42 | 000,405,504 | ---- | C] () -- C:\WINDOWS\System32\NVPostProc.dll
[2012/07/20 16:17:41 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\NVH264vfw.dll
[2012/07/20 11:32:11 | 000,000,128 | ---- | C] () -- C:\WINDOWS\System32\Topica.ini
[2012/07/17 14:05:55 | 000,000,085 | ---- | C] () -- C:\Documents and Settings\user\mm_backup.cfg
[2012/07/14 21:22:02 | 000,000,023 | ---- | C] () -- C:\WINDOWS\XWEBVI~1.INI
[2012/07/14 10:58:40 | 000,149,504 | ---- | C] () -- C:\WINDOWS\System32\ff_realaacBC.dll
[2012/07/14 10:58:39 | 002,555,580 | ---- | C] () -- C:\WINDOWS\System32\libavcodecBC.dll
[2012/07/14 10:58:38 | 000,261,120 | ---- | C] () -- C:\WINDOWS\System32\libmplayerBC.dll
[2012/06/27 18:52:10 | 000,000,363 | ---- | C] () -- C:\WINDOWS\gotcha32.INI
[2012/06/26 17:44:02 | 000,041,008 | ---- | C] () -- C:\WINDOWS\System32\drivers\dsu2cam.sys
[2012/06/26 16:35:57 | 000,000,065 | ---- | C] () -- C:\Documents and Settings\user\jagex_cl_runescape_LIVE_BETA.dat
[2012/06/26 16:35:57 | 000,000,024 | ---- | C] () -- C:\Documents and Settings\user\random.dat
[2012/06/20 13:53:24 | 000,000,092 | ---- | C] () -- C:\WINDOWS\NogaTw.INI
[2012/06/17 07:33:13 | 000,000,061 | ---- | C] () -- C:\Documents and Settings\user\jagex_cl_runescape_LIVE2.dat
[2012/06/01 00:14:28 | 000,000,024 | ---- | C] () -- C:\Documents and Settings\user\jagexappletviewer.preferences
[2012/04/22 20:12:22 | 004,424,704 | ---- | C] () -- C:\WINDOWS\System32\ffmpeg.dll
[2012/04/08 23:40:36 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2012/04/08 23:39:46 | 000,260,608 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2012/04/08 23:39:32 | 000,158,720 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2012/04/08 23:39:32 | 000,099,840 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2012/04/08 23:39:30 | 001,525,248 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2012/04/08 23:39:30 | 000,146,944 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2012/04/08 23:39:28 | 000,212,480 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2012/04/08 23:39:28 | 000,115,200 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2012/04/08 23:39:26 | 000,328,704 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2012/03/29 14:21:26 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\libbluray.dll
[2012/03/29 14:21:18 | 006,582,226 | ---- | C] () -- C:\WINDOWS\System32\avcodec-lav-54.dll
[2012/03/29 14:21:18 | 001,152,365 | ---- | C] () -- C:\WINDOWS\System32\avformat-lav-54.dll
[2012/03/29 14:21:18 | 000,374,152 | ---- | C] () -- C:\WINDOWS\System32\swscale-lav-2.dll
[2012/03/29 14:21:18 | 000,207,872 | ---- | C] () -- C:\WINDOWS\System32\avutil-lav-51.dll
[2012/03/29 14:21:18 | 000,144,523 | ---- | C] () -- C:\WINDOWS\System32\avfilter-lav-2.dll
[2012/03/11 01:02:29 | 000,056,732 | ---- | C] () -- C:\WINDOWS\RFMaxPluginUninstall.exe
[2012/02/25 08:34:53 | 000,096,208 | ---- | C] () -- C:\WINDOWS\System32\RW_FileType.dat
[2012/02/25 08:34:53 | 000,000,636 | ---- | C] () -- C:\WINDOWS\System32\RW_FileFlag.dat
[2012/02/16 23:20:24 | 000,000,263 | ---- | C] () -- C:\WINDOWS\ui_bitmapviewer.ini
[2012/02/16 23:11:30 | 000,010,920 | ---- | C] () -- C:\WINDOWS\POLYTRAN.INI
[2012/02/14 20:22:27 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/01/17 12:25:00 | 000,001,769 | ---- | C] () -- C:\WINDOWS\Language_trs.ini
[2012/01/17 12:23:18 | 000,005,176 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2012/01/17 12:23:16 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2012/01/10 15:59:20 | 002,807,708 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2012/01/10 15:23:49 | 001,074,636 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2012/01/10 15:21:08 | 001,074,636 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2012/01/10 15:21:08 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2012/01/10 11:35:28 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\lgpi32.dll
[2012/01/07 23:19:19 | 002,300,744 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-790525478-343818398-725345543-1003-0.dat
[2011/12/29 14:07:50 | 000,000,061 | ---- | C] () -- C:\Documents and Settings\user\jagex_cl_runescape_LIVE1.dat
[2011/12/29 10:37:05 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/12/21 00:00:58 | 000,000,049 | -H-- | C] () -- C:\Documents and Settings\user\Application Data\eMail Extractor registration.ini
[2011/12/07 19:32:24 | 000,216,064 | ---- | C] ( ) -- C:\WINDOWS\System32\Lagarith.dll
[2011/12/05 19:28:31 | 000,000,363 | ---- | C] () -- C:\Documents and Settings\user\SciTE.session
[2011/11/29 23:23:18 | 000,000,011 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\gem.lic
[2011/11/28 19:26:28 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2011/11/27 10:49:51 | 000,000,568 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
[2011/11/27 10:32:31 | 000,009,206 | ---- | C] () -- C:\WINDOWS\NTTuner.ini
[2011/11/20 08:02:33 | 000,161,781 | ---- | C] () -- C:\WINDOWS\Animated Wallpaper Maker Uninstaller.exe
[2011/11/17 06:04:39 | 000,134,650 | ---- | C] () -- C:\WINDOWS\Data Extractor Uninstaller.exe
[2011/11/16 17:18:21 | 000,000,704 | ---- | C] () -- C:\WINDOWS\IMPhenomenon.INI
[2011/11/09 22:39:44 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\OpenVideo.dll
[2011/11/09 22:39:32 | 000,054,784 | ---- | C] () -- C:\WINDOWS\System32\OVDecode.dll
[2011/11/08 03:26:36 | 000,584,570 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/10/26 08:44:30 | 000,004,107 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ihfeumzb.qzk
[2011/10/25 21:04:14 | 000,000,040 | ---- | C] () -- C:\Documents and Settings\user\jagex_cl_runescape_LIVE.dat
[2011/10/12 00:26:05 | 000,000,159 | RHS- | C] () -- C:\WINDOWS\CTA1STET.BIN
[2011/10/09 08:57:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eDrawingOfficeAutomator.INI
[2011/10/03 20:20:52 | 000,000,152 | ---- | C] () -- C:\Documents and Settings\user\default.pls
[2011/10/03 20:15:37 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2011/09/12 18:10:56 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2011/09/10 15:26:49 | 000,060,416 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/09 22:14:35 | 000,052,140 | ---- | C] () -- C:\WINDOWS\RFC4DPluginUninstall.exe
[2011/09/08 22:47:17 | 000,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2011/09/08 22:39:02 | 000,000,136 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2011/09/08 22:13:38 | 000,115,465 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2011/09/08 22:13:38 | 000,097,545 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2011/09/08 14:00:52 | 000,150,528 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
[2011/09/08 14:00:48 | 000,142,336 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
[2011/09/08 14:00:42 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
[2011/09/08 14:00:38 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
[2011/09/08 14:00:34 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\dsmux.exe
[2011/09/08 14:00:24 | 000,154,624 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2011/09/08 14:00:10 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\mkv2vfr.exe
[2011/09/08 14:00:06 | 000,358,400 | ---- | C] () -- C:\WINDOWS\System32\gdsmux.exe
[2011/09/08 13:59:54 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
[2011/09/08 13:59:52 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
[2011/09/07 20:10:26 | 000,000,571 | ---- | C] () -- C:\WINDOWS\System32\Shortcut to mstsc.exe.lnk
[2011/09/06 11:32:54 | 000,000,566 | ---- | C] () -- C:\WINDOWS\System32\Shortcut to calc.exe.lnk
[2011/09/04 15:00:14 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\user\jagex_runescape_preferences2.dat
[2011/09/04 14:59:06 | 000,000,035 | ---- | C] () -- C:\Documents and Settings\user\jagex_runescape_preferences.dat
[2011/09/02 19:45:48 | 000,002,568 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2011/09/02 16:10:10 | 000,000,086 | ---- | C] () -- C:\WINDOWS\WPCMAPI.INI
[2011/09/02 15:51:47 | 000,000,090 | ---- | C] () -- C:\WINDOWS\msmail.ini
[2011/09/02 11:04:15 | 000,015,898 | ---- | C] () -- C:\WINDOWS\System32\vlmsup.exe
[2011/09/02 11:04:12 | 000,001,724 | ---- | C] () -- C:\WINDOWS\System32\vipx.exe
[2011/09/02 11:04:01 | 000,065,619 | ---- | C] () -- C:\WINDOWS\System32\setupw2k.dll
[2011/09/02 11:03:25 | 000,262,227 | ---- | C] () -- C:\WINDOWS\System32\nwshlxnt.dll
[2011/09/02 11:02:16 | 000,051,200 | ---- | C] () -- C:\WINDOWS\System32\lgncon32.dll
[2011/09/02 10:40:38 | 000,002,757 | ---- | C] () -- C:\WINDOWS\System32\rdrstats.ini
[2011/09/02 10:33:04 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\prtwin32.dll
[2011/09/02 10:32:55 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\nwpsrv32.dll
[2011/09/02 10:32:15 | 000,225,356 | ---- | C] () -- C:\WINDOWS\System32\lgnwnt32.dll
[2011/09/02 10:30:01 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\nwslog32.dll
[2011/09/01 23:28:39 | 000,000,808 | ---- | C] () -- C:\Documents and Settings\user\Application Data\AtomicAlarmClock.ini
[2011/09/01 23:10:34 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\srvany.exe
[2011/09/01 23:09:02 | 000,151,552 | ---- | C] () -- C:\WINDOWS\KMSEmulator.exe
[2011/07/21 14:14:05 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2011/06/17 14:44:28 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\G711Codec.dll
[2011/06/09 19:26:30 | 000,199,680 | ---- | C] () -- C:\WINDOWS\System32\MyAVCD.dll
[2011/06/01 19:19:46 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\ArchiveHelper.dll
[2011/05/30 13:42:50 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\XviDvfw.dll
[2011/05/23 07:46:30 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\XviDcore.dll
[2011/03/03 11:39:56 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
[2011/03/03 11:38:10 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
[2011/03/03 11:37:50 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
[2011/01/10 00:51:55 | 000,243,168 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2010/12/30 22:27:47 | 014,454,784 | ---- | C] () -- C:\WINDOWS\System32\common_res.dll
========== ZeroAccess Check ==========
[2010/09/29 16:30:51 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 00:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 12:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/14 00:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/09/18 22:41:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2011/09/09 17:15:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Abvent
[2011/10/30 17:23:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Altova
[2012/11/17 12:18:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor
[2012/01/07 22:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2011/09/01 23:06:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2011/01/11 15:32:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2012/05/27 23:09:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Capvidia
[2011/01/11 15:36:53 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/11/02 18:01:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CompeGPS
[2011/11/03 11:24:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Compuplast
[2012/11/11 08:53:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Condusiv Technologies
[2012/01/01 18:01:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CrystalMaker Software
[2011/10/09 08:54:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2012/11/11 08:32:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
[2012/01/17 12:05:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2012/10/12 17:17:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2011/09/09 13:03:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
[2011/09/01 18:18:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FlashFXP
[2012/02/18 16:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FNET
[2011/11/07 14:57:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FNP
[2012/09/05 18:42:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GNU
[2012/04/12 08:12:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grasssoft
[2012/11/01 12:28:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2012/01/10 11:35:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Keyword Sniper Pro
[2012/11/02 17:37:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Materialise
[2012/02/14 13:05:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MetaQuotes
[2012/12/14 08:22:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/11/17 06:13:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mirillis
[2012/10/16 23:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2011/09/26 12:42:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2011/11/22 21:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2012/11/05 00:15:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ReviverSoft
[2012/03/08 04:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Right Hemisphere
[2011/09/02 20:02:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2011/10/09 23:34:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
[2012/02/16 21:36:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Solveering LLC
[2011/09/09 19:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2011/10/27 20:30:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2011/10/28 08:26:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spotmau
[2012/10/29 22:07:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SystemSpeedBooster
[2011/10/13 12:08:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2012/12/14 10:49:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/12/04 15:17:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ Total Media Converter
[2012/02/14 17:52:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Transend
[2011/09/16 19:19:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2012/10/12 17:17:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2011/09/29 20:47:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/09/04 14:18:32 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{A70847F9-0478-4850-BE50-19ADF5EC2299}
[2011/11/06 10:47:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\3Matic
[2011/09/09 17:15:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Abvent
[2012/11/07 18:41:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Abvent_Artlantis3
[2012/04/17 21:50:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\aignes
[2012/10/12 07:11:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Ashampoo
[2012/01/07 22:22:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Autodesk
[2011/01/11 15:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\AVG10
[2011/12/31 16:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\avidemux
[2012/05/27 23:09:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Capvidia
[2012/11/02 16:28:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/11/11 09:16:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Condusiv_Technologies
[2012/01/01 18:05:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\CrystalMaker Software
[2011/11/03 14:51:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\DassaultSystemes
[2011/10/31 12:50:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Digiarty
[2011/09/26 12:40:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Downloaded Installations
[2012/03/27 17:03:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\EDrawings
[2012/01/11 01:21:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\EurekaLog
[2012/11/15 22:57:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\FixCleaner
[2012/11/27 01:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\GlarySoft
[2012/09/11 06:50:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\gnupg
[2012/02/06 23:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Grasssoft
[2012/03/15 20:43:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\HDRLightStudio
[2011/11/24 21:35:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\HDRsoft
[2011/12/12 22:09:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\headus
[2012/03/25 20:15:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\HTC
[2011/11/01 20:05:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2012/01/20 16:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Hulubulu
[2012/01/12 23:21:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\IBP
[2011/09/01 22:50:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\user\Application Data\IFViewer
[2011/10/28 08:39:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\ImgBurn
[2012/11/01 13:07:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\IObit
[2012/08/24 07:12:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\iSpy
[2011/09/04 14:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Key Metric Software
[2012/11/02 20:27:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Luxology
[2012/05/27 23:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Materialise
[2011/12/24 19:41:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\MAXON
[2011/12/21 00:00:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Maxprog
[2012/04/30 04:27:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\MedCalc Software
[2012/09/23 20:56:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\MetaQuotes
[2011/11/17 06:13:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mirillis
[2012/10/12 17:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Nikon
[2012/11/19 19:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Nitro PDF
[2012/02/14 15:26:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\ntr
[2012/10/29 23:17:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Oracle
[2012/03/25 20:15:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Outlook
[2012/07/08 07:13:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Passware
[2011/11/23 19:32:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\PE Explorer
[2011/12/13 23:24:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\PhotoScissorsPilot
[2012/01/01 19:07:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Pixelplan
[2012/01/08 00:47:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Plexscape
[2012/03/31 09:37:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\PolyView
[2011/09/09 20:03:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Publish Providers
[2011/10/09 23:35:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Quest3D
[2012/10/15 19:18:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\redsn0w
[2012/03/16 22:12:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Right Hemisphere
[2012/04/13 20:42:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\RobotSoft
[2011/12/14 22:25:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Scooter Software
[2011/11/08 23:45:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\SimLab
[2011/11/07 12:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\SOLIDCast
[2011/09/09 20:03:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Sony
[2012/11/14 08:39:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\SWiSH Max4
[2012/10/29 22:07:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\SystemSpeedBooster
[2012/10/30 21:56:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Systweak
[2012/08/12 22:26:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\TeamViewer
[2011/09/02 20:27:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Thinstall
[2012/08/18 15:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Transcend Elite
[2012/08/22 22:37:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\TrueCrypt
[2011/09/16 19:19:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Ulead Systems
[2012/11/10 17:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\URSoft
[2011/09/20 10:07:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Windows Desktop Search
[2011/09/20 20:20:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Windows Search
[2011/12/05 12:37:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Xi
[2011/10/02 19:55:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Xilisoft
[2011/12/04 15:26:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\XMedia Recode
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012/05/31 20:22:39 | 000,000,000 | ---D | M](C:\Documents and Settings\user\Local Settings\Application Data\????) -- C:\Documents and Settings\user\Local Settings\Application Data\微软中国
[2012/05/31 20:22:39 | 000,000,000 | ---D | M](C:\Documents and Settings\user\Local Settings\Application Data\????) -- C:\Documents and Settings\user\Local Settings\Application Data\微软中国
(C:\Documents and Settings\user\Local Settings\Application Data\????) -- C:\Documents and Settings\user\Local Settings\Application Data\微软中国
========== Alternate Data Streams ==========
@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CE11B51
< End of report >