Hi Gringo,
Getting late here in Tenerife so please leave me instructions for tomorrow, including if you want me to run the programs in your previous post. I've included the log you want and also the report from the warnings issued by Avira AV.
OTL logfile created on: 18/05/2012 22:35:54 - Run 1
OTL by OldTimer - Version 3.2.43.0 Folder = C:\Documents and Settings\Anyone\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.98 Gb Available Physical Memory | 48.92% Memory free
3.85 Gb Paging File | 2.65 Gb Available in Paging File | 68.91% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 375.87 Gb Total Space | 275.91 Gb Free Space | 73.40% Space Free | Partition Type: NTFS
Drive D: | 358.41 Gb Total Space | 311.14 Gb Free Space | 86.81% Space Free | Partition Type: NTFS
Drive E: | 197.23 Gb Total Space | 151.25 Gb Free Space | 76.69% Space Free | Partition Type: NTFS
Computer Name: USER357 | User Name: Anyone | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Anyone\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avscan.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\WINDOWS\system32\java.exe (Oracle Corporation)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\PS3 Media Server\win32\service\wrapper.exe (Tanuki Software, Ltd.)
PRC - C:\Program Files\IncrediMail\Bin\IncMail.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\IncrediMail\Bin\ImApp.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\Program Files\Telefonica\bin\tgsrvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Cordless USB Phone\Cordless DUALphone Suite.exe (RTX Products A/S)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\WINDOWS\vsnpstd3.exe ()
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\WINDOWS\system32\SAgent4.exe (SEIKO EPSON CORPORATION)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)
========== Modules (No Company Name) ========== MOD - C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportMS.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\IncrediMail\Bin\wlessfp1.dll ()
MOD - C:\Program Files\IncrediMail\Bin\ImLookExU.dll ()
MOD - C:\Program Files\IncrediMail\Bin\ImComUtlU.dll ()
MOD - C:\Program Files\IncrediMail\Bin\ImAppRU.dll ()
MOD - C:\Program Files\IncrediMail\Bin\PMC.dll ()
MOD - C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()
MOD - C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()
MOD - C:\WINDOWS\system32\nvapi.dll ()
MOD - C:\Program Files\Vtune\TBPanelExt.dll ()
MOD - C:\WINDOWS\vsnpstd3.exe ()
MOD - C:\Program Files\SpywareGuard\sgmain.exe ()
MOD - C:\Program Files\SpywareGuard\sgbhp.exe ()
MOD - C:\Program Files\SpywareGuard\dlprotect.dll ()
MOD - C:\Program Files\SpywareGuard\spywareguard.dll ()
MOD - C:\WINDOWS\system32\pdfcmnnt.dll ()
========== Win32 Services (SafeList) ========== SRV - (SupportSoft RemoteAssist) -- C:\Program Files\Common Files\supportsoft\bin\ssrc.exe File not found
SRV - (NMIndexingService) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe File not found
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe File not found
SRV - (bgsvcgen) -- C:\WINDOWS\system32\bgsvcgen.exe File not found
SRV - (0320991318273962mcinstcleanup) McAfee Application Installer Cleanup (0320991318273962) -- C:\DOCUME~1\Anyone\LOCALS~1\Temp\032099~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini File not found
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SolutoService) -- C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV - (SamsungAllShareV2.0) -- C:\Program Files\SAMSUNG\AllShare\AllShareDMS\AllShareDMS.exe (Samsung Electronics Co., Ltd.)
SRV - (SimpleSlideShowServer) -- C:\Program Files\SAMSUNG\AllShare\AllShareSlideShowService.exe (Samsung Electronics Co., Ltd.)
SRV - (RapportMgmtService) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (McAfee SiteAdvisor Service) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (nsService) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\nsService.exe (NovaStor)
SRV - (Backup Client Agent Service) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\ManagementServer.Agent.Service.exe (NovaStor Corporation)
SRV - (PS3 Media Server) -- C:\Program Files\PS3 Media Server\win32\service\wrapper.exe (Tanuki Software, Ltd.)
SRV - (ScsiAccess) -- C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
SRV - (PDAgent) -- C:\Program Files\Raxco\PerfectDisk\PDAgent.exe (Raxco Software, Inc.)
SRV - (PDEngine) -- C:\Program Files\Raxco\PerfectDisk\PDEngine.exe (Raxco Software, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (TomTomHOMEService) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (tgsrvc_telefonica) SupportSoft Repair Service (telefonica) -- C:\Program Files\Telefonica\bin\tgsrvc.exe (SupportSoft, Inc.)
SRV - (NMSAccess) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
SRV - (AcrSch2Svc) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (UleadBurningHelper) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
SRV - (LEC TranslateDotNet Server) -- C:\Program Files\Power Translator 11\LogoMedia TranslateDotNet Server.exe (Language Engineering Corporation, LLC)
SRV - (Capture Device Service) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
SRV - (IAANTMon) Intel® -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (StatusAgent4) -- C:\WINDOWS\system32\SAgent4.exe (SEIKO EPSON CORPORATION)
SRV - (OOD2000) -- C:\WINDOWS\system32\OOD2000.exe (O&O Software GmbH)
========== Driver Services (SafeList) ========== DRV - (WDICA) -- File not found
DRV - (vcdrom) -- C:\Documents and Settings\Anyone\Desktop\Movies Temp\Rosetta Stone\Virtual CD ROM\VCdRom.sys File not found
DRV - (SABProcEnum) -- C:\Program Files\Internet Explorer\SABProcEnum.sys File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (Lbd) -- system32\DRIVERS\Lbd.sys File not found
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found
DRV - (i2omgmt) -- File not found
DRV - (cpuz135) -- C:\WINDOWS\TEMP\cpuz135\cpuz135_x32.sys File not found
DRV - (Changer) -- File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (MBAMSwissArmy) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (Soluto) -- C:\WINDOWS\system32\drivers\Soluto.sys (Soluto LTD.)
DRV - (thdudf) -- C:\WINDOWS\system32\drivers\thdudf.sys (TOSHIBA Corporation)
DRV - (RapportCerberus_32029) -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\32029\RapportCerberus32_32029.sys ()
DRV - (avkmgr) -- C:\WINDOWS\system32\drivers\avkmgr.sys (Avira GmbH)
DRV - (RapportPG) -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportEI) -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportKELL) -- C:\WINDOWS\system32\drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (taphss) -- C:\WINDOWS\system32\drivers\taphss.sys (AnchorFree Inc)
DRV - (FSProFilter) -- C:\WINDOWS\system32\drivers\FSPFltd.sys (FSPro Labs)
DRV - (sptd) -- C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (DefragFS) -- C:\WINDOWS\System32\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV - (MSHUSBVideo) -- C:\WINDOWS\system32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (timounter) -- C:\WINDOWS\system32\drivers\timntr.sys (Acronis)
DRV - (tifsfilter) -- C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) -- C:\WINDOWS\system32\drivers\snapman.sys (Acronis)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (StarOpen) -- C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (Aspi32) -- C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (mcdbus) -- C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (SNPSTD3) USB PC Camera (SNPSTD3) -- C:\WINDOWS\system32\drivers\snpstd3.sys (Sonix Co. Ltd.)
DRV - (TBPanel) -- C:\WINDOWS\System32\drivers\TBPanel.sys (Windows ® 2000 DDK provider)
DRV - (Cardex) -- C:\WINDOWS\system32\drivers\TBPanel.sys (Windows ® 2000 DDK provider)
DRV - (ltmodem5) -- C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (rtl8139) Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (aarich) -- C:\WINDOWS\system32\drivers\aarich.sys (Adaptec, Inc.)
DRV - (RTL8023) -- C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (PQNTDrv) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (cvspydr2) -- C:\WINDOWS\system32\drivers\cvspydr2.sys (Colorvision Inc)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) -- C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) -- C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) -- C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) -- C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.co.uk/IE - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/IE - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRCIE - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\..\SearchScopes\{b167b83b-348e-4f8a-a00d-693f28ede787}: "URL" =
http://search.expatshield.com/g/results.php?c=s&q={searchTerms}IE - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.google.co.uk/"FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.87
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_228.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\WINDOWS\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/10/10 20:12:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/04/11 19:10:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 16:38:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/13 07:48:22 | 000,000,000 | ---D | M]
[2010/07/27 09:11:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Anyone\Application Data\Mozilla\Extensions
[2010/07/27 09:11:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Anyone\Application Data\Mozilla\Extensions\home2@tomtom.com
[2012/05/01 17:43:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Anyone\Application Data\Mozilla\Firefox\Profiles\bhe4gn2q.default\extensions
[2011/01/06 14:29:10 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Anyone\Application Data\Mozilla\Firefox\Profiles\bhe4gn2q.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}(2)
[2012/05/01 17:43:06 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Documents and Settings\Anyone\Application Data\Mozilla\Firefox\Profiles\bhe4gn2q.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010/08/05 17:44:23 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Documents and Settings\Anyone\Application Data\Mozilla\Firefox\Profiles\bhe4gn2q.default\extensions\firefox@tvunetworks.com
[2011/10/11 22:15:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/05 19:59:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
[2012/04/11 19:10:24 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2011/10/10 20:12:55 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2010/10/08 17:33:20 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/09/29 07:53:40 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/05 19:58:33 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/29 01:26:50 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Documents and Settings\Anyone\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Photodex Presenter Plugin (Enabled) = C:\Documents and Settings\Anyone\Application Data\Mozilla\plugins\npPxPlay.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 7.0.0.147 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java Platform SE 7 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\WINDOWS\system32\TVUAx\npTVUAx.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Documents and Settings\Anyone\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Documents and Settings\Anyone\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
O1 HOSTS File: ([2012/05/18 09:37:25 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - No CLSID value found.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (no name) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No CLSID value found.
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (LEC) - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Program Files\Power Translator 11\Applications\LEC IE Translation Extension.dll (Language Engineering Corporation, LLC)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O3 - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKU\S-1-5-21-2052111302-1409082233-725345543-1003..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cordless DUALphone Startup.lnk = C:\Program Files\Cordless USB Phone\Cordless DUALphone Suite.exe (RTX Products A/S)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpywareGuard (2).lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O4 - Startup: C:\Documents and Settings\Anyone\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\Anyone\Start Menu\Programs\Startup\Shortcut to Microsoft Outlook.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - C:\Program Files\ScanSoft\OmniPage15.0\PDFConverter3\IEShellExt.dll (ScanSoft, Inc.)
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\..Trusted Domains: cleverreach.com ([novastor] http in Trusted sites)
O15 - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\..Trusted Domains: google-analytics.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\..Trusted Domains: novastor.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-2052111302-1409082233-725345543-1003\..Trusted Domains: novastor.com ([]https in Trusted sites)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
http://web.atar.rima-tde.net/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884}
http://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1277240890953 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD}
http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E}
http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 80.58.61.250 80.58.61.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5454DA06-5E1D-4D1A-B9A9-7F6123954141}: DhcpNameServer = 80.58.61.250 80.58.61.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FB50D478-4645-4576-8278-4064DD586429}: DhcpNameServer = 80.58.61.250 80.58.61.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) - C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.dll) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\accmipca: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\avgrsstarter: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Anyone\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Anyone\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/30 10:44:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/05/18 22:33:58 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Anyone\Desktop\OTL.exe
[2012/05/18 13:16:28 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Anyone\Desktop\aswMBR.exe
[2012/05/18 13:15:43 | 002,126,424 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Anyone\Desktop\tdsskiller.exe
[2012/05/18 09:14:01 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/05/18 09:14:01 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/05/18 09:14:00 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/05/18 09:14:00 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/05/18 09:13:39 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/05/18 09:10:00 | 004,496,857 | R--- | C] (Swearware) -- C:\Documents and Settings\Anyone\Desktop\ComboFix.exe
[2012/05/17 08:09:53 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/05/17 08:01:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Anyone\My Documents\NovaBACKUP
[2012/05/17 08:01:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2012/05/16 20:27:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Anyone\Desktop\New Folder
[2012/05/14 19:26:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Anyone\Desktop\Temp
[2012/04/29 11:10:12 | 000,051,144 | ---- | C] (Soluto LTD.) -- C:\WINDOWS\System32\drivers\Soluto.sys
[2012/04/29 11:10:08 | 000,000,000 | ---D | C] -- C:\Program Files\Soluto
[2012/04/29 11:10:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Soluto
[2011/11/20 22:46:45 | 000,450,560 | ---- | C] (Hewlett-Packard Company) -- C:\Program Files\HPUSBF.EXE
[2011/11/20 22:46:44 | 000,446,464 | ---- | C] (Hewlett-Packard Company) -- C:\Program Files\HPUSBFW.EXE
[2010/06/26 08:06:09 | 001,531,392 | ---- | C] (Toshiba Samsung Storage Technology Corporation) -- C:\Documents and Settings\Anyone\Application Data\tsdnwin.dll
[2010/06/07 21:26:13 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Anyone\Application Data\pcouffin.sys
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/05/18 22:34:06 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Anyone\Desktop\OTL.exe
[2012/05/18 18:07:06 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/05/18 18:04:29 | 000,088,723 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012/05/18 18:04:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/05/18 15:04:58 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/05/18 14:51:38 | 000,021,734 | ---- | M] () -- C:\WINDOWS\System32\notepad.ini
[2012/05/18 14:42:56 | 000,494,640 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/05/18 14:42:56 | 000,084,618 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/05/18 13:37:05 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Anyone\Desktop\MBR.dat
[2012/05/18 13:16:28 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Anyone\Desktop\aswMBR.exe
[2012/05/18 13:15:56 | 002,126,424 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Anyone\Desktop\tdsskiller.exe
[2012/05/18 09:37:25 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/05/18 09:10:00 | 004,496,857 | R--- | M] (Swearware) -- C:\Documents and Settings\Anyone\Desktop\ComboFix.exe
[2012/05/18 09:06:10 | 000,879,714 | ---- | M] () -- C:\Documents and Settings\Anyone\Desktop\SecurityCheck.exe
[2012/05/18 08:54:46 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/05/17 09:16:01 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/17 08:57:00 | 000,294,216 | ---- | M] () -- C:\Documents and Settings\Anyone\Desktop\gmer.zip
[2012/05/17 08:48:03 | 000,000,428 | ---- | M] () -- C:\WINDOWS\zipgenius.xml
[2012/05/17 08:24:46 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Anyone\defogger_reenable
[2012/05/16 19:20:56 | 000,000,119 | ---- | M] () -- C:\Documents and Settings\Anyone\Application Data\mbam.context.scan
[2012/05/13 07:55:20 | 000,284,520 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/05/12 22:00:05 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/05/12 12:07:12 | 000,000,796 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/12 10:17:06 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/05/08 14:18:45 | 000,002,483 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Kindle Collection Manager.lnk
[2012/05/08 10:11:00 | 000,137,928 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2012/05/08 10:11:00 | 000,083,392 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2012/05/08 10:04:56 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/05/08 10:04:51 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/05/08 10:04:50 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/05/05 16:09:51 | 000,000,731 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\calibre - E-book management.lnk
[2012/05/04 12:39:39 | 000,002,483 | ---- | M] () -- C:\Documents and Settings\Anyone\Desktop\Microsoft Word (2).lnk
[2012/05/02 10:15:30 | 000,010,720 | ---- | M] () -- C:\WINDOWS\System32\EPPICResdb0000
[2012/05/02 10:15:30 | 000,000,121 | ---- | M] () -- C:\WINDOWS\System32\EPPICResdb
[2012/05/02 10:15:28 | 000,000,225 | ---- | M] () -- C:\WINDOWS\System32\KYGASM.dat
[2012/05/01 22:16:01 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/01 18:44:11 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/05/01 17:40:21 | 000,001,057 | ---- | M] () -- C:\Documents and Settings\Anyone\Desktop\Digigood.rtf
[2012/05/01 09:00:38 | 000,000,316 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2012/04/30 17:40:19 | 000,000,671 | ---- | M] () -- C:\Documents and Settings\Anyone\Application Data\vso_ts_preview.xml
[2012/04/24 17:13:24 | 000,051,144 | ---- | M] (Soluto LTD.) -- C:\WINDOWS\System32\drivers\Soluto.sys
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/05/18 13:37:05 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Anyone\Desktop\MBR.dat
[2012/05/18 09:14:01 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/05/18 09:14:01 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/05/18 09:14:01 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/05/18 09:14:00 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/05/18 09:14:00 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/05/18 09:06:03 | 000,879,714 | ---- | C] () -- C:\Documents and Settings\Anyone\Desktop\SecurityCheck.exe
[2012/05/17 08:58:02 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Anyone\Desktop\gmer.exe
[2012/05/17 08:56:58 | 000,294,216 | ---- | C] () -- C:\Documents and Settings\Anyone\Desktop\gmer.zip
[2012/05/17 08:24:46 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Anyone\defogger_reenable
[2012/05/16 19:20:56 | 000,000,119 | ---- | C] () -- C:\Documents and Settings\Anyone\Application Data\mbam.context.scan
[2012/05/12 22:02:04 | 000,174,552 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/05/12 12:07:12 | 000,000,796 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/01 17:40:21 | 000,001,057 | ---- | C] () -- C:\Documents and Settings\Anyone\Desktop\Digigood.rtf
[2012/04/10 21:21:17 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2012/04/10 21:21:14 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2012/04/10 21:21:14 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2012/04/10 21:21:12 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2012/03/08 23:16:13 | 000,276,766 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/02/16 18:46:23 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/12/09 16:47:26 | 000,026,874 | ---- | C] () -- C:\Documents and Settings\Anyone\Application Data\Comma Separated Values (Windows).ADR
[2011/11/04 18:21:16 | 000,000,671 | ---- | C] () -- C:\Documents and Settings\Anyone\Application Data\vso_ts_preview.xml
[2011/10/10 11:13:46 | 000,000,193 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/07/27 11:27:55 | 000,000,159 | ---- | C] () -- C:\WINDOWS\rar_crck.ini
[2011/07/08 08:58:30 | 000,021,734 | ---- | C] () -- C:\WINDOWS\System32\notepad.ini
[2011/07/06 18:00:52 | 000,000,097 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\1.12.1.lic
[2011/06/16 18:10:50 | 000,064,176 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/02/18 11:48:08 | 000,114,688 | ---- | C] () -- C:\WINDOWS\tsnpstd3.exe
[2011/02/18 11:48:03 | 000,151,552 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2011/02/18 11:48:03 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\vsnpstd3.dll
[2011/02/18 11:48:02 | 000,020,480 | ---- | C] () -- C:\WINDOWS\usnpstd3.exe
[2011/02/18 11:43:49 | 000,031,831 | ---- | C] () -- C:\WINDOWS\unvpeye.ini
[2011/01/16 17:17:06 | 000,709,456 | ---- | C] () -- C:\WINDOWS\is-91RPS.exe
[2011/01/15 12:33:46 | 000,000,078 | ---- | C] () -- C:\Program Files\erunt.bat
[2011/01/14 12:48:22 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2010/11/23 15:18:30 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2010/10/08 17:19:10 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2010/10/08 17:19:10 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2010/10/08 17:19:10 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2010/10/08 17:19:10 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2010/10/08 17:19:10 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2010/10/08 17:19:10 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2010/10/08 13:02:22 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2010/10/07 15:42:27 | 000,005,080 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\oafcpcef.qqj
[2010/10/07 15:28:53 | 000,004,932 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\kbkwknay.ayh
[2010/10/06 17:29:50 | 000,004,938 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ypkpiykb.yyr
[2010/10/06 15:40:38 | 000,005,097 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ojobkspa.ako
[2010/10/05 11:46:49 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2010/10/05 11:46:49 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2010/10/05 11:46:49 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2010/10/05 11:46:49 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2010/10/05 11:46:49 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2010/10/05 11:46:49 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2010/10/05 11:46:49 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2010/10/05 11:46:49 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2010/10/05 11:46:49 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2010/10/05 11:46:49 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2010/10/05 11:46:49 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010/10/05 11:46:49 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010/10/05 11:46:49 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010/10/05 11:46:49 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010/10/05 11:46:49 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010/10/05 11:46:49 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2010/10/05 11:46:49 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2010/10/05 11:46:49 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2010/10/05 11:46:49 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2010/07/31 13:48:57 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2010/07/19 15:40:30 | 000,000,955 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2010/07/02 20:35:06 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
[2010/06/23 10:36:54 | 000,000,453 | ---- | C] () -- C:\Documents and Settings\Anyone\Application Data\SamsungLiveUpdateConfig.ini
[2010/06/07 21:26:13 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Anyone\Application Data\pcouffin.cat
[2010/06/07 21:26:13 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Anyone\Application Data\pcouffin.inf
[2010/06/07 14:57:52 | 000,000,033 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/06/07 13:14:28 | 000,000,073 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2010/06/07 13:13:52 | 000,001,188 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ss.ini
[2010/05/29 14:07:35 | 000,072,704 | ---- | C] () -- C:\WINDOWS\System32\XMain32A.dll
[2010/05/29 14:07:34 | 000,397,312 | ---- | C] () -- C:\WINDOWS\System32\Snbd6w95.dll
[2010/05/29 14:06:35 | 000,000,356 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
========== Alternate Data Streams ========== @Alternate Data Stream - 240 bytes -> C:\Documents and Settings\All Users\Application Data\sdpsenv.dat:naughtypirates
< End of report >
AND THE AVIRA WARNINGS:-
Avira Free Antivirus
Report file date: 18 May 2012 18:09
Scanning for 3715932 virus strains and unwanted programs.
The program is running as an unrestricted full version.
Online services are available.
Licensee : Avira AntiVir Personal - Free Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Microsoft Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : USER357
Version information:
BUILD.DAT : 12.0.0.1125 41829 Bytes 02/05/2012 17:40:00
AVSCAN.EXE : 12.3.0.15 466896 Bytes 08/05/2012 09:10:58
AVSCAN.DLL : 12.3.0.15 54736 Bytes 08/05/2012 09:10:58
LUKE.DLL : 12.3.0.15 68304 Bytes 08/05/2012 09:11:00
AVSCPLR.DLL : 12.3.0.14 97032 Bytes 08/05/2012 16:51:19
AVREG.DLL : 12.3.0.17 232200 Bytes 10/05/2012 16:51:42
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 19:18:34
VBASE001.VDF : 7.11.0.0 13342208 Bytes 14/12/2010 10:07:39
VBASE002.VDF : 7.11.19.170 14374912 Bytes 20/12/2011 16:27:52
VBASE003.VDF : 7.11.21.238 4472832 Bytes 01/02/2012 17:24:40
VBASE004.VDF : 7.11.26.44 4329472 Bytes 28/03/2012 16:55:08
VBASE005.VDF : 7.11.29.136 2166272 Bytes 10/05/2012 16:51:36
VBASE006.VDF : 7.11.29.137 2048 Bytes 10/05/2012 16:51:36
VBASE007.VDF : 7.11.29.138 2048 Bytes 10/05/2012 16:51:36
VBASE008.VDF : 7.11.29.139 2048 Bytes 10/05/2012 16:51:37
VBASE009.VDF : 7.11.29.140 2048 Bytes 10/05/2012 16:51:37
VBASE010.VDF : 7.11.29.141 2048 Bytes 10/05/2012 16:51:37
VBASE011.VDF : 7.11.29.142 2048 Bytes 10/05/2012 16:51:37
VBASE012.VDF : 7.11.29.143 2048 Bytes 10/05/2012 16:51:37
VBASE013.VDF : 7.11.29.144 2048 Bytes 10/05/2012 16:51:37
VBASE014.VDF : 7.11.30.3 198144 Bytes 14/05/2012 16:52:06
VBASE015.VDF : 7.11.30.69 186368 Bytes 17/05/2012 16:52:08
VBASE016.VDF : 7.11.30.70 2048 Bytes 17/05/2012 16:53:36
VBASE017.VDF : 7.11.30.71 2048 Bytes 17/05/2012 16:53:36
VBASE018.VDF : 7.11.30.72 2048 Bytes 17/05/2012 16:53:37
VBASE019.VDF : 7.11.30.73 2048 Bytes 17/05/2012 16:53:37
VBASE020.VDF : 7.11.30.74 2048 Bytes 17/05/2012 16:53:37
VBASE021.VDF : 7.11.30.75 2048 Bytes 17/05/2012 16:53:38
VBASE022.VDF : 7.11.30.76 2048 Bytes 17/05/2012 16:53:38
VBASE023.VDF : 7.11.30.77 2048 Bytes 17/05/2012 16:53:38
VBASE024.VDF : 7.11.30.78 2048 Bytes 17/05/2012 16:53:39
VBASE025.VDF : 7.11.30.79 2048 Bytes 17/05/2012 16:53:39
VBASE026.VDF : 7.11.30.80 2048 Bytes 17/05/2012 16:53:40
VBASE027.VDF : 7.11.30.81 2048 Bytes 17/05/2012 16:53:40
VBASE028.VDF : 7.11.30.82 2048 Bytes 17/05/2012 16:53:40
VBASE029.VDF : 7.11.30.83 2048 Bytes 17/05/2012 16:53:41
VBASE030.VDF : 7.11.30.84 2048 Bytes 17/05/2012 16:53:42
VBASE031.VDF : 7.11.30.112 107520 Bytes 18/05/2012 16:51:30
Engine version : 8.2.10.68
AEVDF.DLL : 8.1.2.2 106868 Bytes 26/10/2011 09:10:15
AESCRIPT.DLL : 8.1.4.19 455034 Bytes 11/05/2012 09:09:36
AESCN.DLL : 8.1.8.2 131444 Bytes 27/01/2012 10:26:51
AESBX.DLL : 8.2.5.5 606579 Bytes 12/03/2012 17:17:58
AERDL.DLL : 8.1.9.15 639348 Bytes 08/09/2011 22:16:06
AEPACK.DLL : 8.2.16.13 807287 Bytes 11/05/2012 09:09:35
AEOFFICE.DLL : 8.1.2.28 201082 Bytes 27/04/2012 09:13:59
AEHEUR.DLL : 8.1.4.28 4800886 Bytes 17/05/2012 09:12:52
AEHELP.DLL : 8.1.21.0 254326 Bytes 11/05/2012 09:09:19
AEGEN.DLL : 8.1.5.28 422260 Bytes 27/04/2012 09:10:14
AEEXP.DLL : 8.1.0.40 82292 Bytes 17/05/2012 09:12:53
AEEMU.DLL : 8.1.3.0 393589 Bytes 01/09/2011 22:46:01
AECORE.DLL : 8.1.25.6 201078 Bytes 15/03/2012 17:12:21
AEBB.DLL : 8.1.1.0 53618 Bytes 01/09/2011 22:46:01
AVWINLL.DLL : 12.3.0.15 27344 Bytes 08/05/2012 09:10:57
AVPREF.DLL : 12.3.0.15 51920 Bytes 08/05/2012 09:10:58
AVREP.DLL : 12.3.0.15 179208 Bytes 08/05/2012 16:51:19
AVARKT.DLL : 12.3.0.15 211408 Bytes 08/05/2012 09:10:58
AVEVTLOG.DLL : 12.3.0.15 169168 Bytes 08/05/2012 09:10:58
SQLITE3.DLL : 3.7.0.1 398288 Bytes 08/05/2012 09:11:00
AVSMTP.DLL : 12.3.0.15 63440 Bytes 08/05/2012 09:10:58
NETNT.DLL : 12.3.0.15 17104 Bytes 08/05/2012 09:11:00
RCIMAGE.DLL : 12.3.0.15 4450000 Bytes 08/05/2012 09:10:57
RCTEXT.DLL : 12.3.0.15 96720 Bytes 08/05/2012 09:10:57
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\PROFILES\AVSCAN-20120518-180114-FFDFC600.avp
Logging.............................: default
Primary action......................: Interactive
Secondary action....................: Ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:, E:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: extended
Skipped files.......................: C:\Documents and Settings\All Users\Application Data\Rosetta Stone, C:\Documents and Settings\Anyone\Desktop\All Books, C:\Documents and Settings\Anyone\Desktop\Anti -Virus Progs, C:\Documents and Settings\Anyone\Desktop\Avi Films-Not Seen, C:\Documents and Settings\Anyone\Desktop\AVS Suite, C:\Documents and Settings\Anyone\Desktop\CD Progs, C:\Documents and Settings\Anyone\Desktop\Computer Progs, C:\Documents and Settings\Anyone\Desktop\DVD Progs, C:\Documents and Settings\Anyone\Desktop\From Camera, C:\Documents and Settings\Anyone\Desktop\General Progs, C:\Documents and Settings\Anyone\Desktop\iPAD & Kindle, C:\Documents and Settings\Anyone\Desktop\Movie Progs, C:\Documents and Settings\Anyone\Desktop\Office Progs, C:\Documents and Settings\Anyone\Desktop\Photo Progs, C:\Documents and Settings\Anyone\Desktop\Recom Progs, C:\Documents and Settings\Anyone\Desktop\User Guides, C:\Documents and Settings\Anyone\Desktop\WebCam Progs, C:\Documents and Settings\Anyone\My Documents\TomTom, D:\My Documents\DVD\DVD Covers, D:\My Documents\Elaine, D:\My Documents\Generations, D:\My Documents\My Music, D:\My Documents\Photographs, D:\My Documents\Proshow, D:\My Documents\TomTom\Backup of Maps - Patched, D:\My Documents\TomTom\Central _Europe_850_2871, D:\My Documents\TomTom\Europe_850.2800, D:\My Documents\TomTom\TomTom.Maps.of.USA.Canada.and.Mexico.Plus.v8.50.2784.Retail-T0nK4, E:\Photographs,
Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+PFS,+SPR,
Start of the scan: 18 May 2012 18:09
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Boot sector 'E:\'
[INFO] No virus was found!
Starting search for hidden objects.
c:\documents and settings\anyone\my documents\my pictures\lifecam files\vid\done.wmv
c:\documents and settings\anyone\my documents\my pictures\lifecam files\vid\done.wmv
[NOTE] The file is not visible.
c:\documents and settings\anyone\my documents\my pictures\lifecam files\vid\thumbs.db
c:\documents and settings\anyone\my documents\my pictures\lifecam files\vid\thumbs.db
[NOTE] The file is not visible.
c:\documents and settings\anyone\my documents\my pictures\lifecam files\vid
c:\documents and settings\anyone\my documents\my pictures\lifecam files\vid
[NOTE] The directory is not visible.
The scan of running processes will be started
Scan process 'msdtc.exe' - '42' Module(s) have been scanned
Scan process 'dllhost.exe' - '63' Module(s) have been scanned
Scan process 'dllhost.exe' - '47' Module(s) have been scanned
Scan process 'vssvc.exe' - '50' Module(s) have been scanned
Scan process 'avscan.exe' - '74' Module(s) have been scanned
Scan process 'IEXPLORE.EXE' - '102' Module(s) have been scanned
Scan process 'IEXPLORE.EXE' - '74' Module(s) have been scanned
Scan process 'WINWORD.EXE' - '55' Module(s) have been scanned
Scan process 'alg.exe' - '35' Module(s) have been scanned
Scan process 'PDEngine.exe' - '34' Module(s) have been scanned
Scan process 'avshadow.exe' - '25' Module(s) have been scanned
Scan process 'fxssvc.exe' - '37' Module(s) have been scanned
Scan process 'tgsrvc.exe' - '14' Module(s) have been scanned
Scan process 'svchost.exe' - '40' Module(s) have been scanned
Scan process 'SAgent4.exe' - '17' Module(s) have been scanned
Scan process 'ImApp.exe' - '104' Module(s) have been scanned
Scan process 'IncMail.exe' - '131' Module(s) have been scanned
Scan process 'snmp.exe' - '43' Module(s) have been scanned
Scan process 'java.exe' - '64' Module(s) have been scanned
Scan process 'wrapper.exe' - '55' Module(s) have been scanned
Scan process 'PDAgent.exe' - '38' Module(s) have been scanned
Scan process 'sgbhp.exe' - '18' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '39' Module(s) have been scanned
Scan process 'ctfmon.exe' - '28' Module(s) have been scanned
Scan process 'MSCamS32.exe' - '40' Module(s) have been scanned
Scan process 'iaantmon.exe' - '12' Module(s) have been scanned
Scan process 'svchost.exe' - '36' Module(s) have been scanned
Scan process 'OUTLOOK.EXE' - '84' Module(s) have been scanned
Scan process 'E_S40RP7.EXE' - '12' Module(s) have been scanned
Scan process 'devldr32.exe' - '33' Module(s) have been scanned
Scan process 'E_S40ST7.EXE' - '16' Module(s) have been scanned
Scan process 'sgmain.exe' - '35' Module(s) have been scanned
Scan process 'Cordless DUALphone Suite.exe' - '37' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '28' Module(s) have been scanned
Scan process 'TeaTimer.exe' - '37' Module(s) have been scanned
Scan process 'Skype.exe' - '121' Module(s) have been scanned
Scan process 'avgnt.exe' - '68' Module(s) have been scanned
Scan process 'vsnpstd3.exe' - '20' Module(s) have been scanned
Scan process 'winpatrol.exe' - '45' Module(s) have been scanned
Scan process 'Explorer.EXE' - '97' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '62' Module(s) have been scanned
Scan process 'avguard.exe' - '64' Module(s) have been scanned
Scan process 'svchost.exe' - '36' Module(s) have been scanned
Scan process 'sched.exe' - '40' Module(s) have been scanned
Scan process 'spoolsv.exe' - '62' Module(s) have been scanned
Scan process 'svchost.exe' - '44' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'svchost.exe' - '165' Module(s) have been scanned
Scan process 'PresentationFontCache.exe' - '29' Module(s) have been scanned
Scan process 'svchost.exe' - '42' Module(s) have been scanned
Scan process 'svchost.exe' - '54' Module(s) have been scanned
Scan process 'lsass.exe' - '60' Module(s) have been scanned
Scan process 'services.exe' - '27' Module(s) have been scanned
Scan process 'winlogon.exe' - '82' Module(s) have been scanned
Scan process 'csrss.exe' - '14' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned
Starting to scan executable files (registry).
C:\Program Files\Handbrake\uninst.exe
[WARNING] Invalid end of file
C:\Documents and Settings\Anyone\Desktop\A-V Repair Progs\VobSub\uninstall.exe
[WARNING] Invalid compressed data
The registry was scanned ( '5544' files ).
Starting the file scan:
Begin scan in 'C:\' <Active Drive>
C:\Documents and Settings\All Users\Application Data\MFAData\pack\bins\f10idatx1170qq.bin
[WARNING] The file is password protected
C:\Documents and Settings\All Users\Application Data\MFAData\pack\bins\f10idatx1191nu.bin
[WARNING] The file is password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BabylonToolbar.zip
[WARNING] The file is password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterAntiVirusOverride.zip
[WARNING] The file is password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterAntiVirusOverride1.zip
[WARNING] The file is password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAutoRuntmp.zip
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-01-2011 - 16-16-58.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-11-2011 - 22-24-52.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-12-2011 - 22-44-46.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-13-2011 - 17-28-34.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-14-2011 - 19-45-07.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-15-2011 - 21-41-21.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-16-2011 - 17-26-17.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-16-2012 - 21-58-55.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-18-2011 - 23-01-57.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-19-2011 - 09-33-12.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-21-2011 - 13-08-05.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-21-2011 - 19-12-03.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-24-2011 - 21-57-59.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-26-2011 - 19-56-22.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-01-2011 - 22-54-06.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-09-2012 - 22-35-53.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-14-2011 - 12-26-24.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-15-2011 - 00-45-57.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-16-2011 - 11-00-46.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-21-2011 - 14-14-09.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-22-2012 - 10-08-14.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-25-2011 - 10-45-14.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-05-2011 - 00-38-13.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-05-2011 - 17-40-23.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-16-2011 - 12-40-53.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-20-2011 - 15-07-14.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 05-12-2012 - 13-17-53.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 05-17-2012 - 03-08-01.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 05-18-2012 - 08-58-35.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 06-07-2011 - 16-34-02.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 06-12-2011 - 22-38-43.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 06-16-2011 - 20-39-24.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 06-17-2011 - 17-49-44.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 06-18-2011 - 13-20-53.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 06-23-2011 - 14-03-51.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 06-24-2011 - 10-57-10.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 06-30-2011 - 08-49-21.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 06-30-2011 - 20-07-44.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-04-2011 - 11-44-14.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-06-2011 - 20-41-17.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-07-2011 - 09-26-31.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-07-2011 - 20-24-59.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-08-2011 - 23-18-22.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-11-2011 - 23-32-51.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-13-2011 - 12-11-09.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-13-2011 - 21-46-15.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-15-2011 - 08-44-03.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-20-2011 - 22-58-05.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-21-2011 - 14-53-07.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-25-2011 - 20-53-22.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 07-28-2011 - 14-45-41.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 08-01-2011 - 17-11-49.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 08-07-2011 - 22-04-45.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 08-09-2011 - 19-12-10.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 08-19-2011 - 20-29-26.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 08-29-2011 - 21-19-37.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 09-12-2011 - 19-18-20.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 09-27-2011 - 21-35-55.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 10-07-2011 - 10-37-59.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 10-09-2011 - 20-31-24.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 10-20-2011 - 23-05-37.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 10-21-2011 - 23-30-09.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 11-06-2011 - 22-40-56.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 11-09-2011 - 16-43-37.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 12-18-2010 - 10-53-27.SBU
[WARNING] The file is password protected
C:\Documents and Settings\Anyone\Desktop\A-V Repair Progs\VobSub\uninstall.exe
[WARNING] Invalid compressed data
The directory 'C:\Documents and Settings\Anyone\Desktop\All Books\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\Anti -Virus Progs\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\Avi Films-Not Seen\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\AVS Suite\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\CD Progs\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\Computer Progs\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\DVD Progs\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\General Progs\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\iPAD & Kindle\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\Movie Progs\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\Office Progs\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\Photo Progs\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\User Guides\' was excluded from scanning!
The directory 'C:\Documents and Settings\Anyone\Desktop\WebCam Progs\' was excluded from scanning!
C:\Documents and Settings\Anyone\My Documents\My Downloads\AVSPhotoEditor.exe
[WARNING] Invalid end of file
The directory 'C:\Documents and Settings\Anyone\My Documents\TomTom\' was excluded from scanning!
C:\Program Files\Gabest\VobSub\uninstall.exe
[WARNING] Invalid compressed data
C:\Program Files\Generations\cosmo.exe
[WARNING] Invalid end of file
C:\Program Files\Handbrake\uninst.exe
[WARNING] Invalid end of file
C:\Program Files\ieSpell\uninst.exe
[WARNING] Invalid end of file
C:\Sierra\Gen8\cosmo.exe
[WARNING] Invalid end of file
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1088779.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1089140.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1089529.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1089914.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1090303.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1090688.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1091075.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1091458.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1091841.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1092226.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1092619.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1093004.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1093389.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1093776.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1094159.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP425\A1094544.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP426\A1095019.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP426\A1095409.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP426\A1095802.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP426\A1096188.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP426\A1096577.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP426\A1096962.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP426\A1097351.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP426\A1097753.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP426\A1098147.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP426\A1098536.data
[WARNING] Error read format
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP444\A1248470.dll
[WARNING] Error multiple volume
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP445\A1251998.dll
[WARNING] Error multiple volume
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP499\A1481775.exe
[WARNING] The file is password protected
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP499\A1481839.exe
[WARNING] Invalid compressed data
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP499\A1481847.exe
[WARNING] Unsupported archive version
C:\System Volume Information\_restore{952DCA5E-E3D9-41C3-9465-A927F129AB87}\RP499\A1481850.exe
[WARNING] Invalid compressed data
C:\VueScan\vuescan.dat
[WARNING] The file is password protected
Begin scan in 'D:\' <My Office>
End of the scan: 18 May 2012 22:45
Used time: 4:35:45 Hour(s)
The scan has been canceled!
15317 Scanned directories
868844 Files were scanned
0 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 Files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
868844 Files not concerned
5628 Archives were scanned
113 Warnings
3 Notes
1171733 Objects were scanned with rootkit scan
3 Hidden objects were found