Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Internet redirects in new tabs


  • This topic is locked This topic is locked
28 replies to this topic

#1 London76

London76

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:11:47 PM

Posted 29 April 2010 - 05:52 AM

Hi,
In firefox and Internet Expolrer I get the following symptoms:
1) tabs occaisionally opening with adverts on them.
2) adverts opening when I click on links from google searches, and sometimes an internet dictionary opening.

Neither spybot search and destroy, or Malebytes, or Ad-aware, or Norton Live Security can find any problem.

I went through your helpful list on what to do before posting, but got stopped when running gmer. I have tried running it twice, and both times I get a BSOD which quickly mentions 'iastor.sys' before dissapearing.

I then tried running GMER with only 'services' selected, as Budapest reccomended here: http://www.bleepingcomputer.com/forums/t/309401/malware-google-redirects-and-gmer-crashing/
GMER still crashed this way.

So, unfortunately I am unable to provide a GMER

Here is my DDS log:


DDS (Ver_10-03-17.01) - NTFSx86
Run by Duncan at 11:39:19.85 on 29/04/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_15
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.1916.236 [GMT 1:00]

SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\CE\nmSvc.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\CE\nmFlt.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Allway Sync\Bin\syncappw.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Duncan\Desktop\Defogger.exe
C:\Windows\system32\conhost.exe
C:\Users\Duncan\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;
uStart Page = hxxp://www.facebook.com/
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - c:\program files\free-downloads.net\tbfree.dll
mURLSearchHooks: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - c:\program files\free-downloads.net\tbfree.dll
BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 7\SnagItBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.1.0.32\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.1.0.32\IPSBHO.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - c:\program files\free-downloads.net\tbfree.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 7\SnagItIEAddin.dll
TB: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - c:\program files\free-downloads.net\tbfree.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\4.1.0.32\coIEPlg.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Allway Sync] "c:\program files\allway sync\bin\syncappw.exe" -m
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [NMSVC] c:\program files\ce\nmSvc.exe
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mozyho~1.lnk - c:\program files\mozyhome\mozystat.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redire...1&site=home
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: CESpy.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
AppInit_DLLs: c:\progra~1\google\google~1\GO36F4~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\duncan\appdata\roaming\mozilla\firefox\profiles\jmye8nwc.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\picasa2\npPicasa3.dll
FF - plugin: c:\users\duncan\appdata\local\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-4-5 64288]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0401000.020\symds.sys [2010-4-13 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0401000.020\symefa.sys [2010-4-13 172592]
R0 tdrpman140;Acronis Try&Decide and Restore Points filter (build 140);c:\windows\system32\drivers\tdrpm140.sys [2009-8-2 971168]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\bashdefs\20100324.001\BHDrvx86.sys [2010-3-24 536112]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0401000.020\cchpx86.sys [2010-4-13 501888]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\ipsdefs\20100422.002\IDSvix86.sys [2010-4-27 343088]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2009-8-1 20384]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-2-17 66632]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0401000.020\ironx86.sys [2010-4-13 116784]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0401000.020\symtdiv.sys [2010-4-13 340016]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\common files\magix services\database\bin\FABS.exe [2009-8-27 1253376]
R2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [2009-12-12 6656]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1265264]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-8-11 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-3-14 47640]
R2 N360;Norton 360;c:\program files\norton 360\engine\4.1.0.32\ccsvchst.exe [2010-4-13 126392]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-4-3 1153368]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2008-2-6 126976]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-4-13 102448]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-8-7 7168]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\toshiba\smartfacev\SmartFaceVWatchSrv.exe [2008-8-25 77824]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\common files\magix services\database\bin\fbserver.exe [2008-8-7 3276800]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2010-3-9 24576]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\jumpstart\jswpsapi.exe [2009-8-1 954368]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872]
S4 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-8-7 30192]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-8 135664]
S4 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
S4 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2010-2-6 3032360]

=============== Created Last 30 ================

2010-04-26 16:31:02 0 d-----w- c:\programdata\avG
2010-04-17 19:04:15 0 d-----w- c:\windows\system32\drivers\NSS
2010-04-17 19:04:15 0 d-----w- c:\program files\Norton Security Scan
2010-04-17 16:03:28 0 d-----w- c:\programdata\DivX
2010-04-16 20:57:24 44080 ----a-r- c:\windows\system32\drivers\SymIMV.sys
2010-04-16 19:07:33 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-04-16 19:07:31 3899280 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-16 19:07:30 3954568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-16 18:55:12 0 d-sh--w- c:\windows\system32\%APPDATA%
2010-04-16 15:50:09 132608 ----a-w- c:\windows\system32\cabview.dll
2010-04-16 15:47:56 427520 ----a-w- c:\windows\system32\vbscript.dll
2010-04-16 15:47:54 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-16 15:47:54 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-16 15:47:54 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-13 14:42:23 768 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-04-13 13:21:30 20 ----a-w- c:\users\duncan\defogger_reenable
2010-04-13 12:15:02 0 d-----w- c:\program files\Trend Micro
2010-04-13 11:57:43 0 d-----w- c:\programdata\SITEguard
2010-04-13 11:56:38 0 d-----w- c:\program files\common files\iS3
2010-04-13 11:56:37 0 d-----w- c:\programdata\STOPzilla!
2010-04-12 23:50:37 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-04-12 23:46:49 23848 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-04-12 23:46:49 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-04-12 23:46:47 0 d-----w- c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2010-04-12 23:46:29 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-04-12 23:46:29 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-04-12 23:46:29 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-04-12 23:46:28 0 d-----w- c:\program files\Symantec
2010-04-12 23:46:28 0 d-----w- c:\program files\common files\Symantec Shared
2010-04-12 23:45:44 0 d-----w- c:\windows\system32\drivers\N360
2010-04-12 23:45:42 0 d-----w- c:\program files\Norton 360
2010-04-12 23:43:52 0 d-----w- c:\program files\NortonInstaller
2010-04-10 17:59:59 0 d-----w- c:\program files\Vstplugins
2010-04-10 17:59:50 0 d-----w- c:\programdata\Sony
2010-04-10 17:57:07 0 d-----w- c:\program files\Sony Setup
2010-04-10 17:33:09 0 d-----w- c:\users\duncan\appdata\roaming\MAGIX
2010-04-10 17:28:54 0 d-----w- c:\program files\common files\MAGIX Shared
2010-04-10 17:28:25 0 d-----w- c:\program files\MAGIX
2010-04-10 17:27:40 0 d-----w- c:\programdata\MAGIX
2010-04-10 17:27:33 0 d-----w- c:\program files\common files\MAGIX Services
2010-04-09 02:35:12 0 d-----w- c:\windows\system32\URTTEMP
2010-04-08 17:18:42 0 d-----w- C:\For E DRIVE
2010-04-08 03:12:51 2181 ----a-w- c:\windows\Helicon Debug Window.ini
2010-04-08 03:12:00 0 d-----w- c:\program files\Movie Player ActiveX Control
2010-04-08 03:12:00 0 d-----w- c:\program files\Audio Capture ActiveX Control
2010-04-08 03:11:59 0 d-----w- c:\program files\Helicon Software
2010-04-07 20:32:32 33408 ----a-w- c:\windows\system32\drivers\cdrbsdrv.sys
2010-04-07 20:32:31 59488 ----a-w- c:\windows\system32\GenSvcInst.exe
2010-04-07 20:32:31 145504 ----a-w- c:\windows\system32\bgsvcgen.exe
2010-04-07 20:31:09 45056 ----a-w- c:\windows\system32\PhDi2.sys
2010-04-06 23:49:54 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-04-05 11:18:34 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-04-05 11:18:25 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-05 11:13:22 0 dc-h--w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-05 11:12:40 0 d-----w- c:\programdata\Lavasoft
2010-04-05 11:12:40 0 d-----w- c:\program files\Lavasoft
2010-04-05 00:30:52 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-04-05 00:30:26 0 d-----w- c:\users\duncan\appdata\roaming\SUPERAntiSpyware.com
2010-04-05 00:30:26 0 d-----w- c:\program files\SUPERAntiSpyware
2010-04-04 19:55:17 0 d-----w- c:\users\duncan\appdata\roaming\Malwarebytes
2010-04-04 19:54:47 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-04 19:54:44 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-04 19:54:44 0 d-----w- c:\programdata\Malwarebytes
2010-04-04 19:54:44 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-04 03:29:06 0 d-----w- c:\users\duncan\appdata\roaming\myphotobook
2010-04-03 17:17:08 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-04-03 17:17:08 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-04-01 21:02:35 977920 ----a-w- c:\windows\system32\wininet.dll
2010-03-31 01:58:24 353592 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl

==================== Find3M ====================

2010-04-16 09:39:29 173648 ----a-w- c:\windows\system32\drivers\rdyboost.sys
2010-03-22 18:38:00 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-03-09 17:23:19 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-03-09 17:06:58 24576 ----a-w- c:\windows\system32\drivers\ANDROIDUSB.sys
2010-03-09 15:00:34 115081 ----a-w- c:\windows\system32\drivers\androidusb.INF
2010-03-09 15:00:34 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-03-09 00:57:56 21924 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-09 00:11:57 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2010-03-08 22:21:29 319456 ----a-w- c:\windows\DIFxAPI.dll
2010-03-08 17:59:18 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-03-06 04:37:21 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2010-03-04 00:01:43 209920 ----a-w- c:\windows\system32\nmNsp.dll
2010-03-04 00:01:43 160256 ----a-w- c:\windows\system32\CESpy.dll
2010-02-19 19:27:36 720384 ----a-w- c:\windows\system32\DivX.dll
2010-02-19 19:27:16 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2010-02-19 19:27:16 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2010-02-19 19:27:16 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2010-02-19 19:27:16 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2010-02-19 19:27:16 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2010-02-02 07:45:54 2048 ----a-w- c:\windows\system32\tzres.dll
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 11:41:11.48 ===============




I would relly appreciate any help.

Many Thanks

London76

Attached Files



BC AdBot (Login to Remove)

 


#2 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:11:47 PM

Posted 03 May 2010 - 10:47 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE



Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.


  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#3 London76

London76
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:11:47 PM

Posted 03 May 2010 - 11:34 AM

Thanks Schrauber,
The problem is still the same as my first post.

Here is my new DDS logs:

DDS (Ver_10-03-17.01) - NTFSx86
Run by Duncan at 17:10:33.68 on 03/05/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_15
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.1916.890 [GMT 1:00]

SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\CE\nmSvc.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Allway Sync\Bin\syncappw.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\CE\nmFlt.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Duncan\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;
uStart Page = hxxp://www.facebook.com/
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - c:\program files\free-downloads.net\tbfree.dll
mURLSearchHooks: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - c:\program files\free-downloads.net\tbfree.dll
BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 7\SnagItBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.1.0.32\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.1.0.32\IPSBHO.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - c:\program files\free-downloads.net\tbfree.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 7\SnagItIEAddin.dll
TB: free-downloads.net Toolbar: {ecdee021-0d17-467f-a1ff-c7a115230949} - c:\program files\free-downloads.net\tbfree.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\4.1.0.32\coIEPlg.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Allway Sync] "c:\program files\allway sync\bin\syncappw.exe" -m
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [NMSVC] c:\program files\ce\nmSvc.exe
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mozyho~1.lnk - c:\program files\mozyhome\mozystat.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redire...1&site=home
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: CESpy.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
AppInit_DLLs: c:\progra~1\google\google~1\GO36F4~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\duncan\appdata\roaming\mozilla\firefox\profiles\jmye8nwc.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig|http://www.bleepingcomputer.com/forums/index.php?act=Search&CODE=show&searchid=c0fe08b612e6a3bdb421357d5c9abd6a&search_in=posts&result_type=topics&highlite=%2B&kw=
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\picasa2\npPicasa3.dll
FF - plugin: c:\users\duncan\appdata\local\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-4-5 64288]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0401000.020\symds.sys [2010-4-13 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0401000.020\symefa.sys [2010-4-13 172592]
R0 tdrpman140;Acronis Try&Decide and Restore Points filter (build 140);c:\windows\system32\drivers\tdrpm140.sys [2009-8-2 971168]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\bashdefs\20100324.001\BHDrvx86.sys [2010-3-24 536112]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0401000.020\cchpx86.sys [2010-4-13 501888]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\ipsdefs\20100422.002\IDSvix86.sys [2010-4-27 343088]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2009-8-1 20384]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-2-17 66632]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0401000.020\ironx86.sys [2010-4-13 116784]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0401000.020\symtdiv.sys [2010-4-13 340016]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\common files\magix services\database\bin\FABS.exe [2009-8-27 1253376]
R2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [2009-12-12 6656]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1285864]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-8-11 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-3-14 47640]
R2 N360;Norton 360;c:\program files\norton 360\engine\4.1.0.32\ccsvchst.exe [2010-4-13 126392]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-4-3 1153368]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-4-13 102448]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-8-7 7168]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\common files\magix services\database\bin\fbserver.exe [2008-8-7 3276800]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2010-3-9 24576]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\jumpstart\jswpsapi.exe [2009-8-1 954368]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872]
S4 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-8-7 30192]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-8 135664]

=============== Created Last 30 ================

2010-04-29 10:28:46 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys
2010-04-29 10:28:44 133720 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2010-04-29 10:28:44 1037312 ----a-w- c:\windows\system32\lsasrv.dll
2010-04-26 16:31:02 0 d-----w- c:\programdata\avG
2010-04-17 19:04:15 0 d-----w- c:\windows\system32\drivers\NSS
2010-04-17 19:04:15 0 d-----w- c:\program files\Norton Security Scan
2010-04-17 16:03:28 0 d-----w- c:\programdata\DivX
2010-04-16 20:57:24 44080 ----a-r- c:\windows\system32\drivers\SymIMV.sys
2010-04-16 19:07:33 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-04-16 19:07:31 3899280 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-16 19:07:30 3954568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-16 18:55:12 0 d-sh--w- c:\windows\system32\%APPDATA%
2010-04-16 15:50:09 132608 ----a-w- c:\windows\system32\cabview.dll
2010-04-16 15:47:56 427520 ----a-w- c:\windows\system32\vbscript.dll
2010-04-16 15:47:54 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-16 15:47:54 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-16 15:47:54 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-13 14:42:23 768 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-04-13 13:21:30 20 ----a-w- c:\users\duncan\defogger_reenable
2010-04-13 12:15:02 0 d-----w- c:\program files\Trend Micro
2010-04-13 11:57:43 0 d-----w- c:\programdata\SITEguard
2010-04-13 11:56:38 0 d-----w- c:\program files\common files\iS3
2010-04-13 11:56:37 0 d-----w- c:\programdata\STOPzilla!
2010-04-12 23:50:37 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-04-12 23:46:49 23848 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-04-12 23:46:49 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-04-12 23:46:47 0 d-----w- c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2010-04-12 23:46:29 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-04-12 23:46:29 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-04-12 23:46:29 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-04-12 23:46:28 0 d-----w- c:\program files\Symantec
2010-04-12 23:46:28 0 d-----w- c:\program files\common files\Symantec Shared
2010-04-12 23:45:44 0 d-----w- c:\windows\system32\drivers\N360
2010-04-12 23:45:42 0 d-----w- c:\program files\Norton 360
2010-04-12 23:43:52 0 d-----w- c:\program files\NortonInstaller
2010-04-10 17:59:59 0 d-----w- c:\program files\Vstplugins
2010-04-10 17:59:50 0 d-----w- c:\programdata\Sony
2010-04-10 17:57:07 0 d-----w- c:\program files\Sony Setup
2010-04-10 17:33:09 0 d-----w- c:\users\duncan\appdata\roaming\MAGIX
2010-04-10 17:28:54 0 d-----w- c:\program files\common files\MAGIX Shared
2010-04-10 17:28:25 0 d-----w- c:\program files\MAGIX
2010-04-10 17:27:40 0 d-----w- c:\programdata\MAGIX
2010-04-10 17:27:33 0 d-----w- c:\program files\common files\MAGIX Services
2010-04-09 02:35:12 0 d-----w- c:\windows\system32\URTTEMP
2010-04-08 17:18:42 0 d-----w- C:\For E DRIVE
2010-04-08 03:12:51 2181 ----a-w- c:\windows\Helicon Debug Window.ini
2010-04-08 03:12:00 0 d-----w- c:\program files\Movie Player ActiveX Control
2010-04-08 03:12:00 0 d-----w- c:\program files\Audio Capture ActiveX Control
2010-04-08 03:11:59 0 d-----w- c:\program files\Helicon Software
2010-04-07 20:32:32 33408 ----a-w- c:\windows\system32\drivers\cdrbsdrv.sys
2010-04-07 20:32:31 59488 ----a-w- c:\windows\system32\GenSvcInst.exe
2010-04-07 20:32:31 145504 ----a-w- c:\windows\system32\bgsvcgen.exe
2010-04-07 20:31:09 45056 ----a-w- c:\windows\system32\PhDi2.sys
2010-04-06 23:49:54 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-04-05 11:18:34 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-04-05 11:18:25 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-05 11:13:22 0 dc-h--w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-05 11:12:40 0 d-----w- c:\programdata\Lavasoft
2010-04-05 11:12:40 0 d-----w- c:\program files\Lavasoft
2010-04-05 00:30:52 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-04-05 00:30:26 0 d-----w- c:\users\duncan\appdata\roaming\SUPERAntiSpyware.com
2010-04-05 00:30:26 0 d-----w- c:\program files\SUPERAntiSpyware
2010-04-04 19:55:17 0 d-----w- c:\users\duncan\appdata\roaming\Malwarebytes
2010-04-04 19:54:47 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-04 19:54:44 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-04 19:54:44 0 d-----w- c:\programdata\Malwarebytes
2010-04-04 19:54:44 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-04 03:29:06 0 d-----w- c:\users\duncan\appdata\roaming\myphotobook
2010-04-03 17:17:08 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-04-03 17:17:08 0 d-----w- c:\program files\Spybot - Search & Destroy

==================== Find3M ====================

2010-04-16 09:39:29 173648 ----a-w- c:\windows\system32\drivers\rdyboost.sys
2010-03-22 18:38:00 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-03-09 17:23:19 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-03-09 17:06:58 24576 ----a-w- c:\windows\system32\drivers\ANDROIDUSB.sys
2010-03-09 15:00:34 115081 ----a-w- c:\windows\system32\drivers\androidusb.INF
2010-03-09 15:00:34 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-03-09 00:57:56 21924 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-09 00:11:57 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2010-03-08 22:21:29 319456 ----a-w- c:\windows\DIFxAPI.dll
2010-03-08 17:59:18 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-03-06 04:37:21 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2010-03-04 00:01:43 209920 ----a-w- c:\windows\system32\nmNsp.dll
2010-03-04 00:01:43 160256 ----a-w- c:\windows\system32\CESpy.dll
2010-02-23 07:56:00 977920 ----a-w- c:\windows\system32\wininet.dll
2010-02-19 19:27:36 720384 ----a-w- c:\windows\system32\DivX.dll
2010-02-19 19:27:16 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2010-02-19 19:27:16 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2010-02-19 19:27:16 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2010-02-19 19:27:16 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2010-02-19 19:27:16 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 17:13:19.63 ===============

I look forwards to getting any help I can,
thanks.

Attached Files



#4 London76

London76
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:11:47 PM

Posted 03 May 2010 - 12:56 PM

I just tried again to run GMER, I did it in safe mode, and the scan completed without an 'iastor BSOD.'
Here are the results:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-03 18:39:16
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\Duncan\AppData\Local\Temp\uwkyqpoc.sys


---- System - GMER 1.0.15 ----

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82631AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82631104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 826313F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82619634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82619898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 826311DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82631958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 826316F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82631F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 826321A8

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 8224A599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8226EF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.rsrc C:\Windows\System32\drivers\rdyboost.sys entry point in ".rsrc" section [0x88769014]

---- User code sections - GMER 1.0.15 ----

.text C:\Windows\system32\svchost.exe[904] ntdll.dll!NtProtectVirtualMemory 77045360 5 Bytes JMP 0013000A
.text C:\Windows\system32\svchost.exe[904] ntdll.dll!NtWriteVirtualMemory 77045EE0 5 Bytes JMP 0014000A
.text C:\Windows\system32\svchost.exe[904] ntdll.dll!KiUserExceptionDispatcher 77046448 5 Bytes JMP 000A000A
.text C:\Windows\Explorer.EXE[1504] ntdll.dll!NtProtectVirtualMemory 77045360 5 Bytes JMP 002B000A
.text C:\Windows\Explorer.EXE[1504] ntdll.dll!NtWriteVirtualMemory 77045EE0 5 Bytes JMP 002C000A
.text C:\Windows\Explorer.EXE[1504] ntdll.dll!KiUserExceptionDispatcher 77046448 5 Bytes JMP 0019000A

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 tdrpm140.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 tdrpm140.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 tdrpm140.sys (Acronis Try&Decide Volume Filter Driver/Acronis)

Device \Driver\ACPI_HAL \Device\0000005b halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device -> \Driver\iaStor \Device\Harddisk0\DR0 858A1AC8

---- Files - GMER 1.0.15 ----

File C:\Windows\System32\drivers\rdyboost.sys suspicious modification
File C:\Windows\system32\drivers\iaStor.sys suspicious modification

---- EOF - GMER 1.0.15 ----


#5 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:11:47 PM

Posted 04 May 2010 - 12:10 PM

Hello, London76
Welcome to the Bleeping Computer Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.

If you do not make a reply in 5 days, we will have to close your topic.

You may want to keep the link to this topic in your favourites. Alternatively, you can click the button at the top bar of this topic and Track this Topic. The topics you are tracking can be found here.

Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just post back here so that we know you're still here.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.






Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



--------------------------------------------------------------------

Double click on the renamed Combofix.exe & follow the prompts.
    When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#6 London76

London76
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:11:47 PM

Posted 04 May 2010 - 02:15 PM

Hi,
Thanks so much Tom for helping me.
I don't know if this helps, but there were some files that ended up running at some stage during the process:
- Combofix told me that Spybot S&D was running, but as far as I could tell it was closed down.
- During the scan Logos indexer tried to run, so I stopped it (Logos is legit software).
- I also had CE running the whole time, which is an internet accountablility service.
- Allway sync also was running when it restarted (this also is legit software).

Combofix deleted a lot of files (but I have them backed up).

Here's the log:

ComboFix 10-05-03.06 - Duncan 04/05/2010 19:22:20.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.1916.1135 [GMT 1:00]
Running from: c:\users\Duncan\Desktop\schrauber.exe
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\%appdata%
e:\dunks documents\1 THEOLOGY\BIBLE COLLEGES\Oak Hill college\BH1_1\FlashWorksHebrew_Installer_(Win_4.2).exe
e:\dunks documents\1 THEOLOGY\BIBLE COLLEGES\Oak Hill college\BH1_1\Install_TekniaHebrew.exe
e:\dunks documents\1 THEOLOGY\BY BOOK\40 Matthew\Matthew\magicdvd.exe
e:\dunks documents\1 THEOLOGY\BY BOOK\40 Matthew\Matthew\rm2mp3.exe
e:\dunks documents\2 LIBRARY\Boice books\Doc_of_Grace.exe
e:\dunks documents\2 LIBRARY\CLS\MISC\Uninst.EXE
e:\dunks documents\2 LIBRARY\CLS\OWEN\MISC\Uninst.EXE
e:\dunks documents\2 LIBRARY\CLS\OWEN\OWEN_UPDATE.EXE
e:\dunks documents\2 LIBRARY\CLS\OWEN\WiseUpdt.exe
e:\dunks documents\2 LIBRARY\CLS\SHARED_UPDATE.EXE
e:\dunks documents\2 LIBRARY\CLS\WiseUpdt.exe
e:\dunks documents\2 LIBRARY\Journal of Biblical Counseling\Adobe\all_other_os.exe
e:\dunks documents\2 LIBRARY\Journal of Biblical Counseling\Adobe\win_31.exe
e:\dunks documents\2 LIBRARY\Journal of Biblical Counseling\Adobe\win_95.exe
e:\dunks documents\2 LIBRARY\Journal of Biblical Counseling\unins000.exe
e:\dunks documents\2 LIBRARY\LogosBiblicalGreekKeyboard\kbdlbgr\setup.exe
e:\dunks documents\chessSetup.exe
e:\dunks documents\ffdshow-20030523.exe
e:\dunks documents\HeliconFilter4.93.2Free.exe
e:\dunks documents\install_flash_player.exe
e:\dunks documents\moviestudiope90b.exe
e:\dunks documents\setup.exe
e:\dunksd~1\1 THEOLOGY\BIBLE COLLEGES\Oak Hill college\BH1_1\FlashWorksHebrew_Installer_(Win_4.2).exe
e:\dunksd~1\1 THEOLOGY\BIBLE COLLEGES\Oak Hill college\BH1_1\Install_TekniaHebrew.exe
e:\dunksd~1\1 THEOLOGY\BY BOOK\40 Matthew\Matthew\magicdvd.exe
e:\dunksd~1\1 THEOLOGY\BY BOOK\40 Matthew\Matthew\rm2mp3.exe
e:\dunksd~1\2 LIBRARY\Boice books\Doc_of_Grace.exe
e:\dunksd~1\2 LIBRARY\CLS\MISC\Uninst.EXE
e:\dunksd~1\2 LIBRARY\CLS\OWEN\MISC\Uninst.EXE
e:\dunksd~1\2 LIBRARY\CLS\OWEN\OWEN_UPDATE.EXE
e:\dunksd~1\2 LIBRARY\CLS\OWEN\WiseUpdt.exe
e:\dunksd~1\2 LIBRARY\CLS\SHARED_UPDATE.EXE
e:\dunksd~1\2 LIBRARY\CLS\WiseUpdt.exe
e:\dunksd~1\2 LIBRARY\Journal of Biblical Counseling\Adobe\all_other_os.exe
e:\dunksd~1\2 LIBRARY\Journal of Biblical Counseling\Adobe\win_31.exe
e:\dunksd~1\2 LIBRARY\Journal of Biblical Counseling\Adobe\win_95.exe
e:\dunksd~1\2 LIBRARY\Journal of Biblical Counseling\unins000.exe
e:\dunksd~1\2 LIBRARY\LogosBiblicalGreekKeyboard\kbdlbgr\setup.exe
e:\dunksd~1\ADMIN\autotest.exe
e:\dunksd~1\chessSetup.exe
e:\dunksd~1\CROSS Shared\Fch\wsff.exe
e:\dunksd~1\DELL and YIP archive\DELL D DRIVE archive\ADMIN\autotest.exe
e:\dunksd~1\downloaded software\ac3filter_1_11.exe
e:\dunksd~1\downloaded software\Ad-AwareInstaller.exe
e:\dunksd~1\downloaded software\AdbeRdr930_en_US.exe
e:\dunksd~1\downloaded software\allwaysync-8-5-1.exe
e:\dunksd~1\downloaded software\allwaysync-9-2-21.exe
e:\dunksd~1\downloaded software\BBE\SONICMAXIMIZERDXV1_1.EXE
e:\dunksd~1\downloaded software\BE4setup.EXE
e:\dunksd~1\downloaded software\BeInSync_3.2.53.Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\7010instb.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Disk1\Brolink\Brolink0.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Disk1\Diagnosis\BrCollect.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Disk1\setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Disk2\setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Canfre\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Canfre\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Canfre\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Chinese\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Chinese\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Chinese\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Czech\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Czech\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Czech\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Danish\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Danish\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Danish\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Dutch\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Dutch\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Dutch\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\English\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\English\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\English\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\French\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\French\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\French\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\German\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\German\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\German\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Hungaria\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Hungaria\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Hungaria\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Italian\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Italian\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Italian\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Norwegia\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Norwegia\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Norwegia\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Polish\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Polish\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Polish\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Portugus\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Portugus\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Portugus\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Russian\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Russian\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Russian\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Spanish\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Spanish\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Spanish\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Swedish\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Swedish\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Swedish\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Ukenglis\BRQIKMON.EXE
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Ukenglis\brrbtool.exe
e:\dunksd~1\downloaded software\Brother 7010\Data\Pcl\Win9x\Ukenglis\GETUSER.EXE
e:\dunksd~1\downloaded software\Brother 7010\For vista\7000-INST-B.EXE
e:\dunksd~1\downloaded software\Brother 7010\For vista\Data\Disk1\Brolink\Brolink0.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Data\Disk1\setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\CanFre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Chn\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Dan\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Dut\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Eng\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Fre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Ger\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Ita\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Nor\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Por\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Rus\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Spa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Swe\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7010\Usa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7020\CanFre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7020\Chn\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7020\Usa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\CanFre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Chn\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Dan\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Dut\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Eng\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Fre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Ger\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Ita\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Nor\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Por\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Rus\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Spa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Swe\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7025\Usa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\CanFre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Chn\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Dan\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Dut\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Eng\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Fre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Ger\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Ita\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Nor\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Por\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Rus\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Spa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Swe\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7220\Usa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\CanFre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Chn\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Dan\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Dut\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Eng\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Fre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Ger\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Ita\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Nor\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Por\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Rus\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Spa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Swe\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7225N\Usa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\CanFre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Chn\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Dan\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Dut\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Eng\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Fre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Ger\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Ita\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Nor\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Por\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Rus\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Spa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Swe\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7420\Usa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\CanFre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Chn\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Dan\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Dut\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Eng\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Fre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Ger\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Ita\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Nor\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Por\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Rus\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Spa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Swe\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\For vista\Setup7820N\Usa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\CanFre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Chn\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Cze\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Dan\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Dut\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Eng\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Fre\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Ger\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Hun\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Ita\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Nor\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Pol\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Por\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Rus\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Spa\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Swe\Setup.exe
e:\dunksd~1\downloaded software\Brother 7010\Setup7010\Usa\Setup.exe
e:\dunksd~1\downloaded software\Ccleaner\ccsetup219.exe
e:\dunksd~1\downloaded software\Ccleaner\ccsetup220.exe
e:\dunksd~1\downloaded software\Ccleaner\ccsetup224.exe
e:\dunksd~1\downloaded software\Ccleaner\ccsetup225.exe
e:\dunksd~1\downloaded software\chessSetup.exe
e:\dunksd~1\downloaded software\CLS_STARTUP.EXE
e:\dunksd~1\downloaded software\CovenantEyes.exe
e:\dunksd~1\downloaded software\DivXInstaller.exe
e:\dunksd~1\downloaded software\dotnetfx.exe
e:\dunksd~1\downloaded software\drvupdate-x86.exe
e:\dunksd~1\downloaded software\edirol ua1ex driver\UA1EX_WinXPDrv102\Setup.exe
e:\dunksd~1\downloaded software\edirol ua1ex driver\UA1EX_WinXPDrv102\Uninstal.exe
e:\dunksd~1\downloaded software\ENPartitionMagic7.exe
e:\dunksd~1\downloaded software\Esword\setup805.exe
e:\dunksd~1\downloaded software\Firefox Setup 3.6.3.exe
e:\dunksd~1\downloaded software\Free Legit camstadia software\camtasiaf.exe
e:\dunksd~1\downloaded software\Free Legit camstadia software\SnagIt.exe
e:\dunksd~1\downloaded software\Google Updater.exe
e:\dunksd~1\downloaded software\Google_Earth_BZXD.exe
e:\dunksd~1\downloaded software\GoogleEarthPluginSetup.exe
e:\dunksd~1\downloaded software\GoogleEarthSetup.exe
e:\dunksd~1\downloaded software\googleupdatesetup.exe
e:\dunksd~1\downloaded software\GoogleVideoUploaderInstaller.exe
e:\dunksd~1\downloaded software\GoogleVoiceAndVideoSetup.exe
e:\dunksd~1\downloaded software\GrandmasterChessSetup.exe
e:\dunksd~1\downloaded software\HandBrake-0.9.3-Win_GUI.exe
e:\dunksd~1\downloaded software\HTC\_HTC Hero_HTC Sync_2.0.4\HTC Sync_2.0.4.exe
e:\dunksd~1\downloaded software\HTC\_HTC Tattoo_HTC Sync 2.0.18_HTCSync.exe
e:\dunksd~1\downloaded software\HTC\doubleTwistSetup.exe
e:\dunksd~1\downloaded software\HTC\GmoteServer-2.0.2-Setup.exe
e:\dunksd~1\downloaded software\HTC\RUU_Hero_T-Mobile_UK_2.73.110.26_release_signed_NoDriver\RUU_Hero_T-Mobile_UK_2.73.110.26_release_signed_NoDriver.exe
e:\dunksd~1\downloaded software\install_flash_player.exe
e:\dunksd~1\downloaded software\installspeedfan437.exe
e:\dunksd~1\downloaded software\Libronix\DLSSetup.exe
e:\dunksd~1\downloaded software\Libronix\Logos4Setup.exe
e:\dunksd~1\downloaded software\Libronix\LogosBiblicalGreekKeyboard\kbdlbgr\setup.exe
e:\dunksd~1\downloaded software\LogosBiblicalGreekKeyboard.exe
e:\dunksd~1\downloaded software\mbam-setup.exe
e:\dunksd~1\downloaded software\MEDIA CONVERTER\Enhanced_Setup.exe
e:\dunksd~1\downloaded software\MEDIA CONVERTER\Standard_Setup.exe
e:\dunksd~1\downloaded software\microsoft NET\dotnetfx.exe
e:\dunksd~1\downloaded software\microsoft NET\NDP1.1sp1-KB867460-X86.exe
e:\dunksd~1\downloaded software\Mindmaps\sd8_smartpdf.exe
e:\dunksd~1\downloaded software\Mindmaps\smartdraw_YS_F500H_setup.exe
e:\dunksd~1\downloaded software\moviestudiohd90c.exe
e:\dunksd~1\downloaded software\mozy-1_16_3_4-9096.exe
e:\dunksd~1\downloaded software\MS Office 2007 Portable (6-in-1)\Microsoft Office Access 2007.exe
e:\dunksd~1\downloaded software\MS Office 2007 Portable (6-in-1)\Microsoft Office Excel 2007.exe
e:\dunksd~1\downloaded software\MS Office 2007 Portable (6-in-1)\Microsoft Office Picture Manager.exe
e:\dunksd~1\downloaded software\MS Office 2007 Portable (6-in-1)\Microsoft Office PowerPoint 2007.exe
e:\dunksd~1\downloaded software\MS Office 2007 Portable (6-in-1)\Microsoft Office Publisher 2007.exe
e:\dunksd~1\downloaded software\MS Office 2007 Portable (6-in-1)\Microsoft Office Word 2007.exe
e:\dunksd~1\downloaded software\MS Office 2007 Portable (6-in-1)\MSOffice2007-6in1-Settings\1000000b00002i\rundll32.exe
e:\dunksd~1\downloaded software\MS Office 2007 Portable (6-in-1)\MSOffice2007-6in1-Settings\1000000b00002i\verclsid.exe
e:\dunksd~1\downloaded software\MS Office 2007 Portable (6-in-1)\MSOffice2007-6in1-Settings\300000008c00002i\offlb.exe
e:\dunksd~1\downloaded software\MSAoE.exe
e:\dunksd~1\downloaded software\N360Downloader.exe
e:\dunksd~1\downloaded software\NB DEMO\_ISDel.exe
e:\dunksd~1\downloaded software\NB DEMO\Setup.exe
e:\dunksd~1\downloaded software\NB DEMO\Setup16.exe
e:\dunksd~1\downloaded software\NB\_ISDel.exe
e:\dunksd~1\downloaded software\NB\NB 9\lws9pre3.exe
e:\dunksd~1\downloaded software\NB\pdf352std.exe
e:\dunksd~1\downloaded software\NB\Setup.exe
e:\dunksd~1\downloaded software\NB\Setup16.exe
e:\dunksd~1\downloaded software\NET\dotnetfx35setup.exe
e:\dunksd~1\downloaded software\NewBluefx\NewBlueFilmEffectsForWindowsSetup13.exe
e:\dunksd~1\downloaded software\NewBluefx\NewBlueMotionBlendsForWindowsSetup23.exe
e:\dunksd~1\downloaded software\NIS09EN.exe
e:\dunksd~1\downloaded software\Norton systemworksBasic\setup.exe
e:\dunksd~1\downloaded software\Nortonsystemworksbasic setup.exe
e:\dunksd~1\downloaded software\Nota Bene 8\8k update unpacked\_ISDel.exe
e:\dunksd~1\downloaded software\Nota Bene 8\8k update unpacked\Setup.exe
e:\dunksd~1\downloaded software\Nota Bene 8\8k update unpacked\setup16.exe
e:\dunksd~1\downloaded software\Nota Bene 8\fpp322.exe
e:\dunksd~1\downloaded software\Nota Bene 8\lws80g.exe
e:\dunksd~1\downloaded software\Nota Bene 8\lws80uk.exe
e:\dunksd~1\downloaded software\Nota Bene 8i\lws80i.exe
e:\dunksd~1\downloaded software\Nota Bene 8i\unpacked\_ISDel.exe
e:\dunksd~1\downloaded software\Nota Bene 8i\unpacked\Setup.exe
e:\dunksd~1\downloaded software\Nota Bene 8i\unpacked\Setup16.exe
e:\dunksd~1\downloaded software\PartitionMagic 8.0\BTIniNt.exe
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DOCS\PM8Flash.exe
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DOS\BTIni.exe
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DOS\FSIMAGE.EXE
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DOS\partinfo.exe
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DOS\PQBOOT.EXE
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DOS\PQBOOTX.EXE
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DOS\PQMAGIC.EXE
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DOS\PTEDIT.EXE
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DOS\SNUTIL.EXE
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DOS\WRPROG.EXE
e:\dunksd~1\downloaded software\PartitionMagic 8.0\DrvMap.exe
e:\dunksd~1\downloaded software\PartitionMagic 8.0\PartIn.exe
e:\dunksd~1\downloaded software\PartitionMagic 8.0\PartIn9x.exe
e:\dunksd~1\downloaded software\PartitionMagic 8.0\PartInNT.exe
e:\dunksd~1\downloaded software\PartitionMagic 8.0\PMagic.exe
e:\dunksd~1\downloaded software\PartitionMagic 8.0\PMagic9x.exe
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\DOSYSTEM\CHKDSK.EXE
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\DOSYSTEM\EMM386.EXE
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\DOSYSTEM\FLOPPY.EXE
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\DOSYSTEM\FLOPPY9x.EXE
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\DOSYSTEM\FLOPPYME.EXE
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\DOSYSTEM\NWCDEX.EXE
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\DOSYSTEM\PQBOOT.EXE
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\DOSYSTEM\PTEDIT32.EXE
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\DOSYSTEM\restrmbr.exe
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\DOSYSTEM\WRPROG.EXE
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Rescueme\Setup.exe
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Setup\instmsia.exe
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Setup\instmsiw.exe
e:\dunksd~1\downloaded software\PartitionMagic\BTMagic\Setup\setup.exe
e:\dunksd~1\downloaded software\PartitionMagic\DKeeper\instmsia.exe
e:\dunksd~1\downloaded software\PartitionMagic\DKeeper\instmsiw.exe
e:\dunksd~1\downloaded software\PartitionMagic\DKeeper\setup.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition Magic 8 Pro FULL BY PILPELON .exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition Magic 8.0 serial.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\DOSYSTEM\CHKDSK.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\DOSYSTEM\EMM386.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\DOSYSTEM\FLOPPY.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\DOSYSTEM\FLOPPY9x.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\DOSYSTEM\FLOPPYME.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\DOSYSTEM\NWCDEX.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\DOSYSTEM\PQBOOT.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\DOSYSTEM\PTEDIT32.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\DOSYSTEM\restrmbr.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\DOSYSTEM\WRPROG.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Rescueme\Setup.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Setup\instmsia.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Setup\instmsiw.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\BTMagic\Setup\setup.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\DKeeper\instmsia.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\DKeeper\instmsiw.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\DKeeper\setup.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\RESCUEME\DOSYSTEM\CHKDSK.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\RESCUEME\DOSYSTEM\EMM386.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\RESCUEME\DOSYSTEM\FLOPPY.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\RESCUEME\DOSYSTEM\FLOPPY9x.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\RESCUEME\DOSYSTEM\FLOPPYME.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\RESCUEME\DOSYSTEM\NWCDEX.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\RESCUEME\DOSYSTEM\PTEDIT32.EXE
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\RESCUEME\Setup.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\Setup\instmsia.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\Setup\instmsiw.exe
e:\dunksd~1\downloaded software\PartitionMagic\Partition magic8\Setup\setup.exe
e:\dunksd~1\downloaded software\PartitionMagic\partitionmagic2\ENPartitionMagic7.exe
e:\dunksd~1\downloaded software\PartitionMagic\RESCUEME\DOSYSTEM\CHKDSK.EXE
e:\dunksd~1\downloaded software\PartitionMagic\RESCUEME\DOSYSTEM\EMM386.EXE
e:\dunksd~1\downloaded software\PartitionMagic\RESCUEME\DOSYSTEM\FLOPPY.EXE
e:\dunksd~1\downloaded software\PartitionMagic\RESCUEME\DOSYSTEM\FLOPPY9x.EXE
e:\dunksd~1\downloaded software\PartitionMagic\RESCUEME\DOSYSTEM\FLOPPYME.EXE
e:\dunksd~1\downloaded software\PartitionMagic\RESCUEME\DOSYSTEM\NWCDEX.EXE
e:\dunksd~1\downloaded software\PartitionMagic\RESCUEME\DOSYSTEM\PTEDIT32.EXE
e:\dunksd~1\downloaded software\PartitionMagic\RESCUEME\Setup.exe
e:\dunksd~1\downloaded software\PartitionMagic\Setup\instmsia.exe
e:\dunksd~1\downloaded software\PartitionMagic\Setup\instmsiw.exe
e:\dunksd~1\downloaded software\PartitionMagic\Setup\setup.exe
e:\dunksd~1\downloaded software\PDA\CopilotStoragecard\2577\AUTORUN.EXE
e:\dunksd~1\downloaded software\PDA\esword windowmob5\chm_ebook_reader_en_trial\chm_ebook_reader_trial.exe
e:\dunksd~1\downloaded software\PDA\esword windowmob5\ppc2003setup301.exe
e:\dunksd~1\downloaded software\PDA\esword windowmob5\ppc2005setup301.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\BHS_Parsed_Unicode.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\BHS_Unicode.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\BHS_Unicode\Install_OliveTree.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\BibleAtlas_Demo.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\BibleReader_210c.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\BibleReader_368_193.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\Calvin_Institutes.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\Calvin_ofPrayer.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\Douay-Rheims.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\EDNT.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\EDNT\Feb10\EDNT.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\EDNT\Install_OliveTree.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\ExploringTheBible11_OliveTree.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\ExploringTheBible4_OliveTree.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\ExploringTheBible6_OliveTree.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\ExploringTheBible9_OliveTree.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\FBMeyerIntoHoliest.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\GNT_WHT_NA27.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\Gramcord.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\HMT.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\HMT\Install_OliveTree.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\HMT_Parsed.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\JFB.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\JohnOwen_Piper.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\LatinVulgate.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\MurrayDeeperChristian.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\NASBStrongs.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\NETBible.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\PiperSermons.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\StAugConfessions.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\SysTheo_Grudem_with_ESV.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\UBS_HB_NT.exe
e:\dunksd~1\downloaded software\PDA\Olive Tree\WhitefieldSermons.exe
e:\dunksd~1\downloaded software\PDA\Paid for pocket mechanic\Pocket_Mechanic_159\Pocket Mechanic Setup.exe
e:\dunksd~1\downloaded software\PDA\Paid for pocket mechanic\Pocket_Mechanic_159\Precompiled - All Platforms\ARM.PPC\Pocket Mechanic.exe
e:\dunksd~1\downloaded software\PDA\Paid for pocket mechanic\Pocket_Mechanic_159\Precompiled - All Platforms\ARM.PPC2002.WM2003\Pocket Mechanic.exe
e:\dunksd~1\downloaded software\PDA\Paid for pocket mechanic\Pocket_Mechanic_159\Precompiled - All Platforms\MIPS.PPC\Pocket Mechanic.exe
e:\dunksd~1\downloaded software\PDA\Paid for pocket mechanic\Pocket_Mechanic_159\Precompiled - All Platforms\SH3.PPC\Pocket Mechanic.exe
e:\dunksd~1\downloaded software\PDA\pocket music download July07\pmusic.exe
e:\dunksd~1\downloaded software\PDA\pocket_mechanic_159\Pocket Mechanic Setup.exe
e:\dunksd~1\downloaded software\PDA\pocketmusic\pmusic.exe
e:\dunksd~1\downloaded software\PDA\Rom update\HER_TMUK_1211103_1050500_WWE_Ship.exe
e:\dunksd~1\downloaded software\picasa36-setup.exe
e:\dunksd~1\downloaded software\Plink\plink.exe
e:\dunksd~1\downloaded software\pradis6_01_0024.exe
e:\dunksd~1\downloaded software\PSP\PSPMixPack.exe
e:\dunksd~1\downloaded software\PSP\PSPVW.EXE
e:\dunksd~1\downloaded software\PSP\VintageWarmerupdate\PSPvw.exe
e:\dunksd~1\downloaded software\Samsung\DVD writer\Liveudpate20_Eng_Install.exe
e:\dunksd~1\downloaded software\sdsetup.exe
e:\dunksd~1\downloaded software\Silverlight.2.0.exe
e:\dunksd~1\downloaded software\skype\mikogo-starter.exe
e:\dunksd~1\downloaded software\SkypeSetup.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\BlueSoleil_2.3_standard_Release_060728\BlueSoleil_2.3_Release_060728\instmsia.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\BlueSoleil_2.3_standard_Release_060728\BlueSoleil_2.3_Release_060728\instmsiw.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\BlueSoleil_2.3_standard_Release_060728\BlueSoleil_2.3_Release_060728\setup.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\Smoothboard_Setup.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\wiiboard\dotnetfx35setup.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\wiiboard\iwiiboard_ProV4.0_setup\iwiiboard_ProV4.0_setup.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\WiimoteWhiteboardv03\WiimoteWhiteboard\source\windowsxp\WiimoteTest\bin\Debug\WiimoteWhiteboard v0.3.vshost.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\WiimoteWhiteboardv03\WiimoteWhiteboard\source\windowsxp\WiimoteTest\bin\Release\WiimoteWhiteboard v0.3.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\WiimoteWhiteboardv03\WiimoteWhiteboard\source\windowsxp\WiimoteTest\obj\Debug\WiimoteWhiteboard v0.2.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\WiimoteWhiteboardv03\WiimoteWhiteboard\source\windowsxp\WiimoteTest\obj\Debug\WiimoteWhiteboard.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\WiimoteWhiteboardv03\WiimoteWhiteboard\source\windowsxp\WiimoteTest\obj\Release\WiimoteWhiteboard v0.3.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\WiimoteWhiteboardv03\WiimoteWhiteboard\source\windowsxp\WiimoteTest\obj\Release\WiimoteWhiteboard.exe
e:\dunksd~1\downloaded software\Smartboard software for wiimote\WiimoteWhiteboardv03\WiimoteWhiteboard\WiimoteWhiteboard v0.3.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\dotnetfx.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Microsoft .NET Framework 1.1sp1-KB867460-X86.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Sonic Foundry MainConcept MPEG 1.2 Plugin v1.0\Sonic Foundry MainConcept MPEG 1.2 Plugin v1.0.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Capturer\Video Capture 2.0e.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\50comupd.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\expressfx1.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\expressfx2.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\hhupd.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\InstMsi-x86a.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\InstMsi-x86w.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\ReelDVD vs 3.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\Setup.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\Sonic Foundary Vegas DVD v4 manual.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\Sonic.Scenarist.v2.7.0241.incl.crack\Sonic.Scenarist.v2.7.0241.incl.crack.fixed-fYt.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\Sound Forge Noise Reduction 2.0.EXE
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\Vegas v4.0 plugin fx\Plugin Setup\setup.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\Vegas v4.0 plugin fx\vegas video - plugin -SfMPEGWeb_bld22.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\Vegas v4.0 ! KeyGen\! KeyGen.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\Vegas Video Plug-In Pack\InstMsi-x86a.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\Vegas Video Plug-In Pack\InstMsi-x86w.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\Vegas Video Plug-In Pack\videofxSetup.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\vegas4.0d.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\videofx10.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\wmfdist.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\Vegas Video 4.0 (115)\wmfdist2.exe
e:\dunksd~1\downloaded software\Sonic + Sony Vegas 4.0-6.0a+Keygen+MainConcept plugin+Pluginīs\vegas60-trial.exe
e:\dunksd~1\downloaded software\Sony Vegas 6.0 + Sony DVD Architect 3.0 (Incl Keygen)shared by DeeNay for www.torrent.to\Sony Vegas Video 6 keygen\50comupd.exe
e:\dunksd~1\downloaded software\Sony Vegas 6.0 + Sony DVD Architect 3.0 (Incl Keygen)shared by DeeNay for www.torrent.to\Sony Vegas Video 6 keygen\hhupd.exe
e:\dunksd~1\downloaded software\Sony Vegas 6.0 + Sony DVD Architect 3.0 (Incl Keygen)shared by DeeNay for www.torrent.to\Sony Vegas Video 6 keygen\InstMsi-x86a.exe
e:\dunksd~1\downloaded software\Sony Vegas 6.0 + Sony DVD Architect 3.0 (Incl Keygen)shared by DeeNay for www.torrent.to\Sony Vegas Video 6 keygen\InstMsi-x86w.exe
e:\dunksd~1\downloaded software\Sony Vegas 6.0 + Sony DVD Architect 3.0 (Incl Keygen)shared by DeeNay for www.torrent.to\Sony Vegas Video 6 keygen\mediamgr\msde\MDAC_TYP.EXE
e:\dunksd~1\downloaded software\Sony Vegas 6.0 + Sony DVD Architect 3.0 (Incl Keygen)shared by DeeNay for www.torrent.to\Sony Vegas Video 6 keygen\mediamgr\msde\MSDESetup.exe
e:\dunksd~1\downloaded software\Sony Vegas 6.0 + Sony DVD Architect 3.0 (Incl Keygen)shared by DeeNay for www.torrent.to\Sony Vegas Video 6 keygen\mediamgr\msde\msisetup.exe
e:\dunksd~1\downloaded software\Sony Vegas 6.0 + Sony DVD Architect 3.0 (Incl Keygen)shared by DeeNay for www.torrent.to\Sony Vegas Video 6 keygen\mediamgr\Setup.exe
e:\dunksd~1\downloaded software\Sony Vegas 6.0 + Sony DVD Architect 3.0 (Incl Keygen)shared by DeeNay for www.torrent.to\Sony Vegas Video 6 keygen\Setup.exe
e:\dunksd~1\downloaded software\Sony Vegas 6.0 + Sony DVD Architect 3.0 (Incl Keygen)shared by DeeNay for www.torrent.to\Sony.DVD.Architect.v3.0.Incl.Keygen-SSG\dvdarchitect30.exe
e:\dunksd~1\downloaded software\spybotsd162.exe
e:\dunksd~1\downloaded software\SpySweeperSNRSetup_EN.exe
e:\dunksd~1\downloaded software\spyware software\a2FreeSetup.exe
e:\dunksd~1\downloaded software\spyware software\Defogger.exe
e:\dunksd~1\downloaded software\spyware software\HJTInstall.exe
e:\dunksd~1\downloaded software\spywaredetector.exe
e:\dunksd~1\downloaded software\SUPERAntiSpyware.exe
e:\dunksd~1\downloaded software\TDK\lpcw_50_software_update__english.exe
e:\dunksd~1\downloaded software\TomTom\TomTomHOME2winlatest.exe
e:\dunksd~1\downloaded software\trial_photos9dlv_uk.exe
e:\dunksd~1\downloaded software\TrueImage2009_d_en.exe
e:\dunksd~1\downloaded software\UA-1EX_win_vista\UA-1EX_win_vista\Setup.exe
e:\dunksd~1\downloaded software\UA-1EX_win_vista\UA-1EX_win_vista\Uninstal.exe
e:\dunksd~1\downloaded software\utorrent.exe
e:\dunksd~1\downloaded software\veetle-0.9.14.exe
e:\dunksd~1\downloaded software\Vegas 9\audiostudio90d-trial_enu.exe
e:\dunksd~1\downloaded software\Vegas 9\dvdarchitectstudio45d_enu.exe
e:\dunksd~1\downloaded software\Vegas 9\moviestudiope90b.exe
e:\dunksd~1\downloaded software\VirtumundoBeGone.exe
e:\dunksd~1\downloaded software\vlc\vlc-0.9.6-win32.exe
e:\dunksd~1\downloaded software\vlc\vlc-0.9.8a-win32.exe
e:\dunksd~1\downloaded software\vlc\vlc-0.9.9-win32.exe
e:\dunksd~1\downloaded software\vlc\vlc-1.0.0-win32.exe
e:\dunksd~1\downloaded software\VundoFix.exe
e:\dunksd~1\downloaded software\Waves\35update\WavesGold3.5NoDocs.exe
e:\dunksd~1\downloaded software\Waves\Restorationbundle.exe
e:\dunksd~1\downloaded software\Waves\Waves Masters Bundle v1.0\WavesMBundle.EXE
e:\dunksd~1\downloaded software\Waves\Waves_3.5\waves3.5fx.EXE
e:\dunksd~1\downloaded software\Waves\Waves_v3.5.exe
e:\dunksd~1\downloaded software\Waves\Waves2\35update\WavesGold3.5NoDocs.exe
e:\dunksd~1\downloaded software\Waves\Wavesrest.Bundle.exe
e:\dunksd~1\downloaded software\Waves\Wavesrestoration.exe
e:\dunksd~1\downloaded software\WGAPluginInstall.exe
e:\dunksd~1\downloaded software\Windows validation plugin\WGAPluginInstall.exe
e:\dunksd~1\downloaded software\wmpfirefoxplugin.exe
e:\dunksd~1\downloaded software\wrar390.exe
e:\dunksd~1\ffdshow-20030523.exe
e:\dunksd~1\HeliconFilter4.93.2Free.exe
e:\dunksd~1\install_flash_player.exe
e:\dunksd~1\Logos\DLSSetup.exe
e:\dunksd~1\moviestudiope90b.exe
e:\dunksd~1\My Music\NET Bible mp3s\NET_Bible_HTML\fonts\bssw31.exe
e:\dunksd~1\My Music\NET Bible mp3s\NET_Bible_HTML\fonts\bssw95.exe
e:\dunksd~1\setup.exe
e:\dunksd~1\TomTom\HOME\Backup\GO\Backup01\InternalMemory\InstallTomTomHOME.exe
e:\dunksd~1\WM_Duncan1 My Documents\Olive Tree Bible Software\BibleReader_ce30_arm.exe

----- BITS: Possible infected sites -----

hxxp://resources.assets.logos.com
Infected copy of c:\windows\system32\drivers\rdyboost.sys was found and disinfected
Restored copy from - Kitty had a snack tongue.gif
.
((((((((((((((((((((((((( Files Created from 2010-04-04 to 2010-05-04 )))))))))))))))))))))))))))))))
.

2010-05-04 18:36 . 2010-05-04 18:40 -------- d-----w- c:\users\Duncan\AppData\Local\temp
2010-05-04 18:36 . 2010-05-04 18:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-04-30 10:16 . 2010-04-30 10:16 -------- d-----w- c:\users\Duncan\AppData\Local\ElevatedDiagnostics
2010-04-29 10:28 . 2009-09-26 05:58 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys
2010-04-29 10:28 . 2009-12-11 07:44 133720 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2010-04-29 10:28 . 2009-12-11 07:38 1037312 ----a-w- c:\windows\system32\lsasrv.dll
2010-04-26 16:31 . 2010-04-26 16:31 -------- d-----w- c:\users\Duncan\AppData\Local\avG
2010-04-26 16:31 . 2010-04-26 16:31 -------- d-----w- c:\programdata\avG
2010-04-22 16:24 . 2010-04-22 16:24 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-22 16:24 . 2010-05-04 18:06 -------- d-----w- c:\users\Duncan\AppData\Local\CrashDumps
2010-04-19 17:22 . 2010-04-19 17:22 -------- d-----w- c:\users\Duncan\AppData\Local\Diagnostics
2010-04-17 19:04 . 2010-04-17 19:04 -------- d-----w- c:\windows\system32\drivers\NSS
2010-04-17 19:04 . 2010-04-17 19:04 -------- d-----w- c:\program files\Norton Security Scan
2010-04-17 16:03 . 2010-04-17 16:05 -------- d-----w- c:\programdata\DivX
2010-04-16 20:57 . 2009-12-03 06:09 44080 ----a-r- c:\windows\system32\drivers\SymIMV.sys
2010-04-16 19:07 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-04-16 19:07 . 2010-02-27 12:07 3899280 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-16 19:07 . 2010-02-27 12:07 3954568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-16 15:50 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2010-04-16 15:47 . 2010-03-08 21:33 427520 ----a-w- c:\windows\system32\vbscript.dll
2010-04-16 15:47 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-16 15:47 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-16 15:47 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-13 12:15 . 2010-04-13 12:15 -------- d-----w- c:\program files\Trend Micro
2010-04-13 11:57 . 2010-04-13 11:57 -------- d-----w- c:\programdata\SITEguard
2010-04-13 11:56 . 2010-04-13 11:56 -------- d-----w- c:\program files\Common Files\iS3
2010-04-13 11:56 . 2010-04-13 14:48 -------- d-----w- c:\programdata\STOPzilla!
2010-04-13 10:44 . 2009-11-26 06:41 172592 ----a-r- c:\windows\system32\drivers\symefa.sys
2010-04-13 10:44 . 2009-11-22 00:43 340016 ----a-r- c:\windows\system32\drivers\symtdiv.sys
2010-04-13 10:44 . 2009-10-15 03:50 328752 ----a-r- c:\windows\system32\drivers\symds.sys
2010-04-13 10:44 . 2010-02-27 02:23 116784 ----a-w- c:\windows\system32\drivers\ironx86.sys
2010-04-13 10:44 . 2010-02-27 02:23 43696 ----a-w- c:\windows\system32\drivers\srtspx.sys
2010-04-13 10:44 . 2010-02-25 23:22 501888 ----a-w- c:\windows\system32\drivers\cchpx86.sys
2010-04-13 10:17 . 2010-04-13 10:17 -------- d-----w- c:\users\Duncan\AppData\Local\Symantec
2010-04-12 23:50 . 2010-02-24 09:16 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-04-12 23:46 . 2009-01-15 11:19 23848 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-04-12 23:46 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-04-12 23:46 . 2010-04-13 10:37 -------- d-----w- c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2010-04-12 23:46 . 2010-04-13 10:37 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-04-12 23:46 . 2010-04-13 10:37 -------- d-----w- c:\program files\Symantec
2010-04-12 23:46 . 2010-04-13 10:28 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-04-12 23:45 . 2010-04-13 10:47 -------- d-----w- c:\windows\system32\drivers\N360
2010-04-12 23:45 . 2010-04-12 23:45 -------- d-----w- c:\program files\Norton 360
2010-04-12 23:43 . 2010-04-17 19:04 -------- d-----w- c:\program files\NortonInstaller
2010-04-10 18:01 . 2010-04-14 12:36 -------- d-----w- c:\users\Duncan\AppData\Local\Sony
2010-04-10 17:59 . 2010-04-10 17:59 -------- d-----w- c:\program files\Vstplugins
2010-04-10 17:59 . 2010-04-10 17:59 -------- d-----w- c:\programdata\Sony
2010-04-10 17:57 . 2010-04-14 12:32 -------- d-----w- c:\program files\Sony Setup
2010-04-10 17:33 . 2010-04-10 17:33 -------- d-----w- c:\users\Duncan\AppData\Roaming\MAGIX
2010-04-10 17:29 . 2010-04-10 17:29 -------- d-----w- c:\users\Duncan\AppData\Local\Xara
2010-04-10 17:28 . 2010-04-10 17:28 -------- d-----w- c:\program files\Common Files\MAGIX Shared
2010-04-10 17:28 . 2010-04-10 17:30 -------- d-----w- c:\program files\MAGIX
2010-04-10 17:27 . 2010-04-10 17:30 -------- d-----w- c:\programdata\MAGIX
2010-04-10 17:27 . 2010-04-10 17:27 -------- d-----w- c:\program files\Common Files\MAGIX Services
2010-04-09 02:48 . 2010-04-09 02:52 -------- d-----w- c:\users\Duncan\AppData\Local\ApplicationHistory
2010-04-09 02:48 . 2010-04-09 02:48 -------- d-----w- c:\users\Duncan\AppData\Roaming\Publish Providers
2010-04-09 02:35 . 2010-04-09 02:35 -------- d-----w- c:\windows\system32\URTTEMP
2010-04-08 17:18 . 2010-04-30 14:00 -------- d-----w- C:\For E DRIVE
2010-04-08 03:13 . 2010-04-08 03:13 -------- d-----w- c:\users\Duncan\AppData\Local\Helicon
2010-04-08 03:12 . 2010-04-08 03:12 -------- d-----w- c:\program files\Movie Player ActiveX Control
2010-04-08 03:12 . 2010-04-08 03:12 -------- d-----w- c:\program files\Audio Capture ActiveX Control
2010-04-08 03:11 . 2010-04-08 03:11 -------- d-----w- c:\program files\Helicon Software
2010-04-07 20:44 . 2010-04-07 20:44 -------- d-----w- c:\users\Duncan\AppData\Roaming\Panasonic
2010-04-07 20:32 . 2006-02-20 18:17 33408 ----a-w- c:\windows\system32\drivers\cdrbsdrv.sys
2010-04-07 20:32 . 2007-06-15 11:57 59488 ----a-w- c:\windows\system32\GenSvcInst.exe
2010-04-07 20:32 . 2007-06-15 11:57 145504 ----a-w- c:\windows\system32\bgsvcgen.exe
2010-04-07 20:31 . 2008-09-25 20:07 45056 ----a-w- c:\windows\system32\PhDi2.sys
2010-04-07 20:31 . 2010-04-07 20:31 -------- d-----w- c:\program files\Panasonic
2010-04-06 23:49 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-04-05 20:13 . 2010-04-05 20:13 0 ----a-w- c:\windows\nsreg.dat
2010-04-05 11:18 . 2010-02-04 15:53 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-04-05 11:18 . 2010-04-05 11:18 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-05 11:13 . 2010-04-05 11:13 -------- dc-h--w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-05 11:12 . 2010-04-05 11:18 -------- d-----w- c:\programdata\Lavasoft
2010-04-05 11:12 . 2010-04-05 11:13 -------- d-----w- c:\program files\Lavasoft
2010-04-05 00:30 . 2010-04-05 00:30 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-04-05 00:30 . 2010-04-05 00:30 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-04-05 00:30 . 2010-04-05 00:30 -------- d-----w- c:\users\Duncan\AppData\Roaming\SUPERAntiSpyware.com
2010-04-04 19:55 . 2010-04-04 19:55 -------- d-----w- c:\users\Duncan\AppData\Roaming\Malwarebytes
2010-04-04 19:54 . 2010-03-29 14:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-04 19:54 . 2010-04-04 19:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-04 19:54 . 2010-04-04 19:54 -------- d-----w- c:\programdata\Malwarebytes
2010-04-04 19:54 . 2010-03-29 14:24 20824 ----a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-04 14:19 . 2009-08-11 20:41 -------- d-----w- c:\users\Duncan\AppData\Roaming\uTorrent
2010-05-04 14:14 . 2009-08-11 23:19 -------- d-----w- c:\users\Duncan\AppData\Roaming\vlc
2010-05-04 12:33 . 2009-08-14 14:48 -------- d-----w- c:\users\Duncan\AppData\Roaming\CE
2010-05-03 20:38 . 2009-08-25 20:17 -------- d-----w- c:\users\Duncan\AppData\Roaming\dvdcss
2010-05-03 11:18 . 2010-04-05 11:18 893952 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-05-03 11:18 . 2010-04-05 11:18 574632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-05-03 11:18 . 2010-04-05 11:18 443344 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-05-03 11:18 . 2010-04-05 11:18 866224 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-05-03 11:18 . 2010-04-05 11:18 871320 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-05-03 11:18 . 2010-04-05 11:18 1598464 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-05-03 11:18 . 2010-04-05 11:18 834248 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-05-03 11:18 . 2010-04-05 11:18 1285864 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-04-29 11:19 . 2010-04-08 11:19 566432 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\EmailScanner.dll
2010-04-29 11:19 . 2010-04-05 11:18 211600 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-04-29 11:19 . 2010-04-05 11:18 15880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-04-29 11:19 . 2010-04-05 11:18 397480 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-04-29 11:19 . 2010-04-05 11:18 221920 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2010-04-29 11:19 . 2010-04-05 11:18 167824 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-04-29 11:19 . 2010-04-05 11:18 6306640 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2010-04-29 11:19 . 2010-04-05 11:18 335728 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-04-29 11:19 . 2010-04-05 11:18 95248 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-04-29 11:19 . 2010-04-05 11:18 16456 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-04-29 11:19 . 2010-04-05 11:18 967640 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-04-29 11:19 . 2010-04-29 11:18 755096 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2010-04-26 17:18 . 2010-04-05 00:31 117760 ----a-w- c:\users\Duncan\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-04-26 17:11 . 2010-04-03 17:17 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-04-17 19:04 . 2009-08-01 17:27 -------- d-----w- c:\programdata\Symantec
2010-04-17 19:04 . 2009-08-01 17:25 -------- d-----w- c:\programdata\Norton
2010-04-17 16:04 . 2010-04-17 16:04 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-04-17 16:04 . 2009-09-12 19:16 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-04-17 16:04 . 2010-04-17 16:04 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-04-17 16:03 . 2010-04-17 16:03 144696 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-04-17 16:03 . 2010-04-17 16:05 754984 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-04-17 16:03 . 2010-04-17 16:05 1180952 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-04-17 10:59 . 2010-03-09 01:33 168680 ----a-w- c:\users\Duncan\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-16 18:59 . 2008-08-07 16:58 -------- d-----w- c:\programdata\Microsoft Help
2010-04-16 09:39 . 2009-07-13 23:22 173648 ----a-w- c:\windows\system32\drivers\rdyboost.sys
2010-04-14 12:36 . 2009-11-03 13:58 -------- d-----w- c:\users\Duncan\AppData\Roaming\Sony
2010-04-14 12:32 . 2009-11-03 13:54 -------- d-----w- c:\program files\Sony
2010-04-13 14:43 . 2010-04-13 14:42 768 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-04-13 10:37 . 2010-04-12 23:46 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-04-13 10:37 . 2010-04-12 23:46 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-04-12 23:48 . 2009-08-01 17:21 -------- d-----w- c:\programdata\NortonInstaller
2010-04-12 23:01 . 2010-03-13 23:54 -------- d-----w- c:\program files\LogMeIn
2010-04-12 00:00 . 2010-05-04 17:30 1647984 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100504.004\NAVEX32A.DLL
2010-04-12 00:00 . 2010-05-04 17:30 84912 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100504.004\NAVENG.SYS
2010-04-12 00:00 . 2010-05-04 17:30 371248 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100504.004\EECTRL.SYS
2010-04-12 00:00 . 2010-05-04 17:30 2747440 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100504.004\CCERASER.DLL
2010-04-12 00:00 . 2010-05-04 17:30 259440 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100504.004\ECMSVR32.DLL
2010-04-12 00:00 . 2010-05-04 17:30 177520 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100504.004\NAVENG32.DLL
2010-04-12 00:00 . 2010-05-04 17:30 1324720 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100504.004\NAVEX15.SYS
2010-04-12 00:00 . 2010-05-04 17:30 102448 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100504.004\ERASER.SYS
2010-04-09 11:07 . 2010-02-06 14:48 -------- d-----w- c:\users\Duncan\AppData\Roaming\WTablet
2010-04-07 20:30 . 2008-08-07 16:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-07 17:44 . 2008-08-07 16:54 -------- d-----w- c:\program files\Google
2010-04-06 01:37 . 2008-08-07 16:54 -------- d-----w- c:\program files\Picasa2
2010-04-05 11:18 . 2010-04-05 11:18 95024 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2010-04-05 11:18 . 2010-04-05 11:18 516480 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\EmailScannerAddin.dll
2010-04-05 11:18 . 2010-04-05 11:18 566608 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\sbap.dll
2010-04-05 11:18 . 2010-04-05 11:18 17632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\WSCUpdate.dll
2010-04-05 11:18 . 2010-04-05 11:18 1230160 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-04-05 11:18 . 2010-04-05 11:18 247120 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-04-05 00:31 . 2010-04-05 00:31 52224 ----a-w- c:\users\Duncan\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-04-05 00:29 . 2008-08-07 16:54 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-04-04 03:29 . 2010-04-04 03:29 -------- d-----w- c:\users\Duncan\AppData\Roaming\myphotobook
2010-04-03 20:20 . 2010-04-03 17:17 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-25 23:29 . 2010-04-13 10:40 786800 ----a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\components\coFFPlgn.dll
2010-03-24 20:38 . 2010-03-24 20:38 536112 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100324.001\BHDrvx86.sys
2010-03-24 20:38 . 2010-03-24 20:38 201616 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100324.001\BHRules.dll
2010-03-24 20:38 . 2010-03-24 20:38 1407888 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100324.001\BHEngine.dll
2010-03-24 20:38 . 2010-03-24 20:38 678960 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100324.001\BHDrvx64.sys
2010-03-24 20:38 . 2010-03-24 20:38 611216 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100324.001\bbRGen.dll
2010-03-22 18:38 . 2010-03-22 18:38 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-03-18 14:48 . 2010-03-09 21:06 -------- d-----w- c:\program files\GmoteServer
2010-03-13 23:55 . 2010-03-13 23:55 -------- d-----w- c:\programdata\LogMeIn
2010-03-11 20:44 . 2009-09-03 15:12 -------- d-----w- c:\program files\Steam
2010-03-11 17:27 . 2009-09-03 15:12 -------- d-----w- c:\program files\Common Files\Steam
2010-03-09 21:10 . 2010-03-09 21:10 -------- d-----w- c:\users\Duncan\AppData\Roaming\Gmote
2010-03-09 21:10 . 2010-03-09 21:10 -------- d--h--w- c:\program files\InstallJammer Registry
2010-03-09 20:56 . 2010-03-09 20:56 -------- d-----w- c:\users\Duncan\AppData\Roaming\Realtime Soft
2010-03-09 17:23 . 2010-03-09 17:23 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-03-09 17:06 . 2010-03-09 17:06 24576 ----a-w- c:\windows\system32\drivers\ANDROIDUSB.sys
2010-03-09 17:05 . 2010-03-09 17:05 -------- d-----w- c:\program files\Common Files\Teleca Shared
2010-03-09 17:05 . 2010-03-09 17:05 -------- d-----w- c:\programdata\HTC
2010-03-09 17:05 . 2010-03-09 17:05 -------- d-----w- c:\programdata\Teleca
2010-03-09 17:05 . 2010-03-06 04:27 -------- d-----w- c:\program files\HTC
2010-03-09 15:00 . 2010-03-09 16:35 115081 ----a-w- c:\windows\system32\drivers\androidusb.INF
2010-03-09 15:00 . 2009-06-09 14:41 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-03-09 14:24 . 2009-08-29 14:01 778240 ----a-w- c:\users\Duncan\AppData\Roaming\CE\CEUpgrade.exe
2010-03-09 00:57 . 2010-03-09 00:57 21924 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-09 00:28 . 2010-02-26 00:01 -------- dc-h--w- c:\programdata\{CDF61231-6AD7-4969-B4DD-9E6C0F51DD5E}
2010-03-09 00:27 . 2009-08-12 15:10 -------- d-----w- c:\programdata\Libronix DLS
2010-03-09 00:26 . 2008-08-07 16:34 -------- d-----w- c:\program files\Ulead Systems
2010-03-09 00:26 . 2008-08-07 16:24 -------- d-----w- c:\program files\TOSHIBA
2010-03-09 00:26 . 2009-11-05 13:57 -------- d-----w- c:\program files\Teknia
2010-03-09 00:26 . 2009-10-16 15:09 -------- d-----w- c:\program files\TechSmith
2010-03-09 00:26 . 2009-08-02 17:06 -------- d-----w- c:\program files\Targus BT Mouse
2010-03-09 00:26 . 2010-02-06 14:44 -------- d-----w- c:\program files\Tablet
2010-03-09 00:26 . 2009-09-22 00:46 -------- d-----w- c:\program files\SystemRequirementsLab
2010-03-09 00:19 . 2009-09-21 22:48 -------- d-----w- c:\program files\Smart PC Utilities
2010-03-17 21:00 . 2010-03-17 21:00 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfree.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2009-03-10 10:47 2079256 ----a-w- c:\program files\free-downloads.net\tbfree.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfree.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfree.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2010-01-04 11:36 2848568 ----a-w- c:\program files\MozyHome\mozyshell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2010-01-04 11:36 2848568 ----a-w- c:\program files\MozyHome\mozyshell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-04-01 2010864]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-07 68856]
"Allway Sync"="c:\program files\Allway Sync\Bin\syncappw.exe" [2009-07-30 79576]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"LDLS4.Indexer:gwqb1map.asq"="c:\users\Duncan\AppData\Local\Logos4\System\Logos4Indexer.exe" [2010-04-19 149328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-28 7625248]
"NMSVC"="c:\program files\CE\nmSvc.exe" [2010-03-04 1329152]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-04-12 1135912]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
MozyHome Status.lnk - c:\program files\MozyHome\mozystat.exe [2010-1-4 2893624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PHOTOfunSTUDIO HD Edition.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO HD Edition.lnk
backup=c:\windows\pss\PHOTOfunSTUDIO HD Edition.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Targus BT Mouse.lnk]
backup=c:\windows\pss\Targus BT Mouse.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Targus BT Mouse.lnk

[HKLM\~\startupfolder\C:^Users^Duncan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TRDCReminder.lnk]
backup=c:\windows\pss\TRDCReminder.lnk.Startup
backupExtension=.Startup
path=c:\users\Duncan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00TCrdMain]
2008-05-09 10:49 716800 ----a-w- c:\program files\TOSHIBA\FlashCards\TCrdMain.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2008-10-07 00:19 165144 ----a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2008-10-07 00:25 960392 ----a-w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2009-04-24 03:16 203928 ----a-w- c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
2006-12-18 10:08 622592 ----a-w- c:\program files\Brother\Brmfcmon\BrMfcWnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Assistant Software]
2008-09-26 13:22 417792 ----a-w- c:\program files\Camera Assistant Software for Toshiba\traybar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
2006-07-19 13:51 65536 ----a-w- c:\program files\Brother\ControlCenter3\BrCtrCen.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-03-17 21:00 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google EULA Launcher]
2008-05-28 11:40 20480 ----a-w- c:\program files\Google\Google EULA\GoogleEULALauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-03-18 11:05 136176 ----atw- c:\users\Duncan\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2004-04-14 14:04 40960 ----a-w- c:\program files\ScanSoft\PaperPort\IndexSearch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-21 15:36 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mobile Connectivity Suite]
2009-05-27 15:46 598016 ----a-r- c:\program files\HTC\HTC Sync\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2004-04-14 13:46 57393 ----a-w- c:\program files\ScanSoft\PaperPort\pptd40nt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 00:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-07-14 01:14 1173504 ----a-w- c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2003-10-14 09:22 155648 ----a-r- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-03-08 19:49 1217872 ----a-w- c:\program files\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-25 04:23 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-08-07 16:54 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\topi]
2007-07-10 08:24 581632 ----a-w- c:\program files\TOSHIBA\Toshiba Online Product Information\TOPI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
2008-01-11 02:07 574864 ----a-w- c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2008-10-07 00:03 4344816 ----a-w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center]
2007-05-31 08:21 648072 ----a-w- c:\windows\WindowsMobile\wmdc.exe

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-05-03 1285864]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2010-03-09 24576]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [2008-04-16 954368]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-17 12872]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\N360\0300000.086\SYMNDISV.SYS [x]
R4 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-03-17 30192]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 135664]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-09-08 721904]
R4 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-05-01 3032360]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-02-04 64288]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0401000.020\SYMDS.SYS [2009-10-15 328752]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0401000.020\SYMEFA.SYS [2009-11-26 172592]
S0 tdrpman140;Acronis Try&Decide and Restore Points filter (build 140);c:\windows\system32\DRIVERS\tdrpm140.sys [2009-08-02 971168]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100324.001\BHDrvx86.sys [2010-03-24 536112]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0401000.020\ccHPx86.sys [2010-02-25 501888]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100429.001\IDSvix86.sys [2009-11-17 343088]
S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2008-04-28 20384]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-02-17 66632]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0401000.020\Ironx86.SYS [2010-02-27 116784]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\N360\0401000.020\SYMTDIV.SYS [2009-11-22 340016]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
S2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [2009-12-12 6656]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [2008-08-11 12856]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe [2010-02-25 126392]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2008-02-06 126976]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-04-12 102448]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
S3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [2008-08-25 77824]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]

.
Contents of the 'Scheduled Tasks' folder

2010-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 22:07]

2010-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 22:07]

2010-05-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-439322092-450900370-4199317660-1000Core.job
- c:\users\Duncan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-08 11:05]

2010-05-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-439322092-450900370-4199317660-1000UA.job
- c:\users\Duncan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-08 11:05]

2010-05-02 c:\windows\Tasks\Norton Security Scan for Duncan.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-04-17 11:48]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.facebook.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redire...1&site=home
LSP: CESpy.dll
FF - ProfilePath - c:\users\Duncan\AppData\Roaming\Mozilla\Firefox\Profiles\jmye8nwc.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig|http://www.bleepingcomputer.com/forums/index.php?act=Search&CODE=show&searchid=c0fe08b612e6a3bdb421357d5c9abd6a&search_in=posts&result_type=topics&highlite=%2B&kw=
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Picasa2\npPicasa3.dll
FF - plugin: c:\users\Duncan\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-HotKeysCmds - c:\windows\system32\hkcmd.exe
MSConfigStartUp-IgfxTray - c:\windows\system32\igfxtray.exe
MSConfigStartUp-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe
MSConfigStartUp-Persistence - c:\windows\system32\igfxpers.exe
MSConfigStartUp-TomTomHOME - c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
MSConfigStartUp-TOSCDSPD - TOSCDSPD.EXE
MSConfigStartUp-Toshiba TEMPO - c:\program files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
MSConfigStartUp-VirtualCloneDrive - c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
AddRemove-Journal of Biblical Counseling_is1 - e:\dunks documents\2 LIBRARY\Journal of Biblical Counseling\unins000.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe



[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\4.1.0.32\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(340)
c:\program files\MozyHome\mozyshell.dll
c:\program files\Allway Sync\Bin\SyncHook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\MozyHome\mozybackup.exe
c:\program files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
c:\program files\MozyHome\mozybackup.exe
c:\program files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\windows\system32\taskhost.exe
c:\program files\MozyHome\mozybackup.exe
c:\windows\system32\conhost.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\windows\ehome\ehmsas.exe
c:\program files\CE\nmFlt.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
.
**************************************************************************
.
Completion time: 2010-05-04 19:53:03 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-04 18:53

Pre-Run: 8,292,052,992 bytes free
Post-Run: 4,858,085,376 bytes free

- - End Of File - - EDDD5BD2DF453D753A5E5C38E43E824D

Attached Files



#7 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:11:47 PM

Posted 06 May 2010 - 11:47 AM

Hi,

Please update your version of Malwarebytes and run a quick scan, post back with the content of the logfile.



I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
  • Check
  • Click the button.
  • Accept any security warnings from your browser.
  • Check
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push
  • Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the button.
  • Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt




  1. Please download OTL from one of the following mirrors:
  2. Save it to your desktop.
  3. Double click on the icon on your desktop.
  4. Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemdrive%\*.sys /90 /md5
  5. Push the Quick Scan button.
  6. Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt <-- Will be minimized

regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#8 London76

London76
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:11:47 PM

Posted 06 May 2010 - 06:42 PM

Hi Tom,
There havn't been any redirects since running combofix - thanks for that!
I'm running ESET at the moment.
In the meantime, here's the log of the malwarebytes quick scan:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4072

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

06/05/2010 19:01:30
mbam-log-2010-05-06 (19-01-30).txt

Scan type: Quick scan
Objects scanned: 128246
Time elapsed: 8 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


#9 London76

London76
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:11:47 PM

Posted 06 May 2010 - 08:22 PM

Here's the rest of the results:

ESET:

C:\Qoobox\Quarantine\C\Windows\system32\Drivers\rdyboost.sys.vir Win32/Patched.EQ trojan deleted - quarantined
C:\Users\Duncan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\d7d440d-5a094941 Java/TrojanDownloader.Agent.NAM trojan deleted - quarantined
C:\Users\Duncan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\720b4111-2eb2c6ca Java/TrojanDownloader.Agent.NAM trojan deleted - quarantined
C:\Users\Duncan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\5637119f-321da229 Java/TrojanDownloader.Agent.NAM trojan deleted - quarantined
C:\Users\Duncan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\456936ab-578bdb5d Java/TrojanDownloader.Agent.NAM trojan deleted - quarantined
C:\Users\Duncan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\184340f3-7b61a4d1 a variant of Java/TrojanDownloader.Agent.NAN trojan deleted - quarantined
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\5e06aece-2ae45ea8 Java/TrojanDownloader.Agent.NAM trojan deleted - quarantined
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\5c82fb99-103ac7ca Java/TrojanDownloader.Agent.NAM trojan deleted - quarantined
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\6e82365c-76fa9e52 multiple threats deleted - quarantined
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\68894b8-299cc1db Java/TrojanDownloader.Agent.NAM trojan deleted - quarantined


OTL:

OTL logfile created on: 07/05/2010 01:57:16 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Duncan\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 29.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.37 Gb Total Space | 15.59 Gb Free Space | 20.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 73.21 Gb Total Space | 5.04 Gb Free Space | 6.89% Space Free | Partition Type: NTFS
Drive F: | 14.96 Gb Total Space | 14.08 Gb Free Space | 94.12% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOSHIBAOFFICEPC
Current User Name: Duncan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/05/07 01:53:04 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Users\Duncan\Desktop\OTL.exe
PRC - [2010/04/12 23:46:36 | 001,135,912 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/04/01 19:00:32 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/03/04 01:01:45 | 001,329,152 | ---- | M] () -- C:\Program Files\CE\nmSvc.exe
PRC - [2010/03/04 01:01:43 | 000,260,096 | ---- | M] () -- C:\Program Files\CE\nmFlt.exe
PRC - [2010/02/26 00:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\4.1.0.32\ccsvchst.exe
PRC - [2010/01/04 12:36:28 | 002,893,624 | ---- | M] (Mozy, Inc.) -- C:\Program Files\MozyHome\mozystat.exe
PRC - [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/09/28 20:34:16 | 000,378,176 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2009/08/27 17:09:10 | 001,253,376 | ---- | M] (MAGIX AG) -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
PRC - [2009/07/30 13:11:12 | 000,079,576 | ---- | M] () -- C:\Program Files\Allway Sync\Bin\syncappw.exe
PRC - [2009/07/28 22:12:56 | 007,625,248 | ---- | M] (Realtek Semiconductor) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
PRC - [2009/07/14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/14 02:14:13 | 000,776,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\calc.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/10/07 01:19:44 | 000,554,264 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2008/08/25 09:58:20 | 000,077,824 | ---- | M] (Toshiba) -- C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
PRC - [2008/08/11 13:41:00 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2008/08/07 17:54:28 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/07/18 20:39:30 | 000,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2008/02/06 14:12:56 | 000,126,976 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
PRC - [2008/01/17 16:27:34 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2007/11/21 17:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2002/12/17 18:26:22 | 007,520,337 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe


========== Modules (SafeList) ==========

MOD - [2010/05/07 01:53:04 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Users\Duncan\Desktop\OTL.exe
MOD - [2009/07/14 02:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll
MOD - [2009/07/14 02:16:14 | 000,040,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sfc_os.dll
MOD - [2009/07/14 02:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll
MOD - [2009/07/14 02:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll
MOD - [2009/07/14 02:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll
MOD - [2009/07/14 02:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll
MOD - [2009/07/14 02:15:44 | 002,340,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msi.dll
MOD - [2009/07/14 02:15:44 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msiltcfg.dll
MOD - [2009/07/14 02:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll
MOD - [2009/07/14 02:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
MOD - [2009/07/14 02:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll
MOD - [2009/07/14 02:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll
MOD - [2009/07/14 02:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
MOD - [2009/07/14 02:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
MOD - [2009/07/14 02:10:22 | 000,002,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sfc.dll
MOD - [2009/07/14 02:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/05/03 12:18:35 | 001,285,864 | ---- | M] (Lavasoft) [Auto | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/03/17 22:00:38 | 000,030,192 | ---- | M] (Google) [Disabled | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-110309-193829)
SRV - [2010/03/11 18:26:31 | 000,332,720 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/02/26 00:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe -- (N360)
SRV - [2009/09/28 20:34:22 | 000,116,032 | ---- | M] (LogMeIn, Inc.) [Disabled | Stopped] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint)
SRV - [2009/08/27 17:09:10 | 001,253,376 | ---- | M] (MAGIX AG) [Unknown | Running] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2009/07/14 02:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc)
SRV - [2009/07/14 02:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc)
SRV - [2009/07/14 02:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power)
SRV - [2009/07/14 02:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2009/07/14 02:16:15 | 000,313,856 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv)
SRV - [2009/07/14 02:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sppuinotify.dll -- (sppuinotify)
SRV - [2009/07/14 02:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 02:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc)
SRV - [2009/07/14 02:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc)
SRV - [2009/07/14 02:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider)
SRV - [2009/07/14 02:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg)
SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/14 02:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener)
SRV - [2009/07/14 02:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/07/14 02:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2009/07/14 02:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc)
SRV - [2009/07/14 02:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC)
SRV - [2009/07/14 02:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) ActiveX Installer (AxInstSV)
SRV - [2009/07/14 02:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc)
SRV - [2009/07/14 02:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\sppsvc.exe -- (sppsvc)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/10/07 01:19:44 | 000,554,264 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2008/08/25 09:58:20 | 000,077,824 | ---- | M] (Toshiba) [On_Demand | Running] -- C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe -- (SmartFaceVWatchSrv)
SRV - [2008/08/11 13:41:00 | 000,063,040 | ---- | M] (LogMeIn, Inc.) [Disabled | Stopped] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2008/08/07 11:10:02 | 003,276,800 | ---- | M] (MAGIXŪ) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2008/07/18 20:39:30 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/05/01 23:40:44 | 003,032,360 | ---- | M] (Wacom Technology, Corp.) [Disabled | Stopped] -- C:\Windows\System32\Pen_Tablet.exe -- (TabletServicePen)
SRV - [2008/04/16 15:53:00 | 000,954,368 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files\Jumpstart\jswpsapi.exe -- (jswpsapi)
SRV - [2008/02/06 14:12:56 | 000,126,976 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2008/01/17 16:27:34 | 000,431,456 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2007/11/21 17:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2007/06/15 12:57:42 | 000,145,504 | ---- | M] (B.H.A Corporation) [Disabled | Stopped] -- C:\Windows\System32\bgsvcgen.exe -- (bgsvcgen)
SRV - [2007/05/28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Disabled | Stopped] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2006/08/23 16:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
SRV - [2002/12/17 18:26:22 | 007,520,337 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002/12/17 18:23:30 | 000,311,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)


========== Driver Services (SafeList) ==========

DRV - [2010/04/29 18:44:04 | 000,537,136 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100429.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2010/04/16 10:39:29 | 000,173,648 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rdyboost.sys -- (rdyboost)
DRV - [2010/04/13 11:37:30 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010/04/12 09:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/04/12 09:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/04/12 01:00:00 | 001,324,720 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100506.005\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/04/12 01:00:00 | 000,084,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100506.005\NAVENG.SYS -- (NAVENG)
DRV - [2010/03/09 18:06:58 | 000,024,576 | ---- | M] (HTC1124 Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2010/02/27 03:23:54 | 000,116,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\N360\0401000.020\Ironx86.SYS -- (SymIRON)
DRV - [2010/02/27 03:23:21 | 000,325,680 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\Drivers\N360\0401000.020\SRTSP.SYS -- (SRTSP)
DRV - [2010/02/27 03:23:21 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\N360\0401000.020\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/26 00:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\N360\0401000.020\ccHPx86.sys -- (ccHP)
DRV - [2010/02/17 11:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/02/17 11:15:58 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 11:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010/02/04 16:53:02 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009/12/12 08:19:50 | 000,006,656 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\iPodDrv.sys -- (iPodDrv)
DRV - [2009/12/11 08:44:02 | 000,133,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg)
DRV - [2009/12/03 07:09:48 | 000,044,080 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\SymIMV.sys -- (SymIM)
DRV - [2009/11/26 07:41:48 | 000,172,592 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\system32\drivers\N360\0401000.020\SYMEFA.SYS -- (SymEFA)
DRV - [2009/11/22 01:43:47 | 000,340,016 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\N360\0401000.020\SYMTDIV.SYS -- (SYMTDIv)
DRV - [2009/11/17 01:51:14 | 000,343,088 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100429.001\IDSvix86.sys -- (IDSVix86)
DRV - [2009/10/15 04:50:05 | 000,328,752 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\N360\0401000.020\SYMDS.SYS -- (SymDS)
DRV - [2009/09/28 20:34:48 | 000,083,288 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2009/09/21 18:58:28 | 001,218,048 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/09/08 14:34:03 | 000,721,904 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/08/05 19:01:34 | 000,104,512 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2009/08/02 18:15:34 | 000,971,168 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\tdrpm140.sys -- (tdrpman140) Acronis Try&Decide and Restore Points filter (build 140)
DRV - [2009/08/02 18:15:25 | 000,134,272 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\snman380.sys -- (snapman380) Acronis Snapshots Manager (Build 380)
DRV - [2009/07/28 22:02:42 | 002,735,504 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/07/14 02:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\cmdide.sys -- (cmdide)
DRV - [2009/07/14 02:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpahci.sys -- (adpahci)
DRV - [2009/07/14 02:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adp94xx.sys -- (adp94xx)
DRV - [2009/07/14 02:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs)
DRV - [2009/07/14 02:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpu320.sys -- (adpu320)
DRV - [2009/07/14 02:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arcsas.sys -- (arcsas)
DRV - [2009/07/14 02:26:15 | 000,079,952 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsata.sys -- (amdsata)
DRV - [2009/07/14 02:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arc.sys -- (arc)
DRV - [2009/07/14 02:26:15 | 000,023,616 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\amdxata.sys -- (amdxata)
DRV - [2009/07/14 02:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\aliide.sys -- (aliide)
DRV - [2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvstor.sys -- (nvstor)
DRV - [2009/07/14 02:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvraid.sys -- (nvraid)
DRV - [2009/07/14 02:20:44 | 000,044,624 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nfrd960.sys -- (nfrd960)
DRV - [2009/07/14 02:20:37 | 000,089,168 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas.sys -- (LSI_SAS)
DRV - [2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iaStorV.sys -- (iaStorV)
DRV - [2009/07/14 02:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MegaSR.sys -- (MegaSR)
DRV - [2009/07/14 02:20:36 | 000,096,848 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2009/07/14 02:20:36 | 000,095,824 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_fc.sys -- (LSI_FC)
DRV - [2009/07/14 02:20:36 | 000,054,864 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2)
DRV - [2009/07/14 02:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iirsp.sys -- (iirsp)
DRV - [2009/07/14 02:20:36 | 000,030,800 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\megasas.sys -- (megasas)
DRV - [2009/07/14 02:20:36 | 000,013,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hwpolicy.sys -- (hwpolicy)
DRV - [2009/07/14 02:20:28 | 000,453,712 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\elxstor.sys -- (elxstor)
DRV - [2009/07/14 02:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\djsvs.sys -- (aic78xx)
DRV - [2009/07/14 02:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HpSAMD.sys -- (HpSAMD)
DRV - [2009/07/14 02:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fsdepends.sys -- (FsDepends)
DRV - [2009/07/14 02:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vsmraid.sys -- (vsmraid)
DRV - [2009/07/14 02:19:10 | 000,159,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vhdmp.sys -- (vhdmp)
DRV - [2009/07/14 02:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vdrvroot.sys -- (vdrvroot)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/07/14 02:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\viaide.sys -- (viaide)
DRV - [2009/07/14 02:19:04 | 001,383,488 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql2300.sys -- (ql2300)
DRV - [2009/07/14 02:19:04 | 000,106,064 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql40xx.sys -- (ql40xx)
DRV - [2009/07/14 02:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\sisraid4.sys -- (SiSRaid4)
DRV - [2009/07/14 02:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pcw.sys -- (pcw)
DRV - [2009/07/14 02:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\SiSRaid2.sys -- (SiSRaid2)
DRV - [2009/07/14 02:19:04 | 000,021,072 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor)
DRV - [2009/07/14 02:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\cng.sys -- (CNG)
DRV - [2009/07/14 01:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\Brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2009/07/14 01:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\rdpbus.sys -- (rdpbus)
DRV - [2009/07/14 01:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV - [2009/07/14 00:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
DRV - [2009/07/14 00:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\wfplwf.sys -- (WfpLwf)
DRV - [2009/07/14 00:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ndiscap.sys -- (NdisCap)
DRV - [2009/07/14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/14 00:52:04 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vwififlt.sys -- (vwififlt)
DRV - [2009/07/14 00:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifibus.sys -- (vwifibus)
DRV - [2009/07/14 00:52:00 | 000,163,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\1394ohci.sys -- (1394ohci)
DRV - [2009/07/14 00:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\umpass.sys -- (UmPass)
DRV - [2009/07/14 00:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV - [2009/07/14 00:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MTConfig.sys -- (MTConfig)
DRV - [2009/07/14 00:45:26 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CompositeBus.sys -- (CompositeBus)
DRV - [2009/07/14 00:36:52 | 000,050,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\appid.sys -- (AppID)
DRV - [2009/07/14 00:33:50 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\scfilter.sys -- (scfilter)
DRV - [2009/07/14 00:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\discache.sys -- (discache)
DRV - [2009/07/14 00:19:21 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HidBatt.sys -- (HidBatt)
DRV - [2009/07/14 00:16:36 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\acpipmi.sys -- (AcpiPmi)
DRV - [2009/07/14 00:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdppm.sys -- (AmdPPM)
DRV - [2009/07/13 23:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/13 23:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbMdm.sys -- (BrUsbMdm)
DRV - [2009/07/13 23:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbSer.sys -- (BrUsbSer)
DRV - [2009/07/13 23:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrSerWdm.sys -- (BrSerWdm)
DRV - [2009/07/13 23:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltLo.sys -- (BrFiltLo)
DRV - [2009/07/13 23:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltUp.sys -- (BrFiltUp)
DRV - [2009/07/13 23:13:48 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2009/07/13 23:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2009/07/13 23:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\evbdx.sys -- (ebdrv)
DRV - [2009/07/13 23:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\bxvbdx.sys -- (b06bdrv)
DRV - [2009/06/10 22:19:30 | 004,756,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\igdkmd32.sys -- (igfx)
DRV - [2009/02/17 18:11:30 | 000,024,232 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2008/09/24 11:29:25 | 000,029,184 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VClone.sys -- (VClone)
DRV - [2008/08/11 13:41:00 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2008/08/11 13:41:00 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2008/07/15 19:59:06 | 000,017,960 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV - [2008/04/28 16:59:18 | 000,020,384 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\jswpslwf.sys -- (jswpslwf)
DRV - [2008/04/15 17:53:44 | 000,312,344 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2008/04/15 09:05:08 | 000,118,784 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007/12/06 17:12:48 | 000,196,400 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2007/11/09 14:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV - [2007/04/03 14:57:54 | 000,099,080 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116unic.sys -- (s116unic) Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM)
DRV - [2007/04/03 14:57:52 | 000,023,176 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116nd5.sys -- (s116nd5) Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS)
DRV - [2007/04/03 14:57:50 | 000,100,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116mgmt.sys -- (s116mgmt) Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM)
DRV - [2007/04/03 14:57:48 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116mdm.sys -- (s116mdm)
DRV - [2007/04/03 14:57:48 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116mdfl.sys -- (s116mdfl)
DRV - [2007/04/03 14:57:42 | 000,083,336 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116bus.sys -- (s116bus) Sony Ericsson Device 116 driver (WDM)
DRV - [2006/11/20 14:11:14 | 000,007,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2006/10/18 11:50:04 | 000,016,128 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2006/02/20 19:17:40 | 000,033,408 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\cdrbsdrv.sys -- (cdrbsdrv)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br...A&bmod=TSEA
IE - HKLM\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig|http://www.bleepingcomputer.com/forums/index.php?act=Search&CODE=show&searchid=c0fe08b612e6a3bdb421357d5c9abd6a&search_in=posts&result_type=topics&highlite=%2B&kw="
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: foxmarks@kei.com:3.6.7

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/04/27 08:34:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/04/13 11:40:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/13 21:11:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/06 13:15:34 | 000,000,000 | ---D | M]

[2010/04/13 21:11:55 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Mozilla\Extensions
[2009/08/02 21:39:41 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com
[2010/05/06 20:27:13 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Mozilla\Firefox\Profiles\jmye8nwc.default\extensions
[2010/04/14 15:07:26 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Mozilla\Firefox\Profiles\jmye8nwc.default\extensions\foxmarks@kei.com
[2010/04/13 21:19:09 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/01 17:56:49 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/01 17:56:50 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/01 17:56:50 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/01 17:56:50 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/05/04 19:38:41 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HelperObject Class) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.1.0.32\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.1.0.32\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (free-downloads.net Toolbar) - {ECDEE021-0D17-467F-A1FF-C7A115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [NMSVC] C:\Program Files\CE\nmSvc.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [Allway Sync] C:\Program Files\Allway Sync\Bin\syncappw.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: eBay.co.uk - Buy It Sell It Love It - {76577871-04EC-495E-A12B-91F7C3600AFA} - File not found
O9 - Extra Button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\Duncan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Duncan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/07/14 03:37:08 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

========== Files/Folders - Created Within 90 Days ==========

[2010/05/07 01:53:04 | 000,570,880 | ---- | C] (OldTimer Tools) -- C:\Users\Duncan\Desktop\OTL.exe
[2010/05/06 20:20:47 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/05/06 12:43:51 | 000,000,000 | ---D | C] -- C:\ProgramData\NOS
[2010/05/05 20:27:44 | 000,000,000 | ---D | C] -- C:\ProgramData\eSellerate
[2010/05/05 20:26:40 | 000,000,000 | ---D | C] -- E:\Dunks Documents\NewBlueFX
[2010/05/05 20:26:36 | 000,000,000 | ---D | C] -- C:\Program Files\NewBlue
[2010/05/04 19:53:07 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/05/04 19:38:47 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2010/05/04 19:36:37 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\temp
[2010/05/04 19:15:57 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/05/04 19:15:56 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/05/04 19:15:56 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/05/04 19:15:41 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/05/04 19:12:25 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/05/04 19:12:05 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/04/30 11:16:43 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\ElevatedDiagnostics
[2010/04/29 11:21:22 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010/04/26 17:31:02 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\avG
[2010/04/26 17:31:02 | 000,000,000 | ---D | C] -- C:\ProgramData\avG
[2010/04/22 17:24:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/04/22 17:24:40 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010/04/22 17:24:34 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\CrashDumps
[2010/04/20 10:33:18 | 000,000,000 | R--D | C] -- E:\Dunks Documents\Scanned Documents
[2010/04/20 10:33:16 | 000,000,000 | ---D | C] -- E:\Dunks Documents\Fax
[2010/04/19 18:22:34 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\Diagnostics
[2010/04/17 20:04:15 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS
[2010/04/17 20:04:15 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Security Scan
[2010/04/17 20:04:15 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS\0207030.022
[2010/04/17 17:03:28 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2010/04/16 21:57:24 | 000,044,080 | R--- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\SymIMV.sys
[2010/04/13 15:01:59 | 000,000,000 | ---D | C] -- C:\Users\Duncan\Desktop\gmer
[2010/04/13 13:15:02 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/04/13 12:57:43 | 000,000,000 | ---D | C] -- C:\ProgramData\SITEguard
[2010/04/13 12:56:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\iS3
[2010/04/13 12:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\STOPzilla!
[2010/04/13 11:44:05 | 000,340,016 | R--- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\symtdiv.sys
[2010/04/13 11:44:05 | 000,340,016 | R--- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\symtdiv.sys
[2010/04/13 11:44:05 | 000,328,752 | R--- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\symds.sys
[2010/04/13 11:44:05 | 000,328,752 | R--- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\symds.sys
[2010/04/13 11:44:05 | 000,172,592 | R--- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\symefa.sys
[2010/04/13 11:44:05 | 000,172,592 | R--- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\symefa.sys
[2010/04/13 11:44:04 | 000,325,680 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\srtsp.sys
[2010/04/13 11:44:04 | 000,116,784 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\ironx86.sys
[2010/04/13 11:44:04 | 000,116,784 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\ironx86.sys
[2010/04/13 11:44:04 | 000,043,696 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\srtspx.sys
[2010/04/13 11:44:04 | 000,043,696 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\srtspx.sys
[2010/04/13 11:44:03 | 000,501,888 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\cchpx86.sys
[2010/04/13 11:44:03 | 000,501,888 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\cchpx86.sys
[2010/04/13 11:43:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\N360\0401000.020
[2010/04/13 11:17:01 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\Symantec
[2010/04/13 00:46:47 | 000,000,000 | ---D | C] -- C:\ProgramData\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
[2010/04/13 00:46:29 | 000,124,976 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
[2010/04/13 00:46:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2010/04/13 00:46:28 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2010/04/13 00:45:44 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\N360
[2010/04/13 00:45:42 | 000,000,000 | ---D | C] -- C:\Program Files\Norton 360
[2010/04/13 00:43:52 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2010/04/10 19:02:37 | 000,000,000 | ---D | C] -- E:\Dunks Documents\Vegas Movie Studio PE 9.0 Projects
[2010/04/10 19:01:19 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\Sony
[2010/04/10 18:59:59 | 000,000,000 | ---D | C] -- C:\Program Files\Vstplugins
[2010/04/10 18:59:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony
[2010/04/10 18:57:07 | 000,000,000 | ---D | C] -- C:\Program Files\Sony Setup
[2010/04/10 18:33:53 | 000,000,000 | ---D | C] -- E:\Dunks Documents\MAGIX downloads
[2010/04/10 18:33:52 | 000,000,000 | ---D | C] -- E:\Dunks Documents\MAGIX_PhotoStory_on_CD_DVD_9
[2010/04/10 18:33:09 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\MAGIX
[2010/04/10 18:29:19 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\Xara
[2010/04/10 18:28:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MAGIX Shared
[2010/04/10 18:28:25 | 000,000,000 | ---D | C] -- C:\Program Files\MAGIX
[2010/04/10 18:27:40 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX
[2010/04/10 18:27:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MAGIX Services
[2010/04/09 22:40:49 | 000,000,000 | ---D | C] -- E:\Dunks Documents\Vegas Movie Studio HD 9.0 Projects
[2010/04/09 04:13:13 | 000,000,000 | ---D | C] -- E:\Dunks Documents\PHOTOS misc unimportant
[2010/04/09 04:13:13 | 000,000,000 | ---D | C] -- E:\Dunks Documents\birthdaygift
[2010/04/09 03:48:52 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\ApplicationHistory
[2010/04/09 03:48:15 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\Publish Providers
[2010/04/09 03:35:12 | 000,000,000 | ---D | C] -- C:\Windows\System32\URTTEMP
[2010/04/08 18:18:42 | 000,000,000 | ---D | C] -- C:\For E DRIVE
[2010/04/08 04:13:05 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\Helicon
[2010/04/08 04:12:00 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Player ActiveX Control
[2010/04/08 04:12:00 | 000,000,000 | ---D | C] -- C:\Program Files\Audio Capture ActiveX Control
[2010/04/08 04:11:59 | 000,000,000 | ---D | C] -- C:\Program Files\Helicon Software
[2010/04/08 02:58:38 | 000,000,000 | ---D | C] -- E:\Dunks Documents\Camera
[2010/04/07 21:44:10 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\Panasonic
[2010/04/07 21:32:32 | 000,033,408 | ---- | C] (B.H.A Corporation) -- C:\Windows\System32\drivers\cdrbsdrv.sys
[2010/04/07 21:32:31 | 000,145,504 | ---- | C] (B.H.A Corporation) -- C:\Windows\System32\bgsvcgen.exe
[2010/04/07 21:32:31 | 000,059,488 | ---- | C] (B.H.A Corporation) -- C:\Windows\System32\GenSvcInst.exe
[2010/04/07 21:31:09 | 000,045,056 | ---- | C] (Matsubleepa Electric Industrial Co., Ltd.) -- C:\Windows\System32\PhDi2.sys
[2010/04/07 21:31:00 | 000,000,000 | ---D | C] -- C:\Program Files\Panasonic
[2010/04/05 12:18:34 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2010/04/05 12:18:25 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010/04/05 12:13:22 | 000,000,000 | -H-D | C] -- C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/04/05 12:12:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2010/04/05 12:12:40 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010/04/05 01:30:52 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/04/05 01:30:26 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\SUPERAntiSpyware.com
[2010/04/05 01:30:26 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/04/04 20:55:17 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\Malwarebytes
[2010/04/04 20:54:47 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/04 20:54:44 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/04 20:54:44 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/04 20:54:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/04/04 04:29:06 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\myphotobook
[2010/04/04 04:29:05 | 000,000,000 | ---D | C] -- E:\Dunks Documents\myphotobook
[2010/04/03 18:17:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010/04/03 18:17:08 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/04/03 17:27:11 | 000,000,000 | ---D | C] -- E:\Dunks Documents\Logos Log Files
[2010/04/02 02:35:28 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010/03/31 02:58:24 | 000,353,592 | ---- | C] (DivX, Inc.) -- C:\Windows\System32\DivXControlPanelApplet.cpl
[2010/03/22 19:29:06 | 000,000,000 | ---D | C] -- E:\Dunks Documents\Downloads
[2010/03/15 18:52:39 | 000,000,000 | ---D | C] -- C:\Users\Duncan\Documents
[2010/03/14 00:55:46 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\LogMeIn
[2010/03/14 00:55:45 | 000,000,000 | ---D | C] -- C:\ProgramData\LogMeIn
[2010/03/14 00:55:28 | 000,028,984 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\LMIport.dll
[2010/03/14 00:55:27 | 000,083,288 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\LMIRfsClientNP.dll
[2010/03/14 00:55:27 | 000,047,640 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\drivers\LMIRfsDriver.sys
[2010/03/14 00:55:22 | 000,087,352 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\LMIinit.dll
[2010/03/14 00:54:50 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn
[2010/03/14 00:50:24 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\Apps
[2010/03/14 00:50:23 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\Deployment
[2010/03/13 03:06:33 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010/03/10 12:43:53 | 000,000,000 | ---D | C] -- C:\WTablet
[2010/03/09 22:10:09 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\Gmote
[2010/03/09 22:10:02 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallJammer Registry
[2010/03/09 22:06:22 | 000,000,000 | ---D | C] -- C:\Program Files\GmoteServer
[2010/03/09 21:56:03 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\Realtime Soft
[2010/03/09 18:06:58 | 000,024,576 | ---- | C] (HTC1124 Inc) -- C:\Windows\System32\drivers\ANDROIDUSB.sys
[2010/03/09 18:05:31 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\HTC
[2010/03/09 18:05:03 | 000,000,000 | ---D | C] -- C:\ProgramData\HTC
[2010/03/09 18:05:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Teleca Shared
[2010/03/09 18:05:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Teleca
[2010/03/09 15:36:20 | 000,393,216 | ---- | C] (FinePrint Software, LLC) -- C:\Windows\System32\fppmon3.dll
[2010/03/09 15:36:20 | 000,282,624 | ---- | C] (FinePrint Software, LLC) -- C:\Windows\System32\fppr332.dll
[2010/03/09 09:08:56 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2010/03/09 08:54:58 | 000,000,000 | ---D | C] -- C:\$WINDOWS.~Q
[2010/03/09 08:39:17 | 000,000,000 | ---D | C] -- C:\$INPLACE.~TR
[2010/03/09 02:33:10 | 000,000,000 | R--D | C] -- E:\Dunks Documents\Links for United Kingdom
[2010/03/09 02:25:38 | 000,000,000 | ---D | C] -- C:\Recovery
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\AppData\Local\Temporary Internet Files
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\Templates
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\Start Menu
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\SendTo
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\Recent
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\PrintHood
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\NetHood
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\My Documents
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\Local Settings
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\AppData\Local\History
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\Cookies
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\Application Data
[2010/03/09 01:13:16 | 000,000,000 | -HSD | C] -- C:\Users\Duncan\AppData\Local\Application Data
[2010/03/09 01:13:15 | 000,000,000 | --SD | C] -- C:\Users\Duncan\AppData\Roaming\Microsoft
[2010/03/09 01:13:15 | 000,000,000 | R--D | C] -- C:\Users\Duncan\Saved Games
[2010/03/09 01:13:15 | 000,000,000 | R--D | C] -- C:\Users\Duncan\Links
[2010/03/09 01:13:15 | 000,000,000 | R--D | C] -- C:\Users\Duncan\Desktop
[2010/03/09 01:13:15 | 000,000,000 | -H-D | C] -- C:\Users\Duncan\AppData
[2010/03/09 01:13:15 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\Microsoft
[2010/03/09 01:13:15 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\Media Center Programs
[2010/03/09 01:12:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM
[2010/03/09 01:12:02 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2010/03/09 01:11:55 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2010/03/09 01:10:39 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2010/03/08 23:21:19 | 001,784,352 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesLib.dll
[2010/03/08 23:21:19 | 000,339,968 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll
[2010/03/08 23:21:19 | 000,185,776 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll
[2010/03/08 23:21:19 | 000,167,936 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll
[2010/03/08 23:21:19 | 000,135,168 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll
[2010/03/08 23:21:14 | 000,290,304 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DHT32.dll
[2010/03/08 23:21:14 | 000,290,304 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DAA32.dll
[2010/03/08 23:21:13 | 001,933,312 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioEQ.dll
[2010/03/08 23:21:13 | 000,266,240 | ---- | C] (Fortemedia Corporation) -- C:\Windows\System32\FMAPO.dll
[2010/03/08 23:21:13 | 000,159,744 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO20.dll
[2010/03/08 23:21:13 | 000,126,976 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO.dll
[2010/03/08 23:21:12 | 000,000,000 | -H-D | C] -- C:\Program Files\Temp
[2010/03/08 23:21:08 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\WinBatch
[2010/03/08 22:54:03 | 000,393,216 | ---- | C] (Atheros) -- C:\Windows\System32\athihvs.dll
[2010/03/08 18:59:18 | 000,094,208 | ---- | C] (DivX, Inc.) -- C:\Windows\System32\dpl100.dll
[2010/03/07 16:56:55 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\doubleTwist Corporation
[2010/03/07 16:56:34 | 000,000,000 | ---D | C] -- C:\ProgramData\doubleTwist Corporation
[2010/03/07 16:56:28 | 000,060,273 | ---- | C] (Open Source Software community project) -- C:\Windows\System32\pthreadGC2.dll
[2010/03/07 16:56:27 | 000,000,000 | ---D | C] -- C:\Program Files\ffdshow
[2010/03/07 16:51:51 | 000,000,000 | ---D | C] -- C:\Program Files\doubleTwist 2.0
[2010/03/06 06:29:55 | 000,000,000 | ---D | C] -- C:\ruu_log
[2010/03/06 05:30:36 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\Teleca
[2010/03/06 05:27:59 | 000,000,000 | ---D | C] -- C:\Program Files\HTC
[2010/03/06 05:26:27 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
[2010/03/05 17:10:07 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\HandBrake
[2010/03/05 17:09:54 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\HandBrake
[2010/03/05 17:08:35 | 000,000,000 | ---D | C] -- C:\Program Files\HandBrake
[2010/02/28 21:02:40 | 000,000,000 | ---D | C] -- E:\Dunks Documents\Documents on Vario II
[2010/02/26 01:02:26 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\WSStepImport
[2010/02/26 01:01:14 | 000,000,000 | -H-D | C] -- C:\ProgramData\{CDF61231-6AD7-4969-B4DD-9E6C0F51DD5E}
[2010/02/26 01:00:58 | 000,000,000 | ---D | C] -- C:\ProgramData\wsc
[2010/02/26 01:00:56 | 000,000,000 | ---D | C] -- C:\ProgramData\WORDsearch
[2010/02/26 01:00:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\WORDsearch
[2010/02/26 01:00:56 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Local\Bible Explorer 4
[2010/02/26 01:00:56 | 000,000,000 | ---D | C] -- C:\Program Files\Bible Explorer 4
[2010/02/24 22:00:28 | 000,000,000 | ---D | C] -- C:\NBWIN
[2010/02/24 21:42:04 | 000,000,000 | ---D | C] -- C:\Windows\NBLWS
[2010/02/19 20:27:36 | 000,720,384 | ---- | C] (DivX, Inc.) -- C:\Windows\System32\DivX.dll
[2010/02/19 20:27:16 | 000,856,064 | ---- | C] (DivX, Inc.) -- C:\Windows\System32\divx_xx0c.dll
[2010/02/19 20:27:16 | 000,856,064 | ---- | C] (DivX, Inc.) -- C:\Windows\System32\divx_xx07.dll
[2010/02/19 20:27:16 | 000,847,872 | ---- | C] (DivX, Inc.) -- C:\Windows\System32\divx_xx0a.dll
[2010/02/19 20:27:16 | 000,843,776 | ---- | C] (DivX, Inc.) -- C:\Windows\System32\divx_xx16.dll
[2010/02/19 20:27:16 | 000,839,680 | ---- | C] (DivX, Inc.) -- C:\Windows\System32\divx_xx11.dll
[2010/02/19 17:50:02 | 000,000,000 | ---D | C] -- E:\Dunks Documents\Picture Motion Browser
[2010/02/14 00:41:30 | 000,000,000 | ---D | C] -- C:\Program Files\AC3Filter
[2010/02/06 16:01:18 | 000,000,000 | R--D | C] -- E:\Dunks Documents\Notes
[2010/02/06 15:48:00 | 000,000,000 | ---D | C] -- C:\Users\Duncan\AppData\Roaming\WTablet
[2010/02/06 15:47:31 | 003,708,200 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\System32\PenTablet.cpl
[2010/02/06 15:44:17 | 000,000,000 | ---D | C] -- C:\Windows\System32\WTablet
[2010/02/06 15:44:15 | 000,181,544 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\System32\Wintab32.dll
[2010/02/06 15:44:15 | 000,128,296 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\System32\Pen_Tablet.dll
[2010/02/06 15:44:13 | 003,032,360 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\System32\Pen_Tablet.exe
[2010/02/06 15:44:07 | 000,000,000 | ---D | C] -- C:\Program Files\Tablet
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 E:\Dunks Documents\*.tmp files -> E:\Dunks Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/05/07 02:01:51 | 009,699,328 | -HS- | M] () -- C:\Users\Duncan\NTUSER.DAT
[2010/05/07 01:53:04 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Users\Duncan\Desktop\OTL.exe
[2010/05/07 01:41:04 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-439322092-450900370-4199317660-1000UA.job
[2010/05/07 01:10:03 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/07 00:29:23 | 000,753,636 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/05/07 00:29:23 | 000,646,240 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/05/07 00:29:23 | 000,119,502 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/05/06 20:20:10 | 002,672,312 | ---- | M] () -- C:\Users\Duncan\Desktop\esetsmartinstaller_enu.exe
[2010/05/06 19:35:36 | 000,000,476 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Duncan.job
[2010/05/06 18:45:30 | 000,946,418 | ---- | M] () -- C:\Windows\System32\drivers\N360\0401000.020\Cat.DB
[2010/05/06 17:41:01 | 000,000,858 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-439322092-450900370-4199317660-1000Core.job
[2010/05/06 14:42:24 | 000,002,422 | ---- | M] () -- C:\Windows\mozy.blk
[2010/05/06 14:42:23 | 000,000,252 | ---- | M] () -- C:\Windows\mozy.flt
[2010/05/06 13:27:10 | 000,010,896 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/06 13:27:10 | 000,010,896 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/06 13:21:18 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/05/06 13:20:19 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/06 13:20:01 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/05/06 13:19:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/05/06 13:19:49 | 1506,799,616 | -HS- | M] () -- C:\hiberfil.sys
[2010/05/06 13:13:41 | 002,196,921 | -H-- | M] () -- C:\Users\Duncan\AppData\Local\IconCache.db
[2010/05/05 20:50:02 | 000,000,600 | ---- | M] () -- C:\Users\Duncan\AppData\Local\PUTTY.RND
[2010/05/04 19:45:54 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/05/04 19:38:41 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/05/04 19:10:19 | 003,945,780 | R--- | M] () -- C:\Users\Duncan\Desktop\schrauber.exe
[2010/04/29 16:42:15 | 000,002,267 | ---- | M] () -- C:\Users\Duncan\Desktop\Google Chrome.lnk
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/29 11:38:58 | 000,525,824 | ---- | M] () -- C:\Users\Duncan\Desktop\dds.scr
[2010/04/29 11:37:43 | 000,050,477 | ---- | M] () -- C:\Users\Duncan\Desktop\Defogger.exe
[2010/04/29 11:21:40 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/26 17:31:37 | 000,008,938 | -HS- | M] () -- C:\Users\Duncan\AppData\Local\b08620CF7A25y
[2010/04/26 17:31:37 | 000,008,938 | -HS- | M] () -- C:\ProgramData\b08620CF7A25y
[2010/04/26 15:58:12 | 000,256,512 | ---- | M] () -- C:\Windows\PEV.exe
[2010/04/22 10:26:15 | 010,267,136 | ---- | M] () -- E:\Dunks Documents\ARCTIC LIFE.ppt
[2010/04/20 18:07:20 | 000,000,426 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2010/04/19 08:22:23 | 000,100,918 | ---- | M] () -- E:\Dunks Documents\Lecture 08 - Church (Handout).RTF
[2010/04/17 20:04:18 | 000,001,311 | ---- | M] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2010/04/17 20:04:15 | 000,000,172 | ---- | M] () -- C:\Windows\System32\drivers\NSS\0207030.022\isolate.ini
[2010/04/17 16:34:33 | 000,529,736 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/04/17 11:59:07 | 000,168,680 | ---- | M] () -- C:\Users\Duncan\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/04/16 20:13:12 | 000,000,850 | ---- | M] () -- C:\Users\Duncan\Desktop\Allway Sync.lnk
[2010/04/16 12:55:36 | 000,001,540 | ---- | M] () -- C:\Users\Duncan\Desktop\SDMain - Shortcut.lnk
[2010/04/14 13:33:05 | 000,001,972 | ---- | M] () -- C:\Users\Public\Desktop\DVD Architect Studio 4.5.lnk
[2010/04/14 12:33:11 | 000,000,556 | ---- | M] () -- C:\Users\Duncan\Desktop\Nota Bene Lingua Workstation.LNK
[2010/04/13 21:11:27 | 000,001,890 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/04/13 17:38:53 | 000,050,176 | ---- | M] () -- C:\Users\Duncan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/13 15:43:18 | 000,000,768 | ---- | M] () -- C:\Windows\System32\drivers\kgpcpy.cfg
[2010/04/13 15:01:17 | 000,284,915 | ---- | M] () -- C:\Users\Duncan\Desktop\gmer.zip
[2010/04/13 14:22:12 | 000,000,020 | ---- | M] () -- C:\Users\Duncan\defogger_reenable
[2010/04/13 13:15:09 | 000,002,044 | ---- | M] () -- C:\Users\Duncan\Desktop\HijackThis.lnk
[2010/04/13 11:47:35 | 000,002,327 | ---- | M] () -- C:\Users\Public\Desktop\Norton 360.lnk
[2010/04/13 11:41:09 | 000,001,306 | ---- | M] () -- C:\Users\Duncan\Desktop\Norton Installation Files.lnk
[2010/04/13 11:37:30 | 000,124,976 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
[2010/04/13 11:37:30 | 000,007,443 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
[2010/04/13 11:37:30 | 000,000,805 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF
[2010/04/13 00:57:39 | 000,001,251 | ---- | M] () -- C:\Users\Duncan\Desktop\Spybot - Search & Destroy.lnk
[2010/04/10 19:00:16 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Vegas Movie Studio Platinum 9.0.lnk
[2010/04/10 18:32:25 | 000,000,991 | ---- | M] () -- C:\Users\Public\Desktop\MAGIX PhotoStory on CD & DVD 9 Download Version.lnk
[2010/04/08 04:40:00 | 000,002,181 | ---- | M] () -- C:\Windows\Helicon Debug Window.ini
[2010/04/08 04:39:19 | 000,000,287 | ---- | M] () -- C:\Windows\win.ini
[2010/04/08 04:12:32 | 000,001,126 | ---- | M] () -- C:\Users\Duncan\Desktop\Helicon Filter.lnk
[2010/04/07 21:32:48 | 000,001,955 | ---- | M] () -- C:\Users\Public\Desktop\PHOTOfunSTUDIO HD Edition.lnk
[2010/04/07 18:45:59 | 000,002,175 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010/04/06 19:23:25 | 000,385,927 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100406-200413.backup
[2010/04/06 02:27:51 | 000,000,954 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2010/04/05 21:13:42 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2010/04/05 12:18:23 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010/04/05 12:13:19 | 000,001,105 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/04/05 01:30:31 | 000,000,996 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/04/04 20:54:50 | 000,000,984 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/31 02:58:24 | 000,353,592 | ---- | M] (DivX, Inc.) -- C:\Windows\System32\DivXControlPanelApplet.cpl
[2010/03/27 02:39:52 | 000,000,172 | ---- | M] () -- C:\Windows\System32\drivers\N360\0401000.020\isolate.ini
[2010/03/23 01:29:41 | 000,000,217 | ---- | M] () -- C:\Users\Duncan\Desktop\Realtek HD Audio Manager - Shortcut.lnk
[2010/03/23 01:06:15 | 000,001,298 | ---- | M] () -- C:\Users\Duncan\Desktop\plink - Shortcut (2).lnk
[2010/03/16 15:32:39 | 000,000,346 | ---- | M] () -- C:\Users\Duncan\Desktop\Hardware and Sound - Shortcut.lnk
[2010/03/15 23:02:36 | 000,000,505 | ---- | M] () -- C:\Users\Duncan\Desktop\Devices and Printers - Shortcut.lnk
[2010/03/14 00:55:20 | 000,001,024 | ---- | M] () -- C:\.rnd
[2010/03/11 18:30:06 | 000,001,836 | ---- | M] () -- C:\Users\Duncan\Desktop\R.U.S.E. Beta.lnk
[2010/03/11 17:05:54 | 000,001,986 | ---- | M] () -- C:\Users\Duncan\Desktop\Fan noise - Shortcut.lnk
[2010/03/09 22:09:56 | 000,001,006 | ---- | M] () -- C:\Users\Duncan\Desktop\GmoteServer.lnk
[2010/03/09 21:54:27 | 000,162,419 | ---- | M] () -- E:\Dunks Documents\ThemeStudy.st5
[2010/03/09 21:54:27 | 000,159,232 | ---- | M] () -- E:\Dunks Documents\Urban Mission teams.ppt
[2010/03/09 21:54:27 | 000,067,505 | ---- | M] () -- E:\Dunks Documents\ZOndervanLayoutScholar.st5
[2010/03/09 21:54:27 | 000,032,256 | ---- | M] () -- E:\Dunks Documents\YIP church application cover letter2.doc
[2010/03/09 21:54:27 | 000,030,720 | ---- | M] () -- E:\Dunks Documents\YIP church application cover letter3.doc
[2010/03/09 21:54:27 | 000,030,208 | ---- | M] () -- E:\Dunks Documents\YIP church application cover letter.doc
[2010/03/09 21:54:27 | 000,028,672 | ---- | M] () -- E:\Dunks Documents\Upstairs noise.doc
[2010/03/09 21:54:27 | 000,027,648 | ---- | M] () -- E:\Dunks Documents\WotYaGonDoVerses.doc
[2010/03/09 21:54:27 | 000,027,174 | ---- | M] () -- E:\Dunks Documents\W518 (wmr).wma
[2010/03/09 21:54:27 | 000,025,600 | ---- | M] () -- E:\Dunks Documents\virgin 30 research shay.doc
[2010/03/09 21:54:27 | 000,024,064 | ---- | M] () -- E:\Dunks Documents\Toilet Rules.doc
[2010/03/09 21:54:27 | 000,020,836 | ---- | M] () -- E:\Dunks Documents\Untitledlambethpalace.dar
[2010/03/09 21:54:27 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\wireless Home.doc
[2010/03/09 21:54:27 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\Urban Mission.doc
[2010/03/09 21:54:27 | 000,017,920 | ---- | M] () -- E:\Dunks Documents\yip hire research.xls
[2010/03/09 21:54:27 | 000,014,336 | ---- | M] () -- E:\Dunks Documents\teachingVidEditingSheet.xls
[2010/03/09 21:54:27 | 000,013,824 | ---- | M] () -- E:\Dunks Documents\wii.xls
[2010/03/09 21:54:27 | 000,011,074 | ---- | M] () -- E:\Dunks Documents\ZOndervanLayout.st5
[2010/03/09 21:54:27 | 000,008,132 | ---- | M] () -- E:\Dunks Documents\Windows Mobile-based Pocket PC Home Page.url
[2010/03/09 21:54:27 | 000,003,589 | ---- | M] () -- E:\Dunks Documents\wireless 4 keys.rtf
[2010/03/09 21:54:27 | 000,000,352 | ---- | M] () -- E:\Dunks Documents\The Latest News in Video & Audio with Wanadoo Broadband.url
[2010/03/09 21:54:27 | 000,000,294 | ---- | M] () -- E:\Dunks Documents\The Great Dinosaur Mystery STREAMING VIDEO - ChristianAnswers.Net.url
[2010/03/09 21:54:27 | 000,000,272 | ---- | M] () -- E:\Dunks Documents\Tesco.com.url
[2010/03/09 21:54:27 | 000,000,270 | ---- | M] () -- E:\Dunks Documents\What Laptop & Handheld PC Forum - Main Forum.url
[2010/03/09 21:54:27 | 000,000,241 | ---- | M] () -- E:\Dunks Documents\Virtual Tour of Bath.url
[2010/03/09 21:54:27 | 000,000,237 | ---- | M] () -- E:\Dunks Documents\trading standards.url
[2010/03/09 21:54:27 | 000,000,225 | ---- | M] () -- E:\Dunks Documents\TechLore.com - How to connect a computer to your TV set.url
[2010/03/09 21:54:27 | 000,000,198 | ---- | M] () -- E:\Dunks Documents\westminster council.url
[2010/03/09 21:54:27 | 000,000,196 | ---- | M] () -- E:\Dunks Documents\UPS Package Tracking.url
[2010/03/09 21:54:27 | 000,000,186 | ---- | M] () -- E:\Dunks Documents\Wanadoo - Today.url
[2010/03/09 21:54:27 | 000,000,182 | ---- | M] () -- E:\Dunks Documents\Welcome to Wyatt Archaeological Research Inc.url
[2010/03/09 21:54:27 | 000,000,182 | ---- | M] () -- E:\Dunks Documents\uk.weather.com - Local Weather.url
[2010/03/09 21:54:27 | 000,000,174 | ---- | M] () -- E:\Dunks Documents\Welcome to MSN.co.uk.url
[2010/03/09 21:54:27 | 000,000,160 | ---- | M] () -- E:\Dunks Documents\Transport for London - Journey Planner - Home.url
[2010/03/09 21:54:27 | 000,000,150 | ---- | M] () -- E:\Dunks Documents\Welcome to MP3 Networks.url
[2010/03/09 21:54:27 | 000,000,142 | ---- | M] () -- E:\Dunks Documents\Welcome to MP3Review.com.url
[2010/03/09 21:54:26 | 000,967,680 | ---- | M] () -- E:\Dunks Documents\SHaysAltar.doc
[2010/03/09 21:54:26 | 000,022,016 | ---- | M] () -- E:\Dunks Documents\studioinsurance.doc
[2010/03/09 21:54:26 | 000,021,504 | ---- | M] () -- E:\Dunks Documents\studioinsuranceForXLAIRGORMAN.doc
[2010/03/09 21:54:26 | 000,021,504 | ---- | M] () -- E:\Dunks Documents\studioinsuranceAsOf21July04.doc
[2010/03/09 21:54:26 | 000,020,480 | ---- | M] () -- E:\Dunks Documents\sycamoor community centre.doc
[2010/03/09 21:54:26 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\Support info.doc
[2010/03/09 21:54:26 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\SongList.doc
[2010/03/09 21:54:26 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\Smartsound.doc
[2010/03/09 21:54:26 | 000,015,872 | ---- | M] () -- E:\Dunks Documents\Souththameshours20045.xls
[2010/03/09 21:54:26 | 000,015,872 | ---- | M] () -- E:\Dunks Documents\shipping books from USA.xls
[2010/03/09 21:54:26 | 000,001,997 | ---- | M] () -- E:\Dunks Documents\talktalk sign up 12oct07.rtf
[2010/03/09 21:54:26 | 000,000,357 | ---- | M] () -- E:\Dunks Documents\T-Mobile (UK) my T-Mobile.url
[2010/03/09 21:54:26 | 000,000,309 | ---- | M] () -- E:\Dunks Documents\SONY VAIO Laptops, Laptop notebook notebooks at discount prices from Laptopshop.co.uk.url
[2010/03/09 21:54:26 | 000,000,250 | ---- | M] () -- E:\Dunks Documents\Sony UK AC Adaptor 19.5V(DC) for R600HFP & GRX Series.url
[2010/03/09 21:54:26 | 000,000,195 | ---- | M] () -- E:\Dunks Documents\SOS Home.url
[2010/03/09 21:54:26 | 000,000,180 | ---- | M] () -- E:\Dunks Documents\SouthTHamesEmail.url
[2010/03/09 21:54:26 | 000,000,057 | ---- | M] () -- E:\Dunks Documents\Sony Style Europe.url
[2010/03/09 21:54:25 | 000,639,061 | ---- | M] () -- E:\Dunks Documents\shays Go info.JPG
[2010/03/09 21:54:24 | 000,632,636 | ---- | M] () -- E:\Dunks Documents\orange info shay.pdf
[2010/03/09 21:54:24 | 000,239,104 | ---- | M] () -- E:\Dunks Documents\Maidstonewords.ppt
[2010/03/09 21:54:24 | 000,149,504 | ---- | M] () -- E:\Dunks Documents\PMPcomparisons.xls
[2010/03/09 21:54:24 | 000,097,225 | ---- | M] () -- E:\Dunks Documents\S&LAnimals29.05.jpg
[2010/03/09 21:54:24 | 000,083,807 | ---- | M] () -- E:\Dunks Documents\mat20.st5
[2010/03/09 21:54:24 | 000,064,784 | ---- | M] () -- E:\Dunks Documents\out of body audio.veg.bak
[2010/03/09 21:54:24 | 000,064,784 | ---- | M] () -- E:\Dunks Documents\out of body audio.veg
[2010/03/09 21:54:24 | 000,056,832 | ---- | M] () -- E:\Dunks Documents\MuslimBoys.doc
[2010/03/09 21:54:24 | 000,041,984 | ---- | M] () -- E:\Dunks Documents\noah builds ark sunday school.doc
[2010/03/09 21:54:24 | 000,032,842 | ---- | M] () -- E:\Dunks Documents\MyStudy.st5
[2010/03/09 21:54:24 | 000,031,744 | ---- | M] () -- E:\Dunks Documents\Music Production workshops.doc
[2010/03/09 21:54:24 | 000,028,672 | ---- | M] () -- E:\Dunks Documents\Memento.doc
[2010/03/09 21:54:24 | 000,027,136 | ---- | M] () -- E:\Dunks Documents\ordered books.doc
[2010/03/09 21:54:24 | 000,026,112 | ---- | M] () -- E:\Dunks Documents\Persecution.doc
[2010/03/09 21:54:24 | 000,026,112 | ---- | M] () -- E:\Dunks Documents\Newslettershay.doc
[2010/03/09 21:54:24 | 000,025,088 | ---- | M] () -- E:\Dunks Documents\pparking fine letr oct06.doc
[2010/03/09 21:54:24 | 000,025,088 | ---- | M] () -- E:\Dunks Documents\Newsletter.doc
[2010/03/09 21:54:24 | 000,024,576 | ---- | M] () -- E:\Dunks Documents\My wife purchased a Philips One cup kettle on Sunday afternoon.doc
[2010/03/09 21:54:24 | 000,024,064 | ---- | M] () -- E:\Dunks Documents\Noisey neighbours 2.doc
[2010/03/09 21:54:24 | 000,024,064 | ---- | M] () -- E:\Dunks Documents\Movies.doc
[2010/03/09 21:54:24 | 000,022,528 | ---- | M] () -- E:\Dunks Documents\LuvSicEpilogueHVibe.doc
[2010/03/09 21:54:24 | 000,021,504 | ---- | M] () -- E:\Dunks Documents\Rythmingwords.doc
[2010/03/09 21:54:24 | 000,021,504 | ---- | M] () -- E:\Dunks Documents\ProgressReport.doc
[2010/03/09 21:54:24 | 000,021,472 | ---- | M] () -- E:\Dunks Documents\mumsdvd.dar
[2010/03/09 21:54:24 | 000,020,992 | ---- | M] () -- E:\Dunks Documents\Notices 20aug.doc
[2010/03/09 21:54:24 | 000,020,480 | ---- | M] () -- E:\Dunks Documents\Notices 6aug.doc
[2010/03/09 21:54:24 | 000,020,480 | ---- | M] () -- E:\Dunks Documents\MC worskshop.doc
[2010/03/09 21:54:24 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\Printer john browns.doc
[2010/03/09 21:54:24 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\Prayer Requests.doc
[2010/03/09 21:54:24 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\Office XP SERIAL NO.doc
[2010/03/09 21:54:24 | 000,014,848 | ---- | M] () -- E:\Dunks Documents\Observations.xls
[2010/03/09 21:54:24 | 000,013,824 | ---- | M] () -- E:\Dunks Documents\mp3_disk_space.xls
[2010/03/09 21:54:24 | 000,001,626 | ---- | M] () -- E:\Dunks Documents\prelogitectdelete.reg
[2010/03/09 21:54:24 | 000,001,380 | ---- | M] () -- E:\Dunks Documents\saphhires cover plus refund letter.rtf
[2010/03/09 21:54:24 | 000,000,842 | ---- | M] () -- E:\Dunks Documents\PC World ...with you every step of the way.url
[2010/03/09 21:54:24 | 000,000,566 | ---- | M] () -- E:\Dunks Documents\MoS Downloads.url
[2010/03/09 21:54:24 | 000,000,476 | ---- | M] () -- E:\Dunks Documents\roe lettings norley vale 650 studio.url
[2010/03/09 21:54:24 | 000,000,390 | ---- | M] () -- E:\Dunks Documents\My Sharing Folders.lnk
[2010/03/09 21:54:24 | 000,000,299 | ---- | M] () -- E:\Dunks Documents\Moneycorp Commercial Foreign Exchange.url
[2010/03/09 21:54:24 | 000,000,282 | ---- | M] () -- E:\Dunks Documents\National Rail Enquiries Online train times and fare info for mainland UK trains.url
[2010/03/09 21:54:24 | 000,000,231 | ---- | M] () -- E:\Dunks Documents\Sell Your Laptop To Laptopshop.co.uk.url
[2010/03/09 21:54:24 | 000,000,206 | ---- | M] () -- E:\Dunks Documents\PC Magazine Product Features for the Toshiba Satellite P25-S609 (PSP20U-19PS8R) PC Notebook.url
[2010/03/09 21:54:24 | 000,000,206 | ---- | M] () -- E:\Dunks Documents\Maternity - Having a baby at Kingston Hospital.url
[2010/03/09 21:54:24 | 000,000,197 | ---- | M] () -- E:\Dunks Documents\Radio Station Guide.url
[2010/03/09 21:54:24 | 000,000,186 | ---- | M] () -- E:\Dunks Documents\Passport Service - Entry To The USA New Requirements From 26 October 2004.url
[2010/03/09 21:54:24 | 000,000,186 | ---- | M] () -- E:\Dunks Documents\MSNBC - MSNBC Front Page.url
[2010/03/09 21:54:24 | 000,000,182 | ---- | M] () -- E:\Dunks Documents\MIDDLE EAST NEWS.url
[2010/03/09 21:54:24 | 000,000,175 | ---- | M] () -- E:\Dunks Documents\Ryanair.Com - The Low Fares Airline - 50% cheaper than easyJet.url
[2010/03/09 21:54:24 | 000,000,168 | ---- | M] () -- E:\Dunks Documents\Send Free SMS Worldwide - SendSMSnow.com.url
[2010/03/09 21:54:24 | 000,000,168 | ---- | M] () -- E:\Dunks Documents\MP3.com THE destination for digital music..url
[2010/03/09 21:54:24 | 000,000,164 | ---- | M] () -- E:\Dunks Documents\Search.url
[2010/03/09 21:54:24 | 000,000,160 | ---- | M] () -- E:\Dunks Documents\Please sign in.url
[2010/03/09 21:54:24 | 000,000,128 | ---- | M] () -- E:\Dunks Documents\MEGAUPLOAD - We host the Internet - MAKE MONEY with our REWARD PROGRAM.url
[2010/03/09 21:54:24 | 000,000,128 | ---- | M] () -- E:\Dunks Documents\MapQuest Driving Directions, Maps & Live Traffic Reports.url
[2010/03/09 21:54:24 | 000,000,119 | ---- | M] () -- E:\Dunks Documents\MSN.com.url
[2010/03/09 21:54:24 | 000,000,104 | ---- | M] () -- E:\Dunks Documents\Recycle Bin.lnk
[2010/03/09 21:54:24 | 000,000,050 | ---- | M] () -- E:\Dunks Documents\Moodlogic.url
[2010/03/09 21:54:23 | 000,209,204 | ---- | M] () -- E:\Dunks Documents\LloydsTSB-babybond-KeyFeatures.pdf
[2010/03/09 21:54:23 | 000,101,360 | ---- | M] () -- E:\Dunks Documents\Josiah Hoops 001.avi.sfk
[2010/03/09 21:54:23 | 000,035,088 | ---- | M] () -- E:\Dunks Documents\july3rdRapbeats.nri
[2010/03/09 21:54:23 | 000,025,600 | ---- | M] () -- E:\Dunks Documents\Leaving the Studio.doc
[2010/03/09 21:54:23 | 000,024,064 | ---- | M] () -- E:\Dunks Documents\Kerusso.doc
[2010/03/09 21:54:23 | 000,020,992 | ---- | M] () -- E:\Dunks Documents\leaving O2.doc
[2010/03/09 21:54:23 | 000,015,872 | ---- | M] () -- E:\Dunks Documents\Logos purchase options.xls
[2010/03/09 21:54:23 | 000,000,380 | ---- | M] () -- E:\Dunks Documents\landis dell.url
[2010/03/09 21:54:23 | 000,000,378 | ---- | M] () -- E:\Dunks Documents\landis dell shay.url
[2010/03/09 21:54:23 | 000,000,348 | ---- | M] () -- E:\Dunks Documents\LloydsTSB - Statement23aug.url
[2010/03/09 21:54:23 | 000,000,324 | ---- | M] () -- E:\Dunks Documents\LloydsTSB - Statement23aug-2.url
[2010/03/09 21:54:23 | 000,000,307 | ---- | M] () -- E:\Dunks Documents\LUCIA ADDRESS LABEL.rtf
[2010/03/09 21:54:23 | 000,000,252 | ---- | M] () -- E:\Dunks Documents\liz reed address.rtf
[2010/03/09 21:54:23 | 000,000,206 | ---- | M] () -- E:\Dunks Documents\LowRez works.hb
[2010/03/09 21:54:23 | 000,000,198 | ---- | M] () -- E:\Dunks Documents\King James Only Debate.doc
[2010/03/09 21:54:23 | 000,000,162 | ---- | M] () -- E:\Dunks Documents\LloydsTSB online - Welcome.url
[2010/03/09 21:54:23 | 000,000,152 | ---- | M] () -- E:\Dunks Documents\Latest news from AMG.url
[2010/03/09 21:54:22 | 000,045,568 | ---- | M] () -- E:\Dunks Documents\JAMES SHAYS PRINTOUT.doc
[2010/03/09 21:54:22 | 000,025,088 | ---- | M] () -- E:\Dunks Documents\Josiah feeding jan07.doc
[2010/03/09 21:54:22 | 000,024,576 | ---- | M] () -- E:\Dunks Documents\Iriver Prices.doc
[2010/03/09 21:54:22 | 000,024,064 | ---- | M] () -- E:\Dunks Documents\john lewis wii.doc
[2010/03/09 21:54:22 | 000,023,762 | ---- | M] () -- E:\Dunks Documents\jan09 donor list peters twice.pdf
[2010/03/09 21:54:22 | 000,020,992 | ---- | M] () -- E:\Dunks Documents\jobs in church.doc
[2010/03/09 21:54:22 | 000,006,061 | ---- | M] () -- E:\Dunks Documents\John.st5
[2010/03/09 21:54:22 | 000,000,128 | ---- | M] () -- E:\Dunks Documents\Inta Audio - Computer Music, Pro Audio & DAW, Edirol, Fostex, M Audio, Terratec, RME, Steinberg.url
[2010/03/09 21:54:21 | 000,739,918 | ---- | M] () -- E:\Dunks Documents\HVIbe4SoundClick.swi
[2010/03/09 21:54:21 | 000,179,200 | ---- | M] () -- E:\Dunks Documents\hvibesite.ows
[2010/03/09 21:54:21 | 000,146,432 | ---- | M] () -- E:\Dunks Documents\hosea joel obadiah coloring pages.doc
[2010/03/09 21:54:21 | 000,095,009 | ---- | M] () -- E:\Dunks Documents\HVIbe4SoundClick.swf
[2010/03/09 21:54:21 | 000,056,553 | ---- | M] () -- E:\Dunks Documents\Image1.jpg
[2010/03/09 21:54:21 | 000,037,686 | ---- | M] () -- E:\Dunks Documents\Image2.jpg
[2010/03/09 21:54:21 | 000,035,710 | ---- | M] () -- E:\Dunks Documents\Image0.jpg
[2010/03/09 21:54:21 | 000,024,576 | ---- | M] () -- E:\Dunks Documents\HigherVibeTwickenham.doc
[2010/03/09 21:54:21 | 000,000,643 | ---- | M] () -- E:\Dunks Documents\HP ze4718EA Athlon 2600+ DVD+R 256-30 15.0 TFT XPHome Notebooks.url
[2010/03/09 21:54:21 | 000,000,194 | ---- | M] () -- E:\Dunks Documents\history of marijuana by marijuana addiction.info.url
[2010/03/09 21:54:21 | 000,000,190 | ---- | M] () -- E:\Dunks Documents\http--www.nusystems.co.uk-cat-catalogue.aspp=0&g=57&b=0.url
[2010/03/09 21:54:21 | 000,000,160 | ---- | M] () -- E:\Dunks Documents\HOTMAIL.url
[2010/03/09 21:54:21 | 000,000,132 | ---- | M] () -- E:\Dunks Documents\http--www.highervibe.co.uk-.url
[2010/03/09 21:54:20 | 000,419,840 | ---- | M] () -- E:\Dunks Documents\HigherVibeNewsletterSept05.doc
[2010/03/09 21:54:20 | 000,416,768 | ---- | M] () -- E:\Dunks Documents\HigherVibeNewsletterJuly.doc
[2010/03/09 21:54:19 | 000,169,040 | ---- | M] () -- E:\Dunks Documents\Heb Voc 16.veg
[2010/03/09 21:54:19 | 000,165,088 | ---- | M] () -- E:\Dunks Documents\Heb Voc 16.veg.bak
[2010/03/09 21:54:19 | 000,145,155 | ---- | M] () -- E:\Dunks Documents\gpa_advert_inde_29June06.pdf
[2010/03/09 21:54:19 | 000,029,184 | ---- | M] () -- E:\Dunks Documents\HigherVibe Magazine Article.doc
[2010/03/09 21:54:19 | 000,026,112 | ---- | M] () -- E:\Dunks Documents\Here is a list of control motions for Wii Boxing.doc
[2010/03/09 21:54:19 | 000,025,088 | ---- | M] () -- E:\Dunks Documents\hand baggage nwair.doc
[2010/03/09 21:54:19 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\HigherVibe Driving Log.doc
[2010/03/09 21:54:19 | 000,002,978 | ---- | M] () -- E:\Dunks Documents\googlevideotest.htm
[2010/03/09 21:54:19 | 000,001,659 | ---- | M] () -- E:\Dunks Documents\Gmail - Compose Mail.url
[2010/03/09 21:54:19 | 000,000,833 | ---- | M] () -- E:\Dunks Documents\glasses info for josiah.rtf
[2010/03/09 21:54:19 | 000,000,218 | ---- | M] () -- E:\Dunks Documents\Halfords.com britax first class car seat combination seat Ģ99.url
[2010/03/09 21:54:19 | 000,000,183 | ---- | M] () -- E:\Dunks Documents\Google Book Search.url
[2010/03/09 21:54:19 | 000,000,177 | ---- | M] () -- E:\Dunks Documents\Google.url
[2010/03/09 21:54:19 | 000,000,156 | ---- | M] () -- E:\Dunks Documents\HIGHERVIBE.url
[2010/03/09 21:54:18 | 000,741,583 | ---- | M] () -- E:\Dunks Documents\firsthVIBEsWISH.sbk
[2010/03/09 21:54:18 | 000,740,520 | ---- | M] () -- E:\Dunks Documents\firsthVIBEsWISH.swi
[2010/03/09 21:54:18 | 000,092,504 | ---- | M] () -- E:\Dunks Documents\firsthVIBEsWISH.swf
[2010/03/09 21:54:18 | 000,000,278 | ---- | M] () -- E:\Dunks Documents\Friends Reunited - Your Friends.url
[2010/03/09 21:54:18 | 000,000,157 | ---- | M] () -- E:\Dunks Documents\Freeserve.url
[2010/03/09 21:54:17 | 000,066,324 | ---- | M] () -- E:\Dunks Documents\fam.rpc
[2010/03/09 21:54:17 | 000,028,160 | ---- | M] () -- E:\Dunks Documents\Etown youth group.doc
[2010/03/09 21:54:17 | 000,024,576 | ---- | M] () -- E:\Dunks Documents\ebayfeedback.doc
[2010/03/09 21:54:17 | 000,020,992 | ---- | M] () -- E:\Dunks Documents\Estates to reach.doc
[2010/03/09 21:54:17 | 000,013,824 | ---- | M] () -- E:\Dunks Documents\EPcosts.xls
[2010/03/09 21:54:17 | 000,001,507 | ---- | M] () -- E:\Dunks Documents\FastDownloads.lnk
[2010/03/09 21:54:17 | 000,000,163 | ---- | M] () -- E:\Dunks Documents\Email.url
[2010/03/09 21:54:16 | 000,206,336 | ---- | M] () -- E:\Dunks Documents\DVC flyer11 Church advert.pub
[2010/03/09 21:54:16 | 000,020,597 | ---- | M] () -- E:\Dunks Documents\DVD catalogue for website.rtf
[2010/03/09 21:54:16 | 000,002,887 | ---- | M] () -- E:\Dunks Documents\DVD catalogue.rtf
[2010/03/09 21:54:16 | 000,000,137 | ---- | M] () -- E:\Dunks Documents\eBay.co.uk - Buy It Sell It Love It.url
[2010/03/09 21:54:15 | 000,370,688 | ---- | M] () -- E:\Dunks Documents\duncan flight home info nwa.doc
[2010/03/09 21:54:15 | 000,044,597 | ---- | M] () -- E:\Dunks Documents\Duncan.contact
[2010/03/09 21:54:15 | 000,026,112 | ---- | M] () -- E:\Dunks Documents\DunksTImetable.xls
[2010/03/09 21:54:15 | 000,016,896 | ---- | M] () -- E:\Dunks Documents\DuncanTimetable.xls
[2010/03/09 21:54:14 | 000,038,912 | ---- | M] () -- E:\Dunks Documents\DISCIPLESHIP.doc
[2010/03/09 21:54:14 | 000,020,480 | ---- | M] () -- E:\Dunks Documents\DJ worskshop.doc
[2010/03/09 21:54:14 | 000,000,154 | ---- | M] () -- E:\Dunks Documents\Download Fonts - 1001 Free Fonts.url
[2010/03/09 21:54:13 | 000,280,070 | ---- | M] () -- E:\Dunks Documents\Digitaldistortion.pdf
[2010/03/09 21:54:13 | 000,124,104 | ---- | M] () -- E:\Dunks Documents\DellOutlookContacts.CSV
[2010/03/09 21:54:13 | 000,076,524 | ---- | M] () -- E:\Dunks Documents\Deut05.st5
[2010/03/09 21:54:13 | 000,037,888 | ---- | M] () -- E:\Dunks Documents\difficultconversations.doc
[2010/03/09 21:54:12 | 000,040,448 | ---- | M] () -- E:\Dunks Documents\DELIVERANCE MINISTRY.doc
[2010/03/09 21:54:11 | 000,354,304 | ---- | M] () -- E:\Dunks Documents\Definition of the devil.ppt
[2010/03/09 21:54:11 | 000,024,064 | ---- | M] () -- E:\Dunks Documents\DAYPER PASSPORT.doc
[2010/03/09 21:54:11 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\COUNTRYMAN CABLE EXCHANGE.doc
[2010/03/09 21:54:11 | 000,000,704 | ---- | M] () -- E:\Dunks Documents\Default.sfvidcap
[2010/03/09 21:54:11 | 000,000,542 | ---- | M] () -- E:\Dunks Documents\decks sale dec 06 info.rtf
[2010/03/09 21:54:10 | 000,384,000 | ---- | M] () -- E:\Dunks Documents\Copy of King James Only DebateHelp.doc
[2010/03/09 21:54:10 | 000,384,000 | ---- | M] () -- E:\Dunks Documents\Copy of King James Only Debate.doc
[2010/03/09 21:54:10 | 000,003,209 | ---- | M] () -- E:\Dunks Documents\CompleteHV20frameshtml.html
[2010/03/09 21:54:10 | 000,001,718 | ---- | M] () -- E:\Dunks Documents\condoleza rice letter nkorea.rtf
[2010/03/09 21:54:09 | 000,740,059 | ---- | M] () -- E:\Dunks Documents\clickonDJ.swi
[2010/03/09 21:54:09 | 000,095,063 | ---- | M] () -- E:\Dunks Documents\clickonDJ.swf
[2010/03/09 21:54:09 | 000,036,352 | ---- | M] () -- E:\Dunks Documents\ChristsDivinity.doc
[2010/03/09 21:54:09 | 000,000,359 | ---- | M] () -- E:\Dunks Documents\Cinemanow Purchase Options.url
[2010/03/09 21:54:09 | 000,000,062 | ---- | M] () -- E:\Dunks Documents\club VAIO Europe.url
[2010/03/09 21:54:08 | 000,024,576 | ---- | M] () -- E:\Dunks Documents\chords.doc
[2010/03/09 21:54:08 | 000,000,283 | ---- | M] () -- E:\Dunks Documents\Child friendly restaurants in SW London.url
[2010/03/09 21:54:08 | 000,000,152 | ---- | M] () -- E:\Dunks Documents\Choosing the correct futon or mattress.url
[2010/03/09 21:54:01 | 000,072,381 | ---- | M] () -- E:\Dunks Documents\CC Wandsworth site design.jpg
[2010/03/09 21:54:01 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\CastleInternet.doc
[2010/03/09 21:54:01 | 000,000,162 | ---- | M] () -- E:\Dunks Documents\Chat.url
[2010/03/09 21:54:00 | 000,166,550 | ---- | M] () -- E:\Dunks Documents\ati INSTRUCTIONS.tif
[2010/03/09 21:54:00 | 000,090,687 | ---- | M] () -- E:\Dunks Documents\AngeloftheLord.jpg
[2010/03/09 21:54:00 | 000,069,632 | ---- | M] () -- E:\Dunks Documents\Calvary chapel affiliation and escatology.ppt
[2010/03/09 21:54:00 | 000,053,248 | ---- | M] () -- E:\Dunks Documents\bulletinCCWdec05.doc
[2010/03/09 21:54:00 | 000,052,614 | ---- | M] () -- E:\Dunks Documents\attendancebydecade.pdf
[2010/03/09 21:54:00 | 000,038,912 | ---- | M] () -- E:\Dunks Documents\BibleLyrics.doc
[2010/03/09 21:54:00 | 000,033,280 | ---- | M] () -- E:\Dunks Documents\bulletinCCWdec05 2.doc
[2010/03/09 21:54:00 | 000,031,744 | ---- | M] () -- E:\Dunks Documents\bulletinCCWdec05 3.doc
[2010/03/09 21:54:00 | 000,027,136 | ---- | M] () -- E:\Dunks Documents\AmbersTheology.doc
[2010/03/09 21:54:00 | 000,023,040 | ---- | M] () -- E:\Dunks Documents\AthletesFoot.doc
[2010/03/09 21:54:00 | 000,020,480 | ---- | M] () -- E:\Dunks Documents\Afiliation Papers.doc
[2010/03/09 21:54:00 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\camcorder tapes.doc
[2010/03/09 21:54:00 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\Alan sally army building ideas.doc
[2010/03/09 21:54:00 | 000,019,968 | ---- | M] () -- E:\Dunks Documents\Alan Norton Sally Army building.doc
[2010/03/09 21:54:00 | 000,014,848 | ---- | M] () -- E:\Dunks Documents\AmageddonEPSchedule.xls
[2010/03/09 21:54:00 | 000,003,590 | ---- | M] () -- E:\Dunks Documents\BeInSync Net diagnostic.bat
[2010/03/09 21:54:00 | 000,000,398 | ---- | M] () -- E:\Dunks Documents\Audio Computer, Video Editing, Music Laptop.url
[2010/03/09 21:54:00 | 000,000,376 | ---- | M] () -- E:\Dunks Documents\ASDA.com.url
[2010/03/09 21:54:00 | 000,000,307 | ---- | M] () -- E:\Dunks Documents\BBC NEWS News Front Page.url
[2010/03/09 21:54:00 | 000,000,293 | ---- | M] () -- E:\Dunks Documents\Amazon.com - Your Account.url
[2010/03/09 21:54:00 | 000,000,283 | ---- | M] () -- E:\Dunks Documents\Amazon.co.uk Welcome.url
[2010/03/09 21:54:00 | 000,000,268 | ---- | M] () -- E:\Dunks Documents\Boxing Zone Department 'BBE Punch Bags'.url
[2010/03/09 21:54:00 | 000,000,198 | ---- | M] () -- E:\Dunks Documents\BreakTheChain.org - Stop Junk E-Mail and Misinformation.url
[2010/03/09 21:54:00 | 000,000,192 | ---- | M] () -- E:\Dunks Documents\Calvary Chapel Austria conference center.url
[2010/03/09 21:54:00 | 000,000,173 | ---- | M] () -- E:\Dunks Documents\Amazon.co.uk - Online Shopping.url
[2010/03/09 21:54:00 | 000,000,166 | ---- | M] () -- E:\Dunks Documents\Auctions.url
[2010/03/09 21:54:00 | 000,000,160 | ---- | M] () -- E:\Dunks Documents\Arsenal Pub Guide.url
[2010/03/09 21:54:00 | 000,000,152 | ---- | M] () -- E:\Dunks Documents\Another Bit in the Wall.url
[2010/03/09 21:54:00 | 000,000,081 | ---- | M] () -- E:\Dunks Documents\Bath YMCA.url
[2010/03/09 21:53:59 | 000,142,685 | ---- | M] () -- E:\Dunks Documents\2008_Voter_Guide_Promo.jpg
[2010/03/09 21:53:59 | 000,076,475 | ---- | M] () -- E:\Dunks Documents\23Aug06.st5
[2010/03/09 21:53:59 | 000,075,349 | ---- | M] () -- E:\Dunks Documents\4biblesopen.st5
[2010/03/09 21:53:59 | 000,023,040 | ---- | M] () -- E:\Dunks Documents\A Comparison of Pioneer CDJ1000mk1 and Numark CDX.doc
[2010/03/09 21:53:59 | 000,015,872 | ---- | M] () -- E:\Dunks Documents\2004-5finances.xls
[2010/03/09 21:53:59 | 000,000,830 | ---- | M] () -- E:\Dunks Documents\About.com http--www.listen.com-sub1.jspparent=494.url
[2010/03/09 21:53:59 | 000,000,308 | ---- | M] () -- E:\Dunks Documents\7wear - Christian t-shirts event t-shirts christian clothes t-shirt printing. Men's T-Shirts.url
[2010/03/09 21:53:59 | 000,000,253 | ---- | M] () -- E:\Dunks Documents\ac adaptor laptop - Buy at the best price on Kelkoo.url
[2010/03/09 21:53:59 | 000,000,163 | ---- | M] () -- E:\Dunks Documents\About Freeserve.url
[2010/03/09 21:53:58 | 000,081,217 | ---- | M] () -- E:\Dunks Documents\19Aug06.st5
[2010/03/09 21:53:58 | 000,010,471 | ---- | M] () -- E:\Dunks Documents\1Timothy DF.lsn
[2010/03/09 18:23:19 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/03/09 18:06:58 | 000,024,576 | ---- | M] (HTC1124 Inc) -- C:\Windows\System32\drivers\ANDROIDUSB.sys
[2010/03/09 16:00:34 | 000,115,081 | ---- | M] () -- C:\Windows\System32\drivers\androidusb.INF
[2010/03/09 15:57:38 | 000,000,127 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/03/09 09:08:43 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010/03/09 02:25:58 | 000,000,020 | -HS- | M] () -- C:\Users\Duncan\ntuser.ini
[2010/03/09 02:11:00 | 000,041,962 | ---- | M] () -- C:\Windows\System32\license.rtf
[2010/03/09 01:57:56 | 000,021,924 | ---- | M] () -- C:\Windows\System32\emptyregdb.dat
[2010/03/09 01:13:17 | 000,524,288 | -HS- | M] () -- C:\Users\Duncan\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/03/09 01:13:17 | 000,524,288 | -HS- | M] () -- C:\Users\Duncan\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/03/09 01:13:17 | 000,065,536 | -HS- | M] () -- C:\Users\Duncan\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/03/09 01:12:26 | 000,000,034 | ---- | M] () -- C:\Windows\System32\BD7010.DAT
[2010/03/09 01:11:57 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2010/03/09 00:35:25 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/09 00:35:25 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/08 23:38:43 | 000,001,890 | ---- | M] () -- C:\Windows\diagwrn.xml
[2010/03/08 23:38:43 | 000,001,890 | ---- | M] () -- C:\Windows\diagerr.xml
[2010/03/08 23:24:03 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/03/08 18:59:18 | 000,094,208 | ---- | M] (DivX, Inc.) -- C:\Windows\System32\dpl100.dll
[2010/03/06 06:23:03 | 000,000,000 | ---- | M] () -- C:\Windows\DbgOut.INI
[2010/03/06 05:37:21 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2010/03/04 01:01:43 | 000,209,920 | ---- | M] () -- C:\Windows\System32\nmNsp.dll
[2010/03/04 01:01:43 | 000,160,256 | ---- | M] () -- C:\Windows\System32\CESpy.dll
[2010/03/04 00:14:34 | 000,012,986 | ---- | M] () -- C:\Users\Duncan\AppData\Roaming\Comma Separated Values (Windows).CAL
[2010/03/04 00:10:12 | 000,038,450 | ---- | M] () -- C:\Users\Duncan\AppData\Roaming\Comma Separated Values (DOS).ADR
[2010/03/02 04:32:06 | 000,007,442 | ---- | M] () -- C:\Windows\System32\drivers\N360\0401000.020\srtspx.cat
[2010/03/02 04:32:06 | 000,007,438 | ---- | M] () -- C:\Windows\System32\drivers\N360\0401000.020\srtsp.cat
[2010/02/28 21:02:40 | 000,000,648 | ---- | M] () -- C:\Users\Duncan\Desktop\Documents on Vario II.LNK
[2010/02/28 21:02:34 | 000,000,756 | ---- | M] () -- C:\Users\Duncan\Desktop\Windows Mobile Device Center.lnk
[2010/02/27 03:23:54 | 000,116,784 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\ironx86.sys
[2010/02/27 03:23:54 | 000,116,784 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\ironx86.sys
[2010/02/27 03:23:54 | 000,007,438 | ---- | M] () -- C:\Windows\System32\drivers\N360\0401000.020\iron.cat
[2010/02/27 03:23:54 | 000,000,741 | ---- | M] () -- C:\Windows\System32\drivers\N360\0401000.020\iron.inf
[2010/02/27 03:23:21 | 000,325,680 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\srtsp.sys
[2010/02/27 03:23:21 | 000,043,696 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\srtspx.sys
[2010/02/27 03:23:21 | 000,043,696 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\srtspx.sys
[2010/02/27 03:23:21 | 000,001,388 | ---- | M] () -- C:\Windows\System32\drivers\N360\0401000.020\srtspx.inf
[2010/02/27 03:23:21 | 000,001,382 | ---- | M] () -- C:\Windows\System32\drivers\N360\0401000.020\srtsp.inf
[2010/02/26 00:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\N360\0401000.020\cchpx86.sys
[2010/02/26 00:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\cchpx86.sys
[2010/02/25 18:54:56 | 000,007,396 | ---- | M] () -- C:\Windows\System32\drivers\N360\0401000.020\cchpx86.cat
[2010/02/24 22:01:11 | 000,000,188 | ---- | M] () -- C:\Windows\NBSETUP.INI
[2010/02/24 18:14:32 | 000,002,187 | ---- | M] () -- C:\Users\Duncan\Desktop\Windows Mobile Device Center (2).lnk
[2010/02/19 20:27:36 | 000,720,384 | ---- | M] (DivX, Inc.) -- C:\Windows\System32\DivX.dll
[2010/02/19 20:27:16 | 000,856,064 | ---- | M] (DivX, Inc.) -- C:\Windows\System32\divx_xx0c.dll
[2010/02/19 20:27:16 | 000,856,064 | ---- | M] (DivX, Inc.) -- C:\Windows\System32\divx_xx07.dll
[2010/02/19 20:27:16 | 000,847,872 | ---- | M] (DivX, Inc.) -- C:\Windows\System32\divx_xx0a.dll
[2010/02/19 20:27:16 | 000,843,776 | ---- | M] (DivX, Inc.) -- C:\Windows\System32\divx_xx16.dll
[2010/02/19 20:27:16 | 000,839,680 | ---- | M] (DivX, Inc.) -- C:\Windows\System32\divx_xx11.dll
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 E:\Dunks Documents\*.tmp files -> E:\Dunks Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/06 20:20:09 | 002,672,312 | ---- | C] () -- C:\Users\Duncan\Desktop\esetsmartinstaller_enu.exe
[2010/05/06 13:15:56 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/05/04 19:15:57 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/05/04 19:15:57 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/05/04 19:15:56 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/05/04 19:15:56 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/05/04 19:15:56 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/05/04 19:10:02 | 003,945,780 | R--- | C] () -- C:\Users\Duncan\Desktop\schrauber.exe
[2010/04/29 11:37:41 | 000,050,477 | ---- | C] () -- C:\Users\Duncan\Desktop\Defogger.exe
[2010/04/26 17:29:40 | 000,008,938 | -HS- | C] () -- C:\Users\Duncan\AppData\Local\b08620CF7A25y
[2010/04/26 17:29:40 | 000,008,938 | -HS- | C] () -- C:\ProgramData\b08620CF7A25y
[2010/04/22 17:24:51 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/21 16:12:25 | 010,267,136 | ---- | C] () -- E:\Dunks Documents\ARCTIC LIFE.ppt
[2010/04/19 08:22:19 | 000,100,918 | ---- | C] () -- E:\Dunks Documents\Lecture 08 - Church (Handout).RTF
[2010/04/17 20:04:18 | 000,001,311 | ---- | C] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2010/04/17 20:04:18 | 000,000,476 | -H-- | C] () -- C:\Windows\tasks\Norton Security Scan for Duncan.job
[2010/04/17 20:04:15 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\NSS\0207030.022\isolate.ini
[2010/04/14 13:33:05 | 000,001,972 | ---- | C] () -- C:\Users\Public\Desktop\DVD Architect Studio 4.5.lnk
[2010/04/13 21:11:26 | 000,001,890 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/04/13 15:42:23 | 000,000,768 | ---- | C] () -- C:\Windows\System32\drivers\kgpcpy.cfg
[2010/04/13 15:01:15 | 000,284,915 | ---- | C] () -- C:\Users\Duncan\Desktop\gmer.zip
[2010/04/13 14:47:32 | 000,525,824 | ---- | C] () -- C:\Users\Duncan\Desktop\dds.scr
[2010/04/13 14:21:30 | 000,000,020 | ---- | C] () -- C:\Users\Duncan\defogger_reenable
[2010/04/13 13:15:07 | 000,002,044 | ---- | C] () -- C:\Users\Duncan\Desktop\HijackThis.lnk
[2010/04/13 11:47:00 | 000,946,418 | ---- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\Cat.DB
[2010/04/13 11:44:05 | 000,007,787 | R--- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\symnetv.cat
[2010/04/13 11:44:05 | 000,007,444 | R--- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\symefa.cat
[2010/04/13 11:44:05 | 000,007,368 | R--- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\symnet.cat
[2010/04/13 11:44:05 | 000,003,374 | R--- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\symefa.inf
[2010/04/13 11:44:05 | 000,001,473 | R--- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\symnetv.inf
[2010/04/13 11:44:05 | 000,001,445 | R--- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\symnet.inf
[2010/04/13 11:44:04 | 000,007,442 | ---- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\srtspx.cat
[2010/04/13 11:44:04 | 000,007,438 | ---- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\srtsp.cat
[2010/04/13 11:44:04 | 000,007,425 | R--- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\symds.cat
[2010/04/13 11:44:04 | 000,002,793 | R--- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\symds.inf
[2010/04/13 11:44:04 | 000,001,388 | ---- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\srtspx.inf
[2010/04/13 11:44:04 | 000,001,382 | ---- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\srtsp.inf
[2010/04/13 11:44:04 | 000,000,741 | ---- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\iron.inf
[2010/04/13 11:44:03 | 000,007,438 | ---- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\iron.cat
[2010/04/13 11:44:03 | 000,001,754 | ---- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\cchpx86.inf
[2010/04/13 11:44:02 | 000,007,396 | ---- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\cchpx86.cat
[2010/04/13 11:43:24 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\N360\0401000.020\isolate.ini
[2010/04/13 11:33:29 | 000,001,306 | ---- | C] () -- C:\Users\Duncan\Desktop\Norton Installation Files.lnk
[2010/04/13 00:46:29 | 000,007,443 | ---- | C] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
[2010/04/13 00:46:29 | 000,000,805 | ---- | C] () -- C:\Windows\System32\drivers\SYMEVENT.INF
[2010/04/13 00:46:24 | 000,002,327 | ---- | C] () -- C:\Users\Public\Desktop\Norton 360.lnk
[2010/04/10 19:00:16 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Vegas Movie Studio Platinum 9.0.lnk
[2010/04/10 18:32:25 | 000,000,991 | ---- | C] () -- C:\Users\Public\Desktop\MAGIX PhotoStory on CD & DVD 9 Download Version.lnk
[2010/04/08 17:37:40 | 000,002,267 | ---- | C] () -- C:\Users\Duncan\Desktop\Google Chrome.lnk
[2010/04/08 17:36:31 | 000,000,910 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-439322092-450900370-4199317660-1000UA.job
[2010/04/08 17:36:24 | 000,000,858 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-439322092-450900370-4199317660-1000Core.job
[2010/04/08 04:12:51 | 000,002,181 | ---- | C] () -- C:\Windows\Helicon Debug Window.ini
[2010/04/08 04:12:32 | 000,001,126 | ---- | C] () -- C:\Users\Duncan\Desktop\Helicon Filter.lnk
[2010/04/07 21:34:55 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2010/04/07 21:34:55 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2010/04/07 21:34:55 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2010/04/07 21:34:55 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2010/04/07 21:34:55 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2010/04/07 21:34:55 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2010/04/07 21:34:55 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2010/04/07 21:34:55 | 000,013,732 | ---- | C] () -- C:\Windows\System32\EPPICLocal_EN.cfg
[2010/04/07 21:34:55 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2010/04/07 21:34:55 | 000,006,442 | ---- | C] () -- C:\Windows\System32\EPPICLocal_IT.cfg
[2010/04/07 21:34:55 | 000,006,347 | ---- | C] () -- C:\Windows\System32\EPPICLocal_PT.cfg
[2010/04/07 21:34:55 | 000,006,347 | ---- | C] () -- C:\Windows\System32\EPPICLocal_BP.cfg
[2010/04/07 21:34:55 | 000,006,335 | ---- | C] () -- C:\Windows\System32\EPPICLocal_GE.cfg
[2010/04/07 21:34:55 | 000,006,195 | ---- | C] () -- C:\Windows\System32\EPPICLocal_FR.cfg
[2010/04/07 21:34:55 | 000,006,195 | ---- | C] () -- C:\Windows\System32\EPPICLocal_CF.cfg
[2010/04/07 21:34:55 | 000,006,122 | ---- | C] () -- C:\Windows\System32\EPPICLocal_DU.cfg
[2010/04/07 21:34:55 | 000,006,103 | ---- | C] () -- C:\Windows\System32\EPPICLocal_ES.cfg
[2010/04/07 21:34:55 | 000,005,817 | ---- | C] () -- C:\Windows\System32\EPPICLocal_KO.cfg
[2010/04/07 21:34:55 | 000,005,436 | ---- | C] () -- C:\Windows\System32\EPPICLocal_SC.cfg
[2010/04/07 21:34:55 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2010/04/07 21:34:55 | 000,002,889 | ---- | C] () -- C:\Windows\System32\EPPICLocal_RU.cfg
[2010/04/07 21:34:55 | 000,002,426 | ---- | C] () -- C:\Windows\System32\EPPICLocal_TC.cfg
[2010/04/07 21:34:55 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2010/04/07 21:34:55 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2010/04/07 21:34:55 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2010/04/07 21:34:55 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2010/04/07 21:34:55 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2010/04/07 21:34:55 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2010/04/07 21:34:55 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2010/04/07 21:34:55 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2010/04/07 21:34:55 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2010/04/07 21:34:55 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2010/04/07 21:32:48 | 000,001,955 | ---- | C] () -- C:\Users\Public\Desktop\PHOTOfunSTUDIO HD Edition.lnk
[2010/04/07 18:45:59 | 000,002,175 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010/04/06 19:18:16 | 000,001,540 | ---- | C] () -- C:\Users\Duncan\Desktop\SDMain - Shortcut.lnk
[2010/04/06 19:17:17 | 000,000,600 | ---- | C] () -- C:\Users\Duncan\AppData\Local\PUTTY.RND
[2010/04/06 02:27:32 | 000,000,954 | ---- | C] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2010/04/05 21:13:42 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/04/05 12:13:19 | 000,001,105 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/04/05 01:30:31 | 000,000,996 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/04/04 20:54:50 | 000,000,984 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/03 18:17:21 | 000,001,251 | ---- | C] () -- C:\Users\Duncan\Desktop\Spybot - Search & Destroy.lnk
[2010/03/23 01:29:41 | 000,000,217 | ---- | C] () -- C:\Users\Duncan\Desktop\Realtek HD Audio Manager - Shortcut.lnk
[2010/03/23 01:03:06 | 000,001,298 | ---- | C] () -- C:\Users\Duncan\Desktop\plink - Shortcut (2).lnk
[2010/03/17 23:30:50 | 000,050,176 | ---- | C] () -- C:\Users\Duncan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/16 15:32:39 | 000,000,346 | ---- | C] () -- C:\Users\Duncan\Desktop\Hardware and Sound - Shortcut.lnk
[2010/03/15 23:02:36 | 000,000,505 | ---- | C] () -- C:\Users\Duncan\Desktop\Devices and Printers - Shortcut.lnk
[2010/03/14 00:55:17 | 000,001,024 | ---- | C] () -- C:\.rnd
[2010/03/11 18:30:06 | 000,001,836 | ---- | C] () -- C:\Users\Duncan\Desktop\R.U.S.E. Beta.lnk
[2010/03/11 17:05:54 | 000,001,986 | ---- | C] () -- C:\Users\Duncan\Desktop\Fan noise - Shortcut.lnk
[2010/03/09 22:09:56 | 000,001,006 | ---- | C] () -- C:\Users\Duncan\Desktop\GmoteServer.lnk
[2010/03/09 18:23:19 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/03/09 17:35:13 | 000,115,081 | ---- | C] () -- C:\Windows\System32\drivers\androidusb.INF
[2010/03/09 15:57:38 | 000,000,127 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/03/09 02:25:58 | 000,000,020 | -HS- | C] () -- C:\Users\Duncan\ntuser.ini
[2010/03/09 02:12:27 | 1506,799,616 | -HS- | C] () -- C:\hiberfil.sys
[2010/03/09 01:57:56 | 000,021,924 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2010/03/09 01:13:16 | 000,524,288 | -HS- | C] () -- C:\Users\Duncan\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/03/09 01:13:16 | 000,524,288 | -HS- | C] () -- C:\Users\Duncan\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/03/09 01:13:16 | 000,262,144 | -HS- | C] () -- C:\Users\Duncan\ntuser.dat.LOG1
[2010/03/09 01:13:16 | 000,065,536 | -HS- | C] () -- C:\Users\Duncan\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/03/09 01:13:16 | 000,000,000 | -HS- | C] () -- C:\Users\Duncan\ntuser.dat.LOG2
[2010/03/09 01:13:15 | 009,699,328 | -HS- | C] () -- C:\Users\Duncan\NTUSER.DAT
[2010/03/09 01:12:43 | 000,010,896 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/09 01:12:43 | 000,010,896 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/09 01:12:26 | 000,000,426 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2010/03/09 01:12:26 | 000,000,034 | ---- | C] () -- C:\Windows\System32\BD7010.DAT
[2010/03/09 01:11:57 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2010/03/08 23:28:26 | 000,001,890 | ---- | C] () -- C:\Windows\diagwrn.xml
[2010/03/08 23:28:26 | 000,001,890 | ---- | C] () -- C:\Windows\diagerr.xml
[2010/03/07 16:56:29 | 000,057,344 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010/03/06 06:23:03 | 000,000,000 | ---- | C] () -- C:\Windows\DbgOut.INI
[2010/03/06 05:37:21 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2010/03/04 00:14:34 | 000,012,986 | ---- | C] () -- C:\Users\Duncan\AppData\Roaming\Comma Separated Values (Windows).CAL
[2010/03/04 00:10:12 | 000,038,450 | ---- | C] () -- C:\Users\Duncan\AppData\Roaming\Comma Separated Values (DOS).ADR
[2010/02/28 21:02:40 | 000,000,648 | ---- | C] () -- C:\Users\Duncan\Desktop\Documents on Vario II.LNK
[2010/02/28 21:02:34 | 000,000,756 | ---- | C] () -- C:\Users\Duncan\Desktop\Windows Mobile Device Center.lnk
[2010/02/24 22:00:50 | 000,065,288 | ---- | C] () -- C:\Windows\System\NBDAYLIT.TTF
[2010/02/24 22:00:50 | 000,063,184 | ---- | C] () -- C:\Windows\System\NBTRC___.TTF
[2010/02/24 22:00:50 | 000,056,332 | ---- | C] () -- C:\Windows\System\NBTRCSBI.TTF
[2010/02/24 22:00:50 | 000,050,032 | ---- | C] () -- C:\Windows\System\NBTRCS__.TTF
[2010/02/24 22:00:50 | 000,048,660 | ---- | C] () -- C:\Windows\System\NBTRCSB_.TTF
[2010/02/24 22:00:49 | 000,074,832 | ---- | C] () -- C:\Windows\System\NBTRCMBI.TTF
[2010/02/24 22:00:49 | 000,074,716 | ---- | C] () -- C:\Windows\System\NBTRCMI_.TTF
[2010/02/24 22:00:49 | 000,071,416 | ---- | C] () -- C:\Windows\System\NBIPABI_.TTF
[2010/02/24 22:00:49 | 000,070,372 | ---- | C] () -- C:\Windows\System\NBTRCI__.TTF
[2010/02/24 22:00:49 | 000,069,748 | ---- | C] () -- C:\Windows\System\NBIPAI__.TTF
[2010/02/24 22:00:49 | 000,068,904 | ---- | C] () -- C:\Windows\System\NBTRCBI_.TTF
[2010/02/24 22:00:49 | 000,067,408 | ---- | C] () -- C:\Windows\System\NBTRCM__.TTF
[2010/02/24 22:00:49 | 000,066,588 | ---- | C] () -- C:\Windows\System\NBTRCMB_.TTF
[2010/02/24 22:00:49 | 000,065,004 | ---- | C] () -- C:\Windows\System\NBTRCB__.TTF
[2010/02/24 22:00:49 | 000,064,360 | ---- | C] () -- C:\Windows\System\NBIPAB__.TTF
[2010/02/24 22:00:49 | 000,063,440 | ---- | C] () -- C:\Windows\System\NBIPA___.TTF
[2010/02/24 22:00:49 | 000,057,924 | ---- | C] () -- C:\Windows\System\NBTRCSI_.TTF
[2010/02/24 22:00:49 | 000,044,380 | ---- | C] () -- C:\Windows\System\NBRAMAH_.TTF
[2010/02/24 22:00:49 | 000,044,368 | ---- | C] () -- C:\Windows\System\NBRAB___.TTF
[2010/02/24 22:00:49 | 000,041,084 | ---- | C] () -- C:\Windows\System\NBMORIAH.TTF
[2010/02/24 22:00:49 | 000,040,840 | ---- | C] () -- C:\Windows\System\NBMOB___.TTF
[2010/02/24 22:00:49 | 000,039,948 | ---- | C] () -- C:\Windows\System\NBACSSBI.TTF
[2010/02/24 22:00:49 | 000,039,416 | ---- | C] () -- C:\Windows\System\NBLAESBI.TTF
[2010/02/24 22:00:49 | 000,039,240 | ---- | C] () -- C:\Windows\System\NBACSSI_.TTF
[2010/02/24 22:00:49 | 000,038,740 | ---- | C] () -- C:\Windows\System\NBLAESI_.TTF
[2010/02/24 22:00:49 | 000,036,276 | ---- | C] () -- C:\Windows\System\NBSYPS__.TTF
[2010/02/24 22:00:49 | 000,036,148 | ---- | C] () -- C:\Windows\System\NBSYLS__.TTF
[2010/02/24 22:00:49 | 000,034,028 | ---- | C] () -- C:\Windows\System\NBLAESB_.TTF
[2010/02/24 22:00:49 | 000,033,336 | ---- | C] () -- C:\Windows\System\NBLAES__.TTF
[2010/02/24 22:00:49 | 000,033,236 | ---- | C] () -- C:\Windows\System\NBACH___.TTF
[2010/02/24 22:00:48 | 000,043,280 | ---- | C] () -- C:\Windows\System\NBACS___.TTF
[2010/02/24 22:00:48 | 000,041,768 | ---- | C] () -- C:\Windows\System\NBACMBI_.TTF
[2010/02/24 22:00:48 | 000,040,800 | ---- | C] () -- C:\Windows\System\NBACSBI_.TTF
[2010/02/24 22:00:48 | 000,040,676 | ---- | C] () -- C:\Windows\System\NBACMI__.TTF
[2010/02/24 22:00:48 | 000,040,392 | ---- | C] () -- C:\Windows\System\NBACMB__.TTF
[2010/02/24 22:00:48 | 000,039,940 | ---- | C] () -- C:\Windows\System\NBACM___.TTF
[2010/02/24 22:00:48 | 000,039,648 | ---- | C] () -- C:\Windows\System\NBACSI__.TTF
[2010/02/24 22:00:48 | 000,039,392 | ---- | C] () -- C:\Windows\System\NBACSB__.TTF
[2010/02/24 22:00:48 | 000,038,960 | ---- | C] () -- C:\Windows\System\NBACSS__.TTF
[2010/02/24 22:00:48 | 000,038,812 | ---- | C] () -- C:\Windows\System\NBACSSB_.TTF
[2010/02/09 02:44:06 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/09 02:43:58 | 000,000,880 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/06 15:47:34 | 001,532,082 | ---- | C] () -- C:\Windows\System32\PenTablet.znc
[2010/01/25 11:58:06 | 000,462,848 | ---- | C] () -- C:\Windows\System32\ractrlkeyhook.dll
[2009/12/24 22:42:55 | 000,045,056 | ---- | C] () -- C:\Windows\System32\jfwapi.dll
[2009/11/14 20:58:11 | 000,000,324 | ---- | C] () -- C:\Windows\game.ini
[2009/10/29 18:18:03 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2009/09/17 12:48:40 | 000,209,920 | ---- | C] () -- C:\Windows\System32\nmNsp.dll
[2009/09/17 12:48:40 | 000,160,256 | ---- | C] () -- C:\Windows\System32\CESpy.dll
[2009/09/05 20:00:34 | 000,000,237 | ---- | C] () -- C:\Windows\SIERRA.INI
[2009/08/14 01:26:29 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/13 03:25:19 | 000,000,188 | ---- | C] () -- C:\Windows\NBSETUP.INI
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/02 20:40:31 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/08/02 18:20:13 | 000,027,019 | ---- | C] () -- C:\Windows\maxlink.ini
[2009/08/02 16:47:18 | 007,533,568 | ---- | C] () -- C:\Windows\System32\bwbits80.dll
[2009/08/02 16:47:18 | 000,181,760 | ---- | C] () -- C:\Windows\System32\patchw32.dll
[2009/08/02 16:47:18 | 000,116,736 | ---- | C] () -- C:\Windows\System32\patchw.dll
[2009/08/02 16:47:18 | 000,058,280 | ---- | C] () -- C:\Windows\System32\bwntsend.dll
[2009/08/02 16:47:18 | 000,058,280 | ---- | C] () -- C:\Windows\System32\bwnthook.dll
[2009/08/02 16:47:18 | 000,055,808 | ---- | C] () -- C:\Windows\System32\zlib1.dll
[2009/08/01 17:25:17 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2009/08/01 17:25:17 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2009/08/01 17:25:17 | 000,010,150 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2009/08/01 17:25:17 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/07/14 00:23:55 | 000,313,856 | ---- | C] () -- C:\Windows\System32\swprv.dll
[2008/10/07 09:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008/08/07 17:37:59 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2008/08/07 17:37:59 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2008/08/07 17:37:59 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2008/08/07 17:37:59 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2008/08/07 17:37:59 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2008/08/07 17:37:59 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2008/08/07 17:29:47 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2008/08/07 16:31:36 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2007/04/27 09:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2002/03/04 10:16:34 | 000,110,592 | R--- | C] () -- C:\Windows\System32\Jpeg32.dll
[1997/06/14 03:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll

========== LOP Check ==========

[2010/05/06 13:21:37 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\CE
[2010/03/09 01:42:17 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Chessmaster Challenge
[2010/03/09 22:10:24 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Gmote
[2010/03/09 01:42:20 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\HandBrake
[2010/03/09 01:42:21 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\ImgBurn
[2010/03/09 01:42:21 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Libronix DLS
[2010/04/10 18:33:09 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\MAGIX
[2010/03/09 01:42:41 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Mikogo
[2009/09/09 20:33:11 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\My Games
[2010/04/04 04:29:43 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\myphotobook
[2010/04/07 21:44:12 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Panasonic
[2010/04/09 03:48:15 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Publish Providers
[2010/04/14 13:36:55 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Sony
[2010/03/09 01:42:46 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\SpinTop
[2010/03/09 01:42:46 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Sync App Settings
[2010/03/09 01:42:46 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\SystemRequirementsLab
[2010/03/09 01:42:46 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Teleca
[2010/03/09 01:42:46 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Template
[2010/03/09 01:42:48 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\The Creative Assembly
[2010/03/09 01:42:48 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\TomTom
[2010/03/09 01:42:48 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Toshiba
[2010/05/05 20:10:20 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\uTorrent
[2009/12/15 20:01:23 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\Wargaming.Net
[2010/03/09 01:42:49 | 000,000,000 | ---D | M] -- C:\Users\Duncan\AppData\Roaming\WinBatch
[2010/05/06 13:21:18 | 000,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2010/05/02 10:04:13 | 000,030,868 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\ERDNT\cache\AGP440.sys
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\ERDNT\cache\atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\ERDNT\cache\cngaudit.dll
[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2009/01/04 17:43:34 | 000,032,768 | ---- | M] (Panasonic Corporation) MD5=F113CB0CD335B41D55AB7803ECAD7739 -- C:\Program Files\Panasonic\PHOTOfunSTUDIO\Core\EventLog.dll

< MD5 for: IASTOR.SYS >
[2008/04/15 17:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008/04/15 17:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008/04/15 17:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\drivers\iaStor.sys
[2008/04/15 17:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_2d2ec4fd9937ddb4\iaStor.sys

< MD5 for: IASTORV.SYS >
[2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\drivers\iaStorV.sys
[2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\ERDNT\cache\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\drivers\nvstor.sys
[2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\ERDNT\cache\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemdrive%\*.sys /90 /md5 >
[2010/05/06 13:19:49 | 1506,799,616 | -HS- | M] () Unable to obtain MD5 -- C:\hiberfil.sys
[2010/05/06 13:19:53 | 2009,067,520 | -HS- | M] () Unable to obtain MD5 -- C:\pagefile.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 400 bytes -> C:\Users\Duncan\AppData\Local\desktop.ini:bf5af20ce7a419b1178ece347eddc338
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8

< End of report >


OTL Extras logfile created on: 07/05/2010 01:57:16 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Duncan\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 29.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.37 Gb Total Space | 15.59 Gb Free Space | 20.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 73.21 Gb Total Space | 5.04 Gb Free Space | 6.89% Space Free | Partition Type: NTFS
Drive F: | 14.96 Gb Total Space | 14.08 Gb Free Space | 94.12% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOSHIBAOFFICEPC
Current User Name: Duncan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.exe [@ = exefile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AAEE65-C463-44B4-BF7E-FE099C2B44B3}" = Bible Explorer 4 Download Edition
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08C0729E-3E50-11DF-9D81-005056806466}" = Google Earth
"{099BD94D-FA42-44A2-A983-D1BC2E4A0EB0}" = Vista Services Optimizer
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 15
"{2B6E2126-4438-4CF1-BDDE-3C4355092860}" = Pradis Do Not Remove
"{2D5FDE7E-E784-4FD2-BFD7-7C97AE9B5983}" = MAGIX Speed 2 (MSI)
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}" = Firebird SQL Server - MAGIX Edition
"{34F93E31-E1A0-421C-8E86-BCF7C4193A91}" = LogMeIn
"{36BB3322-27BB-4750-851A-DD78E5360961}" = Pradis 6: The Expositior's Bible Commentary
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{37C8899D-FD70-481F-94AA-1F1B08765E22}" = Acronis True Image Home
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4360BB46-507E-4361-8DCB-4FF9BDC9907B}" = SnagIt 7
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5AC5ED2E-2936-4B54-A429-703F9034938E}" = Covenant Eyes
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5F4965B3-AAAF-4562-AEA2-F4F66C7A4EE8}" = MAGIX PhotoStory on CD & DVD 9 Download Version
"{5FCE0BF9-A1AA-4FA3-A28C-F62431CD52C4}" = Sony Vegas 6.0
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69D0D282-E7D6-4408-8FA5-CBE2652936C5}" = Logos Biblical Greek Keyboard
"{6C1804BC-094F-431A-BEA5-37A837958029}" = Rome - Total War - Alexander
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73703571-9EFC-45D0-863B-7BF97EE68F4E}" = Pradis
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder
"{7880A897-876A-46EB-BE51-9F9B89878A5C}" = MAGIX Online Print Service
"{7BEA8ACD-49F0-4B38-94C1-CB2A946330B5}" = Logos 4 Prerequisites
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110378170}" = Catan - The Computer Game
"{86B77B5A-B157-6386-37B0-DB2494DEEAFF}" = MozyHome Remote Backup
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = IntelŪ Matrix Storage Manager
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{911A0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Outlook 2002
"{94A428DC-441D-4725-AB03-148A9FCC670C}" = MAGIX Screenshare
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{97E038E1-41AD-4C93-BCDC-6A2394AEE352}" = Vegas Movie Studio Platinum 9.0
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A9DBEBC-C800-4776-A970-D76D6AA405B1}" = PHOTOfunSTUDIO HD Edition
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A471A73B-EA26-4C1D-B735-DEB0CB57F7DF}" = MAGIX 3D Maker (embedded MSI)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{ABFE9B50-BA4B-4FDF-A943-EA025119DBED}" = Age of Empires III - The WarChiefs Trial
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B038A58E-EAF0-44CB-ADCA-3895ECD0812D}" = BibleWorks 8
"{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}" = Atheros Wi-Fi Protected Setup Library
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{B6D0F294-B844-4FAF-9993-FAC10E9E0F94}" = AlacrityPC
"{B7C7A59F-CF70-481E-A94F-7C2563AA5ADD}" = Sony DVD Architect Studio 4.5
"{C0698BDA-0D29-40EE-8570-A31106DF9AB1}" = Medieval II Total War
"{C4C2307A-8D46-49AD-8A74-A21FD5EF6849}" = Pradis Zondervan Bible Study Library: Scholars Edition
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D83BD5E2-5AF4-49F6-B5C1-484A9760E73D}" = Brother MFL-Pro Suite
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E05B1C38-AE31-4146-8D47-E5E71BEB8D9E}" = Immortal Cities
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
"{E7271ABF-69D3-4E9D-AA0A-2DE34C10A93D}" = TOSHIBA Manuals
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F24E832F-44B4-4AC7-AA88-8EF94B9776BC}" = HTC Sync
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FD02B200-3589-4311-8C45-E50B2A546243}" = Logos Bible Software 4
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"AC3Filter" = AC3Filter (remove only)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Age of Empires" = Microsoft Age of Empires
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires Expansion 1.0" = Microsoft Age of Empires Expansion
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"Allway Sync_is1" = Allway Sync version 9.2.21
"AnyDVD" = AnyDVD
"A-Ray Scanner" = A-Ray Scanner 2.0.2.3
"Bible Explorer 4 Download Edition" = Bible Explorer 4 Download Edition
"CCleaner" = CCleaner
"Chessmaster Challenge" = Chessmaster Challenge
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"doubleTwist" = doubleTwist
"ESET Online Scanner" = ESET Online Scanner v3
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"FlashWorks_is1" = FlashWorks
"Fraps" = Fraps (remove only)
"free-downloads.net Toolbar" = free-downloads.net Toolbar
"Game Booster_is1" = Game Booster
"GameSpy Arcade" = GameSpy Arcade
"Google Desktop" = Google Desktop
"Grandmaster Chess_is1" = Grandmaster Chess
"HandBrake" = Handbrake 0.9.4
"HDMI" = Intel® Graphics Media Accelerator Driver
"Helicon Filter_is1" = Helicon Filter 4.93.2 Free
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IGZones_is1" = IGZ Lobby System
"ImgBurn" = ImgBurn
"InstallShield_{36BB3322-27BB-4750-851A-DD78E5360961}" = Pradis 6: The Expositior's Bible Commentary
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{73703571-9EFC-45D0-863B-7BF97EE68F4E}" = Pradis
"InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder
"InstallShield_{C4C2307A-8D46-49AD-8A74-A21FD5EF6849}" = Pradis Zondervan Bible Study Library: Scholars Edition
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{E05B1C38-AE31-4146-8D47-E5E71BEB8D9E}" = Immortal Cities
"InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"iWiiBoard_is1" = Pro V4.0
"MAGIX_MSI_Fotos_auf_CD_DVD_9" = MAGIX PhotoStory on CD & DVD 9 Download Version
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mikogo" = Mikogo
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"myphotobook" = myphotobook 3.6
"N360" = Norton 360
"NewBlue Stabilizer for Windows" = NewBlue Stabilizer for Windows
"NSS" = Norton Security Scan
"pdfFactory" = pdfFactory
"Pen Tablet Driver" = Pen Tablet
"Picasa 3" = Picasa 3
"Quest_is1" = Quest 4.1.1
"Risk II" = Risk II (remove only)
"RolandRDID0057" = EDIROL UA-1EX Driver
"Smoothboard" = Smoothboard
"Steam App 21940" = World in Conflict - Demo
"Steam App 33310" = R.U.S.E. Beta
"Steam App 4760" = Rome: Total War Gold
"Steam App 4770" = Rome: Total War Alexander
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"Targus BT Mouse" = Targus BT Mouse 1.00.01 (Build 1000)
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"VLC media player" = VLC media player 1.0.0
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"uTorrent" = ĩTorrent

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >


#10 London76

London76
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:11:47 PM

Posted 06 May 2010 - 08:31 PM

Hi Tom
Norton 360 has popped up saying it has found Backdoor.Tidserv.l!inf and it says it requires manual removal. It then gives me an option to "get help" or "rescan".
What should I do?

Thanks

#11 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:11:47 PM

Posted 08 May 2010 - 06:24 AM

Where does it found it?
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#12 London76

London76
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:11:47 PM

Posted 08 May 2010 - 07:33 PM

Its in
C:\Windows\sinsxs\x86_microsoft-windows-readyboostdriver_31bf3856ad364e35_6.1.7600.16385_none_147b5caa5650a0d5

The file is called rdyboost.sys




#13 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:11:47 PM

Posted 11 May 2010 - 11:10 AM

Hi,

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    CODE
    :filefind
    rdyboost*

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#14 London76

London76
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:11:47 PM

Posted 12 May 2010 - 11:57 AM

Hi Tom,
Here's the log, thanks so much for your help.

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 17:53 on 12/05/2010 by Duncan (Administrator - Elevation successful)

========== filefind ==========

Searching for "rdyboost*"
C:\Windows\System32\drivers\rdyboost.sys --a--- 173648 bytes [23:22 13/07/2009] [09:39 16/04/2010] 4EA225BF1CF05E158853F30A99CA29A7
C:\Windows\winsxs\x86_microsoft-windows-readyboostdriver_31bf3856ad364e35_6.1.7600.16385_none_147b5caa5650a0d5\rdyboost.sys --a--- 173648 bytes [23:22 13/07/2009] [09:39 16/04/2010] (Unable to calculate MD5)

-=End Of File=-

#15 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:11:47 PM

Posted 13 May 2010 - 09:39 AM

Hi,

Please delete this file manually:

C:\Windows\winsxs\x86_microsoft-windows-readyboostdriver_31bf3856ad364e35_6.1.7600.16385_none_147b5caa5650a0d5\rdyboost.sys

Then go to c:\windows\system32\drivers and rightclick rdyboost.sys, choose copy, and go back to

C:\Windows\winsxs\x86_microsoft-windows-readyboostdriver_31bf3856ad364e35_6.1.7600.16385_none_147b5caa5650a0d5\ and make rightclick/paste.


Please repeat the step with systemlook.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users