Results 1 to 3 of 3

Thread: linkbucks spam, trojan

  1. #1
    Junior Member
    Join Date
    Sep 2010
    Posts
    3

    Default linkbucks spam, trojan

    Hi guys
    I have an infection on my win 7 box that launches three linkbucks.com windows on boot, and briefly runs the CMD window.

    I believe it came from a game crack that a friend ran on my machine.

    My AV program ad-aware detected and seemingly removed a generic Trojan, but the CMD prompt and links on boot remain.


    Here is an OTL dump.

    Any help greatly appreciated!

    Darren


    OTL logfile created on: 28/09/2010 11:50:56 AM - Run 1
    OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\Darren\Desktop
    Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.7930.16406)
    Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

    2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
    4.00 Gb Paging File | 3.00 Gb Available in Paging File | 71.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]
    a
    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Minimal

    ========== Processes (SafeList) ==========

    PRC - C:\Users\Darren\Desktop\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
    PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
    PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    PRC - C:\Program Files\TuneUpMedia\TuneUpApp.exe ()
    PRC - C:\Program Files\iTunes\iTunes.exe (Apple Inc.)
    PRC - C:\Program Files\Macquarie Library\WGMT\WGMT.exe ()
    PRC - C:\Program Files\Macquarie Library\WGMB\WGMB.exe ()
    PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe (Apple Inc.)
    PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
    PRC - C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe (Apple Inc.)
    PRC - C:\Program Files\Telstra\Telstra Connection Manager\Watcher.exe (Sierra Wireless, Inc.)
    PRC - C:\Program Files\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe (Sierra Wireless, Inc.)
    PRC - C:\Program Files\Sierra Wireless Inc\Common\SwiApiMuxX.exe (Sierra Wireless, Inc.)
    PRC - C:\Program Files\Sierra Wireless Inc\Common\SwiCardDetect.exe (Sierra Wireless, Inc.)
    PRC - C:\Users\Darren\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe (Google Inc.)
    PRC - C:\Program Files\Telstra\Telstra Connection Manager\WaHelper.exe (Sierra Wireless Inc.)
    PRC - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
    PRC - C:\Windows\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
    PRC - C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
    PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
    PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)


    ========== Modules (SafeList) ==========

    MOD - C:\Users\Darren\Desktop\OTL.exe (OldTimer Tools)
    MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
    MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
    MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
    MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
    MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
    MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
    MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
    MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
    MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
    MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
    MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
    MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


    ========== Win32 Services (SafeList) ==========

    SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
    SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
    SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
    SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
    SRV - (SwiCardDetectSvc) -- C:\Program Files\Sierra Wireless Inc\Common\SwiCardDetect.exe (Sierra Wireless, Inc.)
    SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
    SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
    SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
    SRV - (vpnagent) -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
    SRV - (PCToolsSSDMonitorSvc) -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
    SRV - (WwanSvc) -- C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
    SRV - (WbioSrvc) -- C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
    SRV - (Power) -- C:\Windows\System32\umpo.dll (Microsoft Corporation)
    SRV - (Themes) -- C:\Windows\System32\themeservice.dll (Microsoft Corporation)
    SRV - (sppuinotify) -- C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
    SRV - (RpcEptMapper) -- C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
    SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
    SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
    SRV - (PNRPsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
    SRV - (p2pimsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
    SRV - (HomeGroupProvider) -- C:\Windows\System32\provsvc.dll (Microsoft Corporation)
    SRV - (PNRPAutoReg) -- C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
    SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
    SRV - (HomeGroupListener) -- C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
    SRV - (Dhcp) -- C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
    SRV - (defragsvc) -- C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
    SRV - (BDESVC) -- C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
    SRV - (AxInstSV) ActiveX Installer (AxInstSV) -- C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
    SRV - (AppIDSvc) -- C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
    SRV - (sppsvc) -- C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
    SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
    SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)


    ========== Driver Services (SafeList) ==========

    DRV - (SWUMX20) Sierra Wireless USB MUX Driver (UMTS20) -- C:\Windows\System32\DRIVERS\swumx20.sys File not found
    DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
    DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
    DRV - (Lbd) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
    DRV - (swiwdmbus) -- C:\Windows\System32\drivers\swiwdmbus.sys (Sierra Wireless Inc.)
    DRV - (SWNC8UA3) Sierra Wireless MUX NDIS Driver (UMTSA3) -- C:\Windows\System32\drivers\swnc8ua3.sys (Sierra Wireless Inc.)
    DRV - (SWUMXA3) Sierra Wireless USB MUX Driver (UMTSA3) -- C:\Windows\System32\drivers\swumxa3.sys (Sierra Wireless Inc.)
    DRV - (vpnva) -- C:\Windows\System32\drivers\vpnva.sys (Cisco Systems, Inc.)
    DRV - (KSecPkg) -- C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
    DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
    DRV - (pbfilter) -- C:\Program Files\PeerBlock\pbfilter.sys ()
    DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
    DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
    DRV - (BthAvrcp) -- C:\Windows\System32\drivers\BthAvrcp.sys (CSR, plc)
    DRV - (ewusbnet) -- C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
    DRV - (hwusbfake) -- C:\Windows\System32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
    DRV - (cmdide) -- C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
    DRV - (adpahci) -- C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
    DRV - (adp94xx) -- C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
    DRV - (amdsbs) -- C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
    DRV - (adpu320) -- C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
    DRV - (arcsas) -- C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
    DRV - (amdsata) -- C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
    DRV - (arc) -- C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
    DRV - (amdxata) -- C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
    DRV - (aliide) -- C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
    DRV - (nvstor) -- C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
    DRV - (nvraid) -- C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
    DRV - (nfrd960) -- C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
    DRV - (LSI_SAS) -- C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
    DRV - (iaStorV) -- C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
    DRV - (MegaSR) -- C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
    DRV - (LSI_SCSI) -- C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
    DRV - (LSI_FC) -- C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
    DRV - (LSI_SAS2) -- C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
    DRV - (iirsp) -- C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
    DRV - (megasas) -- C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
    DRV - (hwpolicy) -- C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
    DRV - (elxstor) -- C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
    DRV - (aic78xx) -- C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
    DRV - (HpSAMD) -- C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
    DRV - (FsDepends) -- C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
    DRV - (vsmraid) -- C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
    DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
    DRV - (vhdmp) -- C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
    DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
    DRV - (vdrvroot) -- C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
    DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
    DRV - (WIMMount) -- C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
    DRV - (viaide) -- C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
    DRV - (ql2300) -- C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
    DRV - (rdyboost) -- C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
    DRV - (ql40xx) -- C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
    DRV - (SiSRaid4) -- C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
    DRV - (pcw) -- C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
    DRV - (SiSRaid2) -- C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
    DRV - (stexstor) -- C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
    DRV - (CNG) -- C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
    DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
    DRV - (rdpbus) -- C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
    DRV - (RDPREFMP) -- C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
    DRV - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
    DRV - (WfpLwf) -- C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
    DRV - (NdisCap) -- C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
    DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
    DRV - (vwififlt) -- C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
    DRV - (vwifibus) -- C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
    DRV - (1394ohci) -- C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
    DRV - (UmPass) -- C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
    DRV - (WINUSB) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
    DRV - (mshidkmdf) -- C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
    DRV - (MTConfig) -- C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
    DRV - (CompositeBus) -- C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
    DRV - (AppID) -- C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
    DRV - (scfilter) -- C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
    DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
    DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
    DRV - (discache) -- C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
    DRV - (HidBatt) -- C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
    DRV - (AcpiPmi) -- C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
    DRV - (AmdPPM) -- C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
    DRV - (hcw85cir) -- C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
    DRV - (BrUsbMdm) -- C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
    DRV - (BrUsbSer) -- C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
    DRV - (BrSerWdm) -- C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
    DRV - (BrFiltLo) -- C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
    DRV - (BrFiltUp) -- C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
    DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
    DRV - (yukonw7) -- C:\Windows\System32\drivers\yk62x86.sys (Marvell)
    DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
    DRV - (ebdrv) -- C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
    DRV - (b06bdrv) -- C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
    DRV - (ISODrive) -- C:\Program Files\UltraISO\drivers\ISODrive.sys (EZB Systems, Inc.)
    DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
    DRV - (FUJ02E3) -- C:\Windows\System32\drivers\fuj02e3.sys (FUJITSU LIMITED)


    ========== Standard Registry (All) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://jogostorrent.net/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 20 08 B6 5E CC 30 CB 01 [binary data]
    IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "www.google.com.au"
    FF - prefs.js..extensions.enabledItems: craig.simms@cnet.com.au:0.30
    FF - prefs.js..extensions.enabledItems: {340c2bbc-ce74-4362-90b5-7c26312808ef}:1.4.4
    FF - prefs.js..extensions.enabledItems: bkmrksync@nokia.com:1.0.0.732
    FF - prefs.js..extensions.enabledItems: en-AU@dictionaries.addons.mozilla.org:2.1.1
    FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.38
    FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.10
    FF - prefs.js..network.proxy.no_proxies_on: "*.local"
    FF - prefs.js..network.proxy.type: 0

    FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/09/25 20:16:51 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/17 14:41:42 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/27 20:39:31 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/09/17 10:58:26 | 000,000,000 | ---D | M]

    [2010/08/01 11:27:26 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\Mozilla\Extensions
    [2010/08/01 03:22:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darren\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
    [2010/08/01 11:27:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darren\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
    [2010/09/28 11:30:28 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7z8d53a5.default\extensions
    [2010/09/15 12:03:41 | 000,000,000 | ---D | M] (Firefox Sync) -- C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7z8d53a5.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}
    [2010/09/28 11:30:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7z8d53a5.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
    [2010/09/15 09:12:10 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7z8d53a5.default\extensions\craig.simms@cnet.com.au
    [2010/09/27 13:54:17 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7z8d53a5.default\extensions\en-AU@dictionaries.addons.mozilla.org
    [2010/09/15 09:09:03 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2010/09/17 14:41:42 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    [2010/09/17 14:41:41 | 000,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
    [2010/09/17 14:41:41 | 000,138,712 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
    [2007/04/10 17:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
    [2010/09/17 14:41:41 | 000,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
    [2010/08/25 09:19:19 | 000,001,394 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
    [2010/08/25 09:19:19 | 000,002,193 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
    [2010/08/25 09:19:19 | 000,001,534 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
    [2010/08/25 09:19:19 | 000,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
    [2010/08/25 09:19:19 | 000,002,371 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
    [2010/08/25 09:19:19 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
    [2010/08/25 09:19:19 | 000,001,096 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml

    O1 HOSTS File: ([2009/06/11 07:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
    O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
    O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
    O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
    O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
    O4 - HKLM..\Run: [AvgScan] C:\Windows\System32\AvgScan.bat ()
    O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)
    O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)
    O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
    O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)
    O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
    O4 - HKLM..\Run: [SSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
    O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
    O4 - HKLM..\Run: [TRUUpdater] C:\Program Files\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe (Sierra Wireless, Inc.)
    O4 - HKLM..\Run: [WatcherHelper] C:\Program files\Telstra\Telstra Connection Manager\WaHelper.exe (Sierra Wireless Inc.)
    O4 - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [Google Update] C:\Users\Darren\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
    O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
    O4 - Startup: C:\Users\Darren\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Macquarie Dictionary WordGenius Activate.LNK = C:\Program Files\Macquarie Library\WGMB\WGMB.exe ()
    O4 - Startup: C:\Users\Darren\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Macquarie Thesaurus WordGenius Activate.LNK = C:\Program Files\Macquarie Library\WGMT\WGMT.exe ()
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
    O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
    O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000038 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000039 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000040 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000041 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000042 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000043 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000044 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000045 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000046 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000047 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000048 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000049 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000050 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000051 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000052 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000053 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000054 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000055 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000056 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000057 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000058 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000059 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000060 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000061 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000062 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000063 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000064 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000065 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000066 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000067 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000068 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000069 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000070 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000071 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
    O13 - gopher Prefix: missing
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/downlo...eckControl.cab (Windows Genuine Advantage Validation Tool)
    O16 - DPF: {5BDBA960-6534-11D3-97C7-00500422B550} https://remote.idg.com.au/download/,...dolcontrol.cab (LotusDRSControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {983A9C21-8207-4B58-BBB8-0EBC3D7C5505} https://remote.idg.com.au/,DanaInfo=...m.au+dwa8W.cab (Domino Web Access 8 Control)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/ge...sh/swflash.cab (Shockwave Flash Object)
    O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://remote.idg.com.au/dana-cache...etupClient.cab (JuniperSetupClientControl Class)
    O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
    O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
    O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
    O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
    O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\System32\credssp.dll (Microsoft Corporation)
    O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (kerberos) - C:\Windows\System32\kerberos.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (schannel) - C:\Windows\System32\schannel.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (wdigest) - C:\Windows\System32\wdigest.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (tspkg) - C:\Windows\System32\tspkg.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
    O31 - SafeBoot: AlternateShell - cmd.exe
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/06/11 07:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O33 - MountPoints2\{2ca35ae5-9dfa-11df-af48-00037aa2562b}\Shell - "" = AutoRun
    O33 - MountPoints2\{2ca35ae5-9dfa-11df-af48-00037aa2562b}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- File not found
    O33 - MountPoints2\{69164829-9cbd-11df-928d-0017426be574}\Shell - "" = AutoRun
    O33 - MountPoints2\{69164829-9cbd-11df-928d-0017426be574}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- File not found
    O33 - MountPoints2\{8c44c830-b103-11df-acd4-00037aa2562b}\Shell - "" = AutoRun
    O33 - MountPoints2\{8c44c830-b103-11df-acd4-00037aa2562b}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe -- File not found
    O33 - MountPoints2\{8c44c8b9-b103-11df-acd4-00037aa2562b}\Shell - "" = AutoRun
    O33 - MountPoints2\{8c44c8b9-b103-11df-acd4-00037aa2562b}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe -- File not found
    O33 - MountPoints2\{ac3c5d24-b423-11df-b76b-0017426be574}\Shell - "" = AutoRun
    O33 - MountPoints2\{ac3c5d24-b423-11df-b76b-0017426be574}\Shell\AutoRun\command - "" = D:\WIN\setup.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\AutoRun\command - "" = F:\aoesetup.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\directx\command - "" = F:\DirectX\dxsetup.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\dplay\command - "" = F:\DirectX\dplay61a.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\dxdiag\command - "" = F:\goodies\ar40eng.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\dxinfo\command - "" = F:\goodies\DirectX\dxinfo.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\dxtest\command - "" = F:\DirectX\dxdiag.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\dxtool\command - "" = F:\goodies\DirectX\dxtool.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\log\command - "" = F:\goodies\machine\machine.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\machine\command - "" = F:\goodies\machine\machine.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\setup\command - "" = F:\aoesetup.exe -- File not found
    O33 - MountPoints2\{adc0d44d-9e1d-11df-bc57-806e6f6e6963}\Shell\zone\command - "" = F:\goodies\mszone\zoneA600.exe -- File not found
    O33 - MountPoints2\D\Shell - "" = AutoRun
    O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe -- File not found
    O33 - MountPoints2\F\Shell - "" = AutoRun
    O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

  2. #2
    Junior Member
    Join Date
    Sep 2010
    Posts
    3

    Default second half

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/09/28 11:47:04 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Darren\Desktop\OTL.exe
    [2010/09/28 11:30:31 | 000,000,000 | ---D | C] -- C:\Users\Darren\AppData\Roaming\QuickScan
    [2010/09/27 18:29:41 | 000,000,000 | ---D | C] -- C:\Users\Darren\AppData\Roaming\IObit
    [2010/09/27 10:08:37 | 000,000,000 | -H-D | C] -- C:\Windows\msdownld.tmp
    [2010/09/27 10:08:32 | 000,000,000 | ---D | C] -- C:\Windows\System32\directx
    [2010/09/27 08:12:36 | 000,000,000 | ---D | C] -- C:\Users\Darren\Documents\Square Enix
    [2010/09/27 07:43:34 | 000,000,000 | ---D | C] -- C:\Program Files\Steam
    [2010/09/27 07:13:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
    [2010/09/26 22:15:03 | 000,000,000 | -H-D | C] -- C:\Users\Darren\Desktop\cheats_files
    [2010/09/26 22:13:45 | 000,000,000 | RH-D | C] -- C:\Users\Darren\Desktop\sims3cheatscodes_files
    [2010/09/25 20:38:24 | 000,000,000 | ---D | C] -- C:\Users\Darren\Documents\Electronic Arts
    [2010/09/25 20:36:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft WSE
    [2010/09/25 20:29:15 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
    [2010/09/25 20:18:13 | 000,000,000 | ---D | C] -- C:\Users\Darren\AppData\Roaming\PC Suite
    [2010/09/25 20:18:12 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Suite
    [2010/09/25 20:18:12 | 000,000,000 | ---D | C] -- C:\Users\Darren\AppData\Roaming\Nokia
    [2010/09/25 20:16:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PCSuite
    [2010/09/25 20:16:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nokia
    [2010/09/25 20:16:46 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
    [2010/09/25 20:16:44 | 000,018,816 | ---- | C] (Nokia) -- C:\Windows\System32\drivers\pccsmcfd.sys
    [2010/09/25 20:16:36 | 000,000,000 | ---D | C] -- C:\Program Files\PC Connectivity Solution
    [2010/09/25 20:16:18 | 000,092,672 | ---- | C] (Nokia) -- C:\Windows\System32\nmwcdcls.dll
    [2010/09/25 20:16:18 | 000,000,000 | ---D | C] -- C:\Program Files\Nokia
    [2010/09/25 20:15:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Installations
    [2010/09/25 16:38:05 | 000,000,000 | ---D | C] -- C:\Program Files\WeFi Software
    [2010/09/25 15:20:21 | 000,000,000 | ---D | C] -- C:\Program Files\ElcomSoft
    [2010/09/25 15:07:44 | 000,000,000 | ---D | C] -- C:\Program Files\RAR Password Recovery Magic
    [2010/09/17 10:00:53 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2010/09/17 10:00:53 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2010/09/17 10:00:53 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2010/09/17 10:00:52 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
    [2010/09/17 10:00:52 | 000,596,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2010/09/17 10:00:52 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2010/09/17 10:00:51 | 002,381,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
    [2010/09/17 10:00:51 | 001,355,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2010/09/17 10:00:51 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
    [2010/09/17 10:00:51 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2010/09/17 10:00:51 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2010/09/17 10:00:51 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2010/09/17 10:00:51 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2010/09/17 10:00:51 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2010/09/17 10:00:51 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2010/09/17 10:00:47 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2010/09/17 10:00:47 | 000,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2010/09/17 10:00:47 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2010/09/17 10:00:47 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2010/09/17 10:00:46 | 003,695,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2010/09/17 10:00:46 | 000,460,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2010/09/17 10:00:46 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2010/09/17 10:00:46 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2010/09/17 10:00:46 | 000,353,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2010/09/17 10:00:46 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2010/09/17 10:00:46 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2010/09/17 10:00:46 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2010/09/17 10:00:46 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2010/09/17 10:00:46 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2010/09/17 10:00:45 | 001,448,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2010/09/17 10:00:45 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2010/09/17 10:00:45 | 000,150,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2010/09/17 10:00:45 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2010/09/17 10:00:45 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2010/09/17 10:00:45 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2010/09/17 10:00:45 | 000,111,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2010/09/17 10:00:45 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2010/09/17 10:00:45 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2010/09/17 10:00:45 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2010/09/17 10:00:13 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
    [2010/09/17 10:00:12 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
    [2010/09/17 10:00:12 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
    [2010/09/17 09:59:41 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
    [2010/09/17 09:59:41 | 001,076,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
    [2010/09/17 09:59:41 | 000,804,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FntCache.dll
    [2010/09/17 09:59:41 | 000,737,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
    [2010/09/17 09:59:41 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
    [2010/09/17 09:59:07 | 000,279,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
    [2010/09/17 09:59:07 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
    [2010/09/17 09:58:36 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
    [2010/09/17 09:57:40 | 000,000,000 | ---D | C] -- C:\Program Files\Feedback Tool
    [2010/09/15 23:14:25 | 000,000,000 | ---D | C] -- C:\Program Files\FileHound
    [2010/09/15 12:24:34 | 000,000,000 | ---D | C] -- C:\Users\Darren\AppData\Local\Cisco
    [2010/09/15 12:24:04 | 000,000,000 | ---D | C] -- C:\Program Files\Cisco
    [2010/09/15 12:24:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Cisco
    [2010/09/15 09:09:41 | 000,000,000 | ---D | C] -- C:\Users\Darren\AppData\Local\Mozilla
    [2010/09/15 09:09:02 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
    [2010/09/11 17:47:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
    [2010/09/11 17:47:08 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
    [2010/09/10 14:19:10 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUpMedia
    [2010/09/09 18:10:55 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2010/09/09 18:09:01 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
    [2010/09/05 21:51:13 | 000,000,000 | ---D | C] -- C:\Users\Darren\AppData\Roaming\vlc
    [2010/09/05 21:50:50 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
    [2010/09/01 13:00:27 | 000,000,000 | ---D | C] -- C:\Users\Darren\AppData\Roaming\TuneUpMedia
    [2010/09/01 12:59:36 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUpMedia
    [2010/09/01 12:47:51 | 000,000,000 | ---D | C] -- C:\ProgramData\eSellerate
    [2010/08/31 07:16:15 | 000,000,000 | ---D | C] -- C:\Users\Darren\AppData\Roaming\BigPond News Ticker
    [2010/08/30 22:08:50 | 000,000,000 | -HSD | C] -- C:\Users\Darren\AppData\Roaming\.#
    [2010/08/30 21:09:01 | 000,000,000 | ---D | C] -- C:\Program Files\Telstra
    [2010/08/30 21:06:38 | 000,000,000 | ---D | C] -- C:\Program Files\Sierra Wireless Inc
    [2010/08/30 21:06:38 | 000,000,000 | ---D | C] -- C:\Users\Darren\AppData\Roaming\Sierra Wireless
    [2010/08/30 21:06:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Sierra Wireless
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2010/09/28 11:51:17 | 001,835,008 | ---- | M] () -- C:\Users\Darren\NTUSER.DAT
    [2010/09/28 11:47:08 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Darren\Desktop\OTL.exe
    [2010/09/28 11:26:55 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
    [2010/09/28 11:25:42 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2010/09/28 11:25:42 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2010/09/28 11:24:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2733600961-1304474306-1629070223-1000UA.job
    [2010/09/28 11:23:05 | 001,498,506 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
    [2010/09/28 11:23:05 | 000,656,288 | ---- | M] () -- C:\Windows\System32\perfh007.dat
    [2010/09/28 11:23:05 | 000,628,460 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2010/09/28 11:23:05 | 000,133,764 | ---- | M] () -- C:\Windows\System32\perfc007.dat
    [2010/09/28 11:23:05 | 000,110,612 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2010/09/28 11:18:34 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
    [2010/09/28 11:18:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2010/09/28 11:18:26 | 1603,080,192 | -HS- | M] () -- C:\hiberfil.sys
    [2010/09/28 11:17:29 | 003,629,495 | -H-- | M] () -- C:\Users\Darren\AppData\Local\IconCache.db
    [2010/09/28 07:00:48 | 000,000,175 | ---- | M] () -- C:\Windows\System32\AvgScan.bat
    [2010/09/28 06:58:42 | 000,001,463 | ---- | M] () -- C:\Users\Darren\Desktop\Just Cause 2 - Shortcut.lnk
    [2010/09/27 12:34:00 | 000,000,858 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2733600961-1304474306-1629070223-1000Core.job
    [2010/09/26 22:15:05 | 000,032,828 | ---- | M] () -- C:\Users\Darren\Desktop\cheats.htm
    [2010/09/26 22:13:49 | 000,054,483 | ---- | M] () -- C:\Users\Darren\Desktop\sims3cheatscodes.html
    [2010/09/25 20:35:48 | 000,002,036 | ---- | M] () -- C:\Users\Public\Desktop\The Sims™ 3.lnk
    [2010/09/25 20:19:22 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
    [2010/09/17 15:01:22 | 000,001,411 | ---- | M] () -- C:\Users\Darren\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2010/09/15 09:09:04 | 000,001,913 | ---- | M] () -- C:\Users\Darren\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
    [2010/09/14 07:35:26 | 000,154,890 | ---- | M] () -- C:\arts-adpp-record-waiver-authority.pdf
    [2010/09/14 07:35:15 | 000,146,072 | ---- | M] () -- C:\admin.pdf
    [2010/09/14 07:34:24 | 000,759,697 | ---- | M] () -- C:\admissions-eligibility-guide.pdf
    [2010/09/11 17:46:59 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
    [2010/09/11 17:46:59 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
    [2010/09/11 17:46:59 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
    [2010/09/11 17:46:59 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
    [2010/09/09 18:12:04 | 000,001,152 | ---- | M] () -- C:\Windows\System32\mapisvc.inf
    [2010/09/01 00:55:48 | 000,460,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2010/09/01 00:46:36 | 001,355,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2010/09/01 00:44:32 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2010/09/01 00:44:30 | 001,448,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2010/09/01 00:44:22 | 000,441,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2010/09/01 00:44:06 | 000,424,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
    [2010/09/01 00:43:24 | 000,166,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2010/09/01 00:43:22 | 000,109,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2010/09/01 00:43:22 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2010/09/01 00:43:18 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2010/09/01 00:43:12 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2010/09/01 00:43:12 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2010/09/01 00:43:10 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2010/09/01 00:43:10 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2010/09/01 00:43:04 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2010/09/01 00:43:00 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2010/09/01 00:42:58 | 000,193,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2010/09/01 00:42:58 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2010/09/01 00:42:58 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2010/09/01 00:42:54 | 000,075,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2010/09/01 00:42:50 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2010/09/01 00:42:50 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2010/09/01 00:42:48 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2010/09/01 00:42:46 | 000,719,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
    [2010/09/01 00:42:42 | 000,150,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2010/09/01 00:42:42 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2010/09/01 00:42:34 | 000,596,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2010/09/01 00:42:28 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2010/09/01 00:42:26 | 000,353,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2010/09/01 00:42:26 | 000,111,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2010/09/01 00:42:20 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2010/09/01 00:42:20 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2010/09/01 00:42:20 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2010/09/01 00:42:18 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2010/09/01 00:42:16 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2010/09/01 00:42:10 | 002,381,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
    [2010/09/01 00:41:46 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2010/09/01 00:41:46 | 000,160,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2010/09/01 00:36:52 | 000,072,533 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
    [2010/08/31 17:49:48 | 000,001,063 | ---- | M] () -- C:\Users\Darren\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Macquarie Dictionary WordGenius Activate.LNK
    [2010/08/30 22:37:04 | 000,524,288 | -HS- | M] () -- C:\Users\Darren\NTUSER.DAT{050df8a4-b2fc-11df-8bd9-0017426be574}.TMContainer00000000000000000002.regtrans-ms
    [2010/08/30 22:37:04 | 000,524,288 | -HS- | M] () -- C:\Users\Darren\NTUSER.DAT{050df8a4-b2fc-11df-8bd9-0017426be574}.TMContainer00000000000000000001.regtrans-ms
    [2010/08/30 22:37:04 | 000,065,536 | -HS- | M] () -- C:\Users\Darren\NTUSER.DAT{050df8a4-b2fc-11df-8bd9-0017426be574}.TM.blf
    [2010/08/30 22:36:58 | 000,000,366 | ---- | M] () -- C:\Windows\WGMT.INI
    [2010/08/30 22:13:41 | 000,001,063 | ---- | M] () -- C:\Users\Darren\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Macquarie Thesaurus WordGenius Activate.LNK
    [2010/08/30 22:12:59 | 000,000,120 | ---- | M] () -- C:\Windows\WGMB.INI
    [2010/08/30 21:10:00 | 000,002,192 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\My Place.lnk
    [2010/08/30 20:52:34 | 000,304,776 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2010/09/28 11:19:18 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
    [2010/09/28 06:58:42 | 000,001,463 | ---- | C] () -- C:\Users\Darren\Desktop\Just Cause 2 - Shortcut.lnk
    [2010/09/27 18:53:08 | 000,000,175 | ---- | C] () -- C:\Windows\System32\AvgScan.bat
    [2010/09/26 22:15:03 | 000,032,828 | ---- | C] () -- C:\Users\Darren\Desktop\cheats.htm
    [2010/09/26 22:13:45 | 000,054,483 | ---- | C] () -- C:\Users\Darren\Desktop\sims3cheatscodes.html
    [2010/09/25 20:35:48 | 000,002,036 | ---- | C] () -- C:\Users\Public\Desktop\The Sims™ 3.lnk
    [2010/09/25 20:19:22 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
    [2010/09/20 17:25:42 | 000,023,552 | -HS- | C] () -- C:\Users\Darren\Thumbs.db
    [2010/09/20 00:11:20 | 000,045,091 | -H-- | C] () -- C:\Users\Darren\Desktop\Folder.JPG
    [2010/09/17 10:00:45 | 000,072,533 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
    [2010/09/15 09:09:04 | 000,001,913 | ---- | C] () -- C:\Users\Darren\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
    [2010/09/14 07:35:26 | 000,154,890 | ---- | C] () -- C:\arts-adpp-record-waiver-authority.pdf
    [2010/09/14 07:35:15 | 000,146,072 | ---- | C] () -- C:\admin.pdf
    [2010/09/14 07:34:24 | 000,759,697 | ---- | C] () -- C:\admissions-eligibility-guide.pdf
    [2010/08/31 17:49:48 | 000,001,063 | ---- | C] () -- C:\Users\Darren\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Macquarie Dictionary WordGenius Activate.LNK
    [2010/08/30 22:13:41 | 000,001,063 | ---- | C] () -- C:\Users\Darren\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Macquarie Thesaurus WordGenius Activate.LNK
    [2010/08/30 21:10:00 | 000,002,192 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\My Place.lnk
    [2010/08/30 20:59:53 | 000,524,288 | -HS- | C] () -- C:\Users\Darren\NTUSER.DAT{050df8a4-b2fc-11df-8bd9-0017426be574}.TMContainer00000000000000000002.regtrans-ms
    [2010/08/30 20:59:53 | 000,524,288 | -HS- | C] () -- C:\Users\Darren\NTUSER.DAT{050df8a4-b2fc-11df-8bd9-0017426be574}.TMContainer00000000000000000001.regtrans-ms
    [2010/08/30 20:59:53 | 000,065,536 | -HS- | C] () -- C:\Users\Darren\NTUSER.DAT{050df8a4-b2fc-11df-8bd9-0017426be574}.TM.blf
    [2010/08/10 12:18:25 | 000,002,215 | ---- | C] () -- C:\Program Files\Age of Empires II - The Conquerers.lnk
    [2010/08/02 19:34:36 | 000,697,328 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
    [2010/08/02 14:18:07 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
    [2010/08/01 04:21:15 | 000,175,104 | ---- | C] () -- C:\Windows\System32\RemoteControl.dll
    [2010/08/01 02:44:30 | 000,000,366 | ---- | C] () -- C:\Windows\WGMT.INI
    [2010/08/01 02:44:08 | 000,000,120 | ---- | C] () -- C:\Windows\WGMB.INI
    [2010/08/01 02:43:19 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
    [2009/07/14 09:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
    [2009/07/14 09:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
    [1913/08/02 00:18:54 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll

    ========== LOP Check ==========

    [2010/09/28 11:20:31 | 000,000,000 | -HSD | M] -- C:\Users\Darren\AppData\Roaming\.#
    [2010/09/23 21:45:21 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\.purple
    [2010/08/31 07:16:17 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\BigPond News Ticker
    [2010/08/02 20:19:32 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\DAEMON Tools Pro
    [2010/08/03 22:57:46 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\gnupg
    [2010/09/17 13:02:46 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\gtk-2.0
    [2010/09/27 18:29:41 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\IObit
    [2010/09/25 20:19:18 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\Nokia
    [2010/08/01 02:55:27 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\OpenOffice.org
    [2010/08/01 06:42:46 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\Pamela
    [2010/09/25 20:19:18 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\PC Suite
    [2010/09/28 11:30:43 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\QuickScan
    [2010/08/01 02:54:37 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\Registry Mechanic
    [2010/08/30 21:10:28 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\Sierra Wireless
    [2010/08/01 03:22:50 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\Thunderbird
    [2010/09/28 11:30:34 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\TuneUpMedia
    [2010/08/02 11:35:19 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
    [2010/09/27 11:43:04 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\uTorrent
    [2010/08/27 01:37:55 | 000,000,000 | ---D | M] -- C:\Users\Darren\AppData\Roaming\Vodafone
    [2010/09/28 11:26:55 | 000,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
    [2010/09/10 13:43:18 | 000,032,542 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:D1B5B4F1
    < End of report >

  3. #3
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,955

    Default

    Hello darrenpauli,

    In case you missed it please see the forum FAQ which includes tips for this forum and also instructions on posting a preliminary DDS log: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)

    Then start a new topic, copy paste the DDS.txt log into it and a volunteer analyst will advise you when available.

    You can also provide a link back to this thread.

    Best regards.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •