Ok thanks - the otl.txt file
OTL logfile created on: 14/06/2011 12:41:02 - Run 1
OTL by OldTimer - Version 3.2.24.0 Folder = C:\Users\Gill\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 0.99 Gb Available Physical Memory | 32.92% Memory free
6.20 Gb Paging File | 3.91 Gb Available in Paging File | 63.13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 43.64 Gb Free Space | 18.74% Space Free | Partition Type: NTFS
Drive E: | 623.74 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: LUKE-PC | User Name: Gill | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Gill\Downloads\OTL.scr (OldTimer Tools)
PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files (x86)\ThreatFire\TFTray.exe (PC Tools)
PRC - C:\Program Files (x86)\ThreatFire\TFService.exe (PC Tools)
PRC - C:\Program Files (x86)\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files (x86)\PC Tools Security\pctsGui.exe (PC Tools)
PRC - C:\Program Files (x86)\PC Tools Security\pctsSvc.exe (PC Tools)
PRC - C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
PRC - C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe ()
PRC - C:\Program Files (x86)\AskBarDis\bar\bin\AskService.exe ()
PRC - C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
PRC - C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files (x86)\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Users\Gill\Downloads\OTL.scr (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files (x86)\PC Tools Security\PCTGMhk.dll (PC Tools)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (mfevtp) -- C:\Windows\SysNative\mfevtps.exe ()
SRV:
64bit: - (LBTServ) -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (gpsvc) -- C:\Windows\SysNative\svchost.exe ()
SRV - (RapportMgmtService) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (ThreatFire) -- C:\Program Files (x86)\ThreatFire\TFService.exe (PC Tools)
SRV - (TunngleService) -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
SRV - (PCToolsSSDMonitorSvc) -- C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (sdCoreService) -- C:\Program Files (x86)\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (Browser Defender Update Service) -- C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (sdAuxService) -- C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (WinHttpAutoProxySvc) -- winhttp.dll (Microsoft Corporation)
SRV - (ASKUpgrade) -- C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe ()
SRV - (ASKService) -- C:\Program Files (x86)\AskBarDis\bar\bin\AskService.exe ()
SRV - (HotspotShieldService) -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe ()
SRV - (HssSrv) -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (KService) -- C:\Program Files (x86)\Kontiki\KService.exe (Kontiki Inc.)
SRV - (Macromedia Licensing Service) -- C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (nTuneService) -- C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (RapportKE64) -- C:\Windows\SysNative\Drivers\RapportKE64.sys ()
DRV:
64bit: - (TfSysMon) -- C:\Windows\SysNative\drivers\TfSysMon.sys ()
DRV:
64bit: - (TfNetMon) -- C:\Windows\SysNative\drivers\TfNetMon.sys ()
DRV:
64bit: - (TfFsMon) -- C:\Windows\SysNative\drivers\TfFsMon.sys ()
DRV:
64bit: - (mfehidk) -- C:\Windows\SysNative\drivers\mfehidk.sys ()
DRV:
64bit: - (mfeapfk) -- C:\Windows\SysNative\drivers\mfeapfk.sys ()
DRV:
64bit: - (pctgntdi) -- C:\Windows\SysNative\drivers\pctgntdi64.sys ()
DRV:
64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys ()
DRV:
64bit: - (pctplsg) -- C:\Windows\SysNative\drivers\pctplsg64.sys ()
DRV:
64bit: - (PCTCore) -- C:\Windows\SysNative\drivers\PCTCore64.sys ()
DRV:
64bit: - (iPodDrv) -- C:\Windows\SysNative\drivers\iPodDrv.sys ()
DRV:
64bit: - (pctEFA) -- C:\Windows\SysNative\drivers\pctEFA64.sys ()
DRV:
64bit: - (pctDS) -- C:\Windows\SysNative\drivers\pctDS64.sys ()
DRV:
64bit: - (tap0901t) TAP-Win32 Adapter V9 (Tunngle) -- C:\Windows\SysNative\DRIVERS\tap0901t.sys ()
DRV:
64bit: - (hamachi) -- C:\Windows\SysNative\DRIVERS\hamachi.sys ()
DRV:
64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\Drivers\GEARAspiWDM.sys ()
DRV:
64bit: - (mcdbus) -- C:\Windows\SysNative\DRIVERS\mcdbus.sys ()
DRV:
64bit: - (RMCAST) RMCAST (Pgm) -- C:\Windows\SysNative\DRIVERS\RMCAST.sys ()
DRV:
64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys ()
DRV:
64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys ()
DRV:
64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys ()
DRV:
64bit: - (usb_rndisx) -- C:\Windows\SysNative\DRIVERS\usb8023x.sys ()
DRV:
64bit: - (LMouKE) -- C:\Windows\SysNative\DRIVERS\LMouKE.Sys ()
DRV:
64bit: - (L8042mou) -- C:\Windows\SysNative\DRIVERS\L8042mou.Sys ()
DRV:
64bit: - (L8042Kbd) -- C:\Windows\SysNative\DRIVERS\L8042Kbd.sys ()
DRV:
64bit: - (ElbyDelay) -- C:\Windows\SysNative\Drivers\ElbyDelay.sys ()
DRV:
64bit: - (RTL85n64) -- C:\Windows\SysNative\DRIVERS\RTL85n64.sys ()
DRV:
64bit: - (Ntfs) -- C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV:
64bit: - (MTsensor) -- C:\Windows\SysNative\DRIVERS\ASACPI.sys ()
DRV - (RapportPG64) -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys (Trusteer Ltd.)
DRV - (RapportEI64) -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys (Trusteer Ltd.)
DRV - (RivaTuner64) -- C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys ()
DRV - (mcdbus) -- C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (ElbyDelay) -- C:\Windows\SysWOW64\drivers\ElbyDelay.sys (Elaborate Bytes AG)
DRV - (Klmc) -- C:\Windows\SysWOW64\drivers\klmc.sys (Kaspersky Lab)
DRV - (Klif) -- C:\Windows\SysWOW64\drivers\klif.sys (Kaspersky Labs)
DRV - (Klin) -- C:\Windows\System32\drivers\klin.sys (Kaspersky Labs)
DRV - (Klick) -- C:\Windows\System32\drivers\klick.sys (Kaspersky Labs)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=antn&s={searchTerms}&f=4
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.sky.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://start.facemoods.com/?a=antn
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Facemoods Search"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://start.facemoods.com/?a=antn"
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5
FF - prefs.js..extensions.enabledItems: {cb84136f-9c44-433a-9048-c5cd9df1dc16}:2.0.6
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4cd576eb&v=6.010.006.004&i=29&tp=ab&iy=&ychte=uk&lng=en-GB&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files (x86)\PC Tools Security\BDT\FireFox\ [2011/02/08 01:23:24 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/04 13:50:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/04 13:50:01 | 000,000,000 | ---D | M]
[2008/06/17 21:58:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gill\AppData\Roaming\mozilla\Extensions
[2011/06/06 16:00:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gill\AppData\Roaming\mozilla\Firefox\Profiles\e7082dhv.default\extensions
[2009/09/03 15:28:00 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Gill\AppData\Roaming\mozilla\Firefox\Profiles\e7082dhv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/06 16:00:49 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\Gill\AppData\Roaming\mozilla\Firefox\Profiles\e7082dhv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/05/04 14:59:38 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Gill\AppData\Roaming\mozilla\Firefox\Profiles\e7082dhv.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/08/15 20:43:44 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Users\Gill\AppData\Roaming\mozilla\Firefox\Profiles\e7082dhv.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2011/02/08 01:30:10 | 000,002,696 | ---- | M] () -- C:\Users\Gill\AppData\Roaming\Mozilla\Firefox\Profiles\e7082dhv.default\searchplugins\search-defender.xml
[2011/05/04 13:50:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) --
() (No name found) -- C:\USERS\GILL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E7082DHV.DEFAULT\EXTENSIONS\{C50CA3C4-5656-43C2-A061-13E717F73FC8}.XPI
[2011/04/14 17:41:09 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 09:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 09:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/02/28 20:53:04 | 000,002,047 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\fcmdSrchantn.xml
[2010/01/01 09:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2008/02/04 22:55:49 | 000,224,358 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1
www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1
www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
www.032439.com
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1
www.1001-search.info
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1
www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
www.10sek.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1
www.123topsearch.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1
www.132.com
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 7874 more lines...
O2:
64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg64.dll (Google Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files (x86)\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4:
64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ISTray] C:\Program Files (x86)\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files (x86)\ThreatFire\TFTray.exe (PC Tools)
O4 - Startup: C:\Users\Gill\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - File not found
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/downl...-495c-b89f-c1c34c691085/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B}
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab (CDownloadCtrl Object)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}
http://www.systemrequirementslab.com/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB}
http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Reg Error: Key error.)
O18:
64bit: - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18:
64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Gill\Documents\hudf_150dpi.jpg
O24 - Desktop BackupWallPaper: C:\Users\Gill\Documents\hudf_150dpi.jpg
O29:
64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [1996/11/07 18:19:30 | 000,450,560 | R--- | M] () - E:\automenu.exe -- [ CDFS ]
O32 - AutoRun File - [1999/10/07 19:11:58 | 000,011,902 | R--- | M] () - E:\autorun.apm -- [ CDFS ]
O32 - AutoRun File - [1999/02/03 03:02:00 | 000,167,936 | R--- | M] (Indigo Rose Corporation) - E:\autorun.exe -- [ CDFS ]
O32 - AutoRun File - [1999/04/15 15:40:06 | 000,000,029 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{549fe2b5-9230-11e0-a913-0011f57695d8}\Shell - "" = AutoRun
O33 - MountPoints2\{549fe2b5-9230-11e0-a913-0011f57695d8}\Shell\AutoRun\command - "" = E:\autorun.exe -- [1999/02/03 03:02:00 | 000,167,936 | R--- | M] (Indigo Rose Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe - (Logitech Inc.)
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe - (Logitech, Inc.)
MsConfig:64bit - StartUpFolder: C:^Users^Gill^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE - (Microsoft Corporation)
MsConfig:64bit - StartUpReg:
Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg:
AppleSyncNotifier - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
MsConfig:64bit - StartUpReg:
ehTray.exe - hkey= - key= - C:\Windows\ehome\ehtray.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg:
iTunesHelper - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig:64bit - StartUpReg:
kdx - hkey= - key= - C:\Program Files (x86)\Kontiki\KHost.exe (Kontiki Inc.)
MsConfig:64bit - StartUpReg:
Kernel and Hardware Abstraction Layer - hkey= - key= - C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
MsConfig:64bit - StartUpReg:
NvCplDaemon - hkey= - key= - C:\Windows\SysNative\rundll32.exe ()
MsConfig:64bit - StartUpReg:
NVIDIA nTune - hkey= - key= - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
MsConfig:64bit - StartUpReg:
NvMediaCenter - hkey= - key= - C:\Windows\SysNative\rundll32.exe ()
MsConfig:64bit - StartUpReg:
NvSvc - hkey= - key= - C:\Windows\SysNative\rundll32.exe ()
MsConfig:64bit - StartUpReg:
QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg:
Sidebar - hkey= - key= - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg:
SunJavaUpdateSched - hkey= - key= - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
MsConfig:64bit - State: "services" - Reg Error: Key error.
MsConfig:64bit - State: "startup" - Reg Error: Key error.
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/06/13 02:19:08 | 000,000,000 | ---D | C] -- C:\Users\Gill\Desktop\RK_Quarantine
[2011/06/12 00:52:46 | 000,000,000 | ---D | C] -- C:\Users\Gill\Desktop\allied disk
[2011/06/11 23:47:05 | 000,000,000 | ---D | C] -- C:\Users\Gill\Desktop\EA Games
[2011/06/09 20:48:27 | 000,000,000 | ---D | C] -- C:\Users\Gill\Desktop\XP_Patch
[2011/06/09 20:46:17 | 000,000,000 | ---D | C] -- C:\Games
[2011/06/09 20:45:46 | 000,000,000 | ---D | C] -- C:\TBRASetup
[2011/06/09 12:28:40 | 000,000,000 | ---D | C] -- C:\Users\Gill\AppData\Roaming\Malwarebytes
[2011/06/09 12:28:27 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/06/09 12:28:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/09 12:28:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/06/09 12:28:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/06/09 05:22:00 | 000,000,000 | ---D | C] -- C:\Users\Gill\Documents\RedAlert1_AlliedDisc
[2011/06/09 02:21:36 | 000,000,000 | ---D | C] -- C:\Users\Gill\AppData\Roaming\WinRAR
[2011/06/09 02:21:36 | 000,000,000 | ---D | C] -- C:\Users\Gill\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/06/09 02:21:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/06/09 02:21:33 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2011/06/09 01:43:30 | 000,000,000 | ---D | C] -- C:\Users\Gill\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicDisc
[2011/06/09 01:43:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicDisc
[2011/06/09 01:27:24 | 000,000,000 | ---D | C] -- C:\Users\Gill\{b82e5b3e-408d-4c0e-b756-9a781c14568b}
[2011/06/09 01:08:38 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011/06/08 18:44:27 | 000,000,000 | ---D | C] -- C:\Users\Gill\{3fc1cb4a-f134-4f86-ae0f-64cdbd1f84a3}
[2011/06/08 18:44:26 | 000,255,552 | ---- | C] (MagicISO, Inc.) -- C:\Windows\SysWow64\drivers\mcdbus.sys
[2011/06/08 18:44:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MagicDisc
[2011/06/08 17:51:42 | 000,000,000 | ---D | C] -- C:\Users\Gill\{b6f5e937-d964-4e58-9668-db7a533453ff}
[2011/06/08 17:51:37 | 000,000,000 | ---D | C] -- C:\Users\Gill\Documents\Tunngle
[2011/06/08 17:51:37 | 000,000,000 | ---D | C] -- C:\Users\Gill\AppData\Roaming\Tunngle
[2011/06/08 17:51:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Tunngle
[2011/06/08 17:51:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
[2011/06/08 17:51:28 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Tunngle
[2011/06/08 17:51:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tunngle
[2011/06/07 17:28:16 | 000,000,000 | ---D | C] -- C:\ad8f3568418353640f9dbfa9e559
[2011/05/28 19:12:27 | 000,000,000 | ---D | C] -- C:\a21489a318c8a4277ba932
[2011/05/23 12:53:44 | 000,000,000 | ---D | C] -- C:\8d6501e2b89a5600342a0b24a2c1
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Users\Gill\Documents\*.tmp files -> C:\Users\Gill\Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/14 12:46:00 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{947F2976-1144-4A50-B1C3-84F7A01DC0E4}.job
[2011/06/14 12:40:17 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/14 12:39:10 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011/06/14 12:33:58 | 000,003,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/14 12:33:58 | 000,003,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/14 12:33:57 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/14 12:33:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/14 12:33:47 | 3219,709,952 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/12 00:19:07 | 000,001,090 | ---- | M] () -- C:\Users\Gill\Desktop\Game - Shortcut.lnk
[2011/06/09 20:46:21 | 000,000,000 | ---- | M] () -- C:\MAIN.MIX
[2011/06/09 18:41:24 | 000,002,025 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011/06/09 12:28:27 | 000,000,948 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/09 01:46:08 | 000,790,054 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/09 01:46:08 | 000,667,982 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/06/09 01:46:08 | 000,133,210 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/06/09 01:43:30 | 000,000,828 | ---- | M] () -- C:\Users\Gill\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
[2011/06/09 01:43:30 | 000,000,792 | ---- | M] () -- C:\Users\Gill\Desktop\MagicDisc.lnk
[2011/06/09 01:39:59 | 000,000,792 | ---- | M] () -- C:\Users\Gill\Application Data\Microsoft\Internet Explorer\Quick Launch\Tunngle beta.lnk
[2011/06/09 01:39:59 | 000,000,768 | ---- | M] () -- C:\Users\Public\Desktop\Tunngle beta.lnk
[2011/06/08 17:54:45 | 000,293,040 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/07 11:36:45 | 000,000,000 | ---- | M] () -- C:\Users\Gill\AppData\Local\{8D906D26-82F1-4618-960A-0B6BBCD6D0D6}
[2011/06/06 21:43:32 | 000,000,316 | ---- | M] () -- C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2011/06/03 23:09:34 | 000,000,000 | ---- | M] () -- C:\Users\Gill\AppData\Local\{854C6583-12DC-4602-92A6-A88B259211DB}
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,025,912 | ---- | M] () -- C:\Windows\SysNative\drivers\mbam.sys
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Users\Gill\Documents\*.tmp files -> C:\Users\Gill\Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/12 00:19:07 | 000,001,090 | ---- | C] () -- C:\Users\Gill\Desktop\Game - Shortcut.lnk
[2011/06/11 22:03:02 | 3219,709,952 | -HS- | C] () -- C:\hiberfil.sys
[2011/06/09 20:46:21 | 000,000,000 | ---- | C] () -- C:\MAIN.MIX
[2011/06/09 20:36:24 | 654,348,288 | ---- | C] () -- C:\Users\Gill\Desktop\CD1_ALLIED_DISC.ISO
[2011/06/09 12:28:27 | 000,000,948 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/09 12:28:23 | 000,025,912 | ---- | C] () -- C:\Windows\SysNative\drivers\mbam.sys
[2011/06/09 01:43:30 | 000,000,828 | ---- | C] () -- C:\Users\Gill\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
[2011/06/09 01:43:30 | 000,000,792 | ---- | C] () -- C:\Users\Gill\Desktop\MagicDisc.lnk
[2011/06/08 18:44:26 | 000,255,552 | ---- | C] () -- C:\Windows\SysNative\drivers\mcdbus.sys
[2011/06/08 17:51:29 | 000,031,232 | ---- | C] () -- C:\Windows\SysNative\drivers\tap0901t.sys
[2011/06/08 17:51:29 | 000,000,792 | ---- | C] () -- C:\Users\Gill\Application Data\Microsoft\Internet Explorer\Quick Launch\Tunngle beta.lnk
[2011/06/08 17:51:29 | 000,000,768 | ---- | C] () -- C:\Users\Public\Desktop\Tunngle beta.lnk
[2011/06/07 11:36:45 | 000,000,000 | ---- | C] () -- C:\Users\Gill\AppData\Local\{8D906D26-82F1-4618-960A-0B6BBCD6D0D6}
[2011/06/03 23:09:34 | 000,000,000 | ---- | C] () -- C:\Users\Gill\AppData\Local\{854C6583-12DC-4602-92A6-A88B259211DB}
[2011/02/08 01:23:23 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2010/11/12 20:37:43 | 000,000,133 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2009/09/15 15:57:26 | 000,001,356 | ---- | C] () -- C:\Users\Gill\AppData\Local\d3d9caps.dat
[2008/07/22 12:49:04 | 000,000,092 | ---- | C] () -- C:\Users\Gill\AppData\Local\fusioncache.dat
[2008/07/22 12:37:29 | 000,735,162 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2008/06/06 16:39:15 | 000,000,976 | ---- | C] () -- C:\Windows\eReg.dat
[2008/05/22 23:22:18 | 003,596,288 | ---- | C] () -- C:\Windows\SysWow64\qt-dx331.dll
[2008/05/22 23:18:54 | 000,012,288 | ---- | C] () -- C:\Windows\SysWow64\DivXWMPExtType.dll
[2008/04/13 12:08:26 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2008/02/24 20:26:17 | 003,049,984 | ---- | C] () -- C:\Windows\SysWow64\libavcodec.dll
[2008/02/24 20:26:17 | 000,404,480 | ---- | C] () -- C:\Windows\SysWow64\libmplayer.dll
[2008/02/24 20:26:17 | 000,200,704 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll
[2008/02/24 20:26:17 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll
[2008/02/02 00:29:16 | 000,052,224 | ---- | C] () -- C:\Users\Gill\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/16 17:10:59 | 000,000,732 | ---- | C] () -- C:\Users\Gill\AppData\Local\d3d9caps64.dat
[2007/12/24 19:49:52 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2007/12/12 18:45:25 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2007/12/12 18:45:17 | 000,100,043 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2007/12/12 18:45:15 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2007/03/12 13:01:30 | 000,273,408 | ---- | C] () -- C:\Windows\NVGfxOgl.dll
[2007/03/10 12:51:48 | 000,282,624 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2007/02/06 01:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2006/11/02 16:37:05 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 13:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006/11/02 13:26:55 | 000,018,271 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2006/11/02 13:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 13:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006/11/02 10:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/02/25 19:09:38 | 000,774,144 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[1996/02/23 22:34:48 | 000,014,629 | ---- | C] () -- C:\Windows\SysWow64\Declw.dll
[1996/02/22 20:09:20 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\Decln.dll
========== LOP Check ==========
[2011/05/13 01:10:14 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\.minecraft
[2008/07/22 12:38:14 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\2K Games
[2011/02/28 21:24:24 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\Azureus
[2009/07/20 20:12:38 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\blinkx
[2011/02/28 20:53:04 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\ChemTable Software
[2008/06/12 11:35:03 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\Command & Conquer 3 Kane's Wrath
[2008/08/19 20:02:11 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2011/02/21 16:40:15 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\Dropbox
[2011/01/17 21:57:40 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\eBookPro6
[2011/01/17 21:57:48 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\GetRightToGo
[2011/06/09 01:57:10 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\GlarySoft
[2011/05/04 13:36:02 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\PCTools
[2009/03/27 18:22:14 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\Red Alert 3
[2008/08/12 14:11:03 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\Red Alert 3 Beta
[2011/02/28 20:40:24 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\Registry Mechanic
[2008/09/06 13:32:59 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\SPORE
[2008/09/05 22:37:25 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\SPORE Creature Creator
[2010/08/03 13:05:22 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\SystemRequirementsLab
[2011/01/20 22:23:10 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\Trusteer
[2011/05/04 14:15:16 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\TuneUpMedia
[2011/06/12 19:34:53 | 000,000,000 | ---D | M] -- C:\Users\Gill\AppData\Roaming\Tunngle
[2011/02/28 20:33:53 | 000,000,264 | ---- | M] () -- C:\Windows\Tasks\RMSchedule.job
[2011/05/03 22:47:40 | 000,032,592 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/06/14 12:46:00 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{947F2976-1144-4A50-B1C3-84F7A01DC0E4}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/01/19 08:45:45 | 000,333,203 | RHS- | M] () -- C:\bootmgr
[2008/01/16 20:58:46 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2008/02/24 20:32:53 | 000,009,833 | ---- | M] () -- C:\Cucu_Video_log.txt
[2011/06/14 12:33:47 | 3219,709,952 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/03 13:07:54 | 000,012,125 | ---- | M] () -- C:\hs_err_pid5460.log
[2008/08/01 17:00:27 | 000,000,102 | ---- | M] () -- C:\LevelParTimes.csv
[2011/06/09 20:46:21 | 000,000,000 | ---- | M] () -- C:\MAIN.MIX
[2006/12/02 00:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2011/06/14 12:33:46 | 3533,447,168 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/12/23 13:43:08 | 000,171,520 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\Windows\SysWOW64\wintrust.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\system32\*.exe /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\* >
[2008/06/07 02:42:39 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU >
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/04/14 17:41:11 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/04/14 17:41:11 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/04/14 17:41:11 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files (x86)\Mozilla Firefox\firefox.exe [2011/04/14 17:41:09 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -preferences [2011/04/14 17:41:09 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode [2011/04/14 17:41:09 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --show-icons [2011/06/06 06:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --hide-icons [2011/06/06 06:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [2011/06/06 06:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [2011/06/06 06:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\SysWOW64\ie4uinit.exe" -hide [2011/02/22 05:43:42 | 000,173,568 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\SysWOW64\ie4uinit.exe" -show [2011/02/22 05:43:42 | 000,173,568 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\SysWOW64\ie4uinit.exe" -reinstall [2011/02/22 05:43:42 | 000,173,568 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -extoff [2011/02/22 07:21:12 | 000,638,232 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files (x86)\Internet Explorer\iexplore.exe [2011/02/22 07:21:12 | 000,638,232 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Safari\Safari.exe" /reinstall [2008/06/17 16:16:14 | 003,463,976 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Safari\Safari.exe" /hideicons [2008/06/17 16:16:14 | 003,463,976 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Safari\Safari.exe" /showicons [2008/06/17 16:16:14 | 003,463,976 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files (x86)\Safari\Safari.exe" [2008/06/17 16:16:14 | 003,463,976 | ---- | M] (Apple Inc.)
< hklm\software\clients\startmenuinternet|command /64 /rs >
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2011/02/22 06:15:33 | 000,070,656 | ---- | M] ()
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2011/02/22 06:15:33 | 000,070,656 | ---- | M] ()
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2011/02/22 06:15:33 | 000,070,656 | ---- | M] ()
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2011/02/22 07:21:12 | 000,638,232 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE [2011/02/22 07:21:12 | 000,638,232 | ---- | M] (Microsoft Corporation)
========== Alternate Data Streams ==========
@Alternate Data Stream - 195 bytes -> C:\ProgramData\TEMP
FC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP
1B5B4F1
< End of report >