1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Malware And Trogen Problems

Discussion in 'Malware Removal Help' started by wendy, Jan 18, 2010.

  1. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    hiya the message reads "The webiste has encournterd a problem and cannot display the page the error number is 0x8024811 " it has said to delete temp files and refesh but still same message. its giving me instructions to follow ok to try these
     
  2. schrauber

    schrauber Guest

    First try:

    Please disable your firewall and try again.
     
  3. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    When searching for available updates on the Update site, you receive the 0x80248011 error. Last updated : 05/24/2005 Print | Close



    Problem description
    This error can occur due to an issue with the Internet cache or corruption in the Data store.


    Applicable operating systems and products


    Windows 2000

    Windows XP

    Windows Server 2003



    Resolutions
    1. Delete the datastore and allow it to rebuild itself. First stop the Automatic Update Service
    Click Start.
    Choose Run.
    In the Run box, type services.msc.
    Click OK.
    Right-click the Automatic Updates Service.
    Click Stop.
    After Stopping the Service please rename the folder c:\Windows\SoftwareDistribution
    Open Windows Explorer
    Navigate to the Windows folder
    Click on the + next to the Windows folder
    Navigate to SoftwareDistribution folder
    Right Click on the SoftwareDistribution folder
    Select rename from the Menu
    Rename the folder to SoftwareDistribution.old and click Enter
    Now restart the Automatic Update Service
    Click Start.
    Choose Run.
    In the Run box, type services.msc.
    Click OK.
    Right-click the Automatic Updates Service.
    Click Start.

    Starting the service will take a moment.

    Retry Windows Update again

    Did this resolve your problem?
     
  4. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    this is what windows asked me to do firewall off
    what do you think
     
  5. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
     
  6. schrauber

    schrauber Guest

    Follow those instructions. Microsoft should know how to fix their own problems ;)
     
  7. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    she thing will try speak tomorrow tired now going to chill with a glass of wine its friday night in uk 10.40 nite nite
     
  8. schrauber

    schrauber Guest

    11.40 pm at my end ;).

    chilling is a good idea, in an hour or two :D
     
  9. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
     
  10. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
     
  11. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    hiya windows update complete what next :rolleyes:
     
  12. schrauber

    schrauber Guest

    Hi,

    please post back with a fresh OTL logfile after installing service pack 3 :)
     
  13. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    OTL logfile created on: 24/01/2010 17:51:48 - Run 8
    OTL by OldTimer - Version 3.1.25.2 Folder = C:\Documents and Settings\Tasha Z\Desktop
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    502.00 Mb Total Physical Memory | 180.00 Mb Available Physical Memory | 36.00% Memory free
    1.00 Gb Paging File | 1.00 Gb Available in Paging File | 76.00% Paging File free
    Paging file location(s): c:\pagefile.sys 756 1512 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 93.15 Gb Total Space | 81.08 Gb Free Space | 87.04% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: TASHA
    Current User Name: Tasha Z
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Minimal

    ========== Processes (SafeList) ==========

    PRC - C:\Documents and Settings\Tasha Z\Desktop\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
    PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)


    ========== Modules (SafeList) ==========

    MOD - C:\Documents and Settings\Tasha Z\Desktop\OTL.exe (OldTimer Tools)


    ========== Win32 Services (SafeList) ==========

    SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
    SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
    SRV - (EvtEng) Intel(R) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
    SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
    SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


    ========== Driver Services (SafeList) ==========

    DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
    DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
    DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
    DRV - (AegisP) AEGIS Protocol (IEEE 802.1x) -- C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
    DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
    DRV - (ialm) -- C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
    DRV - (O2MDRDR) -- C:\WINDOWS\System32\DRIVERS\o2media.sys (O2Micro )
    DRV - (RTL8023xp) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
    DRV - (O2SDRDR) -- C:\WINDOWS\System32\DRIVERS\o2sd.sys (O2Micro )
    DRV - (smserial) -- C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
    DRV - (w39n51) Intel(R) -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
    DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
    DRV - (cercsr6) -- C:\WINDOWS\system32\drivers\cercsr6.sys (Adaptec, Inc.)
    DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)


    ========== Standard Registry (All) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://computerhelpforums.net/topic/14391-malware-and-trogen-problems/page__gopid__52878&
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKCU\..\URLSearchHook: {31c7d459-9cc3-44f2-9dca-fc11795309b4} - C:\Program Files\IObitCom\tbIObi.dll (Conduit Ltd.)
    IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Google"
    FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
    FF - prefs.js..browser.search.selectedEngine: "Google"

    FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/09/23 13:00:04 | 00,000,000 | ---D | M]

    [2007/11/07 21:38:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tasha Z\Application Data\Mozilla\Firefox\Profiles\uykhn9v0.default\extensions
    [2007/11/07 21:38:29 | 00,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Tasha Z\Application Data\Mozilla\Firefox\Profiles\uykhn9v0.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
    [2007/07/26 23:03:34 | 00,717,312 | ---- | M] (DivX,Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll
    [2007/05/10 21:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
    [2010/01/12 12:47:30 | 00,002,221 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\SafeSearch.xml

    O1 HOSTS File: ([2010/01/20 21:35:53 | 00,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (IObitCom Toolbar) - {31C7D459-9CC3-44F2-9DCA-FC11795309B4} - C:\Program Files\IObitCom\tbIObi.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
    O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
    O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
    O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
    O15 - HKCU\..Trusted Domains: 9 domain(s) and sub-domain(s) not assigned to a zone.
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
    O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ipp - No CLSID value found
    O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
    O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
    O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
    O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
    O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
    O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
    O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O24 - Desktop Components:0 (My Current Home Page) - About:Home
    O24 - Desktop Components:1 () - http://www.orange.co.uk/
    O24 - Desktop WallPaper: C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
    O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
    O31 - SafeBoot: AlternateShell - cmd.exe
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/12/18 22:35:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - comfile [open] -- "%1" %*
    O35 - exefile [open] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/01/24 12:18:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
    [2010/01/24 12:16:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
    [2010/01/24 11:58:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
    [2010/01/24 11:58:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
    [2010/01/24 11:58:37 | 00,000,000 | ---D | C] -- C:\Program Files\msn
    [2010/01/24 11:58:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en
    [2010/01/24 11:58:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
    [2010/01/24 11:48:48 | 00,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic
    [2010/01/24 11:42:21 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
    [2010/01/24 01:45:46 | 00,276,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmphoto.dll
    [2010/01/24 01:45:38 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wlanapi.dll
    [2010/01/24 01:45:35 | 00,712,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\windowscodecs.dll
    [2010/01/24 01:45:35 | 00,346,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\windowscodecsext.dll
    [2010/01/24 01:45:33 | 00,025,471 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\watv10nt.sys
    [2010/01/24 01:45:33 | 00,022,271 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\watv06nt.sys
    [2010/01/24 01:45:33 | 00,011,935 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\wadv11nt.sys
    [2010/01/24 01:45:33 | 00,011,871 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\wadv09nt.sys
    [2010/01/24 01:45:33 | 00,011,807 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\wadv07nt.sys
    [2010/01/24 01:45:33 | 00,011,295 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\wadv08nt.sys
    [2010/01/24 01:45:32 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vidcap.ax
    [2010/01/24 01:45:31 | 00,011,325 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\vchnt5.dll
    [2010/01/24 01:45:30 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usb8023x.sys
    [2010/01/24 01:45:27 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsgqec.dll
    [2010/01/24 01:45:18 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdwxp.exe
    [2010/01/24 01:45:15 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spdwnwxp.exe
    [2010/01/24 01:45:14 | 00,005,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\smbali.sys
    [2010/01/24 01:45:13 | 00,404,990 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slntamr.sys
    [2010/01/24 01:45:13 | 00,286,792 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slextspk.dll
    [2010/01/24 01:45:13 | 00,188,508 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slgen.dll
    [2010/01/24 01:45:13 | 00,129,535 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slnt7554.sys
    [2010/01/24 01:45:13 | 00,095,424 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slnthal.sys
    [2010/01/24 01:45:13 | 00,086,016 | ---- | C] (Sipro Lab Telecom Inc.) -- C:\WINDOWS\System32\dllcache\sl_anet.acm
    [2010/01/24 01:45:13 | 00,073,832 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slcoinst.dll
    [2010/01/24 01:45:13 | 00,073,796 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slserv.exe
    [2010/01/24 01:45:13 | 00,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slrundll.exe
    [2010/01/24 01:45:13 | 00,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\slrundll.exe
    [2010/01/24 01:45:13 | 00,013,240 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slwdmsup.sys
    [2010/01/24 01:45:12 | 00,003,901 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\siint5.dll
    [2010/01/24 01:45:09 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\setupn.exe
    [2010/01/24 01:45:04 | 00,397,056 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\s3gnb.dll
    [2010/01/24 01:45:04 | 00,166,912 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\drivers\s3gnbm.sys
    [2010/01/24 01:45:02 | 00,290,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rhttpaa.dll
    [2010/01/24 01:45:02 | 00,030,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rndismpx.sys
    [2010/01/24 01:45:01 | 00,013,776 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\recagent.sys
    [2010/01/24 01:45:00 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasqec.dll
    [2010/01/24 01:44:59 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qutil.dll
    [2010/01/24 01:44:58 | 00,150,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qagent.dll
    [2010/01/24 01:44:58 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qcliprov.dll
    [2010/01/24 01:44:56 | 00,412,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\photometadatahandler.dll
    [2010/01/24 01:44:53 | 00,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\onex.dll
    [2010/01/24 01:44:49 | 04,274,816 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nv4_disp.dll
    [2010/01/24 01:44:49 | 01,897,408 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\nv4_mini.sys
    [2010/01/24 01:44:48 | 00,180,360 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\ntmtlfax.sys
    [2010/01/24 01:44:43 | 00,176,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napstat.exe
    [2010/01/24 01:44:42 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napmontr.dll
    [2010/01/24 01:44:42 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napipsec.dll
    [2010/01/24 01:44:42 | 00,012,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mutohpen.sys
    [2010/01/24 01:44:41 | 01,737,856 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\mtxparhd.dll
    [2010/01/24 01:44:41 | 01,372,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6.dll
    [2010/01/24 01:44:41 | 01,309,184 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\mtlstrm.sys
    [2010/01/24 01:44:41 | 00,452,736 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\drivers\mtxparhm.sys
    [2010/01/24 01:44:41 | 00,126,686 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\mtlmnt5.sys
    [2010/01/24 01:44:41 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml6r.dll
    [2010/01/24 01:44:41 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6r.dll
    [2010/01/24 01:44:39 | 00,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mssha.dll
    [2010/01/24 01:44:39 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msshavmsg.dll
    [2010/01/24 01:44:26 | 00,294,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msaud32.acm
    [2010/01/24 01:44:22 | 00,397,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcex.dll
    [2010/01/24 01:44:22 | 00,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcfxcommon.dll
    [2010/01/24 01:44:22 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcperf.exe
    [2010/01/24 01:44:21 | 00,184,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\microsoft.managementconsole.dll
    [2010/01/24 01:44:19 | 00,086,016 | ---- | C] (Conexant) -- C:\WINDOWS\System32\mdmxsdk.dll
    [2010/01/24 01:44:19 | 00,011,868 | ---- | C] (Conexant) -- C:\WINDOWS\System32\drivers\mdmxsdk.sys
    [2010/01/24 01:44:08 | 00,290,816 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\WINDOWS\System32\dllcache\l3codeca.acm
    [2010/01/24 01:44:08 | 00,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\l2gpstore.dll
    [2010/01/24 01:44:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpash.dll
    [2010/01/24 01:44:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdnepr.dll
    [2010/01/24 01:44:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdiultn.dll
    [2010/01/24 01:44:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbhc.dll
    [2010/01/24 01:43:55 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\smtpapi.dll
    [2010/01/24 01:43:54 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwnh.dll
    [2010/01/24 01:43:50 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irbus.sys
    [2010/01/24 01:43:49 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsdupd.exe
    [2010/01/24 01:43:46 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ieencode.dll
    [2010/01/24 01:43:44 | 01,041,536 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\hsfdpsp2.sys
    [2010/01/24 01:43:44 | 00,685,056 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\hsfcxts2.sys
    [2010/01/24 01:43:44 | 00,220,032 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\hsfbs2s2.sys
    [2010/01/24 01:43:44 | 00,032,285 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\hsfcisp2.dll
    [2010/01/24 01:43:37 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\faxpatch.exe
    [2010/01/24 01:43:35 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapphost.dll
    [2010/01/24 01:43:35 | 00,126,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappcfg.dll
    [2010/01/24 01:43:35 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappgnui.dll
    [2010/01/24 01:43:35 | 00,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapqec.dll
    [2010/01/24 01:43:35 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappprxy.dll
    [2010/01/24 01:43:34 | 00,184,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapp3hst.dll
    [2010/01/24 01:43:34 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapolqec.dll
    [2010/01/24 01:43:32 | 00,650,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3ui.dll
    [2010/01/24 01:43:31 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3cfg.dll
    [2010/01/24 01:43:31 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3msm.dll
    [2010/01/24 01:43:31 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3gpclnt.dll
    [2010/01/24 01:43:31 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3api.dll
    [2010/01/24 01:43:31 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3dlg.dll
    [2010/01/24 01:43:30 | 00,294,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dlimport.exe
    [2010/01/24 01:43:29 | 00,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dhcpqec.dll
    [2010/01/24 01:43:29 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dimsroam.dll
    [2010/01/24 01:43:20 | 00,015,423 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\ch7xxnt5.dll
    [2010/01/24 01:43:19 | 00,036,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthprint.sys
    [2010/01/24 01:43:18 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx4.dll
    [2010/01/24 01:43:17 | 00,516,768 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ativvaxx.dll
    [2010/01/24 01:43:17 | 00,233,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\azroles.dll
    [2010/01/24 01:43:17 | 00,032,768 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativtmxx.dll
    [2010/01/24 01:43:17 | 00,025,471 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\atv04nt5.dll
    [2010/01/24 01:43:17 | 00,023,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativmvxx.ax
    [2010/01/24 01:43:17 | 00,021,183 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\atv01nt5.dll
    [2010/01/24 01:43:17 | 00,017,279 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\atv10nt5.dll
    [2010/01/24 01:43:17 | 00,014,143 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\atv06nt5.dll
    [2010/01/24 01:43:17 | 00,011,359 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\atv02nt5.dll
    [2010/01/24 01:43:17 | 00,009,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativdaxx.ax
    [2010/01/24 01:43:16 | 01,888,992 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ati3duag.dll
    [2010/01/24 01:43:16 | 00,870,784 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ati3d1ag.dll
    [2010/01/24 01:43:16 | 00,104,960 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinrvxx.sys
    [2010/01/24 01:43:16 | 00,073,216 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atintuxx.sys
    [2010/01/24 01:43:16 | 00,063,488 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinxsxx.sys
    [2010/01/24 01:43:16 | 00,057,856 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinbtxx.sys
    [2010/01/24 01:43:16 | 00,052,224 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinraxx.sys
    [2010/01/24 01:43:16 | 00,031,744 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinxbxx.sys
    [2010/01/24 01:43:16 | 00,028,672 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinsnxx.sys
    [2010/01/24 01:43:16 | 00,014,336 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinpdxx.sys
    [2010/01/24 01:43:16 | 00,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinttxx.sys
    [2010/01/24 01:43:16 | 00,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinmdxx.sys
    [2010/01/24 01:43:15 | 00,701,440 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati2mtag.sys
    [2010/01/24 01:43:15 | 00,377,984 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2dvaa.dll
    [2010/01/24 01:43:15 | 00,327,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati2mtaa.sys
    [2010/01/24 01:43:15 | 00,229,376 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2cqag.dll
    [2010/01/24 01:43:15 | 00,201,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2dvag.dll
    [2010/01/24 01:43:15 | 00,063,663 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1rvxx.sys
    [2010/01/24 01:43:15 | 00,056,623 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1btxx.sys
    [2010/01/24 01:43:15 | 00,036,463 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1tuxx.sys
    [2010/01/24 01:43:15 | 00,034,735 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1xsxx.sys
    [2010/01/24 01:43:15 | 00,030,671 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1raxx.sys
    [2010/01/24 01:43:15 | 00,029,455 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1xbxx.sys
    [2010/01/24 01:43:15 | 00,026,367 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1snxx.sys
    [2010/01/24 01:43:15 | 00,021,343 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1ttxx.sys
    [2010/01/24 01:43:15 | 00,012,047 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1pdxx.sys
    [2010/01/24 01:43:15 | 00,011,615 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1mdxx.sys
    [2010/01/24 01:43:09 | 00,004,255 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv01nt5.dll
    [2010/01/24 01:43:09 | 00,003,967 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv02nt5.dll
    [2010/01/24 01:43:09 | 00,003,775 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv11nt5.dll
    [2010/01/24 01:43:09 | 00,003,711 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv09nt5.dll
    [2010/01/24 01:43:09 | 00,003,647 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv07nt5.dll
    [2010/01/24 01:43:09 | 00,003,615 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv05nt5.dll
    [2010/01/24 01:43:09 | 00,003,135 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv08nt5.dll
    [2010/01/24 01:43:08 | 00,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aaclient.dll
    [2010/01/23 23:23:03 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\Tasha Z\IECompatCache
    [2010/01/23 23:22:13 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\Tasha Z\PrivacIE
    [2010/01/23 23:19:33 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\Tasha Z\IETldCache
    [2010/01/23 20:20:17 | 01,985,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
    [2010/01/23 20:20:17 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
    [2010/01/23 20:20:17 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
    [2010/01/23 20:20:16 | 11,070,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
    [2010/01/23 20:20:10 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
    [2010/01/23 20:18:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\WBEM
    [2010/01/23 20:17:27 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
    [2010/01/23 19:57:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\zh-TW
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\zh-HK
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\tr-TR
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\sv-SE
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\pt-BR
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\nl-NL
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\nb-NO
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ko-KR
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\it-IT
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\he-IL
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\fr-FR
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\fi-FI
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\es-ES
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\el-GR
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\de-DE
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\da-DK
    [2010/01/23 19:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ar-SA
    [2010/01/23 19:34:08 | 00,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
    [2010/01/23 19:13:33 | 00,730,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll
    [2010/01/23 19:13:32 | 02,189,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
    [2010/01/23 19:13:32 | 02,145,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
    [2010/01/23 19:13:30 | 02,023,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
    [2010/01/23 18:28:59 | 00,471,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclayers.dll
    [2010/01/23 18:23:52 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\t2embed.dll
    [2010/01/23 18:23:52 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fontsub.dll
    [2010/01/23 17:54:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
    [2010/01/23 17:44:25 | 00,455,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
    [2010/01/23 17:44:06 | 00,333,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srv.sys
    [2010/01/23 17:42:45 | 00,691,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcomm.dll
    [2010/01/23 17:39:36 | 00,337,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\netapi32.dll
    [2010/01/21 20:12:09 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
    [2010/01/21 19:11:14 | 00,000,000 | -HSD | C] -- C:\RECYCLER
    [2010/01/21 19:10:36 | 00,000,000 | ---D | C] -- C:\_OTL
    [2010/01/21 10:21:08 | 00,016,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
    [2010/01/21 10:21:07 | 00,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
    [2010/01/20 22:06:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Application Data\Malwarebytes
    [2010/01/20 22:06:04 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/20 22:06:02 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/01/20 22:06:02 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/01/20 22:06:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/01/20 21:39:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
    [2010/01/20 20:32:12 | 00,000,000 | RHSD | C] -- C:\cmdcons
    [2010/01/20 20:29:50 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/01/20 20:29:50 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/01/20 20:29:50 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/01/20 20:29:50 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/01/20 20:29:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/01/20 20:29:27 | 00,000,000 | ---D | C] -- C:\Qoobox
    [2010/01/20 12:26:19 | 00,547,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    [2010/01/17 10:24:24 | 00,054,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fssfltr_tdi.sys
    [2010/01/16 23:33:09 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
    [2010/01/16 23:07:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\My Documents\Downloads
    [2010/01/16 23:01:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Temp
    [2010/01/16 22:27:00 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Tasha Z\My Documents\Copy of My Music
    [2010/01/16 22:25:44 | 00,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Program Files\IObitCom
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\IObitCom
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Program Files\Conduit
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Conduit
    [2010/01/16 18:25:50 | 00,000,000 | ---D | C] -- C:\Program Files\IObit
    [2010/01/16 18:25:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Application Data\IObit
    [2010/01/16 18:24:32 | 09,537,816 | ---- | C] (IObit ) -- C:\Documents and Settings\Tasha Z\My Documents\asc-setup.exe
    [2010/01/16 16:45:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Logfiles
    [2010/01/16 16:45:05 | 00,000,000 | ---D | C] -- C:\Inetpub
    [2010/01/15 18:47:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Identities
    [2010/01/14 21:53:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
    [2010/01/14 21:22:20 | 00,055,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
    [2010/01/14 12:05:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\ICS
    [2010/01/13 22:57:09 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
    [2010/01/13 22:01:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
    [2010/01/13 22:01:21 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
    [2010/01/13 20:28:35 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
    [2010/01/13 20:28:33 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
    [2010/01/13 20:27:36 | 00,000,000 | ---D | C] -- C:\Config.Msi
    [2010/01/13 19:17:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Tracing
    [2010/01/13 19:15:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\microsoft
    [2010/01/13 19:15:12 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live
    [2010/01/13 15:23:54 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
    [2010/01/13 10:21:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Desktop\mike
    [2010/01/12 13:40:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Desktop\sue doc
    [2010/01/12 11:23:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Symantec
    [2010/01/12 10:38:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
    [2010/01/12 10:35:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
    [2010/01/12 10:22:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
    [2007/07/27 13:55:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Help
    [2007/07/27 13:55:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
    [2007/05/30 11:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
    [2006/12/18 22:34:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
    [2006/12/18 22:34:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2010/01/24 17:48:16 | 00,002,444 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/01/24 17:48:14 | 00,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
    [2010/01/24 17:48:06 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/01/24 17:48:03 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/01/24 12:24:27 | 00,000,112 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/01/24 12:19:10 | 04,194,304 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\NTUSER.DAT
    [2010/01/24 12:19:10 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\Tasha Z\ntuser.ini
    [2010/01/24 12:19:03 | 05,352,044 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\IconCache.db
    [2010/01/24 12:18:29 | 00,360,124 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2010/01/24 12:18:29 | 00,315,408 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/01/24 12:18:29 | 00,041,586 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/01/24 12:18:15 | 00,044,608 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    [2010/01/24 12:16:54 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
    [2010/01/24 12:15:32 | 00,196,960 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/01/24 12:13:20 | 00,002,675 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/01/24 12:06:17 | 00,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    [2010/01/24 11:48:17 | 00,250,048 | RHS- | M] () -- C:\ntldr
    [2010/01/23 12:11:53 | 00,004,826 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\1123195570.htm
    [2010/01/20 22:06:06 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/01/20 21:36:07 | 00,000,000 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/01/20 21:35:53 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/01/20 20:32:18 | 00,000,281 | RHS- | M] () -- C:\boot.ini
    [2010/01/20 20:27:41 | 03,830,599 | R--- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\schrauber.exe
    [2010/01/20 16:35:46 | 00,293,376 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\u0n696ig.exe
    [2010/01/20 12:26:26 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    [2010/01/16 23:06:00 | 00,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    [2010/01/16 22:17:15 | 00,005,569 | ---- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\My Favorite Theme.theme
    [2010/01/16 18:56:28 | 00,502,752 | ---- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\cfremover.exe
    [2010/01/16 18:25:56 | 00,000,874 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/01/16 18:25:19 | 09,537,816 | ---- | M] (IObit ) -- C:\Documents and Settings\Tasha Z\My Documents\asc-setup.exe
    [2010/01/15 18:31:51 | 52,659,8144 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
    [2010/01/14 23:20:16 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\~$ssage to Natasha Skye Zeraschi.doc
    [2010/01/14 21:57:52 | 00,000,779 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\Launch Internet Explorer Browser.lnk
    [2010/01/14 18:31:15 | 61,551,4112 | -HS- | M] () -- C:\NRTPage.sys
    [2010/01/14 18:03:27 | 00,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/01/13 20:13:16 | 00,001,743 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2010/01/13 10:24:35 | 25,753,6806 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\photos 1.zip
    [2010/01/12 12:48:44 | 00,002,473 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Global.sw2
    [2010/01/12 10:21:17 | 00,000,453 | ---- | M] () -- C:\WINDOWS\ODBC.INI
    [2010/01/07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2010/01/24 01:45:46 | 00,613,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.chm
    [2010/01/24 01:45:46 | 00,067,374 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.adm
    [2010/01/24 01:45:46 | 00,023,195 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplay.chm
    [2010/01/24 01:45:46 | 00,010,457 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.hta
    [2010/01/24 01:45:46 | 00,001,771 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.css
    [2010/01/24 01:45:46 | 00,000,855 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpocm.inf
    [2010/01/24 01:45:46 | 00,000,420 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmploc.js
    [2010/01/24 01:45:45 | 00,354,468 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud1.wav
    [2010/01/24 01:45:45 | 00,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud7.wav
    [2010/01/24 01:45:45 | 00,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud6.wav
    [2010/01/24 01:45:45 | 00,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud9.wav
    [2010/01/24 01:45:45 | 00,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud8.wav
    [2010/01/24 01:45:45 | 00,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud3.wav
    [2010/01/24 01:45:45 | 00,086,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud5.wav
    [2010/01/24 01:45:45 | 00,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud4.wav
    [2010/01/24 01:45:45 | 00,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud2.wav
    [2010/01/24 01:45:45 | 00,029,070 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmp.inf
    [2010/01/24 01:45:39 | 00,017,272 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmdm.inf
    [2010/01/24 01:45:39 | 00,008,677 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm7.gif
    [2010/01/24 01:45:39 | 00,007,892 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm9.gif
    [2010/01/24 01:45:39 | 00,006,769 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmfsdk.inf
    [2010/01/24 01:45:39 | 00,006,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm6.gif
    [2010/01/24 01:45:39 | 00,004,193 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm8.gif
    [2010/01/24 01:45:38 | 00,007,636 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm2.gif
    [2010/01/24 01:45:38 | 00,007,369 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm4.gif
    [2010/01/24 01:45:38 | 00,006,241 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm3.gif
    [2010/01/24 01:45:38 | 00,005,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm1.gif
    [2010/01/24 01:45:38 | 00,002,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm5.gif
    [2010/01/24 01:45:32 | 00,300,969 | ---- | C] () -- C:\WINDOWS\System32\dllcache\viz.wmv
    [2010/01/24 01:45:32 | 00,017,489 | ---- | C] () -- C:\WINDOWS\System32\dllcache\videobg.gif
    [2010/01/24 01:45:32 | 00,005,290 | ---- | C] () -- C:\WINDOWS\System32\dllcache\vidsamp.gif
    [2010/01/24 01:45:26 | 00,023,829 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tourbg.gif
    [2010/01/24 01:45:26 | 00,003,187 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tour.js
    [2010/01/24 01:45:26 | 00,002,469 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplay.gif
    [2010/01/24 01:45:26 | 00,002,450 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpause.gif
    [2010/01/24 01:45:26 | 00,002,375 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplayh.gif
    [2010/01/24 01:45:26 | 00,002,371 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpauseh.gif
    [2010/01/24 01:45:24 | 00,001,398 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taon.gif
    [2010/01/24 01:45:24 | 00,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taonh.gif
    [2010/01/24 01:45:24 | 00,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoff.gif
    [2010/01/24 01:45:24 | 00,001,367 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoffh.gif
    [2010/01/24 01:45:14 | 00,001,148 | ---- | C] () -- C:\WINDOWS\System32\dllcache\snd.htm
    [2010/01/24 01:45:13 | 00,000,908 | ---- | C] () -- C:\WINDOWS\System32\dllcache\skins.inf
    [2010/01/24 01:45:03 | 00,572,557 | ---- | C] () -- C:\WINDOWS\System32\dllcache\rtuner.wmv
    [2010/01/24 01:45:01 | 00,066,725 | ---- | C] () -- C:\WINDOWS\System32\dllcache\revert.wmz
    [2010/01/24 01:44:56 | 00,077,307 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plyr_err.chm
    [2010/01/24 01:44:56 | 00,001,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst6.wpl
    [2010/01/24 01:44:56 | 00,001,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst5.wpl
    [2010/01/24 01:44:56 | 00,001,474 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst3.wpl
    [2010/01/24 01:44:56 | 00,001,451 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst12.wpl
    [2010/01/24 01:44:56 | 00,001,448 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst4.wpl
    [2010/01/24 01:44:56 | 00,001,250 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst1.wpl
    [2010/01/24 01:44:56 | 00,001,049 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst2.wpl
    [2010/01/24 01:44:56 | 00,001,046 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst7.wpl
    [2010/01/24 01:44:56 | 00,001,036 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst8.wpl
    [2010/01/24 01:44:56 | 00,000,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst11.wpl
    [2010/01/24 01:44:56 | 00,000,787 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst10.wpl
    [2010/01/24 01:44:56 | 00,000,784 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst9.wpl
    [2010/01/24 01:44:56 | 00,000,783 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst13.wpl
    [2010/01/24 01:44:56 | 00,000,775 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst14.wpl
    [2010/01/24 01:44:56 | 00,000,733 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst15.wpl
    [2010/01/24 01:44:49 | 00,375,519 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nuskin.wmv
    [2010/01/24 01:44:45 | 00,022,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npds.zip
    [2010/01/24 01:44:45 | 00,000,403 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npdrmv2.zip
    [2010/01/24 01:44:44 | 00,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
    [2010/01/24 01:44:24 | 00,097,117 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.hlp
    [2010/01/24 01:44:24 | 00,018,286 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.inf
    [2010/01/24 01:44:24 | 00,002,778 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogoh.gif
    [2010/01/24 01:44:24 | 00,002,545 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogo.gif
    [2010/01/24 01:44:24 | 00,001,885 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.cnt
    [2010/01/24 01:44:18 | 00,457,607 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mdlib.wmv
    [2010/01/24 01:43:54 | 00,000,974 | ---- | C] () -- C:\WINDOWS\System32\pid.inf
    [2010/01/24 01:43:37 | 00,005,971 | ---- | C] () -- C:\WINDOWS\System32\dllcache\events.js
    [2010/01/24 01:43:27 | 00,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
    [2010/01/24 01:43:25 | 00,381,425 | ---- | C] () -- C:\WINDOWS\System32\dllcache\copycd.wmv
    [2010/01/24 01:43:25 | 00,009,585 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.css
    [2010/01/24 01:43:25 | 00,008,298 | ---- | C] () -- C:\WINDOWS\System32\dllcache\contents.htm
    [2010/01/24 01:43:25 | 00,006,878 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.js
    [2010/01/24 01:43:24 | 00,184,959 | ---- | C] () -- C:\WINDOWS\System32\dllcache\compact.wmz
    [2010/01/24 01:43:23 | 00,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnth.gif
    [2010/01/24 01:43:23 | 00,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnt.gif
    [2010/01/24 01:43:23 | 00,000,772 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cntd.gif
    [2010/01/24 01:43:23 | 00,000,760 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapph.gif
    [2010/01/24 01:43:23 | 00,000,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapp.gif
    [2010/01/24 01:43:18 | 00,000,999 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bktrh.gif
    [2010/01/24 01:43:17 | 00,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
    [2010/01/23 19:34:55 | 00,000,236 | ---- | C] () -- C:\WINDOWS\tasks\OGALogon.job
    [2010/01/23 12:11:53 | 00,004,826 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\1123195570.htm
    [2010/01/20 22:06:06 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/01/20 20:32:18 | 00,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/01/20 20:32:14 | 00,260,272 | ---- | C] () -- C:\cmldr
    [2010/01/20 20:29:50 | 00,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/01/20 20:29:50 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/01/20 20:29:50 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/01/20 20:29:50 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/01/20 20:29:50 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/01/20 20:27:41 | 03,830,599 | R--- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\schrauber.exe
    [2010/01/20 16:35:45 | 00,293,376 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\u0n696ig.exe
    [2010/01/19 21:26:21 | 00,002,675 | ---- | C] () -- C:\WINDOWS\imsins.BAK
    [2010/01/16 23:01:25 | 00,000,986 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    [2010/01/16 23:01:24 | 00,000,934 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    [2010/01/16 18:56:04 | 00,502,752 | ---- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\cfremover.exe
    [2010/01/16 18:25:56 | 00,000,874 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/01/14 23:20:16 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\~$ssage to Natasha Skye Zeraschi.doc
    [2010/01/14 18:31:15 | 61,551,4112 | -HS- | C] () -- C:\NRTPage.sys
    [2010/01/13 20:13:16 | 00,001,743 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2010/01/13 10:23:37 | 25,753,6806 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\photos 1.zip
    [2010/01/12 12:21:18 | 00,005,569 | ---- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\My Favorite Theme.theme
    [2009/08/03 15:07:42 | 00,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
    [2009/03/21 20:06:40 | 00,002,880 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Application Data\NMM-MetaData.db
    [2007/12/25 23:22:03 | 00,009,216 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/09/18 10:52:59 | 00,326,589 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Application Data\update.log
    [2007/03/29 23:00:40 | 00,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
    [2006/12/19 20:28:00 | 00,000,453 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56spn.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56itl.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56eng.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56brz.dll
    [2006/12/19 20:14:37 | 00,061,440 | R--- | C] () -- C:\WINDOWS\sm56ger.dll
    [2006/12/19 20:14:37 | 00,061,440 | R--- | C] () -- C:\WINDOWS\sm56fra.dll
    [2006/12/19 20:14:37 | 00,053,248 | R--- | C] () -- C:\WINDOWS\sm56jpn.dll
    [2006/12/19 20:14:37 | 00,049,152 | R--- | C] () -- C:\WINDOWS\sm56cht.dll
    [2006/12/19 20:14:37 | 00,049,152 | R--- | C] () -- C:\WINDOWS\sm56chs.dll
    [2005/01/21 04:02:28 | 00,013,312 | ---- | C] () -- C:\WINDOWS\System32\RMDevice.dll
    [2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
    [2001/09/24 06:59:00 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
    < End of report >
     
  14. schrauber

    schrauber Guest

    Hi,


    Delete ComboFix and Clean Up
    Click Start > Run > type combofix /Uninstall > OK (Note the space between combofix and /Uninstall)
    Please advise if this step is missed for any reason as it performs some important actions.



    Please run OTL one more time and hit Cleanup. This will remove OTL and all helper tools.




    Your machine appears to be clean, please take the time to read below on how to secure the machine and take the necessary steps to keep it Clean :)



    Below I have outlined a series of categories that outline how you can increase the security of your computer so that you will not be infected again in the future.


    Practice Safe Internet

    One of the main reasons people get infected in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to properly use the Internet through the use of security tools and good practice. Knowing how you can get infected and what types of files and sites to avoid will be the most crucial step in keeping your computer malware free. The reality is that the majority of people who are infected with malware are ones who click on things they shouldn't be clicking on. Whether these things are files or sites it doesn't really matter. If something is out to get you, and you click on it, it most likely will. Below are a list of simple precautions to take to keep your computer clean and running securely:
    1. If you receive an attachment from someone you do not know, DO NOT OPEN IT! Simple as that. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.

    2. If you receive an attachment and it ends with a .exe, .com, .bat, or .pif do not open the attachment unless you know for a fact that it is clean. For the casual computer user, you will almost never receive a valid attachment of this type.

    3. If you receive an attachment from someone you know, and it looks suspicious, then it probably is. The email could be from someone you know infected with a malware that is trying to infect everyone in their address book.

    4. If you are browsing the Internet and a popup appears saying that you are infected, ignore it!. These are, as far as I am concerned, scams that are being used to scare you into purchasing a piece of software.

      There are also programs that disguise themselves as Anti-Spyware or security products but are instead scams. For a list of these types of programs we recommend you visit this link: Rogue/Suspect Anti-Spyware Products & Web Sites

    5. Another tactic to fool you on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you. We suggest that you close these windows by clicking on the X instead of the OK button. Alternatively, you can check to see if it's a real alert by right-clicking on the window. If there is a menu that comes up saying Add to Favorites... you know it's a fake.

    6. Do not go to adult sites. I know this may bother some of you, but the fact is that a large amount of malware is pushed through these types of sites. I am not saying all adult sites do this, but a lot do.

    7. When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person's contact list that contains a link to an infection. Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.

    8. Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections.

    9. Be careful of what you download off of web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.

    10. DO NOT INSTALL any software without first reading the End User License Agreement, otherwise known as the EULA. A tactic that some developers use is to offer their software for free, but have spyware and other programs you do not want bundled with it. This is where they make their money. By reading the agreement there is a good chance you can spot this and not install the software.
    Visit Microsoft's Windows Update Site Frequently

    It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


    Make Internet Explorer 7 more secure
    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    5. Next press the Apply button and then the OK to exit the Internet Properties page.
     
  15. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    :D Thats all done, for spyware protection etc i have norton which i could put on this laptop but can you recommend any free virus software i have at the moment Advanced systme care do i leave this on or use another,also i think this computer is showing all hidden files how do i change this.
    Thank you very much for your help
     
  16. schrauber

    schrauber Guest

    When you uninstall Combofix like I wrote in the instructions above you should not see the hidden files anymore.


    Two good antivirus programs free for non-commercial home use are Avast! and Antivir
    Note: You should only have one antivirus installed at a time. Having more than one antivirus program installed at once is likely to cause conflicts and may well decrease your overall protection as well as impairing the performance of your PC.
     
  17. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    do i unstall malwarebytes program
     
  18. schrauber

    schrauber Guest

    You can keep Malwarebytes if you want to scan the system once in a while :)
     
  19. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    Cheers bye Take Care :) :D :D :D
     
  20. schrauber

    schrauber Guest

    You're welcome :)
     

Share This Page