Logs
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_2_202_228.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER [2011/12/05 17:16:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2011/12/05 17:16:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2011/12/05 17:34:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/12/07 00:50:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/03/16 12:16:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2011/12/07 21:29:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/12/20 00:46:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/17 20:18:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/01/12 15:59:26 | 000,000,000 | ---D | M]
[2011/12/05 16:41:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\CPDC2007\AppData\Roaming\Mozilla\Extensions
[2012/03/17 20:18:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\CPDC2007\AppData\Roaming\Mozilla\Firefox\Profiles\6yqqso73.default\extensions
[2012/03/08 20:07:16 | 000,000,000 | ---D | M] (ZoneAlarm Security Community Toolbar) -- C:\Users\CPDC2007\AppData\Roaming\Mozilla\Firefox\Profiles\6yqqso73.default\extensions\{91da5e8a-3318-4f8c-b67e-5964de3ab546}
[2012/03/17 20:18:53 | 000,000,000 | ---D | M] (Vuze Remote Community Toolbar) -- C:\Users\CPDC2007\AppData\Roaming\Mozilla\Firefox\Profiles\6yqqso73.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2012/02/29 09:44:25 | 000,000,000 | ---D | M] (easyfundraising toolbar) -- C:\Users\CPDC2007\AppData\Roaming\Mozilla\Firefox\Profiles\6yqqso73.default\extensions\{CB7F6D95-59AF-4D57-8341-14C70BEAA4FB}
[2011/12/12 13:14:09 | 000,000,000 | ---D | M] (Yontoo Layers) -- C:\Users\CPDC2007\AppData\Roaming\Mozilla\Firefox\Profiles\6yqqso73.default\extensions\plugin@yontoo.com
[2011/12/31 19:39:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/12/20 00:46:07 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>

-- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2012/03/17 20:18:14 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/02/12 11:53:48 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/02/12 11:53:48 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/02/12 11:53:48 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/02/12 11:53:48 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/02/12 11:53:48 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
O1 HOSTS File: ([2012/04/06 22:22:35 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20111205163439.dll (McAfee, Inc.)
O2:
64bit: - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner64.dll (Google Inc.)
O2:
64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - No CLSID value found.
O2 - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll (Google Inc.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (ZoneAlarm Security Toolbar) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\prxtbZone.dll (Conduit Ltd.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:
64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Toolbar) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\prxtbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:
64bit: - HKU\S-1-5-21-1554654578-367115620-786508447-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-1554654578-367115620-786508447-1001\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1554654578-367115620-786508447-1001\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-1554654578-367115620-786508447-1001\..\Toolbar\WebBrowser: (ZoneAlarm Security Toolbar) - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - C:\Program Files (x86)\ZoneAlarm_Security\prxtbZone.dll (Conduit Ltd.)
O3:
64bit: - HKU\S-1-5-21-1554654578-367115620-786508447-1001\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKU\S-1-5-21-1554654578-367115620-786508447-1001\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [ISW] File not found
O4:
64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\windows\KHALMNPR.Exe (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [ThpSrv] C:\windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [Toshiba Registration] C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH)
O4:
64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4:
64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (CANON INC.)
O4 - HKLM..\Run: [iolo Startup] C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe (iolo technologies, LLC)
O4 - HKLM..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [NBAgent] C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [Nuance OmniPage 18-reminder] C:\Program Files (x86)\Nuance\OmniPage18\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [OmniPage Preload] C:\Program Files (x86)\Nuance\OmniPage18\OmniPage18.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TRCMan] C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKU\.DEFAULT..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (TOSHIBA)
O4 - HKU\S-1-5-18..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (TOSHIBA)
O4 - HKU\S-1-5-21-1554654578-367115620-786508447-1000..\Run: [] File not found
O4 - HKU\S-1-5-21-1554654578-367115620-786508447-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1554654578-367115620-786508447-1000..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (TOSHIBA)
O4 - HKU\S-1-5-21-1554654578-367115620-786508447-1001..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - HKU\S-1-5-21-1554654578-367115620-786508447-1001..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-1554654578-367115620-786508447-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1554654578-367115620-786508447-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1554654578-367115620-786508447-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1554654578-367115620-786508447-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1554654578-367115620-786508447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1554654578-367115620-786508447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1554654578-367115620-786508447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKU\S-1-5-21-1554654578-367115620-786508447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O8:
64bit: - Extra context menu item: Add to TOSHIBA Bulletin Board - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O8:
64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to TOSHIBA Bulletin Board - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9:
64bit: - Extra Button: @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-229 - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom64.dll (TODO: <会社名>)
O9:
64bit: - Extra 'Tools' menuitem : @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-228 - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom64.dll (TODO: <会社名>)
O9 - Extra Button: @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-229 - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O9 - Extra 'Tools' menuitem : @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-228 - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1E207565-88A3-4271-9D9E-2D0E0C28180C}: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:
64bit: - Protocol\Filter\application/x-mfe-ipt - No CLSID value found
O18 - Protocol\Filter\application/x-mfe-ipt - No CLSID value found
O20:
64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (sdnclean64.exe)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3acm - C:\windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\windows\SysWow64\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/04/06 22:52:09 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\CPDC2007\Desktop\OTL.exe
[2012/04/06 22:22:42 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/04/06 20:06:23 | 004,450,572 | R--- | C] (Swearware) -- C:\Users\CPDC2007\Desktop\ComboFix.exe
[2012/04/06 19:15:03 | 001,932,256 | ---- | C] (Symantec Corporation) -- C:\Users\CPDC2007\Desktop\FixTDSS.exe
[2012/04/06 19:06:37 | 002,073,136 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\CPDC2007\Desktop\TDSSKiller.exe
[2012/04/06 18:48:32 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Users\CPDC2007\Desktop\boot_cleaner.exe
[2012/04/06 18:22:05 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2012/04/06 18:10:59 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\CPDC2007\Desktop\aswMBR.exe
[2012/04/06 17:26:03 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\CPDC2007\Desktop\dds.scr
[2012/04/06 13:41:53 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Local\Adobe
[2012/04/06 13:29:08 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Local\adaware
[2012/04/03 10:52:46 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Roaming\Registry Mechanic
[2012/04/03 10:00:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2012/04/03 09:59:26 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012/04/03 09:59:25 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Roaming\Product_RM
[2012/04/02 23:56:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia
[2012/04/02 23:56:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nokia
[2012/04/02 23:53:35 | 000,025,600 | ---- | C] (Nokia) -- C:\windows\SysNative\drivers\pccsmcfdx64.sys
[2012/04/02 23:53:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Connectivity Solution
[2012/04/02 22:10:04 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\Desktop\Security Tools
[2012/03/31 16:50:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Browsing Protection
[2012/03/31 16:50:19 | 000,060,504 | ---- | C] (Sunbelt Software, Inc.) -- C:\windows\SysNative\drivers\sbhips.sys
[2012/03/31 16:50:08 | 000,094,296 | ---- | C] (Sunbelt Software, Inc.) -- C:\windows\SysNative\drivers\sbtis.sys
[2012/03/31 16:49:42 | 000,084,568 | ---- | C] (Sunbelt Software, Inc.) -- C:\windows\SysNative\drivers\SbFwIm.sys
[2012/03/31 16:49:27 | 000,253,528 | ---- | C] (Sunbelt Software, Inc.) -- C:\windows\SysNative\drivers\SbFw.sys
[2012/03/31 11:38:28 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Roaming\gizza
[2012/03/31 11:38:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Local Settings
[2012/03/31 09:19:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2012/03/31 09:19:06 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/03/30 18:34:18 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2012/03/30 18:34:18 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2012/03/30 18:34:18 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2012/03/30 18:34:14 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
[2012/03/30 18:33:21 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/03/27 23:04:27 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Roaming\Malwarebytes
[2012/03/27 23:04:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/27 23:04:16 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012/03/27 23:04:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/03/27 23:04:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/03/18 23:31:48 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Roaming\FLEXnet
[2012/03/18 23:31:28 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Roaming\Zeon
[2012/03/18 23:31:03 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Roaming\ScanSoft
[2012/03/18 23:31:03 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Local\ScanSoft
[2012/03/18 23:30:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Nuance
[2012/03/18 23:28:06 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2012/03/18 23:27:23 | 000,000,000 | ---D | C] -- C:\Users\CPDC2007\AppData\Roaming\Nuance
[2012/03/18 23:27:01 | 000,000,000 | ---D | C] -- C:\ProgramData\ScanSoft
[2012/03/18 23:26:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nuance OmniPage 18
[2012/03/18 23:26:45 | 000,000,000 | ---D | C] -- C:\windows\pixtran
[2012/03/18 23:25:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nuance
[2012/03/18 23:25:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Macrovision
[2012/03/18 23:25:53 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[1 C:\Users\CPDC2007\Desktop\*.tmp files -> C:\Users\CPDC2007\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/04/06 22:52:11 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\CPDC2007\Desktop\OTL.exe
[2012/04/06 22:46:00 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/06 22:24:58 | 000,025,120 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/06 22:24:58 | 000,025,120 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/06 22:22:35 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2012/04/06 22:17:30 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/06 22:17:17 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/04/06 22:17:14 | 2074,099,711 | -HS- | M] () -- C:\hiberfil.sys
[2012/04/06 21:57:16 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/04/06 20:06:28 | 004,450,572 | R--- | M] (Swearware) -- C:\Users\CPDC2007\Desktop\ComboFix.exe
[2012/04/06 19:52:58 | 005,268,047 | ---- | M] () -- C:\Users\CPDC2007\Desktop\IMG (2).jpg
[2012/04/06 19:15:05 | 001,932,256 | ---- | M] (Symantec Corporation) -- C:\Users\CPDC2007\Desktop\FixTDSS.exe
[2012/04/06 19:06:25 | 002,053,661 | ---- | M] () -- C:\Users\CPDC2007\Desktop\tdsskiller.zip
[2012/04/06 18:45:45 | 000,000,512 | ---- | M] () -- C:\Users\CPDC2007\Desktop\MBR.dat
[2012/04/06 18:34:35 | 000,044,607 | ---- | M] () -- C:\Users\CPDC2007\Desktop\bootkit_remover.zip
[2012/04/06 18:11:12 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\CPDC2007\Desktop\aswMBR.exe
[2012/04/06 17:26:05 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\CPDC2007\Desktop\dds.scr
[2012/04/06 17:12:35 | 000,302,592 | ---- | M] () -- C:\Users\CPDC2007\Desktop\7j6o4nq9.exe
[2012/04/06 00:16:35 | 000,001,188 | ---- | M] () -- C:\windows\SysWow64\ServiceConfig.xml
[2012/04/05 21:09:00 | 000,730,320 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/04/05 21:09:00 | 000,631,584 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/04/05 21:09:00 | 000,111,676 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/04/04 20:58:46 | 726,930,608 | ---- | M] () -- C:\windows\MEMORY.DMP
[2012/04/04 19:55:36 | 002,073,136 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\CPDC2007\Desktop\TDSSKiller.exe
[2012/04/04 10:36:17 | 002,298,144 | ---- | M] () -- C:\Users\CPDC2007\Desktop\IMG1.jpg
[2012/04/03 23:12:44 | 000,023,724 | ---- | M] () -- C:\Users\CPDC2007\Desktop\0,,10335~5292458,00.jpg
[2012/04/02 23:56:25 | 000,002,095 | ---- | M] () -- C:\Users\Public\Desktop\Nokia Suite.lnk
[2012/04/02 11:18:59 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts.20120402-143559.backup
[2012/04/01 23:44:46 | 000,000,036 | ---- | M] () -- C:\Users\CPDC2007\AppData\Local\housecall.guid.cache
[2012/03/31 23:21:21 | 000,297,768 | ---- | M] () -- C:\Users\CPDC2007\Desktop\Test_manager_CV_template.pdf
[2012/03/30 22:45:51 | 026,101,051 | ---- | M] () -- C:\Users\CPDC2007\Desktop\IMG.jpg
[2012/03/28 13:56:00 | 000,025,600 | ---- | M] (Nokia) -- C:\windows\SysNative\drivers\pccsmcfdx64.sys
[2012/03/25 01:33:39 | 000,000,200 | ---- | M] () -- C:\Users\CPDC2007\AppData\Roaming\default.rss
[2012/03/25 01:33:38 | 000,000,069 | ---- | M] () -- C:\windows\NeroDigital.ini
[2012/03/24 11:12:21 | 001,015,556 | ---- | M] () -- C:\Users\CPDC2007\Documents\Performance 2.pdf
[2012/03/22 23:01:38 | 000,661,741 | ---- | M] () -- C:\Users\CPDC2007\Documents\Performance anaylis.pdf
[2012/03/18 23:27:59 | 000,000,403 | ---- | M] () -- C:\windows\MAXLINK.INI
[2012/03/16 12:16:37 | 000,002,032 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2012/03/14 19:32:08 | 004,976,472 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[1 C:\Users\CPDC2007\Desktop\*.tmp files -> C:\Users\CPDC2007\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/04/06 19:34:13 | 005,268,047 | ---- | C] () -- C:\Users\CPDC2007\Desktop\IMG (2).jpg
[2012/04/06 19:06:21 | 002,053,661 | ---- | C] () -- C:\Users\CPDC2007\Desktop\tdsskiller.zip
[2012/04/06 18:45:45 | 000,000,512 | ---- | C] () -- C:\Users\CPDC2007\Desktop\MBR.dat
[2012/04/06 18:34:33 | 000,044,607 | ---- | C] () -- C:\Users\CPDC2007\Desktop\bootkit_remover.zip
[2012/04/06 17:12:33 | 000,302,592 | ---- | C] () -- C:\Users\CPDC2007\Desktop\7j6o4nq9.exe
[2012/04/06 00:16:35 | 000,001,188 | ---- | C] () -- C:\windows\SysWow64\ServiceConfig.xml
[2012/04/04 10:36:10 | 002,298,144 | ---- | C] () -- C:\Users\CPDC2007\Desktop\IMG1.jpg
[2012/04/03 23:12:42 | 000,023,724 | ---- | C] () -- C:\Users\CPDC2007\Desktop\0,,10335~5292458,00.jpg
[2012/04/03 09:41:29 | 000,000,830 | ---- | C] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/04/02 23:56:25 | 000,002,095 | ---- | C] () -- C:\Users\Public\Desktop\Nokia Suite.lnk
[2012/04/01 23:44:46 | 000,000,036 | ---- | C] () -- C:\Users\CPDC2007\AppData\Local\housecall.guid.cache
[2012/03/31 23:21:21 | 000,297,768 | ---- | C] () -- C:\Users\CPDC2007\Desktop\Test_manager_CV_template.pdf
[2012/03/31 11:44:07 | 726,930,608 | ---- | C] () -- C:\windows\MEMORY.DMP
[2012/03/30 18:34:18 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2012/03/30 18:34:18 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2012/03/30 18:34:18 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2012/03/30 18:34:18 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2012/03/30 18:34:18 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2012/03/24 11:12:18 | 001,015,556 | ---- | C] () -- C:\Users\CPDC2007\Documents\Performance 2.pdf
[2012/03/22 23:01:34 | 000,661,741 | ---- | C] () -- C:\Users\CPDC2007\Documents\Performance anaylis.pdf
[2012/03/18 23:31:04 | 006,448,640 | ---- | C] () -- C:\Users\CPDC2007\Documents\Newsletter Sample.opd
[2012/03/18 23:27:59 | 000,000,403 | ---- | C] () -- C:\windows\MAXLINK.INI
[2012/02/28 02:22:16 | 000,000,200 | ---- | C] () -- C:\Users\CPDC2007\AppData\Roaming\default.rss
[2012/02/28 01:28:37 | 000,000,069 | ---- | C] () -- C:\windows\NeroDigital.ini
[2012/02/05 23:25:31 | 000,739,442 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2011/12/24 01:07:48 | 000,004,608 | ---- | C] () -- C:\Users\CPDC2007\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/10 23:29:18 | 000,175,616 | ---- | C] () -- C:\windows\SysWow64\unrar.dll
[2011/12/10 23:29:17 | 000,650,752 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll
[2011/12/10 23:29:17 | 000,243,200 | ---- | C] () -- C:\windows\SysWow64\xvidvfw.dll
[2011/12/10 23:29:16 | 000,074,752 | ---- | C] () -- C:\windows\SysWow64\ff_vfw.dll
[2011/12/10 18:35:09 | 000,074,703 | ---- | C] () -- C:\windows\SysWow64\mfc45.dll
[2011/12/05 23:52:12 | 000,008,192 | ---- | C] () -- C:\windows\SysWow64\srvany.exe
[2011/12/05 18:02:37 | 000,059,232 | ---- | C] () -- C:\windows\SysWow64\CNC_391W.DAT
[2011/12/05 17:16:14 | 000,000,144 | ---- | C] () -- C:\windows\SysWow64\lkfl.dat
[2011/12/05 17:16:14 | 000,000,128 | ---- | C] () -- C:\windows\SysWow64\pdfl.dat
[2011/12/05 17:16:14 | 000,000,080 | ---- | C] () -- C:\windows\SysWow64\ibfl.dat
[2011/10/14 02:24:58 | 000,000,000 | ---- | C] () -- C:\windows\NDSTray.INI
[2011/04/05 04:07:00 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2011/04/05 04:06:58 | 000,963,116 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2011/04/05 04:06:58 | 000,216,876 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2011/02/04 03:56:58 | 000,066,856 | ---- | C] () -- C:\windows\SysWow64\SynTPEnhPS.dll
[2010/11/09 20:09:58 | 000,028,672 | ---- | C] () -- C:\windows\SysWow64\SPCtl.dll
========== LOP Check ==========
[2011/12/10 23:13:10 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\#ISW.FS#
[2011/12/11 15:26:04 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Acoustica
[2012/04/04 01:04:47 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Azureus
[2011/12/08 14:49:56 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Canon
[2011/12/05 17:16:42 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\CheckPoint
[2011/12/05 16:48:09 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\com.soccertutor.TacticsManager
[2012/03/31 11:38:57 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\gizza
[2012/02/22 13:36:00 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\gtk-2.0
[2011/12/10 20:34:40 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\iolo
[2011/12/06 23:34:46 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Leadertech
[2011/12/06 00:33:21 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\MailFrontier
[2012/01/04 23:57:22 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Nokia
[2011/12/06 14:09:31 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Nokia Suite
[2012/03/18 23:27:23 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Nuance
[2011/12/06 13:52:05 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\PC Suite
[2012/04/03 09:59:25 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Product_RM
[2012/04/03 10:52:46 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Registry Mechanic
[2012/03/18 23:31:03 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\ScanSoft
[2012/02/14 18:07:39 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Toshiba
[2011/12/05 16:44:43 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\TOSHIBA Online Product Information
[2011/12/05 16:33:19 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\WinBatch
[2012/03/18 23:31:28 | 000,000,000 | ---D | M] -- C:\Users\CPDC2007\AppData\Roaming\Zeon
[2012/02/07 09:44:49 | 000,032,612 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========