Hi touch, the redirection has stopped and most applications are working as normal now, there is still something amiss but I can't locate it (there is a folder called avenger that appears on the c: everytime I run any scan?. However this has allowed me to run the otview program you suggested earlier hereis the log:
OTViewIt logfile created on: 22/11/2008 09:55:05 - Run
OTViewIt by OldTimer - Version 1.0.20.0 Folder = C:\
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1022.37 Mb Total Physical Memory | 528.64 Mb Available Physical Memory | 51.71% Memory free
2.40 Gb Paging File | 2.03 Gb Available in Paging File | 84.65% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.15 Gb Total Space | 48.04 Gb Free Space | 45.69% Space Free | Partition Type: NTFS
Drive D: | 526.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 6.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 7.47 Gb Total Space | 7.04 Gb Free Space | 94.12% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: STEPHEN-D234885
Current User Name: Stephen Banks
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
[color=orange]========== Processes ==========[/color]
[2005/08/05 13:56:34 | 00,064,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehtray.exe
[2008/04/14 00:12:33 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
[2005/06/20 04:32:24 | 00,127,118 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerCinema\PCMService.exe
[2008/06/10 03:27:04 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[2006/03/24 16:30:44 | 00,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
[2007/04/23 10:23:14 | 01,032,640 | ---- | M] (Kontiki Inc.) -- C:\Program Files\Kontiki\KHost.exe
[2008/11/17 18:38:33 | 01,234,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
[2008/04/14 00:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
[2008/11/17 18:38:32 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
[2005/07/07 10:40:10 | 00,221,281 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
[2005/01/26 15:15:16 | 00,884,838 | ---- | M] (NETGEAR) -- C:\Program Files\NETGEAR\WPN111\WPN111.exe
[2005/06/20 04:32:56 | 00,061,440 | ---- | M] (Cyberlink) -- C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
[2005/06/20 04:32:56 | 00,737,381 | ---- | M] (Cyberlink) -- C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
[2005/08/05 13:56:32 | 00,235,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehRecvr.exe
[2005/08/05 13:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehSched.exe
[2007/04/23 10:22:14 | 03,068,352 | ---- | M] (Kontiki Inc.) -- C:\Program Files\Kontiki\KService.exe
[2006/03/21 20:03:00 | 00,143,428 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
[2005/07/07 10:40:12 | 00,110,687 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
[2008/11/17 18:38:33 | 00,287,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
[2005/08/05 13:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe
[2008/11/17 18:38:33 | 00,875,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
[2005/08/05 13:56:28 | 00,046,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehmsas.exe
[2008/04/14 00:12:40 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
[2008/08/23 05:56:15 | 00,635,848 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2008/11/17 18:38:42 | 00,540,440 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\aAvgApi.exe
[2008/11/22 09:53:24 | 00,422,400 | ---- | M] (OldTimer Tools) -- C:\OTViewIt.exe
[color=orange]========== (O23) Win32 Services ==========[/color]
[2007/04/13 02:20:52 | 00,033,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2008/11/17 18:38:33 | 00,875,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Running])
[2008/11/17 18:38:32 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
[2005/07/07 10:40:10 | 00,221,281 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe -- (CLCapSvc [Auto | Running])
[2007/04/13 02:21:18 | 00,068,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2005/07/07 10:40:12 | 00,110,687 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe -- (CLSched [Auto | Running])
[2005/06/20 04:32:56 | 00,061,440 | ---- | M] (Cyberlink) -- C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe -- (CyberLink Media Library Service [Auto | Running])
[2005/08/05 13:56:32 | 00,235,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehRecvr.exe -- (ehRecvr [Auto | Running])
[2005/08/05 13:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehSched.exe -- (ehSched [Auto | Running])
[2005/11/14 01:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2007/04/23 10:22:14 | 03,068,352 | ---- | M] (Kontiki Inc.) -- C:\Program Files\Kontiki\KService.exe -- (KService [Auto | Running])
[2005/08/05 13:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe -- (McrdSvc [Auto | Running])
File not found -- -- (McShield [Unknown | Stopped])
File not found -- -- (McSysmon [Auto | Stopped])
[2006/12/14 02:21:20 | 00,045,056 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV [On_Demand | Stopped])
[2006/03/21 20:03:00 | 00,143,428 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
[2006/12/14 01:46:16 | 00,057,344 | ---- | M] () -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR [On_Demand | Stopped])
[2007/02/20 14:53:02 | 00,112,184 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe -- (SonicStage Back-End Service [On_Demand | Stopped])
[2006/12/14 02:02:08 | 00,069,632 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV [On_Demand | Stopped])
[2007/02/20 14:53:06 | 00,075,320 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe -- (SSScsiSV [On_Demand | Stopped])
[2005/08/03 18:29:52 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [On_Demand | Stopped])
[color=orange]========== Driver Services ==========[/color]
[2007/12/27 21:02:30 | 00,017,801 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP [Auto | Running])
[2008/11/17 18:38:48 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (AvgLdx86 [System | Running])
[2008/11/17 18:38:47 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (AvgMfx86 [System | Running])
[2008/11/17 18:38:52 | 00,076,040 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (AvgTdiX [Auto | Running])
[2006/08/17 07:55:16 | 00,044,544 | R--- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp [On_Demand | Running])
[2004/12/13 21:14:00 | 00,039,904 | ---- | M] (Adaptec, Inc.) -- C:\WINDOWS\System32\drivers\cercsr6.sys -- (cercsr6 [Boot | Stopped])
[2007/04/04 17:15:02 | 00,839,880 | ---- | M] (Authentium, Inc.) -- C:\WINDOWS\system32\drivers\Css-Dvp.sys -- (CSS DVP [Auto | Running])
[2007/03/02 10:26:18 | 00,067,352 | ---- | M] (Raxco Software, Inc.) -- C:\WINDOWS\System32\drivers\DefragFs.sys -- (DefragFS [Boot | Running])
[2003/07/24 12:10:34 | 00,017,149 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\system32\DNINDIS5.sys -- (DNINDIS5 [On_Demand | Stopped])
[2008/04/13 16:36:05 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus [On_Demand | Running])
[2005/12/01 00:40:56 | 00,936,960 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\drivers\HSX_DPV.sys -- (HSF_DPV [On_Demand | Running])
[2005/12/01 00:40:12 | 00,192,512 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\drivers\HSXHWAZL.sys -- (HSXHWAZL [On_Demand | Running])
[2005/10/04 22:57:08 | 00,012,544 | ---- | M] (Conexant) -- C:\WINDOWS\system32\drivers\mdmxsdk.sys -- (mdmxsdk [Auto | Running])
[2008/04/13 18:46:22 | 00,015,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE [On_Demand | Stopped])
[2006/03/21 19:03:00 | 03,652,128 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Running])
[2004/11/24 14:34:48 | 00,050,976 | ---- | M] (FotoNation Inc.) -- C:\WINDOWS\system32\drivers\CoachUsb.sys -- (PentaxUsb [On_Demand | Stopped])
[2004/11/24 14:36:42 | 00,044,256 | ---- | M] (FotoNation Inc.) -- C:\WINDOWS\system32\drivers\CoachVc.sys -- (PentaxVc [On_Demand | Stopped])
[2008/01/27 22:34:30 | 00,009,856 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc [On_Demand | Running])
[2004/08/10 11:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2008/02/21 02:05:38 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2005/07/14 18:58:14 | 00,028,544 | ---- | M] (REDC) -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk [On_Demand | Running])
[2005/07/12 19:00:30 | 00,051,328 | ---- | M] (REDC) -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk [On_Demand | Running])
[2005/07/14 17:28:38 | 00,307,968 | ---- | M] (REDC) -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp [On_Demand | Running])
[2005/03/21 10:00:24 | 00,004,096 | ---- | M] (SuperAdBlocker.com) -- C:\WINDOWS\System32\sabprocenum.sys -- (SABProcEnum [On_Demand | Stopped])
[2008/04/13 18:36:44 | 00,079,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\sdbus.sys -- (sdbus [On_Demand | Running])
[2007/11/13 10:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [Auto | Running])
[2008/04/13 18:40:47 | 00,011,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\sffdisk.sys -- (sffdisk [On_Demand | Stopped])
[2008/04/13 18:40:47 | 00,011,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\sffp_sd.sys -- (sffp_sd [On_Demand | Stopped])
[2006/03/24 16:34:30 | 01,156,648 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA [On_Demand | Running])
[2005/09/06 14:11:50 | 00,202,496 | R--- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\system32\drivers\emBDA.sys -- (USB28xxBGA [On_Demand | Stopped])
[2005/09/06 14:11:38 | 00,005,376 | R--- | M] (eMPIA Technology, Inc.) -- C:\WINDOWS\system32\drivers\emOEM.sys -- (USB28xxOEM [On_Demand | Stopped])
[2008/04/13 18:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Stopped])
[2006/11/02 06:22:54 | 00,492,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wdf01000.sys -- (Wdf01000 [On_Demand | Stopped])
[2005/12/01 00:40:08 | 00,669,696 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\drivers\HSX_CNXT.sys -- (winachsf [On_Demand | Running])
[2006/11/02 06:00:08 | 00,039,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\winusb.sys -- (winusb [On_Demand | Stopped])
[2008/04/13 18:36:38 | 00,008,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wmiacpi.sys -- (WmiAcpi [System | Running])
[2005/09/26 16:02:50 | 00,362,944 | ---- | M] (NETGEAR, Inc.) -- C:\WINDOWS\system32\drivers\WPN111.sys -- (WPN111 [On_Demand | Stopped])
[color=orange]========== (R ) Internet Explorer ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=https://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
"Default_Search_URL"=https://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=C:\windows\system32\blank.htm
"Search Page"=https://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Security Risk Page"=about:SecurityRisk
"Start Page"=https://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=https://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"Default_Search_URL"=https://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"SearchAssistant"=https://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=https://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=C:\windows\system32\blank.htm
"Search Page"=https://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=https://uk.yahoo.com/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=https://home.microsoft.com/access/autosearch.asp?p=%s
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = <local>
[color=orange]========== (O1) Hosts File ==========[/color]
HOSTS File = (225204 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
127.0.0.1 babe.the-killer.bz
127.0.0.1
www.babe.the-killer.bz
127.0.0.1 babe.k-lined.com
127.0.0.1
www.babe.k-lined.com
127.0.0.1 did.i-used.cc
127.0.0.1
www.did.i-used.cc
127.0.0.1 coolwwwsearch.com
127.0.0.1
www.coolwwwsearch.com
127.0.0.1 coolwebsearch.com
127.0.0.1
www.coolwebsearch.com
127.0.0.1 hi.studioaperto.net
127.0.0.1
www.hi.studioaperto.net
127.0.0.1 webbrowser.tv
127.0.0.1
www.webbrowser.tv
127.0.0.1 wazzupnet.com
127.0.0.1
www.wazzupnet.com
127.0.0.1 gueb.com
127.0.0.1
www.gueb.com
127.0.0.1 kabex.com
127.0.0.1
www.kabex.com
127.0.0.1 hityou.com
127.0.0.1
www.hityou.com
127.0.0.1 miosearch.com
127.0.0.1
www.miosearch.com
7904 more lines...
[color=orange]========== (O2) BHO's ==========[/color]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (HKLM) -- C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
{67ED1188-2AD5-4B5A-A309-2AE0E4BB6B43} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
{92842A94-C620-4FC7-9684-7BC0FAB6A021} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{A057A204-BACC-4D26-9990-79A187E2698E} (HKLM) -- C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )
{E90DAC4E-6E13-45EA-AF15-F738115EE56A} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[color=orange]========== (O3) Toolbars ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )
"{E1BACF55-35E1-4E47-9247-2D48660E5545}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[color=orange]========== (O4) Run Keys ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"4oD"="C:\Program Files\Kontiki\KHost.exe" -all (Kontiki Inc.)
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
"ehTray"=C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
"Malwarebytes Anti-Malware (reboot)"="C:\malwar\mbam.exe" /runcleanupscript File not found
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"NVHotkey"=rundll32.exe nvHotkey.dll,Start (NVIDIA Corporation)
"NvMediaCenter"=RunDLL32.exe NvMCTray.dll,NvTaskbarInit (NVIDIA Corporation)
"nwiz"=nwiz.exe /installquiet ()
"PCMService"="C:\Program Files\CyberLink\PowerCinema\PCMService.exe" (CyberLink Corp.)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
"SigmatelSysTrayApp"=stsystra.exe (SigmaTel, Inc.)
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"=C:\Program Files\Kontiki\KHost.exe -all (Kontiki Inc.)
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 (Adobe Systems Incorporated)
[color=orange]========== (O4) RunOnceEx Keys ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
"Flags"= File not found
[color=orange]========== (O4) Startup Folders ==========[/color]
[2005/09/23 22:05:26 | 00,029,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[2005/01/26 15:15:16 | 00,884,838 | ---- | M] (NETGEAR) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WPN111 Smart Wizard.lnk = C:\Program Files\NETGEAR\WPN111\WPN111.exe
[color=orange]========== (O6 & O7) Current Version Policies ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.mss -- File not found
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.the -- File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[color=orange]========== (O9) IE Extensions ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [2008/06/10 03:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{08E730A4-FB02-45BD-A900-01E4AD8016F6}: Button: Sky -- File not found
{95B3F550-91C4-4627-BCC4-521288C52977}: Button: PPLive -- %ProgramFiles%\PPLive\PPLive.exe [2007/03/16 05:46:10 | 00,190,072 | ---- | M] ()
{95B3F550-91C4-4627-BCC4-521288C52977}: Menu: PPLive -- %ProgramFiles%\PPLive\PPLive.exe [2007/03/16 05:46:10 | 00,190,072 | ---- | M] ()
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 18:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/14 00:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/14 00:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 03:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{95B3F550-91C4-4627-BCC4-521288C52977} [HKLM] -> %ProgramFiles%\PPLive\PPLive.exe [PPLive] -> [2007/03/16 05:46:10 | 00,190,072 | ---- | M] ()
CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{E908B145-C847-4e85-B315-07E2E70DECF8} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
[color=orange]========== (O12) Internet Explorer Plugins ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = [url=https://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s]https://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s[/url]
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
[color=orange]========== (O13) Default Prefixes ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=https://
[color=orange]========== (O15) Trusted Sites ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
35 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
34 domain(s) and sub-domain(s) not assigned to a zone.
[color=orange]========== (O16) DPF ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}:
https://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab -- QuickTime Plugin Control
{15B782AF-55D8-11D1-B477-006097098764}:
https://download.macromedia.com/pub/shockwave/cabs/authorware/awswax70.cab -- Macromedia Authorware Web Player Control
{166B1BCA-3F9C-11CF-8075-444553540000}:
https://download.macromedia.com/pub/shockwave/cabs/director/sw.cab -- Shockwave ActiveX Control
{8AD9C840-044E-11D1-B3E9-00805F499D93}:
https://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab -- Java Plug-in 1.6.0_07
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}:
https://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.
{B1E2B96C-12FE-45E2-BEF1-44A219113CDD}:
https://www.superadblocker.com/activex/sabspx.cab -- SABScanProcesses Class
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}:
https://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab -- Java Plug-in 1.5.0_06
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:
https://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab -- Java Plug-in 1.6.0_05
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:
https://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}:
https://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab -- Java Plug-in 1.6.0_07
{CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}:
https://www.adobe.com/products/acrobat/nos/gp.cab -- get_atlcom Class
[color=orange]========== (O17) DNS Name Servers ==========[/color]
{3377A786-A543-4CA8-BDDD-FD8F76A667E4} (Servers: | Description: 1394 Net Adapter)
{580C0553-5553-4702-B2C1-C34DFEE14E50} (Servers: | Description: Broadcom 440x 10/100 Integrated Controller)
{93D77F72-59EA-44B2-8257-02F729068671} (Servers: | Description: NETGEAR RangeMax(TM) Wireless USB 2.0 Adapter WPN111)
{DE4B71A4-11ED-4977-8D43-6CEE45422C90} (Servers: | Description: )
[color=orange]========== (O20) AppInit_DLLs ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls"=avgrsstx.dll
>[2008/11/17 18:38:53 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\avgrsstx.dll
[color=orange]========== LSA *Authentication Packages* ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=msv1_0,C:\WINDOWS\system32\efcASlMC,
>File not found --
[color=orange]========== Safeboot Options ==========[/color]
"AlternateShell"=cmd.exe
[color=orange]========== CDRom AutoRun Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
[color=orange]========== Autorun Files on Drives ==========[/color]
AUTOEXEC.BAT []
[2007/03/22 11:17:18 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
autorun.exe [MZ | ]
[2007/09/26 16:38:34 | 00,039,680 | R--- | M] (Sports Interactive) -- D:\autorun.exe -- [ UDF ]
autorun.inf [[autorun] | OPEN=autorun.exe | ]
[2007/09/05 20:47:46 | 00,000,027 | R--- | M] () -- D:\autorun.inf -- [ UDF ]
autorun.inf [[AutoRun] | open=LaunchU3.exe -a | icon=LaunchU3.exe,0 | | [Definitions] | Launchpad=LaunchPad.exe | Vtype=2 | | [CopyFiles] | FileNumber=1 | File1=LaunchPad.zip | | [Update] | URL=https://u3.sandisk.com/download/lp_installer.asp?custom=1.6.1.1&brand=CruzerBFG | | | [Comment] | brand=CruzerBFG | ]
[2007/10/23 07:22:58 | 00,000,283 | R--- | M] () -- E:\autorun.inf -- [ CDFS ]
[color=orange]========== MountPoints2 ==========[/color]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{25e3f5a8-20f9-11dd-bf88-0015c55aa980}\Shell]
""=AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{25e3f5a8-20f9-11dd-bf88-0015c55aa980}\Shell\AutoRun]
""=Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{25e3f5a8-20f9-11dd-bf88-0015c55aa980}\Shell\AutoRun\command]
""=E:\LaunchU3.exe -- [2007/10/23 07:45:39 | 01,336,632 | R--- | M] ()
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efede284-d85a-11db-88e0-806d6172696f}\Shell]
""=AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efede284-d85a-11db-88e0-806d6172696f}\Shell\AutoRun]
""=Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efede284-d85a-11db-88e0-806d6172696f}\Shell\AutoRun\command]
""=D:\autorun.exe -- [2007/09/26 16:38:34 | 00,039,680 | R--- | M] (Sports Interactive)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell]
""=AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\AutoRun]
""=Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\AutoRun\command]
""=D:\autorun.exe -- [2007/09/26 16:38:34 | 00,039,680 | R--- | M] (Sports Interactive)
[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]
[2008/11/22 09:54:38 | 03,051,752 | ---- | C] () -- C:\ComboFix.exe
[2008/11/22 09:53:17 | 00,422,400 | ---- | C] (OldTimer Tools) -- C:\OTViewIt.exe
[2008/11/22 01:59:31 | 00,000,000 | ---D | C] -- C:\Avenger
[2008/11/21 21:07:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Stephen Banks\Application Data\Malwarebytes
[2008/11/20 22:53:05 | 00,001,461 | ---- | C] () -- C:\Documents and Settings\Stephen Banks\Desktop\hjt.lnk
[2008/11/20 22:53:05 | 00,000,000 | ---D | C] -- C:\Program Files\ht
[2008/11/20 16:46:19 | 00,000,000 | ---D | C] -- C:\malwar
[2008/11/20 14:58:55 | 00,000,782 | ---- | C] () -- C:\Documents and Settings\Stephen Banks\Desktop\Spybot - Search & Destroy.lnk
[2008/11/20 14:58:49 | 00,000,000 | ---D | C] -- C:\Program Files\Sbsd
[2008/11/18 22:05:16 | 00,000,640 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPER.lnk
[2008/11/18 22:05:16 | 00,000,000 | ---D | C] -- C:\Program Files\super
[2008/11/18 21:51:51 | 00,000,000 | ---D | C] -- C:\Program Files\Malwar
[2008/11/18 21:43:29 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2008/11/18 21:15:27 | 00,002,608 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2008/11/18 21:12:05 | 00,000,000 | ---D | C] -- C:\SmitfraudFix
[2008/11/18 20:54:59 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008/11/18 20:54:56 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/11/18 20:54:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/11/18 17:04:26 | 01,580,523 | ---- | C] () -- C:\sf.exe
[2008/11/18 16:30:46 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2008/11/18 16:20:01 | 05,738,016 | ---- | C] () -- C:\sats.exe
[2008/11/18 16:19:55 | 02,372,472 | ---- | C] (Malwarebytes Corporation ) -- C:\setup.exe
[2008/11/17 18:45:36 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2008/11/17 18:38:53 | 00,010,520 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2008/11/17 18:38:53 | 00,001,507 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2008/11/17 18:38:52 | 00,076,040 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2008/11/17 18:38:48 | 00,097,928 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2008/11/17 18:38:47 | 00,026,824 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2008/11/17 18:38:43 | 30,269,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2008/11/17 18:38:43 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2008/11/17 18:38:43 | 00,334,743 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/11/17 18:38:43 | 00,042,274 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2008/11/17 18:38:43 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2008/11/17 18:38:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Stephen Banks\Application Data\AVGTOOLBAR
[2008/11/12 19:39:25 | 00,455,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2008/11/12 19:38:06 | 01,106,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml3.dll
[2008/10/24 17:22:11 | 00,337,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\netapi32.dll
[color=orange]========== Files - Modified Within 30 Days ==========[/color]
[2 C:\WINDOWS\System32\*.tmp files]
[12 C:\WINDOWS\*.tmp files]
[2008/11/22 09:54:38 | 03,051,752 | ---- | M] () -- C:\ComboFix.exe
[2008/11/22 09:53:24 | 00,422,400 | ---- | M] (OldTimer Tools) -- C:\OTViewIt.exe
[2008/11/22 09:43:52 | 00,472,336 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2008/11/22 09:43:52 | 00,402,200 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2008/11/22 09:43:52 | 00,063,148 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2008/11/22 09:39:18 | 00,018,200 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2008/11/22 09:39:03 | 00,050,868 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2008/11/22 09:38:56 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/11/22 09:38:53 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008/11/22 01:58:52 | 04,840,236 | -H-- | M] () -- C:\Documents and Settings\Stephen Banks\Local Settings\Application Data\IconCache.db
[2008/11/21 22:22:15 | 30,269,304 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2008/11/21 22:22:01 | 00,334,743 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/11/21 22:22:01 | 00,042,274 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2008/11/21 20:46:27 | 00,001,461 | ---- | M] () -- C:\Documents and Settings\Stephen Banks\Desktop\hjt.lnk
[2008/11/20 14:58:55 | 00,000,782 | ---- | M] () -- C:\Documents and Settings\Stephen Banks\Desktop\Spybot - Search & Destroy.lnk
[2008/11/18 22:06:58 | 00,000,640 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPER.lnk
[2008/11/18 21:39:33 | 00,002,608 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2008/11/18 17:04:26 | 01,580,523 | ---- | M] () -- C:\sf.exe
[2008/11/18 12:15:36 | 02,372,472 | ---- | M] (Malwarebytes Corporation ) -- C:\setup.exe
[2008/11/18 12:15:12 | 05,738,016 | ---- | M] () -- C:\sats.exe
[2008/11/17 18:38:53 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2008/11/17 18:38:53 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2008/11/17 18:38:52 | 00,076,040 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2008/11/17 18:38:48 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2008/11/17 18:38:47 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2008/11/17 18:38:43 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2008/11/16 22:57:48 | 00,032,256 | ---- | M] () -- C:\Documents and Settings\Stephen Banks\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/11/12 19:31:41 | 00,018,200 | ---- | M] () -- C:\WINDOWS\System32\nvModes.dat
[2008/11/07 23:26:06 | 00,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008/11/04 00:10:25 | 17,318,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2008/10/24 11:21:09 | 00,455,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mrxsmb.sys
[2008/10/24 11:21:09 | 00,455,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2008/10/23 16:40:03 | 00,000,286 | ---- | M] () -- C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
< End of report >