Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Google Redirect  (Read 48547 times)

0 Members and 1 Guest are viewing this topic.

Kerjifire

  • Guest
Re: Google Redirect
« Reply #30 on: March 02, 2010, 11:24:06 PM »

Found mount point       : C:\WINDOWS\CSC\d5\d5

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\CSC\d5\d5

Found mount point       : C:\WINDOWS\CSC\d6\d6

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\CSC\d6\d6

Found mount point       : C:\WINDOWS\CSC\d7\d7

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\CSC\d7\d7

Found mount point       : C:\WINDOWS\CSC\d8\d8

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\CSC\d8\d8

Found mount point       : C:\WINDOWS\Debug\WPD\WPD

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Debug\WPD\WPD

Found mount point       : C:\WINDOWS\Downloaded Installations\{628E8630-7947-49EA-BE90-7F8BFF77A79C}\{628E8630-7947-49EA-BE90-7F8BFF77A79C}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Downloaded Installations\{628E8630-7947-49EA-BE90-7F8BFF77A79C}\{628E8630-7947-49EA-BE90-7F8BFF77A79C}

Found mount point       : C:\WINDOWS\Downloaded Installations\{6A553D7E-037E-43C7-ABFF-A270BBB1458F}\{6A553D7E-037E-43C7-ABFF-A270BBB1458F}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Downloaded Installations\{6A553D7E-037E-43C7-ABFF-A270BBB1458F}\{6A553D7E-037E-43C7-ABFF-A270BBB1458F}

Found mount point       : C:\WINDOWS\ftpcache\ftpcache

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\ftpcache\ftpcache

Found mount point       : C:\WINDOWS\ime\chsime\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\ime\chsime\applets\applets

Found mount point       : C:\WINDOWS\ime\CHTIME\Applets\Applets

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\ime\CHTIME\Applets\Applets

Found mount point       : C:\WINDOWS\ime\imejp\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\ime\imejp\applets\applets

Found mount point       : C:\WINDOWS\ime\imejp98\imejp98

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\ime\imejp98\imejp98

Found mount point       : C:\WINDOWS\ime\imjp8_1\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\ime\imjp8_1\applets\applets

Found mount point       : C:\WINDOWS\ime\imkr6_1\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\ime\imkr6_1\applets\applets

Found mount point       : C:\WINDOWS\ime\imkr6_1\dicts\dicts

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\ime\imkr6_1\dicts\dicts

Found mount point       : C:\WINDOWS\ime\shared\res\res

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\ime\shared\res\res

Found mount point       : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729

Found mount point       : C:\WINDOWS\Installer\$PatchCache$\Managed\D7314F9862C648A4DB8BE2A5B47BE100\1.0.0\1.0.0

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\$PatchCache$\Managed\D7314F9862C648A4DB8BE2A5B47BE100\1.0.0\1.0.0

Found mount point       : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729

Found mount point       : C:\WINDOWS\Installer\{00180409-78E1-11D2-B60F-006097C998E7}\{00180409-78E1-11D2-B60F-006097C998E7}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{00180409-78E1-11D2-B60F-006097C998E7}\{00180409-78E1-11D2-B60F-006097C998E7}

Found mount point       : C:\WINDOWS\Installer\{02DFF6B1-1654-411C-8D7B-FD6052EF016F}\{02DFF6B1-1654-411C-8D7B-FD6052EF016F}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{02DFF6B1-1654-411C-8D7B-FD6052EF016F}\{02DFF6B1-1654-411C-8D7B-FD6052EF016F}

Found mount point       : C:\WINDOWS\Installer\{08CA9554-B5FE-4313-938F-D4A417B81175}\{08CA9554-B5FE-4313-938F-D4A417B81175}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{08CA9554-B5FE-4313-938F-D4A417B81175}\{08CA9554-B5FE-4313-938F-D4A417B81175}

Found mount point       : C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}

Found mount point       : C:\WINDOWS\Installer\{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}\{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}\{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}

Found mount point       : C:\WINDOWS\Installer\{3248F0A8-6813-11D6-A77B-00B0D0150060}\{3248F0A8-6813-11D6-A77B-00B0D0150060}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{3248F0A8-6813-11D6-A77B-00B0D0150060}\{3248F0A8-6813-11D6-A77B-00B0D0150060}

Found mount point       : C:\WINDOWS\Installer\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}

Found mount point       : C:\WINDOWS\Installer\{3CB41017-F5CA-4C56-934C-ED02156251E6}\{3CB41017-F5CA-4C56-934C-ED02156251E6}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{3CB41017-F5CA-4C56-934C-ED02156251E6}\{3CB41017-F5CA-4C56-934C-ED02156251E6}

Found mount point       : C:\WINDOWS\Installer\{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}\{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}\{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}

Found mount point       : C:\WINDOWS\Installer\{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}\{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}\{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}

Found mount point       : C:\WINDOWS\Installer\{83437081-8186-4F63-BD39-4BE8A691E055}\{83437081-8186-4F63-BD39-4BE8A691E055}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{83437081-8186-4F63-BD39-4BE8A691E055}\{83437081-8186-4F63-BD39-4BE8A691E055}

Found mount point       : C:\WINDOWS\Installer\{9176251A-4CC1-4DDB-B343-B487195EB397}\{9176251A-4CC1-4DDB-B343-B487195EB397}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{9176251A-4CC1-4DDB-B343-B487195EB397}\{9176251A-4CC1-4DDB-B343-B487195EB397}

Found mount point       : C:\WINDOWS\Installer\{9D9A73EA-B2D5-42CF-BB54-5CC4D9F08134}\{9D9A73EA-B2D5-42CF-BB54-5CC4D9F08134}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{9D9A73EA-B2D5-42CF-BB54-5CC4D9F08134}\{9D9A73EA-B2D5-42CF-BB54-5CC4D9F08134}

Found mount point       : C:\WINDOWS\Installer\{9DE006A5-B384-4EDE-A760-0F217136B9EA}\{9DE006A5-B384-4EDE-A760-0F217136B9EA}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{9DE006A5-B384-4EDE-A760-0F217136B9EA}\{9DE006A5-B384-4EDE-A760-0F217136B9EA}

Found mount point       : C:\WINDOWS\Installer\{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}\{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}\{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}

Found mount point       : C:\WINDOWS\Installer\{A9CF9052-F4A0-475D-A00F-A8388C62DD63}\{A9CF9052-F4A0-475D-A00F-A8388C62DD63}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{A9CF9052-F4A0-475D-A00F-A8388C62DD63}\{A9CF9052-F4A0-475D-A00F-A8388C62DD63}

Found mount point       : C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A70700000002}\{AC76BA86-7AD7-1033-7B44-A70700000002}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A70700000002}\{AC76BA86-7AD7-1033-7B44-A70700000002}

Found mount point       : C:\WINDOWS\Installer\{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}\{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}\{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}

Found mount point       : C:\WINDOWS\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}

Found mount point       : C:\WINDOWS\java\classes\classes

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\java\classes\classes

Found mount point       : C:\WINDOWS\java\trustlib\trustlib

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\java\trustlib\trustlib

Found mount point       : C:\WINDOWS\Media\java\classes\classes

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Media\java\classes\classes

Found mount point       : C:\WINDOWS\Media\java\trustlib\trustlib

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Media\java\trustlib\trustlib

Found mount point       : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs

Found mount point       : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files

Found mount point       : C:\WINDOWS\msapps\msinfo\msinfo

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\msapps\msinfo\msinfo

Found mount point       : C:\WINDOWS\pchealth\ErrorRep\UserDumps\UserDumps

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\pchealth\ErrorRep\UserDumps\UserDumps

Found mount point       : C:\WINDOWS\pchealth\helpctr\BATCH\BATCH

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\pchealth\helpctr\BATCH\BATCH

Found mount point       : C:\WINDOWS\pchealth\helpctr\Config\News\News

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\pchealth\helpctr\Config\News\News

Found mount point       : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles

Found mount point       : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs

Found mount point       : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS

Found mount point       : C:\WINDOWS\pchealth\helpctr\System_OEM\System_OEM

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\pchealth\helpctr\System_OEM\System_OEM

Found mount point       : C:\WINDOWS\pchealth\helpctr\Temp\Temp

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\pchealth\helpctr\Temp\Temp

Found mount point       : C:\WINDOWS\PIF\PIF

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\PIF\PIF

Found mount point       : C:\WINDOWS\RegisteredPackages\Provisioning\Schemas\Schemas

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\Provisioning\Schemas\Schemas

Found mount point       : C:\WINDOWS\RegisteredPackages\{077ACEC7-979C-40AB-9835-435BA1511E0D}\{077ACEC7-979C-40AB-9835-435BA1511E0D}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{077ACEC7-979C-40AB-9835-435BA1511E0D}\{077ACEC7-979C-40AB-9835-435BA1511E0D}

Found mount point       : C:\WINDOWS\RegisteredPackages\{077ACEC7-979C-40AB-9835-435BA1511E0D}$BACKUP$\System\System

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{077ACEC7-979C-40AB-9835-435BA1511E0D}$BACKUP$\System\System

Found mount point       : C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\{30C7234B-6482-4A55-A11D-ECD9030313F2}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\{30C7234B-6482-4A55-A11D-ECD9030313F2}

Found mount point       : C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\System

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\System

Found mount point       : C:\WINDOWS\RegisteredPackages\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}

Found mount point       : C:\WINDOWS\RegisteredPackages\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}$BACKUP$\System\System

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}$BACKUP$\System\System

Found mount point       : C:\WINDOWS\RegisteredPackages\{60204BB3-7078-4F70-8F69-68297621941C}\{60204BB3-7078-4F70-8F69-68297621941C}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{60204BB3-7078-4F70-8F69-68297621941C}\{60204BB3-7078-4F70-8F69-68297621941C}

Found mount point       : C:\WINDOWS\RegisteredPackages\{60204BB3-7078-4F70-8F69-68297621941C}$BACKUP$\System\System

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{60204BB3-7078-4F70-8F69-68297621941C}$BACKUP$\System\System

Found mount point       : C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\{981FB688-E76B-4246-987B-92083185B90A}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\{981FB688-E76B-4246-987B-92083185B90A}

Found mount point       : C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\System

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\System

Found mount point       : C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\{A47B3654-48EE-48A5-B629-97D70175E58F}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\{A47B3654-48EE-48A5-B629-97D70175E58F}

Found mount point       : C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\System

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\System

Found mount point       : C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}

Found mount point       : C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\System

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\System

Found mount point       : C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}

Found mount point       : C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\System

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\System

Found mount point       : C:\WINDOWS\RegisteredPackages\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}

Found mount point       : C:\WINDOWS\RegisteredPackages\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}$BACKUP$\System\System

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}$BACKUP$\System\System

Found mount point       : C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}\{DD90D410-1823-43EB-9A16-A2331BF08799}

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}\{DD90D410-1823-43EB-9A16-A2331BF08799}

Found mount point       : C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\System

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\System

Found mount point       : C:\WINDOWS\Registration\CRMLog\CRMLog

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Registration\CRMLog\CRMLog

Found mount point       : C:\WINDOWS\setup.pss\setup.pss

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\setup.pss\setup.pss

Found mount point       : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\0af5890fd4bd4b5e665ff4f51f8aab77\sp2gdr\sp2gdr

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\0af5890fd4bd4b5e665ff4f51f8aab77\sp2gdr\sp2gdr

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\0af5890fd4bd4b5e665ff4f51f8aab77\sp2qfe\sp2qfe

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\0af5890fd4bd4b5e665ff4f51f8aab77\sp2qfe\sp2qfe

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\0af5890fd4bd4b5e665ff4f51f8aab77\update\update

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\0af5890fd4bd4b5e665ff4f51f8aab77\update\update

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\10\msft\windows\gdiplus\gdiplus

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\10\msft\windows\gdiplus\gdiplus

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\52\msft\windows\net\dxmrtp\dxmrtp

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\52\msft\windows\net\dxmrtp\dxmrtp

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\52\msft\windows\net\rtcdll\rtcdll

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\52\msft\windows\net\rtcdll\rtcdll

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\52\msft\windows\net\rtcres\rtcres

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\52\msft\windows\net\rtcres\rtcres

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\60\msft\vcrtl\vcrtl

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\60\msft\vcrtl\vcrtl

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\60\msft\windows\common\controls\controls

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\60\msft\windows\common\controls\controls

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\70\msft\windows\mswincrt\mswincrt

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\asms\70\msft\windows\mswincrt\mswincrt

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\ip\ip

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\ip\ip

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\lang\lang

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\backup\lang\lang

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\download\download

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\download\download

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\3cc7b0afacb1662aadcdf242becc1a47\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\3cc7b0afacb1662aadcdf242becc1a47\backup\backup

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\3cc7b0afacb1662aadcdf242becc1a47\sp2gdr\sp2gdr

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\3cc7b0afacb1662aadcdf242becc1a47\sp2gdr\sp2gdr

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\3cc7b0afacb1662aadcdf242becc1a47\update\update

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\3cc7b0afacb1662aadcdf242becc1a47\update\update

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\58bffe479c581eda56fcf7412cce5cc0\sp2gdr\sp2gdr

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\58bffe479c581eda56fcf7412cce5cc0\sp2gdr\sp2gdr

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\58bffe479c581eda56fcf7412cce5cc0\sp2qfe\sp2qfe

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\58bffe479c581eda56fcf7412cce5cc0\sp2qfe\sp2qfe

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\58bffe479c581eda56fcf7412cce5cc0\update\update

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\58bffe479c581eda56fcf7412cce5cc0\update\update

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\backup\backup

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\73c38420ed6fcb4d7aee2a7564af0e8f\sp2gdr\sp2gdr

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\73c38420ed6fcb4d7aee2a7564af0e8f\sp2gdr\sp2gdr

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\73c38420ed6fcb4d7aee2a7564af0e8f\sp2qfe\sp2qfe

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\73c38420ed6fcb4d7aee2a7564af0e8f\sp2qfe\sp2qfe

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\73c38420ed6fcb4d7aee2a7564af0e8f\update\update

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\73c38420ed6fcb4d7aee2a7564af0e8f\update\update

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\7e9c3219e54b43a6d50fc3202fbc3a2b\sp2gdr\sp2gdr

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\7e9c3219e54b43a6d50fc3202fbc3a2b\sp2gdr\sp2gdr

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\7e9c3219e54b43a6d50fc3202fbc3a2b\sp2qfe\sp2qfe

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\7e9c3219e54b43a6d50fc3202fbc3a2b\sp2qfe\sp2qfe

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\7e9c3219e54b43a6d50fc3202fbc3a2b\update\update

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\7e9c3219e54b43a6d50fc3202fbc3a2b\update\update

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\7f3ae1c8d5ca0198c5822b2c4364147d\7f3ae1c8d5ca0198c5822b2c4364147d

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\7f3ae1c8d5ca0198c5822b2c4364147d\7f3ae1c8d5ca0198c5822b2c4364147d

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\backup\backup

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\90ab7a7d58cf9102adba0adb5ddf1362\sp2gdr\sp2gdr

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\90ab7a7d58cf9102adba0adb5ddf1362\sp2gdr\sp2gdr

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\90ab7a7d58cf9102adba0adb5ddf1362\sp2qfe\sp2qfe

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\90ab7a7d58cf9102adba0adb5ddf1362\sp2qfe\sp2qfe

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\90ab7a7d58cf9102adba0adb5ddf1362\update\update

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\90ab7a7d58cf9102adba0adb5ddf1362\update\update

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\925d6ee61b7b50b981d47dfff68dc8a7\sp2gdr\sp2gdr

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\925d6ee61b7b50b981d47dfff68dc8a7\sp2gdr\sp2gdr

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\925d6ee61b7b50b981d47dfff68dc8a7\sp2qfe\sp2qfe

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\925d6ee61b7b50b981d47dfff68dc8a7\sp2qfe\sp2qfe

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\925d6ee61b7b50b981d47dfff68dc8a7\update\update

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\925d6ee61b7b50b981d47dfff68dc8a7\update\update

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\backup\backup

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\991affb71ad97addf21cf4d2cf2c0f71\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\991affb71ad97addf21cf4d2cf2c0f71\backup\backup

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\991affb71ad97addf21cf4d2cf2c0f71\sp2gdr\sp2gdr

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\991affb71ad97addf21cf4d2cf2c0f71\sp2gdr\sp2gdr

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\991affb71ad97addf21cf4d2cf2c0f71\update\update

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\991affb71ad97addf21cf4d2cf2c0f71\update\update

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\a4c6f78366f403fa7e7d062ca70ddddc\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\a4c6f78366f403fa7e7d062ca70ddddc\backup\backup

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\a8a198f29fa1e0036a0893ee4e32b46a\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\a8a198f29fa1e0036a0893ee4e32b46a\backup\backup

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\bc2e08df13ade612507748ca3eefdc83\sp2gdr\sp2gdr

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\bc2e08df13ade612507748ca3eefdc83\sp2gdr\sp2gdr

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\bc2e08df13ade612507748ca3eefdc83\sp2qfe\sp2qfe

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\bc2e08df13ade612507748ca3eefdc83\sp2qfe\sp2qfe

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\bc2e08df13ade612507748ca3eefdc83\update\update

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\bc2e08df13ade612507748ca3eefdc83\update\update

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\cf7ced0e70c80a1e476f1abf49afecb1\cf7ced0e70c80a1e476f1abf49afecb1

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\cf7ced0e70c80a1e476f1abf49afecb1\cf7ced0e70c80a1e476f1abf49afecb1

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\backup\backup

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\f9afad35863057b4d78a8a2fae680dce\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\f9afad35863057b4d78a8a2fae680dce\backup\backup

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\f9afad35863057b4d78a8a2fae680dce\sp2gdr\sp2gdr

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\f9afad35863057b4d78a8a2fae680dce\sp2gdr\sp2gdr

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\f9afad35863057b4d78a8a2fae680dce\update\update

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\f9afad35863057b4d78a8a2fae680dce\update\update

Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\51ca4a3fc75deb57bb45c683cb369013\51ca4a3fc75deb57bb45c683cb369013

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\51ca4a3fc75deb57bb45c683cb369013\51ca4a3fc75deb57bb45c683cb369013

Found mount point       : C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\Default

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\Default

Found mount point       : C:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\Registered

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\Registered

Found mount point       : C:\WINDOWS\Sun\Java\Deployment\Deployment

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\Sun\Java\Deployment\Deployment

Found mount point       : C:\WINDOWS\SxsCaPendDel\SxsCaPendDel

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\SxsCaPendDel\SxsCaPendDel

Found mount point       : C:\WINDOWS\WinSxS\InstallTemp\58143\58143

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\WinSxS\InstallTemp\58143\58143

Found mount point       : C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da

Found mount point       : C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9839.0_x-ww_ed80bd5c\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9839.0_x-ww_ed80bd5c

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9839.0_x-ww_ed80bd5c\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9839.0_x-ww_ed80bd5c

Found mount point       : C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213

Found mount point       : C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2

Found mount point       : C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1801_x-ww_5eed8217\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1801_x-ww_5eed8217

Mount point destination : \Device\__max++>\^

Removing mount point    : C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1801_x-ww_5eed8217\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1801_x-ww_5eed8217



Finished!


Dr Jay

  • Malware Removal Specialist


  • Specialist
  • Moderator emeritus
  • Thanked: 119
  • Experience: Guru
  • OS: Windows 10
Re: Google Redirect
« Reply #31 on: March 03, 2010, 07:36:15 AM »
Good job.  ;D

  • Please download maxlook and save the file to your desktop.
    • Double click maxlook.exe to run it. Note - you must run it only once!
    • As instructed when the tool runs, restart the computer and logon to the Recovery Console.
  • Start the Recovery Console directly from the Windows XP CD by do the following:
    • Insert the Windows XP cd in your computer.
    • Restart your computer so you are booting off of the CD.
    • When the Welcome to Setup screen appears, press the R button on your keyboard to start the Recovery Console.
    • The Recovery Console will start and ask you which Windows installation you would like to log on to. If you have multiple Windows installations, it will list each one, and you would enter the number associated with the installation you would like to work on and press enter. If you have just one Windows installation, type 1 and press enter.
    • It will then prompt you for the Administrator's password. If there is no password, simply press enter. Otherwise type in the password and then press enter. If you do not know your password then see this.
    • If you entered the correct password you will now be presented with a C:\Windows> prompt and you can start using the Recovery Console.
  • Type the following bolded command at the C:\windows> prompt and press Enter:
      batch look.bat
    • You will see "1 file(s) copied" many times then return to the c:\windows> prompt.
    • Type Exit and press Enter to restart your computer then logon in normal mode.
    • Please run maxlook.exe again now. Note - you must run it only once!
      • It will produce looklog.txt on the desktop.
      • Please post the results here.
    ~Dr Jay

    Kerjifire

    • Guest
    Re: Google Redirect
    « Reply #32 on: March 04, 2010, 12:22:53 AM »
    I have 2 XP CD Packs, i don't know which one i used to install windows. does it matter?

    Dr Jay

    • Malware Removal Specialist


    • Specialist
    • Moderator emeritus
    • Thanked: 119
    • Experience: Guru
    • OS: Windows 10
    Re: Google Redirect
    « Reply #33 on: March 04, 2010, 12:05:24 PM »
    Place each of them in the drive and boot from it. If you are allowed to press R for repair, then that is the one.
    ~Dr Jay

    Kerjifire

    • Guest
    Re: Google Redirect
    « Reply #34 on: March 05, 2010, 05:18:25 PM »
    Can u help me with something b4 i do that, i got the BSOD again and ran Who Crashed

    Analysis
    --------------------------------------------------------------------------------

    Crash dump directory: C:\WINDOWS\Minidump

    Crash dumps are enabled on your computer.


    On Fri 5/03/2010 11:55:06 PM your computer crashed
    This was likely caused by the following module: ntoskrnl.exe
    Bugcheck code: 0x50 (0xE146ACF8, 0x1, 0x804DAAB5, 0x1)
    Error: PAGE_FAULT_IN_NONPAGED_AREA
    Dump file: C:\WINDOWS\Minidump\Mini030610-01.dmp
    file path: C:\WINDOWS\system32\ntoskrnl.exe
    product: Microsoft® Windows® Operating System
    company: Microsoft Corporation
    description: NT Kernel & System
    The crash took place in a standard Microsoft module. Your system configuration may be incorrect, possibly the culprit may be another driver on your system which cannot be identified at this time.




    --------------------------------------------------------------------------------
    Conclusion
    --------------------------------------------------------------------------------

    1 crash dumps have been found and analyzed. Note that it's not always possible to state with certainty whether a reported driver is really responsible for crashing your system or that the root cause is in another module. Nonetheless it's suggested you look for updates for the products that these drivers belong to and regularly visit Windows update or enable automatic updates for Windows. In case a piece of malfunctioning hardware is causing trouble, a search with Google on the bug check errors together with the model name and brand of your computer may help you investigate this further.

    Dr Jay

    • Malware Removal Specialist


    • Specialist
    • Moderator emeritus
    • Thanked: 119
    • Experience: Guru
    • OS: Windows 10
    Re: Google Redirect
    « Reply #35 on: March 05, 2010, 08:32:46 PM »
    The infection spawned that blue screen. If you do not get that Recovery Console ready to do the infection removal soon, the computer will become unbootable.
    ~Dr Jay

    Kerjifire

    • Guest
    Re: Google Redirect
    « Reply #36 on: March 05, 2010, 09:51:19 PM »
    Run from C:\Documents and Settings\S Chung\Desktop\maxlook.exe on Sat 06/03/2010 at 15:50:50.04

    No infected file found


    Dr Jay

    • Malware Removal Specialist


    • Specialist
    • Moderator emeritus
    • Thanked: 119
    • Experience: Guru
    • OS: Windows 10
    Re: Google Redirect
    « Reply #37 on: March 06, 2010, 01:29:51 AM »
    Please re-run Win32kDiag and post a log.
    ~Dr Jay

    Kerjifire

    • Guest
    Re: Google Redirect
    « Reply #38 on: March 06, 2010, 03:15:22 AM »
    Running from: C:\Documents and Settings\S Chung\Desktop\Win32kDiag.exe

    Log file at : C:\Documents and Settings\S Chung\Desktop\Win32kDiag.txt

    WARNING: Could not get backup privileges!

    Searching 'C:\WINDOWS'...





    Finished!

    Oh & HELP ME!, my Antivirus, Reg Mechanic, anti-spyware & Combat Arms can't access the interent/update.


    Dr Jay

    • Malware Removal Specialist


    • Specialist
    • Moderator emeritus
    • Thanked: 119
    • Experience: Guru
    • OS: Windows 10
    Re: Google Redirect
    « Reply #39 on: March 06, 2010, 08:05:52 AM »
    Re-run ComboFix and post a log, please.
    ~Dr Jay

    Kerjifire

    • Guest
    Re: Google Redirect
    « Reply #40 on: March 07, 2010, 03:41:03 AM »
    After running combofix, the PC reset and this came up.

    7/03/2010 9:31:46 PM   C:\WINDOWS\system32\drivers\atapi.sys [L] Win32:Alureon-FQ (0)
    File was successfully moved to chest...

    From Avast.

    & my Combofix folder went spaz. Look at picture

    [Saving space, attachment deleted by admin]

    Kerjifire

    • Guest
    Re: Google Redirect
    « Reply #41 on: March 07, 2010, 03:46:50 PM »
    *censored* DUDE!
    I can't boot up my PC, it keeps on reseting itself when it reaches the choose the OS system part. I CAN ONLY BOOT OFF MY WINDOWS CD & AM TALKING TO U VIA ANOTHER PC
    « Last Edit: March 07, 2010, 04:21:18 PM by Kerjifire »

    Dr Jay

    • Malware Removal Specialist


    • Specialist
    • Moderator emeritus
    • Thanked: 119
    • Experience: Guru
    • OS: Windows 10
    Re: Google Redirect
    « Reply #42 on: March 08, 2010, 02:04:43 PM »
    Silly avast.

    First
    ISOBurner this will allow you to burn OTLPE ISO to a cd and make it bootable. Just install the program, from there on in it is fairly automatic.  Instructions

    Second
    • Download OTLPE.iso and burn to a CD using ISO Burner. NOTE: This file is 292Mb in size so it may take some time to download.
    • When downloaded double click and this will then open ISOBurner to burn the file to CD
    • Reboot your system using the boot CD you just created.
    Note : If you do not know how to set your computer to boot from CD follow the steps here
    • Your system should now display a REATOGO-X-PE desktop.
    • Double-click on the OTLPE icon.
    • When asked "Do you wish to load the remote registry", select Yes
    • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
    • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
    • OTL should now start. Change the following settings
    • Change Drivers to Non-Microsoft
    • Press Run Scan to start the scan.
    • When finished, the file will be saved  in drive C:\_OTL\MovedFiles
    • Copy this file to your USB drive if you do not have internet connection on this system
    • Please post the contents of the OTL.txt file in your reply.
    [/list]
    ~Dr Jay

    Kerjifire

    • Guest
    Re: Google Redirect
    « Reply #43 on: March 09, 2010, 05:36:11 AM »
    OTL logfile created on: 3/9/2010 7:57:49 PM - Run
    OTLPE by OldTimer - Version 3.1.35.0     Folder = X:\Programs\OTLPE
    Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
     
    2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 87.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 97.00% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
     
    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 64.74 Gb Total Space | 15.68 Gb Free Space | 24.22% Space Free | Partition Type: NTFS
    Drive D: | 39.06 Gb Total Space | 20.66 Gb Free Space | 52.89% Space Free | Partition Type: NTFS
    Drive E: | 45.25 Gb Total Space | 11.29 Gb Free Space | 24.94% Space Free | Partition Type: NTFS
    Drive F: | 39.06 Gb Total Space | 4.55 Gb Free Space | 11.65% Space Free | Partition Type: NTFS
    Drive G: | 199.73 Gb Total Space | 135.39 Gb Free Space | 67.79% Space Free | Partition Type: NTFS
    Drive H: | 296.53 Gb Total Space | 13.07 Gb Free Space | 4.41% Space Free | Partition Type: NTFS
    Drive I: | 329.06 Gb Total Space | 214.31 Gb Free Space | 65.13% Space Free | Partition Type: NTFS
    Drive X: | 276.79 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
     
    Computer Name: REATOGO
    Current User Name: SYSTEM
    Logged in as Administrator.
     
    Current Boot Mode: Normal
    Scan Mode: All users
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Standard
    Using ControlSet: ControlSet001
     
    ========== Win32 Services (SafeList) ==========
     
    SRV - File not found [Auto] --  -- (ssrcc)
    SRV - File not found [Auto] --  -- (msrvc)
    SRV - File not found [Auto] --  -- (DNTVSchedulerPro)
    SRV - [2010/02/19 03:31:44 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
    SRV - [2010/02/11 13:53:39 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
    SRV - [2010/02/11 13:53:39 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
    SRV - [2010/02/11 13:53:39 | 000,040,384 | ---- | M] (ALWIL Software) [Auto] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
    SRV - [2010/01/07 00:07:10 | 000,236,368 | ---- | M] (Malwarebytes Corporation) [Auto] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2009/11/09 18:28:08 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto] -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
    SRV - [2009/11/05 22:29:22 | 001,141,712 | ---- | M] (PC Tools) [On_Demand] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
    SRV - [2009/10/29 19:18:16 | 000,359,624 | ---- | M] (PC Tools) [On_Demand] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
    SRV - [2009/07/19 20:28:10 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
    SRV - [2009/05/18 20:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
    SRV - [2009/02/15 09:10:22 | 002,402,184 | ---- | M] (Check Point Software Technologies LTD) [Auto] -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
    SRV - [2001/04/05 22:57:46 | 000,238,080 | ---- | M] (O&O Software GmbH) [Auto] -- C:\WINDOWS\System32\OOD2000.exe -- (OOD2000)
     
     
    ========== Driver Services (SafeList) ==========
     
    DRV - File not found [Kernel | On_Demand] --  -- (WDICA)
    DRV - File not found [Kernel | On_Demand] --  -- (Trufos)
    DRV - File not found [Kernel | Boot] --  -- (TfSysMon)
    DRV - File not found [Kernel | On_Demand] --  -- (TfNetMon)
    DRV - File not found [Kernel | Boot] --  -- (TfFsMon)
    DRV - File not found [Kernel | System] --  -- (SuperMounter)
    DRV - File not found [Kernel | On_Demand] --  -- (rootrepeal)
    DRV - File not found [Kernel | On_Demand] --  -- (Profos)
    DRV - File not found [Kernel | On_Demand] --  -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand] --  -- (PDRELI)
    DRV - File not found [Kernel | On_Demand] --  -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand] --  -- (PDCOMP)
    DRV - File not found [Kernel | System] --  -- (PCIDump)
    DRV - File not found [Kernel | On_Demand] --  -- (MEMSWEEP2)
    DRV - File not found [Kernel | System] --  -- (lbrtfdc)
    DRV - File not found [File_System | Boot] --  -- (Lbd)
    DRV - File not found [Kernel | System] --  -- (i2omgmt)
    DRV - File not found [Kernel | On_Demand] --  -- (gagp440p)
    DRV - File not found [Kernel | On_Demand] --  -- (EagleNT)
    DRV - File not found [Kernel | System] --  -- (Changer)
    DRV - File not found [Kernel | On_Demand] --  -- (catchme)
    DRV - File not found [Kernel | On_Demand] --  -- (BDRsDrv)
    DRV - File not found [Kernel | On_Demand] --  -- (BDFsDrv)
    DRV - File not found [Kernel | On_Demand] --  -- (bdfdll)
    DRV - [2010/02/16 04:48:18 | 000,017,984 | ---- | M] () [File_System | Auto] -- C:\WINDOWS\system32\WinFLdrv.sys -- (WinFLdrv)
    DRV - [2010/02/11 13:42:34 | 000,046,672 | ---- | M] (ALWIL Software) [Kernel | System] -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
    DRV - [2010/02/11 13:42:13 | 000,162,512 | ---- | M] (ALWIL Software) [Kernel | System] -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)
    DRV - [2010/02/11 13:39:01 | 000,023,376 | ---- | M] (ALWIL Software) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)
    DRV - [2010/02/11 13:38:34 | 000,100,432 | ---- | M] (ALWIL Software) [File_System | Auto] -- C:\WINDOWS\system32\drivers\aswmon2.sys -- (aswMon2)
    DRV - [2010/02/11 13:38:23 | 000,019,024 | ---- | M] (ALWIL Software) [File_System | Auto] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
    DRV - [2010/02/11 13:38:07 | 000,028,880 | ---- | M] (ALWIL Software) [Kernel | System] -- C:\WINDOWS\system32\drivers\aavmker4.sys -- (Aavmker4)
    DRV - [2010/02/02 23:52:08 | 004,605,952 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
    DRV - [2010/01/07 00:07:04 | 000,019,160 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
    DRV - [2009/11/22 16:43:30 | 000,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
    DRV - [2009/11/22 16:43:30 | 000,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
    DRV - [2009/11/22 16:43:28 | 000,074,480 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
    DRV - [2009/11/08 19:20:12 | 000,207,792 | ---- | M] (PC Tools) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
    DRV - [2009/09/27 20:22:00 | 000,298,752 | ---- | M] () [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
    DRV - [2009/07/28 05:49:05 | 000,033,408 | ---- | M] (B.H.A Corporation) [Kernel | System] -- C:\WINDOWS\system32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)
    DRV - [2009/06/17 11:56:16 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
    DRV - [2009/06/17 11:56:06 | 000,035,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
    DRV - [2009/06/17 11:55:34 | 000,010,384 | ---- | M] (Logitech, Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\LBeepKE.sys -- (LBeepKE)
    DRV - [2009/02/15 09:10:26 | 000,353,672 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
    DRV - [2008/12/18 08:44:00 | 000,028,816 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt)
    DRV - [2008/11/16 11:24:00 | 000,051,688 | ---- | M] (Check Point Software Technologies LTD) [Kernel | Boot] -- C:\WINDOWS\system32\ZoneLabs\srescan.sys -- (srescan)
    DRV - [2008/10/28 04:57:42 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
    DRV - [2008/09/23 18:40:22 | 004,122,368 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
    DRV - [2008/06/24 00:10:52 | 000,449,664 | R--- | M] (AfaTech                  ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\AF15BDA.sys -- (AF15BDA)
    DRV - [2008/04/13 13:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
    DRV - [2008/04/13 13:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
    DRV - [2008/01/23 23:09:34 | 000,048,904 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
    DRV - [2008/01/23 23:09:24 | 000,014,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
    DRV - [2008/01/23 23:09:04 | 000,028,168 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
    DRV - [2008/01/23 23:08:54 | 000,019,336 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
    DRV - [2008/01/23 16:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\tapvpn.sys -- (tapvpn)
    DRV - [2007/01/23 00:44:00 | 000,020,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
    DRV - [2004/12/09 10:25:49 | 000,047,104 | ---- | M] (Protection Technology) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
    DRV - [2004/12/03 05:20:41 | 000,020,544 | ---- | M] (Protection Technology) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
    DRV - [2004/10/28 05:47:59 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
    DRV - [2004/08/09 06:33:26 | 000,114,016 | ---- | M] (Protection Technology) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\prohlp02.sys -- (prohlp02)
    DRV - [2004/08/09 06:29:28 | 000,053,920 | ---- | M] (Protection Technology) [Kernel | System] -- C:\WINDOWS\System32\drivers\prodrv06.sys -- (prodrv06)
    DRV - [2004/08/03 07:39:32 | 000,020,864 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LwAdiHid.sys -- (lwadihid) Logitech WingMan Digital Devices(Auto-Detect)
    DRV - [2004/07/19 09:49:54 | 000,007,040 | ---- | M] (Protection Technology) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\prosync1.sys -- (prosync1)
    DRV - [2004/05/06 22:12:23 | 000,008,703 | R--- | M] (ASUSTeK Computer Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\EIO.sys -- (EIO)
    DRV - [2004/02/23 22:08:52 | 000,400,384 | ---- | M] (Sensaura) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS)
    DRV - [2003/12/01 10:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sfhlp01.sys -- (sfhlp01)
     
     
    ========== Standard Registry (SafeList) ==========
     
     
    ========== Internet Explorer ==========
     
    IE - HKLM\Software\Microsoft\Internet Explorer\Search,Local Page = http://www.Google.com/
    IE - HKLM\Software\Microsoft\Internet Explorer\Search,Local Page Restore =
     
     
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
     
     
    IE - HKU\CS_Chung_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
     
    IE - HKU\Guest_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
     
     
    IE - HKU\M_Chung_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
    IE - HKU\M_Chung_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
    IE - HKU\M_Chung_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
     
     
    IE - HKU\S_Chung_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    IE - HKU\S_Chung_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
    IE - HKU\S_Chung_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
    IE - HKU\S_Chung_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
    IE - HKU\S_Chung_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S_Chung_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
    IE - HKU\S_Chung_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8080
     
     
    FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/10/14 06:33:02 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/21 02:47:10 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/21 02:47:09 | 000,000,000 | ---D | M]
     
    [2010/03/06 06:04:42 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2009/06/08 06:29:36 | 000,239,432 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
     
    O1 HOSTS File: ([2010/02/04 03:21:29 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1       localhost
    O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
    O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
    O3 - HKU\CS_Chung_ON_C\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    O3 - HKU\CS_Chung_ON_C\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O3 - HKU\Guest_ON_C\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
    O3 - HKU\M_Chung_ON_C\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O3 - HKU\M_Chung_ON_C\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
    O3 - HKU\S_Chung_ON_C\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O3 - HKU\S_Chung_ON_C\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
    O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
    O4 - HKLM..\Run: [DNTVSchedulerProTray Icon] C:\Program Files\DNTV Scheduler Pro\DNTVSchedulerProTray.exe (Renura Enterprises Pty Ltd)
    O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
    O4 - HKLM..\Run: [OpwareSE2] C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
    O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
    O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
    O4 - HKU\.DEFAULT..\Run: [DWQueuedReporting] C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE (Microsoft Corporation)
    O4 - HKU\S_Chung_ON_C..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
    O4 - HKU\S_Chung_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
    O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\CS_Chung_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\Guest_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\LocalService.NT_AUTHORITY_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\M_Chung_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\NetworkService.NT_AUTHORITY_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S_Chung_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S_Chung_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S_Chung_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
    O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab (Symantec AntiVirus scanner)
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1256421470390 (WUWebControl Class)
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab (CBreakshotControl Class)
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
    O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
    O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
    O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2005/04/06 08:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O32 - AutoRun File - [2005/04/06 08:15:00 | 000,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ NTFS ]
    O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
    O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
    O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
    O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
     
    ========== Files/Folders - Created Within 30 Days ==========
     
    [2010/03/07 05:14:08 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/03/07 05:14:08 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/03/07 05:14:08 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/03/07 05:14:08 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/03/07 05:13:55 | 000,000,000 | --SD | C] -- C:\ComboFix
    [2010/03/07 04:39:30 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2010/03/06 23:37:55 | 000,155,648 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\Oemdspif.dll
    [2010/03/06 23:37:54 | 000,446,464 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\ATIDEMGX.dll
    [2010/03/06 23:37:54 | 000,045,056 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\System32\aticalrt.dll
    [2010/03/06 23:37:54 | 000,043,520 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\ati2edxx.dll
    [2010/03/06 23:37:54 | 000,017,408 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\atitvo32.dll
    [2010/03/06 23:37:53 | 014,188,544 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\atioglxx.dll
    [2010/03/06 23:37:53 | 003,633,152 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\System32\aticaldd.dll
    [2010/03/06 23:37:53 | 000,565,248 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\atikvmag.dll
    [2010/03/06 23:37:53 | 000,397,312 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\atiok3x2.dll
    [2010/03/06 23:37:53 | 000,311,296 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\atiiiexx.dll
    [2010/03/06 23:37:53 | 000,301,568 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2dvag.dll
    [2010/03/06 23:37:53 | 000,208,896 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\atipdlxx.dll
    [2010/03/06 23:37:53 | 000,180,224 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\atiadlxx.dll
    [2010/03/06 23:37:53 | 000,159,744 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2evxx.dll
    [2010/03/06 23:37:53 | 000,143,360 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\atiapfxx.exe
    [2010/03/06 23:37:53 | 000,118,784 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\atibtmon.exe
    [2010/03/06 23:37:53 | 000,065,024 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\System32\atimpc32.dll
    [2010/03/06 23:37:53 | 000,065,024 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\System32\amdpcom32.dll
    [2010/03/06 23:37:53 | 000,053,248 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati2erec.dll
    [2010/03/06 23:37:53 | 000,053,248 | ---- | C] ( ATI Technologies Inc.) -- C:\WINDOWS\System32\ATIDDC.DLL
    [2010/03/06 23:37:53 | 000,045,056 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\System32\aticalcl.dll
    [2010/03/06 23:37:53 | 000,026,112 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\Ati2mdxx.exe
    [2010/03/06 23:37:53 | 000,024,064 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\ativcoxx.dll
    [2010/03/06 23:37:16 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
    [2010/03/06 23:37:11 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
    [2010/03/06 23:36:29 | 000,000,000 | ---D | C] -- C:\ATI
    [2010/03/06 23:18:25 | 000,073,216 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atintuxx.sys
    [2010/03/06 23:18:25 | 000,073,216 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atintuxx.sys
    [2010/03/06 23:18:25 | 000,063,488 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinxsxx.sys
    [2010/03/06 23:18:25 | 000,063,488 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinxsxx.sys
    [2010/03/06 23:18:25 | 000,031,744 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinxbxx.sys
    [2010/03/06 23:18:25 | 000,031,744 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinxbxx.sys
    [2010/03/06 23:18:24 | 000,028,672 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinsnxx.sys
    [2010/03/06 23:18:24 | 000,028,672 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinsnxx.sys
    [2010/03/06 23:18:24 | 000,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinttxx.sys
    [2010/03/06 23:18:24 | 000,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinttxx.sys
    [2010/03/06 23:18:23 | 000,104,960 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinrvxx.sys
    [2010/03/06 23:18:23 | 000,104,960 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinrvxx.sys
    [2010/03/06 23:18:23 | 000,052,224 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinraxx.sys
    [2010/03/06 23:18:23 | 000,052,224 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinraxx.sys
    [2010/03/06 23:18:23 | 000,014,336 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinpdxx.sys
    [2010/03/06 23:18:23 | 000,014,336 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinpdxx.sys
    [2010/03/06 23:18:22 | 000,057,856 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinbtxx.sys
    [2010/03/06 23:18:22 | 000,057,856 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinbtxx.sys
    [2010/03/06 23:18:22 | 000,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinmdxx.sys
    [2010/03/06 23:18:22 | 000,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinmdxx.sys
    [2010/03/06 23:17:13 | 000,000,000 | ---D | C] -- C:\Program Files\Phyxion.net
    [2010/03/05 23:41:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\maxdriver
    [2010/03/05 18:03:07 | 000,000,000 | -HSD | C] -- C:\WINDOWS\system32\config\systemprofile\Cookies
    [2010/03/04 02:39:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S Chung\Application Data\mIRC
    [2010/03/03 05:04:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S Chung\My Documents\8R Buttons
    [2010/03/02 04:08:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NSS
    [2010/03/02 04:08:56 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Security Scan
    [2010/03/02 04:08:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NSS\0207000.034
    [2010/03/02 04:08:51 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
    [2010/03/02 03:08:38 | 000,000,000 | ---D | C] -- C:\_OTS
    [2010/03/02 02:57:18 | 000,000,000 | ---D | C] -- C:\_OTL
    [2010/02/28 03:43:11 | 000,632,832 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\S Chung\Desktop\OTS.exe
    [2010/02/26 23:40:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\CS Chung\Application Data\Logitech
    [2010/02/26 18:36:01 | 000,000,000 | ---D | C] -- C:\Program Files\WhoCrashed
    [2010/02/25 03:24:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S Chung\Desktop\Ratings
    [2010/02/25 03:15:25 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2010/02/25 02:28:05 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2010/02/25 01:13:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S Chung\Desktop\avenger
    [2010/02/23 06:21:45 | 000,000,000 | ---D | C] -- C:\Program Files\Combined Community Codec Pack
    [2010/02/23 06:16:56 | 000,000,000 | ---D | C] -- C:\Program Files\Xvid
    [2010/02/23 00:53:05 | 000,000,000 | ---D | C] -- C:\Program Files\MegaLeecher
    [2010/02/22 02:22:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S Chung\Application Data\uTorrent
    [2010/02/19 02:58:38 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/02/19 02:58:36 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/02/19 02:58:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/02/17 06:23:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
    [2010/02/16 05:18:01 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\S Chung\Recent
    [2010/02/16 03:51:11 | 000,126,976 | ---- | C] (Adavanced Systems ) -- C:\WINDOWS\System32\tton.ocx
    [2010/02/16 01:37:14 | 000,000,000 | ---D | C] -- C:\Program Files\Audio Mid Recorder
    [2010/02/13 00:29:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S Chung\Application Data\dvdcss
    [2010/02/12 06:04:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S Chung\Application Data\vlc
    [2010/02/11 06:24:36 | 000,000,000 | R--D | C] -- C:\Documents and Settings\S Chung\My Documents\My Music
    [2010/02/11 01:29:56 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
    [2010/02/10 06:12:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S Chung\Application Data\AVS4YOU
    [2010/02/10 06:09:27 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\GdiPlus.dll
    [2010/02/10 05:32:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S Chung\My Documents\Adobe Programs
    [9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    Kerjifire

    • Guest
    Re: Google Redirect
    « Reply #44 on: March 09, 2010, 05:36:45 AM »

    [6 C:\Documents and Settings\M Chung\My Documents\*.tmp files -> C:\Documents and Settings\M Chung\My Documents\*.tmp -> ]
    [32 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [14 C:\Documents and Settings\S Chung\My Documents\*.tmp files -> C:\Documents and Settings\S Chung\My Documents\*.tmp -> ]
     
    ========== Files - Modified Within 30 Days ==========
     
    [2010/03/09 19:54:17 | 000,524,288 | ---- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
    [2010/03/07 05:43:08 | 000,262,144 | ---- | M] () -- C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT
    [2010/03/07 05:43:08 | 000,233,472 | ---- | M] () -- C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT
    [2010/03/07 05:43:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/03/07 05:43:00 | 009,437,184 | ---- | M] () -- C:\Documents and Settings\S Chung\NTUSER.DAT
    [2010/03/07 05:42:58 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\S Chung\ntuser.ini
    [2010/03/07 05:31:10 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/03/07 05:30:24 | 000,350,192 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
    [2010/03/07 05:30:13 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
    [2010/03/07 05:29:55 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/03/07 05:29:26 | 2147,012,608 | -HS- | M] () -- C:\hiberfil.sys
    [2010/03/07 05:29:25 | 2145,386,496 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
    [2010/03/07 05:00:18 | 004,121,899 | R--- | M] () -- C:\Documents and Settings\S Chung\Desktop\ComboFix.exe
    [2010/03/07 04:14:37 | 000,051,200 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\maths PROBLEMS Part 4.doc
    [2010/03/06 23:13:09 | 000,000,051 | ---- | M] () -- C:\WINDOWS\WININIT.INI
    [2010/03/06 22:21:40 | 000,000,508 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\Combat Arms.lnk
    [2010/03/06 00:52:28 | 003,932,160 | ---- | M] () -- C:\Documents and Settings\CS Chung\ntuser.dat.rmbak
    [2010/03/06 00:52:28 | 000,233,472 | ---- | M] () -- C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.rmbak
    [2010/03/06 00:51:45 | 009,699,328 | ---- | M] () -- C:\Documents and Settings\S Chung\ntuser.dat.rmbak
    [2010/03/06 00:51:17 | 003,731,456 | ---- | M] () -- C:\Documents and Settings\M Chung\NTUSER.DAT
    [2010/03/06 00:51:17 | 000,774,144 | ---- | M] () -- C:\Documents and Settings\Guest\NTUSER.DAT
    [2010/03/06 00:51:17 | 000,462,848 | ---- | M] () -- C:\Documents and Settings\Administrator\s-1-5-21-1935655697-688789844-1801674531-500.rrr
    [2010/03/06 00:51:15 | 003,702,784 | ---- | M] () -- C:\Documents and Settings\CS Chung\NTUSER.DAT
    [2010/03/06 00:50:53 | 000,233,472 | ---- | M] () -- C:\Documents and Settings\LocalService.NT AUTHORITY\s-1-5-19.rrr
    [2010/03/05 20:13:49 | 000,007,410 | ---- | M] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100306_121346.reg
    [2010/03/05 18:57:28 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
    [2010/03/05 18:57:28 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
    [2010/03/05 18:57:28 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
    [2010/03/05 18:57:28 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
    [2010/03/05 18:00:06 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\CS Chung\ntuser.ini
    [2010/03/05 17:59:52 | 000,000,082 | ---- | M] () -- C:\WINDOWS\SuperUtil.ini
    [2010/03/05 17:59:22 | 000,443,588 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/03/05 17:59:22 | 000,071,846 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/03/05 05:40:27 | 000,164,864 | ---- | M] () -- C:\Documents and Settings\S Chung\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/03/04 05:33:46 | 000,038,197 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\flashvortex1.swf
    [2010/03/04 05:11:47 | 000,086,038 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\flashvortex.swf
    [2010/03/04 03:08:51 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
    [2010/03/04 03:05:24 | 000,060,056 | ---- | M] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100304_190440.reg
    [2010/03/04 00:40:52 | 001,138,992 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\maxlook.exe
    [2010/03/03 03:56:21 | 000,172,335 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\avatar_1218.gif
    [2010/03/03 00:41:40 | 000,047,616 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\Win32kDiag.exe
    [2010/03/02 07:24:28 | 000,023,552 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\China Essay.doc
    [2010/03/02 05:45:59 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2010/03/02 05:45:28 | 007,520,288 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\SUPERAntiSpyware.exe
    [2010/03/02 05:41:16 | 000,000,476 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for S Chung.job
    [2010/03/02 04:08:56 | 000,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\NSS\0207000.034\isolate.ini
    [2010/03/02 03:16:23 | 000,100,908 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\SystemLook.exe
    [2010/03/01 06:21:08 | 000,000,490 | ---- | M] () -- C:\WINDOWS\tasks\Install_NSS.job
    [2010/02/28 03:43:15 | 000,632,832 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\S Chung\Desktop\OTS.exe
    [2010/02/27 01:53:10 | 000,028,160 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\test.doc
    [2010/02/26 23:40:38 | 000,149,440 | ---- | M] () -- C:\Documents and Settings\CS Chung\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    [2010/02/26 20:01:07 | 000,638,548 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\GetSystemInfo_CSC2_S Chung_2010_02_27_11_54_57.zip
    [2010/02/26 18:36:01 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\WhoCrashed.lnk
    [2010/02/26 06:32:31 | 003,729,202 | -H-- | M] () -- C:\Documents and Settings\S Chung\Local Settings\Application Data\IconCache.db
    [2010/02/26 06:13:46 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cab6d4c3b7d16a.job
    [2010/02/26 01:07:29 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\S Chung\My Documents\~$THS PROBLEMS Part 4.doc
    [2010/02/25 05:23:35 | 001,190,400 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\Should Australia Have An R Rating For Games.ppt
    [2010/02/25 02:59:28 | 000,009,654 | ---- | M] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100225_185909.reg
    [2010/02/25 02:45:12 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/02/25 02:28:12 | 000,000,330 | RHS- | M] () -- C:\boot.ini
    [2010/02/24 05:44:38 | 000,724,952 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\avenger.zip
    [2010/02/24 05:25:19 | 000,028,672 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\Australia should have an R rating for games.doc
    [2010/02/24 05:20:59 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\S Chung\My Documents\~$stralia should have an R rating for games.doc
    [2010/02/22 19:11:28 | 000,085,797 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\Cheetah-Anti-Rogue.cmd
    [2010/02/22 04:02:53 | 000,001,015 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\Shortcut to HprSnap6.lnk
    [2010/02/21 04:37:49 | 000,032,256 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\Maths Questions.doc
    [2010/02/19 02:58:44 | 000,000,500 | ---- | M] () -- C:\WINDOWS\tasks\Malwarebytes' Scheduled Scan for S Chung.job
    [2010/02/18 02:58:58 | 000,093,174 | ---- | M] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100218_185746.reg
    [2010/02/16 05:19:15 | 000,021,504 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\The Most Dangerous Game Review.doc
    [2010/02/16 05:17:51 | 000,009,036 | -HS- | M] () -- C:\WINDOWS\System32\sys_drv.dat
    [2010/02/16 05:17:51 | 000,006,024 | -HS- | M] () -- C:\WINDOWS\System32\sys_drv_2.dat
    [2010/02/16 05:17:36 | 000,000,990 | -HS- | M] () -- C:\Documents and Settings\S Chung\Application Data\systemfl.$dk
    [2010/02/16 04:48:20 | 000,180,224 | ---- | M] () -- C:\WINDOWS\System32\WinVd32.sys
    [2010/02/16 04:48:18 | 000,017,984 | ---- | M] () -- C:\WINDOWS\System32\WinFLdrv.sys
    [2010/02/16 04:48:18 | 000,007,680 | ---- | M] () -- C:\WINDOWS\System32\WinFLsrv.exe
    [2010/02/16 02:50:28 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\S Chung\My Documents\~$e Most Dangerous Game Review.doc
    [2010/02/16 01:44:19 | 000,000,067 | ---- | M] () -- C:\WINDOWS\AudioMidRecorder.INI
    [2010/02/13 19:36:30 | 003,932,160 | ---- | M] () -- C:\Documents and Settings\M Chung\ntuser.dat.rmbak
    [2010/02/13 00:25:01 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\S Chung\My Documents\Women drivers are safer than men drivers.doc
    [2010/02/12 05:54:34 | 000,000,482 | ---- | M] () -- C:\Documents and Settings\S Chung\Desktop\Fraps.lnk
    [2010/02/12 00:54:27 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
    [2010/02/12 00:43:28 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/02/11 13:53:57 | 000,038,848 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\avastSS.scr
    [2010/02/11 13:53:36 | 000,153,184 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
    [2010/02/11 13:42:34 | 000,046,672 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
    [2010/02/11 13:42:13 | 000,162,512 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
    [2010/02/11 13:39:01 | 000,023,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
    [2010/02/11 13:38:34 | 000,100,432 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
    [2010/02/11 13:38:31 | 000,094,800 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
    [2010/02/11 13:38:23 | 000,019,024 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
    [2010/02/11 13:38:07 | 000,028,880 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
    [2010/02/11 01:58:49 | 000,004,690 | ---- | M] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100211_175828.reg
    [2010/02/10 05:22:10 | 000,007,292 | ---- | M] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100210_212206.reg
    [9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [6 C:\Documents and Settings\M Chung\My Documents\*.tmp files -> C:\Documents and Settings\M Chung\My Documents\*.tmp -> ]
    [32 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [14 C:\Documents and Settings\S Chung\My Documents\*.tmp files -> C:\Documents and Settings\S Chung\My Documents\*.tmp -> ]
     
    ========== Files Created - No Company Name ==========
     
    [2010/03/07 05:14:08 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/03/07 05:14:08 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/03/07 05:14:08 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/03/07 05:14:08 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/03/07 05:14:08 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/03/06 23:44:18 | 2147,012,608 | -HS- | C] () -- C:\hiberfil.sys
    [2010/03/06 23:37:55 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
    [2010/03/06 23:37:54 | 000,455,520 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.cap
    [2010/03/06 23:37:53 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\ATIODE.exe
    [2010/03/06 23:37:53 | 000,198,341 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
    [2010/03/06 23:37:53 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ATIODCLI.exe
    [2010/03/06 23:37:53 | 000,031,240 | ---- | C] () -- C:\WINDOWS\System32\atiapfxx.blb
    [2010/03/06 23:37:53 | 000,020,274 | ---- | C] () -- C:\WINDOWS\atiogl.xml
    [2010/03/06 23:37:53 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
    [2010/03/06 06:43:07 | 000,000,508 | ---- | C] () -- C:\Documents and Settings\S Chung\Desktop\Combat Arms.lnk
    [2010/03/05 20:13:47 | 000,007,410 | ---- | C] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100306_121346.reg
    [2010/03/05 17:45:39 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
    [2010/03/05 17:45:39 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
    [2010/03/05 17:45:39 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
    [2010/03/05 17:45:39 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
    [2010/03/05 06:47:19 | 000,000,082 | ---- | C] () -- C:\WINDOWS\SuperUtil.ini
    [2010/03/04 05:33:46 | 000,038,197 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\flashvortex1.swf
    [2010/03/04 05:11:47 | 000,086,038 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\flashvortex.swf
    [2010/03/04 03:04:41 | 000,060,056 | ---- | C] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100304_190440.reg
    [2010/03/04 00:40:51 | 001,138,992 | ---- | C] () -- C:\Documents and Settings\S Chung\Desktop\maxlook.exe
    [2010/03/03 03:56:20 | 000,172,335 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\avatar_1218.gif
    [2010/03/03 00:41:39 | 000,047,616 | ---- | C] () -- C:\Documents and Settings\S Chung\Desktop\Win32kDiag.exe
    [2010/03/02 05:45:59 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\S Chung\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2010/03/02 05:45:24 | 007,520,288 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\SUPERAntiSpyware.exe
    [2010/03/02 05:41:16 | 000,000,476 | ---- | C] () -- C:\WINDOWS\tasks\Norton Security Scan for S Chung.job
    [2010/03/02 04:08:56 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\NSS\0207000.034\isolate.ini
    [2010/03/02 03:16:23 | 000,100,908 | ---- | C] () -- C:\Documents and Settings\S Chung\Desktop\SystemLook.exe
    [2010/03/02 02:52:56 | 000,023,552 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\China Essay.doc
    [2010/03/01 06:21:08 | 000,000,490 | ---- | C] () -- C:\WINDOWS\tasks\Install_NSS.job
    [2010/02/27 01:52:58 | 000,028,160 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\test.doc
    [2010/02/26 23:06:08 | 004,121,899 | R--- | C] () -- C:\Documents and Settings\S Chung\Desktop\ComboFix.exe
    [2010/02/26 19:55:08 | 000,638,548 | ---- | C] () -- C:\Documents and Settings\S Chung\Desktop\GetSystemInfo_CSC2_S Chung_2010_02_27_11_54_57.zip
    [2010/02/26 18:36:01 | 000,000,654 | ---- | C] () -- C:\Documents and Settings\S Chung\Desktop\WhoCrashed.lnk
    [2010/02/26 06:13:46 | 000,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cab6d4c3b7d16a.job
    [2010/02/26 01:07:29 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\S Chung\My Documents\~$THS PROBLEMS Part 4.doc
    [2010/02/26 00:47:19 | 000,085,797 | ---- | C] () -- C:\Documents and Settings\S Chung\Desktop\Cheetah-Anti-Rogue.cmd
    [2010/02/25 04:05:09 | 001,190,400 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\Should Australia Have An R Rating For Games.ppt
    [2010/02/25 02:59:11 | 000,009,654 | ---- | C] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100225_185909.reg
    [2010/02/25 02:28:11 | 000,000,260 | ---- | C] () -- C:\Boot.bak
    [2010/02/25 02:28:08 | 000,260,272 | ---- | C] () -- C:\cmldr
    [2010/02/24 05:44:37 | 000,724,952 | ---- | C] () -- C:\Documents and Settings\S Chung\Desktop\avenger.zip
    [2010/02/24 05:20:59 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\S Chung\My Documents\~$stralia should have an R rating for games.doc
    [2010/02/23 06:16:57 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2010/02/23 06:16:57 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2010/02/22 05:46:38 | 000,051,200 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\maths PROBLEMS Part 4.doc
    [2010/02/22 04:01:06 | 000,001,015 | ---- | C] () -- C:\Documents and Settings\S Chung\Desktop\Shortcut to HprSnap6.lnk
    [2010/02/22 03:28:38 | 000,028,672 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\Australia should have an R rating for games.doc
    [2010/02/21 03:08:33 | 000,032,256 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\Maths Questions.doc
    [2010/02/19 02:58:44 | 000,000,500 | ---- | C] () -- C:\WINDOWS\tasks\Malwarebytes' Scheduled Scan for S Chung.job
    [2010/02/18 02:57:48 | 000,093,174 | ---- | C] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100218_185746.reg
    [2010/02/16 04:48:23 | 000,009,036 | -HS- | C] () -- C:\WINDOWS\System32\sys_drv.dat
    [2010/02/16 04:48:23 | 000,006,024 | -HS- | C] () -- C:\WINDOWS\System32\sys_drv_2.dat
    [2010/02/16 04:48:20 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\WinVd32.sys
    [2010/02/16 04:48:18 | 000,017,984 | ---- | C] () -- C:\WINDOWS\System32\WinFLdrv.sys
    [2010/02/16 04:48:18 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\WinFLsrv.exe
    [2010/02/16 04:48:17 | 000,000,990 | -HS- | C] () -- C:\Documents and Settings\S Chung\Application Data\systemfl.$dk
    [2010/02/16 04:48:05 | 000,033,982 | ---- | C] () -- C:\WINDOWS\System32\flk-icon.ico
    [2010/02/16 02:50:28 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\S Chung\My Documents\~$e Most Dangerous Game Review.doc
    [2010/02/16 01:37:31 | 000,000,067 | ---- | C] () -- C:\WINDOWS\AudioMidRecorder.INI
    [2010/02/15 05:41:01 | 000,021,504 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\The Most Dangerous Game Review.doc
    [2010/02/13 00:25:00 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\S Chung\My Documents\Women drivers are safer than men drivers.doc
    [2010/02/11 01:58:30 | 000,004,690 | ---- | C] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100211_175828.reg
    [2010/02/10 05:22:07 | 000,007,292 | ---- | C] () -- C:\Documents and Settings\CS Chung\My Documents\cc_20100210_212206.reg
    [2010/01/25 22:08:06 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
    [2010/01/25 00:03:25 | 000,000,532 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
    [2009/12/14 23:08:59 | 000,000,355 | ---- | C] () -- C:\WINDOWS\Sonic3K.INI
    [2009/12/14 03:02:54 | 000,075,600 | ---- | C] () -- C:\Documents and Settings\S Chung\Application Data\ReplayMusicLog.log
    [2009/11/24 05:45:51 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
    [2009/11/23 06:02:51 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
    [2009/11/09 14:17:25 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\CS Chung\Local Settings\Application Data\housecall.guid.cache
    [2009/10/26 06:13:43 | 000,000,068 | ---- | C] () -- C:\WINDOWS\MyProg.ini
    [2009/10/24 04:07:25 | 000,298,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\yk51x86.sys
    [2009/09/10 19:00:34 | 000,041,872 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
    [2009/08/03 00:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
    [2009/07/28 06:28:32 | 000,305,408 | ---- | C] () -- C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\FontCache3.0.0.0.dat
    [2009/07/25 05:36:54 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\CS Chung\Local Settings\Application Data\fusioncache.dat
    [2009/07/24 04:00:27 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
    [2009/07/04 00:06:18 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\S Chung\Local Settings\Application Data\fusioncache.dat
    [2009/05/27 05:40:54 | 000,001,814 | ---- | C] () -- C:\WINDOWS\HprSnap.INI
    [2009/05/26 04:19:33 | 000,000,051 | ---- | C] () -- C:\WINDOWS\WININIT.INI
    [2009/05/22 08:10:40 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\ood2kmsg.dll
    [2009/05/22 08:10:39 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\OODCSPRO.dll
    [2008/11/11 15:59:33 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
    [2008/11/05 06:58:55 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
    [2008/10/11 17:36:19 | 000,000,022 | ---- | C] () -- C:\WINDOWS\REGPSD20.INI
    [2008/10/11 17:36:11 | 000,000,037 | ---- | C] () -- C:\WINDOWS\Viewer.ini
    [2008/10/11 17:36:06 | 000,000,778 | ---- | C] () -- C:\WINDOWS\PSDEWIN.INI
    [2008/10/11 17:36:06 | 000,000,080 | ---- | C] () -- C:\WINDOWS\psdxport.ini
    [2008/08/18 16:07:05 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\CS Chung\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2008/07/03 02:38:01 | 000,138,576 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
    [2008/07/03 02:38:01 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\S Chung\Application Data\PnkBstrK.sys
    [2008/01/28 06:05:33 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\KMVIDC32.DLL
    [2007/12/06 00:59:26 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\M Chung\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/10/22 04:47:36 | 000,000,059 | ---- | C] () -- C:\Documents and Settings\S Chung\Application Data\AVSDVDPlayer.m3u
    [2007/09/08 02:06:57 | 000,000,745 | ---- | C] () -- C:\WINDOWS\CoD.INI
    [2007/08/25 00:38:36 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\CS Chung\Application Data\AVSDVDPlayer.m3u
    [2007/08/04 06:51:55 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
    [2007/07/04 06:26:05 | 000,164,864 | ---- | C] () -- C:\Documents and Settings\S Chung\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/06/30 00:02:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
    [2007/06/27 02:11:04 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2007/06/18 05:09:05 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2007/06/15 05:12:31 | 000,087,808 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
    [2007/06/15 04:01:19 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS7M.DLL
    [2007/06/14 06:28:12 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
    [2004/11/28 17:09:03 | 000,086,016 | -H-- | C] () -- C:\WINDOWS\System32\DNT4.dll
    [2004/11/28 17:05:56 | 000,086,016 | -H-- | C] () -- C:\WINDOWS\System32\DNT3.dll
    [2004/11/27 23:28:03 | 000,086,016 | -H-- | C] () -- C:\WINDOWS\System32\DNT2.dll
    [2004/11/27 23:11:01 | 000,086,016 | -H-- | C] () -- C:\WINDOWS\System32\DNT1.dll
    [2004/08/03 19:56:46 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
    [2003/07/08 07:04:46 | 000,000,015 | ---- | C] () -- C:\WINDOWS\System32\caacedfedaadeca.dll
     
    ========== LOP Check ==========
     
    [2009/05/30 20:05:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\CS Chung\Application Data\Canon
    [2008/06/29 01:45:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\CS Chung\Application Data\CD-LabelPrint
    [2009/07/25 05:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\CS Chung\Application Data\Cuttermaran
    [2009/01/28 02:33:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\CS Chung\Application Data\HiYo
    [2009/07/28 06:19:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\CS Chung\Application Data\Pegasys Inc
    [2009/11/09 14:31:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\CS Chung\Application Data\QuickScan
    [2009/08/09 08:10:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\CS Chung\Application Data\VideoReDo-TVSuite
    [2009/08/05 07:04:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\CS Chung\Application Data\VideoReDoPlus
    [2009/02/28 18:28:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M Chung\Application Data\HiYo
    [2009/07/24 18:49:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M Chung\Application Data\My Battle for Middle-earth Files
    [2007/07/01 21:16:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M Chung\Application Data\Sierra
    [2007/11/24 06:25:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M Chung\Application Data\Thunderbird
    [2009/11/25 06:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\Any Video Converter
    [2010/01/29 02:54:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\Auslogics
    [2010/01/25 01:03:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\Error Fix
    [2010/01/22 19:38:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\Leadertech
    [2009/11/26 03:29:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\Mp3tag
    [2009/12/13 22:06:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\My Battle for Middle-earth(tm) II Files
    [2009/11/19 05:14:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\Registry Mechanic
    [2010/01/25 00:03:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\ScanSoft
    [2010/01/25 23:16:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\Simply Super Software
    [2009/11/19 18:15:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\Ubisoft
    [2010/03/05 07:42:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S Chung\Application Data\uTorrent
    [2010/03/05 18:57:28 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
    [2010/03/05 18:57:28 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
    [2010/03/05 18:57:28 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
    [2010/03/05 18:57:28 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
    [2010/03/01 06:21:08 | 000,000,490 | ---- | M] () -- C:\WINDOWS\Tasks\Install_NSS.job
     
    ========== Purity Check ==========
     
     
    < End of report >