OTL logfile created on: 23/10/2009 10:21:19 - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Documents and Settings\admin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
503.48 Mb Total Physical Memory | 170.71 Mb Available Physical Memory | 33.91% Memory free
1.20 Gb Paging File | 0.92 Gb Available in Paging File | 76.80% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 65.38 Gb Free Space | 87.73% Space Free | Partition Type: NTFS
Drive D: | 702.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ADMIN-434ECF3F8
Current User Name: admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\taskmgr.exe (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Net Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\System32\HPZinw12.dll (Hewlett-Packard)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\System32\HPZipm12.dll (Hewlett-Packard)
========== Driver Services (SafeList) ==========
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (STAC97NA [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\stac97na.sys (SigmaTel Inc.)
DRV - (STAC97NH [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\stac97nh.sys (SigmaTel Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\admin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\System32\ATL.DLL (Microsoft Corporation)
MOD - C:\WINDOWS\System32\LINKINFO.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\ntshrui.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mail.live.com...x?wa=wsignin1.0
IE - HKCU\..\URLSearchHook: *{6E6624DD-AB4A-45E9-B9B7-393CB62C45ED} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/10/01 10:49:40 | 00,000,000 | ---D | M]
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MRT] C:\WINDOWS\System32\MRT.exe (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKCU..\Run: [ms18_word] C:\Documents and Settings\admin\ms18_word.exe File not found
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.micros...ntent/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail....ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\explorer.exe: Debugger - C:\Program Files\Microsoft Common\svchost.exe File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/12 17:07:37 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
========== Files/Folders - Created Within 30 Days ==========
[5 C:\WINDOWS\*.tmp files]
[2009/10/08 14:33:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/10/08 14:32:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2009/10/19 16:01:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/08 14:18:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Application Data\AVG8
[2009/10/01 10:51:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Application Data\HPAppData
[2009/10/15 11:32:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Local Settings\Application Data\PCHealth
[3 C:\Documents and Settings\admin\My Documents\*.tmp files]
[2009/10/08 14:32:48 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/10/19 13:40:07 | 00,000,000 | ---D | C] -- C:\Program Files\Backup&Synchronize Pro
[2009/10/20 12:12:04 | 00,000,000 | ---D | C] -- C:\Program Files\backups
[2009/10/23 10:00:43 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\admin\Desktop\OTL.exe
[2009/10/22 15:20:16 | 00,000,000 | --SD | C] -- C:\ComboFix
[2009/10/22 11:35:05 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/10/22 11:35:05 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/10/22 11:35:05 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/10/22 11:35:05 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/10/22 11:34:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/10/22 11:33:57 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/10/19 13:40:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\RD Technologies
[2009/10/19 13:40:09 | 00,587,456 | ---- | C] (Xceed Software Inc (450) 442-2626 support@xceedsoft.com www.xceedsoft.com) -- C:\WINDOWS\System32\XceedZip.dll
[2009/10/19 13:40:09 | 00,413,696 | ---- | C] (Polar info@polarsoftware.com www.polarsoftware.com) -- C:\WINDOWS\System32\PolarCryptoLight.dll
[2009/10/16 10:27:49 | 00,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Program Files\HijackThis.exe
[2009/10/15 17:03:02 | 01,396,264 | ---- | C] (Microsoft Corporation) -- C:\WindowsXP-KB948277-x86-ENU.exe
[2009/10/15 12:27:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/10/15 12:13:45 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/10/08 14:51:04 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2009/10/08 14:33:47 | 00,108,552 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/10/08 14:33:47 | 00,011,952 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/10/08 14:33:39 | 00,335,240 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/10/08 14:33:38 | 00,027,784 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/10/08 14:33:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2009/10/01 10:48:59 | 00,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
[2009/10/01 10:31:04 | 00,000,000 | R--D | C] -- C:\Documents and Settings\admin\My Documents\My Music
[2009/10/01 10:26:08 | 00,100,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/10/01 10:25:55 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/10/01 10:25:29 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll
[2009/10/01 10:25:28 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/10/01 10:25:28 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/10/01 10:25:27 | 11,069,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/10/01 10:25:27 | 01,985,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/10/01 10:25:27 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll
[2009/10/01 10:25:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2009/10/01 10:22:03 | 25,198,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/10/01 10:18:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\My Documents\Shoe Pics
[2009/10/01 10:17:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\My Documents\Signs for shop
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[3 C:\Documents and Settings\admin\My Documents\*.tmp files]
[2009/10/23 10:15:48 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin\Desktop\OTL.exe
[2009/10/23 09:57:42 | 43,629,494 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/10/23 09:57:42 | 00,048,786 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/10/23 09:55:10 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2009/10/23 09:55:06 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/23 09:55:03 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/21 16:09:20 | 00,023,932 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Current Sale Stock.docx
[2009/10/21 15:36:18 | 00,565,746 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Autumn Winter Stock.rtf
[2009/10/21 11:46:26 | 03,351,153 | R--- | M] () -- C:\Documents and Settings\admin\Desktop\ComboFix.exe
[2009/10/20 16:55:02 | 00,182,272 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Autumn Winter Stock.doc
[2009/10/20 13:59:45 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\admin\My Documents\~$tumn Winter Stock.doc
[2009/10/20 13:44:42 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\admin\My Documents\~$rrent Sale Stock.docx
[2009/10/20 13:44:36 | 00,042,915 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Sale Stock from 10th March.docx
[2009/10/20 13:41:59 | 00,031,041 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Stock 2009 - Before 20th July.docx
[2009/10/20 13:07:30 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\admin\My Documents\~$TAL SPENDING FOR AUTUMN WINTER 2009.docx
[2009/10/20 12:29:36 | 00,007,396 | ---- | M] () -- C:\WINDOWS\System32\drivers\pctcore.cat
[2009/10/20 12:09:06 | 00,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\HijackThis.exe
[2009/10/19 16:39:14 | 00,102,660 | ---- | M] () -- C:\SystemLook.exe
[2009/10/19 13:40:15 | 00,000,664 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Backup&Synchronize.lnk
[2009/10/19 13:28:43 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\admin\My Documents\~$tumn Winter Stock.docx
[2009/10/19 10:45:22 | 00,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/17 11:39:02 | 00,011,775 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\summer '10 spending.xlsx
[2009/10/16 13:11:33 | 04,002,939 | ---- | M] () -- C:\Program Files\stock charlie nelson.zip
[2009/10/16 09:56:05 | 00,477,696 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Winter 09-10 STOCK. paco gil.doc
[2009/10/15 12:16:39 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/10/15 09:52:33 | 00,000,528 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2009/10/14 17:28:20 | 00,037,569 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Autumn Winter Stock.docx
[2009/10/14 16:48:46 | 00,015,168 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\TOTAL SPENDING FOR AUTUMN WINTER 2009.docx
[2009/10/14 15:59:29 | 00,376,219 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Jersey Now.zip
[2009/10/14 15:58:47 | 00,018,432 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Cash Flow Analysis.xls
[2009/10/14 09:55:20 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\agp440.sys
[2009/10/14 09:55:20 | 00,042,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agp440.sys
[2009/10/12 17:31:03 | 00,015,085 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\tillmanual.docx
[2009/10/12 12:51:52 | 00,016,238 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Sundry Expenses.docx
[2009/10/11 08:10:09 | 00,236,544 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009/10/08 23:21:00 | 01,396,264 | ---- | M] (Microsoft Corporation) -- C:\WindowsXP-KB948277-x86-ENU.exe
[2009/10/08 17:05:39 | 03,756,080 | -H-- | M] () -- C:\Documents and Settings\admin\Local Settings\Application Data\IconCache.db
[2009/10/08 14:33:48 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/10/08 14:33:47 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/10/08 14:33:47 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/10/08 14:33:39 | 00,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/10/08 14:33:38 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/10/08 14:33:11 | 00,492,629 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/10/08 14:33:09 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/10/07 15:46:54 | 00,051,200 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Credi App Filled Out.doc
[2009/10/07 14:34:26 | 00,059,556 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Umbrella Heaven Price List.zip
[2009/10/07 14:22:03 | 00,032,173 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Stock 2009.docx
[2009/10/07 14:21:36 | 00,016,870 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\before sale figures.docx
[2009/10/07 10:32:22 | 00,084,480 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Credit Application Hunter.doc
[2009/10/07 10:19:53 | 00,000,646 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/10/05 15:59:40 | 00,034,462 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Costs.rtf
[2009/10/02 11:01:58 | 25,198,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/10/01 13:53:45 | 00,166,630 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\Stock 2009.rtf
[2009/09/30 17:22:27 | 00,011,082 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\summerstock££.xlsx
[2009/09/29 13:22:07 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\admin\My Documents\~$rdi sign.docx
[2009/09/25 13:04:09 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\admin\My Documents\~$ily sales.rtf
[2009/09/24 09:44:06 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\admin\My Documents\~$ndry Expenses.rtf
[2009/09/23 23:02:00 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
========== Files - No Company Name ==========
[2009/10/22 11:35:05 | 00,236,544 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/10/22 11:35:05 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/10/22 11:35:05 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/10/22 11:35:05 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/10/21 14:00:05 | 00,565,746 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Autumn Winter Stock.rtf
[2009/10/21 11:46:25 | 03,351,153 | R--- | C] () -- C:\Documents and Settings\admin\Desktop\ComboFix.exe
[2009/10/21 10:43:52 | 43,629,494 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/10/20 13:59:45 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\admin\My Documents\~$tumn Winter Stock.doc
[2009/10/20 13:59:44 | 00,182,272 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Autumn Winter Stock.doc
[2009/10/20 13:44:42 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\admin\My Documents\~$rrent Sale Stock.docx
[2009/10/20 13:41:21 | 00,031,041 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Stock 2009 - Before 20th July.docx
[2009/10/20 13:07:30 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\admin\My Documents\~$TAL SPENDING FOR AUTUMN WINTER 2009.docx
[2009/10/20 12:29:36 | 00,007,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctcore.cat
[2009/10/19 16:39:14 | 00,102,660 | ---- | C] () -- C:\SystemLook.exe
[2009/10/19 13:40:15 | 00,000,664 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Backup&Synchronize.lnk
[2009/10/19 13:28:43 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\admin\My Documents\~$tumn Winter Stock.docx
[2009/10/16 13:11:27 | 04,002,939 | ---- | C] () -- C:\Program Files\stock charlie nelson.zip
[2009/10/16 09:56:00 | 00,477,696 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Winter 09-10 STOCK. paco gil.doc
[2009/10/15 09:52:33 | 00,000,528 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/10/14 15:59:26 | 00,376,219 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Jersey Now.zip
[2009/10/14 15:58:44 | 00,018,432 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Cash Flow Analysis.xls
[2009/10/14 14:07:32 | 00,015,168 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\TOTAL SPENDING FOR AUTUMN WINTER 2009.docx
[2009/10/13 11:20:06 | 00,023,932 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Current Sale Stock.docx
[2009/10/13 11:17:51 | 00,042,915 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Sale Stock from 10th March.docx
[2009/10/12 12:51:00 | 00,016,238 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Sundry Expenses.docx
[2009/10/10 13:11:14 | 00,015,085 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\tillmanual.docx
[2009/10/08 14:33:48 | 00,001,507 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/10/08 14:33:11 | 00,048,786 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/10/08 14:33:09 | 00,492,629 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/10/08 14:33:05 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/10/07 15:46:53 | 00,051,200 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Credi App Filled Out.doc
[2009/10/07 14:34:09 | 00,059,556 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Umbrella Heaven Price List.zip
[2009/10/07 14:22:02 | 00,032,173 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Stock 2009.docx
[2009/10/07 14:21:12 | 00,016,870 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\before sale figures.docx
[2009/10/07 14:20:37 | 00,037,569 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Autumn Winter Stock.docx
[2009/10/07 10:32:21 | 00,084,480 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\Credit Application Hunter.doc
[2009/10/05 16:28:16 | 00,011,775 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\summer '10 spending.xlsx
[2009/09/30 17:22:27 | 00,011,082 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\summerstock££.xlsx
[2009/09/29 13:22:07 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\admin\My Documents\~$rdi sign.docx
[2009/09/25 11:35:47 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\admin\My Documents\~$ily sales.rtf
[2009/09/24 09:44:06 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\admin\My Documents\~$ndry Expenses.rtf
[2009/05/08 10:57:46 | 00,025,304 | ---- | C] () -- C:\Documents and Settings\admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/05/08 10:39:54 | 00,000,753 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/04/30 12:51:47 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/02/12 17:20:55 | 03,756,080 | -H-- | C] () -- C:\Documents and Settings\admin\Local Settings\Application Data\IconCache.db
[2009/02/12 17:12:35 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\admin\Application Data\desktop.ini
[2009/02/12 16:53:03 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2006/02/28 13:00:00 | 00,000,646 | ---- | C] () -- C:\WINDOWS\win.ini
[2006/02/28 13:00:00 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2006/02/28 12:56:28 | 01,614,848 | ---- | C] () -- C:\WINDOWS\System32\sfcfiles.dll.bak
[2006/02/28 12:56:28 | 01,614,848 | ---- | C] () -- C:\WINDOWS\System32\sfcfiles.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >