Downloaded OTL to my PC as a normal user and then ran the exe as the administrator.
There was no OTL folder created it just opened the two files and saved the OTL file automatically to the desktop.
I ran it again as the normal user, which as I expected contained fewer entries probably due to insufficient privilege, but no Extras.txt was created.
The outputs below are from the first run.
OTL.txt output
OTL logfile created on: 21/05/2010 08:20:17 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Martin\My Documents\Martins download\Apps\anti virus spy clean etc
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 83.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 226.88 Gb Total Space | 100.65 Gb Free Space | 44.36% Space Free | Partition Type: NTFS
Drive D: | 5.99 Gb Total Space | 1.66 Gb Free Space | 27.72% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: BLADE2
Current User Name: HP_Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Martin\My Documents\Martins download\Apps\anti virus spy clean etc\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
PRC - C:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Martin\My Documents\Martins download\Apps\anti virus spy clean etc\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (VMware NAT Service) – C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
SRV - (VMAuthdService) – C:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (VMnetDHCP) – C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
SRV - (vmount2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Driver Services (SafeList) ==========
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (VMnetBridge) – C:\WINDOWS\system32\drivers\vmnetbridge.sys (VMware, Inc.)
DRV - (vmx86) – C:\WINDOWS\system32\drivers\vmx86.sys (VMware, Inc.)
DRV - (VMnetuserif) – C:\WINDOWS\system32\drivers\vmnetuserif.sys (VMware, Inc.)
DRV - (hcmon) – C:\WINDOWS\system32\drivers\hcmon.sys (VMware, Inc.)
DRV - (VMnetAdapter) – C:\WINDOWS\system32\drivers\vmnetadapter.sys (VMware, Inc.)
DRV - (VMparport) – C:\WINDOWS\system32\drivers\vmparport.sys (VMware, Inc.)
DRV - (vstor2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys (VMware, Inc.)
DRV - (PCANDIS5) – C:\WINDOWS\system32\PCANDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (BDA_Loader_225) – C:\WINDOWS\system32\drivers\BDA_Loader_225.sys (WideView Technology Inc.)
DRV - (BDA_Capture_225) – C:\WINDOWS\system32\drivers\BDA_Capture_225.sys (WideViewer Electronics CO., LTD)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (PcdrNdisuio) – C:\WINDOWS\system32\drivers\PcdrNdisuio.sys (Windows ® 2000 DDK provider)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/04/27 17:39:18 | 000,000,000 | —D | M]
O1 HOSTS File: ([2004/08/04 19:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\Hdaudpropshortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab (VerifyGMN Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1141845025035 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1200144945578 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} http://download.zonelabs.com/bin/promotion…canner37960.cab (ICSScanner Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/11/09 21:20:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/05/20 07:00:15 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/05/20 06:48:58 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/05/20 06:48:58 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/05/20 06:48:58 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/05/20 06:48:58 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/05/20 06:48:51 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/05/20 06:48:41 | 000,000,000 | —D | C] – C:\Qoobox
[2010/05/19 19:25:18 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\Malwarebytes
[2010/05/19 19:25:10 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/05/19 19:25:09 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/05/19 19:25:09 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/19 19:25:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/19 11:37:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/05/19 11:37:25 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/19 11:37:25 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/19 11:37:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/19 11:37:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/04/27 17:39:11 | 000,185,920 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2010/04/27 17:39:03 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2010/04/27 17:39:03 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2010/04/27 17:38:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2010/04/27 17:37:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Real
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/05/21 08:08:15 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1009.job
[2010/05/21 08:08:08 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/21 08:08:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1008.job
[2010/05/21 08:08:05 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-501.job
[2010/05/21 08:08:05 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1020.job
[2010/05/21 08:07:28 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/21 08:07:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/21 08:07:22 | 3220,557,824 | -HS- | M] () – C:\hiberfil.sys
[2010/05/20 18:51:42 | 060,199,940 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/05/20 18:49:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/20 11:05:30 | 004,194,304 | -H– | M] () – C:\Documents and Settings\HP_Owner\NTUSER.DAT
[2010/05/20 11:05:30 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\HP_Owner\ntuser.ini
[2010/05/20 07:05:20 | 000,000,184 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2010/05/20 07:05:18 | 004,316,176 | -H– | M] () – C:\Documents and Settings\HP_Owner\Local Settings\Application Data\IconCache.db
[2010/05/20 06:55:52 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/05/20 06:28:23 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/19 20:36:34 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1008.job
[2010/05/19 20:31:27 | 003,692,000 | R— | M] () – C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
[2010/05/19 15:50:38 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1009.job
[2010/05/18 08:42:33 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/05/18 08:42:33 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/05/10 21:30:11 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1020.job
[2010/05/01 10:08:35 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-501.job
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/27 17:39:19 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RealPlayer SP.lnk
[2010/04/27 17:39:11 | 000,185,920 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2010/04/27 17:39:03 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2010/04/27 17:39:03 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2010/04/27 17:38:16 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\WINDOWS\System32\pncrt.dll
[2010/04/26 15:58:12 | 000,256,512 | —- | M] () – C:\WINDOWS\PEV.exe
[2010/04/21 08:56:02 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/05/20 06:48:58 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/05/20 06:48:58 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/05/20 06:48:58 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/05/20 06:48:58 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/05/20 06:48:58 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/05/20 06:29:25 | 003,692,000 | R— | C] () – C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
[2010/05/18 08:42:33 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/05/18 08:42:33 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/05/01 10:08:35 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-501.job
[2010/05/01 10:08:34 | 000,000,286 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-501.job
[2010/04/28 21:12:08 | 000,000,286 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1020.job
[2010/04/28 21:12:08 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1020.job
[2010/04/27 19:42:52 | 000,000,288 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1009.job
[2010/04/27 19:42:52 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1009.job
[2010/04/27 17:39:29 | 000,000,292 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1008.job
[2010/04/27 17:39:29 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1008.job
[2010/04/27 17:39:19 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer SP.lnk
[2009/04/13 16:15:01 | 000,022,723 | —- | C] () – C:\WINDOWS\System32\cl31cl3.dll
[2009/03/03 13:18:04 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/01/15 09:57:26 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/12/30 19:09:46 | 000,000,122 | —- | C] () – C:\WINDOWS\CROCCLIP.INI
[2007/12/28 15:19:11 | 000,000,026 | —- | C] () – C:\WINDOWS\WAR2R.INI
[2007/09/29 11:08:06 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2006/12/21 11:41:13 | 000,004,151 | —- | C] () – C:\WINDOWS\estwn323.ini
[2006/12/20 17:33:27 | 000,000,109 | —- | C] () – C:\WINDOWS\Epscan2.INI
[2006/12/17 12:41:31 | 000,000,331 | —- | C] () – C:\WINDOWS\doom3.ini
[2006/09/09 08:27:16 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/07/29 17:35:45 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2006/07/29 17:35:45 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2006/05/20 18:25:32 | 000,000,037 | —- | C] () – C:\WINDOWS\Acroread.ini
[2005/10/14 10:56:50 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/10/14 10:56:50 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 10:56:50 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 10:56:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2005/10/14 10:56:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2005/10/14 10:56:50 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2005/10/14 10:56:50 | 000,155,136 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2005/10/14 10:56:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2005/04/30 03:29:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/01/19 23:45:40 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2005/01/19 23:45:40 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2005/01/02 06:56:29 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/01/02 06:54:18 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/01/02 06:54:18 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/01/02 06:54:18 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/01/02 06:54:18 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/01/02 06:54:18 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/01/02 06:54:18 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/01/02 06:30:01 | 000,013,780 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/01/02 06:29:55 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/01/02 06:11:47 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/01/02 06:06:52 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/01/02 06:06:52 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/01/02 06:06:52 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/01/02 06:06:52 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/01/02 05:56:45 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/01/02 05:54:54 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/01/02 05:54:54 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/01/02 05:54:32 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/06/25 03:10:06 | 000,000,567 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 23:04:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
========== LOP Check ==========
[2010/04/27 09:40:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/11/22 18:36:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/05/17 18:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/12/28 12:04:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2006/02/11 23:06:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lionhead Studios
[2007/09/27 02:31:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2006/08/12 19:25:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OLYMPUS
[2010/02/17 18:45:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2006/08/18 18:28:00 | 000,000,278 | —- | M] () – C:\WINDOWS\Tasks\Easy Internet Sign-up.job
========== Purity Check ==========
< End of report >
Extras output:
OTL logfile created on: 21/05/2010 08:20:17 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Martin\My Documents\Martins download\Apps\anti virus spy clean etc
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 83.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 226.88 Gb Total Space | 100.65 Gb Free Space | 44.36% Space Free | Partition Type: NTFS
Drive D: | 5.99 Gb Total Space | 1.66 Gb Free Space | 27.72% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: BLADE2
Current User Name: HP_Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Martin\My Documents\Martins download\Apps\anti virus spy clean etc\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
PRC - C:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Martin\My Documents\Martins download\Apps\anti virus spy clean etc\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (VMware NAT Service) – C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
SRV - (VMAuthdService) – C:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (VMnetDHCP) – C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
SRV - (vmount2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Driver Services (SafeList) ==========
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (VMnetBridge) – C:\WINDOWS\system32\drivers\vmnetbridge.sys (VMware, Inc.)
DRV - (vmx86) – C:\WINDOWS\system32\drivers\vmx86.sys (VMware, Inc.)
DRV - (VMnetuserif) – C:\WINDOWS\system32\drivers\vmnetuserif.sys (VMware, Inc.)
DRV - (hcmon) – C:\WINDOWS\system32\drivers\hcmon.sys (VMware, Inc.)
DRV - (VMnetAdapter) – C:\WINDOWS\system32\drivers\vmnetadapter.sys (VMware, Inc.)
DRV - (VMparport) – C:\WINDOWS\system32\drivers\vmparport.sys (VMware, Inc.)
DRV - (vstor2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys (VMware, Inc.)
DRV - (PCANDIS5) – C:\WINDOWS\system32\PCANDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (BDA_Loader_225) – C:\WINDOWS\system32\drivers\BDA_Loader_225.sys (WideView Technology Inc.)
DRV - (BDA_Capture_225) – C:\WINDOWS\system32\drivers\BDA_Capture_225.sys (WideViewer Electronics CO., LTD)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (PcdrNdisuio) – C:\WINDOWS\system32\drivers\PcdrNdisuio.sys (Windows ® 2000 DDK provider)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/04/27 17:39:18 | 000,000,000 | —D | M]
O1 HOSTS File: ([2004/08/04 19:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\Hdaudpropshortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab (VerifyGMN Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1141845025035 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1200144945578 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} http://download.zonelabs.com/bin/promotion…canner37960.cab (ICSScanner Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/11/09 21:20:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/05/20 07:00:15 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/05/20 06:48:58 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/05/20 06:48:58 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/05/20 06:48:58 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/05/20 06:48:58 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/05/20 06:48:51 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/05/20 06:48:41 | 000,000,000 | —D | C] – C:\Qoobox
[2010/05/19 19:25:18 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\Malwarebytes
[2010/05/19 19:25:10 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/05/19 19:25:09 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/05/19 19:25:09 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/19 19:25:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/19 11:37:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/05/19 11:37:25 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/19 11:37:25 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/19 11:37:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/19 11:37:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/04/27 17:39:11 | 000,185,920 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2010/04/27 17:39:03 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2010/04/27 17:39:03 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2010/04/27 17:38:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2010/04/27 17:37:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Real
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/05/21 08:08:15 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1009.job
[2010/05/21 08:08:08 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/21 08:08:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1008.job
[2010/05/21 08:08:05 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-501.job
[2010/05/21 08:08:05 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1020.job
[2010/05/21 08:07:28 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/21 08:07:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/21 08:07:22 | 3220,557,824 | -HS- | M] () – C:\hiberfil.sys
[2010/05/20 18:51:42 | 060,199,940 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/05/20 18:49:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/20 11:05:30 | 004,194,304 | -H– | M] () – C:\Documents and Settings\HP_Owner\NTUSER.DAT
[2010/05/20 11:05:30 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\HP_Owner\ntuser.ini
[2010/05/20 07:05:20 | 000,000,184 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2010/05/20 07:05:18 | 004,316,176 | -H– | M] () – C:\Documents and Settings\HP_Owner\Local Settings\Application Data\IconCache.db
[2010/05/20 06:55:52 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/05/20 06:28:23 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/19 20:36:34 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1008.job
[2010/05/19 20:31:27 | 003,692,000 | R— | M] () – C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
[2010/05/19 15:50:38 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1009.job
[2010/05/18 08:42:33 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/05/18 08:42:33 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/05/10 21:30:11 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1020.job
[2010/05/01 10:08:35 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-501.job
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/27 17:39:19 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RealPlayer SP.lnk
[2010/04/27 17:39:11 | 000,185,920 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2010/04/27 17:39:03 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2010/04/27 17:39:03 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2010/04/27 17:38:16 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\WINDOWS\System32\pncrt.dll
[2010/04/26 15:58:12 | 000,256,512 | —- | M] () – C:\WINDOWS\PEV.exe
[2010/04/21 08:56:02 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/05/20 06:48:58 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/05/20 06:48:58 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/05/20 06:48:58 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/05/20 06:48:58 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/05/20 06:48:58 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/05/20 06:29:25 | 003,692,000 | R— | C] () – C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
[2010/05/18 08:42:33 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/05/18 08:42:33 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/05/01 10:08:35 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-501.job
[2010/05/01 10:08:34 | 000,000,286 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-501.job
[2010/04/28 21:12:08 | 000,000,286 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1020.job
[2010/04/28 21:12:08 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1020.job
[2010/04/27 19:42:52 | 000,000,288 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1009.job
[2010/04/27 19:42:52 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1009.job
[2010/04/27 17:39:29 | 000,000,292 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3882495902-1733513528-3747878165-1008.job
[2010/04/27 17:39:29 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3882495902-1733513528-3747878165-1008.job
[2010/04/27 17:39:19 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer SP.lnk
[2009/04/13 16:15:01 | 000,022,723 | —- | C] () – C:\WINDOWS\System32\cl31cl3.dll
[2009/03/03 13:18:04 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/01/15 09:57:26 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/12/30 19:09:46 | 000,000,122 | —- | C] () – C:\WINDOWS\CROCCLIP.INI
[2007/12/28 15:19:11 | 000,000,026 | —- | C] () – C:\WINDOWS\WAR2R.INI
[2007/09/29 11:08:06 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2006/12/21 11:41:13 | 000,004,151 | —- | C] () – C:\WINDOWS\estwn323.ini
[2006/12/20 17:33:27 | 000,000,109 | —- | C] () – C:\WINDOWS\Epscan2.INI
[2006/12/17 12:41:31 | 000,000,331 | —- | C] () – C:\WINDOWS\doom3.ini
[2006/09/09 08:27:16 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/07/29 17:35:45 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2006/07/29 17:35:45 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2006/05/20 18:25:32 | 000,000,037 | —- | C] () – C:\WINDOWS\Acroread.ini
[2005/10/14 10:56:50 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/10/14 10:56:50 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 10:56:50 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 10:56:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2005/10/14 10:56:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2005/10/14 10:56:50 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2005/10/14 10:56:50 | 000,155,136 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2005/10/14 10:56:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2005/04/30 03:29:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/01/19 23:45:40 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2005/01/19 23:45:40 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2005/01/02 06:56:29 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/01/02 06:54:18 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/01/02 06:54:18 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/01/02 06:54:18 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/01/02 06:54:18 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/01/02 06:54:18 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/01/02 06:54:18 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/01/02 06:30:01 | 000,013,780 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/01/02 06:29:55 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/01/02 06:11:47 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/01/02 06:06:52 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/01/02 06:06:52 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/01/02 06:06:52 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/01/02 06:06:52 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/01/02 05:56:45 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/01/02 05:54:54 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/01/02 05:54:54 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/01/02 05:54:32 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/06/25 03:10:06 | 000,000,567 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 23:04:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
========== LOP Check ==========
[2010/04/27 09:40:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/11/22 18:36:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/05/17 18:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/12/28 12:04:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2006/02/11 23:06:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lionhead Studios
[2007/09/27 02:31:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2006/08/12 19:25:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OLYMPUS
[2010/02/17 18:45:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2006/08/18 18:28:00 | 000,000,278 | —- | M] () – C:\WINDOWS\Tasks\Easy Internet Sign-up.job
========== Purity Check ==========
< End of report >