OTL.txt
OTL logfile created on: 08.09.2010 19:43:08 - Run 2
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\T2\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000100C | Country: Switzerland | Language: FRS | Date Format: dd.MM.yyyy
1'012.00 Mb Total Physical Memory | 348.00 Mb Available Physical Memory | 34.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.17 Gb Total Space | 46.86 Gb Free Space | 32.50% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PEQUENINO
Current User Name: T2
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\T2\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\T2\Local Settings\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (Boingo Wireless, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\SDL International\License Server\trados.exe ()
PRC - C:\Program Files\SDL International\License Server\lmgrd.exe (Macrovision Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (SafeNet, Inc)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\T2\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Common Files\OnlineFilesManager.dll (Microsoft)
MOD - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.dll (Adobe Systems, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (Sun Microsystems, Inc.)
MOD - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\stlport_vc7145.dll (STLport Consulting, Inc.)
MOD - C:\WINDOWS\system32\xpsp2res.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\AudioShell\AudioShellExt.dll (Softpointer Inc)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (ServiceLayer) – C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (BlueSoleilCS) – C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe ()
SRV - (BsHelpCS) – C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe ()
SRV - (BsMobileCS) – C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe ()
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (lxdi_device) – C:\WINDOWS\System32\lxdicoms.exe ( )
SRV - (lxdiCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe ()
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (NewServiceInstall1) – C:\Program Files\SDL International\T2007\TT\Lng\Dialogs1031.lng ()
SRV - (SDL FLEXlm License Server) – C:\Program Files\SDL International\License Server\lmgrd.exe (Macrovision Corporation)
SRV - (SentinelProtectionServer) – C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (SafeNet, Inc)
========== Driver Services (SafeList) ==========
DRV - (upperdev) – C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (mcdbus) – C:\WINDOWS\System32\DRIVERS\mcdbus.sys File not found
DRV - (catchme) – C:\DOCUME~1\T2\LOCALS~1\Temp\catchme.sys File not found
DRV - (Wpsnuio) – C:\WINDOWS\system32\drivers\wpsnuio.sys (Skyhook Wireless)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (BtHidBus) – C:\WINDOWS\System32\Drivers\BtHidBus.sys (IVT Corporation.)
DRV - (JMCR) – C:\WINDOWS\system32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - (IvtBtBUs) – C:\WINDOWS\system32\drivers\IvtBtBus.sys (IVT Corporation.)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation.)
DRV - (Btcsrusb) – C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation.)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (BT) – C:\WINDOWS\system32\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation.)
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (Sentinel) – C:\WINDOWS\System32\Drivers\SENTINEL.SYS (SafeNet, Inc.)
DRV - (sfcure01) StarForce Cure Driver (version 1.x) – C:\WINDOWS\system32\drivers\sfcure01.sys ()
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (int15.sys) – C:\Acer\Empowering Technology\eRecovery\int15.sys ()
DRV - (DKbFltr) – C:\WINDOWS\system32\drivers\DKbFltr.SYS (Dritek System Inc.)
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (prohlp02) – C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (sfhlp01) – C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (prodrv06) – C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (prosync1) – C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ch/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.ch/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.10 07:57:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.09.03 23:53:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.09.02 16:18:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010.09.03 23:53:05 | 000,000,000 | —D | M]
[2010.09.02 16:18:49 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Mozilla\Extensions
[2010.09.02 16:18:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\T2\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.09.08 16:40:10 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\extensions
[2010.04.28 07:16:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009.03.04 15:30:50 | 000,001,504 | —- | M] () – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\searchplugins\imdb.xml
[2008.11.17 05:01:06 | 000,001,032 | —- | M] () – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\searchplugins\wikipedia-eng.xml
[2010.09.08 16:40:10 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010.03.29 09:55:27 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.09.01 18:29:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.09.01 18:29:39 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009.11.30 18:59:59 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2008.11.20 13:04:50 | 000,239,432 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2010.03.13 16:49:04 | 000,001,516 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-france.xml
[2010.03.13 16:49:04 | 000,001,822 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\cnrtl-tlfi-fr.xml
[2010.03.13 16:49:04 | 000,000,757 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-france.xml
[2008.11.17 14:06:34 | 000,000,748 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\MediaDICO-fr.xml
[2010.03.13 16:49:06 | 000,001,426 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fr.xml
[2010.03.24 13:18:59 | 000,000,956 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-france.xml
O1 HOSTS File: ([2010.09.02 18:17:15 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Boingo Wi-Fi] C:\Program Files\Boingo\Boingo Wi-Fi\Boingo.lnk ()
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE}
http://qc.nokia.com/qcbin/Spider90.ocx (Loader Class v3)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO: )
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\T2\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\T2\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.08.15 19:37:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DIVXA32.ACM (Hacked With Joy !)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\DIVX.DLL (DivXNetworks, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\XVIDVFW.DLL ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)
========== Files/Folders - Created Within 90 Days ==========
[2010.09.08 12:13:01 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Desktop\2466009_20100907151956
[2010.09.08 09:57:59 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010.09.07 11:36:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010.09.07 11:34:32 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010.09.07 11:24:50 | 000,000,000 | -HSD | C] – C:\Documents and Settings\T2\PrivacIE
[2010.09.05 17:36:27 | 001,286,232 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\T2\Desktop\TDSSKiller.exe
[2010.09.03 08:48:56 | 000,000,000 | -HSD | C] – C:\Documents and Settings\T2\IETldCache
[2010.09.02 17:48:25 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2010.09.02 17:45:02 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010.09.02 15:42:14 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\T2\Desktop\OTL.exe
[2010.09.02 08:46:59 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010.09.01 18:43:23 | 000,378,880 | —- | C] (The RaProducts Team: Paul McLain and Fred de Vries) – C:\Documents and Settings\T2\Desktop\JavaRa.exe
[2010.09.01 18:30:28 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010.09.01 17:18:16 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Application Data\Malwarebytes
[2010.09.01 17:18:08 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.09.01 17:18:06 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010.09.01 17:18:06 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010.09.01 17:18:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.09.01 11:07:49 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010.09.01 11:03:32 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010.09.01 11:03:32 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010.09.01 11:03:32 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010.09.01 11:03:32 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010.09.01 11:03:13 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010.09.01 11:02:39 | 000,000,000 | —D | C] – C:\Qoobox
[2010.08.24 13:44:17 | 000,000,000 | —D | C] – C:\_OTL
[2010.08.24 13:14:32 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\My Documents\EXPO
[2010.08.23 16:56:17 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Local Settings\Application Data\IsolatedStorage
[2010.08.23 16:52:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nokia
[2010.08.23 16:52:10 | 000,018,816 | —- | C] (Nokia) – C:\WINDOWS\System32\drivers\pccsmcfd.sys
[2010.08.23 16:50:49 | 000,000,000 | —D | C] – C:\Program Files\Nokia
[2010.08.20 16:48:46 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Desktop\muzic putain
[2010.08.18 16:56:50 | 000,000,000 | —D | C] – C:\Program Files\Safari
[2010.08.18 15:21:15 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Local Settings\Application Data\Nokia
[2010.08.18 15:21:06 | 000,000,000 | —D | C] – C:\WINDOWS\Globalization
[2010.08.18 15:20:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NokiaMusic
[2010.08.18 15:17:38 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2010.08.15 21:03:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Data
[2010.08.15 21:01:11 | 000,197,632 | —- | C] (Microsoft) – C:\Program Files\Common Files\OnlineFilesManager.dll
[2010.08.09 23:51:15 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010.08.09 23:50:59 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010.08.09 23:50:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010.08.09 23:43:09 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010.08.09 23:34:54 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010.07.20 08:21:08 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Application Data\vlc
[2010.06.28 09:25:27 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mercury Interactive
[2010.06.13 11:26:02 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\My Documents\Promo
[2009.08.21 18:28:50 | 000,356,352 | —- | C] ( ) – C:\WINDOWS\System32\lxdiinpa.dll
[2009.08.21 18:28:50 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdiiesc.dll
[2009.08.21 18:28:50 | 000,311,296 | —- | C] ( ) – C:\WINDOWS\System32\lxdihcp.dll
[2009.08.21 18:28:49 | 001,187,840 | —- | C] ( ) – C:\WINDOWS\System32\lxdiserv.dll
[2009.08.21 18:28:49 | 000,942,080 | —- | C] ( ) – C:\WINDOWS\System32\lxdiusb1.dll
[2009.08.21 18:28:48 | 000,614,400 | —- | C] ( ) – C:\WINDOWS\System32\lxdipmui.dll
[2009.08.21 18:28:48 | 000,532,480 | —- | C] ( ) – C:\WINDOWS\System32\lxdilmpm.dll
[2009.08.21 18:28:48 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdiprox.dll
[2009.08.21 18:28:48 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdipplc.dll
[2009.08.21 18:28:47 | 000,671,744 | —- | C] ( ) – C:\WINDOWS\System32\lxdihbn3.dll
[2009.08.21 18:28:45 | 000,765,952 | —- | C] ( ) – C:\WINDOWS\System32\lxdicomc.dll
[2009.08.21 18:28:45 | 000,360,448 | —- | C] ( ) – C:\WINDOWS\System32\lxdicomm.dll
[2007.04.02 06:40:54 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2005.11.23 01:55:32 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[1 C:\Documents and Settings\T2\My Documents\*.tmp files -> C:\Documents and Settings\T2\My Documents\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010.09.08 19:40:59 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\T2\Desktop\OTL.exe
[2010.09.08 19:15:33 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010.09.08 19:09:00 | 000,001,054 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.09.08 19:06:01 | 000,001,134 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2094639727-349796869-1728803408-1006UA.job
[2010.09.08 09:01:26 | 000,111,571 | —- | M] () – C:\Documents and Settings\T2\Desktop\antivirus-download.JPG
[2010.09.08 08:57:30 | 000,061,352 | —- | M] () – C:\Documents and Settings\T2\Desktop\adobreader-popup.JPG
[2010.09.08 08:57:15 | 000,061,352 | —- | M] () – C:\Documents and Settings\T2\Desktop\wmp-popup.JPG
[2010.09.08 08:55:43 | 000,039,630 | —- | M] () – C:\Documents and Settings\T2\Desktop\hands-popup.JPG
[2010.09.07 15:17:50 | 000,659,968 | —- | M] () – C:\Documents and Settings\T2\Desktop\MicrosoftFixit50195.msi
[2010.09.07 13:32:32 | 000,143,872 | —- | M] () – C:\Documents and Settings\T2\Desktop\Timesheet_Nokia_Switzerland.xls
[2010.09.07 12:37:48 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010.09.07 11:36:00 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010.09.07 11:20:38 | 000,024,832 | —- | M] () – C:\WINDOWS\System32\9203853141.dll
[2010.09.07 11:18:32 | 000,001,050 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.09.07 11:18:10 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010.09.07 11:17:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010.09.07 11:17:53 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2010.09.07 11:16:58 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\T2\ntuser.ini
[2010.09.07 11:16:57 | 008,388,608 | -H– | M] () – C:\Documents and Settings\T2\NTUSER.DAT
[2010.09.07 11:16:17 | 000,001,646 | —- | M] () – C:\WINDOWS\System32\spupdsvc.inf
[2010.09.07 09:40:35 | 000,133,632 | —- | M] () – C:\Documents and Settings\T2\Desktop\RKUnhookerLE.EXE
[2010.09.06 01:06:00 | 000,001,082 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2094639727-349796869-1728803408-1006Core.job
[2010.09.04 19:57:29 | 000,218,624 | —- | M] () – C:\Documents and Settings\T2\Desktop\Copy of Feedbackbogen_RC_frz.xls
[2010.09.03 10:27:06 | 001,286,232 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\T2\Desktop\TDSSKiller.exe
[2010.09.02 18:17:30 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010.09.02 18:17:15 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010.09.02 17:49:54 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010.09.02 17:49:14 | 003,830,422 | R— | M] () – C:\Documents and Settings\T2\Desktop\ComboFix.exe
[2010.09.02 15:51:27 | 000,869,051 | —- | M] () – C:\Documents and Settings\T2\Desktop\SecurityCheck.exe
[2010.09.01 11:07:55 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010.09.01 10:48:47 | 000,000,174 | —- | M] () – C:\Documents and Settings\T2\defogger_reenable
[2010.08.27 23:35:25 | 000,331,480 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.27 21:20:41 | 000,050,477 | —- | M] () – C:\Documents and Settings\T2\Desktop\Defogger.exe
[2010.08.27 15:35:18 | 000,083,768 | —- | M] () – C:\Documents and Settings\T2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010.08.26 11:18:44 | 000,997,390 | —- | M] () – C:\Documents and Settings\T2\Desktop\neirongzhinan.PDF
[2010.08.26 10:59:15 | 000,443,442 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010.08.26 10:59:15 | 000,072,516 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010.08.25 23:52:46 | 000,000,347 | —- | M] () – C:\WINDOWS\mercury.ini
[2010.08.25 17:32:45 | 000,526,486 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010.08.24 14:48:25 | 000,001,730 | -H– | M] () – C:\Documents and Settings\T2\My Documents\Default.rdp
[2010.08.23 21:59:44 | 000,000,440 | —- | M] () – C:\Documents and Settings\T2\Desktop\dump0.zip
[2010.08.23 21:59:11 | 000,000,512 | —- | M] () – C:\Documents and Settings\T2\Desktop\dump0.dat
[2010.08.23 13:46:15 | 000,043,266 | —- | M] () – C:\Documents and Settings\T2\Desktop\4917217001L_1.jpg
[2010.08.19 11:34:06 | 000,000,819 | —- | M] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010.08.18 16:57:43 | 000,057,896 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010.08.18 15:27:02 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010.08.18 15:20:08 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010.08.18 15:17:41 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010.08.09 14:51:12 | 000,378,880 | —- | M] (The RaProducts Team: Paul McLain and Fred de Vries) – C:\Documents and Settings\T2\Desktop\JavaRa.exe
[2010.08.08 14:08:40 | 000,003,027 | —- | M] () – C:\Documents and Settings\T2\Desktop\Français.lng
[2010.08.06 11:34:22 | 000,017,408 | —- | M] () – C:\Documents and Settings\T2\My Documents\Budgetisation.xls
[2010.07.30 19:20:28 | 004,768,204 | -H– | M] () – C:\Documents and Settings\T2\Local Settings\Application Data\IconCache.db
[2010.06.29 22:12:58 | 000,288,474 | —- | M] () – C:\Documents and Settings\T2\My Documents\Titus plonge5.wmv
[2010.06.29 11:30:00 | 001,426,900 | —- | M] () – C:\Documents and Settings\T2\My Documents\VIDEO_019.mp4
[1 C:\Documents and Settings\T2\My Documents\*.tmp files -> C:\Documents and Settings\T2\My Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.09.08 09:01:26 | 000,111,571 | —- | C] () – C:\Documents and Settings\T2\Desktop\antivirus-download.JPG
[2010.09.08 08:57:30 | 000,061,352 | —- | C] () – C:\Documents and Settings\T2\Desktop\adobreader-popup.JPG
[2010.09.08 08:56:03 | 000,061,352 | —- | C] () – C:\Documents and Settings\T2\Desktop\wmp-popup.JPG
[2010.09.08 08:55:43 | 000,039,630 | —- | C] () – C:\Documents and Settings\T2\Desktop\hands-popup.JPG
[2010.09.07 15:17:50 | 000,659,968 | —- | C] () – C:\Documents and Settings\T2\Desktop\MicrosoftFixit50195.msi
[2010.09.07 11:20:38 | 000,024,832 | —- | C] () – C:\WINDOWS\System32\9203853141.dll
[2010.09.07 09:40:34 | 000,133,632 | —- | C] () – C:\Documents and Settings\T2\Desktop\RKUnhookerLE.EXE
[2010.09.04 19:57:28 | 000,218,624 | —- | C] () – C:\Documents and Settings\T2\Desktop\Copy of Feedbackbogen_RC_frz.xls
[2010.09.02 17:46:59 | 000,001,646 | —- | C] () – C:\WINDOWS\System32\spupdsvc.inf
[2010.09.02 15:51:26 | 000,869,051 | —- | C] () – C:\Documents and Settings\T2\Desktop\SecurityCheck.exe
[2010.09.01 18:43:23 | 000,003,027 | —- | C] () – C:\Documents and Settings\T2\Desktop\Français.lng
[2010.09.01 11:07:55 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010.09.01 11:07:51 | 000,263,488 | —- | C] () – C:\cmldr
[2010.09.01 11:03:32 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010.09.01 11:03:32 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010.09.01 11:03:32 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010.09.01 11:03:32 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010.09.01 11:03:32 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010.09.01 10:48:31 | 000,000,174 | —- | C] () – C:\Documents and Settings\T2\defogger_reenable
[2010.08.27 21:21:05 | 003,830,422 | R— | C] () – C:\Documents and Settings\T2\Desktop\ComboFix.exe
[2010.08.27 21:20:40 | 000,050,477 | —- | C] () – C:\Documents and Settings\T2\Desktop\Defogger.exe
[2010.08.27 15:46:09 | 000,143,872 | —- | C] () – C:\Documents and Settings\T2\Desktop\Timesheet_Nokia_Switzerland.xls
[2010.08.26 11:19:15 | 000,997,390 | —- | C] () – C:\Documents and Settings\T2\Desktop\neirongzhinan.PDF
[2010.08.23 21:59:44 | 000,000,440 | —- | C] () – C:\Documents and Settings\T2\Desktop\dump0.zip
[2010.08.23 21:59:11 | 000,000,512 | —- | C] () – C:\Documents and Settings\T2\Desktop\dump0.dat
[2010.08.23 20:40:45 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010.08.23 13:46:14 | 000,043,266 | —- | C] () – C:\Documents and Settings\T2\Desktop\4917217001L_1.jpg
[2010.08.18 17:59:50 | 000,001,730 | -H– | C] () – C:\Documents and Settings\T2\My Documents\Default.rdp
[2010.08.18 16:57:43 | 000,057,896 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010.08.18 16:20:35 | 000,002,528 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2010.08.18 16:18:18 | 000,690,656 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010.08.18 15:27:02 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010.08.18 15:17:41 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010.07.19 21:37:55 | 001,426,900 | —- | C] () – C:\Documents and Settings\T2\My Documents\VIDEO_019.mp4
[2010.07.19 21:37:55 | 000,288,474 | —- | C] () – C:\Documents and Settings\T2\My Documents\Titus plonge5.wmv
[2010.06.28 09:25:22 | 000,000,347 | —- | C] () – C:\WINDOWS\mercury.ini
[2010.06.16 13:20:18 | 000,011,164 | —- | C] () – C:\Documents and Settings\T2\hs_err_pid3604.log
[2010.04.14 14:24:45 | 000,036,352 | —- | C] () – C:\WINDOWS\System32\SX32W.DLL
[2010.01.19 18:45:14 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010.01.19 18:45:14 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2010.01.18 21:36:36 | 000,002,143 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010.01.18 21:18:39 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009.10.10 16:22:40 | 000,002,528 | —- | C] () – C:\Documents and Settings\T2\Application Data\$_hpcst$.hpc
[2009.08.21 18:31:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdivs.dll
[2009.08.21 18:31:18 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\lxdicoin.dll
[2009.08.21 18:30:11 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\lxdicaps.dll
[2009.08.21 18:30:10 | 000,692,224 | —- | C] () – C:\WINDOWS\System32\lxdidrs.dll
[2009.08.21 18:30:10 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdicnv4.dll
[2009.08.21 18:28:50 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\lxdiinst.dll
[2009.08.21 18:28:47 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdigrd.dll
[2009.05.05 21:40:31 | 000,002,686 | —- | C] () – C:\WINDOWS\System32\SHORTCUT.INI
[2009.05.05 21:39:48 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\REMOTEDEVICE.INI
[2009.05.05 21:38:30 | 000,004,535 | —- | C] () – C:\WINDOWS\System32\LOCALSERVICE.INI
[2009.05.05 21:38:28 | 000,000,101 | —- | C] () – C:\WINDOWS\System32\LOCALDEVICE.INI
[2009.05.05 21:30:46 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\BSPRINT.INI
[2009.04.16 21:12:45 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\drivers\sfcure01.sys
[2009.02.06 11:01:24 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS45.DLL
[2008.11.17 15:38:34 | 000,052,736 | —- | C] () – C:\Documents and Settings\T2\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.11.16 18:40:00 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008.11.16 03:39:04 | 000,000,125 | —- | C] () – C:\Documents and Settings\T2\Local Settings\Application Data\fusioncache.dat
[2008.08.30 09:36:18 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008.08.04 18:04:44 | 000,000,951 | —- | C] () – C:\WINDOWS\System32\bscs.ini
[2008.08.04 17:36:50 | 000,405,589 | —- | C] () – C:\WINDOWS\System32\BsUI.dll
[2008.08.01 15:58:50 | 000,278,647 | —- | C] () – C:\WINDOWS\System32\outlookAddin.dll
[2008.08.01 15:58:30 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\HtmPrintHelper.dll
[2008.08.01 15:58:14 | 000,622,693 | —- | C] () – C:\WINDOWS\System32\BSShell.dll
[2008.08.01 15:56:14 | 000,098,403 | —- | C] () – C:\WINDOWS\System32\Bs2Res.dll
[2008.08.01 15:55:40 | 000,118,880 | —- | C] () – C:\WINDOWS\System32\BsMobileSDK.dll
[2008.08.01 15:55:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\BsMobileCSps.dll
[2008.08.01 15:46:30 | 017,907,824 | —- | C] () – C:\WINDOWS\System32\BsLangInDepRes.dll
[2008.08.01 15:46:30 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\BsVistaCommon.dll
[2008.07.31 04:37:26 | 000,006,782 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008.05.16 10:12:30 | 000,000,036 | —- | C] () – C:\WINDOWS\PidList.ini
[2008.04.15 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008.02.15 07:21:56 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2007.10.01 08:59:46 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2007.05.09 09:16:40 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2006.09.18 15:37:50 | 000,000,530 | —- | C] () – C:\WINDOWS\System32\tx12_ic.ini
[2006.09.18 15:37:48 | 000,667,280 | —- | C] () – C:\WINDOWS\System32\tx12.dll
[2005.03.29 00:45:26 | 000,000,153 | —- | C] () – C:\WINDOWS\ALaunch.ini
[2004.06.07 00:00:00 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\XVIDCORE.DLL
[2004.06.07 00:00:00 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\XVIDVFW.DLL
========== LOP Check ==========
[2008.12.04 13:57:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2DBoy
[2010.02.08 20:36:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010.02.04 18:57:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2009.04.19 08:34:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010.05.18 07:42:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoBoingo
[2010.02.01 11:23:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2010.08.18 15:20:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NokiaMusic
[2010.07.27 20:01:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010.04.14 14:15:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SDL International
[2008.11.17 05:29:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TRADOS
[2010.05.21 11:34:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEngineLite
[2010.08.09 23:52:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009.09.26 12:54:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.07.06 18:18:33 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Ableton
[2010.05.26 19:57:53 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\avidemux
[2009.10.10 12:31:45 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.04.19 08:33:45 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\DAEMON Tools Pro
[2009.10.20 17:56:23 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\FileZilla
[2010.05.08 12:05:51 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\foobar2000
[2009.11.30 19:00:08 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Foxit
[2010.01.04 15:32:26 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Foxit Software
[2010.03.22 11:39:20 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\GCMSWorkbench.2C30485F6B8C679517FCFDBDF0D73C7F278DFACC.1
[2009.05.05 21:04:27 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\GetRightToGo
[2009.08.21 18:35:17 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Lexmark Productivity Studio
[2010.08.18 15:22:01 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Nokia
[2010.04.12 17:58:39 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Notepad++
[2009.09.03 00:35:17 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\OpenOffice.org
[2008.12.11 07:47:54 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Opera
[2010.02.15 16:56:12 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\PC Suite
[2009.11.18 01:04:32 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\ScummVM
[2009.02.26 13:40:03 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\SDL International
[2010.06.16 13:18:29 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\SystemRequirementsLab
[2010.09.02 16:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Thunderbird
[2008.12.03 15:09:13 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Trados
[2010.09.02 17:31:28 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\uTorrent
[2010.06.05 11:51:22 | 000,000,564 | —- | M] () – C:\WINDOWS\Tasks\12-March_to_the_Shore-FYU.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008.08.15 19:37:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010.01.26 11:43:41 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010.09.01 11:07:55 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004.08.03 23:00:08 | 000,263,488 | —- | M] () – C:\cmldr
[2010.09.02 18:22:57 | 000,038,306 | —- | M] () – C:\ComboFix.txt
[2008.08.15 19:37:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010.09.07 11:17:53 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2008.08.15 19:37:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010.09.01 18:44:39 | 000,006,986 | —- | M] () – C:\JavaRa.log
[2010.02.11 11:14:28 | 000,003,163 | —- | M] () – C:\license.lic
[2008.08.15 19:37:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008.04.15 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008.04.15 05:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010.09.07 11:17:51 | 1585,446,912 | -HS- | M] () – C:\pagefile.sys
[2008.08.30 09:40:32 | 000,000,080 | —- | M] () – C:\Preload.aaa
[2008.08.15 19:57:08 | 000,000,542 | —- | M] () – C:\RHDSetup.log
[2010.04.14 14:13:15 | 145,245,184 | —- | M] () – C:\SDLT2007.msi
[2009.04.20 18:20:23 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009.04.20 18:45:49 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009.04.20 18:50:41 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009.04.20 19:05:00 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009.04.20 19:08:33 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009.04.20 19:41:06 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009.04.21 20:58:05 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009.10.10 14:48:25 | 000,000,292 | -H– | M] () – C:\sqmdata07.sqm
[2009.11.05 20:28:09 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009.03.12 04:08:03 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009.04.14 17:03:07 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009.04.16 16:45:39 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009.04.16 20:41:01 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009.04.17 17:54:07 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009.04.19 08:27:34 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2009.04.19 08:58:38 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009.04.20 18:04:40 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2009.04.20 18:07:28 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009.04.20 18:11:36 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009.04.20 18:17:50 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009.04.20 18:20:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009.04.20 18:45:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009.04.20 18:50:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009.04.20 19:04:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009.04.20 19:08:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009.04.20 19:41:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009.04.21 20:58:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009.10.10 14:48:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009.11.05 20:28:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009.03.12 04:08:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009.04.14 17:03:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009.04.16 16:45:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009.04.16 20:41:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009.04.17 17:54:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009.04.19 08:27:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009.04.19 08:58:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009.04.20 18:04:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009.04.20 18:07:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009.04.20 18:11:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009.04.20 18:17:49 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010.08.25 17:26:16 | 000,054,674 | —- | M] () – C:\TDSSKiller.2.4.1.2_25.08.2010_17.24.15_log.txt
[2010.09.05 17:43:58 | 000,054,054 | —- | M] () – C:\TDSSKiller.2.4.2.0_05.09.2010_17.37.17_log.txt
[1999.11.11 09:17:54 | 000,000,049 | —- | M] () – C:\XPH.TAG
< %systemroot%\Fonts\*.com >
[2006.04.18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006.06.29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006.04.18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006.06.29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008.08.15 19:37:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002.02.11 23:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD45.DLL
[2002.02.11 23:00:00 | 000,043,008 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP45.DLL
[2008.07.06 14:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007.03.15 23:08:12 | 000,113,664 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdidrpp.dll
[2007.04.09 07:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006.10.27 04:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008.07.06 12:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008.08.15 12:29:32 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008.08.15 12:29:32 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008.08.15 12:29:32 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008.08.15 19:37:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008.11.16 07:22:48 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008.08.15 19:43:46 | 000,000,079 | —- | M] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010.09.02 17:49:14 | 003,830,422 | R— | M] () – C:\Documents and Settings\T2\Desktop\ComboFix.exe
[2010.08.27 21:20:41 | 000,050,477 | —- | M] () – C:\Documents and Settings\T2\Desktop\Defogger.exe
[2010.08.09 14:51:12 | 000,378,880 | —- | M] (The RaProducts Team: Paul McLain and Fred de Vries) – C:\Documents and Settings\T2\Desktop\JavaRa.exe
[2010.09.08 19:40:59 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\T2\Desktop\OTL.exe
[2008.08.06 11:27:08 | 003,520,552 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Documents and Settings\T2\Desktop\procexp.exe
[2010.09.07 09:40:35 | 000,133,632 | —- | M] () – C:\Documents and Settings\T2\Desktop\RKUnhookerLE.EXE
[2010.09.02 15:51:27 | 000,869,051 | —- | M] () – C:\Documents and Settings\T2\Desktop\SecurityCheck.exe
[2010.09.03 10:27:06 | 001,286,232 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\T2\Desktop\TDSSKiller.exe
< %PROGRAMFILES%\Common Files\*.* >
[2010.08.15 21:01:11 | 000,197,632 | —- | M] (Microsoft) – C:\Program Files\Common Files\OnlineFilesManager.dll
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
[2005.02.19 21:52:52 | 000,240,640 | —- | M] () – C:\Documents and Settings\T2\My Documents\SFNightmare.exe
[1 C:\Documents and Settings\T2\My Documents\*.tmp files -> C:\Documents and Settings\T2\My Documents\*.tmp -> ]
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2008.04.15 05:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2008.11.16 07:22:49 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\T2\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2010.09.08 18:55:40 | 000,049,152 | —- | M] () – C:\Documents and Settings\T2\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2008.04.15 05:00:00 | 000,208,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.exe >
[2008.04.14 14:42:30 | 001,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< %USERPROFILE%\Templates\*.tmp >
< %SYSTEMDRIVE%\explorexxx.exe\*.* >
< %Windir%\Installer\*.tmp >
[4 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
< %systemroot%\System32\*.xco >
< %ProgramFiles%\system32\*.* >
< %systemroot%\System32\windos\*.* >
< %SystemRoot%\system32\sandbox\*.* >
< %SystemRoot%\system32\*.amo >
< %SystemRoot%\system32\Windows Live\*.* >
< %ProgramFiles%\logs\*.* >
< %ProgramFiles%\Bifrost\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-24 11:55:58
< End of report >