Good evening mowman. I followed the OTL scan instructions as posted by LDTate on the forum instruction page and have posted the OTL results below.
OTL logfile created on: 11/2/2010 8:18:11 PM - Run 2
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Virus Scan
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 174.00 Mb Available Physical Memory | 17.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.04 Gb Total Space | 69.41 Gb Free Space | 48.52% Space Free | Partition Type: NTFS
Computer Name: SAMSUNG120 | User Name: JM | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\John Hurst\Application Data\Microsoft\Windows\shell.exe ()
PRC - C:\Documents and Settings\John Hurst\Local Settings\Temp\dwm.exe ()
PRC - C:\Documents and Settings\John Hurst\Application Data\Microsoft\svchost.exe ()
PRC - C:\Documents and Settings\JM\Application Data\Microsoft\Windows\shell.exe ()
PRC - C:\Documents and Settings\JM\Local Settings\Temp\dwm.exe ()
PRC - C:\Documents and Settings\JM\Application Data\Microsoft\svchost.exe ()
PRC - C:\Virus Scan\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - C:\Program Files\iMesh Applications\MediaBar\DataMngr\DataMngrUI.exe (iMesh, Inc)
PRC - C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe ()
PRC - C:\Program Files\Crawler\Toolbar\CToolbar.exe (Crawler.com)
PRC - C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files\NCH Software\Components\mp3el\mp3enc.exe ()
PRC - C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
PRC - C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
PRC - C:\Program Files\Common Files\BSD\AppUpdater\BSDChecker.exe (Bootstrap Software Development)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller2.exe (SRS Labs, Inc.)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\Samsung\MagicKBD\PerformanceManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
PRC - C:\Program Files\Samsung\MagicKBD\Session.exe ()
========== Modules (SafeList) ==========
MOD - C:\Virus Scan\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Real\RealPlayer\browserrecord\chrome\hook\rpchromebrowserrecordhelper.dll (RealPlayer)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)
========== Win32 Services (SafeList) ==========
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_062a651.dll ()
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (BarQuery Service) – C:\Documents and Settings\All Users\Application Data\BarQuery\barquery135.exe ()
SRV - (iWinTrusted) – C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (BroadWaveService) – C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
SRV - (yksvc) – C:\WINDOWS\system32\ykx32mpcoinst.dll (Marvell)
SRV - (SRS_PostInstaller) – C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller2.exe (SRS Labs, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (cpuz132) – C:\DOCUME~1\JM\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (btwmodem) – C:\WINDOWS\System32\DRIVERS\btwmodem.sys File not found
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (TPkd) – C:\WINDOWS\System32\drivers\TPkd.sys (PACE Anti-Piracy, Inc.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (wowfilter) – C:\WINDOWS\system32\drivers\WOWFilter.sys ()
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ntcdrdrv) – C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys (NoteBurn Software)
DRV - (VMC326) – C:\WINDOWS\system32\drivers\VMC326.sys (Vimicro Corporation)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (DOSMEMIO) – C:\WINDOWS\system32\MEMIO.SYS ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://dnl.crawler.com/support/sa_customize.aspx?TbId=60001
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.crawler.com/search/ie.aspx?tb_id=60001
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/redirectdomain?br…N&bmod;=SMSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.babylon.com/home?AF=14542
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
IE - HKCU\..\URLSearchHook: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: "
http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch⁡=14542"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {1CE11043-9A15-4207-A565-0C94C42D590D}:11.3.7.0
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.006.004
FF - prefs.js..extensions.enabledItems: {D5493C6A-FD62-4255-AA85-AB7E7D0F0001}:1.0
FF - prefs.js..extensions.enabledItems: {4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3
FF - prefs.js..extensions.enabledItems: {98e34367-8df7-42b4-837b-20b892ff0849}:1.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {28D35620-51D9-11DE-9D13-2DB156D89593}:3.1
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {99E00A4C-D35E-11DD-BA95-9B6A56D89593}:2.2
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..keyword.URL: "
http://search.search-star.net/?sid=10101045100&s;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50370
FF - prefs.js..network.proxy.type: 1
FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..keyword.URL: "
http://search.search-star.net/?sid=10101045100&s;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0849}: C:\Program Files\iWin Games\firefox\ [2010/04/15 20:01:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}: C:\Program Files\Crawler\Toolbar\firefox\ [2010/04/16 16:55:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/10/26 17:49:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/28 07:24:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 07:24:58 | 000,000,000 | —D | M]
[2009/12/27 15:49:24 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Mozilla\Extensions
[2010/11/01 21:33:19 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions
[2010/06/02 00:44:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/24 10:30:01 | 000,000,000 | —D | M] (MediaBar) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{28D35620-51D9-11DE-9D13-2DB156D89593}
[2010/07/25 19:29:55 | 000,000,000 | —D | M] (ooVoo Toolbar) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{99E00A4C-D35E-11DD-BA95-9B6A56D89593}
[2010/08/03 13:56:37 | 000,000,000 | —D | M] (myBabylon English Toolbar) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010/04/12 14:01:34 | 000,002,456 | —- | M] () – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\searchplugins\iMeshWebSearch.xml
[2010/11/01 21:33:19 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/03 18:52:48 | 000,000,000 | —D | M] (Adobe Flash Plugin) – C:\Program Files\Mozilla Firefox\extensions\{1CE11043-9A15-4207-A565-0C94C42D590D}
[2010/05/20 16:51:53 | 000,000,000 | —D | M] (BarQuery) – C:\Program Files\Mozilla Firefox\extensions\{D5493C6A-FD62-4255-AA85-AB7E7D0F0001}
[2010/08/03 13:56:29 | 000,002,226 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/03/27 11:13:27 | 000,002,389 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\barquery129.xml
[2009/09/21 11:24:16 | 000,001,329 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
[2010/07/26 08:38:42 | 000,002,076 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google_search.xml
[2010/04/12 14:01:34 | 000,002,456 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\iMeshWebSearch.xml
O1 HOSTS File: ([2008/04/14 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Gamevance) - {0ED403E8-470A-4a8a-85A4-D7688CFE39A3} - C:\Program Files\Gamevance\gamevancelib32.dll File not found
O2 - BHO: (GameBox Toolbar) - {0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF} - C:\Program Files\GameBox\gamebox_toolbar.dll ()
O2 - BHO: () - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (PCCBHO.CPCCBHO) - {22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF} - C:\Program Files\Winferno\PC Confidential\PCCBHO.dll (Capital Intellect Inc)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Updater For ooVoo Toolbar) - {442AE524-EBA5-4b17-82F3-888D68BC999A} - C:\Program Files\oovootb\auxi\oovooAu.dll (Visicom Media)
O2 - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\MediaBar\DataMngr\IEBHO.dll (iMesh, Inc)
O2 - BHO: (PriceGong Class) - {4D3F3F3A-0E4B-4085-9032-7D072072319A} - C:\Program Files\PriceGong\2.0.0\PriceLoadIE.dll (PriceGong)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (no name) - {99E00A4C-D35E-11DD-BA95-9B6A56D89593} - No CLSID value found.
O2 - BHO: (ooVoo Toolbar) - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll ()
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O2 - BHO: (MediaBar) - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - C:\Program Files\iMesh Applications\MediaBar\ToolBar\iMeshMediaBarDx.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll File not found
O2 - BHO: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.)
O2 - BHO: (Gamevance Text) - {BEAC7DC8-E106-4C6A-931E-5A42E7362883} - C:\Program Files\Gamevance\gvtl.dll ()
O2 - BHO: () - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O2 - BHO: (NetAssistantBHO Class) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\Freeze.com\My.Freeze.com NetAssistant\NetAssistant.dll (W3i, LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (GameBox Toolbar) - {0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF} - C:\Program Files\GameBox\gamebox_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKLM\..\Toolbar: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKLM\..\Toolbar: (ooVoo Toolbar) - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files\oovootb\oovoodx.dll ()
O3 - HKLM\..\Toolbar: (MediaBar) - {ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F} - C:\Program Files\iMesh Applications\MediaBar\ToolBar\iMeshMediaBarDx.dll ()
O3 - HKLM\..\Toolbar: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
O4 - HKLM..\Run: [BroadWave] C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
O4 - HKLM..\Run: [BSDAppUpdater] C:\Program Files\Common Files\BSD\AppUpdater\BSDChecker.exe (Bootstrap Software Development)
O4 - HKLM..\Run: [DataMngr] C:\Program Files\iMesh Applications\MediaBar\DataMngr\DataMngrUI.exe (iMesh, Inc)
O4 - HKLM..\Run: [DMHotKey] C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe (SAMSUNG Electronics)
O4 - HKLM..\Run: [Gamevance] C:\Program Files\Gamevance\gamevance32.exe File not found
O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\Samsung\MagicKBD\PreMKbd.exe ()
O4 - HKLM..\Run: [nlgxtayd] C:\Documents and Settings\LocalService\Local Settings\Application Data\jfemsclun\rpthiynshdw.exe File not found
O4 - HKLM..\Run: [SUPBackGround] C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe ()
O4 - HKLM..\Run: [svchost] C:\Documents and Settings\John Hurst\Application Data\Microsoft\svchost.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VerboseRun] C:\Program Files\NCH Swift Sound\Verbose\verbose.exe File not found
O4 - HKCU..\Run: [BatteryLifeExtender] C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe (Samsung Electronics. Co. Ltd.)
O4 - HKCU..\Run: [CSmileys] C:\PROGRA~1\Crawler\Smileys\CSmileysIM.exe File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTAgent.exe File not found
O4 - HKCU..\Run: [Jing] C:\Program Files\TechSmith\Jing\Jing.exe (TechSmith Corporation)
O4 - HKCU..\Run: [ManyCam] C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
O4 - HKCU..\Run: [ooVoo.exe] C:\program files\oovoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
O4 - HKCU..\Run: [U36VRSFLG6] C:\DOCUME~1\JM\LOCALS~1\Temp\Vqe.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\JM\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
F3 - HKCU WinNT: Load - (C:\DOCUME~1\JM\LOCALS~1\Temp\dwm.exe) - C:\Documents and Settings\JM\Local Settings\Temp\dwm.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (Capital Intellect, Inc)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (Capital Intellect, Inc)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\gameboxchrome {494D4E3B-FA53-4487-8AF6-3F50FE1167A9} - C:\Program Files\GameBox\gamebox_toolbar.dll ()
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\tbr {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll) - C:\Program Files\iMesh Applications\MediaBar\DataMngr\datamngr.dll (iMesh, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\JM\Application Data\Microsoft\Windows\shell.exe) - C:\Documents and Settings\JM\Application Data\Microsoft\Windows\shell.exe ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: SwUpdate - {003541A1-3BC0-1B1C-AAF3-040114001C01}— | M] (Microsoft Corporation) - CLSID or File not found.
O24 - Desktop WallPaper: C:\Documents and Settings\JM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\JM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/13 20:47:07 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{339222ac-44c4-11de-8867-001377b4714c}\Shell - "" = AutoRun
O33 - MountPoints2\{339222ac-44c4-11de-8867-001377b4714c}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{339222ac-44c4-11de-8867-001377b4714c}\Shell\AutoRun\command - "" = D:\Autorun.exe – File not found
O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell - "" = AutoRun
O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell\1\Command - "" = Recycle.exe
O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell\2\Command - "" = Recycle.exe
O33 - MountPoints2\{e63f9308-462c-11de-8869-001377b682bf}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS
http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.CFHD - C:\WINDOWS\System32\cfhd.dll (CineForm Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)
========== Files/Folders - Created Within 30 Days ==========
[2010/11/01 22:33:12 | 000,000,000 | R–D | C] – C:\32788R22FWJFW
[2010/10/26 20:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\JM\Local Settings\Application Data\AVG Security Toolbar
[2010/10/19 07:01:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\35148
[2009/12/26 11:23:16 | 000,800,544 | —- | C] (Sun Microsystems, Inc.) – C:\Program Files\JavaSetup6u17-rv.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/02 20:22:01 | 000,000,966 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1006UA.job
[2010/11/02 20:21:04 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/02 20:15:53 | 067,122,403 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/11/02 20:13:55 | 000,000,432 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{F89E5EF8-7ACA-4DBF-954D-55BFE72ABEE9}.job
[2010/11/01 22:36:00 | 000,000,266 | -H– | M] () – C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/11/01 22:29:05 | 003,898,593 | —- | M] () – C:\Documents and Settings\JM\Desktop\ComboFix.exe
[2010/11/01 22:05:00 | 000,000,240 | -H– | M] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/11/01 21:50:00 | 000,000,270 | -H– | M] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/11/01 21:43:15 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/01 21:43:13 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\PCConfidential.job
[2010/11/01 21:42:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/01 21:42:41 | 1063,702,528 | -HS- | M] () – C:\hiberfil.sys
[2010/11/01 21:40:00 | 000,000,998 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1005UA.job
[2010/10/31 20:40:00 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1005Core.job
[2010/10/31 13:27:24 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/29 19:21:27 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/10/29 14:39:10 | 000,000,484 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for John Hurst.job
[2010/10/29 07:22:00 | 000,000,914 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1006Core.job
[2010/10/28 17:23:18 | 000,000,783 | —- | M] () – C:\Documents and Settings\JM\Desktop\Shortcut to chrome.lnk
[2010/10/27 16:44:17 | 000,028,672 | —- | M] () – C:\Documents and Settings\JM\My Documents\El tiempo en Miami.doc
[2010/10/27 16:21:31 | 000,002,497 | —- | M] () – C:\Documents and Settings\JM\Desktop\Microsoft Office Word 2003.lnk
[2010/10/26 22:57:00 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\wavepadDowngrade.job
[2010/10/26 21:22:06 | 000,313,968 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/24 18:59:09 | 000,020,992 | —- | M] () – C:\Documents and Settings\JM\My Documents\edgar allen poe.doc
[2010/10/24 18:49:49 | 000,104,448 | —- | M] () – C:\Documents and Settings\JM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/24 15:16:22 | 000,029,696 | —- | M] () – C:\Documents and Settings\JM\My Documents\Independant Novel Synopsis 10.26.10.doc
[2010/10/21 22:57:00 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2010/10/19 19:40:52 | 000,000,650 | —- | M] () – C:\Documents and Settings\JM\Desktop\Firefox.lnk
[2010/10/15 06:41:29 | 000,028,672 | —- | M] () – C:\Documents and Settings\JM\My Documents\science notes 10.15..doc
[2010/10/14 05:29:46 | 000,040,448 | —- | M] () – C:\Documents and Settings\JM\My Documents\science notes 218.doc
[2010/10/13 07:49:05 | 000,040,448 | —- | M] () – C:\Documents and Settings\JM\My Documents\science notes 312.doc
[2010/10/07 16:37:10 | 000,000,162 | -H– | M] () – C:\Documents and Settings\JM\My Documents\~$ Birthday List.doc
[2010/10/07 16:37:09 | 001,334,272 | —- | M] () – C:\Documents and Settings\JM\My Documents\JM Birthday List.doc
[2010/10/05 19:32:59 | 000,031,232 | —- | M] () – C:\Documents and Settings\JM\My Documents\98-104.doc
[2010/10/05 07:09:07 | 000,031,744 | —- | M] () – C:\Documents and Settings\JM\My Documents\90-97.doc
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/01 22:29:01 | 003,898,593 | —- | C] () – C:\Documents and Settings\JM\Desktop\ComboFix.exe
[2010/10/28 17:23:18 | 000,000,783 | —- | C] () – C:\Documents and Settings\JM\Desktop\Shortcut to chrome.lnk
[2010/10/27 16:44:16 | 000,028,672 | —- | C] () – C:\Documents and Settings\JM\My Documents\El tiempo en Miami.doc
[2010/10/26 20:07:26 | 000,000,266 | -H– | C] () – C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/10/26 20:07:21 | 000,000,270 | -H– | C] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/10/26 20:07:02 | 000,000,240 | -H– | C] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/10/24 18:59:09 | 000,020,992 | —- | C] () – C:\Documents and Settings\JM\My Documents\edgar allen poe.doc
[2010/10/24 15:16:22 | 000,029,696 | —- | C] () – C:\Documents and Settings\JM\My Documents\Independant Novel Synopsis 10.26.10.doc
[2010/10/19 19:40:52 | 000,000,650 | —- | C] () – C:\Documents and Settings\JM\Desktop\Firefox.lnk
[2010/10/15 06:41:28 | 000,028,672 | —- | C] () – C:\Documents and Settings\JM\My Documents\science notes 10.15..doc
[2010/10/14 05:25:09 | 000,040,448 | —- | C] () – C:\Documents and Settings\JM\My Documents\science notes 218.doc
[2010/10/13 07:49:05 | 000,040,448 | —- | C] () – C:\Documents and Settings\JM\My Documents\science notes 312.doc
[2010/10/12 22:57:45 | 000,000,292 | —- | C] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2010/10/11 14:23:14 | 000,000,292 | —- | C] () – C:\WINDOWS\tasks\wavepadDowngrade.job
[2010/10/07 16:37:10 | 000,000,162 | -H– | C] () – C:\Documents and Settings\JM\My Documents\~$ Birthday List.doc
[2010/10/07 16:37:09 | 001,334,272 | —- | C] () – C:\Documents and Settings\JM\My Documents\JM Birthday List.doc
[2010/10/05 19:32:58 | 000,031,232 | —- | C] () – C:\Documents and Settings\JM\My Documents\98-104.doc
[2010/10/05 07:09:06 | 000,031,744 | —- | C] () – C:\Documents and Settings\JM\My Documents\90-97.doc
[2010/09/23 22:48:59 | 000,348,536 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/27 11:10:43 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2010/07/26 22:18:06 | 000,697,328 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2010/07/25 13:28:37 | 000,000,789 | —- | C] () – C:\WINDOWS\hegames.ini
[2010/04/06 22:13:07 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/03/04 19:21:05 | 000,050,630 | —- | C] () – C:\Documents and Settings\JM\Application Data\speech.wav
[2009/12/26 21:17:53 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2009/12/26 15:02:47 | 000,104,448 | —- | C] () – C:\Documents and Settings\JM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/26 02:00:22 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/26 01:19:06 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\John Hurst_KBD.ini
[2009/12/25 17:21:14 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\JM_KBD.ini
[2009/10/05 19:46:46 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/05/13 20:59:17 | 000,000,002 | —- | C] () – C:\WINDOWS\HotFixList.ini
[2009/05/13 20:59:11 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2009/05/13 20:59:11 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\Owner_KBD.ini
[2009/05/13 20:59:09 | 000,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2009/05/13 20:59:09 | 000,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2009/05/13 20:59:09 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2009/05/13 20:59:09 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2009/05/13 20:59:09 | 000,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2009/05/13 20:59:09 | 000,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2009/05/13 20:59:09 | 000,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2009/05/13 20:59:09 | 000,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2009/05/13 20:59:09 | 000,001,857 | —- | C] () – C:\WINDOWS\System32\KBDUU.INI
[2009/05/13 20:59:09 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2009/05/13 20:59:09 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2009/05/13 20:59:09 | 000,001,834 | —- | C] () – C:\WINDOWS\System32\KBDU.INI
[2009/05/13 20:59:09 | 000,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2009/05/13 20:59:09 | 000,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2009/05/13 20:59:09 | 000,001,697 | —- | C] () – C:\WINDOWS\System32\KBDV.INI
[2009/05/13 20:59:09 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2009/05/13 20:59:09 | 000,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2009/05/13 20:57:52 | 000,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2009/05/13 20:57:52 | 000,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2009/05/13 20:53:57 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/05/13 20:51:14 | 000,004,300 | —- | C] () – C:\WINDOWS\System32\MEMIO.SYS
[2009/05/13 18:57:57 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2009/05/13 13:39:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/03/23 18:40:06 | 002,854,976 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2009/02/18 23:08:50 | 000,043,240 | —- | C] () – C:\WINDOWS\System32\drivers\WOWXT_kern_i386.sys
[2009/02/18 23:08:48 | 000,025,560 | —- | C] () – C:\WINDOWS\System32\drivers\WOWFilter.sys
[2009/02/18 23:08:46 | 000,036,712 | —- | C] () – C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
========== LOP Check ==========
[2010/07/23 12:43:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\21271
[2010/10/19 07:01:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\35148
[2010/06/30 12:33:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\3B261
[2010/10/26 17:49:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/08/12 14:28:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/05/20 16:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BarQuery
[2010/09/05 15:51:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BearShare
[2010/02/10 19:37:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BSD
[2010/07/26 11:20:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/07/26 22:17:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010/07/05 18:32:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Inspector
[2010/01/10 13:55:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2010/02/17 21:28:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Extensions
[2010/03/23 21:30:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2010/03/20 16:11:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoBit Games
[2010/06/24 10:28:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iMesh
[2010/04/15 20:02:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/07/26 22:38:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lionhead Studios
[2010/03/07 17:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/09/05 17:00:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NoteBurner
[2010/07/09 16:27:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
[2010/07/12 13:57:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PhotoChances
[2010/04/19 18:08:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/06/14 15:42:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Temp
[2010/07/05 18:33:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UAB
[2010/03/23 21:08:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\W3i
[2010/08/03 19:04:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2009/12/26 04:35:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinClon
[2010/03/30 20:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Winferno
[2009/05/13 20:54:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLAN
[2010/06/30 20:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/25 17:35:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/09/05 15:52:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{A7135C8B-F43E-46A1-88B2-668FD0EBD306}
[2010/06/24 10:29:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{B76CD956-76B8-4594-8C7C-A647643939D2}
[2010/05/25 13:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\3M
[2010/07/09 16:21:32 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Antares
[2010/02/10 19:34:14 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\AnvSoft
[2010/07/27 10:53:50 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Atari
[2010/10/24 17:39:18 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Audacity
[2010/07/26 09:32:52 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\BitComet
[2010/07/29 00:17:51 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\BitTorrent
[2010/02/10 19:37:36 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\BSD
[2010/07/26 22:29:39 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\DAEMON Tools Lite
[2010/07/26 22:26:10 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\DAEMON Tools Pro
[2010/01/10 17:54:12 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\EmailNotifier
[2010/04/08 22:10:46 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Facebook
[2010/03/24 07:55:22 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\FCSB000062035
[2010/08/13 22:29:52 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\GameBox
[2010/05/25 13:21:38 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\GetRightToGo
[2010/07/13 16:43:43 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\imeshmediabartb
[2010/05/03 16:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Inbox Toolbar
[2010/07/27 00:43:48 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\Leadertech
[2010/07/27 17:31:26 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\ManyCam
[2010/03/04 19:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\NCH Swift Sound
[2010/01/10 13:56:49 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\ooVoo Details
[2010/06/07 18:44:28 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\oovooinstaller
[2010/07/13 16:43:45 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\oovootb
[2010/07/27 14:04:42 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\OxelonMC
[2010/07/09 16:27:42 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\PACE Anti-Piracy
[2010/07/12 13:57:54 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\PhotoChances
[2010/07/12 14:08:26 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\PhotoScape
[2010/07/26 20:02:37 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\PriceGong
[2010/08/25 20:23:15 | 000,000,000 | —D | M] – C:\Documents and Settings\JM\Application Data\uTorrent
[2010/08/02 16:36:00 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressburnSevenDays.job
[2010/07/29 16:36:00 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\expressburnShakeIcon.job
[2010/11/01 21:43:13 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\PCConfidential.job
[2010/11/02 20:13:55 | 000,000,432 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{F89E5EF8-7ACA-4DBF-954D-55BFE72ABEE9}.job
[2010/10/26 22:57:00 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\wavepadDowngrade.job
[2010/10/21 22:57:00 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\wavepadShakeIcon.job
[2010/11/01 21:50:00 | 000,000,270 | -H– | M] () – C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/11/01 22:05:00 | 000,000,240 | -H– | M] () – C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/11/01 22:36:00 | 000,000,266 | -H– | M] () – C:\WINDOWS\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/05/13 20:47:07 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/12/26 01:18:25 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2009/05/13 20:47:07 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/03 10:20:08 | 000,001,808 | —- | M] () – C:\Desktop Security
[2010/11/01 21:42:41 | 1063,702,528 | -HS- | M] () – C:\hiberfil.sys
[2009/05/13 20:47:07 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/07/13 01:21:02 | 000,000,289 | —- | M] () – C:\Longest Video Ever On Youtube.log
[2009/05/13 20:47:07 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 08:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/01 21:42:40 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2009/05/13 20:57:54 | 000,000,173 | —- | M] () – C:\Setup.log
[2010/11/01 21:50:48 | 000,038,058 | —- | M] () – C:\TDSSKiller.2.4.5.1_01.11.2010_21.49.26_log.txt
[2010/08/03 10:23:33 | 000,000,711 | —- | M] () – C:\Untitled.log
[2010/05/02 09:12:56 | 000,085,933 | —- | M] () – C:\WaxCrash.dmp
[2010/05/02 09:12:53 | 000,075,464 | —- | M] () – C:\WaxCrash.txt
[2010/07/26 12:58:11 | 000,000,150 | —- | M] () – C:\zrpt.xml
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/05/13 20:46:34 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2007/02/26 19:49:10 | 001,744,896 | —- | M] (TopThinks, INC.) – C:\WINDOWS\imagine digital freedom.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/10/31 21:08:30 | 000,010,511 | —- | M] () – C:\Documents and Settings\JM\Application Data\Microsoft\stor.cfg
[2010/11/01 21:43:18 | 000,104,960 | —- | M] () – C:\Documents and Settings\JM\Application Data\Microsoft\svchost.exe
< %PROGRAMFILES%\*.* >
[2009/12/26 11:23:20 | 000,800,544 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\JavaSetup6u17-rv.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/05/13 13:37:30 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/05/13 13:37:30 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/05/13 13:37:30 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/05/13 20:47:14 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2010/01/17 18:08:34 | 000,005,120 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/25 17:21:06 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\JM\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/05/13 20:51:30 | 000,000,079 | —- | M] () – C:\Documents and Settings\JM\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/11/01 22:29:05 | 003,898,593 | —- | M] () – C:\Documents and Settings\JM\Desktop\ComboFix.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-15 07:24:21
========== Alternate Data Streams ==========
@Alternate Data Stream - 990 bytes -> C:\Program Files\WindowsUpdate:jUwsjxIR6OIzKGKUKuispnC92of
@Alternate Data Stream - 828 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:35E5AF34
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:453190EC
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:D1B5B4F1
@Alternate Data Stream - 1134 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:nBlALKTo5W826T0tCQ4f6WP9
@Alternate Data Stream - 1132 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:aIF2EwvJ6jviacDEypJ2H
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:5804A24D
@Alternate Data Stream - 1016 bytes -> C:\Program Files\WindowsUpdate:ZCgaypncyLSHfArnOH4DgoH66QzV
< End of report >