OTL logfile created on: 2/21/2011 4:37:53 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\hp\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 158.14 Gb Free Space | 67.91% Space Free | Partition Type: NTFS
Computer Name: HP-PC | User Name: hp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\hp\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\hp\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe (Symantec Corporation)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110220.002\navex15.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110220.002\naveng.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\NAV\1205000.07D\SYMTDIV.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\NAV\1205000.07D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\NAV\1205000.07D\SRTSPX.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110114.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\NAV\1205000.07D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\NAV\1205000.07D\Ironx86.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110218.003\IDSvix86.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\NAV\1205000.07D\SYMDS.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://toshiba.aol.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://ca.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1D 5F 48 8E FD A4 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/02/21 16:16:16 | 000,000,000 | —D | M]
O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ips\ipsbho.dll (Symantec Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\hp\Pictures\wallpaper2 copy.jpg
O24 - Desktop BackupWallPaper: C:\Users\hp\Pictures\wallpaper2 copy.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\Shell\AutoRun\command - "" = System\DriveGuard\DriveProtect.exe -run
O33 - MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\Shell\Explore\Command - "" = System\DriveGuard\DriveProtect.exe -run
O33 - MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\Shell\Open\Command - "" = System\DriveGuard\DriveProtect.exe -run
O33 - MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\Shell\AutoRun\command - "" = D:\hbcd\wintools\autorun.exe
O33 - MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\Shell\Option1\Command - "" = D:\hbcd\wintools\autorun.exe
O33 - MountPoints2\{283e29ed-ca25-11de-9d20-001eec767838}\Shell\AutoRun\command - "" = F:\wt.BAT
O33 - MountPoints2\{7f778b13-f724-11df-bdae-001eec87380e}\Shell - "" = AutoRun
O33 - MountPoints2\{7f778b13-f724-11df-bdae-001eec87380e}\Shell\AutoRun\command - "" = G:\HPLauncher.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.vp60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/02/21 16:35:46 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\hp\Desktop\OTL.exe
[2011/02/21 16:25:57 | 001,372,248 | —- | C] (Kaspersky Lab ZAO) – C:\Users\hp\Desktop\TDSSKiller.exe
[2011/02/20 20:31:29 | 000,652,336 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symefa.sys
[2011/02/20 20:31:29 | 000,509,560 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.sys
[2011/02/20 20:31:29 | 000,340,016 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symds.sys
[2011/02/20 20:31:29 | 000,330,360 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symtdiv.sys
[2011/02/20 20:31:29 | 000,295,032 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symnets.sys
[2011/02/20 20:31:29 | 000,136,312 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\ironx86.sys
[2011/02/20 20:31:29 | 000,050,168 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.sys
[2011/02/20 20:31:08 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\NAV\1205000.07D
[2011/02/20 19:24:35 | 000,126,512 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/02/20 19:24:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/02/20 19:24:30 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/02/20 19:23:22 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\NAV
[2011/02/20 19:23:16 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton AntiVirus
[2011/02/20 19:23:16 | 000,000,000 | —D | C] – C:\Program Files\Norton AntiVirus
[2011/02/20 19:23:14 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2011/02/20 19:23:00 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2011/02/20 19:23:00 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2011/02/16 18:34:34 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/02/16 18:34:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/16 18:34:29 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/02/16 18:34:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/10 13:07:00 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/02/09 16:40:26 | 002,039,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/02/09 16:40:01 | 003,602,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/02/09 16:40:00 | 003,550,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/02/09 16:39:51 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/02/09 16:39:51 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/02/09 16:39:51 | 000,797,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FntCache.dll
[2011/02/09 16:39:50 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/02/09 16:39:50 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/02/09 16:39:49 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/02/09 16:39:49 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/02/09 16:39:49 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/02/09 16:39:49 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/02/09 16:39:48 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/02/09 16:39:47 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/02/09 16:39:47 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/02/09 16:39:47 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/02/09 16:39:47 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/02/09 16:39:46 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/02/09 16:39:46 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/02/09 16:39:46 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/02/09 16:39:46 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/02/09 16:39:45 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/02/09 16:39:45 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/02/09 16:39:44 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/02/09 16:39:44 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/02/09 16:39:42 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/02/09 16:39:41 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/02/09 16:39:41 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/02/09 16:38:57 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/02/09 16:38:57 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/02/09 16:38:56 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/02/09 16:38:56 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/02/09 16:38:56 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/02/09 16:38:56 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/02/09 16:38:56 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/02/09 16:38:56 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/02/09 16:38:56 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/02/09 16:38:56 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/02/09 16:38:56 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/02/09 16:38:55 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/02/09 16:38:55 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/02/09 16:38:55 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/02/09 16:38:55 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/02/09 16:38:55 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/02/09 16:38:55 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/02/09 16:38:44 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/02/09 16:38:44 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/02/07 17:32:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\HP
[2011/02/07 17:32:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard
[2011/02/07 17:32:15 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard
[2011/02/07 17:30:32 | 000,118,272 | —- | C] (Hewlett-Packard Company) – C:\Windows\System32\hpz3l5mu.dll
[2011/02/07 17:30:02 | 000,000,000 | -H-D | C] – C:\Config.Msi
[2011/02/07 17:20:30 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2011/02/07 17:20:26 | 000,271,704 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hpzids01.dll
[2011/02/07 17:20:25 | 000,729,088 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hpowiax7.dll
[2011/02/07 17:20:25 | 000,372,736 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hppldcoi.dll
[2011/02/07 17:20:24 | 000,581,632 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpotscl6.dll
[2011/02/07 17:20:24 | 000,303,104 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpovst15.dll
[2011/02/07 17:08:26 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/02/07 17:07:48 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2011/01/31 15:45:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/01/31 15:44:46 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/01/31 15:44:44 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/01/23 12:57:59 | 000,000,000 | —D | C] – C:\Users\hp\Documents\tv
========== Files - Modified Within 30 Days ==========
[2011/08/16 20:28:06 | 000,022,683 | —- | M] () – C:\Users\hp\Documents\grey.jpg
[2011/02/21 16:36:35 | 000,611,992 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/02/21 16:36:35 | 000,107,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/02/21 16:36:12 | 000,035,064 | —- | M] () – C:\Users\hp\Documents\Hello Mowman.docx
[2011/02/21 16:35:52 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\hp\Desktop\OTL.exe
[2011/02/21 16:29:29 | 000,003,648 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/21 16:29:29 | 000,003,648 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/21 16:29:21 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/02/21 16:29:15 | 3210,756,096 | -HS- | M] () – C:\hiberfil.sys
[2011/02/21 16:25:44 | 001,257,772 | —- | M] () – C:\Users\hp\Desktop\tdsskiller.zip
[2011/02/21 16:14:00 | 002,081,958 | —- | M] () – C:\Windows\System32\drivers\NAV\1205000.07D\Cat.DB
[2011/02/21 16:13:59 | 000,002,136 | —- | M] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2011/02/21 11:09:14 | 001,372,248 | —- | M] (Kaspersky Lab ZAO) – C:\Users\hp\Desktop\TDSSKiller.exe
[2011/02/20 21:24:39 | 000,000,036 | —- | M] () – C:\Users\hp\AppData\Local\housecall.guid.cache
[2011/02/20 21:06:41 | 000,175,616 | —- | M] () – C:\Users\hp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/20 19:38:10 | 334,104,196 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/02/20 19:24:30 | 000,126,512 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/02/20 19:24:30 | 000,007,456 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/02/20 19:24:30 | 000,000,805 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2011/02/20 17:42:29 | 000,000,412 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{AA33D315-A20A-4FC4-B90C-F28A545631BA}.job
[2011/02/16 20:51:35 | 000,062,432 | —- | M] () – C:\Users\hp\Documents\myreport khan.pdf
[2011/02/16 20:49:34 | 000,062,925 | —- | M] () – C:\Users\hp\Documents\myreport hunain.pdf
[2011/02/16 18:34:34 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/13 19:23:37 | 000,001,892 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/02/10 12:04:24 | 000,374,680 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/02/07 17:37:12 | 000,017,447 | —- | M] () – C:\Users\hp\Documents\hunain CV.docx
[2011/02/07 17:35:59 | 000,163,142 | —- | M] () – C:\Windows\hpoins28.dat
[2011/02/07 11:38:55 | 000,043,812 | —- | M] () – C:\Users\hp\Documents\myreport.PDF
[2011/02/05 00:02:06 | 731,430,913 | —- | M] () – C:\Users\hp\Documents\the hangover.avi
[2011/01/31 15:45:47 | 000,001,664 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
========== Files Created - No Company Name ==========
[2011/02/21 16:36:11 | 000,035,064 | —- | C] () – C:\Users\hp\Documents\Hello Mowman.docx
[2011/02/21 16:25:38 | 001,257,772 | —- | C] () – C:\Users\hp\Desktop\tdsskiller.zip
[2011/02/21 16:12:45 | 002,081,958 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\Cat.DB
[2011/02/20 21:24:39 | 000,000,036 | —- | C] () – C:\Users\hp\AppData\Local\housecall.guid.cache
[2011/02/20 20:31:29 | 000,007,877 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnetv.cat
[2011/02/20 20:31:29 | 000,007,528 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\iron.cat
[2011/02/20 20:31:29 | 000,007,458 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnet.cat
[2011/02/20 20:31:29 | 000,007,456 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symefa.cat
[2011/02/20 20:31:29 | 000,007,454 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.cat
[2011/02/20 20:31:29 | 000,007,450 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symds.cat
[2011/02/20 20:31:29 | 000,007,450 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.cat
[2011/02/20 20:31:29 | 000,003,374 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symefa.inf
[2011/02/20 20:31:29 | 000,002,792 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symds.inf
[2011/02/20 20:31:29 | 000,001,474 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnetv.inf
[2011/02/20 20:31:29 | 000,001,446 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnet.inf
[2011/02/20 20:31:29 | 000,001,389 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.inf
[2011/02/20 20:31:29 | 000,001,383 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.inf
[2011/02/20 20:31:29 | 000,000,742 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\iron.inf
[2011/02/20 20:31:08 | 000,000,172 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\isolate.ini
[2011/02/20 19:24:35 | 000,007,456 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/02/20 19:24:35 | 000,000,805 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2011/02/20 19:24:09 | 000,002,136 | —- | C] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2011/02/16 20:51:34 | 000,062,432 | —- | C] () – C:\Users\hp\Documents\myreport khan.pdf
[2011/02/16 20:49:30 | 000,062,925 | —- | C] () – C:\Users\hp\Documents\myreport hunain.pdf
[2011/02/16 20:28:53 | 000,022,683 | —- | C] () – C:\Users\hp\Documents\grey.jpg
[2011/02/16 18:34:34 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/10 13:06:27 | 334,104,196 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/02/07 17:20:33 | 000,000,355 | —- | C] () – C:\ProgramData\hpzinstall.log
[2011/02/07 17:20:32 | 000,163,142 | —- | C] () – C:\Windows\hpoins28.dat
[2011/02/07 17:20:32 | 000,000,796 | —- | C] () – C:\Windows\hpomdl28.dat
[2011/02/07 13:34:16 | 000,017,447 | —- | C] () – C:\Users\hp\Documents\hunain CV.docx
[2011/02/07 11:38:53 | 000,043,812 | —- | C] () – C:\Users\hp\Documents\myreport.PDF
[2011/02/05 00:01:32 | 731,430,913 | —- | C] () – C:\Users\hp\Documents\the hangover.avi
[2011/01/31 15:45:47 | 000,001,664 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/01/03 16:08:03 | 000,000,161 | —- | C] () – C:\Windows\AutoKMS.ini
[2010/10/11 12:03:21 | 000,000,065 | —- | C] () – C:\Windows\DIPLOMA.INI
[2010/10/11 12:03:21 | 000,000,047 | —- | C] () – C:\Windows\BRGVARS.INI
[2010/10/11 12:03:20 | 000,000,023 | —- | C] () – C:\Windows\VBCTL3D.INI
[2010/09/26 22:21:53 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/09/18 23:32:56 | 000,175,616 | —- | C] () – C:\Users\hp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/18 22:06:11 | 000,081,158 | —- | C] () – C:\Windows\System32\manage-bde.ini.en
[2010/09/12 22:36:09 | 000,140,288 | —- | C] () – C:\Windows\System32\igfxtvcx.dll
[2010/05/24 14:33:00 | 004,670,829 | —- | C] () – C:\Windows\System32\libavcodec.dll
[2010/05/24 14:33:00 | 001,529,856 | —- | C] () – C:\Windows\System32\ff_samplerate.dll
[2010/05/24 14:33:00 | 001,447,921 | —- | C] () – C:\Windows\System32\ffmpegmt.dll
[2010/05/24 14:33:00 | 000,877,385 | —- | C] () – C:\Windows\System32\ff_x264.dll
[2010/05/24 14:33:00 | 000,336,384 | —- | C] () – C:\Windows\System32\ff_libfaad2.dll
[2010/05/24 14:33:00 | 000,324,096 | —- | C] () – C:\Windows\System32\TomsMoComp_ff.dll
[2010/05/24 14:33:00 | 000,248,320 | —- | C] () – C:\Windows\System32\ff_kernelDeint.dll
[2010/05/24 14:33:00 | 000,216,576 | —- | C] () – C:\Windows\System32\ff_libdts.dll
[2010/05/24 14:33:00 | 000,151,552 | —- | C] () – C:\Windows\System32\ff_libmad.dll
[2010/05/24 14:33:00 | 000,145,408 | —- | C] () – C:\Windows\System32\libmpeg2_ff.dll
[2010/05/24 14:33:00 | 000,139,944 | —- | C] () – C:\Windows\System32\libmplayer.dll
[2010/05/24 14:33:00 | 000,121,856 | —- | C] () – C:\Windows\System32\ff_liba52.dll
[2010/05/24 14:33:00 | 000,116,736 | —- | C] () – C:\Windows\System32\ff_tremor.dll
[2010/05/24 14:33:00 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/05/24 14:33:00 | 000,100,864 | —- | C] () – C:\Windows\System32\ff_wmv9.dll
[2010/05/24 14:33:00 | 000,097,792 | —- | C] () – C:\Windows\System32\ff_unrar.dll
[2010/05/19 15:59:20 | 000,150,528 | —- | C] () – C:\Windows\System32\mkx.dll
[2010/05/19 15:59:10 | 000,109,568 | —- | C] () – C:\Windows\System32\avi.dll
[2010/05/19 15:59:02 | 000,141,824 | —- | C] () – C:\Windows\System32\mp4.dll
[2010/05/19 15:58:52 | 000,123,392 | —- | C] () – C:\Windows\System32\ogm.dll
[2010/05/19 15:58:18 | 000,154,112 | —- | C] () – C:\Windows\System32\ts.dll
[2010/05/19 15:58:08 | 000,249,856 | —- | C] () – C:\Windows\System32\dxr.dll
[2010/05/19 15:57:42 | 000,097,792 | —- | C] () – C:\Windows\System32\avs.dll
[2010/05/19 15:57:26 | 000,093,184 | —- | C] () – C:\Windows\System32\avss.dll
[2010/05/19 15:55:40 | 000,080,384 | —- | C] () – C:\Windows\System32\mkzlib.dll
[2010/05/19 15:55:36 | 000,024,576 | —- | C] () – C:\Windows\System32\mkunicode.dll
[2009/11/05 11:18:32 | 000,000,000 | —- | C] () – C:\Users\hp\AppData\Local\QSwitch.txt
[2009/11/05 11:18:32 | 000,000,000 | —- | C] () – C:\Users\hp\AppData\Local\DSwitch.txt
[2009/11/05 11:18:32 | 000,000,000 | —- | C] () – C:\Users\hp\AppData\Local\AtStart.txt
[2009/11/05 10:52:39 | 000,000,680 | —- | C] () – C:\Users\hp\AppData\Local\d3d9caps.dat
[2009/01/10 17:15:44 | 000,159,744 | —- | C] () – C:\Windows\System32\mmfinfo.dll
[2008/11/06 10:37:32 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/02/11 19:55:18 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1437.dll
[2007/10/13 04:30:20 | 000,000,137 | —- | C] () – C:\Windows\System32\Registration.ini
[2007/08/20 23:34:08 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1318.dll
[2007/08/20 23:25:00 | 000,910,720 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2006/11/02 07:34:20 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2011/02/21 16:27:27 | 000,032,564 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/02/20 17:42:29 | 000,000,412 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{AA33D315-A20A-4FC4-B90C-F28A545631BA}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/11/05 12:19:25 | 000,000,086 | —- | M] () – C:\bcmwl6.log
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/11/05 10:43:05 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/04/14 22:51:45 | 000,171,136 | RHS- | M] () – C:\grldr
[2011/02/21 16:29:15 | 3210,756,096 | -HS- | M] () – C:\hiberfil.sys
[2011/02/21 16:29:14 | 3524,546,560 | -HS- | M] () – C:\pagefile.sys
[2011/02/21 16:27:20 | 000,064,340 | —- | M] () – C:\TDSSKiller.2.4.18.0_21.02.2011_16.26.07_log.txt
[2011/02/21 16:36:17 | 000,063,734 | —- | M] () – C:\TDSSKiller.2.4.18.0_21.02.2011_16.30.44_log.txt
< %systemroot%\Fonts\*.com >
[2006/11/02 07:35:26 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:35:26 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:35:26 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/10/11 12:22:13 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2006/11/02 07:34:09 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2010/09/26 21:42:16 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/26 22:50:02 | 000,000,286 | -HS- | M] () – C:\Users\hp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/02/21 16:35:52 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\hp\Desktop\OTL.exe
[2011/02/21 11:09:14 | 001,372,248 | —- | M] (Kaspersky Lab ZAO) – C:\Users\hp\Desktop\TDSSKiller.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2006/11/02 07:33:56 | 000,000,802 | —- | M] () – C:\Windows\addins\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2009/11/05 10:52:53 | 000,000,402 | -HS- | M] () – C:\Users\hp\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2011/02/07 17:36:00 | 000,000,355 | —- | M] () – C:\ProgramData\hpzinstall.log
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-10 16:00:43
< End of report >