Hi here it is……..
OTL logfile created on: 08/04/2011 14:50:50 - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Administrator
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 238.16 Gb Free Space | 51.13% Space Free | Partition Type: NTFS
Drive E: | 581.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: ANDREW-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Administrator\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
========== Modules (SafeList) ==========
MOD - C:\Users\Administrator\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcr80.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcp80.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (vsmon) – C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Media Toolbox 6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (Vsdatant) – C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (t3) – C:\Windows\System32\drivers\t3.sys (Creative Technology Ltd.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (MRV6X32P) – C:\Windows\System32\drivers\MRVW13B.sys (Marvell Semiconductor, Inc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://uk.msn.com/
IE - HKLM\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://uk.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Yahoo!"
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:[removed]
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/02/07 14:47:43 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/02 23:00:33 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/07 12:57:39 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/01/31 23:20:12 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2011/01/31 23:20:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Extensions
[2011/01/31 23:20:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/03/27 13:53:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\bhwd8ppd.default\extensions
[2011/02/06 09:59:22 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) – C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\bhwd8ppd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/04/07 12:57:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/07 12:57:41 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2011/02/07 14:47:43 | 000,000,000 | -H-D | M] (ZoneAlarm Security Engine) – C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
[2011/04/07 12:56:05 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/03 18:47:02 | 000,001,538 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/03 18:47:02 | 000,000,947 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/03 18:47:02 | 000,000,769 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2009/04/07 14:59:38 | 000,000,872 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\Yahooober4735472.gif
[2011/02/16 19:31:31 | 000,000,199 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\Yahooober4735472.src
O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | -H– | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [SPIRunE] C:\Windows\System32\SpiRunE.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884}
http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx2.hotmail.com/mail/w4/pr01/photo…NPUplden-gb.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://ccfiles.creative.com/Web/softwareup…15112/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | -H– | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/06/14 11:44:42 | 000,000,085 | R— | M] () - E:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/04/08 14:48:14 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{DD0BF8A3-9786-41F9-8924-DD66217F3C2E}
[2011/04/08 14:47:49 | 000,000,000 | —D | C] – C:\Windows\LastGood
[2011/04/07 12:57:39 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/04/07 12:57:39 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/04/07 12:57:39 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/07 12:47:21 | 016,525,088 | —- | C] (Sun Microsystems, Inc.) – C:\Users\Administrator\jre-6u24-windows-i586.exe
[2011/04/07 12:33:39 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{4B14A281-11EB-40D1-B456-A11EECEA2049}
[2011/04/06 20:38:58 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{248239B4-518D-40FD-91A1-9C6B51331548}
[2011/04/06 12:01:06 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/04/06 08:48:17 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/06 08:48:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/06 08:48:14 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/04/06 08:47:46 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\Administrator\mbam-setup-1.50.1.1100.exe
[2011/04/06 08:38:21 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{46150EDD-ADFE-4191-83FB-268566A5C543}
[2011/04/05 20:46:58 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/05 08:54:19 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{F4FCF50E-D051-4604-957E-8C22B1AB346E}
[2011/04/05 08:46:29 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{91ED111D-CD38-4AB4-A4B9-FB05689B2E41}
[2011/04/04 15:34:16 | 000,000,000 | —D | C] – C:\_OTL
[2011/04/04 10:05:23 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Administrator\OTL.exe
[2011/04/04 10:03:10 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{A34D152F-16D7-436E-B4E7-0CE11E0F1EBF}
[2011/04/03 23:21:57 | 000,000,000 | —D | C] – C:\Users\Administrator\tdsskiller
[2011/04/03 18:31:13 | 000,000,000 | R–D | C] – C:\32788R22FWJFW
[2011/04/03 15:35:56 | 001,090,912 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Users\Administrator\avg_remover_stf_x86_2011_1184.exe
[2011/04/03 09:41:06 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{78EB8057-2B37-4E81-A487-74F19944D270}
[2011/04/02 09:39:20 | 000,000,000 | -H-D | C] – C:\Users\Administrator\RK_Quarantine
[2011/04/02 09:29:26 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{805C14E6-AA7B-4D3C-BE40-6F40DCA36B11}
[2011/04/01 11:06:06 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{7A0F5FB6-8BEC-4F9F-944D-DEB0FD832895}
[2011/04/01 10:57:39 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{73813386-9006-4EB5-BD8C-A921C07E10B6}
[2011/03/31 22:15:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{9A1CCCB4-25D3-4CAF-8C6F-30CAB69455C7}
[2011/03/30 21:21:03 | 000,000,000 | -H-D | C] – C:\Program Files\Trend Micro
[2011/03/30 21:21:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/03/23 14:51:05 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/23 14:51:05 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
========== Files - Modified Within 30 Days ==========
[2011/04/08 14:49:11 | 000,000,900 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/08 14:47:34 | 000,000,896 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/08 14:47:32 | 000,037,685 | —- | M] () – C:\ProgramData\nvModes.001
[2011/04/08 14:47:31 | 000,004,192 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/08 14:47:31 | 000,004,192 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/08 14:47:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/08 14:47:26 | 3220,545,536 | -HS- | M] () – C:\hiberfil.sys
[2011/04/08 12:19:00 | 000,000,938 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3164612162-256102785-1375235700-500UA.job
[2011/04/07 20:31:03 | 000,029,184 | —- | M] () – C:\Users\Administrator\Performance Tests Conclusion
[2011/04/07 17:19:00 | 000,000,886 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3164612162-256102785-1375235700-500Core.job
[2011/04/07 16:48:51 | 000,294,400 | —- | M] () – C:\Users\Administrator\exeHelper.com
[2011/04/07 12:56:03 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/04/07 12:56:03 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/04/07 12:56:03 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/04/07 12:56:03 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/07 12:47:35 | 016,525,088 | —- | M] (Sun Microsystems, Inc.) – C:\Users\Administrator\jre-6u24-windows-i586.exe
[2011/04/07 12:42:07 | 000,001,892 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/04/06 08:48:17 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/06 08:47:53 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Administrator\mbam-setup-1.50.1.1100.exe
[2011/04/04 10:05:25 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Administrator\OTL.exe
[2011/04/03 23:20:11 | 001,263,721 | —- | M] () – C:\Users\Administrator\tdsskiller.zip
[2011/04/03 16:03:40 | 004,310,402 | —- | M] () – C:\Users\Administrator\mytool.exe
[2011/04/03 15:51:19 | 000,037,685 | —- | M] () – C:\ProgramData\nvModes.dat
[2011/04/03 15:35:57 | 001,090,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Users\Administrator\avg_remover_stf_x86_2011_1184.exe
[2011/04/03 09:48:57 | 000,879,081 | —- | M] () – C:\Users\Administrator\SecurityCheck.exe
[2011/04/02 17:14:02 | 001,058,816 | —- | M] () – C:\Users\Administrator\RogueKiller.exe
[2011/04/01 18:26:55 | 341,400,810 | -H– | M] () – C:\Windows\MEMORY.DMP
[2011/03/31 22:21:55 | 001,006,778 | -H– | M] () – C:\Users\Administrator\rkill.com
[2011/03/31 22:20:16 | 001,006,778 | -H– | M] () – C:\Users\Administrator\rkill.exe
[2011/03/31 07:00:17 | 000,070,656 | -H– | M] () – C:\Users\Administrator\English c-w essay 2011 childhood
[2011/03/31 06:59:55 | 000,611,664 | -H– | M] () – C:\Windows\System32\perfh009.dat
[2011/03/31 06:59:55 | 000,109,112 | -H– | M] () – C:\Windows\System32\perfc009.dat
[2011/03/30 21:22:05 | 000,002,539 | -H– | M] () – C:\Users\Administrator\Desktop\HiJackThis.lnk
[2011/03/29 07:04:24 | 000,002,281 | -H– | M] () – C:\Users\Public\Desktop\Safari.lnk
[2011/03/28 16:55:39 | 000,002,231 | -H– | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/03/26 01:20:13 | 000,002,082 | -H– | M] () – C:\Users\Administrator\Desktop\Google Chrome.lnk
[2011/03/26 01:20:13 | 000,002,044 | -H– | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
========== Files Created - No Company Name ==========
[2011/04/07 20:31:03 | 000,029,184 | —- | C] () – C:\Users\Administrator\Performance Tests Conclusion
[2011/04/07 16:48:50 | 000,294,400 | —- | C] () – C:\Users\Administrator\exeHelper.com
[2011/04/07 12:42:07 | 000,001,892 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/04/07 12:42:06 | 000,001,804 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/04/06 08:48:17 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/03 23:20:09 | 001,263,721 | —- | C] () – C:\Users\Administrator\tdsskiller.zip
[2011/04/03 15:58:43 | 004,310,402 | —- | C] () – C:\Users\Administrator\mytool.exe
[2011/04/03 15:30:04 | 000,037,685 | —- | C] () – C:\ProgramData\nvModes.dat
[2011/04/03 15:30:04 | 000,037,685 | —- | C] () – C:\ProgramData\nvModes.001
[2011/04/02 09:38:31 | 001,058,816 | —- | C] () – C:\Users\Administrator\RogueKiller.exe
[2011/04/01 21:21:15 | 3220,545,536 | -HS- | C] () – C:\hiberfil.sys
[2011/03/31 22:21:53 | 001,006,778 | -H– | C] () – C:\Users\Administrator\rkill.com
[2011/03/31 22:17:18 | 001,006,778 | -H– | C] () – C:\Users\Administrator\rkill.exe
[2011/03/31 12:26:10 | 000,879,081 | —- | C] () – C:\Users\Administrator\SecurityCheck.exe
[2011/03/31 07:00:47 | 000,070,656 | -H– | C] () – C:\Users\Administrator\English c-w essay 2011 childhood
[2011/03/30 21:21:03 | 000,002,539 | -H– | C] () – C:\Users\Administrator\Desktop\HiJackThis.lnk
[2010/12/21 13:40:50 | 000,000,527 | -H– | C] () – C:\Windows\eReg.dat
[2010/07/25 18:40:19 | 000,003,584 | -H– | C] () – C:\Users\Administrator\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/14 10:48:32 | 000,000,210 | -H– | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/07/10 11:46:25 | 000,134,044 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2010/05/04 16:00:13 | 000,004,626 | -H– | C] () – C:\Windows\System32\AudioDrv.ini
[2010/05/04 16:00:01 | 000,000,049 | RH– | C] () – C:\Windows\System32\ctzapxx.ini
[2010/05/03 17:01:54 | 000,073,728 | -H– | C] () – C:\Windows\System32\CmdRtr.DLL
[2010/05/03 17:01:53 | 000,148,480 | -H– | C] () – C:\Windows\System32\APOMngr.DLL
[2010/05/03 17:00:04 | 000,004,984 | -H– | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/04/26 11:49:48 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/04/26 11:49:47 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/04/24 16:49:11 | 000,000,376 | -H– | C] () – C:\Windows\ODBC.INI
[2010/04/24 08:38:08 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/04/22 17:23:00 | 000,000,680 | -H– | C] () – C:\Users\Administrator\AppData\Local\d3d9caps.dat
[2009/08/26 05:29:28 | 000,150,016 | -H– | C] () – C:\Windows\System32\OemSpiE.dll
[2009/08/03 15:07:42 | 000,403,816 | -H– | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | -H– | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/15 08:22:48 | 000,032,914 | -H– | C] () – C:\Windows\System32\t3.ini
[2009/01/14 02:47:24 | 000,001,436 | -H– | C] () – C:\Windows\CfgHPSp.ini
[2009/01/14 02:47:24 | 000,001,434 | -H– | C] () – C:\Windows\Cfg05Sp.ini
[2009/01/14 02:47:24 | 000,001,434 | -H– | C] () – C:\Windows\Cfg04Sp.ini
[2009/01/14 02:47:24 | 000,001,091 | -H– | C] () – C:\Windows\Cfg03Sp.ini
[2009/01/14 02:47:24 | 000,001,091 | -H– | C] () – C:\Windows\Cfg02Sp.ini
[2009/01/14 02:47:24 | 000,001,000 | -H– | C] () – C:\Windows\Cfg01Sp.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\CfgHPHp.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\CfgHPDO.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\Cfg05DO.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\Cfg04DO.ini
[2009/01/14 02:47:24 | 000,000,930 | -H– | C] () – C:\Windows\Cfg05Hp.ini
[2009/01/14 02:47:24 | 000,000,930 | -H– | C] () – C:\Windows\Cfg04Hp.ini
[2009/01/14 02:47:24 | 000,000,818 | -H– | C] () – C:\Windows\Cfg01APR.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg03Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg03DO.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg02Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg02DO.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg01Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg01DO.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03DI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02DI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01Mic.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01LI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01DI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPRMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPRLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPFMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPDI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05DI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04DI.ini
[2006/11/02 13:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 000,305,584 | -H– | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 000,611,664 | -H– | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | -H– | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,109,112 | -H– | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | -H– | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:23:21 | 000,215,943 | -H– | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | -H– | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | -H– | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | -H– | C] () – C:\Windows\System32\mlang.dat
[2003/01/07 15:05:08 | 000,002,695 | -H– | C] () – C:\Windows\System32\OUTLPERF.INI
[1997/06/14 01:56:08 | 000,056,832 | -H– | C] () – C:\Windows\System32\iyvu9_32.dll
========== Custom Scans ==========
< MD5 for: EXPLORER.EXE >
[2008/10/29 07:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 07:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/30 04:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/28 03:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/21 03:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: WINLOGON.EXE >
[2009/04/11 07:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 07:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/21 03:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< End of report >
Thanks