Hello again,
I ran Hi Jack and OLT as asked for in the previous post. However when I tried to run GMer (the first time, my computer froze and the second time I got a blue screen). If you would like me to keep trying please let me know
Other wise I will break the OLT logs into 2 different posts. Thanks again
OLT LOG
OTL logfile created on: 3/31/2011 5:31:29 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = D:\Documents and Settings\Aleksandr\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 189.91 Gb Total Space | 181.95 Gb Free Space | 95.81% Space Free | Partition Type: NTFS
Drive D: | 298.08 Gb Total Space | 7.78 Gb Free Space | 2.61% Space Free | Partition Type: NTFS
Computer Name: SASHA | User Name: Aleksandr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Documents and Settings\Aleksandr\My Documents\Downloads\OTL (3).exe (OldTimer Tools)
PRC - D:\Documents and Settings\Aleksandr\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - D:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - D:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - D:\Documents and Settings\Aleksandr\Local Settings\Apps\2.0\X66DWTDW.1RE\3CN3NG33.19T\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe (Curse)
PRC - D:\Program Files\Zune\ZuneBusEnum.exe (Microsoft Corporation)
PRC - D:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - D:\Program Files\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - D:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\903CB56BA52F42478957BE8314837A86\PamelaPCR.exe (Scendix Software GmbH)
PRC - D:\WINDOWS\ALCFDRTM.EXE (Realtek Semiconductor Corp.)
PRC - D:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - D:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - D:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - D:\Documents and Settings\Aleksandr\Application Data\Dropbox\bin\Dropbox.exe ()
PRC - D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - D:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - D:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe ()
PRC - D:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - D:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - D:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Pinnacle Systems GmbH)
PRC - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
PRC - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
PRC - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
PRC - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
PRC - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - D:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Co.)
PRC - D:\Program Files\NETGEAR GA311 Adapter\GA311.exe ()
========== Modules (SafeList) ==========
MOD - D:\Documents and Settings\Aleksandr\My Documents\Downloads\OTL (3).exe (OldTimer Tools)
MOD - D:\Program Files\AVAST Software\Avast\snxhk.dll (AVAST Software)
MOD - D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (avast! Antivirus) – D:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (WMZuneComm) – D:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – D:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – D:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – D:\Program Files\Zune\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (MSCamSvc) – D:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (McComponentHostService) – D:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (LVPrcSrv) – D:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (Pml Driver HPZ12) – D:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) – D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
SRV - (nSvcIp) – D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
SRV - (nSvcLog) – D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
SRV - (ForcewareWebInterface) – D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe (Apache Software Foundation)
========== Driver Services (SafeList) ==========
DRV - (aswSnx) – D:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – D:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – D:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – D:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – D:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – D:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – D:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (MSHUSBVideo) – D:\WINDOWS\system32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – D:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – D:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – D:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (LVPr2Mon) – D:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – D:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (nm) – D:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (WinUSB) – D:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (emAudio) – D:\WINDOWS\system32\drivers\emAudio.sys (Pinnacle Systems, Inc.)
DRV - (DCamUSBEMPIA) – D:\WINDOWS\system32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) – D:\WINDOWS\system32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) – D:\WINDOWS\system32\drivers\emScan.sys (eMPIA Technology, Inc.)
DRV - (nvata) – D:\WINDOWS\System32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnetbus) – D:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – D:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (PCLEPCI) – D:\WINDOWS\system32\drivers\Pclepci.sys (Pinnacle Systems GmbH)
DRV - (ASAPIW2K) – D:\WINDOWS\system32\drivers\asapiW2k.sys (VOB Computersysteme GmbH)
DRV - (Diag69xp) – D:\WINDOWS\system32\drivers\diag69xp.sys (Realtek Semiconductor Corporation)
DRV - (LANPkt) – D:\WINDOWS\system32\drivers\LANPkt.sys (Windows ® 2000 DDK provider)
DRV - (ADM8511) – D:\WINDOWS\system32\drivers\ADM8511.SYS (ADMtek Incorporated)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - D:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.1.100:2
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "XfireXO Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "
http://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledItems: [removed]:11.0.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..extensions.enabledItems: avg@igeared:6.103.018.001
FF - prefs.js..extensions.enabledItems: [removed]:20110101
FF - prefs.js..keyword.URL: "
http://search.avg.com/route/?d=4d93b88c&v;=6.103.018.001&i;=26&tp;=ab&iy;=&ychte;=us&lng;=en-US&q;="
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: D:\Program Files\HBLite\bin\11.0.264.0\firefox\extensions [2010/08/27 17:01:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: D:\Program Files\AVAST Software\Avast\WebRep\FF [2011/03/30 19:54:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/20 17:03:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/12 16:43:48 | 000,000,000 | —D | M]
[2010/08/27 17:03:15 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Extensions
[2010/08/27 17:03:15 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Extensions\[removed]
[2011/03/30 23:44:44 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Firefox\Profiles\9jwm7dmn.default\extensions
[2010/09/09 19:10:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Firefox\Profiles\9jwm7dmn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/31 19:59:31 | 000,000,000 | —D | M] (XfireXO Toolbar) – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Firefox\Profiles\9jwm7dmn.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2010/06/11 02:08:24 | 000,000,917 | —- | M] () – D:\Documents and Settings\Aleksandr\Application Data\Mozilla\Firefox\Profiles\9jwm7dmn.default\searchplugins\conduit.xml
[2010/10/06 23:26:31 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/03/30 19:54:22 | 000,000,000 | —D | M] (avast! WebRep) – D:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
File not found (No name found) – D:\PROGRAM FILES\AVG\AVG10\FIREFOX4
File not found (No name found) – D:\PROGRAM FILES\AVG\AVG10\TOOLBAR\FIREFOX\AVG@IGEARED
[2010/08/27 17:01:19 | 000,000,000 | —D | M] (Hotbar Component) – D:\PROGRAM FILES\HBLITE\BIN\11.0.264.0\FIREFOX\EXTENSIONS
O1 HOSTS File: ([2003/03/31 08:00:00 | 000,000,734 | —- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - D:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - D:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - D:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast] D:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [IWHE Agent] File not found
O4 - HKLM..\Run: [LifeCam] D:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] D:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [nTrayFw] D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [PinnacleDriverCheck] D:\WINDOWS\System32\\PSDrvCheck.exe ()
O4 - HKLM..\Run: [USB2Check] D:\WINDOWS\System32\PCLECoInst.dll (Pinnacle Systems)
O4 - HKLM..\Run: [USBToolTip] D:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Pinnacle Systems GmbH)
O4 - HKLM..\Run: [Zune Launcher] D:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ooVoo.exe] D:\Program Files\ooVoo\oovoo.exe (ooVoo LLC)
O4 - Startup: D:\Documents and Settings\Aleksandr\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O4 - Startup: D:\Documents and Settings\Aleksandr\Start Menu\Programs\Startup\Dropbox.lnk = D:\Documents and Settings\Aleksandr\Application Data\Dropbox\bin\Dropbox.exe ()
O4 - Startup: D:\Documents and Settings\Aleksandr\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = D:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\GA311 Smart Wizard Utility.lnk = D:\Program Files\NETGEAR GA311 Adapter\GA311.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - D:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: D:\Documents and Settings\Aleksandr\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\Aleksandr\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/07/31 19:52:50 | 000,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.l3acm - D:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - D:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - D:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - D:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - D:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - D:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - D:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: VIDC.FPS1 - D:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: VIDC.MJPG - D:\WINDOWS\System32\pvmjpg30.dll (Pegasus Imaging Corporation)
Drivers32: VIDC.PIM1 - pclepim1.dll File not found
Drivers32: vidc.tscc - D:\WINDOWS\system32\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.XFR1 - D:\WINDOWS\System32\xfcodec.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)
========== Files/Folders - Created Within 30 Days ==========
[2011/03/30 23:49:20 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\TEMP
[2011/03/30 23:49:13 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Stellar Phoenix Photo Recovery
[2011/03/30 23:49:10 | 000,000,000 | —D | C] – D:\Program Files\Stellar Phoenix Photo Recovery
[2011/03/30 23:44:25 | 000,000,000 | —D | C] – D:\Documents and Settings\Aleksandr\Local Settings\Application Data\AVG Security Toolbar
[2011/03/30 19:54:50 | 000,301,528 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswSP.sys
[2011/03/30 19:54:50 | 000,019,544 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/03/30 19:54:50 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/03/30 19:54:49 | 000,371,544 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswSnx.sys
[2011/03/30 19:54:49 | 000,102,232 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswmon2.sys
[2011/03/30 19:54:49 | 000,096,344 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswmon.sys
[2011/03/30 19:54:49 | 000,049,240 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswTdi.sys
[2011/03/30 19:54:49 | 000,030,680 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aavmker4.sys
[2011/03/30 19:54:49 | 000,025,432 | —- | C] (AVAST Software) – D:\WINDOWS\System32\drivers\aswRdr.sys
[2011/03/30 19:54:21 | 000,190,016 | —- | C] (AVAST Software) – D:\WINDOWS\System32\aswBoot.exe
[2011/03/30 19:54:21 | 000,040,648 | —- | C] (AVAST Software) – D:\WINDOWS\avastSS.scr
[2011/03/30 19:54:13 | 000,000,000 | —D | C] – D:\Program Files\AVAST Software
[2011/03/30 19:54:13 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/29 21:06:16 | 000,000,000 | —D | C] – D:\Documents and Settings\Aleksandr\Desktop\4chan
[2011/03/29 20:41:14 | 000,000,000 | —D | C] – D:\Documents and Settings\Aleksandr\Application Data\AVG10
[2011/03/29 20:33:43 | 000,000,000 | -H-D | C] – D:\Documents and Settings\All Users\Application Data\Common Files
[2011/03/29 20:31:59 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\AVG10
[2011/03/29 20:27:34 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\MFAData
[2011/03/25 19:58:02 | 000,000,000 | —D | C] – D:\Documents and Settings\NetworkService\Application Data\Xfire
[2011/03/23 19:35:34 | 000,000,000 | -HSD | C] – D:\found.000
[2011/03/08 22:07:48 | 000,000,000 | —D | C] – D:\WINDOWS\XSxS
[2011/03/08 22:07:48 | 000,000,000 | —D | C] – D:\Program Files\Xenocode
[2011/03/07 00:36:31 | 000,000,000 | —D | C] – D:\Program Files\Common Files\Skype
[2011/03/03 22:21:23 | 000,000,000 | —D | C] – D:\WINDOWS\System32\QuickTime
[2011/03/03 22:21:23 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Camtasia Studio 7
[2011/03/03 22:21:16 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\TechSmith
[2011/03/03 22:21:03 | 000,000,000 | —D | C] – D:\Program Files\Common Files\TechSmith Shared
[2011/03/03 22:20:58 | 000,000,000 | —D | C] – D:\Program Files\TechSmith
[6 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[12 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/03/31 17:26:29 | 000,002,048 | –S- | M] () – D:\WINDOWS\bootstat.dat
[2011/03/31 17:26:26 | 2683,883,520 | -HS- | M] () – D:\hiberfil.sys
[2011/03/31 00:26:24 | 000,025,600 | —- | M] () – D:\Documents and Settings\Aleksandr\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/31 00:09:00 | 000,000,994 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-152049171-839522115-1004UA.job
[2011/03/30 23:49:13 | 000,000,835 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Stellar Phoenix Photo Recovery.lnk
[2011/03/30 19:54:50 | 000,001,689 | —- | M] () – D:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/03/30 19:54:49 | 000,002,625 | —- | M] () – D:\WINDOWS\System32\CONFIG.NT
[2011/03/30 16:09:02 | 000,000,942 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-152049171-839522115-1004Core.job
[2011/03/29 22:36:33 | 000,332,966 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\wow.jpg
[2011/03/29 20:06:09 | 000,079,055 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\19502121.jpg
[2011/03/28 22:29:53 | 000,316,492 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 27.png
[2011/03/28 22:05:59 | 000,141,288 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 4.png
[2011/03/28 22:05:51 | 000,141,641 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 6.png
[2011/03/28 22:03:56 | 000,341,489 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 13.png
[2011/03/28 18:09:57 | 000,002,316 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Google Chrome.lnk
[2011/03/28 18:09:57 | 000,002,294 | —- | M] () – D:\Documents and Settings\Aleksandr\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/03/28 17:31:04 | 000,013,646 | —- | M] () – D:\WINDOWS\System32\wpa.dbl
[2011/03/25 19:58:02 | 000,000,284 | —- | M] () – D:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/19 15:02:26 | 000,819,661 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Zuleika_Blood_Elf_Death_Knight_by_morganagod.jpg
[2011/03/19 14:53:44 | 000,000,664 | —- | M] () – D:\WINDOWS\System32\d3d9caps.dat
[2011/03/16 15:38:01 | 000,001,374 | —- | M] () – D:\WINDOWS\imsins.BAK
[2011/03/13 20:52:39 | 000,501,382 | —- | M] () – D:\WINDOWS\System32\perfh009.dat
[2011/03/13 20:52:39 | 000,087,288 | —- | M] () – D:\WINDOWS\System32\perfc009.dat
[2011/03/08 20:21:47 | 038,068,268 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\City and Colour (Ukulele Sample) - Sasha Marchant.wav
[2011/03/08 19:54:58 | 038,314,028 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\testsong1.wav
[2011/03/03 22:21:23 | 000,000,893 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Camtasia Studio 7.lnk
[6 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[12 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/03/30 23:49:13 | 000,000,835 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Stellar Phoenix Photo Recovery.lnk
[2011/03/30 19:54:50 | 000,001,689 | —- | C] () – D:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/03/29 22:36:33 | 000,332,966 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\wow.jpg
[2011/03/29 20:06:16 | 000,079,055 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\19502121.jpg
[2011/03/28 22:29:44 | 000,316,492 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 27.png
[2011/03/28 22:05:52 | 000,141,288 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 4.png
[2011/03/28 22:05:44 | 000,141,641 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 6.png
[2011/03/28 22:03:47 | 000,341,489 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Video call snapshot 13.png
[2011/03/19 15:02:29 | 000,819,661 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\Zuleika_Blood_Elf_Death_Knight_by_morganagod.jpg
[2011/03/19 14:53:44 | 000,000,664 | —- | C] () – D:\WINDOWS\System32\d3d9caps.dat
[2011/03/08 20:21:40 | 038,068,268 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\City and Colour (Ukulele Sample) - Sasha Marchant.wav
[2011/03/08 19:54:55 | 038,314,028 | —- | C] () – D:\Documents and Settings\Aleksandr\Desktop\testsong1.wav
[2011/03/03 22:21:23 | 000,000,893 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Camtasia Studio 7.lnk
[2011/02/25 21:19:32 | 000,041,872 | —- | C] () – D:\WINDOWS\System32\xfcodec.dll
[2011/01/30 18:33:33 | 000,000,262 | —- | C] () – D:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/01/27 20:24:27 | 000,000,156 | —- | C] () – D:\WINDOWS\ae_mini.INI
[2011/01/27 20:23:00 | 000,000,128 | —- | C] () – D:\WINDOWS\smrpro.INI
[2010/11/13 11:03:58 | 000,025,600 | —- | C] () – D:\Documents and Settings\Aleksandr\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/02 10:59:47 | 000,000,132 | —- | C] () – D:\Documents and Settings\Aleksandr\Local Settings\Application Data\fusioncache.dat
[2010/09/19 22:05:48 | 000,274,384 | —- | C] () – D:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/09/12 19:58:12 | 000,088,397 | —- | C] () – D:\WINDOWS\hpoins06.dat
[2010/09/12 19:58:12 | 000,005,389 | —- | C] () – D:\WINDOWS\hpomdl06.dat
[2010/09/07 18:04:24 | 000,122,713 | —- | C] () – D:\WINDOWS\HPHins11.dat
[2010/09/07 18:04:24 | 000,013,767 | —- | C] () – D:\WINDOWS\hphmdl11.dat
[2010/09/07 18:04:20 | 000,077,824 | R— | C] () – D:\WINDOWS\System32\HPZIDS01.dll
[2010/08/05 15:59:19 | 000,153,088 | —- | C] () – D:\Program Files\UNWISE.EXE
[2010/07/31 19:55:16 | 000,194,248 | —- | C] () – D:\WINDOWS\System32\LTRFD13n.DLL
[2010/07/31 19:52:50 | 000,001,208 | —- | C] () – D:\WINDOWS\VFO.INI
[2010/07/31 19:52:49 | 000,196,096 | —- | C] () – D:\WINDOWS\System32\macd32.dll
[2010/07/31 19:52:49 | 000,138,752 | —- | C] () – D:\WINDOWS\System32\mase32.dll
[2010/07/31 19:52:49 | 000,136,192 | —- | C] () – D:\WINDOWS\System32\mamc32.dll
[2010/07/31 19:52:49 | 000,057,856 | —- | C] () – D:\WINDOWS\System32\masd32.dll
[2010/07/31 19:52:49 | 000,027,648 | —- | C] () – D:\WINDOWS\System32\ma32.dll
[2010/07/30 14:56:51 | 000,000,056 | -H– | C] () – D:\WINDOWS\System32\ezsidmv.dat
[2010/07/29 16:26:13 | 000,040,960 | R— | C] () – D:\WINDOWS\System32\psfind.dll
[2010/07/29 14:00:18 | 000,004,569 | —- | C] () – D:\WINDOWS\System32\secupd.dat
[2010/07/28 19:54:55 | 000,000,552 | —- | C] () – D:\WINDOWS\System32\d3d8caps.dat
[2010/07/25 21:26:54 | 000,000,000 | —- | C] () – D:\WINDOWS\nsreg.dat
[2010/07/25 19:30:09 | 000,002,048 | –S- | C] () – D:\WINDOWS\bootstat.dat
[2010/07/25 19:27:15 | 000,021,640 | —- | C] () – D:\WINDOWS\System32\emptyregdb.dat
[2010/07/25 15:23:29 | 000,004,161 | —- | C] () – D:\WINDOWS\ODBCINST.INI
[2010/07/25 15:22:12 | 000,169,096 | —- | C] () – D:\WINDOWS\System32\FNTCACHE.DAT
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – D:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – D:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/09/27 16:12:22 | 001,604,482 | —- | C] () – D:\WINDOWS\System32\nvdata.bin
[2009/04/30 22:39:36 | 000,082,289 | —- | C] () – D:\WINDOWS\System32\lvcoinst.ini
[2005/07/29 14:38:24 | 003,375,104 | —- | C] () – D:\WINDOWS\System32\qt-mt331.dll
[2004/03/11 00:26:10 | 000,406,016 | —- | C] () – D:\WINDOWS\System32\PSDrvCheck.exe
[2003/03/31 08:00:00 | 013,107,200 | —- | C] () – D:\WINDOWS\System32\oembios.bin
[2003/03/31 08:00:00 | 000,673,088 | —- | C] () – D:\WINDOWS\System32\mlang.dat
[2003/03/31 08:00:00 | 000,501,382 | —- | C] () – D:\WINDOWS\System32\perfh009.dat
[2003/03/31 08:00:00 | 000,272,128 | —- | C] () – D:\WINDOWS\System32\perfi009.dat
[2003/03/31 08:00:00 | 000,218,003 | —- | C] () – D:\WINDOWS\System32\dssec.dat
[2003/03/31 08:00:00 | 000,087,288 | —- | C] () – D:\WINDOWS\System32\perfc009.dat
[2003/03/31 08:00:00 | 000,046,258 | —- | C] () – D:\WINDOWS\System32\mib.bin
[2003/03/31 08:00:00 | 000,028,626 | —- | C] () – D:\WINDOWS\System32\perfd009.dat
[2003/03/31 08:00:00 | 000,004,461 | —- | C] () – D:\WINDOWS\System32\oembios.dat
[2003/03/31 08:00:00 | 000,001,804 | —- | C] () – D:\WINDOWS\System32\dcache.bin
[2003/03/31 08:00:00 | 000,000,741 | —- | C] () – D:\WINDOWS\System32\noise.dat
[2001/07/06 15:30:00 | 000,003,399 | —- | C] () – D:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2010/10/17 23:08:40 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\.minecraft
[2010/08/04 21:39:29 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Acoustica
[2011/01/27 19:58:32 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Audacity
[2010/12/26 23:01:56 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\AudioTuner
[2011/03/29 20:41:15 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\AVG10
[2011/03/31 17:28:16 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Dropbox
[2010/08/24 15:44:57 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\FOG Downloader
[2010/08/27 17:01:19 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\HBLite
[2010/08/01 19:34:11 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Leadertech
[2010/10/28 21:03:43 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\LimeWire
[2010/10/05 22:56:36 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\ooVoo Details
[2010/10/06 23:28:32 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\OpenOffice.org
[2010/08/04 15:47:25 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Publish Providers
[2010/08/04 15:47:13 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\Sony
[2010/08/04 21:43:04 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\SynthMaker
[2011/01/25 18:42:49 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\TS3Client
[2011/01/25 17:20:55 | 000,000,000 | —D | M] – D:\Documents and Settings\Aleksandr\Application Data\uTorrent
[2010/08/27 17:01:19 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
[2010/08/04 21:37:44 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Acoustica
[2011/03/30 19:54:13 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/31 17:21:03 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\AVG10
[2011/03/29 20:33:43 | 000,000,000 | -H-D | M] – D:\Documents and Settings\All Users\Application Data\Common Files
[2010/07/28 21:33:38 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Driver Whiz
[2011/03/31 17:14:48 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\HBLiteSA
[2011/03/29 20:31:29 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\MFAData
[2010/08/04 17:50:57 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Pinnacle
[2010/08/04 17:51:10 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2010/10/16 18:26:20 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\PMB Files
[2010/07/31 19:54:12 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/08/04 23:42:36 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Sony
[2011/03/03 22:21:16 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\TechSmith
[2011/03/30 23:49:20 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/25 22:02:25 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\{B7A015B7-4802-4678-8CEC-700380BA9AFD}
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/03/31 17:26:26 | 2683,883,520 | -HS- | M] () – D:\hiberfil.sys
[2011/03/31 17:26:25 | 2145,386,496 | -HS- | M] () – D:\pagefile.sys
[2010/09/28 17:36:17 | 000,006,599 | —- | M] () – D:\video.pass
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – D:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – D:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – D:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – D:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
[2005/05/11 23:36:48 | 000,012,288 | —- | M] (Hewlett-Packard Co.) – D:\WINDOWS\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2010/07/25 19:28:50 | 000,000,067 | -HS- | M] () – D:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/05/05 08:48:54 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2006/03/22 21:08:20 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp463.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/02/23 10:04:21 | 000,040,648 | —- | M] (AVAST Software) – D:\WINDOWS\avastSS.scr
[6 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2002/07/26 18:02:06 | 000,153,088 | —- | M] () – D:\Program Files\UNWISE.EXE
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/07/25 15:21:24 | 000,094,208 | —- | M] () – D:\WINDOWS\system32\config\default.sav
[2010/07/25 15:21:24 | 000,602,112 | —- | M] () – D:\WINDOWS\system32\config\software.sav
[2010/07/25 15:21:24 | 000,425,984 | —- | M] () – D:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/07/29 15:03:17 | 000,000,272 | -HS- | M] () – D:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/29 15:07:01 | 000,000,177 | -HS- | M] () – D:\Documents and Settings\Aleksandr\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/07/25 19:32:50 | 000,000,079 | —- | M] () – D:\Documents and Settings\Aleksandr\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/10/17 23:02:19 | 000,232,501 | —- | M] () – D:\Documents and Settings\Aleksandr\Desktop\Minecraft.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2011/03/08 20:22:15 | 000,144,276 | —- | M] ()(D:\Documents and Settings\Aleksandr\Desktop\??? ? ???????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\вид с балкона.JPG
[2011/03/08 20:22:10 | 000,144,276 | —- | C] ()(D:\Documents and Settings\Aleksandr\Desktop\??? ? ???????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\вид с балкона.JPG
[2011/03/08 20:15:32 | 000,164,767 | —- | M] ()(D:\Documents and Settings\Aleksandr\Desktop\???????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\Виталик.JPG
[2011/03/08 20:15:28 | 000,164,767 | —- | C] ()(D:\Documents and Settings\Aleksandr\Desktop\???????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\Виталик.JPG
[2011/03/08 20:11:29 | 000,267,371 | —- | M] ()(D:\Documents and Settings\Aleksandr\Desktop\?????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\каска.JPG
[2011/03/08 20:11:23 | 000,267,371 | —- | C] ()(D:\Documents and Settings\Aleksandr\Desktop\?????.JPG) – D:\Documents and Settings\Aleksandr\Desktop\каска.JPG
< End of report >