This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Multiple Infections

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi - This computer was totally infested with a ton of viruses and other bad stuff; I think it's clean now, but before I give it back to the owner, I'd like to see if there is anything still hiding that would cause problems later on. I'm concerned that there may still be something that's redirecting the browser. I've included the OTL files below - hope that's ok. Thanks for looking - I appreciate any help!



OTL logfile created on: 7/15/2011 9:48:51 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Repair\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.25 Mb Total Physical Memory | 290.89 Mb Available Physical Memory | 32.53% Memory free
2.12 Gb Paging File | 1.55 Gb Available in Paging File | 73.09% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 62.05 Gb Free Space | 83.26% Space Free | Partition Type: NTFS

Computer Name: ZACK | User Name: Repair | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Repair\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sigmatel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Repair\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Nwsapagent) – File not found
SRV - (itlperf) – File not found
SRV - (6to4) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (STacSV) – C:\Program Files\Sigmatel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)


========== Driver Services (SafeList) ==========

DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Sftvol) – C:\WINDOWS\system32\drivers\Sftvolxp.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\WINDOWS\system32\drivers\Sftredirxp.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\WINDOWS\system32\drivers\Sftplayxp.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\WINDOWS\system32\drivers\Sftfsxp.sys (Microsoft Corporation)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (RMCAST) – C:\WINDOWS\system32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (MQAC) – C:\WINDOWS\system32\drivers\mqac.sys (Microsoft Corporation)
DRV - (NETw4x32) Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{CD0912BB-88D3-4791-AAEE-AED15C6906B5}: C:\Documents and Settings\Myself\Local Settings\Application Data\{CD0912BB-88D3-4791-AAEE-AED15C6906B5} [2011/05/12 19:29:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/07/11 17:39:35 | 000,000,000 | —D | M]


O1 HOSTS File: ([2011/05/12 16:15:46 | 000,001,527 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 69.10.57.34 www.google.com
O1 - Hosts: 69.10.57.34 www.google.com.au
O1 - Hosts: 69.10.57.34 www.google.be
O1 - Hosts: 69.10.57.34 www.google.com.br
O1 - Hosts: 69.10.57.34 www.google.ca
O1 - Hosts: 69.10.57.34 www.google.ch
O1 - Hosts: 69.10.57.34 www.google.de
O1 - Hosts: 69.10.57.34 www.google.dk
O1 - Hosts: 69.10.57.34 www.google.fr
O1 - Hosts: 69.10.57.34 www.google.ie
O1 - Hosts: 69.10.57.34 www.google.it
O1 - Hosts: 69.10.57.34 www.google.co.jp
O1 - Hosts: 69.10.57.34 www.google.nl
O1 - Hosts: 69.10.57.34 www.google.no
O1 - Hosts: 69.10.57.34 www.google.co.nz
O1 - Hosts: 69.10.57.34 www.google.pl
O1 - Hosts: 69.10.57.34 www.google.se
O1 - Hosts: 69.10.57.34 www.google.co.uk
O1 - Hosts: 69.10.57.34 www.google.co.za
O1 - Hosts: 69.10.57.34 www.bing.com
O1 - Hosts: 69.10.57.34 search.yahoo.com
O1 - Hosts: 69.10.57.34 uk.search.yahoo.com
O1 - Hosts: 69.10.57.34 ca.search.yahoo.com
O1 - Hosts: 69.10.57.34 de.search.yahoo.com
O1 - Hosts: 3 more lines…
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKCU..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 6bmn9ya = C:\WINDOWS\TEMP\6iu1cfb.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([www.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([]https in Trusted sites)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/sit…b?1310745410296 (MUCatalogWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1310745184093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Blue Lace 16.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Blue Lace 16.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/11/10 15:39:09 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/07/15 21:46:55 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Repair\Desktop\OTL.exe
[2011/07/15 21:37:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Desktop\tdsskiller
[2011/07/15 21:02:44 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/07/15 19:58:41 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Repair\Desktop\ATF-Cleaner.exe
[2011/07/15 19:27:26 | 000,000,000 | —D | C] – C:\WINDOWS\System32\winrm
[2011/07/15 19:27:13 | 000,000,000 | -H-D | C] – C:\WINDOWS\$968930Uinstall_KB968930$
[2011/07/15 18:54:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Local Settings\Application Data\ApplicationHistory
[2011/07/15 18:49:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Windows Search
[2011/07/15 18:24:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Local Settings\Application Data\Identities
[2011/07/15 18:24:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Windows Desktop Search
[2011/07/15 18:20:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/07/15 18:19:33 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2011/07/15 18:13:23 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2011/07/15 18:13:18 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2011/07/15 18:13:10 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2011/07/15 18:07:33 | 000,000,000 | —D | C] – C:\Program Files\Windows Desktop Search
[2011/07/15 18:07:33 | 000,000,000 | —D | C] – C:\WINDOWS\System32\GroupPolicy
[2011/07/15 18:03:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\URTTemp
[2011/07/15 17:49:30 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2011/07/15 13:54:26 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2011/07/15 13:54:26 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2011/07/15 13:54:25 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2011/07/15 13:54:25 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2011/07/15 13:54:24 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2011/07/15 13:54:24 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2011/07/15 13:54:24 | 000,000,000 | —D | C] – C:\ce8d60a6157be8fc9e4aa3e9ca1a95
[2011/07/15 13:19:07 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidserv.dll
[2011/07/15 11:20:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\ElevatedDiagnostics
[2011/07/15 11:20:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2011/07/15 11:19:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2011/07/15 09:38:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\DriverCure
[2011/07/15 09:38:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\ParetoLogic
[2011/07/15 09:38:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/07/15 08:20:54 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/07/14 22:55:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\IIS Resources
[2011/07/14 22:55:30 | 000,000,000 | —D | C] – C:\Program Files\IIS Resources
[2011/07/14 22:54:18 | 000,000,000 | —D | C] – C:\WINDOWS\Downloaded Installations
[2011/07/14 22:31:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\SecurityScans
[2011/07/14 22:30:42 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Baseline Security Analyzer 2
[2011/07/14 22:10:10 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/07/14 22:02:05 | 002,134,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpsnap.dll
[2011/07/14 22:02:05 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\irbus.sys
[2011/07/14 22:02:05 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2011/07/14 22:02:04 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2011/07/14 22:02:04 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2011/07/14 22:02:04 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2011/07/14 22:02:04 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2011/07/14 22:02:04 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2011/07/14 22:02:04 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2011/07/14 22:02:03 | 004,274,816 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nv4_disp.dll
[2011/07/14 22:02:03 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2011/07/14 22:02:03 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2011/07/14 22:02:03 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2011/07/14 22:02:02 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2011/07/14 22:02:02 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2011/07/14 22:02:02 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2011/07/14 22:02:02 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2011/07/14 22:02:02 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vidcap.ax
[2011/07/14 22:02:01 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\slrundll.exe
[2011/07/14 22:01:50 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/07/14 22:01:36 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lonsint.dll
[2011/07/14 22:01:35 | 000,364,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\w3svc.dll
[2011/07/14 22:01:35 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisadmin.dll
[2011/07/14 22:01:34 | 000,829,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetmgr.dll
[2011/07/14 22:01:34 | 000,290,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adsiis51.dll
[2011/07/14 22:01:34 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tools.dll
[2011/07/14 22:01:33 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\appconf.dll
[2011/07/14 22:01:31 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\metada51.dll
[2011/07/14 22:01:31 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetin51.exe
[2011/07/14 22:01:29 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asp51.dll
[2011/07/14 22:01:29 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpapi.dll
[2011/07/14 22:01:25 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnfgprts.ocx
[2011/07/14 22:01:25 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sspifilt.dll
[2011/07/14 22:01:15 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\httpmb51.dll
[2011/07/14 22:01:14 | 000,103,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\uihelper.dll
[2011/07/14 22:01:13 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\davcdata.exe
[2011/07/14 22:01:10 | 000,275,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\certwiz.ocx
[2011/07/14 22:01:10 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pwsdata.dll
[2011/07/14 22:01:09 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rwnh.dll
[2011/07/14 22:01:07 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisext51.dll
[2011/07/14 22:01:07 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\exstrace.dll
[2011/07/14 22:01:04 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iische51.dll
[2011/07/14 22:01:04 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\httpod51.dll
[2011/07/14 22:01:04 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iscomlog.dll
[2011/07/14 22:01:01 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\infocomm.dll
[2011/07/14 22:00:58 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\logui.ocx
[2011/07/14 22:00:49 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisfecnv.dll
[2011/07/14 22:00:48 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wam51.dll
[2011/07/14 22:00:48 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ssinc51.dll
[2011/07/14 22:00:43 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\isatq.dll
[2011/07/14 22:00:42 | 000,221,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\seo.dll
[2011/07/14 22:00:42 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\infoadmn.dll
[2011/07/14 22:00:41 | 000,268,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\httpext.dll
[2011/07/14 22:00:40 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\compfilt.dll
[2011/07/14 22:00:35 | 000,189,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpadm.dll
[2011/07/14 22:00:35 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wamreg51.dll
[2011/07/14 22:00:35 | 000,029,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admexs.dll
[2011/07/14 22:00:33 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iislog51.dll
[2011/07/14 22:00:31 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admwprox.dll
[2011/07/14 22:00:29 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iismap.dll
[2011/07/14 22:00:28 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nsepm.dll
[2011/07/14 22:00:28 | 000,032,256 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gzip.dll
[2011/07/14 22:00:28 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcref.dll
[2011/07/14 22:00:26 | 000,037,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\md5filt.dll
[2011/07/14 22:00:26 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrstas.exe
[2011/07/14 22:00:25 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrtl.dll
[2011/07/14 22:00:25 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\coadmin.dll
[2011/07/14 22:00:25 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\staxmem.dll
[2011/07/14 22:00:24 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\svcext51.dll
[2011/07/14 22:00:10 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\evntcmd.exe
[2011/07/14 22:00:10 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\evntcmd.exe
[2011/07/14 21:59:51 | 000,236,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smi2smir.exe
[2011/07/14 21:59:44 | 000,022,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\lpdsvc.dll
[2011/07/14 21:59:44 | 000,022,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lpdsvc.dll
[2011/07/14 21:59:41 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\evntwin.exe
[2011/07/14 21:59:41 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\evntwin.exe
[2011/07/14 21:59:29 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\snmpmib.dll
[2011/07/14 21:59:29 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpmib.dll
[2011/07/14 21:59:15 | 000,188,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpsmir.dll
[2011/07/14 21:59:15 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\hostmib.dll
[2011/07/14 21:59:15 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hostmib.dll
[2011/07/14 21:58:32 | 000,259,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpcl.dll
[2011/07/14 21:58:02 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmp.exe
[2011/07/14 21:57:58 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmptrap.exe
[2011/07/14 21:57:42 | 000,358,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpincl.dll
[2011/07/14 21:57:12 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\lprmon.dll
[2011/07/14 21:57:12 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lprmon.dll
[2011/07/14 21:56:20 | 000,456,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpsvc.dll
[2011/07/14 21:56:15 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\lmmib2.dll
[2011/07/14 21:56:15 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lmmib2.dll
[2011/07/14 21:55:53 | 000,331,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aqueue.dll
[2011/07/14 21:55:53 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\evntagnt.dll
[2011/07/14 21:55:53 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\evntagnt.dll
[2011/07/14 21:55:52 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpthrd.dll
[2011/07/14 21:55:47 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2011/07/14 21:55:43 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2011/07/14 21:55:43 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2011/07/14 21:55:43 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2011/07/14 21:55:43 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2011/07/14 21:55:43 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2011/07/14 21:55:43 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2011/07/14 21:55:43 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2011/07/14 21:55:42 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2011/07/14 21:55:42 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2011/07/14 21:55:42 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2011/07/14 21:55:42 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2011/07/14 21:55:42 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2011/07/14 21:55:42 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2011/07/14 21:55:42 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2011/07/14 21:55:42 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2011/07/14 21:55:42 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2011/07/14 21:55:42 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2011/07/14 21:55:42 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2011/07/14 21:55:41 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2011/07/14 21:55:41 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2011/07/14 21:55:41 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2011/07/14 21:55:41 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2011/07/14 21:55:41 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2011/07/14 21:55:41 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2011/07/14 21:55:41 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2011/07/14 21:55:41 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2011/07/14 21:55:39 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2011/07/14 21:55:39 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2011/07/14 21:55:39 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2011/07/14 21:55:39 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2011/07/14 21:55:39 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2011/07/14 21:55:38 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2011/07/14 21:55:38 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2011/07/14 21:55:38 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2011/07/14 21:55:38 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2011/07/14 21:55:37 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2011/07/14 21:55:37 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2011/07/14 21:55:37 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2011/07/14 21:55:36 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2011/07/14 21:55:36 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2011/07/14 21:55:35 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2011/07/14 21:55:35 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2011/07/14 21:55:35 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2011/07/14 21:55:35 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2011/07/14 21:55:35 | 000,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2011/07/14 21:55:35 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2011/07/14 21:55:35 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2011/07/14 21:55:32 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2011/07/14 21:55:32 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2011/07/14 21:55:31 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2011/07/14 21:55:31 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2011/07/14 21:55:31 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2011/07/14 21:55:31 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2011/07/14 21:55:31 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2011/07/14 21:55:31 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2011/07/14 21:55:31 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2011/07/14 21:24:01 | 000,000,000 | —D | C] – C:\WINDOWS\System32\msmq
[2011/07/14 21:24:00 | 000,000,000 | —D | C] – C:\Inetpub
[2011/07/13 20:00:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\VirtualizedApplications
[2011/07/13 18:25:30 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/07/13 18:21:31 | 000,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2011/07/13 18:19:30 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2011/07/13 18:19:16 | 000,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2011/07/13 18:15:03 | 000,000,000 | —D | C] – C:\bd11bf1a02cc73b032c610b5b0f3
[2011/07/13 17:42:49 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/07/13 17:36:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Local Settings\Application Data\SoftGrid Client
[2011/07/13 17:35:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\SoftGrid Client
[2011/07/13 17:35:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office Home and Student (English)
[2011/07/13 17:33:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2011/07/13 17:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\SoftGrid Client
[2011/07/13 17:33:23 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/07/13 17:33:23 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Application Virtualization Client
[2011/07/13 17:33:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Microsoft
[2011/07/13 17:31:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\TP
[2011/07/13 17:27:54 | 000,000,000 | -HSD | C] – C:\WINDOWS\System32\AI_RecycleBin
[2011/07/13 17:27:51 | 000,000,000 | —D | C] – C:\Program Files\W3i
[2011/07/13 17:27:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\W3i
[2011/07/13 17:27:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\InstallIQ Updater
[2011/07/13 16:47:59 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\My Documents\My Videos
[2011/07/13 16:31:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Sun
[2011/07/13 13:21:08 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2011/07/13 13:00:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Malwarebytes
[2011/07/13 12:33:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\AVG
[2011/07/13 12:30:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Adobe
[2011/07/13 12:30:27 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Repair\PrivacIE
[2011/07/13 12:19:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\AVG10
[2011/07/13 12:19:08 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Repair\IETldCache
[2011/07/13 12:19:04 | 000,000,000 | –SD | C] – C:\Documents and Settings\Repair\Application Data\Microsoft
[2011/07/13 12:19:04 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Repair\SendTo
[2011/07/13 12:19:04 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Repair\Recent
[2011/07/13 12:19:04 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Repair\Application Data
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\Start Menu\Programs\Startup
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\Start Menu
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\My Documents\My Pictures
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\My Documents\My Music
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\My Documents
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\Favorites
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\Start Menu\Programs\Accessories
[2011/07/13 12:19:04 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Repair\Cookies
[2011/07/13 12:19:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Repair\Templates
[2011/07/13 12:19:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Repair\PrintHood
[2011/07/13 12:19:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Repair\NetHood
[2011/07/13 12:19:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Repair\Local Settings
[2011/07/13 12:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Local Settings\Application Data\Microsoft
[2011/07/13 12:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Macromedia
[2011/07/13 12:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Identities
[2011/07/13 12:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Desktop
[2011/07/12 20:41:06 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/07/12 20:24:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Registry Mechanic
[2011/07/11 23:36:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/07/11 23:35:21 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/07/11 23:35:19 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/07/11 23:35:19 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/07/11 23:35:18 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/07/11 21:11:37 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/07/11 18:28:56 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/07/11 17:39:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011
[2011/07/11 17:38:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/07/11 17:38:07 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/07/11 17:37:27 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/07/11 17:27:21 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/11 16:58:54 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/15 21:47:00 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Repair\Desktop\OTL.exe
[2011/07/15 21:37:25 | 000,000,872 | —- | M] () – C:\Documents and Settings\Repair\Desktop\Shortcut to TDSSKiller.lnk
[2011/07/15 21:10:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1336724463-1398281268-1674753652-1005UA.job
[2011/07/15 21:02:51 | 000,517,230 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/15 21:02:51 | 000,091,782 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/15 20:45:54 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/07/15 20:44:51 | 000,012,696 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/15 20:35:09 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/15 19:58:41 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Repair\Desktop\ATF-Cleaner.exe
[2011/07/15 18:37:19 | 122,441,935 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/07/15 18:23:20 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/15 18:07:44 | 000,001,787 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/07/15 13:19:47 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2011/07/15 13:19:45 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2011/07/15 11:43:17 | 000,000,739 | —- | M] () – C:\Documents and Settings\Repair\Desktop\Shortcut to F-Secure.lnk
[2011/07/15 11:18:39 | 000,000,134 | —- | M] () – C:\Documents and Settings\Repair\Desktop\Microsoft Fix it.url
[2011/07/15 08:23:25 | 000,000,815 | —- | M] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/14 23:10:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1336724463-1398281268-1674753652-1005Core.job
[2011/07/14 22:30:45 | 000,000,870 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Baseline Security Analyzer 2.2.lnk
[2011/07/14 20:46:15 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/13 16:47:48 | 000,000,800 | —- | M] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/07/13 16:47:48 | 000,000,782 | —- | M] () – C:\Documents and Settings\Repair\Desktop\Windows Media Player.lnk
[2011/07/12 08:11:19 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjw.avm
[2011/07/11 17:39:41 | 000,000,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/07/11 17:01:10 | 000,000,120 | —- | M] () – C:\WINDOWS\Hqibexaheqimezoc.dat
[2011/07/11 17:01:10 | 000,000,000 | —- | M] () – C:\WINDOWS\Dhepiyukebicitaq.bin
[2011/07/11 17:01:01 | 000,010,082 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\b6rkrv8a73spxby2vvgdh23go6k2up6vsdslct8n34k05yp
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/15 21:37:25 | 000,000,872 | —- | C] () – C:\Documents and Settings\Repair\Desktop\Shortcut to TDSSKiller.lnk
[2011/07/15 18:37:19 | 122,441,935 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/07/15 18:07:44 | 000,001,803 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Search.lnk
[2011/07/15 18:07:44 | 000,001,787 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/07/15 13:19:47 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2011/07/15 13:19:45 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2011/07/15 11:43:17 | 000,000,739 | —- | C] () – C:\Documents and Settings\Repair\Desktop\Shortcut to F-Secure.lnk
[2011/07/15 11:18:39 | 000,000,134 | —- | C] () – C:\Documents and Settings\Repair\Desktop\Microsoft Fix it.url
[2011/07/14 22:30:45 | 000,000,876 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Baseline Security Analyzer 2.2.lnk
[2011/07/14 22:30:45 | 000,000,870 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Baseline Security Analyzer 2.2.lnk
[2011/07/14 21:55:39 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2011/07/14 21:55:38 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2011/07/14 21:55:36 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2011/07/13 16:47:48 | 000,000,800 | —- | C] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/07/13 12:19:15 | 000,000,788 | —- | C] () – C:\Documents and Settings\Repair\Start Menu\Programs\Windows Media Player.lnk
[2011/07/13 12:19:15 | 000,000,782 | —- | C] () – C:\Documents and Settings\Repair\Desktop\Windows Media Player.lnk
[2011/07/13 12:19:05 | 000,001,599 | —- | C] () – C:\Documents and Settings\Repair\Start Menu\Programs\Remote Assistance.lnk
[2011/07/13 12:19:05 | 000,000,815 | —- | C] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/13 12:19:05 | 000,000,803 | —- | C] () – C:\Documents and Settings\Repair\Start Menu\Programs\Internet Explorer.lnk
[2011/07/13 12:19:05 | 000,000,079 | —- | C] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/07/12 19:33:59 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/07/12 16:45:10 | 000,000,982 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1336724463-1398281268-1674753652-1005UA.job
[2011/07/12 16:45:10 | 000,000,930 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1336724463-1398281268-1674753652-1005Core.job
[2011/07/12 08:11:19 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\iavichjw.avm
[2011/07/11 17:39:41 | 000,000,690 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/07/11 16:58:37 | 000,000,004 | -H– | C] () – C:\Documents and Settings\LocalService\Application Data\inlog
[2011/07/11 16:58:35 | 000,000,113 | -H– | C] () – C:\Documents and Settings\LocalService\Application Data\Input.bat
[2011/07/11 16:58:29 | 000,001,120 | -H– | C] () – C:\Documents and Settings\LocalService\Application Data\mlog
[2011/07/11 16:58:27 | 000,000,114 | -H– | C] () – C:\Documents and Settings\LocalService\Application Data\Plug.bat
[2011/07/11 16:58:23 | 000,000,004 | -H– | C] () – C:\Documents and Settings\LocalService\Application Data\ylog
[2011/05/14 19:53:00 | 000,010,082 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\b6rkrv8a73spxby2vvgdh23go6k2up6vsdslct8n34k05yp
[2011/05/12 19:29:18 | 000,000,120 | —- | C] () – C:\WINDOWS\Hqibexaheqimezoc.dat
[2011/05/12 19:29:18 | 000,000,000 | —- | C] () – C:\WINDOWS\Dhepiyukebicitaq.bin
[2011/05/12 16:48:05 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2011/04/08 02:00:52 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/03/11 15:50:29 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2011/02/21 17:17:38 | 000,037,336 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2011/02/04 13:47:06 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/11/15 17:38:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2010/11/11 12:51:46 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2010/11/11 12:51:45 | 000,128,813 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/11/10 15:42:03 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/11/10 15:35:20 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/11/10 07:24:43 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/11/10 07:23:03 | 000,095,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 08:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2008/04/14 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 08:00:00 | 000,517,230 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 08:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2008/04/14 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 08:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2008/04/14 08:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2008/04/14 08:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2008/04/14 08:00:00 | 000,091,782 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 08:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2005/04/15 12:52:33 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/04/15 12:52:33 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat

========== LOP Check ==========

[2011/04/19 16:53:38 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\14f206
[2011/07/11 22:32:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/03/26 22:45:43 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\BMYTWMP
[2011/07/12 00:04:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\cAp28209eGiKp28209
[2010/12/29 13:51:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CitrixWire
[2011/07/11 17:27:21 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/11 17:45:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/07/15 09:54:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/03/27 15:34:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/07/15 14:15:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/13 20:00:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VirtualizedApplications
[2011/07/13 17:27:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\W3i
[2011/07/13 12:33:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\AVG
[2011/07/13 12:19:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\AVG10
[2011/07/15 09:38:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\DriverCure
[2011/07/15 11:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\ElevatedDiagnostics
[2011/07/15 09:38:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\ParetoLogic
[2011/07/15 13:05:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\SoftGrid Client
[2011/07/13 17:36:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\TP
[2011/07/15 18:24:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\Windows Desktop Search
[2011/07/15 18:49:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\Windows Search

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/11/10 15:39:09 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/12/07 12:02:20 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/11/10 15:39:09 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/04/20 02:25:33 | 001,228,854 | —- | M] () – C:\fsqwr.bmp
[2010/11/10 15:39:09 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/10 15:39:09 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 08:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/15 20:35:04 | 1409,286,144 | -HS- | M] () – C:\pagefile.sys
[2011/07/14 21:12:08 | 000,038,668 | —- | M] () – C:\TDSSKiller.2.5.11.0_14.07.2011_21.04.11_log.txt
[2011/07/15 21:38:15 | 000,039,154 | —- | M] () – C:\TDSSKiller.2.5.11.0_15.07.2011_21.37.51_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/11/10 15:38:40 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/11/10 07:22:02 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/11/10 07:22:02 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/11/10 07:22:01 | 000,929,792 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/07/14 22:02:58 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/13 12:19:21 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/11/15 14:54:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/07/15 19:58:41 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Repair\Desktop\ATF-Cleaner.exe
[2011/07/15 21:47:00 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Repair\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2010/10/20 23:23:26 | 000,000,698 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-15 22:45:42

< >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >





OTL Extras logfile created on: 7/15/2011 9:48:51 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Repair\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.25 Mb Total Physical Memory | 290.89 Mb Available Physical Memory | 32.53% Memory free
2.12 Gb Paging File | 1.55 Gb Available in Paging File | 73.09% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 62.05 Gb Free Space | 83.26% Space Free | Partition Type: NTFS

Computer Name: ZACK | User Name: Repair | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{13CD417D-F1F1-4AC4-945D-FDDEB884756F}" = Microsoft Baseline Security Analyzer 2.2
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{228814B2-6A64-4AD5-8D2D-4E2188DEB191}" = AVG 2011
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 26
"{2764CA82-DFB9-4498-AF85-719340BF5305}" = Dell Resource CD
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{80490945-CE48-45CF-9CCA-CA0EF44D9FE4}" = AVG 2011
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-006D-0409-0000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90140011-0061-0409-0000-0000000FF1CE}" = Microsoft Office Home and Student 2010 - English
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{A9FE59F0-5BFA-4FDF-84C6-F45457715379}" = InstallIQ Updater
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F8FBDC28-C265-4F0D-8B91-6E92913E19F6}" = IIS 6.0 Resource Kit Tools
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ATI Display Driver" = ATI Display Driver
"AVG" = AVG 2011
"CitrixWire" = CitrixWire
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"ie8" = Windows Internet Explorer 8
"InstallShield_{F8FBDC28-C265-4F0D-8B91-6E92913E19F6}" = IIS 6.0 Resource Kit Tools
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/11/2011 11:17:34 PM | Computer Name = HOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 4/11/2011 11:17:56 PM | Computer Name = HOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 4/11/2011 11:25:25 PM | Computer Name = HOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 4/11/2011 11:25:52 PM | Computer Name = HOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 4/11/2011 11:26:42 PM | Computer Name = HOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 4/12/2011 1:27:29 AM | Computer Name = HOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

[ System Events ]
Error - 7/15/2011 7:04:40 PM | Computer Name = ZACK | Source = Service Control Manager | ID = 7023
Description = The SAP Agent service terminated with the following error: %%126

Error - 7/15/2011 7:43:01 PM | Computer Name = ZACK | Source = Service Control Manager | ID = 7023
Description = The Network Security service terminated with the following error:
%%126

Error - 7/15/2011 7:43:01 PM | Computer Name = ZACK | Source = Service Control Manager | ID = 7023
Description = The Intel CPU service terminated with the following error: %%126

Error - 7/15/2011 7:43:01 PM | Computer Name = ZACK | Source = Service Control Manager | ID = 7023
Description = The SAP Agent service terminated with the following error: %%126

Error - 7/15/2011 8:30:56 PM | Computer Name = ZACK | Source = Service Control Manager | ID = 7023
Description = The Network Security service terminated with the following error:
%%126

Error - 7/15/2011 8:30:56 PM | Computer Name = ZACK | Source = Service Control Manager | ID = 7023
Description = The Intel CPU service terminated with the following error: %%126

Error - 7/15/2011 8:30:56 PM | Computer Name = ZACK | Source = Service Control Manager | ID = 7023
Description = The SAP Agent service terminated with the following error: %%126

Error - 7/15/2011 8:35:36 PM | Computer Name = ZACK | Source = Service Control Manager | ID = 7023
Description = The Network Security service terminated with the following error:
%%126

Error - 7/15/2011 8:35:36 PM | Computer Name = ZACK | Source = Service Control Manager | ID = 7023
Description = The Intel CPU service terminated with the following error: %%126

Error - 7/15/2011 8:35:36 PM | Computer Name = ZACK | Source = Service Control Manager | ID = 7023
Description = The SAP Agent service terminated with the following error: %%126


< End of report >
Hi there this should be an easy one. On completion of these runs can you check for redirects

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    [2011/07/11 17:01:10 | 000,000,120 | —- | M] () – C:\WINDOWS\Hqibexaheqimezoc.dat
    [2011/07/11 17:01:10 | 000,000,000 | —- | M] () – C:\WINDOWS\Dhepiyukebicitaq.bin
    [2011/07/11 17:01:01 | 000,010,082 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\b6rkrv8a73spxby2vvgdh23go6k2up6vsdslct8n34k05yp
    [2011/05/14 19:53:00 | 000,010,082 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\b6rkrv8a73spxby2vvgdh23go6k2up6vsdslct8n34k05yp
    [2011/05/12 19:29:18 | 000,000,120 | —- | C] () – C:\WINDOWS\Hqibexaheqimezoc.dat
    [2011/05/12 19:29:18 | 000,000,000 | —- | C] () – C:\WINDOWS\Dhepiyukebicitaq.bin
    [2011/04/19 16:53:38 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\14f206
    [2011/07/12 00:04:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\cAp28209eGiKp28209

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Hi Essexboy - I'm on my desktop to send you this reply. In trying to post the results from the OTL quick scan with the other computer, I keep getting a 503 Service Unavailable error page. Any suggestions? Thanks!
Intriguing - can you get to other sites ?

  • To open a command prompt, click Start > All Programs > Accessories and then click command prompt .
  • Copy and paste (or type) the following command in the command box box and then press ENTER:
    netsh winsock reset c:\resetlog.txt
  • Reboot the computer.
  • In next reply please post content of the file c:\resetlog.txt
I know for some reason on my system that command generates a log… But no one else appears to get it weird or what :smack:
Okay, I don't what the problem is, but it just won't let me post the results from the scan. It keeps going to that error page when I try.
Let's try this again. These are the quick scan results.


OTL logfile created on: 7/16/2011 12:59:04 PM - Run 3
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Repair\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.25 Mb Total Physical Memory | 374.80 Mb Available Physical Memory | 41.91% Memory free
2.12 Gb Paging File | 1.64 Gb Available in Paging File | 77.58% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 62.95 Gb Free Space | 84.46% Space Free | Partition Type: NTFS

Computer Name: ZACK | User Name: Repair | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Repair\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sigmatel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Repair\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Nwsapagent) – File not found
SRV - (itlperf) – File not found
SRV - (6to4) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (STacSV) – C:\Program Files\Sigmatel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)


========== Driver Services (SafeList) ==========

DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Sftvol) – C:\WINDOWS\system32\drivers\Sftvolxp.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\WINDOWS\system32\drivers\Sftredirxp.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\WINDOWS\system32\drivers\Sftplayxp.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\WINDOWS\system32\drivers\Sftfsxp.sys (Microsoft Corporation)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (RMCAST) – C:\WINDOWS\system32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (MQAC) – C:\WINDOWS\system32\drivers\mqac.sys (Microsoft Corporation)
DRV - (NETw4x32) Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{CD0912BB-88D3-4791-AAEE-AED15C6906B5}: C:\Documents and Settings\Myself\Local Settings\Application Data\{CD0912BB-88D3-4791-AAEE-AED15C6906B5} [2011/05/12 19:29:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/07/11 17:39:35 | 000,000,000 | —D | M]


O1 HOSTS File: ([2011/07/16 12:56:28 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKCU..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 6bmn9ya = C:\WINDOWS\TEMP\6iu1cfb.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([www.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: whatthetech.com ([forums] https in Trusted sites)
O15 - HKCU\..Trusted Domains: whatthetech.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([]https in Trusted sites)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/sit…b?1310745410296 (MUCatalogWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1310745184093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Blue Lace 16.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Blue Lace 16.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/11/10 15:39:09 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/16 11:40:42 | 000,000,000 | —D | C] – C:\_OTL
[2011/07/16 11:39:37 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Repair\Desktop\OTL.exe
[2011/07/16 09:55:51 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2011/07/15 21:37:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Desktop\tdsskiller
[2011/07/15 19:27:13 | 000,000,000 | —D | C] – C:\WINDOWS\$968930Uinstall_KB968930$
[2011/07/15 18:54:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Local Settings\Application Data\ApplicationHistory
[2011/07/15 18:49:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Windows Search
[2011/07/15 18:24:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Local Settings\Application Data\Identities
[2011/07/15 18:24:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Windows Desktop Search
[2011/07/15 18:20:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/07/15 18:19:33 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2011/07/15 18:13:23 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2011/07/15 18:13:18 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2011/07/15 18:13:10 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2011/07/15 18:07:33 | 000,000,000 | —D | C] – C:\Program Files\Windows Desktop Search
[2011/07/15 18:07:33 | 000,000,000 | —D | C] – C:\WINDOWS\System32\GroupPolicy
[2011/07/15 18:03:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\URTTemp
[2011/07/15 17:49:30 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2011/07/15 13:54:24 | 000,000,000 | —D | C] – C:\ce8d60a6157be8fc9e4aa3e9ca1a95
[2011/07/15 11:20:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\ElevatedDiagnostics
[2011/07/15 11:20:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2011/07/15 11:19:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2011/07/15 09:38:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\DriverCure
[2011/07/15 09:38:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\ParetoLogic
[2011/07/15 09:38:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/07/15 08:20:54 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/07/14 22:55:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\IIS Resources
[2011/07/14 22:55:30 | 000,000,000 | —D | C] – C:\Program Files\IIS Resources
[2011/07/14 22:54:18 | 000,000,000 | —D | C] – C:\WINDOWS\Downloaded Installations
[2011/07/14 22:31:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\SecurityScans
[2011/07/14 22:30:42 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Baseline Security Analyzer 2
[2011/07/14 22:10:10 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/07/14 22:01:50 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/07/14 21:55:47 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2011/07/14 21:24:01 | 000,000,000 | —D | C] – C:\WINDOWS\System32\msmq
[2011/07/14 21:24:00 | 000,000,000 | —D | C] – C:\Inetpub
[2011/07/13 20:00:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\VirtualizedApplications
[2011/07/13 18:25:30 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/07/13 18:21:31 | 000,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2011/07/13 18:19:30 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2011/07/13 18:19:16 | 000,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2011/07/13 18:15:03 | 000,000,000 | —D | C] – C:\bd11bf1a02cc73b032c610b5b0f3
[2011/07/13 17:42:49 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/07/13 17:36:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Local Settings\Application Data\SoftGrid Client
[2011/07/13 17:35:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\SoftGrid Client
[2011/07/13 17:35:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office Home and Student (English)
[2011/07/13 17:33:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2011/07/13 17:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\SoftGrid Client
[2011/07/13 17:33:23 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/07/13 17:33:23 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Application Virtualization Client
[2011/07/13 17:33:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Microsoft
[2011/07/13 17:31:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\TP
[2011/07/13 17:27:54 | 000,000,000 | -HSD | C] – C:\WINDOWS\System32\AI_RecycleBin
[2011/07/13 17:27:51 | 000,000,000 | —D | C] – C:\Program Files\W3i
[2011/07/13 17:27:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\W3i
[2011/07/13 17:27:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\InstallIQ Updater
[2011/07/13 16:47:59 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\My Documents\My Videos
[2011/07/13 16:31:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Sun
[2011/07/13 13:21:08 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2011/07/13 13:00:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Malwarebytes
[2011/07/13 12:33:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\AVG
[2011/07/13 12:30:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Adobe
[2011/07/13 12:30:27 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Repair\PrivacIE
[2011/07/13 12:19:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\AVG10
[2011/07/13 12:19:08 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Repair\IETldCache
[2011/07/13 12:19:04 | 000,000,000 | –SD | C] – C:\Documents and Settings\Repair\Application Data\Microsoft
[2011/07/13 12:19:04 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Repair\SendTo
[2011/07/13 12:19:04 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Repair\Recent
[2011/07/13 12:19:04 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Repair\Application Data
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\Start Menu\Programs\Startup
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\Start Menu
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\My Documents\My Pictures
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\My Documents\My Music
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\My Documents
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\Favorites
[2011/07/13 12:19:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Repair\Start Menu\Programs\Accessories
[2011/07/13 12:19:04 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Repair\Cookies
[2011/07/13 12:19:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Repair\Templates
[2011/07/13 12:19:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Repair\PrintHood
[2011/07/13 12:19:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Repair\NetHood
[2011/07/13 12:19:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Repair\Local Settings
[2011/07/13 12:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Local Settings\Application Data\Microsoft
[2011/07/13 12:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Macromedia
[2011/07/13 12:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Application Data\Identities
[2011/07/13 12:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Repair\Desktop
[2011/07/12 20:41:06 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/07/12 20:24:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Registry Mechanic
[2011/07/11 23:36:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/07/11 21:11:37 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/07/11 18:28:56 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/07/11 17:39:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011
[2011/07/11 17:38:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/07/11 17:38:07 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/07/11 17:37:27 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/07/11 17:27:21 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files

========== Files - Modified Within 30 Days ==========

[2011/07/16 12:59:45 | 000,012,696 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/16 12:57:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/16 12:56:28 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2011/07/16 12:37:45 | 000,547,436 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/16 12:37:45 | 000,097,092 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/16 12:10:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1336724463-1398281268-1674753652-1005UA.job
[2011/07/16 11:39:42 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Repair\Desktop\OTL.exe
[2011/07/16 09:47:28 | 122,495,328 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/07/15 23:10:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1336724463-1398281268-1674753652-1005Core.job
[2011/07/15 21:02:56 | 000,004,566 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/07/15 18:23:20 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/15 18:07:44 | 000,001,787 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/07/15 13:19:47 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2011/07/15 13:19:45 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2011/07/15 13:15:38 | 000,000,590 | —- | M] () – C:\Documents and Settings\Repair\Desktop\Shortcut to TDSSKiller.2.5.11.0_14.07.2011_21.04.11_log.lnk
[2011/07/15 11:43:17 | 000,000,739 | —- | M] () – C:\Documents and Settings\Repair\Desktop\Shortcut to F-Secure.lnk
[2011/07/15 11:18:39 | 000,000,134 | —- | M] () – C:\Documents and Settings\Repair\Desktop\Microsoft Fix it.url
[2011/07/15 08:23:25 | 000,000,815 | —- | M] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/14 22:30:45 | 000,000,870 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Baseline Security Analyzer 2.2.lnk
[2011/07/14 20:46:15 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/13 16:47:48 | 000,000,800 | —- | M] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/07/13 16:47:48 | 000,000,782 | —- | M] () – C:\Documents and Settings\Repair\Desktop\Windows Media Player.lnk
[2011/07/12 08:11:19 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjw.avm
[2011/07/11 17:39:41 | 000,000,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk

========== Files Created - No Company Name ==========

[2011/07/16 09:47:28 | 122,495,328 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/07/15 18:07:44 | 000,001,803 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Search.lnk
[2011/07/15 18:07:44 | 000,001,787 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/07/15 13:19:47 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2011/07/15 13:19:45 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2011/07/15 13:15:38 | 000,000,590 | —- | C] () – C:\Documents and Settings\Repair\Desktop\Shortcut to TDSSKiller.2.5.11.0_14.07.2011_21.04.11_log.lnk
[2011/07/15 11:43:17 | 000,000,739 | —- | C] () – C:\Documents and Settings\Repair\Desktop\Shortcut to F-Secure.lnk
[2011/07/15 11:18:39 | 000,000,134 | —- | C] () – C:\Documents and Settings\Repair\Desktop\Microsoft Fix it.url
[2011/07/14 22:30:45 | 000,000,876 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Baseline Security Analyzer 2.2.lnk
[2011/07/14 22:30:45 | 000,000,870 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Baseline Security Analyzer 2.2.lnk
[2011/07/14 21:55:39 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2011/07/14 21:55:38 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2011/07/14 21:55:36 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2011/07/13 16:47:48 | 000,000,800 | —- | C] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/07/13 12:19:15 | 000,000,788 | —- | C] () – C:\Documents and Settings\Repair\Start Menu\Programs\Windows Media Player.lnk
[2011/07/13 12:19:15 | 000,000,782 | —- | C] () – C:\Documents and Settings\Repair\Desktop\Windows Media Player.lnk
[2011/07/13 12:19:05 | 000,001,599 | —- | C] () – C:\Documents and Settings\Repair\Start Menu\Programs\Remote Assistance.lnk
[2011/07/13 12:19:05 | 000,000,815 | —- | C] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/13 12:19:05 | 000,000,803 | —- | C] () – C:\Documents and Settings\Repair\Start Menu\Programs\Internet Explorer.lnk
[2011/07/13 12:19:05 | 000,000,079 | —- | C] () – C:\Documents and Settings\Repair\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/07/12 19:33:59 | 000,004,566 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/07/12 16:45:10 | 000,000,982 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1336724463-1398281268-1674753652-1005UA.job
[2011/07/12 16:45:10 | 000,000,930 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1336724463-1398281268-1674753652-1005Core.job
[2011/07/12 08:11:19 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\iavichjw.avm
[2011/07/11 17:39:41 | 000,000,690 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/07/11 16:58:37 | 000,000,004 | -H– | C] () – C:\Documents and Settings\LocalService\Application Data\inlog
[2011/07/11 16:58:35 | 000,000,113 | -H– | C] () – C:\Documents and Settings\LocalService\Application Data\Input.bat
[2011/07/11 16:58:29 | 000,001,120 | -H– | C] () – C:\Documents and Settings\LocalService\Application Data\mlog
[2011/07/11 16:58:27 | 000,000,114 | -H– | C] () – C:\Documents and Settings\LocalService\Application Data\Plug.bat
[2011/07/11 16:58:23 | 000,000,004 | -H– | C] () – C:\Documents and Settings\LocalService\Application Data\ylog
[2011/05/12 16:48:05 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2011/04/08 02:00:52 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/03/11 15:50:29 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2011/02/21 17:17:38 | 000,037,336 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2011/02/04 13:47:06 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/11/15 17:38:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2010/11/11 12:51:46 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2010/11/11 12:51:45 | 000,128,813 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/11/10 15:42:03 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/11/10 15:35:20 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/11/10 07:24:43 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/11/10 07:23:03 | 000,095,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 08:00:00 | 000,547,436 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 08:00:00 | 000,097,092 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 08:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2005/04/15 12:52:33 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/04/15 12:52:33 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat

========== LOP Check ==========

[2011/07/11 22:32:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/03/26 22:45:43 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\BMYTWMP
[2011/07/12 00:04:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\cAp28209eGiKp28209
[2010/12/29 13:51:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CitrixWire
[2011/07/11 17:27:21 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/11 17:45:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/07/15 09:54:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/03/27 15:34:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/07/15 14:15:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/13 20:00:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VirtualizedApplications
[2011/07/13 17:27:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\W3i
[2011/07/13 12:33:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\AVG
[2011/07/13 12:19:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\AVG10
[2011/07/15 09:38:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\DriverCure
[2011/07/15 11:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\ElevatedDiagnostics
[2011/07/15 09:38:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\ParetoLogic
[2011/07/15 13:05:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\SoftGrid Client
[2011/07/13 17:36:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\TP
[2011/07/15 18:24:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\Windows Desktop Search
[2011/07/15 18:49:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Repair\Application Data\Windows Search

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >
I'm running Malwarebytes now, it just finished and reports that there are no malicious items detected (yeah!) But, it's hard to tell, for me, if something evil is redirecting the webpage or if it's something the page is going to do with everyone. If it's okay with you, I'll surf around on the laptop and see how it behaves then post back to you if something appears to be messed up. I can't thank you enough for all your help! It's been a definite challenge this past week trying to get that laptop straightened out - it started out with at least 30 to 50 viruses on it! And I'm no expert with computers - most everything I did I got from either you guys at WhatTheTech or Microsoft/Windows. By the way, did I say THANK YOU!
As I say that was an easy one as the Host file was Hijacked

O1 HOSTS File: ([2011/05/12 16:15:46 | 000,001,527 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 69.10.57.34 www.google.com
O1 - Hosts: 69.10.57.34 www.google.com.au
O1 - Hosts: 69.10.57.34 www.google.be
O1 - Hosts: 69.10.57.34 www.google.com.br
O1 - Hosts: 69.10.57.34 www.google.ca
O1 - Hosts: 69.10.57.34 www.google.ch
O1 - Hosts: 69.10.57.34 www.google.de
O1 - Hosts: 69.10.57.34 www.google.dk
O1 - Hosts: 69.10.57.34 www.google.fr
O1 - Hosts: 69.10.57.34 www.google.ie
O1 - Hosts: 69.10.57.34 www.google.it
O1 - Hosts: 69.10.57.34 www.google.co.jp
O1 - Hosts: 69.10.57.34 www.google.nl
O1 - Hosts: 69.10.57.34 www.google.no
O1 - Hosts: 69.10.57.34 www.google.co.nz
O1 - Hosts: 69.10.57.34 www.google.pl
O1 - Hosts: 69.10.57.34 www.google.se
O1 - Hosts: 69.10.57.34 www.google.co.uk
O1 - Hosts: 69.10.57.34 www.google.co.za
O1 - Hosts: 69.10.57.34 www.bing.com
O1 - Hosts: 69.10.57.34 search.yahoo.com
O1 - Hosts: 69.10.57.34 uk.search.yahoo.com
O1 - Hosts: 69.10.57.34 ca.search.yahoo.com
O1 - Hosts: 69.10.57.34 de.search.yahoo.com
O1 - Hosts: 3 more lines…

What does it mean that the Host file was Hijacked? Also, I meant to ask if you meant that you saw something in the OTL quick scan results when you said " …… one did not want to go" ?

[2011/07/12 00:04:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\cAp28209eGiKp28209

This one but it is an empty directory

The host file is the first place that windows checks for IP addresses so any calls for google were redirected to [removed] which for a change is in the US rather than Ukraine
Thanks for explaining that for me. I need to take some classes on computers so I can understand all this stuff. So, everything looks okay on the laptop?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI