OTL Extras logfile created on: 7/17/2011 3:09:46 AM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Big H\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.04 Gb Available Physical Memory | 67.95% Memory free
4.84 Gb Paging File | 4.19 Gb Available in Paging File | 86.59% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 43.57 Gb Free Space | 38.98% Space Free | Partition Type: NTFS
Computer Name: HYDRO | User Name: Big H | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:TCP" = 1900:TCP:LocalSubNet:Enabled:UDP 1900
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" = C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome – (Google Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{153F839F-0A63-41D8-890F-7324C0E13743}" = Broadcom Driver v4.170.25.12_Foxconn Installation Program
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Acer Crystal Eye webcam
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A633ED0-E5D7-4D65-AB8D-53ED43510284}" = Symantec AntiVirus
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{669A032D-4E28-3D11-BB26-8AD5D51EFE87}" = Google Talk Plugin
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{78764173-3805-4916-B3CE-B433702B8870}" = O2Micro Flash Memory Card Reader Driver Installer(x86)
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BE}" = WinZip 15.0
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"ATI Display Driver" = ATI Display Driver (Omega 3.8.442)
"DivX Setup.divx.com" = DivX Setup
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.6.6 (Standard)
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MultiRes (remove only)" = MultiRes (remove only)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Radeon Omega Drivers for Windows XP/2kv4.8.442" = Radeon Omega Drivers v4.8.442 Setup Files and Tools
"RealPlayer 12.0" = RealPlayer
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Veetle TV" = Veetle TV 0.9.18
"VLC media player" = VLC media player 1.1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 7/16/2011 10:00:04 PM | Computer Name = HYDRO | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Bloodhound.MalPE in File: C:\System Volume Information\_restore{31E217E4-C6BB-49FC-85EA-11675B3EEF5F}\RP1\A0000038.exe
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.
Error - 7/16/2011 10:00:04 PM | Computer Name = HYDRO | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{31E217E4-C6BB-49FC-85EA-11675B3EEF5F}\RP1\A0000038.exe by:
Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.
Error - 7/16/2011 10:00:12 PM | Computer Name = HYDRO | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{31E217E4-C6BB-49FC-85EA-11675B3EEF5F}\RP1\A0000039.exe by:
Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully.
Error - 7/16/2011 10:00:12 PM | Computer Name = HYDRO | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Bloodhound.MalPE in File: C:\System Volume Information\_restore{31E217E4-C6BB-49FC-85EA-11675B3EEF5F}\RP1\A0000039.exe
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.
Error - 7/16/2011 10:00:12 PM | Computer Name = HYDRO | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{31E217E4-C6BB-49FC-85EA-11675B3EEF5F}\RP1\A0000039.exe by:
Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.
Error - 7/16/2011 10:00:20 PM | Computer Name = HYDRO | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{31E217E4-C6BB-49FC-85EA-11675B3EEF5F}\RP1\A0000040.exe by:
Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully.
Error - 7/16/2011 10:00:20 PM | Computer Name = HYDRO | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Bloodhound.MalPE in File: C:\System Volume Information\_restore{31E217E4-C6BB-49FC-85EA-11675B3EEF5F}\RP1\A0000040.exe
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.
Error - 7/16/2011 10:00:20 PM | Computer Name = HYDRO | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{31E217E4-C6BB-49FC-85EA-11675B3EEF5F}\RP1\A0000040.exe by:
Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.
Error - 7/16/2011 10:19:00 PM | Computer Name = HYDRO | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 7/16/2011 10:19:01 PM | Computer Name = HYDRO | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
[ System Events ]
Error - 7/16/2011 4:35:18 AM | Computer Name = HYDRO | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll.
Reference
error message: The operation completed successfully. .
Error - 7/16/2011 5:05:18 AM | Computer Name = HYDRO | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.DebugCRT could not be found and
Last Error was The referenced assembly is not installed on your system.
Error - 7/16/2011 5:05:18 AM | Computer Name = HYDRO | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.DebugCRT. Reference
error message: The referenced assembly is not installed on your system. .
Error - 7/16/2011 5:05:18 AM | Computer Name = HYDRO | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll.
Reference
error message: The operation completed successfully. .
Error - 7/16/2011 5:35:18 AM | Computer Name = HYDRO | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.DebugCRT could not be found and
Last Error was The referenced assembly is not installed on your system.
Error - 7/16/2011 5:35:18 AM | Computer Name = HYDRO | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.DebugCRT. Reference
error message: The referenced assembly is not installed on your system. .
Error - 7/16/2011 5:35:18 AM | Computer Name = HYDRO | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll.
Reference
error message: The operation completed successfully. .
Error - 7/16/2011 8:37:41 PM | Computer Name = HYDRO | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.
Error - 7/16/2011 10:11:18 PM | Computer Name = HYDRO | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.
Error - 7/16/2011 11:02:00 PM | Computer Name = HYDRO | Source = System Error | ID = 1003
Description = Error code 1000000a, parameter1 00c61000, parameter2 00000002, parameter3
00000000, parameter4 806163cf.
< End of report >
OTL logfile created on: 7/17/2011 3:09:46 AM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Big H\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.04 Gb Available Physical Memory | 67.95% Memory free
4.84 Gb Paging File | 4.19 Gb Available in Paging File | 86.59% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 43.57 Gb Free Space | 38.98% Space Free | Partition Type: NTFS
Computer Name: HYDRO | User Name: Big H | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Big H\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Documents and Settings\Big H\Local Settings\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\O2Micro Oz128 Driver\o2flash.exe (O2Micro International)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Big H\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AgereModemAudio) – C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
SRV - (o2flash) – C:\Program Files\O2Micro Oz128 Driver\o2flash.exe (O2Micro International)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
========== Driver Services (SafeList) ==========
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110715.004\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110715.004\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atitray) – C:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys ()
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corp.)
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (O2MDRDR) – C:\WINDOWS\system32\DRIVERS\o2media.sys (O2Micro )
DRV - (O2SDRDR) – C:\WINDOWS\system32\DRIVERS\o2sd.sys (O2Micro )
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.609: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.609: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.609: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.609: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Big H\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Big H\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/23 06:27:48 | 000,000,000 | —D | M]
Hosts file not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AtiPTA] C:\WINDOWS\System32\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSet] C:\WINDOWS\PLFSet.dll ( )
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Big H\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Big H\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/12/22 04:01:42 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/07/17 03:06:28 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Big H\Desktop\OTL.exe
[2011/07/17 03:03:10 | 001,906,176 | —- | C] (AVAST Software) – C:\Documents and Settings\Big H\Desktop\aswMBR.exe
[2011/07/16 22:04:45 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Big H\Desktop\HiJackThis.exe
[2011/07/16 21:56:49 | 000,000,000 | R–D | C] – C:\Documents and Settings\Big H\Start Menu\Programs\Administrative Tools
[2011/07/16 21:56:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Big H\Desktop\Downloads
[2011/07/16 21:52:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Big H\Desktop\Misc
[2011/07/16 21:50:29 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2011/07/16 21:50:26 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/07/16 18:19:48 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/07/16 18:19:46 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/07/12 19:36:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Big H\Application Data\Mozilla
[2011/07/10 17:20:30 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2011/07/10 17:20:28 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2011/07/10 17:20:24 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2011/07/10 17:20:15 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2011/07/07 02:36:36 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2011/07/04 03:53:27 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/12/22 04:19:31 | 000,045,056 | —- | C] ( ) – C:\WINDOWS\PLFSet.dll
[2010/12/22 04:19:30 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2010/12/22 04:19:30 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/07/17 03:13:42 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/17 03:08:21 | 000,000,539 | —- | M] () – C:\Documents and Settings\Big H\Desktop\MBR.zip
[2011/07/17 03:07:17 | 000,092,160 | —- | M] () – C:\Documents and Settings\Big H\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/17 03:06:29 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Big H\Desktop\OTL.exe
[2011/07/17 03:05:50 | 000,000,512 | —- | M] () – C:\Documents and Settings\Big H\Desktop\MBR.dat
[2011/07/17 03:03:56 | 001,906,176 | —- | M] (AVAST Software) – C:\Documents and Settings\Big H\Desktop\aswMBR.exe
[2011/07/17 03:03:19 | 000,312,172 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/17 03:03:19 | 000,040,394 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/17 03:00:23 | 000,000,258 | —- | M] () – C:\WINDOWS\tasks\WGASetup.job
[2011/07/17 02:57:42 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-583907252-562591055-1801674531-1003.job
[2011/07/17 02:57:38 | 000,000,312 | -HS- | M] () – C:\WINDOWS\tasks\LPIE.job
[2011/07/17 02:57:33 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/16 22:43:36 | 737,260,870 | —- | M] () – C:\Documents and Settings\Big H\Desktop\Exam[2009]DVDRip XviD-ExtraTorrentRG.avi
[2011/07/16 22:04:48 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Big H\Desktop\HiJackThis.exe
[2011/07/16 21:24:08 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-562591055-1801674531-1003UA.job
[2011/07/16 18:45:51 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/16 18:43:11 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2011/07/16 18:37:36 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/07/16 18:31:03 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/07/16 18:25:58 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/07/16 18:19:23 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/07/16 18:19:16 | 000,062,976 | RHS- | M] () – C:\WINDOWS\System32\esentj.dll
[2011/07/16 02:24:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-562591055-1801674531-1003Core.job
[2011/07/14 23:51:54 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-583907252-562591055-1801674531-1003.job
[2011/07/13 16:12:13 | 000,135,664 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/13 15:23:17 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/07/06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/05 19:27:39 | 048,140,259 | —- | M] () – C:\Documents and Settings\Big H\Desktop\Lady Gaga - Hair (Live on Taratata).flv
[2011/07/02 22:38:17 | 000,013,409 | —- | M] () – C:\Documents and Settings\Big H\Desktop\genbc.jpg
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/07/17 03:08:20 | 000,000,539 | —- | C] () – C:\Documents and Settings\Big H\Desktop\MBR.zip
[2011/07/17 03:07:19 | 737,260,870 | —- | C] () – C:\Documents and Settings\Big H\Desktop\Exam[2009]DVDRip XviD-ExtraTorrentRG.avi
[2011/07/17 03:05:50 | 000,000,512 | —- | C] () – C:\Documents and Settings\Big H\Desktop\MBR.dat
[2011/07/16 18:19:16 | 000,062,976 | RHS- | C] () – C:\WINDOWS\System32\esentj.dll
[2011/07/16 18:19:16 | 000,000,312 | -HS- | C] () – C:\WINDOWS\tasks\LPIE.job
[2011/07/16 15:34:57 | 000,000,322 | —- | C] () – C:\WINDOWS\tasks\At5.job
[2011/07/16 15:34:57 | 000,000,322 | —- | C] () – C:\WINDOWS\tasks\At4.job
[2011/07/16 15:34:57 | 000,000,322 | —- | C] () – C:\WINDOWS\tasks\At3.job
[2011/07/16 15:34:56 | 000,000,322 | —- | C] () – C:\WINDOWS\tasks\At2.job
[2011/07/16 15:34:56 | 000,000,322 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2011/07/05 19:18:59 | 048,140,259 | —- | C] () – C:\Documents and Settings\Big H\Desktop\Lady Gaga - Hair (Live on Taratata).flv
[2011/07/02 22:38:22 | 000,013,409 | —- | C] () – C:\Documents and Settings\Big H\Desktop\genbc.jpg
[2011/06/04 09:39:05 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/27 23:00:23 | 000,025,020 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/12/24 18:25:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/12/23 05:34:11 | 000,092,160 | —- | C] () – C:\Documents and Settings\Big H\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/23 05:29:52 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/12/23 05:22:19 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2010/12/22 05:37:23 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2010/12/22 05:36:11 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\atiiprxx.exe
[2010/12/22 05:36:09 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2010/12/22 05:36:09 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/12/22 05:36:08 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/12/22 05:36:08 | 000,158,080 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/12/22 05:36:08 | 000,000,011 | —- | C] () – C:\WINDOWS\System32\atiicdxx.ini
[2010/12/22 05:36:03 | 000,472,576 | —- | C] () – C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe
[2010/12/22 05:04:55 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\Desktop_.ini
[2010/12/22 04:19:30 | 001,729,152 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2010/12/22 04:14:34 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/12/22 04:03:41 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/12/22 03:58:11 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/12/21 19:47:26 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/12/21 19:46:01 | 000,135,664 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/14 07:55:28 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2006/12/31 09:57:08 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,312,172 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,040,394 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/12/22 05:04:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broadcom
[2010/12/23 05:45:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/12/27 22:58:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/01/23 22:46:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Big H\Application Data\PriceGong
[2011/07/16 21:49:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Big H\Application Data\uTorrent
[2011/07/16 18:19:23 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/07/16 18:25:58 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/07/16 18:31:03 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/07/16 18:37:36 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2011/07/16 18:43:11 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2011/07/17 02:57:38 | 000,000,312 | -HS- | M] () – C:\WINDOWS\Tasks\LPIE.job
[2011/07/17 03:00:23 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\WGASetup.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/12/22 04:01:42 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/12/22 04:15:34 | 000,000,223 | RHS- | M] () – C:\boot.ini
[2010/12/22 04:01:42 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/12/22 04:01:42 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/12/22 04:01:42 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/12/22 04:53:54 | 000,022,729 | —- | M] () – C:\newfile.enc
[2010/12/22 04:53:54 | 000,022,729 | —- | M] () – C:\newkey
[2008/04/14 00:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 02:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/17 02:57:13 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/12/22 04:01:16 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/01/02 02:03:25 | 000,001,666 | -H– | M] () – C:\Documents and Settings\Big H\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/12/21 19:45:17 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/12/21 19:45:17 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/12/21 19:45:17 | 000,929,792 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2010/12/22 04:01:48 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2010/12/22 04:01:48 | 000,001,607 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2010/12/22 04:01:48 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2010/12/22 04:01:48 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Deskuop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-13 20:25:18
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< MD5 for: EXPLORER.EXE >
[2008/04/14 07:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 07:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2011/07/16 01:36:05 | 000,068,350 | —- | M] () MD5=502B52DB54A08F58A77874A63DB1AD31 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.SCF >
[2004/08/04 07:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2007/04/03 00:09:24 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 11:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\Help\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2010/12/20 06:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\ie7updates\KB2497640-IE7\iexplore.exe
[2011/04/21 05:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2008/04/14 07:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2010/10/18 06:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2482017-IE7\iexplore.exe
[2010/10/18 06:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\SoftwareDistribution\Download\6f45bbb9bc87c683482142e5b18b2399\SP3GDR\iexplore.exe
[2010/04/16 06:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/04/16 06:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\SoftwareDistribution\Download\626f83f88e86511ae79d7ff76840cc8e\SP3QFE\iexplore.exe
[2011/04/21 05:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\Program Files\Internet Explorer\iexplore.exe
[2011/04/21 05:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\system32\dllcache\iexplore.exe
[2010/12/20 05:49:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\$hf_mig$\KB2482017-IE7\SP3QFE\iexplore.exe
[2010/04/16 06:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2010/04/16 06:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\SoftwareDistribution\Download\626f83f88e86511ae79d7ff76840cc8e\SP3GDR\iexplore.exe
[2010/10/18 05:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2010/10/18 05:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\SoftwareDistribution\Download\6f45bbb9bc87c683482142e5b18b2399\SP3QFE\iexplore.exe
[2007/08/13 21:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2011/02/14 06:36:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[2011/02/14 07:17:08 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2010/08/25 06:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2010/08/25 06:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\SoftwareDistribution\Download\ec5f3c04575717e1f2f35e24c8375b92\SP3GDR\iexplore.exe
[2010/08/25 06:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2010/08/25 06:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\SoftwareDistribution\Download\ec5f3c04575717e1f2f35e24c8375b92\SP3QFE\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2007/08/13 21:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2011/07/16 18:50:34 | 000,065,784 | —- | M] () MD5=186DEBCB8652ED44EF20F22CFA2233D4 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/04 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: WINLOGON.EXE >
[2008/04/14 07:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 07:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< End of report >