lelo
Topic Starter
Hi, my computer has the windows restore virus. All the desktop icons are hidden and can only be viewed if I change the folder options to show hidden files and folder. Also messages keep popping up including "Windows - Delayed Write Filed Failed to save all the components for the file \\System32\\496A8300. The file is corrupted or unreadable. This error may be caused by a PC hardware problem.". Could someone please help me?
OTL logfile created on: 30/03/2011 2:58:26 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\sonam\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 916.44 Gb Total Space | 7.47 Gb Free Space | 0.81% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 10.17 Gb Free Space | 67.81% Space Free | Partition Type: NTFS
Computer Name: SONAM-PC | User Name: sonam | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\sonam\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.AutoUpdate.exe (Research In Motion)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\K-Meleon\k-meleon.exe (http://kmeleon.sf.net/)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Hotspot Shield\bin\openvpntray.exe ()
PRC - C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
PRC - C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Windows\System32\pmxmiced.exe (Primax Electronics Ltd.)
PRC - C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Users\sonam\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (RoxLiveShare9) – File not found
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (HssTrayService) – C:\Program Files\Hotspot Shield\bin\HssTrayService.exe ()
SRV - (HotspotShieldService) – C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec AntiVirus\SNAC.EXE (Symantec Corporation)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec AntiVirus\Smc.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (AresChatServer) – C:\Program Files\Ares\chatServer.exe (Ares Development Group)
SRV - (NMSAccessU) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110330.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110330.003\NAVENG.SYS (Symantec Corporation)
DRV - (Lbd) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (HssDrv) – C:\Windows\System32\drivers\HssDrv.sys (AnchorFree Inc.)
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (LVPr2Mon) – C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (COH_Mon) – C:\Windows\System32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (AnyDVD) – C:\Windows\System32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (NPF) – C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (RtNdPt60) – C:\Windows\System32\drivers\RtNdPt60.sys (Windows ® Codename Longhorn DDK provider)
DRV - (tapvpn) – C:\Windows\System32\drivers\tapvpn.sys (The OpenVPN Project)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (RTL8187) – C:\Windows\System32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (pmxmouse) – C:\Windows\System32\drivers\pmxmouse.sys (Primax Electronics Ltd.)
DRV - (pmxusblf) – C:\Windows\System32\drivers\pmxusblf.sys (Primax Electronics Ltd.)
DRV - (QCMerced) – C:\Windows\System32\drivers\lvcm.sys ()
DRV - (LVUSBSta) – C:\Windows\System32\drivers\LVUSBSta.sys (Logitech Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/enterprise/securit…ponse/index.jsp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID;=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 A3 23 3B 64 E6 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
========== FireFox ==========
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Plugins: C:\Program Files\K-Meleon\Plugins [2010/10/06 18:17:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Components: C:\Program Files\K-Meleon\Components [2010/10/06 18:18:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 06:39:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/23 06:39:26 | 000,000,000 | —D | M]
[2009/02/09 15:14:14 | 000,000,000 | —D | M] (No name found) – C:\Users\sonam\AppData\Roaming\Mozilla\Extensions
[2009/02/09 15:14:14 | 000,000,000 | —D | M] (No name found) – C:\Users\sonam\AppData\Roaming\Mozilla\Extensions\{ae2cff10-0d52-4066-8be9-4abcf119fa79}
[2011/03/28 19:45:33 | 000,000,000 | —D | M] (No name found) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions
[2010/05/03 10:45:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/06/15 19:00:06 | 000,000,000 | —D | M] (jDownFF) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{a3b24d40-bac4-11dc-95ff-0800200c9a66}
[2010/05/03 10:45:17 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/04 18:04:59 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/06/04 18:04:53 | 000,000,000 | —D | M] ("BitDefender QuickScan") – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/05/28 21:04:24 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\[removed]
[2011/03/24 23:59:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/24 23:59:37 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
O1 HOSTS File: ([2010/01/05 18:08:21 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Veoh Video Compass) - {52836EB0-631A-47B1-94A6-61F9D9112DAE} - C:\Program Files\Veoh Networks\Veoh Video Compass\SearchRecsPlugin.dll (Veoh Networks)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QT Lite\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10n_Plugin.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab (RIM AxLoader)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img11.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{6699b567-46de-11e0-92c7-0021703a9f80}\Shell\AutoRun\command - "" = J:\start.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3acm - C:\Windows\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\Windows\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\Windows\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\Windows\System32\mcdvd_32.dll (MainConcept)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/03/30 14:50:48 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\sonam\Desktop\OTL.exe
[2011/03/30 14:50:08 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{33AD8694-4811-4125-973D-CFBA1B5B716A}
[2011/03/25 00:00:25 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\skypePM
[2011/03/24 23:59:44 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\Skype
[2011/03/24 23:59:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/03/24 23:59:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/03/24 23:59:00 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2011/03/24 23:58:46 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2011/03/23 03:22:47 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{3E593D15-4E84-4ED5-BAFB-632910E5C572}
[2011/03/22 18:08:21 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/22 18:08:21 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/03/18 15:10:33 | 000,000,000 | —D | C] – C:\Users\sonam\Documents\BkUp554
[2011/03/17 20:21:31 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{AC2A6EF1-8818-4002-870B-5376CBC63AD3}
[2011/03/16 03:25:25 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{43A2E345-378C-499F-929E-DB4AA7CF365E}
[2011/03/11 14:37:52 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{73BBFA43-A80D-4E47-BEDA-54EA2B5A1A70}
[2011/03/11 13:53:27 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2011/03/11 13:52:29 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\Dropbox
[2011/03/10 22:20:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2011/03/10 22:19:52 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2011/03/10 22:19:19 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2011/03/10 12:41:39 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{E361019C-C46E-48CD-8CAB-83B5C9FC61AB}
[2011/03/09 16:22:05 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/09 16:22:04 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/09 16:22:04 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/03/09 16:22:04 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2011/03/06 17:22:39 | 000,000,000 | —D | C] – C:\Users\sonam\Documents\BlackBerry
[2011/03/06 17:21:38 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\Research In Motion
[2011/03/06 17:15:51 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{B4A4FB8B-1774-4BDD-8A53-5075870837C1}
[2011/03/06 16:53:09 | 000,038,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2011/03/06 16:52:16 | 000,000,000 | —D | C] – C:\ProgramData\Research In Motion
[2011/03/06 16:40:35 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion Limited
[2011/03/05 00:16:27 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{79597155-7FD4-47F4-BF7F-28693DA8670B}
[2011/03/04 13:03:52 | 000,000,000 | —D | C] – C:\Program Files\Pegasys Inc
[2011/03/03 19:52:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2008/10/22 11:56:11 | 000,047,360 | —- | C] (VSO Software) – C:\Users\sonam\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 30 Days ==========
[2011/03/30 14:55:18 | 000,001,057 | —- | M] () – C:\Users\sonam\AppData\Roaming\vso_ts_preview.xml
[2011/03/30 14:50:53 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\sonam\Desktop\OTL.exe
[2011/03/30 14:04:15 | 000,113,152 | —- | M] () – C:\Users\sonam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/30 13:19:26 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/30 13:19:26 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/27 18:26:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-807892715-3149862127-586907164-1000UA.job
[2011/03/27 15:26:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-807892715-3149862127-586907164-1000Core.job
[2011/03/25 00:00:26 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2011/03/24 23:59:06 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/03/24 00:41:18 | 000,000,000 | —- | M] () – C:\Windows\System32\null
[2011/03/23 03:26:25 | 000,611,664 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/03/23 03:26:25 | 000,109,112 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/03/23 03:20:31 | 000,000,276 | —- | M] () – C:\Windows\tasks\RtlNICDiagVistaStart.job
[2011/03/23 03:19:45 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/03/23 03:19:01 | 3220,365,312 | -HS- | M] () – C:\hiberfil.sys
[2011/03/06 17:11:55 | 000,384,568 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/03/06 16:54:10 | 000,002,098 | —- | M] () – C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
[2011/03/06 16:54:08 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2011/03/06 16:54:05 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/03/05 13:15:28 | 000,103,032 | —- | M] () – C:\Users\sonam\Documents\cc_20110305_121354.reg
[2011/03/05 01:08:29 | 005,509,734 | —- | M] () – C:\Users\sonam\Documents\Backup-(2011-03-05).ipd
[2011/03/05 00:42:47 | 000,744,140 | —- | M] () – C:\Users\sonam\Documents\LoaderBackup-(2011-03-04).ipd
[2011/03/05 00:05:31 | 000,000,256 | —- | M] () – C:\Windows\System32\pool.bin
[2011/03/03 19:52:49 | 000,000,861 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
========== Files Created - No Company Name ==========
[2011/03/25 00:00:26 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/03/24 23:59:06 | 000,001,878 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/03/06 16:54:10 | 000,002,098 | —- | C] () – C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
[2011/03/06 16:54:08 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2011/03/06 16:54:05 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/03/06 16:53:13 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
[2011/03/05 13:15:22 | 000,103,032 | —- | C] () – C:\Users\sonam\Documents\cc_20110305_121354.reg
[2011/03/05 01:08:15 | 005,509,734 | —- | C] () – C:\Users\sonam\Documents\Backup-(2011-03-05).ipd
[2011/03/05 00:42:47 | 000,744,140 | —- | C] () – C:\Users\sonam\Documents\LoaderBackup-(2011-03-04).ipd
[2011/03/05 00:05:31 | 000,000,256 | —- | C] () – C:\Windows\System32\pool.bin
[2011/03/03 19:52:49 | 000,000,861 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/11/11 04:05:04 | 000,000,118 | —- | C] () – C:\Windows\System32\MRT.INI
[2010/10/29 01:34:24 | 000,000,008 | —- | C] () – C:\Users\sonam\AppData\Roaming\vfzwln.dat
[2010/10/21 14:38:49 | 000,087,608 | —- | C] () – C:\Users\sonam\AppData\Roaming\inst.exe
[2010/09/22 13:58:11 | 000,113,152 | —- | C] () – C:\Users\sonam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/02 21:24:01 | 000,015,880 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2010/01/05 17:57:57 | 000,261,632 | —- | C] () – C:\Windows\PEV.exe
[2010/01/05 17:57:57 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/01/05 03:03:31 | 000,000,000 | —- | C] () – C:\Windows\System32\cd.dat
[2009/12/03 10:27:28 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/10/16 15:42:47 | 000,180,720 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2009/10/16 15:42:47 | 000,081,920 | —- | C] () – C:\Windows\System32\ATIODE.exe
[2009/10/16 15:42:47 | 000,045,056 | —- | C] () – C:\Windows\System32\ATIODCLI.exe
[2009/10/16 15:42:47 | 000,011,264 | —- | C] () – C:\Windows\System32\atimuixx.dll
[2009/10/11 01:01:05 | 000,000,046 | —- | C] () – C:\Windows\System32\DonationCoder_urlsnooper_InstallInfo.dat
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2009/09/11 01:59:40 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/11 01:59:39 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/19 11:48:25 | 000,000,726 | —- | C] () – C:\Windows\Mp3CutterJoiner.ini
[2009/05/17 16:57:54 | 000,000,005 | —- | C] () – C:\Windows\System32\SySMP3CutJoin.dat
[2009/05/17 16:57:40 | 000,237,568 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2009/03/09 01:05:12 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2009/02/24 15:55:27 | 000,001,057 | —- | C] () – C:\Users\sonam\AppData\Roaming\vso_ts_preview.xml
[2009/01/26 16:02:18 | 000,028,672 | —- | C] () – C:\Windows\System32\AVEQT.dll
[2008/12/25 14:40:14 | 000,129,024 | —- | C] () – C:\Windows\System32\AVERM.dll
[2008/12/23 11:33:18 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2008/11/02 17:05:06 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/10/28 18:29:16 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2008/10/22 11:56:11 | 000,007,887 | —- | C] () – C:\Users\sonam\AppData\Roaming\pcouffin.cat
[2008/10/22 11:56:11 | 000,001,144 | —- | C] () – C:\Users\sonam\AppData\Roaming\pcouffin.inf
[2008/10/17 21:40:46 | 000,139,264 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/10/17 21:40:45 | 000,524,288 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/10/16 17:38:31 | 000,024,206 | —- | C] () – C:\Users\sonam\AppData\Roaming\UserTile.png
[2008/10/15 20:20:23 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/10/04 02:28:21 | 002,192,024 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2008/10/04 02:28:21 | 000,495,376 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2008/10/04 02:28:21 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1527.dll
[2008/10/04 02:28:21 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2008/10/04 02:28:18 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2008/10/04 02:28:18 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2008/10/04 02:28:18 | 000,090,112 | —- | C] () – C:\Windows\System32\atibrtmon.exe
[2008/10/03 23:46:08 | 000,303,104 | —- | C] () – C:\Windows\System32\FontZoom.exe
[2008/10/03 23:46:08 | 000,131,062 | —- | C] () – C:\Windows\System32\DellPM.ini
[2008/10/03 18:34:16 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,384,568 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,611,664 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,109,112 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2005/05/27 09:32:52 | 001,317,152 | —- | C] () – C:\Windows\System32\drivers\lvcm.sys
[2005/05/27 09:10:26 | 000,009,255 | —- | C] () – C:\Windows\System32\lvcoinst.ini
========== LOP Check ==========
[2009/10/15 21:40:45 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\.anomos
[2009/12/25 15:20:01 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\AVSMedia
[2009/07/06 23:21:08 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\BOXEE
[2009/02/09 15:14:13 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Broad Intelligence
[2008/12/25 12:51:14 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Canneverbe_Limited
[2008/12/25 14:12:12 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\devede
[2009/10/11 01:01:05 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\DonationCoder
[2011/03/16 12:50:10 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Dropbox
[2009/06/18 23:22:41 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\FFSJ
[2010/11/09 13:13:44 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\FrostWire
[2009/12/25 15:32:42 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\GetRightToGo
[2009/03/02 15:22:16 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Graboid Inc
[2010/01/05 20:31:26 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\GrabPro
[2008/12/25 14:14:45 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\gtk-2.0
[2009/11/17 16:53:39 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\ICAClient
[2008/11/14 18:24:38 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\ImgBurn
[2009/03/03 23:40:45 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\iPodifier
[2010/10/06 18:20:59 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\K-Meleon
[2010/09/21 21:05:27 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Leadertech
[2009/10/08 15:53:54 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Livestation
[2010/10/17 23:56:39 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\ManyCam
[2009/10/08 15:53:54 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Mchid
[2009/10/18 01:04:11 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Moyea
[2009/06/07 15:27:17 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Octoshape
[2009/04/06 21:16:31 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Opera
[2011/03/17 15:25:24 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Orbit
[2008/10/16 17:38:31 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\PeerNetworking
[2011/02/18 12:18:03 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Pegasys Inc
[2010/12/14 19:43:51 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\QuickScan
[2010/10/28 19:31:04 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Red Kawa
[2011/03/06 17:22:08 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Research In Motion
[2011/03/30 15:02:35 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\uTorrent
[2011/03/30 14:55:20 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Vso
[2011/03/23 03:20:31 | 000,000,276 | —- | M] () – C:\Windows\Tasks\RtlNICDiagVistaStart.job
[2011/03/23 03:17:20 | 000,032,600 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/03/23 03:18:57 | 000,009,180 | —- | M] () – C:\aaw7boot.log
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/10/04 02:28:28 | 000,004,871 | RH– | M] () – C:\dell.sdr
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/03/23 03:19:01 | 3220,365,312 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2009/03/15 19:57:16 | 000,001,363 | —- | M] () – C:\MP4debug.log
[2011/03/23 03:18:58 | 3534,172,160 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/11/02 08:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/15 08:54:21 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 08:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 03:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 22:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 23:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/03 21:17:30 | 000,000,574 | -HS- | M] () – C:\Users\sonam\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2008/11/02 16:46:58 | 004,411,392 | —- | M] (Gabest) – C:\Users\sonam\Desktop\mplayerc.exe
[2011/03/30 14:50:53 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\sonam\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-24 07:01:06
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >
OTL logfile created on: 30/03/2011 2:58:26 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\sonam\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 916.44 Gb Total Space | 7.47 Gb Free Space | 0.81% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 10.17 Gb Free Space | 67.81% Space Free | Partition Type: NTFS
Computer Name: SONAM-PC | User Name: sonam | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\sonam\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.AutoUpdate.exe (Research In Motion)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\K-Meleon\k-meleon.exe (http://kmeleon.sf.net/)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Hotspot Shield\bin\openvpntray.exe ()
PRC - C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
PRC - C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Windows\System32\pmxmiced.exe (Primax Electronics Ltd.)
PRC - C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Users\sonam\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (RoxLiveShare9) – File not found
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (HssTrayService) – C:\Program Files\Hotspot Shield\bin\HssTrayService.exe ()
SRV - (HotspotShieldService) – C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec AntiVirus\SNAC.EXE (Symantec Corporation)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec AntiVirus\Smc.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (AresChatServer) – C:\Program Files\Ares\chatServer.exe (Ares Development Group)
SRV - (NMSAccessU) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110330.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110330.003\NAVENG.SYS (Symantec Corporation)
DRV - (Lbd) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (HssDrv) – C:\Windows\System32\drivers\HssDrv.sys (AnchorFree Inc.)
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (LVPr2Mon) – C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (COH_Mon) – C:\Windows\System32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (AnyDVD) – C:\Windows\System32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (NPF) – C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (RtNdPt60) – C:\Windows\System32\drivers\RtNdPt60.sys (Windows ® Codename Longhorn DDK provider)
DRV - (tapvpn) – C:\Windows\System32\drivers\tapvpn.sys (The OpenVPN Project)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (RTL8187) – C:\Windows\System32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (pmxmouse) – C:\Windows\System32\drivers\pmxmouse.sys (Primax Electronics Ltd.)
DRV - (pmxusblf) – C:\Windows\System32\drivers\pmxusblf.sys (Primax Electronics Ltd.)
DRV - (QCMerced) – C:\Windows\System32\drivers\lvcm.sys ()
DRV - (LVUSBSta) – C:\Windows\System32\drivers\LVUSBSta.sys (Logitech Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/enterprise/securit…ponse/index.jsp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID;=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 A3 23 3B 64 E6 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
========== FireFox ==========
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Plugins: C:\Program Files\K-Meleon\Plugins [2010/10/06 18:17:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Components: C:\Program Files\K-Meleon\Components [2010/10/06 18:18:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 06:39:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/23 06:39:26 | 000,000,000 | —D | M]
[2009/02/09 15:14:14 | 000,000,000 | —D | M] (No name found) – C:\Users\sonam\AppData\Roaming\Mozilla\Extensions
[2009/02/09 15:14:14 | 000,000,000 | —D | M] (No name found) – C:\Users\sonam\AppData\Roaming\Mozilla\Extensions\{ae2cff10-0d52-4066-8be9-4abcf119fa79}
[2011/03/28 19:45:33 | 000,000,000 | —D | M] (No name found) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions
[2010/05/03 10:45:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/06/15 19:00:06 | 000,000,000 | —D | M] (jDownFF) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{a3b24d40-bac4-11dc-95ff-0800200c9a66}
[2010/05/03 10:45:17 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/04 18:04:59 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/06/04 18:04:53 | 000,000,000 | —D | M] ("BitDefender QuickScan") – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/05/28 21:04:24 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\[removed]
[2011/03/24 23:59:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/24 23:59:37 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
O1 HOSTS File: ([2010/01/05 18:08:21 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Veoh Video Compass) - {52836EB0-631A-47B1-94A6-61F9D9112DAE} - C:\Program Files\Veoh Networks\Veoh Video Compass\SearchRecsPlugin.dll (Veoh Networks)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QT Lite\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10n_Plugin.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab (RIM AxLoader)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img11.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{6699b567-46de-11e0-92c7-0021703a9f80}\Shell\AutoRun\command - "" = J:\start.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3acm - C:\Windows\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\Windows\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\Windows\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\Windows\System32\mcdvd_32.dll (MainConcept)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/03/30 14:50:48 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\sonam\Desktop\OTL.exe
[2011/03/30 14:50:08 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{33AD8694-4811-4125-973D-CFBA1B5B716A}
[2011/03/25 00:00:25 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\skypePM
[2011/03/24 23:59:44 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\Skype
[2011/03/24 23:59:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/03/24 23:59:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/03/24 23:59:00 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2011/03/24 23:58:46 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2011/03/23 03:22:47 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{3E593D15-4E84-4ED5-BAFB-632910E5C572}
[2011/03/22 18:08:21 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/22 18:08:21 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/03/18 15:10:33 | 000,000,000 | —D | C] – C:\Users\sonam\Documents\BkUp554
[2011/03/17 20:21:31 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{AC2A6EF1-8818-4002-870B-5376CBC63AD3}
[2011/03/16 03:25:25 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{43A2E345-378C-499F-929E-DB4AA7CF365E}
[2011/03/11 14:37:52 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{73BBFA43-A80D-4E47-BEDA-54EA2B5A1A70}
[2011/03/11 13:53:27 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2011/03/11 13:52:29 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\Dropbox
[2011/03/10 22:20:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2011/03/10 22:19:52 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2011/03/10 22:19:19 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2011/03/10 12:41:39 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{E361019C-C46E-48CD-8CAB-83B5C9FC61AB}
[2011/03/09 16:22:05 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/09 16:22:04 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/09 16:22:04 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/03/09 16:22:04 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2011/03/06 17:22:39 | 000,000,000 | —D | C] – C:\Users\sonam\Documents\BlackBerry
[2011/03/06 17:21:38 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\Research In Motion
[2011/03/06 17:15:51 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{B4A4FB8B-1774-4BDD-8A53-5075870837C1}
[2011/03/06 16:53:09 | 000,038,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2011/03/06 16:52:16 | 000,000,000 | —D | C] – C:\ProgramData\Research In Motion
[2011/03/06 16:40:35 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion Limited
[2011/03/05 00:16:27 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{79597155-7FD4-47F4-BF7F-28693DA8670B}
[2011/03/04 13:03:52 | 000,000,000 | —D | C] – C:\Program Files\Pegasys Inc
[2011/03/03 19:52:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2008/10/22 11:56:11 | 000,047,360 | —- | C] (VSO Software) – C:\Users\sonam\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 30 Days ==========
[2011/03/30 14:55:18 | 000,001,057 | —- | M] () – C:\Users\sonam\AppData\Roaming\vso_ts_preview.xml
[2011/03/30 14:50:53 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\sonam\Desktop\OTL.exe
[2011/03/30 14:04:15 | 000,113,152 | —- | M] () – C:\Users\sonam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/30 13:19:26 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/30 13:19:26 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/27 18:26:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-807892715-3149862127-586907164-1000UA.job
[2011/03/27 15:26:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-807892715-3149862127-586907164-1000Core.job
[2011/03/25 00:00:26 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2011/03/24 23:59:06 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/03/24 00:41:18 | 000,000,000 | —- | M] () – C:\Windows\System32\null
[2011/03/23 03:26:25 | 000,611,664 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/03/23 03:26:25 | 000,109,112 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/03/23 03:20:31 | 000,000,276 | —- | M] () – C:\Windows\tasks\RtlNICDiagVistaStart.job
[2011/03/23 03:19:45 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/03/23 03:19:01 | 3220,365,312 | -HS- | M] () – C:\hiberfil.sys
[2011/03/06 17:11:55 | 000,384,568 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/03/06 16:54:10 | 000,002,098 | —- | M] () – C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
[2011/03/06 16:54:08 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2011/03/06 16:54:05 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/03/05 13:15:28 | 000,103,032 | —- | M] () – C:\Users\sonam\Documents\cc_20110305_121354.reg
[2011/03/05 01:08:29 | 005,509,734 | —- | M] () – C:\Users\sonam\Documents\Backup-(2011-03-05).ipd
[2011/03/05 00:42:47 | 000,744,140 | —- | M] () – C:\Users\sonam\Documents\LoaderBackup-(2011-03-04).ipd
[2011/03/05 00:05:31 | 000,000,256 | —- | M] () – C:\Windows\System32\pool.bin
[2011/03/03 19:52:49 | 000,000,861 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
========== Files Created - No Company Name ==========
[2011/03/25 00:00:26 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/03/24 23:59:06 | 000,001,878 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/03/06 16:54:10 | 000,002,098 | —- | C] () – C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
[2011/03/06 16:54:08 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2011/03/06 16:54:05 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/03/06 16:53:13 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
[2011/03/05 13:15:22 | 000,103,032 | —- | C] () – C:\Users\sonam\Documents\cc_20110305_121354.reg
[2011/03/05 01:08:15 | 005,509,734 | —- | C] () – C:\Users\sonam\Documents\Backup-(2011-03-05).ipd
[2011/03/05 00:42:47 | 000,744,140 | —- | C] () – C:\Users\sonam\Documents\LoaderBackup-(2011-03-04).ipd
[2011/03/05 00:05:31 | 000,000,256 | —- | C] () – C:\Windows\System32\pool.bin
[2011/03/03 19:52:49 | 000,000,861 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/11/11 04:05:04 | 000,000,118 | —- | C] () – C:\Windows\System32\MRT.INI
[2010/10/29 01:34:24 | 000,000,008 | —- | C] () – C:\Users\sonam\AppData\Roaming\vfzwln.dat
[2010/10/21 14:38:49 | 000,087,608 | —- | C] () – C:\Users\sonam\AppData\Roaming\inst.exe
[2010/09/22 13:58:11 | 000,113,152 | —- | C] () – C:\Users\sonam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/02 21:24:01 | 000,015,880 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2010/01/05 17:57:57 | 000,261,632 | —- | C] () – C:\Windows\PEV.exe
[2010/01/05 17:57:57 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/01/05 03:03:31 | 000,000,000 | —- | C] () – C:\Windows\System32\cd.dat
[2009/12/03 10:27:28 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/10/16 15:42:47 | 000,180,720 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2009/10/16 15:42:47 | 000,081,920 | —- | C] () – C:\Windows\System32\ATIODE.exe
[2009/10/16 15:42:47 | 000,045,056 | —- | C] () – C:\Windows\System32\ATIODCLI.exe
[2009/10/16 15:42:47 | 000,011,264 | —- | C] () – C:\Windows\System32\atimuixx.dll
[2009/10/11 01:01:05 | 000,000,046 | —- | C] () – C:\Windows\System32\DonationCoder_urlsnooper_InstallInfo.dat
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2009/09/11 01:59:40 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/11 01:59:39 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/19 11:48:25 | 000,000,726 | —- | C] () – C:\Windows\Mp3CutterJoiner.ini
[2009/05/17 16:57:54 | 000,000,005 | —- | C] () – C:\Windows\System32\SySMP3CutJoin.dat
[2009/05/17 16:57:40 | 000,237,568 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2009/03/09 01:05:12 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2009/02/24 15:55:27 | 000,001,057 | —- | C] () – C:\Users\sonam\AppData\Roaming\vso_ts_preview.xml
[2009/01/26 16:02:18 | 000,028,672 | —- | C] () – C:\Windows\System32\AVEQT.dll
[2008/12/25 14:40:14 | 000,129,024 | —- | C] () – C:\Windows\System32\AVERM.dll
[2008/12/23 11:33:18 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2008/11/02 17:05:06 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/10/28 18:29:16 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2008/10/22 11:56:11 | 000,007,887 | —- | C] () – C:\Users\sonam\AppData\Roaming\pcouffin.cat
[2008/10/22 11:56:11 | 000,001,144 | —- | C] () – C:\Users\sonam\AppData\Roaming\pcouffin.inf
[2008/10/17 21:40:46 | 000,139,264 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/10/17 21:40:45 | 000,524,288 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/10/16 17:38:31 | 000,024,206 | —- | C] () – C:\Users\sonam\AppData\Roaming\UserTile.png
[2008/10/15 20:20:23 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/10/04 02:28:21 | 002,192,024 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2008/10/04 02:28:21 | 000,495,376 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2008/10/04 02:28:21 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1527.dll
[2008/10/04 02:28:21 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2008/10/04 02:28:18 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2008/10/04 02:28:18 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2008/10/04 02:28:18 | 000,090,112 | —- | C] () – C:\Windows\System32\atibrtmon.exe
[2008/10/03 23:46:08 | 000,303,104 | —- | C] () – C:\Windows\System32\FontZoom.exe
[2008/10/03 23:46:08 | 000,131,062 | —- | C] () – C:\Windows\System32\DellPM.ini
[2008/10/03 18:34:16 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,384,568 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,611,664 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,109,112 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2005/05/27 09:32:52 | 001,317,152 | —- | C] () – C:\Windows\System32\drivers\lvcm.sys
[2005/05/27 09:10:26 | 000,009,255 | —- | C] () – C:\Windows\System32\lvcoinst.ini
========== LOP Check ==========
[2009/10/15 21:40:45 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\.anomos
[2009/12/25 15:20:01 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\AVSMedia
[2009/07/06 23:21:08 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\BOXEE
[2009/02/09 15:14:13 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Broad Intelligence
[2008/12/25 12:51:14 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Canneverbe_Limited
[2008/12/25 14:12:12 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\devede
[2009/10/11 01:01:05 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\DonationCoder
[2011/03/16 12:50:10 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Dropbox
[2009/06/18 23:22:41 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\FFSJ
[2010/11/09 13:13:44 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\FrostWire
[2009/12/25 15:32:42 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\GetRightToGo
[2009/03/02 15:22:16 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Graboid Inc
[2010/01/05 20:31:26 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\GrabPro
[2008/12/25 14:14:45 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\gtk-2.0
[2009/11/17 16:53:39 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\ICAClient
[2008/11/14 18:24:38 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\ImgBurn
[2009/03/03 23:40:45 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\iPodifier
[2010/10/06 18:20:59 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\K-Meleon
[2010/09/21 21:05:27 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Leadertech
[2009/10/08 15:53:54 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Livestation
[2010/10/17 23:56:39 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\ManyCam
[2009/10/08 15:53:54 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Mchid
[2009/10/18 01:04:11 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Moyea
[2009/06/07 15:27:17 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Octoshape
[2009/04/06 21:16:31 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Opera
[2011/03/17 15:25:24 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Orbit
[2008/10/16 17:38:31 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\PeerNetworking
[2011/02/18 12:18:03 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Pegasys Inc
[2010/12/14 19:43:51 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\QuickScan
[2010/10/28 19:31:04 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Red Kawa
[2011/03/06 17:22:08 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Research In Motion
[2011/03/30 15:02:35 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\uTorrent
[2011/03/30 14:55:20 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Vso
[2011/03/23 03:20:31 | 000,000,276 | —- | M] () – C:\Windows\Tasks\RtlNICDiagVistaStart.job
[2011/03/23 03:17:20 | 000,032,600 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/03/23 03:18:57 | 000,009,180 | —- | M] () – C:\aaw7boot.log
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/10/04 02:28:28 | 000,004,871 | RH– | M] () – C:\dell.sdr
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/03/23 03:19:01 | 3220,365,312 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2009/03/15 19:57:16 | 000,001,363 | —- | M] () – C:\MP4debug.log
[2011/03/23 03:18:58 | 3534,172,160 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/11/02 08:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/15 08:54:21 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 08:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 03:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 22:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 23:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/03 21:17:30 | 000,000,574 | -HS- | M] () – C:\Users\sonam\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2008/11/02 16:46:58 | 004,411,392 | —- | M] (Gabest) – C:\Users\sonam\Desktop\mplayerc.exe
[2011/03/30 14:50:53 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\sonam\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-24 07:01:06
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >