OTL
OTL logfile created on: 10/16/2011 12:04:28 AM - Run 1
OTL by OldTimer - Version 3.2.30.0 Folder = C:\Documents and Settings\Richard\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.44 Gb Total Physical Memory | 1.86 Gb Available Physical Memory | 76.26% Memory free
4.28 Gb Paging File | 3.82 Gb Available in Paging File | 89.20% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 444.20 Gb Free Space | 95.37% Space Free | Partition Type: NTFS
Computer Name: EVILEMPIRE1 | User Name: Richard | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Richard\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Spyware Doctor\pctsGui.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
PRC - C:\WINDOWS\system32\dlcccoms.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Trusteer\Rapport\bin\js32.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportMS.dll ()
MOD - C:\Program Files\Spyware Doctor\NetworkLayer\PCTCFHook.dll ()
MOD - C:\Program Files\Spyware Doctor\UserModeFileCache.dll ()
MOD - C:\Program Files\Spyware Doctor\avengine\sdkBSCtrl.dll ()
MOD - C:\Program Files\ASUS WiFi-AP Solo\acAuth.dll ()
MOD - C:\Program Files\ASUS WiFi-AP Solo\EnumDevLib.dll ()
MOD - C:\WINDOWS\system32\dlccserv.dll ()
MOD - C:\WINDOWS\system32\dlcclmpm.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlccpplc.dll ()
MOD - C:\WINDOWS\system32\dlcccoms.exe ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlcccomc.dll ()
MOD - C:\WINDOWS\system32\dlccprox.dll ()
MOD - C:\WINDOWS\system32\dlccusb1.dll ()
MOD - C:\WINDOWS\system32\dlcccfg.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlcccfg.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlccdrec.dll ()
MOD - C:\WINDOWS\system32\dlcccnv4.dll ()
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state) – File not found
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\Spyware Doctor\TFEngine\TFService.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (dlcc_device) – C:\WINDOWS\System32\dlcccoms.exe ()
========== Driver Services (SafeList) ==========
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportEI) – C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\WINDOWS\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (RapportCerberus_29574) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\29574\RapportCerberus32_29574.sys ()
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (ADIDTSFiltService) – C:\WINDOWS\system32\drivers\adidts.sys (Analog Devices, Inc.)
DRV - (SjyPkt) – C:\WINDOWS\system32\drivers\SjyPkt.sys (Windows ® 2000 DDK provider)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://vshare.toolbarhome.com/?hp=df
IE - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "vshare.tv Bar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "
http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.facebook.com/"
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.2
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/09 10:59:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/24 22:12:29 | 000,000,000 | —D | M]
[2010/08/11 21:57:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard\Application Data\Mozilla\Extensions
[2011/09/27 17:17:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions
[2011/09/24 15:48:01 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/27 17:16:54 | 000,000,000 | —D | M] (vshare.tv Bar Community Toolbar) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{7aeb3efd-e564-43f1-b658-5058a7c5743b}
[2011/09/27 17:17:00 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/08/27 19:51:40 | 000,000,000 | —D | M] (BetterLinks) – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\extensions\[removed]
[2011/01/01 23:31:05 | 000,001,919 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\bing-zugo.xml
[2011/08/31 11:26:36 | 000,000,929 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\conduit.xml
[2010/11/17 22:41:47 | 000,002,689 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\search-defender.xml
[2011/05/10 12:48:19 | 000,001,583 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Mozilla\Firefox\Profiles\vgkroduj.default\searchplugins\web-search.xml
[2011/10/09 10:59:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/09/29 01:53:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/08/31 05:38:58 | 000,082,944 | —- | M] (vShare.tv ) – C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2011/09/28 19:26:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Complitly plugin for chrome = C:\Documents and Settings\Richard\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.1_0\
CHR - Extension: vshare plugin = C:\Documents and Settings\Richard\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
O1 HOSTS File: ([2010/09/22 18:06:42 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [DLCCCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.DLL ()
O4 - HKLM..\Run: [dlccmon.exe] C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /installquiet File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ASUS WiFi-AP Solo.lnk = C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe (ASUSTek Computer Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-220523388-1958367476-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1281501938125 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Garmin Communicator Plug-In
https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FB34C3F4-5CD3-4F21-94B5-CB6BAF3B9CBB}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/10 23:09:28 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/10/15 23:57:33 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Richard\Desktop\aswMBR.exe
[2011/10/15 23:56:19 | 000,583,168 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Richard\Desktop\OTL.exe
[2011/10/14 12:36:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\PCTools
[2011/10/14 12:19:39 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Richard\Recent
[2011/10/14 12:14:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\PC Cleaners
[2011/10/14 12:14:32 | 005,356,304 | —- | C] (PC Cleaners) – C:\WINDOWS\uninst.exe
[2011/10/14 12:14:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC1Data
[2011/10/09 10:49:35 | 000,000,000 | —D | C] – C:\8017a49069b9c72076
[2011/09/25 19:00:08 | 000,056,336 | —- | C] (Trusteer Ltd.) – C:\WINDOWS\System32\drivers\RapportKELL.sys
[2011/09/24 22:13:02 | 000,000,000 | —D | C] – C:\Program Files\Complitly
[2011/09/24 22:13:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\Complitly
[2011/09/24 22:12:43 | 000,000,000 | —D | C] – C:\Program Files\vshare.tv_Bar
[2011/09/24 22:12:22 | 000,000,000 | —D | C] – C:\Program Files\vShare.tv plugin
[2011/09/19 17:15:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/09/19 17:14:58 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/09/19 17:14:51 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/09/19 17:09:09 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/09/18 17:48:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\vShare
[2011/09/18 12:15:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard\Application Data\StreamTorrent
[2006/12/20 16:58:02 | 000,397,312 | —- | C] ( ) – C:\WINDOWS\System32\dlcciesc.dll
[2006/12/20 16:47:32 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\dlccinpa.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[11 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/10/16 00:03:45 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/16 00:03:27 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/16 00:03:23 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\PCConfidential.job
[2011/10/16 00:03:22 | 000,276,202 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2011/10/16 00:03:15 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/15 23:57:39 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Richard\Desktop\aswMBR.exe
[2011/10/15 23:56:21 | 000,583,168 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Richard\Desktop\OTL.exe
[2011/10/15 23:53:00 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/14 12:14:03 | 005,356,304 | —- | M] (PC Cleaners) – C:\WINDOWS\uninst.exe
[2011/10/10 14:54:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/09 11:00:04 | 000,000,742 | —- | M] () – C:\Documents and Settings\Richard\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/09 11:00:04 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/10/09 10:53:51 | 000,405,372 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/10/09 10:53:51 | 000,062,350 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/10/09 10:40:36 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/10/09 10:37:03 | 000,001,784 | —- | M] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103656.reg
[2011/10/09 10:36:26 | 000,096,532 | —- | M] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103614.reg
[2011/10/08 12:35:59 | 000,024,064 | —- | M] () – C:\Documents and Settings\Richard\My Documents\982B1400
[2011/10/05 02:54:10 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/09/27 20:42:18 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/09/25 19:00:08 | 000,056,336 | —- | M] (Trusteer Ltd.) – C:\WINDOWS\System32\drivers\RapportKELL.sys
[2011/09/24 22:11:01 | 001,400,408 | —- | M] () – C:\Documents and Settings\Richard\Desktop\vshare-plugin-v7.exe
[2011/09/19 17:15:43 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/09/16 03:05:54 | 000,681,086 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[11 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/10/09 11:00:04 | 000,000,742 | —- | C] () – C:\Documents and Settings\Richard\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/09 11:00:04 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/10/09 11:00:03 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/10/09 10:36:57 | 000,001,784 | —- | C] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103656.reg
[2011/10/09 10:36:16 | 000,096,532 | —- | C] () – C:\Documents and Settings\Richard\My Documents\cc_20111009_103614.reg
[2011/09/24 22:11:01 | 001,400,408 | —- | C] () – C:\Documents and Settings\Richard\Desktop\vshare-plugin-v7.exe
[2011/09/19 17:15:43 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/02/05 02:28:13 | 000,054,996 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/01/10 19:16:57 | 000,003,584 | —- | C] () – C:\Documents and Settings\Richard\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/11 21:57:26 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/08/10 23:38:53 | 000,023,714 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/08/10 23:38:51 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/08/10 23:38:48 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/08/10 23:38:19 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/08/10 23:11:21 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/10 23:06:51 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/10 17:20:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/10 17:17:12 | 000,260,640 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/04/03 22:55:32 | 002,183,470 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2007/02/14 16:23:20 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\dlccih.exe
[2007/02/14 16:23:18 | 000,491,520 | —- | C] () – C:\WINDOWS\System32\dlcccoms.exe
[2007/02/14 16:23:18 | 000,368,640 | —- | C] () – C:\WINDOWS\System32\dlcccfg.exe
[2007/02/07 12:57:16 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\dlcccoin.dll
[2007/01/26 07:11:42 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlccinsr.dll
[2007/01/26 07:11:20 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcccur.dll
[2007/01/26 07:09:58 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlccjswr.dll
[2007/01/26 06:59:04 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlccinsb.dll
[2007/01/26 06:58:30 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcccub.dll
[2007/01/26 06:57:38 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcccu.dll
[2007/01/26 06:57:18 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccins.dll
[2007/01/26 06:53:46 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlccutil.dll
[2007/01/22 02:24:50 | 000,065,536 | R— | C] () – C:\WINDOWS\System32\dlcccfg.dll
[2006/12/20 17:08:24 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlccpmui.dll
[2006/12/20 17:06:58 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlccserv.dll
[2006/12/20 17:01:04 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcccomm.dll
[2006/12/20 16:59:24 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcclmpm.dll
[2006/12/20 16:55:40 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlccpplc.dll
[2006/12/20 16:54:54 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcccomc.dll
[2006/12/20 16:54:20 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccprox.dll
[2006/12/20 16:46:50 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlccusb1.dll
[2006/12/20 16:42:36 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcchbn3.dll
[2005/08/18 06:26:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlccvs.dll
[2005/04/01 11:44:16 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dlcccnv4.dll
[2004/08/04 01:07:22 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,405,372 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,062,350 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/08/14 20:21:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/08/27 19:52:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2011/10/14 12:14:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC1Data
[2011/10/16 00:03:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/04/23 19:45:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2010/10/24 10:08:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/08/28 15:08:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}
[2011/08/28 15:12:41 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~0
[2011/05/10 18:37:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\Trusteer
[2010/10/25 17:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\Auslogics
[2011/10/16 00:01:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\Complitly
[2011/07/13 17:39:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\GARMIN
[2011/10/14 12:14:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\PC Cleaners
[2011/10/14 12:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\PCTools
[2011/09/14 23:54:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\simppulltoolbar
[2011/09/18 12:15:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\StreamTorrent
[2011/04/23 19:46:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\Trusteer
[2011/09/18 17:48:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\vShare
[2010/08/22 22:38:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard\Application Data\WeatherBug
[2011/10/16 00:03:23 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\PCConfidential.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 206 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
< End of report >