computer is running great. the google redirect seems to be gone (thanks you! sooo annoying lol) but the windows install still dosent work. and i dont think system restore is fixed yet. still have a few file on the desktop that the virus blocked. so i cant i cant delete them or move them. but heres the log
OTL logfile created on: 10/25/2011 4:40:54 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\matt\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1015.30 Mb Total Physical Memory | 523.34 Mb Available Physical Memory | 51.55% Memory free
14.65 Gb Paging File | 14.33 Gb Available in Paging File | 97.82% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.12 Gb Total Space | 50.40 Gb Free Space | 22.49% Space Free | Partition Type: NTFS
Drive D: | 8.74 Gb Total Space | 4.76 Gb Free Space | 54.41% Space Free | Partition Type: FAT32
Computer Name: MATTHEW-B672D25 | User Name: matt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\matt\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\PROMon.exe (Intel Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
========== Win32 Services (SafeList) ==========
SRV - (RalinkRegistryWriter) – File not found
SRV - (PCToolsSSDMonitorSvc) – File not found
SRV - (NMSSvc) Intel® – File not found
SRV - (Icecast-trunk) – File not found
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (MSIServer) – C:\WINDOWS\System32\msiexec.exe ()
========== Driver Services (SafeList) ==========
DRV - (catchme) – File not found
DRV - (39128875) – C:\WINDOWS\system32\drivers\80223438.sys (Kaspersky Lab, GERT)
DRV - (51518490) – C:\WINDOWS\system32\drivers\76704618.sys (Kaspersky Lab, GERT)
DRV - (38982636) – C:\WINDOWS\system32\drivers\61068841.sys (Kaspersky Lab, GERT)
DRV - (Partizan) – C:\WINDOWS\system32\drivers\Partizan.sys (Greatis Software)
DRV - (mvxxmm) – C:\WINDOWS\System32\drivers\mvxxmm.sys (Marvell Semiconductor Inc.)
DRV - (mv64xxmm) – C:\WINDOWS\System32\drivers\mv64xxmm.sys (Marvell Semiconductor Inc.)
DRV - (mv61xxmm) – C:\WINDOWS\System32\drivers\mv61xxmm.sys (Marvell Semiconductor Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (Scutum50) – C:\WINDOWS\system32\drivers\Scutum50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (VCSVADHWSer) Avnex Virtual Audio Device (WDM) – C:\WINDOWS\system32\drivers\vcsvad.sys (Avnex)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (es1371) Creative AudioPCI (ES1371,ES1373) (WDM) – C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.ask.com/?l=dis&o;=16794S
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B2 19 A5 54 5A F4 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: [removed]:3.3.5.1
FF - prefs.js..extensions.enabledItems: [removed]:1.7.3
FF - prefs.js..extensions.enabledItems: [removed]:5.90
FF - prefs.js..extensions.enabledItems: {3DB5ABE1-407D-458F-AD5D-8D89BD625CCC}:1.2.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.3.5.20110120033202
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.4
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.8
FF - prefs.js..extensions.enabledItems: {e6103d7b-6052-4575-a010-59037765e87a}:[removed]
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:5.0.0
FF - prefs.js..extensions.enabledItems: [removed]:2.5.3
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:0.2.7
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.7
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.66
FF - prefs.js..extensions.enabledItems: [removed]:1.1.1
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: {bb6bc1bb-f824-4702-90cd-35e2fb24f25d}:1.5.1
FF - prefs.js..keyword.URL: "
http://flvtubesearch.co/?prt=flvtubetb02ff&Keywords;="
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.gopher_port: 80
FF - prefs.js..network.proxy.http: "[removed]"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.ssl_port: 80
FF - user.js..keyword.URL: "
http://flvtubesearch.co/?prt=flvtubetb02ff&Keywords;="
FF - user.js..keyword.enabled: 1
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/04/07 00:28:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/04/07 00:28:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2011/04/29 21:29:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/21 15:22:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/25 00:35:23 | 000,000,000 | —D | M]
[2011/05/24 21:41:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\matt\Application Data\Mozilla\Extensions
[2011/05/24 21:41:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\matt\Application Data\Mozilla\Extensions\[removed]
[2011/10/16 17:39:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions
[2011/06/21 14:04:38 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/07/18 13:07:56 | 000,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2011/05/08 16:55:17 | 000,000,000 | —D | M] (Veehd Plugin) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{3DB5ABE1-407D-458F-AD5D-8D89BD625CCC}
[2011/08/17 23:53:08 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/05/08 17:04:25 | 000,000,000 | —D | M] (Tamper Data) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2011/08/16 18:46:21 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
[2011/07/07 17:12:35 | 000,000,000 | —D | M] (Cookies Manager+) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d}
[2011/07/07 07:29:22 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2011/08/16 18:46:25 | 000,000,000 | —D | M] ("BetterPrivacy") – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}(2)
[2011/08/16 18:46:22 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}(2)
[2011/08/16 18:46:23 | 000,000,000 | —D | M] (quixley_v2 Community Toolbar) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{e6103d7b-6052-4575-a010-59037765e87a}(2)
[2011/07/07 06:42:59 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/04/23 04:18:30 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/06/21 14:04:58 | 000,000,000 | —D | M] (Firebug) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/10/16 17:39:19 | 000,000,000 | —D | M] (Ghostery) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/05/04 23:17:12 | 000,000,000 | —D | M] (FLV Blaster) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/06/10 22:28:27 | 000,002,568 | —- | M] () – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\searchplugins\askcom.xml
[2011/12/24 18:44:45 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/12 18:21:21 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/12 19:07:02 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/05/07 03:35:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\{888D99E7-E8B5-46A3-851E-1EC45DA1E644}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\[removed]
[2011/04/12 18:21:01 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/21 15:22:54 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 05:08:00 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/13 18:58:48 | 002,418,176 | —- | M] (1 mal 1 Software GmbH) – C:\Program Files\mozilla firefox\plugins\NpFp530.dll
[2011/12/21 15:22:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/24 18:34:05 | 000,001,235 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\flvtube.xml
O1 HOSTS File: ([2011/10/25 16:01:17 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [cFosTASKTR] C:\WINDOWS\BOX_cFosTASK.exe ()
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PROMon.exe] C:\WINDOWS\System32\PROMon.exe (Intel Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk = C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download with FLV Blaster - C:\Documents and Settings\matt\Application Data\FLV Blaster\Internet Explorer\script.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBBAC1D3-9A89-4AC7-B78F-AF89E2DEA75A}: DhcpNameServer = 192.168.15.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/12/24 21:28:18 | 000,000,097 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (Partizan)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011/12/24 21:28:00 | 000,000,000 | —D | C] – C:\Program Files\Creative
[2011/12/24 20:44:05 | 000,000,000 | —D | C] – C:\Documents and Settings\matt\Desktop\New Folder (2)(2)
[2011/12/24 19:30:50 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\matt\Desktop\HiJackThis.exe
[2011/12/24 15:08:31 | 004,272,498 | R— | C] (Swearware) – C:\svchost(6).exe
[2011/12/24 15:08:31 | 004,272,498 | R— | C] (Swearware) – C:\svchost(5).exe
[2011/12/24 15:08:31 | 004,272,498 | R— | C] (Swearware) – C:\svchost(4).exe
[2011/12/24 15:08:31 | 004,272,498 | R— | C] (Swearware) – C:\svchost(3).exe
[2011/12/24 15:08:31 | 004,272,498 | R— | C] (Swearware) – C:\svchost(2).exe
[2011/12/24 06:30:41 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/24 06:27:11 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/12/24 06:27:10 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/12/24 06:27:06 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/12/24 06:27:05 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/12/24 06:26:34 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/12/24 06:26:10 | 000,000,000 | —D | C] – C:\Qoobox
[2011/12/24 06:21:00 | 004,271,407 | R— | C] (Swearware) – C:\ComboFix.exe
[2011/12/22 15:46:27 | 000,000,000 | —D | C] – C:\_OTL
[2011/12/22 15:00:51 | 004,274,341 | R— | C] (Swearware) – C:\Documents and Settings\matt\Desktop\ComboFix.exe
[2011/12/22 05:16:00 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\matt\Desktop\OTL.exe
[2011/12/22 04:59:38 | 000,000,000 | —D | C] – C:\New Folder (2)
[2011/12/18 07:10:48 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Real
[2011/10/25 16:05:25 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2011/10/25 01:07:35 | 000,000,000 | —D | C] – C:\Documents and Settings\matt\Desktop\device identifyer
[2011/10/25 00:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\matt\DoctorWeb
[2011/10/24 23:49:15 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/10/24 23:08:08 | 000,000,000 | —D | C] – C:\ComboFix(7)
[2011/10/24 23:04:40 | 000,000,000 | —D | C] – C:\ComboFix(6)
[2011/10/24 23:01:02 | 000,000,000 | —D | C] – C:\ComboFix(5)
[2011/10/24 22:57:49 | 000,000,000 | —D | C] – C:\ComboFix(4)
[2011/10/24 22:53:59 | 000,000,000 | —D | C] – C:\ComboFix(3)
[2011/10/24 22:32:41 | 000,000,000 | —D | C] – C:\ComboFix(2)
[2011/10/24 20:59:49 | 000,000,000 | —D | C] – C:\Documents and Settings\matt\Application Data\GetRightToGo
[2011/10/16 09:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/10/16 09:38:22 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/24 21:34:43 | 000,504,722 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/24 21:34:43 | 000,088,848 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/24 21:28:18 | 000,000,097 | —- | M] () – C:\AUTOEXEC.BAT
[2011/12/24 19:56:50 | 000,000,227 | —- | M] () – C:\WINDOWS\SYSTEM.I~I
[2011/12/24 19:30:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\matt\Desktop\HiJackThis.exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(6).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(5).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(4).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(3).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(2).exe
[2011/12/24 06:21:03 | 004,271,407 | R— | M] (Swearware) – C:\ComboFix.exe
[2011/12/22 17:43:07 | 079,471,296 | —- | M] () – C:\Documents and Settings\matt\Desktop\u38dn2jh.exe
[2011/12/22 16:10:48 | 098,304,600 | —- | M] () – C:\Documents and Settings\matt\Desktop\setup_11.0.0.1245.x01_2011_10_22_21_43.exe
[2011/12/22 04:03:59 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/20 19:13:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/25 16:40:12 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\matt\Desktop\OTL.exe
[2011/10/25 16:01:17 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/10/25 16:00:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/25 15:39:43 | 004,274,341 | R— | M] (Swearware) – C:\Documents and Settings\matt\Desktop\ComboFix.exe
[2011/10/25 00:25:58 | 000,000,064 | —- | M] () – C:\WINDOWS\wininit.ini
[2011/10/25 00:16:45 | 000,000,336 | RHS- | M] () – C:\boot.ini
[2011/10/24 23:50:12 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/10/24 22:55:52 | 000,050,112 | -HS- | M] () – C:\WINDOWS\System32\c_43440.nl_
[2011/10/24 20:44:23 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/16 23:15:25 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/10/16 10:56:20 | 000,000,865 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Phoenix Viewer.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/24 21:28:07 | 000,011,760 | —- | C] () – C:\WINDOWS\System32\WFM0001A.CSP
[2011/12/24 21:28:07 | 000,009,004 | —- | C] () – C:\WINDOWS\System32\WFM0203A.CSP
[2011/12/24 21:28:07 | 000,009,004 | —- | C] () – C:\WINDOWS\System32\WFM0202A.CSP
[2011/12/24 21:28:07 | 000,006,776 | —- | C] () – C:\WINDOWS\System32\WFM0201A.CSP
[2011/12/24 21:28:07 | 000,006,108 | —- | C] () – C:\WINDOWS\System32\WFM0011A.CSP
[2011/12/24 21:28:07 | 000,002,238 | —- | C] () – C:\WINDOWS\System32\WFM0200A.CSP
[2011/12/24 21:28:07 | 000,001,524 | —- | C] () – C:\WINDOWS\System32\WFM0006A.CSP
[2011/12/24 21:28:07 | 000,001,478 | —- | C] () – C:\WINDOWS\System32\WFM0007A.CSP
[2011/12/24 21:27:37 | 000,000,227 | —- | C] () – C:\WINDOWS\SYSTEM.I~I
[2011/12/24 06:31:32 | 000,000,220 | —- | C] () – C:\Boot.bak
[2011/12/24 06:31:29 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/12/24 06:27:11 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/12/24 06:27:11 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/12/24 06:27:08 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/12/24 06:27:08 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/12/24 06:27:08 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/12/22 17:43:03 | 079,471,296 | —- | C] () – C:\Documents and Settings\matt\Desktop\u38dn2jh.exe
[2011/12/22 16:06:34 | 098,304,600 | —- | C] () – C:\Documents and Settings\matt\Desktop\setup_11.0.0.1245.x01_2011_10_22_21_43.exe
[2011/12/18 15:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI(6).dll
[2011/12/18 15:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI(5).dll
[2011/12/18 15:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI(4).dll
[2011/12/18 15:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI(3).dll
[2011/12/18 15:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI(2).dll
[2011/10/25 00:25:58 | 000,000,064 | —- | C] () – C:\WINDOWS\wininit.ini
[2011/10/25 00:03:24 | 000,000,691 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
[2011/10/16 10:56:20 | 000,000,865 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Phoenix Viewer.lnk
[2011/08/23 06:04:51 | 000,001,638 | —- | C] () – C:\WINDOWS\Sandboxie.ini
[2011/07/14 15:49:19 | 000,000,819 | —- | C] () – C:\WINDOWS\CoDUO.INI
[2011/07/14 15:24:21 | 000,037,336 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2011/07/14 14:52:16 | 000,000,036 | —- | C] () – C:\Documents and Settings\matt\Local Settings\Application Data\housecall.guid.cache
[2011/07/14 12:09:21 | 000,000,745 | —- | C] () – C:\WINDOWS\CoD.INI
[2011/07/08 23:43:00 | 000,000,203 | —- | C] () – C:\WINDOWS\GSdx9.INI
[2011/07/08 13:01:19 | 000,000,203 | —- | C] () – C:\WINDOWS\GSdx9 sse2.INI
[2011/06/13 14:38:55 | 000,182,275 | —- | C] () – C:\WINDOWS\System32\d3d10core.dll
[2011/06/13 14:38:55 | 000,124,931 | —- | C] () – C:\WINDOWS\System32\dxgi.dll
[2011/06/13 14:38:52 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\M2000Twn.dll
[2011/06/13 14:38:49 | 000,728,858 | —- | C] () – C:\Program Files\Common Files\unins000.exe
[2011/06/13 14:38:49 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\CompressATI2.dll
[2011/06/13 14:38:49 | 000,003,005 | —- | C] () – C:\Program Files\Common Files\unins000.dat
[2011/05/31 12:30:07 | 000,000,171 | —- | C] () – C:\WINDOWS\icecast2.ini
[2011/05/30 22:19:36 | 000,000,016 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2011/04/29 20:55:50 | 000,008,704 | —- | C] () – C:\Documents and Settings\matt\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/23 05:56:54 | 000,000,980 | —- | C] () – C:\WINDOWS\eReg.dat
[2011/04/21 21:03:42 | 000,230,752 | —- | C] () – C:\WINDOWS\patchw32.dll
[2011/04/21 21:03:41 | 000,118,176 | —- | C] () – C:\WINDOWS\patchw.dll
[2011/04/18 18:38:30 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2011/04/13 16:44:06 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2011/04/08 22:04:58 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/07 16:20:49 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2011/04/06 08:49:03 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/04/06 08:23:13 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\DiagFunc.dll
[2011/04/06 08:23:13 | 000,001,191 | —- | C] () – C:\WINDOWS\System32\W32N55.INI
[2011/04/06 08:23:13 | 000,000,480 | —- | C] () – C:\WINDOWS\System32\DiagFunc.ini
[2011/04/06 08:22:11 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4764.dll
[2011/04/05 22:31:10 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/04/05 22:25:31 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/04/05 17:18:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/04/05 17:16:47 | 002,019,440 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/25 12:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/01 02:46:04 | 000,407,476 | —- | C] () – C:\WINDOWS\BOX_cFosTASK.exe
[2010/02/28 10:17:48 | 003,284,480 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2008/04/14 06:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 06:00:00 | 000,504,722 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 06:00:00 | 000,095,744 | —- | C] () – C:\WINDOWS\System32\msiexec.exe
[2008/04/14 06:00:00 | 000,088,848 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 06:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 06:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 06:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/03/26 08:36:48 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\PROInst.dll
[2002/02/06 09:04:14 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\NMSInst.dll
[1996/04/03 14:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2011/06/15 13:23:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ableton
[2011/06/03 22:14:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2011/10/16 23:20:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/08/23 05:28:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/08/12 08:41:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\firebird
[2011/08/14 00:40:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/08/23 05:28:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/12 12:16:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/05/13 08:29:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2011/07/13 22:29:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2011/04/06 10:24:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2011/04/21 20:46:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/08/16 18:53:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Premium
[2011/04/06 08:23:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ralink Driver
[2011/10/25 00:18:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/06/13 15:07:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/06/13 14:55:24 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011/05/24 21:01:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/08/23 03:36:23 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\.minecraft
[2011/06/15 13:23:05 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Ableton
[2011/06/03 22:16:19 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\acccore
[2011/05/27 13:47:01 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Avnex
[2011/08/27 10:24:00 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\BitLord
[2011/08/16 19:17:59 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Blender Foundation
[2011/04/06 08:04:49 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Blitware
[2011/04/07 00:29:45 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\DDMSettings
[2011/08/12 07:55:31 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\ElevatedDiagnostics
[2011/05/04 23:17:11 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\FLV Blaster
[2011/06/13 15:29:53 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\FrostWire
[2011/10/24 21:03:55 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\GetRightToGo
[2011/08/22 20:06:05 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\MWSE
[2011/05/13 08:30:04 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Paltalk
[2011/07/20 11:42:41 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Python-Eggs
[2011/07/14 15:34:50 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Registry Mechanic
[2011/05/24 22:38:40 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\rockbox.org
[2011/06/26 11:35:49 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\SecondLife
[2011/08/24 09:19:40 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\SystemRequirementsLab
[2011/06/13 13:51:52 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\TeamViewer
[2011/06/02 01:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Titanium
[2011/08/19 21:30:32 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\tixati
[2011/08/16 18:49:42 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\tixati(3)
[2011/06/13 14:56:09 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\TuneUp Software
[2011/10/25 16:06:41 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\uTorrent
[2011/09/05 08:14:00 | 000,000,474 | —- | M] () – C:\WINDOWS\Tasks\Automatic Maintenance.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2011/12/24 06:21:03 | 004,271,407 | R— | M] (Swearware) – C:\ComboFix.exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install(2).exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install(3).exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install(4).exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install(5).exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install(6).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(2).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(3).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(4).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(5).exe
[2011/12/24 15:08:35 | 004,272,498 | R— | M] (Swearware) – C:\svchost(6).exe
< MD5 for: SFCFILES.DLL >
[2011/02/14 13:56:08 | 001,614,848 | —- | M] (Microsoft Corporation) MD5=E17798E1E6FF1CA9C67B8576570E05EE – C:\pebuilder3110a\BartPE\i386\system32\sfcfiles.dll
[2011/02/14 13:56:08 | 001,614,848 | —- | M] (Microsoft Corporation) MD5=E17798E1E6FF1CA9C67B8576570E05EE – C:\WINDOWS\system32\sfcfiles.dll
< C:\Windows\assembly\tmp\U\*.* /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 177 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:76650B61
< End of report >