OTL by OldTimer - Version 3.2.70.1 Folder = C:\Documents and Settings\Salim.CCLAPTOP\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
503.37 Mb Total Physical Memory | 110.00 Mb Available Physical Memory | 21.85% Memory free
1.20 Gb Paging File | 0.82 Gb Available in Paging File | 67.88% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.17 Gb Total Space | 5.01 Gb Free Space | 14.65% Space Free | Partition Type: NTFS
Computer Name: CCLAPTOP | User Name: Salim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Salim.CCLAPTOP\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\ESI\GIGA_HD\GIGAPan.exe (EGO SYS)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe ()
PRC - C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\FxSvr2.exe (Logitech Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files\DigitalPersona\Bin\DpHost.exe (DigitalPersona, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Dell\QuickSet\quickset.exe ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Dell\QuickSet\preflibcl.dll ()
MOD - C:\Program Files\Winamp\winampa.exe ()
========== Services (SafeList) ==========
SRV - (McciCMService) – C:\Program Files\Common Files\Motive\McciCMService.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (WLANKEEPER) – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHost.exe (DigitalPersona, Inc.)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (wanatw) – system32\DRIVERS\wanatw4.sys File not found
DRV - (USBAAPL) – System32\Drivers\usbaapl.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS File not found
DRV - (motmodem) – system32\DRIVERS\motmodem.sys File not found
DRV - (MotDev) – system32\DRIVERS\motodrv.sys File not found
DRV - (motccgpfl) – system32\DRIVERS\motccgpfl.sys File not found
DRV - (motccgp) – system32\DRIVERS\motccgp.sys File not found
DRV - (Micorsoft Windows Service) – C:\DOCUME~1\SALIM~1.CCL\LOCALS~1\Temp\dksojwwo.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (nmwcd) – C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (UsbserFilt) – C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\WINDOWS\system32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdnsu) – C:\WINDOWS\system32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdc) – C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (GIGAPORTHD_AA) – C:\WINDOWS\system32\drivers\GIGAdrv.sys ()
DRV - (GIGA_01) – C:\WINDOWS\system32\drivers\GIGAWdm.sys ()
DRV - (U3sHlpDr) – C:\WINDOWS\system32\drivers\U3sHlpDr.sys ()
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (APPDRV) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Audisvgramis) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (QCMerced) – C:\WINDOWS\system32\drivers\lvcm.sys ()
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (w29n51) – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (UsbdpFP) – C:\WINDOWS\system32\drivers\UsbdpFP.sys (DigitalPersona, Inc.)
DRV - (dpK00701) – C:\WINDOWS\system32\drivers\dpK00701.sys (DigitalPersona, Inc.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (IWCA) – C:\WINDOWS\system32\drivers\iwca.sys (Intel Corporation)
DRV - (Ser2pl) – C:\WINDOWS\system32\drivers\ser2pl.sys (Prolific Technology Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3072253
IE - HKCU\..\SearchScopes\{B3FC9D01-9D84-4CC8-B3B2-CE9B5ABDCA1D}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.5.109: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.5.109: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.5.109: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.5.109: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.5.109: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\@yverinfo.yahoo.com/YahooVersionInfoPlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYVerInfo.dll File not found
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\WINDOWS\cache\npyaxmpb.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{C3949AC2-4B17-43ee-B4F1-D26B9D42404D}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/07/09 11:22:03 | 000,000,000 | —D | M]
[2012/10/02 12:48:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Mozilla\Firefox\extensions
[2012/10/02 12:48:16 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2006/06/11 09:42:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2006/06/11 09:42:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2004/02/20 21:14:09 | 000,176,177 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2008/09/28 10:29:58 | 000,000,952 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - !{687578b9-7132-4a7a-80e4-30ee31099e03} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKCU..\Run: [VyuHjabc] C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\Salim.CCLAPTOP\Start Menu\Programs\Startup\GIGAPORT HD Control Panel.lnk = C:\Program Files\ESI\GIGA_HD\GIGAPan.exe (EGO SYS)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: motive.com ([pbttbc.bt] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…or/sw_promo.cab (Reg Error: Unable to open value key)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Reg Error: Unable to open value key)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Unable to open value key)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Unable to open value key)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Unable to open value key)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C098F866-0293-472D-B7A6-A7CF6DAD2E36}: NameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe) - C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\nsduyaul\vyuhjabc.exe File not found
O20 - Winlogon\Notify\IntelWireless: DllName - (C:\Program Files\Intel\Wireless\Bin\LgNotify.dll) - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - (TPSvc.dll) - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{d2936f38-744d-11de-83b4-00142291334c}\Shell - "" = AutoRun
O33 - MountPoints2\{d2936f38-744d-11de-83b4-00142291334c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d2936f38-744d-11de-83b4-00142291334c}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Unable to open value key File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/10/03 08:44:36 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\OTL.exe
[2012/10/02 12:49:38 | 000,000,000 | —D | C] – C:\ac672509a795966ad5b188094c
[2012/10/02 12:49:38 | 000,000,000 | —D | C] – C:\741650c739fe17d253a851c2c6
[2012/10/02 12:49:37 | 000,000,000 | —D | C] – C:\0daa56741bb7a7c546d6b3b689e5
[2012/10/02 12:49:31 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie7
[2012/10/02 12:48:53 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2012/10/02 12:48:53 | 000,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2012/10/02 12:48:53 | 000,000,000 | —D | C] – C:\WINDOWS\Connection Wizard
[2012/10/02 12:48:52 | 000,000,000 | —D | C] – C:\WINDOWS\twain_32
[2012/10/02 12:48:49 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/10/02 12:48:45 | 000,000,000 | —D | C] – C:\Program Files\Viewpoint
[2012/10/02 12:48:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/10/02 12:48:44 | 000,000,000 | —D | C] – C:\Program Files\Windows Installer Clean Up
[2012/10/02 12:48:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Sonic
[2012/10/02 12:48:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Motorola
[2012/10/02 12:48:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Apple Computer
[2012/10/02 12:48:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\AOL
[2012/10/02 12:48:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\You've Got Pictures Screensaver
[2012/10/02 12:48:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Yahoo!
[2012/10/02 12:48:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\searchquband
[2012/10/02 12:48:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\TuneUp Software
[2012/10/02 12:48:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Tanagra
[2012/10/02 12:48:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Mozilla
[2012/10/02 12:48:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Malwarebytes
[2012/10/02 12:48:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Gtek
[2012/09/06 17:34:41 | 000,157,448 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/09/06 17:34:41 | 000,149,256 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/09/06 17:34:41 | 000,149,256 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/11/03 17:32:24 | 000,457,054 | —- | C] (Winmxconex ) – C:\Program Files\Winmx_3.54.exe
[2007/07/19 18:56:23 | 000,092,064 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmmdm.sys
[2007/07/19 18:56:23 | 000,079,328 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmserd.sys
[2007/07/19 18:56:23 | 000,066,656 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmbus.sys
[2007/07/19 18:56:23 | 000,009,232 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmmdfl.sys
[2007/07/19 18:56:23 | 000,006,208 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmcmnt.sys
[2007/07/19 18:56:23 | 000,005,936 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmwhnt.sys
[2007/07/19 18:56:23 | 000,004,048 | —- | C] (MCCI) – C:\Documents and Settings\Salim.CCLAPTOP\mqdmcr.sys
[2007/07/19 18:46:34 | 000,024,192 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Salim.CCLAPTOP\usbsermptxp.sys
[2007/07/19 18:46:34 | 000,022,768 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Salim.CCLAPTOP\usbsermpt.sys
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/03 08:44:37 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\OTL.exe
[2012/10/03 08:36:01 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1975611791-2844101239-1228591925-1011.job
[2012/10/03 08:35:00 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/03 08:34:19 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2012/10/03 08:33:28 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/03 08:33:27 | 527,892,480 | -HS- | M] () – C:\hiberfil.sys
[2012/10/02 16:31:17 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/02 13:31:35 | 000,696,240 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/02 13:31:35 | 000,073,136 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/10/01 20:35:54 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\ReclaimerResumeInstall_Salim.job
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/01 20:35:52 | 000,000,428 | —- | C] () – C:\WINDOWS\tasks\ReclaimerResumeInstall_Salim.job
[2012/08/03 10:10:21 | 000,093,644 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\ms.exe
[2012/04/30 18:57:13 | 000,551,070 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1975611791-2844101239-1228591925-1011-0.dat
[2012/04/30 18:57:04 | 000,259,550 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/03/28 22:11:06 | 000,974,848 | —- | C] () – C:\WINDOWS\System32\cis-2.4.dll
[2012/03/28 22:11:06 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2012/03/28 22:11:06 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2012/03/28 22:11:06 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\issacapi_se-2.3.dll
[2012/02/16 06:56:18 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/06/07 12:41:14 | 000,012,860 | -HS- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\2tont435w72033v0e7808tcv1dex245
[2011/06/07 12:41:14 | 000,012,860 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2tont435w72033v0e7808tcv1dex245
[2011/04/19 12:14:50 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/02/22 08:59:12 | 000,016,026 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289552-oem50.PNF
[2009/02/22 08:59:12 | 000,009,913 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289552-oem50.inf
[2009/02/22 08:59:11 | 000,015,706 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289551-oem47.PNF
[2009/02/22 08:59:11 | 000,012,444 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289551-oem46.PNF
[2009/02/22 08:59:11 | 000,009,232 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289551-oem47.inf
[2009/02/22 08:59:11 | 000,005,960 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289551-oem46.inf
[2009/02/22 08:59:10 | 000,012,852 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289550-oem40.PNF
[2009/02/22 08:59:10 | 000,012,818 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289550-oem41.PNF
[2009/02/22 08:59:10 | 000,006,141 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289550-oem41.inf
[2009/02/22 08:59:10 | 000,005,880 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289550-oem40.inf
[2009/02/22 08:59:09 | 000,014,358 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289548-oem37.PNF
[2009/02/22 08:59:09 | 000,007,201 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1235289548-oem37.inf
[2007/09/26 22:22:10 | 006,548,309 | —- | C] () – C:\Documents and Settings\All Users\B.T. Express - That's What I Want For You Baby.mp3
[2007/07/19 18:56:23 | 000,015,706 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem47.PNF
[2007/07/19 18:56:23 | 000,014,022 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem37.PNF
[2007/07/19 18:56:23 | 000,012,844 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem40.PNF
[2007/07/19 18:56:23 | 000,012,706 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem41.PNF
[2007/07/19 18:56:23 | 000,012,372 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem46.PNF
[2007/07/19 18:56:23 | 000,009,913 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\MCCI_MDM.INF
[2007/07/19 18:56:23 | 000,009,232 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem47.inf
[2007/07/19 18:56:23 | 000,006,989 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\MCCI_BUS.INF
[2007/07/19 18:56:23 | 000,006,947 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867783-(null)
[2007/07/19 18:56:23 | 000,006,009 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem41.inf
[2007/07/19 18:56:23 | 000,005,877 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem40.inf
[2007/07/19 18:56:23 | 000,005,813 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Copy of oem46.inf
[2007/07/19 18:56:23 | 000,004,477 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\MCCI_SDM.INF
[2007/07/19 18:55:27 | 000,009,232 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\USB_MOT_BRIT.INF
[2007/07/19 18:55:27 | 000,005,960 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\USB_MOT_A1000.INF
[2007/07/19 18:55:26 | 000,012,570 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867726-oem41.PNF
[2007/07/19 18:55:26 | 000,005,891 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867726-oem41.inf
[2007/07/19 18:55:25 | 000,014,318 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867725-oem37.PNF
[2007/07/19 18:55:25 | 000,012,844 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867725-oem40.PNF
[2007/07/19 18:55:25 | 000,007,195 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867725-oem37.inf
[2007/07/19 18:55:25 | 000,005,877 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867725-oem40.inf
[2007/07/19 18:46:34 | 000,007,195 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\USBMOT2000.INF
[2007/07/19 18:46:34 | 000,005,891 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\USBMOT2000XP.INF
[2007/07/19 18:46:34 | 000,005,877 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\USB_CMCS_2000.INF
[2007/07/19 18:45:58 | 000,064,954 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867157-oem37.PNF
[2007/07/19 18:45:58 | 000,048,144 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\1184867157-oem37.inf
[2006/12/17 12:12:46 | 000,020,480 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/12 23:17:48 | 000,066,730 | —- | C] () – C:\Program Files\2nd half.htm
[2006/12/12 20:52:38 | 002,658,841 | —- | C] () – C:\Program Files\burst-3.1.0b.exe
[2006/12/10 09:16:39 | 000,023,374 | —- | C] () – C:\Program Files\ViewpointKiller.zip
[2006/10/03 21:11:28 | 000,000,846 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Updater.ini
[2006/05/14 02:59:02 | 000,000,137 | —- | C] () – C:\Documents and Settings\Salim.CCLAPTOP\Local Settings\Application Data\fusioncache.dat
[2006/01/26 04:44:03 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
========== ZeroAccess Check ==========
[2004/08/11 18:21:56 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2009/04/29 05:46:52 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 13:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 01:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2007/05/22 22:14:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2007/05/22 22:16:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2012/04/30 13:14:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2010/08/03 11:11:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2012/04/30 13:32:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2012/08/13 13:56:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/05/19 10:52:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2007/10/08 22:45:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tanagra
[2012/01/14 19:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2012/10/02 12:48:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/01/14 18:20:06 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012/03/24 16:26:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/14 13:43:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/10 11:48:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/06/13 09:22:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Amazon
[2006/04/17 14:24:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Leadertech
[2012/10/02 12:48:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Motorola
[2006/10/16 19:36:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\MSNInstaller
[2010/08/03 11:11:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\NCH Swift Sound
[2012/04/30 13:32:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Nokia
[2012/04/30 13:32:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\PC Suite
[2012/04/30 15:34:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Samsung
[2012/10/02 12:48:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\searchquband
[2012/10/02 12:48:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Tanagra
[2012/05/01 19:35:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Temp
[2012/10/02 12:48:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\TuneUp Software
[2012/10/02 12:50:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\uTorrent
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EX_ >
[2004/08/04 06:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\i386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 12:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/10/02 12:55:42 | 000,049,934 | —- | M] () MD5=8F4CDD98BB6331D34A9651220261D1A6 – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf
< MD5 for: EXPLORER.SC_ >
[2004/08/04 06:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2004/08/04 06:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EX_ >
[2004/08/04 06:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\i386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2009/06/29 08:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2009/04/25 06:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2009/04/25 06:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\SoftwareDistribution\Download\803badc49670f68514bc104c4297fe82\SP3GDR\iexplore.exe
[2009/08/27 06:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2009/06/29 09:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2009/10/28 07:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 14:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2008/04/14 01:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2008/04/14 01:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2009/10/28 07:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2010/02/23 06:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie8\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/04/25 06:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2009/04/25 06:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\SoftwareDistribution\Download\803badc49670f68514bc104c4297fe82\SP3QFE\iexplore.exe
[2010/02/23 06:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2009/12/18 08:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2009/08/27 06:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/10/03 08:36:19 | 000,089,968 | —- | M] () MD5=635ED2F1D5581A30478C50513D626A9B – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/04 06:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/04 06:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.EXE >
[2009/02/06 12:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 01:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 12:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
< MD5 for: SERVICES.LNK >
[2012/01/14 18:35:08 | 000,001,602 | —- | M] () MD5=D009F33D20281A74346CE5033DCEE6A5 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MOCHIADS.COM.SOL >
[2012/04/21 15:27:02 | 000,000,351 | —- | M] () MD5=058919773E86AD96071EC3619653B22E – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Macromedia\Flash Player\#SharedObjects\9XHZEBRR\mochiads.com\services.mochiads.com.sol
< MD5 for: SERVICES.MSC >
[2004/08/04 06:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: WINLOGON.EXE >
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 01:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2004/08/11 18:15:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/11/02 23:14:47 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2004/08/11 18:15:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/07/19 18:53:54 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2006/01/26 04:20:38 | 000,005,184 | RH– | M] () – C:\dell.sdr
[2012/10/03 08:33:27 | 527,892,480 | -HS- | M] () – C:\hiberfil.sys
[2006/01/31 21:48:23 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/11 18:15:00 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/01/26 04:52:00 | 000,000,893 | -H– | M] () – C:\IPH.PH
[2006/09/16 16:52:14 | 000,000,062 | —- | M] () – C:\MMCD.INI
[2004/08/11 18:15:00 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/06/26 12:33:05 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/10/03 08:33:17 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2006/09/16 16:52:20 | 000,000,207 | —- | M] () – C:\RECache.idx
[2006/04/17 08:33:33 | 000,000,441 | —- | M] () – C:\Shortcut to My Documents.lnk
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/11 18:14:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/10 14:02:32 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/08/03 19:05:28 | 000,001,674 | -H– | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2006/12/12 23:17:49 | 000,066,730 | —- | M] () – C:\Program Files\2nd half.htm
[2006/12/12 20:52:44 | 002,658,841 | —- | M] () – C:\Program Files\burst-3.1.0b.exe
[2006/12/10 09:16:40 | 000,023,374 | —- | M] () – C:\Program Files\ViewpointKiller.zip
[2009/11/03 17:32:27 | 000,457,054 | —- | M] (Winmxconex ) – C:\Program Files\Winmx_3.54.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/11 18:06:14 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/11 18:06:14 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/11 18:06:14 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/06/26 12:46:30 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/06/26 13:08:22 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/11 18:20:42 | 000,000,079 | —- | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2006/12/29 16:50:00 | 000,380,928 | —- | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\Darkman_TMLoader_187.exe
[2012/05/03 17:55:35 | 008,577,640 | —- | M] (Motorola) – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\MotoHelper_2.1.40_Driver_5.5.0.exe
[2012/05/03 19:48:03 | 025,732,000 | —- | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\Motorola_Software_Update.exe
[2012/04/30 13:13:55 | 067,525,120 | —- | M] () – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\Nokia_PC_Suite_ALL.exe
[2012/10/03 08:44:37 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Salim.CCLAPTOP\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-11 06:37:07
< End of report >