Hello OCD,
Here are the results of the OTL scan.
Thanks,
Beatles4Life
OTL logfile created on: 16/10/2013 00:41:52 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\I K\Desktop\HSG_wtt
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1023.23 Mb Total Physical Memory | 387.95 Mb Available Physical Memory | 37.91% Memory free
2.40 Gb Paging File | 1.88 Gb Available in Paging File | 78.04% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 139.85 Gb Total Space | 102.20 Gb Free Space | 73.08% Space Free | Partition Type: FAT32
Drive D: | 92.97 Gb Total Space | 92.97 Gb Free Space | 99.99% Space Free | Partition Type: FAT32
Computer Name: YOUR-EB98910CC7 | User Name: I K | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\I K\Desktop\HSG_wtt\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Documents and Settings\All Users\Application Data\RHelpers\IeHelper\IeHelper.exe (WatchDog)
PRC - C:\Documents and Settings\All Users\Application Data\RHelpers\FirefoxHelper\FirefoxHelper.exe (WatchDog)
PRC - C:\Documents and Settings\All Users\Application Data\RHelpers\ChromeHelper\ChromeHelper.exe (WatchDog)
PRC - C:\Documents and Settings\All Users\Application Data\Updater\updater.exe (Updater)
PRC - C:\Documents and Settings\All Users\Application Data\Search Protection\SearchProtection.exe (Lavasoft)
PRC - C:\Documents and Settings\I K\Local Settings\Application Data\Updater32912\Updater32912.exe (Innovative Apps)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAService.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Program Files\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)
PRC - C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - c:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE (Infineon Technologies AG)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Intel\Wireless\Bin\Libeay32.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()
========== Services (SafeList) ==========
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (PSUAService) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAService.exe (Panda Security, S.L.)
SRV - (NanoServiceMain) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (PACSPTISVR-Sound_Organizer) – C:\Program Files\Sony\Sound Organizer\Sony.Earth\PACSPTISVR.exe (Sony Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (PersonalSecureDriveService) – c:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE (Infineon Technologies AG)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (bdftdif) – C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdftdif.sys File not found
DRV - (Bdfndisf) – C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfndisf.sys File not found
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (NNSHTTPS) – C:\WINDOWS\system32\drivers\NNSHttps.sys (Panda Security, S.L.)
DRV - (NNSSTRM) – C:\WINDOWS\system32\drivers\NNSStrm.sys (Panda Security, S.L.)
DRV - (NNSSMTP) – C:\WINDOWS\system32\drivers\NNSSmtp.sys (Panda Security, S.L.)
DRV - (NNSTLSC) – C:\WINDOWS\system32\drivers\NNStlsc.sys (Panda Security, S.L.)
DRV - (NNSPROT) – C:\WINDOWS\system32\drivers\NNSProt.sys (Panda Security, S.L.)
DRV - (NNSPRV) – C:\WINDOWS\system32\drivers\NNSPrv.sys (Panda Security, S.L.)
DRV - (NNSPOP3) – C:\WINDOWS\system32\drivers\NNSPop3.sys (Panda Security, S.L.)
DRV - (NNSIDS) – C:\WINDOWS\system32\drivers\NNSIds.sys (Panda Security, S.L.)
DRV - (NNSHTTP) – C:\WINDOWS\system32\drivers\NNSHttp.sys (Panda Security, S.L.)
DRV - (NNSPICC) – C:\WINDOWS\system32\drivers\NNSpicc.sys (Panda Security, S.L.)
DRV - (NNSPIHS) – C:\WINDOWS\system32\drivers\NNSpihs.sys (Panda Security, S.L.)
DRV - (NNSALPC) – C:\WINDOWS\system32\drivers\NNSAlpc.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\WINDOWS\system32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (PSINProt) – C:\WINDOWS\system32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINProc) – C:\WINDOWS\system32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINAflt) – C:\WINDOWS\system32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\WINDOWS\system32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (PSKMAD) – C:\WINDOWS\system32\drivers\PSKMAD.sys (Panda Security, S.L.)
DRV - (NNSNAHS) – C:\WINDOWS\system32\drivers\NNSNAHS.sys (Panda Security, S.L.)
DRV - (ssadbus) – C:\WINDOWS\system32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (SNP2STD) – C:\WINDOWS\system32\drivers\snp2sxp.sys ()
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (w39n51) – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (PersonalSecureDrive) – C:\WINDOWS\system32\drivers\psd.sys (Infineon Technologies AG)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (IFXTPM) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTSLBCSP) – C:\WINDOWS\system32\drivers\btslbcsp.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ATKACPI.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.msn.com/?ocid=OIE8HP&PC;=B8DF
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securedsearch2.lavasoft.com/index.p…69739525988D799
IE - HKCU\..\URLSearchHook: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" =
http://securedsearch2.lavasoft.com/results…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.co.uk"
FF - prefs.js..extensions.enabledAddons: %7B87934c42-161d-45bc-8cef-ef18abe2a30c%7D:3.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:24.0
FF - prefs.js..keyword.URL: "
http://securedsearch2.lavasoft.com/results.php?pr=vmn&id;=adawaretb&v;=3_5&idate;=__installtime__&hsimp;=yhs-lavasoft&ent;=bs&q;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/02/14 22:53:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\I K\Application Data\Mozilla\Extensions
[2012/02/20 20:09:30 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\I K\Application Data\Mozilla\Firefox\Profiles\zeijqalt.default\extensions
[2013/10/12 18:37:34 | 000,000,000 | —D | M] (Ad-Aware Security Add-on) – C:\Documents and Settings\I K\Application Data\Mozilla\Firefox\Profiles\zeijqalt.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
[2013/10/13 19:10:50 | 000,000,000 | —D | M] (Spy Alert) – C:\Documents and Settings\I K\Application Data\Mozilla\Firefox\Profiles\zeijqalt.default\extensions\[removed]
[2013/10/11 21:34:24 | 000,915,554 | —- | M] () (No name found) – C:\Documents and Settings\I K\Application Data\Mozilla\Firefox\Profiles\zeijqalt.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/10/13 17:24:50 | 000,487,348 | —- | M] () (No name found) – C:\Documents and Settings\I K\Application Data\Mozilla\Firefox\Profiles\zeijqalt.default\extensions\[removed]
[2013/10/01 21:58:54 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/10/01 21:58:54 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2012/02/15 20:01:58 | 000,441,696 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 15182 more lines…
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
O2 - BHO: (Searchcore Toolbar) - {af6ac4f2-9825-4fb6-a600-92bc5361f209} - C:\Program Files\Searchcore Toolbar\Datamngr\ToolBar\searchcoredtx.dll ()
O3 - HKLM\..\Toolbar: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (Searchcore Toolbar) - {af6ac4f2-9825-4fb6-a600-92bc5361f209} - C:\Program Files\Searchcore Toolbar\Datamngr\ToolBar\searchcoredtx.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PSUAMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [Search Protection] C:\Documents and Settings\All Users\Application Data\Search Protection\SearchProtection.exe (Lavasoft)
O4 - HKLM..\Run: [Updater] C:\Documents and Settings\All Users\Application Data\Updater\updater.exe (Updater)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Updater] C:\Documents and Settings\All Users\Application Data\Updater\updater.exe (Updater)
O4 - HKCU..\Run: [Updater32912.exe] C:\Documents and Settings\I K\Local Settings\Application Data\Updater32912\Updater32912.exe (Innovative Apps)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Send To &Bluetooth; - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A44DD6C6-363E-49FD-A167-F7C7AC810A96}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\I K\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\I K\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/08/08 19:01:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
R\QUICK LAUNCH\*.LNK /X
%USERPROFILE%\DESKTOP\*.EXE
%PROGRAMFILES%\COMMON FILES\*.*
%SYSTEMROOT%\*.SRC
%SYSTEMROOT%\INSTALL\*.*
%SYSTEMROOT%\SYSTEM32\DLL\*.*
%SYSTEMROOT%\SYSTEM32\HELPFILES\*.*
%SYSTEMROOT%\SYSTEM32\RUNDLL\*.*
%SYSTEMROOT%\WINN32\*.*
%SYSTEMROOT%\JAVA\*.*
%SYSTEMROOT%\SYSTEM32\TEST\*.*
%SYSTEMROOT%\SYSTEM32\RUNDLL32\*.*
%SYSTEMROOT%\APPPATCH\CUSTOM\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\POLICIES\MICROSOFT\WINDOWS\WINDOWSUPDATE\AU
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\WINDOWSUPDATE\AUTO UPDATE\RESULTS\INSTALL|LASTSUCCESSTIME /RS
BASESERVICES
DRIVES
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/10/14 21:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\I K\Desktop\HSG_wtt
[2013/10/13 19:10:05 | 000,046,672 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\PSKMAD.sys
[2013/10/13 18:46:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SpyAlert
[2013/10/13 18:33:53 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2013/10/13 17:27:35 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\COMODO
[2013/10/13 17:24:46 | 000,000,000 | —D | C] – C:\Program Files\AdTrustMedia
[2013/10/13 17:24:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adtrustmedia
[2013/10/13 17:24:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\COMODO
[2013/10/13 17:22:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Comodo
[2013/10/13 17:22:06 | 000,000,000 | —D | C] – C:\Documents and Settings\I K\Local Settings\Application Data\COMODO
[2013/10/12 22:40:02 | 000,000,000 | —D | C] – C:\Avenger
[2013/10/12 19:57:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/10/12 19:57:05 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2013/10/12 19:57:05 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/10/12 19:14:47 | 000,000,000 | —D | C] – C:\Documents and Settings\I K\Application Data\LavasoftStatistics
[2013/10/12 19:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\BitDefender
[2013/10/12 18:38:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Search Protection
[2013/10/12 18:38:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2013/10/12 18:38:13 | 000,000,000 | —D | C] – C:\Documents and Settings\I K\Local Settings\Application Data\adawarebp
[2013/10/12 18:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection
[2013/10/12 18:37:51 | 000,000,000 | —D | C] – C:\Program Files\Toolbar Cleaner
[2013/10/12 18:37:29 | 000,000,000 | —D | C] – C:\Documents and Settings\I K\Application Data\adawaretb
[2013/10/12 18:37:27 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2013/10/12 18:33:38 | 000,000,000 | —D | C] – C:\Documents and Settings\I K\Desktop\For HSG's lappy
[2013/10/11 23:13:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2013/10/11 23:10:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2013/10/11 23:00:58 | 000,000,000 | -HSD | C] – C:\FOUND.001
[2013/10/10 13:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RHelpers
[2013/10/10 13:47:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Updater
[2013/10/10 09:51:30 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidparse.sys
[2013/10/10 09:51:30 | 000,014,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2013/10/10 09:51:29 | 000,123,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbvideo.sys
[2013/10/10 09:51:29 | 000,060,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2013/10/10 09:50:23 | 000,144,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbport.sys
[2013/10/10 09:50:23 | 000,032,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/10/10 09:50:23 | 000,030,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbehci.sys
[2013/10/10 09:50:23 | 000,005,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbd.sys
[2013/10/01 21:58:50 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[2 C:\Documents and Settings\I K\Desktop\*.tmp files -> C:\Documents and Settings\I K\Desktop\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/10/16 00:40:00 | 000,000,162 | -H– | M] () – C:\Documents and Settings\I K\Desktop\~$l_text_to_paste.rtf
[2013/10/16 00:32:30 | 000,033,099 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2013/10/16 00:32:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/10/16 00:31:56 | 1073,008,640 | -HS- | M] () – C:\hiberfil.sys
[2013/10/16 00:18:38 | 002,397,045 | —- | M] () – C:\WINDOWS\TempCloudAV1015123901_604.csv
[2013/10/15 23:56:02 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/10/15 13:45:20 | 000,000,513 | —- | M] () – C:\Documents and Settings\I K\Desktop\MBR.zip
[2013/10/14 23:36:52 | 000,000,512 | —- | M] () – C:\Documents and Settings\I K\Desktop\MBR.dat
[2013/10/14 22:26:14 | 000,125,054 | —- | M] () – C:\WINDOWS\TempCloudAV1013181002_400.csv
[2013/10/14 21:57:58 | 000,003,323 | —- | M] () – C:\Documents and Settings\I K\Desktop\otl_text_to_paste.rtf
[2013/10/13 19:04:24 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2013/10/13 18:19:44 | 001,260,332 | —- | M] () – C:\WINDOWS\TempCloudAV1013165553_820.csv
[2013/10/12 22:52:14 | 000,249,484 | —- | M] () – C:\WINDOWS\TempCloudAV1012214423_396.csv
[2013/10/12 19:57:18 | 000,000,688 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/10/12 19:15:20 | 000,088,698 | —- | M] () – C:\WINDOWS\TempCloudAV1011231939_1884.csv
[2013/10/12 00:13:14 | 000,002,150 | —- | M] () – C:\WINDOWS\wininit.ini
[2013/10/11 23:13:46 | 000,000,855 | —- | M] () – C:\Documents and Settings\I K\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2013/10/11 23:13:46 | 000,000,837 | —- | M] () – C:\Documents and Settings\I K\Desktop\Spybot - Search & Destroy.lnk
[2013/10/11 21:37:24 | 001,165,278 | —- | M] () – C:\WINDOWS\TempCloudAV1011192334_1316.csv
[2013/10/11 20:23:02 | 003,540,096 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/10/11 20:22:54 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/10/10 14:39:50 | 003,334,126 | —- | M] () – C:\WINDOWS\TempCloudAV1010084657_1228.csv
[2013/10/10 14:38:02 | 000,506,238 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/10/10 14:38:02 | 000,089,536 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/10/10 14:33:52 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/10/08 18:58:22 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/10/08 18:58:20 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/10/07 17:30:20 | 001,038,843 | —- | M] () – C:\WINDOWS\TempCloudAV1007142727_568.csv
[2013/10/06 22:47:22 | 000,457,278 | —- | M] () – C:\WINDOWS\TempCloudAV1006182720_944.csv
[2013/10/06 01:21:24 | 001,263,034 | —- | M] () – C:\WINDOWS\TempCloudAV1005135905_660.csv
[2013/10/03 18:37:10 | 001,629,999 | —- | M] () – C:\WINDOWS\TempCloudAV1003135147_872.csv
[2013/10/01 23:07:44 | 001,558,472 | —- | M] () – C:\WINDOWS\TempCloudAV1001191628_900.csv
[2013/10/01 20:15:02 | 000,038,543 | —- | M] () – C:\WINDOWS\TempCloudAV1001191122_972.csv
[2013/09/29 04:25:08 | 000,561,199 | —- | M] () – C:\WINDOWS\TempCloudAV0928105939_1192.csv
[2013/09/29 02:00:02 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-YOUR-EB98910CC7-I K.job
[2013/09/28 00:02:38 | 001,394,079 | —- | M] () – C:\WINDOWS\TempCloudAV0927131145_868.csv
[2013/09/27 09:49:06 | 000,583,185 | —- | M] () – C:\WINDOWS\TempCloudAV0927083429_1460.csv
[2013/09/26 19:24:58 | 000,874,278 | —- | M] () – C:\WINDOWS\TempCloudAV0926171501_1360.csv
[2013/09/24 22:44:10 | 000,607,427 | —- | M] () – C:\WINDOWS\TempCloudAV0924152019_672.csv
[2013/09/24 11:41:04 | 000,626,536 | —- | M] () – C:\WINDOWS\TempCloudAV0924102808_424.csv
[2013/09/23 23:36:50 | 000,174,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2013/09/23 23:36:50 | 000,174,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2013/09/23 19:33:58 | 011,113,472 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2013/09/23 19:33:58 | 006,017,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2013/09/23 19:33:58 | 002,006,016 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2013/09/23 19:33:58 | 001,469,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2013/09/23 19:33:58 | 001,469,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2013/09/23 19:33:58 | 001,215,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2013/09/23 19:33:58 | 000,920,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2013/09/23 19:33:58 | 000,759,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vgx.dll
[2013/09/23 19:33:58 | 000,630,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2013/09/23 19:33:58 | 000,630,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2013/09/23 19:33:58 | 000,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2013/09/23 19:33:58 | 000,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2013/09/23 19:33:58 | 000,522,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/09/23 19:33:58 | 000,206,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2013/09/23 19:33:58 | 000,184,320 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2013/09/23 19:33:58 | 000,184,320 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2013/09/23 19:33:58 | 000,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2013/09/23 19:33:58 | 000,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2013/09/23 19:33:58 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2013/09/23 19:33:58 | 000,055,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2013/09/23 19:33:58 | 000,055,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2013/09/23 19:33:58 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2013/09/23 19:33:58 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2013/09/23 19:33:58 | 000,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2013/09/23 19:33:58 | 000,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2013/09/23 19:33:56 | 000,743,424 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2013/09/23 19:33:56 | 000,387,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2013/09/23 19:33:56 | 000,387,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2013/09/23 19:33:56 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2013/09/23 19:33:56 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2013/09/23 19:06:48 | 000,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2013/09/22 14:53:14 | 000,087,422 | —- | M] () – C:\WINDOWS\TempCloudAV0922130405_772.csv
[2013/09/21 21:46:50 | 000,505,915 | —- | M] () – C:\WINDOWS\TempCloudAV0921190244_660.csv
[2013/09/21 20:01:56 | 000,006,784 | —- | M] () – C:\Documents and Settings\All Users\Application Data\NanoRepository.bin
[2013/09/21 20:01:36 | 000,151,030 | —- | M] () – C:\WINDOWS\TempCloudAV0921175619_564.csv
[2013/09/18 21:07:52 | 001,042,247 | —- | M] () – C:\WINDOWS\TempCloudAV0918173224_660.csv
[2013/09/18 09:00:20 | 000,285,066 | —- | M] () – C:\WINDOWS\TempCloudAV0918072852_428.csv
[2013/09/17 09:44:00 | 000,496,583 | —- | M] () – C:\WINDOWS\TempCloudAV0916175442_280.csv
[2013/09/16 18:50:30 | 000,244,849 | —- | M] () – C:\WINDOWS\TempCloudAV0916172713_768.csv
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[2 C:\Documents and Settings\I K\Desktop\*.tmp files -> C:\Documents and Settings\I K\Desktop\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/10/16 00:40:00 | 000,000,162 | -H– | C] () – C:\Documents and Settings\I \Desktop\~$l_text_to_paste.rtf
[2013/10/16 00:37:02 | 000,003,323 | —- | C] () – C:\Documents and Settings\I K\Desktop\otl_text_to_paste.rtf
[2013/10/15 13:45:18 | 000,000,513 | —- | C] () – C:\Documents and Settings\I K\Desktop\MBR.zip
[2013/10/15 13:39:35 | 002,397,045 | —- | C] () – C:\WINDOWS\TempCloudAV1015123901_604.csv
[2013/10/14 23:36:47 | 000,000,512 | —- | C] () – C:\Documents and Settings\I K\Desktop\MBR.dat
[2013/10/14 21:58:33 | 000,125,054 | —- | C] () – C:\WINDOWS\TempCloudAV1013181002_400.csv
[2013/10/13 17:56:29 | 001,260,332 | —- | C] () – C:\WINDOWS\TempCloudAV1013165553_820.csv
[2013/10/12 22:44:39 | 000,249,484 | —- | C] () – C:\WINDOWS\TempCloudAV1012214423_396.csv
[2013/10/12 19:57:16 | 000,000,688 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/10/12 18:32:41 | 000,088,698 | —- | C] () – C:\WINDOWS\TempCloudAV1011231939_1884.csv
[2013/10/12 00:19:01 | 1073,008,640 | -HS- | C] () – C:\hiberfil.sys
[2013/10/11 23:13:45 | 000,000,855 | —- | C] () – C:\Documents and Settings\I K\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2013/10/11 23:13:45 | 000,000,837 | —- | C] () – C:\Documents and Settings\I K\Desktop\Spybot - Search & Destroy.lnk
[2013/10/11 20:33:10 | 001,165,278 | —- | C] () – C:\WINDOWS\TempCloudAV1011192334_1316.csv
[2013/10/10 09:47:10 | 003,334,126 | —- | C] () – C:\WINDOWS\TempCloudAV1010084657_1228.csv
[2013/10/07 15:27:45 | 001,038,843 | —- | C] () – C:\WINDOWS\TempCloudAV1007142727_568.csv
[2013/10/06 19:27:34 | 000,457,278 | —- | C] () – C:\WINDOWS\TempCloudAV1006182720_944.csv
[2013/10/05 14:59:19 | 001,263,034 | —- | C] () – C:\WINDOWS\TempCloudAV1005135905_660.csv
[2013/10/03 14:52:04 | 001,629,999 | —- | C] () – C:\WINDOWS\TempCloudAV1003135147_872.csv
[2013/10/01 20:16:46 | 001,558,472 | —- | C] () – C:\WINDOWS\TempCloudAV1001191628_900.csv
[2013/10/01 20:11:43 | 000,038,543 | —- | C] () – C:\WINDOWS\TempCloudAV1001191122_972.csv
[2013/09/28 11:59:53 | 000,561,199 | —- | C] () – C:\WINDOWS\TempCloudAV0928105939_1192.csv
[2013/09/27 14:12:02 | 001,394,079 | —- | C] () – C:\WINDOWS\TempCloudAV0927131145_868.csv
[2013/09/27 09:34:43 | 000,583,185 | —- | C] () – C:\WINDOWS\TempCloudAV0927083429_1460.csv
[2013/09/26 18:15:22 | 000,874,278 | —- | C] () – C:\WINDOWS\TempCloudAV0926171501_1360.csv
[2013/09/24 16:28:00 | 000,607,427 | —- | C] () – C:\WINDOWS\TempCloudAV0924152019_672.csv
[2013/09/24 11:28:24 | 000,626,536 | —- | C] () – C:\WINDOWS\TempCloudAV0924102808_424.csv
[2013/09/22 14:25:44 | 000,087,422 | —- | C] () – C:\WINDOWS\TempCloudAV0922130405_772.csv
[2013/09/21 20:03:00 | 000,505,915 | —- | C] () – C:\WINDOWS\TempCloudAV0921190244_660.csv
[2013/09/21 20:01:55 | 000,006,784 | —- | C] () – C:\Documents and Settings\All Users\Application Data\NanoRepository.bin
[2013/09/21 19:20:40 | 000,151,030 | —- | C] () – C:\WINDOWS\TempCloudAV0921175619_564.csv
[2013/09/19 19:05:52 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/09/18 18:32:39 | 001,042,247 | —- | C] () – C:\WINDOWS\TempCloudAV0918173224_660.csv
[2013/09/18 08:29:11 | 000,285,066 | —- | C] () – C:\WINDOWS\TempCloudAV0918072852_428.csv
[2013/09/16 18:55:06 | 000,496,583 | —- | C] () – C:\WINDOWS\TempCloudAV0916175442_280.csv
[2013/09/16 18:27:31 | 000,244,849 | —- | C] () – C:\WINDOWS\TempCloudAV0916172713_768.csv
[2013/09/03 20:12:30 | 000,079,360 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2013/05/24 20:00:21 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\0x0304A000.sfl
[2012/03/14 22:39:49 | 000,002,150 | —- | C] () – C:\WINDOWS\wininit.ini
[2012/02/17 22:54:10 | 000,031,232 | —- | C] () – C:\Documents and Settings\I K\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/14 21:53:37 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/17 18:55:17 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2012/01/17 18:55:17 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2012/01/17 18:55:08 | 000,002,528 | —- | C] () – C:\Documents and Settings\I K\Application Data\$_hpcst$.hpc
[2012/01/17 18:53:07 | 000,069,632 | —- | C] () – C:\Program Files\2057.MST
[2012/01/17 18:53:07 | 000,013,752 | —- | C] () – C:\Program Files\0x0809.ini
[2012/01/17 18:53:02 | 097,979,392 | —- | C] () – C:\Program Files\Samsung New PC Studio.msi
[2011/08/15 17:31:51 | 000,000,130 | —- | C] () – C:\Documents and Settings\I K\Local Settings\Application Data\fusioncache.dat
[2011/08/14 17:55:39 | 000,001,456 | —- | C] () – C:\Documents and Settings\I K\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
========== ZeroAccess Check ==========
[2011/08/14 14:56:48 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2011/11/01 20:35:20 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 13:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 01:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/08/08 19:26:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Infineon
[2011/08/12 17:35:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2012/01/17 22:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2012/01/22 17:01:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HardwareHelper
[2012/02/25 12:42:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2013/05/06 16:36:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2013/05/06 16:36:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2013/05/06 16:43:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2013
[2013/05/06 17:30:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2013/05/28 15:01:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2013/05/28 15:03:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BrowserProtect
[2013/10/10 13:47:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Updater
[2013/10/10 13:47:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RHelpers
[2013/10/12 18:38:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection
[2013/10/12 18:38:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2013/10/12 18:38:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Search Protection
[2013/10/12 19:03:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BitDefender
[2013/10/13 17:24:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adtrustmedia
[2013/10/13 18:46:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpyAlert
[2011/08/08 19:26:04 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\Infineon
[2011/08/22 14:57:56 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/09/30 19:14:22 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/01/17 18:55:06 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\Samsung
[2012/01/17 22:06:26 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\PC Suite
[2012/01/22 15:52:28 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\ElevatedDiagnostics
[2012/01/22 16:48:38 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\searchcoretoolbar
[2012/02/20 20:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\searchcoreband
[2012/02/23 21:04:10 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\Opera
[2013/01/16 12:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\ICAClient
[2013/05/06 17:33:50 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\Panda Security
[2013/05/28 15:13:22 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\player
[2013/08/08 22:47:40 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2013/08/10 15:34:10 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\BBCiPlayerDesktop
[2013/09/03 20:11:34 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\SeeSimilar02
[2013/09/03 20:12:50 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\PerformerSoft
[2013/10/12 18:37:30 | 000,000,000 | —D | M] – C:\Documents and Settings\I K\Application Data\adawaretb
========== Purity Check ==========
< End of report >