Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4076
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
5/8/2010 1:27:43 PM
mbam-log-2010-05-08 (13-27-43).txt
Scan type: Quick scan
Objects scanned: 152970
Time elapsed: 9 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL logfile created on: 5/8/2010 1:56:50 PM - Run 3
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\tony.S0027470697.000\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
766.00 Mb Total Physical Memory | 417.00 Mb Available Physical Memory | 54.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1150 1300 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 53.30 Gb Free Space | 71.52% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: S0027470697
Current User Name: tony
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/05/08 13:48:49 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\tony.S0027470697.000\Desktop\OTL.exe
PRC - [2010/04/16 20:01:14 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/11/16 09:04:30 | 000,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2009/11/16 09:03:32 | 002,054,360 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2008/06/10 04:27:04 | 000,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINNT\explorer.exe
PRC - [2007/04/02 01:15:40 | 000,061,440 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTDevSrv.exe
PRC - [2005/03/23 18:26:09 | 000,217,088 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliPoint\point32.exe
PRC - [2003/08/22 02:24:08 | 000,426,098 | ---- | M] (Executive Software International, Inc.) -- C:\Program Files\Executive Software\Diskeeper\DkService.exe
PRC - [2002/05/03 12:36:24 | 001,118,208 | ---- | M] (Intel Corporation) -- C:\WINNT\system32\NMSSvc.Exe
PRC - [2002/03/06 10:08:36 | 000,101,611 | ---- | M] (GTW) -- C:\WINNT\GWMDMMSG.exe
========== Modules (SafeList) ========== MOD - [2010/05/08 13:48:49 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\tony.S0027470697.000\Desktop\OTL.exe
MOD - [2008/04/13 19:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (PictureTaker)
SRV - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/11/16 09:12:54 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009/11/16 09:04:30 | 000,735,960 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2008/05/21 06:42:56 | 000,064,000 | ---- | M] (Creative Technology Ltd) [On_Demand | Stopped] -- C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe -- (CTUPnPSv)
SRV - [2007/04/02 01:15:40 | 000,061,440 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files\Creative\Shared Files\CTDevSrv.exe -- (CTDevice_Srv)
SRV - [2005/03/30 17:46:56 | 000,411,920 | ---- | M] (Eastman Kodak Company) [On_Demand | Stopped] -- C:\WINNT\system32\drivers\KodakCCS.exe -- (KodakCCS)
SRV - [2003/08/22 02:24:08 | 000,426,098 | ---- | M] (Executive Software International, Inc.) [Auto | Running] -- C:\Program Files\Executive Software\Diskeeper\DkService.exe -- (Diskeeper)
SRV - [2003/03/09 15:31:02 | 000,065,795 | R--- | M] (HP) [On_Demand | Stopped] -- C:\WINNT\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2003/02/08 14:10:57 | 000,052,736 | ---- | M] (Macrovision) [Disabled | Stopped] -- C:\WINNT\system32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA)
SRV - [2002/05/03 12:36:24 | 001,118,208 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINNT\system32\NMSSvc.Exe -- (NMSSvc) Intel®
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2009/11/16 10:06:50 | 000,096,408 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINNT\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2009/11/16 10:03:36 | 000,108,792 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINNT\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009/11/16 09:56:12 | 000,116,520 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINNT\system32\drivers\eamon.sys -- (eamon)
DRV - [2005/06/16 15:41:02 | 000,037,150 | ---- | M] (Eastman Kodak Company) [Kernel | System | Running] -- C:\WINNT\system32\drivers\DcCam.sys -- (DcCam)
DRV - [2005/03/31 09:00:08 | 000,152,081 | ---- | M] (Eastman Kodak Company) [Kernel | System | Stopped] -- C:\WINNT\system32\drivers\ExportIt.sys -- (Exportit)
DRV - [2005/03/31 08:47:56 | 000,070,262 | ---- | M] (Eastman Kodak Company) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\DcPtp.sys -- (DcPTP)
DRV - [2005/03/31 08:47:50 | 000,008,022 | ---- | M] (Eastman Kodak Company) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\DcLps.sys -- (DcLps)
DRV - [2005/03/31 08:47:48 | 000,038,673 | ---- | M] (Eastman Kodak Company) [Kernel | Auto | Running] -- C:\WINNT\system32\drivers\DCFS2k.sys -- (DCFS2K)
DRV - [2005/03/31 08:47:42 | 000,061,564 | ---- | M] (Eastman Kodak Company) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\DcFpoint.sys -- (DcFpoint)
DRV - [2004/10/07 20:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINNT\system32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/08/04 00:29:54 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2003/02/08 14:10:54 | 000,011,376 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\WINNT\system32\drivers\CdaC15BA.SYS -- (CdaC15BA)
DRV - [2002/05/03 12:36:44 | 000,009,868 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\NMSCFG.SYS -- (NMSCFG)
DRV - [2002/04/11 22:21:38 | 000,013,335 | R--- | M] (Microsystems Corp) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\usbcm.sys -- (usbcm)
DRV - [2002/03/06 10:08:34 | 001,167,936 | ---- | M] (GTW) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\GWMDM.sys -- (GTWModem)
DRV - [2002/02/28 08:47:04 | 000,233,984 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINNT\system32\drivers\cdudf_xp.sys -- (cdudf_xp)
DRV - [2002/02/28 08:47:04 | 000,110,278 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINNT\system32\drivers\pwd_2K.sys -- (pwd_2K)
DRV - [2002/02/28 08:47:04 | 000,024,918 | ---- | M] (Roxio) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\Mmc_2k.sys -- (mmc_2K)
DRV - [2002/02/28 08:47:04 | 000,024,502 | ---- | M] (Roxio) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\Dvd_2k.sys -- (dvd_2K)
DRV - [2002/02/28 08:47:00 | 000,057,136 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINNT\system32\drivers\cdr4_xp.sys -- (Cdr4_xp)
DRV - [2002/02/28 08:47:00 | 000,023,721 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINNT\system32\drivers\cdralw2k.sys -- (Cdralw2k)
DRV - [2002/01/23 13:59:24 | 000,206,208 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINNT\system32\drivers\udfreadr_xp.sys -- (UdfReadr_xp)
DRV - [2001/08/17 13:57:38 | 000,016,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\MODEMCSA.sys -- (MODEMCSA)
DRV - [2001/08/17 13:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINNT\System32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 13:28:00 | 000,871,388 | ---- | M] (BCM) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\BCMDM.sys -- (BCMModem)
DRV - [2001/08/17 12:50:26 | 000,731,648 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\nv4.sys -- (nv4)
DRV - [2001/08/17 12:20:04 | 000,096,256 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\ac97intc.sys -- (ac97intc) Intel® 82801 Audio Driver Install Service (WDM)
DRV - [2001/08/17 12:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\el90xbc5.sys -- (EL90XBC)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Answers.com"
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"FF - prefs.js..extensions.enabledItems: {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.9.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.8
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.3
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.3
FF - prefs.js..extensions.enabledItems:
[email protected]:4.0.3
FF - prefs.js..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.3.7
FF - prefs.js..extensions.enabledItems: {5C46D283-ABDE-4dce-B83C-08881401921C}:2.0.2
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:4.9
FF - prefs.js..extensions.enabledItems: {1f91cde0-c040-11da-a94d-0800200c9a66}:3.0.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2008/11/17 02:26:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/04/16 20:02:33 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/16 20:02:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/23 11:29:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\
[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/04/23 11:32:19 | 000,000,000 | ---D | M]
[2009/10/07 15:15:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Extensions
[2010/05/07 15:26:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions
[2010/04/16 20:32:07 | 000,000,000 | ---D | M] (RSS Ticker) -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\{1f91cde0-c040-11da-a94d-0800200c9a66}
[2010/03/12 21:47:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/05 16:50:04 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2010/04/25 09:03:30 | 000,000,000 | ---D | M] (Google Shortcuts) -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}
[2010/04/16 19:53:17 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/03/15 13:23:36 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/04/16 21:03:55 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/03/14 11:53:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/03/12 18:52:24 | 000,000,000 | ---D | M] (Download Manager Tweak) -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}
[2010/04/16 20:32:09 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2010/04/05 16:50:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Mozilla\Firefox\Profiles\omeg6iys.default\extensions\
[email protected][2010/05/07 15:26:01 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/23 11:29:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2008/06/18 01:43:04 | 000,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/04/23 11:29:10 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2010/05/08 12:17:46 | 000,000,027 | ---- | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [GWMDMMSG] C:\WINNT\GWMDMMSG.exe (GTW)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\AutorunsDisabled: wininet.dll = regperf.exe
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINNT\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C}
http://myitlab.pears...ces/ax/stub.cab (Enlite 2.x Simulation Engine Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.115.71.53 24.213.60.93 24.196.64.53
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINNT\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINNT\webshots.bmp
O24 - Desktop BackupWallPaper: C:\WINNT\webshots.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/07/08 13:28:12 | 000,000,004 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINNT\system32\ias [2010/05/08 12:17:07 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: Ip6FwHlp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 90 Days ========== [2010/05/08 13:49:10 | 000,570,880 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\tony.S0027470697.000\Desktop\OTL.exe
[2010/05/08 13:47:39 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/05/08 11:51:27 | 000,000,000 | ---D | C] -- C:\Avenger
[2010/05/07 15:33:24 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINNT\System32\drivers\mbamswissarmy.sys
[2010/05/07 15:33:22 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINNT\System32\drivers\mbam.sys
[2010/05/07 15:33:22 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/07 15:27:07 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/05/07 12:25:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\Local Settings\Application Data\Threat Expert
[2010/05/07 11:38:05 | 001,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\WINNT\PCTBDCore.dll.old
[2010/05/07 11:35:06 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/05/07 11:34:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/06 14:42:17 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/05/06 14:41:51 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/05/06 14:34:09 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010/05/04 17:06:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\GMArcade
[2010/05/01 19:43:53 | 000,000,000 | ---D | C] -- C:\Program Files\KO Interactive
[2010/05/01 17:17:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\WINDOWS
[2010/05/01 17:01:54 | 000,000,000 | ---D | C] -- C:\Program Files\THQ
[2010/04/23 21:53:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\FileCure
[2010/04/16 20:01:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2010/04/05 16:54:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Uniblue
[2010/04/05 11:37:19 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\tony.S0027470697.000\Recent
[2010/04/01 16:18:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Apple Computer
[2010/04/01 16:15:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/01 15:57:08 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
[2010/03/26 19:05:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/03/26 19:03:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010/03/26 19:03:06 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010/03/26 19:03:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2010/03/26 17:30:10 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack
[2010/03/26 15:38:29 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\WINNT\System32\drivers\SBREDrv.sys
[2010/03/25 10:41:56 | 000,000,000 | ---D | C] -- C:\WINNT\temp
[2010/03/15 12:32:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\dwhelper
[2010/03/14 14:45:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\My Documents\iMacros
[2010/03/13 23:43:46 | 000,000,000 | ---D | C] -- C:\WINNT\System32\Adobe
[2010/03/13 23:24:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/03/13 23:21:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/03/11 14:24:36 | 000,116,224 | ---- | C] (Xerox) -- C:\WINNT\System32\dllcache\xrxwiadr.dll
[2010/03/11 14:19:28 | 000,149,376 | ---- | C] (M-Systems) -- C:\WINNT\System32\dllcache\tffsport.sys
[2010/03/11 14:15:39 | 000,029,696 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINNT\System32\dllcache\rw450ext.dll
[2010/03/11 14:15:38 | 000,027,648 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINNT\System32\dllcache\rw430ext.dll
[2010/03/11 14:15:20 | 000,079,104 | ---- | C] (Comtrol Corporation) -- C:\WINNT\System32\dllcache\rocket.sys
[2010/03/11 14:04:50 | 000,028,288 | ---- | C] (Gemplus) -- C:\WINNT\System32\dllcache\grserial.sys
[2010/03/11 14:00:46 | 000,249,856 | ---- | C] (Comtrol® Corporation) -- C:\WINNT\System32\dllcache\ctmasetp.dll
[2010/03/09 19:55:49 | 000,000,000 | ---D | C] -- C:\WINNT\System32\oodag
[2010/03/09 18:46:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\My Documents\O&O
[2010/03/09 14:15:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/03/09 14:14:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\SUPERAntiSpyware.com
[2010/03/09 14:14:12 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/03/09 13:37:30 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/03/09 13:35:21 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINNT\NIRCMD.exe
[2010/03/09 13:35:16 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINNT\SWREG.exe
[2010/03/09 13:35:15 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINNT\SWSC.exe
[2010/03/09 13:35:14 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINNT\SWXCACLS.exe
[2010/03/09 13:30:02 | 000,000,000 | ---D | C] -- C:\WINNT\ERDNT
[2010/03/09 13:29:19 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/03/09 12:11:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Malwarebytes
[2010/03/09 12:11:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/03/05 13:38:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\MSN6
[2010/03/05 12:57:25 | 000,000,000 | ---D | C] -- C:\PFiles
[2010/03/01 19:12:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\tony.S0027470697.000\Local Settings\Application Data\ESET
[2010/03/01 19:00:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2010/03/01 18:56:44 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/03/01 18:56:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010/02/10 00:33:02 | 000,000,000 | ---D | C] -- C:\indhub_filez
========== Files - Modified Within 90 Days ========== [2010/05/08 13:48:49 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\tony.S0027470697.000\Desktop\OTL.exe
[2010/05/08 13:13:55 | 000,000,284 | ---- | M] () -- C:\WINNT\tasks\RealUpgradeScheduledTaskS-1-5-21-3253555194-248915221-3852222622-1006.job
[2010/05/08 13:13:55 | 000,000,276 | ---- | M] () -- C:\WINNT\tasks\RealUpgradeLogonTaskS-1-5-21-3253555194-248915221-3852222622-1006.job
[2010/05/08 13:05:11 | 000,000,886 | ---- | M] () -- C:\WINNT\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/08 12:35:32 | 000,000,868 | ---- | M] () -- C:\WINNT\tasks\Google Software Updater.job
[2010/05/08 12:18:13 | 000,000,182 | ---- | M] () -- C:\WINNT\system.ini
[2010/05/08 12:17:46 | 000,000,027 | ---- | M] () -- C:\WINNT\System32\drivers\etc\hosts
[2010/05/08 12:17:33 | 000,002,206 | ---- | M] () -- C:\WINNT\System32\wpa.dbl
[2010/05/08 12:17:31 | 000,000,882 | ---- | M] () -- C:\WINNT\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/08 12:16:45 | 000,000,006 | -H-- | M] () -- C:\WINNT\tasks\SA.DAT
[2010/05/08 12:16:42 | 000,002,048 | --S- | M] () -- C:\WINNT\bootstat.dat
[2010/05/08 12:15:40 | 003,407,872 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\ntuser.dat
[2010/05/08 12:15:40 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\tony.S0027470697.000\ntuser.ini
[2010/05/08 11:58:57 | 003,684,271 | R--- | M] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\ComboFix.exe
[2010/05/08 11:34:39 | 000,724,952 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\avenger.zip
[2010/05/08 11:11:29 | 000,000,488 | ---- | M] () -- C:\hpfr5550.xml
[2010/05/07 17:17:01 | 000,284,915 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\gmer.zip
[2010/05/07 15:33:26 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/07 15:27:08 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\NTREGOPT.lnk
[2010/05/07 15:27:08 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\ERUNT.lnk
[2010/05/06 14:43:10 | 000,001,800 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/05/06 11:15:02 | 000,000,284 | ---- | M] () -- C:\WINNT\tasks\AppleSoftwareUpdate.job
[2010/05/02 16:01:18 | 001,044,610 | -H-- | M] () -- C:\Documents and Settings\tony.S0027470697.000\Local Settings\Application Data\IconCache.db
[2010/05/02 15:38:52 | 000,001,584 | ---- | M] () -- C:\WINNT\disney.ini
[2010/05/02 11:23:34 | 000,000,447 | ---- | M] () -- C:\WINNT\win.ini
[2010/05/02 11:16:49 | 000,000,372 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\My Documents\spider.sav
[2010/05/01 21:49:55 | 000,000,664 | ---- | M] () -- C:\WINNT\System32\d3d9caps.dat
[2010/05/01 20:45:52 | 000,000,552 | ---- | M] () -- C:\WINNT\System32\d3d8caps.dat
[2010/05/01 17:53:22 | 000,211,968 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\My Documents\awsome slide.ppt
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINNT\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINNT\System32\drivers\mbam.sys
[2010/04/28 16:41:58 | 000,000,075 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\jagex_runescape_preferences2.dat
[2010/04/28 16:41:58 | 000,000,041 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\jagex_runescape_preferences.dat
[2010/04/26 15:58:12 | 000,256,512 | ---- | M] () -- C:\WINNT\PEV.exe
[2010/04/23 22:20:25 | 000,000,015 | ---- | M] () -- C:\WINNT\wgedit.ini
[2010/04/16 20:01:18 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINNT\System32\pncrt.dll
[2010/04/04 16:23:13 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\jagex__preferences3.dat
[2010/03/30 12:33:01 | 000,004,592 | ---- | M] () -- C:\WINNT\cplaptop9.dat
[2010/03/30 11:31:14 | 007,426,545 | ---- | M] () -- C:\WINNT\Slideshw.ini
[2010/03/26 15:38:20 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\WINNT\System32\drivers\SBREDrv.sys
[2010/03/26 15:30:50 | 000,014,282 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\My Documents\cc_20100326_153046.reg
[2010/03/14 04:22:56 | 000,001,526 | ---- | M] () -- C:\WINNT\Mpcwty02.ini
[2010/03/11 16:16:08 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/03/10 13:31:08 | 000,000,323 | ---- | M] () -- C:\WINNT\wininit.ini
[2010/03/10 12:02:41 | 000,000,000 | ---- | M] () -- C:\WINNT\oodcnt.INI
[2010/03/09 13:37:38 | 000,000,278 | --S- | M] () -- C:\boot.ini
[2010/02/17 01:13:40 | 000,001,827 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\My Documents\CoPilot Truck - Laptop 9 User Guide.lnk
[2010/02/17 01:13:40 | 000,001,827 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\CoPilot Truck - Laptop 9 User Guide.lnk
[2010/02/17 01:11:16 | 000,001,776 | ---- | M] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\CoPilot Truck - Laptop 9.lnk
[2010/02/10 12:13:48 | 000,165,376 | ---- | M] () -- C:\WINNT\System32\unrar.dll
========== Files Created - No Company Name ========== [2010/05/08 11:58:57 | 003,684,271 | R--- | C] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\ComboFix.exe
[2010/05/08 11:34:39 | 000,724,952 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\avenger.zip
[2010/05/07 17:17:25 | 000,284,915 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\gmer.zip
[2010/05/07 15:33:26 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/07 15:27:08 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\NTREGOPT.lnk
[2010/05/07 15:27:08 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\ERUNT.lnk
[2010/05/06 14:43:10 | 000,001,800 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/05/01 20:45:52 | 000,000,552 | ---- | C] () -- C:\WINNT\System32\d3d8caps.dat
[2010/05/01 20:45:45 | 000,000,664 | ---- | C] () -- C:\WINNT\System32\d3d9caps.dat
[2010/05/01 17:47:52 | 000,211,968 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\My Documents\awsome slide.ppt
[2010/05/01 16:56:19 | 000,000,372 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\My Documents\spider.sav
[2010/04/23 22:20:25 | 000,000,015 | ---- | C] () -- C:\WINNT\wgedit.ini
[2010/04/05 16:02:07 | 000,000,276 | ---- | C] () -- C:\WINNT\tasks\RealUpgradeLogonTaskS-1-5-21-3253555194-248915221-3852222622-1006.job
[2010/04/05 16:02:06 | 000,000,284 | ---- | C] () -- C:\WINNT\tasks\RealUpgradeScheduledTaskS-1-5-21-3253555194-248915221-3852222622-1006.job
[2010/04/04 16:23:13 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\jagex__preferences3.dat
[2010/03/29 14:27:28 | 000,001,827 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\My Documents\CoPilot Truck - Laptop 9 User Guide.lnk
[2010/03/26 19:03:12 | 000,000,284 | ---- | C] () -- C:\WINNT\tasks\AppleSoftwareUpdate.job
[2010/03/26 17:30:19 | 000,165,376 | ---- | C] () -- C:\WINNT\System32\unrar.dll
[2010/03/26 15:30:48 | 000,014,282 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\My Documents\cc_20100326_153046.reg
[2010/03/11 16:16:08 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/03/11 14:24:34 | 000,018,944 | ---- | C] () -- C:\WINNT\System32\dllcache\xrxscnui.dll
[2010/03/11 12:48:57 | 000,000,886 | ---- | C] () -- C:\WINNT\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/11 12:48:56 | 000,000,882 | ---- | C] () -- C:\WINNT\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/10 12:02:41 | 000,000,000 | ---- | C] () -- C:\WINNT\oodcnt.INI
[2010/03/09 13:37:38 | 000,000,208 | ---- | C] () -- C:\Boot.bak
[2010/03/09 13:37:34 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/03/09 13:35:21 | 000,077,312 | ---- | C] () -- C:\WINNT\MBR.exe
[2010/03/09 13:35:17 | 000,256,512 | ---- | C] () -- C:\WINNT\PEV.exe
[2010/03/09 13:35:16 | 000,098,816 | ---- | C] () -- C:\WINNT\sed.exe
[2010/03/09 13:35:16 | 000,080,412 | ---- | C] () -- C:\WINNT\grep.exe
[2010/03/09 13:35:16 | 000,068,096 | ---- | C] () -- C:\WINNT\zip.exe
[2010/03/03 23:51:13 | 003,407,872 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\ntuser.dat
[2010/02/17 01:13:40 | 000,001,827 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\CoPilot Truck - Laptop 9 User Guide.lnk
[2010/02/17 01:11:16 | 000,001,776 | ---- | C] () -- C:\Documents and Settings\tony.S0027470697.000\Desktop\CoPilot Truck - Laptop 9.lnk
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINNT\System32\OGACheckControl.dll
[2008/01/04 20:50:41 | 000,185,344 | ---- | C] () -- C:\WINNT\patchw32.dll
[2006/05/20 00:41:44 | 000,000,020 | ---- | C] () -- C:\WINNT\InfModM.ini
[2006/05/04 20:55:00 | 000,027,136 | ---- | C] () -- C:\WINNT\System32\VERMONT1.DLL
[2006/05/04 20:55:00 | 000,012,416 | ---- | C] () -- C:\WINNT\System32\VRX1.DLL
[2006/05/04 20:54:59 | 000,107,520 | ---- | C] () -- C:\WINNT\System32\SIMANT.DLL
[2006/03/20 14:25:53 | 000,000,055 | ---- | C] () -- C:\WINNT\VistaEmail.ini
[2006/03/01 13:31:19 | 000,000,026 | ---- | C] () -- C:\WINNT\DfrgUIEx.INI
[2006/01/27 19:28:24 | 000,000,000 | ---- | C] () -- C:\WINNT\Webspace.INI
[2005/07/12 13:31:16 | 000,204,800 | ---- | C] () -- C:\WINNT\System32\KPDVS.dll
[2005/02/27 16:32:20 | 000,000,032 | ---- | C] () -- C:\WINNT\AuthMgr.INI
[2004/10/11 21:03:49 | 000,000,000 | ---- | C] () -- C:\WINNT\hpqEmlsz.INI
[2004/08/12 19:03:04 | 000,000,045 | ---- | C] () -- C:\WINNT\iltwain.ini
[2004/08/12 17:21:21 | 000,000,018 | ---- | C] () -- C:\WINNT\cnc.ini
[2004/08/12 17:03:07 | 000,000,000 | ---- | C] () -- C:\WINNT\PROTOCOL.INI
[2004/07/22 20:23:08 | 000,000,021 | ---- | C] () -- C:\WINNT\PI4_setup.ini
[2004/07/22 20:04:36 | 000,000,021 | ---- | C] () -- C:\WINNT\PMK_setup.ini
[2004/06/16 17:09:45 | 000,000,011 | ---- | C] () -- C:\WINNT\ka.ini
[2004/05/31 10:36:52 | 000,000,482 | ---- | C] () -- C:\WINNT\hegames.ini
[2004/04/20 23:09:52 | 000,000,155 | ---- | C] () -- C:\WINNT\sb_affiliate.ini
[2004/04/20 09:36:02 | 000,000,400 | ---- | C] () -- C:\WINNT\System32\master.dll
[2004/04/11 09:22:39 | 000,000,323 | ---- | C] () -- C:\WINNT\wininit.ini
[2004/02/07 16:25:19 | 000,000,048 | ---- | C] () -- C:\WINNT\PerWin.ini
[2003/12/04 10:43:15 | 000,363,520 | ---- | C] () -- C:\WINNT\System32\psisdecd.dll
[2003/12/03 19:03:44 | 000,071,749 | ---- | C] () -- C:\WINNT\HCExtOutput.dll
[2003/12/03 19:03:44 | 000,000,823 | ---- | C] () -- C:\WINNT\TSC.ini
[2003/12/03 19:03:10 | 000,000,170 | ---- | C] () -- C:\WINNT\GetServer.ini
[2003/09/14 20:57:46 | 000,000,069 | ---- | C] () -- C:\WINNT\System32\msrev0.dll
[2003/05/17 22:35:48 | 000,172,128 | ---- | C] () -- C:\WINNT\msview.ini
[2003/04/26 16:20:33 | 000,000,002 | ---- | C] () -- C:\WINNT\msoffice.ini
[2003/03/14 23:28:37 | 000,458,752 | ---- | C] () -- C:\WINNT\GoogleToolbar_en_1.1.70-big.dll
[2003/03/09 15:31:04 | 000,561,152 | ---- | C] () -- C:\WINNT\System32\hpotscl.dll
[2003/02/08 14:18:33 | 000,001,526 | ---- | C] () -- C:\WINNT\Mpcwty02.ini
[2003/02/08 14:10:57 | 000,202,752 | ---- | C] () -- C:\WINNT\CDAC14BA.DLL
[2003/02/08 14:10:55 | 000,011,376 | ---- | C] () -- C:\WINNT\System32\drivers\CdaC15BA.SYS
[2003/02/05 20:10:54 | 000,000,064 | ---- | C] () -- C:\WINNT\QBWCD.INI
[2002/12/27 19:30:57 | 000,021,840 | ---- | C] () -- C:\WINNT\System32\SIntfNT.dll
[2002/12/27 19:30:57 | 000,017,212 | ---- | C] () -- C:\WINNT\System32\SIntf32.dll
[2002/12/09 23:16:26 | 007,426,545 | ---- | C] () -- C:\WINNT\Slideshw.ini
[2002/11/30 23:38:16 | 000,000,063 | ---- | C] () -- C:\WINNT\SANTAS~1.ini
[2002/10/24 08:54:18 | 000,000,171 | ---- | C] () -- C:\WINNT\INTUIT.INI
[2002/10/24 08:10:34 | 000,000,185 | ---- | C] () -- C:\WINNT\intuprof.ini
[2002/10/24 08:10:06 | 000,000,924 | ---- | C] () -- C:\WINNT\QUICKEN.INI
[2002/10/23 19:15:24 | 000,001,584 | ---- | C] () -- C:\WINNT\disney.ini
[2002/10/04 23:15:18 | 000,024,368 | ---- | C] () -- C:\WINNT\cdplayer.ini
[2002/09/26 21:04:30 | 000,000,594 | ---- | C] () -- C:\WINNT\WSST_Screen_Saver.ini
[2002/09/18 18:21:27 | 000,000,021 | ---- | C] () -- C:\WINNT\progman.ini
[2002/09/15 19:23:26 | 000,306,688 | ---- | C] () -- C:\WINNT\System32\LFFPX7.DLL
[2002/09/15 19:23:26 | 000,095,232 | ---- | C] () -- C:\WINNT\System32\LFKODAK.DLL
[2002/09/15 19:22:53 | 000,044,544 | ---- | C] () -- C:\WINNT\System32\gif89.dll
[2002/09/15 19:19:09 | 000,000,062 | ---- | C] () -- C:\WINNT\SIERRA.INI
[2002/07/08 13:33:15 | 000,000,061 | ---- | C] () -- C:\WINNT\smscfg.ini
[2002/07/08 13:13:58 | 000,377,600 | ---- | C] () -- C:\WINNT\System32\BOCOLE.DLL
[2002/07/08 13:13:58 | 000,167,456 | ---- | C] () -- C:\WINNT\System32\Bocof.dll
[2002/07/08 13:13:58 | 000,004,051 | ---- | C] () -- C:\WINNT\unwise32.ini
[2002/07/08 13:13:58 | 000,004,051 | ---- | C] () -- C:\WINNT\unwise.ini
[2002/07/08 13:13:34 | 000,000,370 | ---- | C] () -- C:\WINNT\ODBC.INI
[2002/07/08 13:09:21 | 000,069,632 | ---- | C] () -- C:\WINNT\System32\PROInst.dll
[2002/07/08 13:09:21 | 000,065,536 | ---- | C] () -- C:\WINNT\System32\NMSInst.dll
[2002/07/08 13:08:21 | 000,000,698 | ---- | C] () -- C:\WINNT\System32\OEMINFO.INI
[2002/03/13 17:46:46 | 000,053,248 | R--- | C] () -- C:\WINNT\System32\zlib.dll
[2001/10/09 14:27:17 | 000,000,872 | ---- | C] () -- C:\WINNT\orun32.ini
[2000/09/08 18:53:50 | 000,073,839 | ---- | C] () -- C:\WINNT\System32\KodakOneTouch.dll
[1999/12/02 13:01:20 | 000,229,376 | ---- | C] () -- C:\WINNT\System32\ISP2000.dll
[1999/07/23 13:46:48 | 000,000,116 | ---- | C] () -- C:\WINNT\AuHCcup1.ini
[1999/07/23 10:53:20 | 000,129,536 | ---- | C] () -- C:\WINNT\AuHCcup1.dll
[1998/10/22 22:46:00 | 000,047,104 | ---- | C] () -- C:\WINNT\System32\wh2robo.dll
[1998/08/16 06:00:00 | 000,004,096 | ---- | C] () -- C:\WINNT\System32\sysres.dll
[1998/05/27 15:13:34 | 000,032,256 | ---- | C] () -- C:\WINNT\System32\_UNODBC.dll
[1997/11/10 15:18:48 | 000,010,240 | ---- | C] () -- C:\WINNT\System32\vidx16.dll
[1997/06/13 19:56:08 | 000,056,832 | ---- | C] () -- C:\WINNT\System32\iyvu9_32.dll
[1980/01/01 00:00:00 | 000,262,144 | ---- | C] () -- C:\WINNT\System32\shpshftr.dll
[1980/01/01 00:00:00 | 000,009,785 | ---- | C] () -- C:\WINNT\System32\drivers\a312.sys
========== LOP Check ========== [2008/01/25 23:12:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Age of Empires 3
[2002/12/01 22:25:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Disney Interactive
[2009/03/31 19:40:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2010/03/01 18:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010/04/23 21:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileCure
[2006/05/26 14:28:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Geek Squad
[2007/09/20 15:51:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/09/19 11:40:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\myitlab
[2008/11/30 00:26:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Screaming Bee
[2010/05/07 14:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/30 19:31:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YoYoGames
[2009/04/02 17:33:36 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{333D5C37-01AF-4BD4-8380-38D8974725EE}
[2010/04/01 16:17:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/04/02 17:34:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{615DB4DC-B7C1-4125-9858-78EF460B76D2}
[2010/03/13 23:24:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2002/07/08 13:10:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\InterTrust
[2010/04/05 16:54:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\tony.S0027470697.000\Application Data\Uniblue
[2005/01/29 20:24:54 | 000,000,358 | ---- | M] () -- C:\WINNT\Tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1090275553.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2004/10/16 11:11:33 | 022,245,337 | ---- | M] () .cab file -- C:\WINNT\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/01/20 16:37:37 | 023,852,652 | ---- | M] () .cab file -- C:\WINNT\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/10/16 11:11:33 | 022,245,337 | ---- | M] () .cab file -- C:\WINNT\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/01/20 16:37:37 | 023,852,652 | ---- | M] () .cab file -- C:\WINNT\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINNT\ERDNT\cache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINNT\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINNT\system32\dllcache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINNT\system32\drivers\agp440.sys
[2004/08/04 01:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINNT\system32\ReinstallBackups\0014\DriverFiles\i386\AGP440.SYS
[2004/08/04 01:07:41 | 000,042,368 | ---- | M] ()
Unable to obtain MD5 -- C:\WINNT\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >[2002/10/29 09:04:37 | 012,091,533 | ---- | M] () .cab file -- C:\WINNT\Driver Cache\i386\sp1.cab:atapi.sys
[2004/10/16 11:11:33 | 022,245,337 | ---- | M] () .cab file -- C:\WINNT\Driver Cache\i386\sp2.cab:atapi.sys
[2009/01/20 16:37:37 | 023,852,652 | ---- | M] () .cab file -- C:\WINNT\Driver Cache\i386\sp3.cab:atapi.sys
[2002/10/29 09:04:37 | 012,091,533 | ---- | M] () .cab file -- C:\WINNT\ServicePackFiles\i386\sp1.cab:atapi.sys
[2004/10/16 11:11:33 | 022,245,337 | ---- | M] () .cab file -- C:\WINNT\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/01/20 16:37:37 | 023,852,652 | ---- | M] () .cab file -- C:\WINNT\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINNT\ERDNT\cache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINNT\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINNT\system32\dllcache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINNT\system32\drivers\atapi.sys
[2001/08/17 13:51:56 | 000,086,656 | ---- | M] (Microsoft Corporation) MD5=A64013E98426E1877CB653685C5C0009 -- C:\WINNT\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2004/08/04 00:59:42 | 000,095,360 | ---- | M] ()
Unable to obtain MD5 -- C:\WINNT\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINNT\ERDNT\cache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINNT\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINNT\system32\dllcache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINNT\system32\eventlog.dll
[2004/08/04 02:56:42 | 000,055,808 | ---- | M] ()
Unable to obtain MD5 -- C:\WINNT\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINNT\ERDNT\cache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINNT\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINNT\system32\dllcache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINNT\system32\netlogon.dll
[2004/08/04 02:56:44 | 000,407,040 | ---- | M] ()
Unable to obtain MD5 -- C:\WINNT\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINNT\ERDNT\cache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINNT\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINNT\system32\dllcache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINNT\system32\scecli.dll
[2004/08/04 02:56:44 | 000,180,224 | ---- | M] ()
Unable to obtain MD5 -- C:\WINNT\$NtServicePackUninstall$\scecli.dll
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2010/01/05 05:00:20 | 000,347,136 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINNT\system32\dxtmsft.dll
[2010/01/05 05:00:21 | 000,214,528 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINNT\system32\dxtrans.dll
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2001/10/09 14:03:32 | 000,090,112 | ---- | M] () -- C:\WINNT\system32\config\default.sav
[2001/10/09 14:03:32 | 000,630,784 | ---- | M] () -- C:\WINNT\system32\config\software.sav
[2001/10/09 14:03:32 | 000,385,024 | ---- | M] () -- C:\WINNT\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINNT\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINNT\system32\drivers\mbamswissarmy.sys
[2010/03/26 15:38:20 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\WINNT\system32\drivers\SBREDrv.sys
========== Alternate Data Streams ========== @Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >