eSage TDSS remover found a hidden driver but couldn't remove it.
Everything else I tried (including TDSSKiller) couldn't see anything.
It prevents MSE updates and booting into safe mode, as well as all the secondary infections (antimalware, search redirects etc)
Any help much appreciated sad.gif
Did all suggested steps.
logs:
I ran MBAM a couple times before coming here, including those logs
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4328
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/19/2010 9:00:48 PM
mbam-log-2010-07-19 (21-00-48).txt
Scan type: Quick scan
Objects scanned: 173812
Time elapsed: 1 hour(s), 16 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 28
Registry Values Infected: 5
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 16
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\cscrptxt.cscrptxt (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e0ec6fba-f009-3535-95d6-b6390db27da1} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e6b02e22-80a8-472a-88f2-3d7db18ba26e} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{e6b02e22-80a8-472a-88f2-3d7db18ba26e} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e6b02e22-80a8-472a-88f2-3d7db18ba26e} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e6b02e22-80a8-472a-88f2-3d7db18ba26e} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\cscrptxt.cscrptxt.1.0 (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adgj.aghlp (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adgj.aghlp.1 (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adshothlpr.adshothlpr (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adshothlpr.adshothlpr.1.0 (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AVSolution (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\AVSolution (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ff1225d3-edb1-499b-bf2a-729239f695bb} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ff1225d3-edb1-499b-bf2a-729239f695bb} (Adware.AdRotator) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\070700setup.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mchk (Trojan.Adware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ibflbrxy (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ibflbrxy (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\h3yb0y1 (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\paul\Application Data\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\paul\Application Data\Sky-Banners\skb (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\paul\Application Data\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\paul\Application Data\Street-Ads\sta (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\paul\Application Data\5164C7C72C869D4F087B706C0A24CC44\070700Setup.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dzsip.exe (Trojan.Adware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qzsip.dll (Adware.EZlife) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-795874254-138367639-1861382812-1005\Dc142\EvID4226Patch.exe (Malware.Tool) -> Quarantined and deleted successfully.
C:\Documents and Settings\paul\Local Settings\Temp\c4bbea93.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\paul\Local Settings\Temp\6D.tmp (Rootkit.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\paul\Local Settings\Temp\eblmw.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\paul\Local Settings\Temp\hoagfk.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\6F.tmp (Rootkit.Dropper) -> Delete on reboot.
C:\WINDOWS\$NtUninstallMTF1011$\apUninstall.exe (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$\zrpt.xml (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\paul\Local Settings\Application Data\qhbcveiwv\ycidarftssd.exe (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\awf\LSASS.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\awf\system.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\awf\serv-u.ini (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mzsip.dll (Adware.AdRotator) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4328
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/24/2010 7:03:44 PM
mbam-log-2010-07-24 (19-03-44).txt
Scan type: Full scan (C:\|)
Objects scanned: 399593
Time elapsed: 4 hour(s), 1 minute(s), 46 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\esrensbl (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\LocalService\Local Settings\Application Data\tcbxvalpb\qviuiqftssd.exe (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4364
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/28/2010 6:26:07 PM
mbam-log-2010-07-28 (18-26-07).txt
Scan type: Quick scan
Objects scanned: 145015
Time elapsed: 10 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-29 00:51:49
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\paul\LOCALS~1\Temp\pxtdapob.sys
---- Kernel code sections - GMER 1.0.15 ----
PAGE ntkrnlpa.exe!IoRegisterPlugPlayNotification 8058A15A 8 Bytes PUSH B7F5D370; RET rk_remover.sys (TDSS Remover Kernel Driver/eSage Lab)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB67FB380, 0x566445, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xA98A5300, 0x3ACC8, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xB8398300, 0x1B7E, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[576] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[576] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C1000A
.text C:\WINDOWS\Explorer.EXE[576] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C
.text C:\WINDOWS\System32\svchost.exe[1256] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 009A000A
.text C:\WINDOWS\System32\svchost.exe[1256] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009B000A
.text C:\WINDOWS\System32\svchost.exe[1256] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0099000C
.text C:\WINDOWS\System32\svchost.exe[1256] ole32.dll!CoCreateInstance 7750057E 3 Bytes JMP 00DC000A
.text C:\WINDOWS\System32\svchost.exe[1256] ole32.dll!CoCreateInstance + 4 77500582 1 Byte [89]
.text C:\WINDOWS\system32\wuauclt.exe[2040] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\wuauclt.exe[2040] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009B000A
.text C:\WINDOWS\system32\wuauclt.exe[2040] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0099000C
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
OTL logfile created on: 7/29/2010 1:44:28 AM - Run 3
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\paul\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 74.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 3070 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 100.62 Gb Free Space | 43.21% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PCB
Current User Name: paul
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/07/29 01:02:12 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\paul\Desktop\OTL.exe
PRC - [2010/06/01 14:53:46 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/05/23 21:38:00 | 000,015,688 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Silverlight\4.0.50524.0\agcp.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009/10/07 06:04:44 | 003,872,552 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version4\TeamViewer.exe
PRC - [2009/10/07 05:50:26 | 000,185,640 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/11/12 21:43:30 | 000,019,456 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CtHelper.exe
PRC - [2007/10/17 16:13:22 | 000,389,120 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2006/05/23 21:05:45 | 000,730,112 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CTXFISPI.EXE
PRC - [2005/11/04 18:07:56 | 000,049,152 | ---- | M] (Creative Technology Ltd.) -- C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
========== Modules (SafeList) ==========
MOD - [2010/07/29 01:02:12 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\paul\Desktop\OTL.exe
MOD - [2008/04/13 17:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe -- (ccSchedulerSVC)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009/10/07 05:50:26 | 000,185,640 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe -- (TeamViewer4)
SRV - [2007/10/17 16:13:22 | 000,389,120 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\Senfilt.sys -- (SenFiltService)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\PNDIS5.SYS -- (PNDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\AEAudio.sys -- (AEAudio)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\adidts.sys -- (ADIDTSFiltService)
DRV - [2010/07/26 22:32:37 | 000,052,736 | ---- | M] (eSage Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\rk_remover.sys -- (rk_remover-boot)
DRV - [2010/04/03 15:55:31 | 010,232,128 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2010/03/25 21:30:22 | 000,151,216 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2009/12/30 12:20:54 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009/09/07 14:11:48 | 000,138,736 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK)
DRV - [2009/08/22 11:25:00 | 000,009,088 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys -- (RivaTuner32)
DRV - [2009/02/24 18:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2008/04/13 11:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/04/13 09:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/11/12 23:01:52 | 000,095,168 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTERFXFX.DLL -- (CTERFXFX.DLL)
DRV - [2006/11/18 16:20:47 | 000,271,360 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2006/11/18 16:20:46 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2006/11/10 06:08:50 | 000,024,064 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ATITool.sys -- (ATITool)
DRV - [2006/06/16 00:30:16 | 000,176,128 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8187.sys -- (RTLWUSB)
DRV - [2006/05/23 20:48:07 | 000,061,952 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTHWIUT.DLL -- (CTHWIUT.DLL)
DRV - [2006/05/23 20:48:02 | 000,158,720 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CT20XUT.DLL -- (CT20XUT.DLL)
DRV - [2006/05/23 20:47:44 | 001,170,432 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTEXFIFX.DLL -- (CTEXFIFX.DLL)
DRV - [2006/05/23 20:46:58 | 000,548,352 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTSBLFX.DLL -- (CTSBLFX.DLL)
DRV - [2006/05/23 20:46:32 | 000,160,768 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTEAPSFX.DLL -- (CTEAPSFX.DLL)
DRV - [2006/05/23 20:46:02 | 000,536,576 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTAUDFX.DLL -- (CTAUDFX.DLL)
DRV - [2006/05/23 20:45:48 | 000,087,552 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\COMMONFX.DLL -- (COMMONFX.DLL)
DRV - [2006/05/23 20:45:42 | 000,317,952 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTEDSPSY.DLL -- (CTEDSPSY.DLL)
DRV - [2006/05/23 20:41:38 | 000,115,200 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTEDSPIO.DLL -- (CTEDSPIO.DLL)
DRV - [2006/05/23 20:41:22 | 000,269,824 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\CTEDSPFX.DLL -- (CTEDSPFX.DLL)
DRV - [2006/05/23 20:41:07 | 000,007,168 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV - [2006/05/23 20:41:04 | 000,499,584 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)
DRV - [2006/05/23 20:40:21 | 001,110,016 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ha20x2k.sys -- (ha20x2k)
DRV - [2006/05/23 20:38:30 | 000,116,224 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2006/05/23 20:38:08 | 000,143,872 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2006/05/23 20:38:01 | 000,078,336 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia)
DRV - [2006/05/23 20:37:44 | 000,502,272 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k)
DRV - [2006/05/02 02:12:40 | 000,229,888 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\adihdaud.sys -- (ADIHdAudAddService)
DRV - [2006/03/31 04:39:54 | 000,013,532 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SjyPkt.sys -- (SjyPkt)
DRV - [2006/03/24 04:51:00 | 000,244,608 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2005/11/10 02:06:04 | 000,340,704 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctdvda2k.sys -- (ctdvda2k)
DRV - [2005/06/15 07:55:53 | 000,004,096 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2004/08/12 14:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004/08/04 05:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2004/08/04 05:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2004/08/03 15:31:20 | 000,036,224 | ---- | M] (ADMtek Incorporated.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\an983.sys -- (AN983)
DRV - [1996/04/03 12:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://red.clientapp...//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://hotmail.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://hotmail.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:3.0
FF - prefs.js..extensions.enabledItems: {A5AA4E40-5504-4A80-92F2-4BDA01936BEA}:1.9.1
FF - HKLM\software\mozilla\Firefox\Extensions\\{A5AA4E40-5504-4A80-92F2-4BDA01936BEA}: C:\Documents and Settings\paul\Local Settings\Application Data\{A5AA4E40-5504-4A80-92F2-4BDA01936BEA} [2010/07/19 19:06:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/12 22:26:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/26 14:15:21 | 000,000,000 | ---D | M]
[2009/03/02 14:33:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Mozilla\Extensions
[2009/03/02 14:33:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\paul\Application Data\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2010/07/28 18:14:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\1mn9conl.default\extensions
[2010/07/19 18:20:46 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\1mn9conl.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/28 18:14:25 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/07/26 13:15:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2009/08/22 16:45:05 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2007/10/19 14:02:08 | 000,019,104 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
[2007/10/19 14:02:08 | 000,105,632 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
[2007/10/19 14:02:07 | 000,057,504 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2010/07/26 13:14:52 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/10/21 11:25:41 | 000,024,576 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npgcplug.dll
[2008/04/28 16:13:00 | 000,114,688 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2009/10/12 19:18:58 | 000,238,776 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2009/03/30 17:13:54 | 000,098,304 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npraclient.dll
[2005/04/27 13:10:49 | 000,102,400 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [AudioDrvEmulator] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: msn.com ([adcenter] https in Trusted sites)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplane...C_2.3.7.109.cab (CDownloadCtrl Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative....15035/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/10/10 07:36:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{029d621c-6464-11db-87e9-0018f300afd6}\Shell - "" = AutoRun
O33 - MountPoints2\{029d621c-6464-11db-87e9-0018f300afd6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{029d621c-6464-11db-87e9-0018f300afd6}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- File not found
O33 - MountPoints2\{894dc727-09bb-11de-88fb-0015af044f4c}\Shell - "" = AutoRun
O33 - MountPoints2\{894dc727-09bb-11de-88fb-0015af044f4c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{894dc727-09bb-11de-88fb-0015af044f4c}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (69537929998893056)
========== Files/Folders - Created Within 90 Days ==========
[2010/07/29 01:02:27 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\paul\Desktop\OTL.exe
[2010/07/28 18:10:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/07/28 18:09:23 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/07/26 21:51:14 | 000,052,736 | ---- | C] (eSage Lab) -- C:\WINDOWS\System32\drivers\rk_remover.sys
[2010/07/26 19:21:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/07/26 19:05:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Local Settings\Application Data\VS Revo Group
[2010/07/26 19:05:03 | 000,027,064 | ---- | C] (VS Revo Group) -- C:\WINDOWS\System32\drivers\revoflt.sys
[2010/07/26 19:05:01 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2010/07/26 19:00:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2010/07/26 17:34:49 | 000,000,000 | ---D | C] -- C:\8e184e99c5078efe49dcd2d10cc9dc
[2010/07/26 13:15:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/07/26 13:15:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/07/26 13:14:46 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2010/07/26 12:25:12 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010/07/23 22:29:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\tcbxvalpb
[2010/07/23 22:28:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/07/23 22:28:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2010/07/23 10:25:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Desktop\utils
[2010/07/22 11:55:34 | 000,000,000 | ---D | C] -- C:\Program Files\Hitman Pro 3.5
[2010/07/22 11:55:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/07/22 11:50:24 | 000,000,000 | ---D | C] -- C:\Program Files\Unlocker
[2010/07/22 11:15:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\My Documents\Simply Super Software
[2010/07/22 11:15:30 | 000,000,000 | ---D | C] -- C:\Program Files\Trojan Remover
[2010/07/22 11:15:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Simply Super Software
[2010/07/22 11:15:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Simply Super Software
[2010/07/22 01:29:50 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2010/07/22 01:29:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\IObit
[2010/07/22 00:29:02 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\paul\Recent
[2010/07/22 00:27:07 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010/07/21 17:57:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2010/07/21 17:57:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Mozilla
[2010/07/21 04:49:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/21 04:48:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/07/19 19:40:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\Malwarebytes
[2010/07/19 19:40:00 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/19 19:39:58 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/19 19:39:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/19 19:39:57 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/19 19:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/19 19:17:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/19 19:06:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Local Settings\Application Data\{A5AA4E40-5504-4A80-92F2-4BDA01936BEA}
[2010/07/19 19:05:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Local Settings\Application Data\qhbcveiwv
[2010/07/19 19:04:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\5164C7C72C869D4F087B706C0A24CC44
[2010/07/18 11:00:56 | 000,201,968 | ---- | C] (CA, Inc.) -- C:\WINDOWS\System32\Isafprod.dll
[2010/07/18 11:00:56 | 000,128,240 | ---- | C] (Computer Associates International, Inc.) -- C:\WINDOWS\System32\Isafeif.dll
[2010/07/18 11:00:56 | 000,095,472 | ---- | C] (Computer Associates International, Inc.) -- C:\WINDOWS\System32\Vetredir.dll
[2010/07/16 16:33:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\My Documents\Downloads
[2010/07/16 15:43:35 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2010/07/16 15:31:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\paul\Application Data\uTorrent
[2010/05/24 21:02:16 | 000,000,000 | ---D | C] -- C:\Program Files\UFOAI-2.3-dev
[2010/05/07 19:27:12 | 000,061,440 | ---- | C] (Khronos Group) -- C:\WINDOWS\System32\OpenCL.dll
[2010/05/07 18:55:04 | 000,000,000 | ---D | C] -- C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
[2006/08/17 11:32:46 | 000,033,792 | R--- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
========== Files - Modified Within 90 Days ==========
[2010/07/29 01:13:22 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/07/29 01:07:48 | 000,000,308 | -HS- | M] () -- C:\WINDOWS\tasks\GVCQOA.job
[2010/07/29 01:07:48 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/29 01:07:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/29 01:02:12 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\paul\Desktop\OTL.exe
[2010/07/28 18:00:27 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/28 17:58:47 | 006,815,744 | -H-- | M] () -- C:\Documents and Settings\paul\NTUSER.DAT
[2010/07/28 17:58:46 | 000,064,900 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000005-00000000-00000002-00001102-00000005-00311102}.rfx
[2010/07/28 17:58:46 | 000,053,588 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000002-00001102-00000005-00311102}.rfx
[2010/07/28 17:58:46 | 000,053,588 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000005-00000000-00000002-00001102-00000005-00311102}.rfx
[2010/07/28 17:58:46 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2010/07/28 17:58:46 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2010/07/27 20:32:28 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/07/27 16:59:42 | 000,016,968 | ---- | M] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/07/27 11:35:05 | 000,276,202 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010/07/27 11:32:32 | 014,467,268 | -H-- | M] () -- C:\Documents and Settings\paul\Local Settings\Application Data\IconCache.db
[2010/07/26 22:32:37 | 000,052,736 | ---- | M] (eSage Lab) -- C:\WINDOWS\System32\drivers\rk_remover.sys
[2010/07/26 20:38:39 | 000,988,300 | ---- | M] () -- C:\WINDOWS\System32\drivers\KmxAgent.asc
[2010/07/26 20:32:05 | 000,113,194 | ---- | M] () -- C:\Documents and Settings\paul\My Documents\cc_20100726_203201.reg
[2010/07/26 19:22:39 | 000,042,768 | ---- | M] () -- C:\Documents and Settings\paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/26 18:55:45 | 000,000,868 | ---- | M] () -- C:\Documents and Settings\paul\My Documents\cc_20100726_185542.reg
[2010/07/26 18:49:49 | 000,005,568 | ---- | M] () -- C:\Documents and Settings\paul\My Documents\cc_20100726_184945.reg
[2010/07/26 18:31:58 | 001,657,551 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2010/07/26 18:31:58 | 000,000,345 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2010/07/26 18:31:58 | 000,000,345 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2010/07/26 18:31:58 | 000,000,289 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2010/07/26 18:31:58 | 000,000,081 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2010/07/26 18:31:58 | 000,000,081 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2010/07/26 18:31:58 | 000,000,081 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2010/07/26 18:31:58 | 000,000,081 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2010/07/26 18:31:58 | 000,000,081 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2010/07/26 18:31:58 | 000,000,081 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2010/07/26 18:31:58 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2010/07/26 18:31:58 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2010/07/26 18:31:58 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2010/07/26 18:31:58 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2010/07/26 18:31:58 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2010/07/26 18:31:58 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2010/07/26 14:33:09 | 000,000,568 | ---- | M] () -- C:\Documents and Settings\paul\My Documents\cc_20100726_143306.reg
[2010/07/26 14:02:38 | 000,000,214 | ---- | M] () -- C:\WINDOWS\System32\.crusader
[2010/07/26 13:35:38 | 000,006,140 | ---- | M] () -- C:\Documents and Settings\paul\My Documents\cc_20100726_133532.reg
[2010/07/26 13:05:10 | 000,000,067 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2010/07/24 19:12:24 | 000,000,464 | ---- | M] () -- C:\Documents and Settings\paul\My Documents\cc_20100724_191158.reg
[2010/07/23 22:28:35 | 000,001,984 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/07/22 09:57:47 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Mjoda.bin
[2010/07/22 09:57:04 | 000,005,260 | ---- | M] () -- C:\Documents and Settings\paul\My Documents\cc_20100722_095656.reg
[2010/07/22 09:49:44 | 000,192,976 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/22 01:48:01 | 000,501,106 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/22 01:48:01 | 000,441,014 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/07/22 01:48:01 | 000,071,206 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/07/22 01:16:18 | 000,024,232 | ---- | M] () -- C:\Documents and Settings\paul\My Documents\cc_20100722_011614.reg
[2010/07/22 00:36:00 | 000,395,128 | ---- | M] () -- C:\Documents and Settings\paul\My Documents\cc_20100722_003520.reg
[2010/07/21 18:05:24 | 000,000,610 | ---- | M] () -- C:\Documents and Settings\paul\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/07/19 21:27:03 | 000,012,540 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
[2010/07/19 19:06:46 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Ygexamo.dat
[2010/07/19 19:05:17 | 000,000,150 | ---- | M] () -- C:\zrpt.xml
[2010/07/19 10:27:53 | 000,024,084 | ---- | M] () -- C:\Documents and Settings\paul\Desktop\paper.odt
[2010/07/18 20:02:04 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\paul\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/18 10:58:09 | 000,000,227 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI
[2010/07/16 15:43:35 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/06/08 16:23:35 | 000,465,508 | ---- | M] () -- C:\Documents and Settings\paul\Desktop\Ahissar-Nahum-PhilTrans.pdf
[2010/06/08 16:18:34 | 001,647,290 | ---- | M] () -- C:\Documents and Settings\paul\Desktop\Ahissar-Nature-1997.pdf
[2010/06/05 14:56:08 | 001,323,008 | ---- | M] () -- C:\Documents and Settings\paul\My Documents\Impossiblepictures.pps
[2010/06/02 11:10:19 | 000,136,979 | ---- | M] () -- C:\Documents and Settings\paul\Desktop\role of attn in vision - maunsell.pdf
[2010/05/24 21:03:53 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\paul\Desktop\UFOAlien Invasion.lnk
[2010/05/04 17:41:14 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\paul\.gtk-bookmarks
========== Files Created - No Company Name ==========
[2010/07/28 18:34:37 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\paul\Desktop\gmer.exe
[2010/07/26 20:32:03 | 000,113,194 | ---- | C] () -- C:\Documents and Settings\paul\My Documents\cc_20100726_203201.reg
[2010/07/26 19:27:11 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/07/26 18:55:44 | 000,000,868 | ---- | C] () -- C:\Documents and Settings\paul\My Documents\cc_20100726_185542.reg
[2010/07/26 18:49:47 | 000,005,568 | ---- | C] () -- C:\Documents and Settings\paul\My Documents\cc_20100726_184945.reg
[2010/07/26 14:33:08 | 000,000,568 | ---- | C] () -- C:\Documents and Settings\paul\My Documents\cc_20100726_143306.reg
[2010/07/26 13:35:36 | 000,006,140 | ---- | C] () -- C:\Documents and Settings\paul\My Documents\cc_20100726_133532.reg
[2010/07/26 13:05:10 | 000,000,067 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010/07/24 19:12:01 | 000,000,464 | ---- | C] () -- C:\Documents and Settings\paul\My Documents\cc_20100724_191158.reg
[2010/07/22 12:32:25 | 000,000,214 | ---- | C] () -- C:\WINDOWS\System32\.crusader
[2010/07/22 11:56:06 | 000,016,968 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/07/22 11:15:31 | 000,162,304 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar36.dll
[2010/07/22 11:15:31 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\ztvunace26.dll
[2010/07/22 11:15:31 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\unacev2.dll
[2010/07/22 11:15:30 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\UNRAR3.dll
[2010/07/22 09:56:58 | 000,005,260 | ---- | C] () -- C:\Documents and Settings\paul\My Documents\cc_20100722_095656.reg
[2010/07/22 01:16:16 | 000,024,232 | ---- | C] () -- C:\Documents and Settings\paul\My Documents\cc_20100722_011614.reg
[2010/07/22 00:35:25 | 000,395,128 | ---- | C] () -- C:\Documents and Settings\paul\My Documents\cc_20100722_003520.reg
[2010/07/21 18:05:24 | 000,000,610 | ---- | C] () -- C:\Documents and Settings\paul\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/07/19 21:02:55 | 000,988,300 | ---- | C] () -- C:\WINDOWS\System32\drivers\KmxAgent.asc
[2010/07/19 19:06:46 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Ygexamo.dat
[2010/07/19 19:06:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Mjoda.bin
[2010/07/19 19:05:16 | 000,000,150 | ---- | C] () -- C:\zrpt.xml
[2010/07/19 17:03:21 | 000,000,345 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2010/07/19 17:03:21 | 000,000,345 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2010/07/19 17:03:21 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2010/07/19 17:03:21 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2010/07/19 17:03:21 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2010/07/19 17:03:21 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2010/07/19 17:03:21 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2010/07/19 17:03:21 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2010/07/19 16:59:35 | 001,657,551 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2010/07/19 16:59:35 | 000,000,289 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2010/07/19 16:59:35 | 000,000,081 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2010/07/19 16:59:35 | 000,000,081 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2010/07/19 16:59:35 | 000,000,081 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2010/07/19 16:59:35 | 000,000,081 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2010/07/19 16:59:35 | 000,000,081 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2010/07/19 16:59:35 | 000,000,081 | ---- | C] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2010/07/16 15:43:35 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/06/08 16:23:35 | 000,465,508 | ---- | C] () -- C:\Documents and Settings\paul\Desktop\Ahissar-Nahum-PhilTrans.pdf
[2010/06/08 16:18:34 | 001,647,290 | ---- | C] () -- C:\Documents and Settings\paul\Desktop\Ahissar-Nature-1997.pdf
[2010/06/05 14:56:10 | 001,323,008 | ---- | C] () -- C:\Documents and Settings\paul\My Documents\Impossiblepictures.pps
[2010/06/02 11:10:19 | 000,136,979 | ---- | C] () -- C:\Documents and Settings\paul\Desktop\role of attn in vision - maunsell.pdf
[2010/05/23 22:07:40 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\paul\Desktop\UFOAlien Invasion.lnk
[2010/05/07 19:27:10 | 002,183,470 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2009/11/06 10:58:04 | 000,178,975 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2008/04/05 12:55:04 | 000,086,445 | R--- | C] () -- C:\WINDOWS\System32\instwdm.ini
[2008/04/05 12:55:04 | 000,000,191 | R--- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2008/03/12 04:16:58 | 000,000,029 | ---- | C] () -- C:\WINDOWS\sfbm.INI
[2007/11/05 12:38:44 | 000,003,072 | ---- | C] () -- C:\WINDOWS\CTXFIRES.DLL
[2007/10/19 14:02:26 | 000,051,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\atnt40k.sys
[2007/10/15 17:19:26 | 000,000,006 | ---- | C] () -- C:\WINDOWS\System32\mkghj.dll
[2007/07/03 03:22:35 | 000,138,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/03/27 15:24:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2006/11/18 16:20:46 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2006/11/18 16:20:46 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2006/11/10 06:08:50 | 000,024,064 | ---- | C] () -- C:\WINDOWS\System32\drivers\ATITool.sys
[2006/10/25 14:00:15 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/10/25 13:52:04 | 000,000,020 | ---- | C] () -- C:\WINDOWS\Hposcv07.INI
[2006/10/25 13:23:44 | 000,000,102 | ---- | C] () -- C:\WINDOWS\VSWizard.ini
[2006/10/24 19:16:56 | 000,023,885 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2006/10/24 19:16:48 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/10/11 12:33:47 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/10/10 10:26:20 | 000,005,810 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/10/10 10:25:46 | 000,000,636 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/05/23 22:00:48 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\CTBURST.DLL
[2005/07/26 14:13:12 | 000,000,214 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI
[2005/06/07 06:10:50 | 000,070,656 | ---- | C] () -- C:\WINDOWS\System32\CTMMACTL.DLL
[1997/06/13 19:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[1996/04/03 12:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2008/01/21 13:14:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Aliasworlds
[2007/07/03 16:59:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2007/05/16 14:08:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bryxen Software
[2010/07/26 18:30:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CA
[2010/07/26 19:00:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2009/03/04 20:13:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/03/12 19:16:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CCP
[2007/12/26 19:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EA
[2010/01/23 13:01:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2008/01/05 12:54:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HipSoft
[2010/07/26 11:29:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2008/01/06 12:59:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear
[2007/12/26 22:38:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/10/10 14:00:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
[2008/02/02 21:33:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/10/12 19:19:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2009/08/22 16:01:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2010/07/22 11:15:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Simply Super Software
[2010/07/26 11:27:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/01/30 13:57:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2010/07/19 21:00:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\5164C7C72C869D4F087B706C0A24CC44
[2008/01/21 19:33:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\alawar
[2007/12/30 12:41:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\AlwaysNeat
[2010/07/22 00:30:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Azureus
[2010/01/18 15:03:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Camel101
[2007/12/26 19:21:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\EA
[2008/03/08 10:43:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\EVEMon
[2007/12/26 20:29:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Eyeblaster
[2008/01/21 13:36:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\funkitron
[2008/02/02 21:02:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Gaijin Ent
[2010/07/22 01:12:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\GameRanger
[2007/10/15 15:18:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\GetRightToGo
[2009/03/14 18:06:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\HexWar Launcher
[2008/01/11 21:33:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Hulabee
[2010/07/22 01:29:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\IObit
[2010/07/22 01:23:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Itykzo
[2008/01/21 13:44:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Jamdat
[2006/10/25 13:24:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Leadertech
[2008/01/12 18:23:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Mind Control Software
[2009/02/08 22:48:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Mount&Blade
[2009/10/17 12:59:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\OpenOffice.org
[2006/10/28 12:38:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Opera
[2009/01/17 12:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\PACE Anti-Piracy
[2008/02/02 21:38:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\PlayFirst
[2010/07/22 11:15:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Simply Super Software
[2010/05/22 23:54:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Spore
[2007/12/15 13:20:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Super-Cow
[2008/01/04 00:59:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\SystemRequirementsLab
[2010/03/03 13:41:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\TeamViewer
[2006/10/25 15:44:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\TextPad
[2009/03/02 00:35:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\The Creative Assembly
[2009/10/12 22:41:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Turbine
[2010/05/23 22:09:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\UFOAI
[2010/07/22 00:19:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\uTorrent
[2007/10/19 14:02:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\webex
[2008/03/23 16:35:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\paul\Application Data\Wildfire
[2010/07/29 01:07:48 | 000,000,308 | -HS- | M] () -- C:\WINDOWS\Tasks\GVCQOA.job
[2010/07/29 01:13:22 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< >
< %SYSTEMDRIVE%\*.* >
[2006/10/10 07:36:08 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2008/12/01 12:52:04 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2006/10/10 07:36:08 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2008/06/01 12:32:31 | 000,000,102 | ---- | M] () -- C:\DownloadLog.txt
[2006/10/10 07:36:08 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2006/10/10 07:36:08 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/01/07 16:30:47 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/07/29 01:07:20 | 3219,128,320 | -HS- | M] () -- C:\pagefile.sys
[2007/06/18 12:35:14 | 000,000,004 | ---- | M] () -- C:\results.bin
[2010/07/24 11:28:51 | 000,000,267 | ---- | M] () -- C:\rkill.log
[2007/04/12 19:45:12 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2007/05/01 22:34:56 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2007/05/08 19:48:32 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2007/05/08 19:53:20 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2007/05/08 21:28:33 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2007/05/08 21:52:23 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2007/05/12 18:31:37 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2007/05/15 20:30:03 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2007/04/12 19:45:12 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2007/05/01 22:34:56 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2007/05/08 19:48:32 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2007/05/08 19:53:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2007/05/08 21:28:33 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2007/05/08 21:52:23 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2007/05/12 18:31:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2007/05/15 20:30:03 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2010/07/26 16:19:44 | 000,001,954 | ---- | M] () -- C:\TDSSKiller.2.4.0.0_26.07.2010_16.19.41_log.txt
[2010/07/27 14:56:02 | 000,040,416 | ---- | M] () -- C:\TDSSKiller.2.4.0.0_27.07.2010_14.53.05_log.txt
[2007/05/26 01:05:17 | 000,020,225 | ---- | M] () -- C:\TomeWizard070526005112.tom
[2007/05/26 01:05:17 | 000,175,109 | ---- | M] () -- C:\TomeWizard0705260051121.rsa
[2007/05/26 17:01:09 | 000,043,242 | ---- | M] () -- C:\TomeWizard070526162926.tom
[2007/05/26 17:01:10 | 000,260,513 | ---- | M] () -- C:\TomeWizard0705261629261.rsa
[2010/07/19 19:05:17 | 000,000,150 | ---- | M] () -- C:\zrpt.xml
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/10/10 07:35:51 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/15 21:00:00 | 000,027,136 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8Z.DLL
[2007/04/15 21:00:00 | 000,069,632 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8Z.DLL
[2008/07/06 05:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 03:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/01/12 10:54:29 | 000,802,816 | ---- | M] (Sprout Games, LLC) -- C:\WINDOWS\feedingfrenzy.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2005/09/28 01:56:46 | 000,185,856 | ---- | M] () -- C:\Program Files\7za.exe
[2007/10/21 11:25:40 | 000,774,144 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2006/08/27 07:38:28 | 001,015,973 | RHS- | M] () -- C:\Program Files\serial.tde
[2006/08/27 07:38:28 | 001,015,973 | RHS- | M] () -- C:\Program Files\serial.zip
[2006/08/27 07:19:51 | 000,056,239 | ---- | M] () -- C:\Program Files\svchosts.tbe
[2006/10/07 12:54:40 | 000,390,023 | RHS- | M] () -- C:\Program Files\wunauclt.tbe
[2006/10/07 12:54:40 | 000,390,023 | RHS- | M] () -- C:\Program Files\wunauclt.zip
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
[2010/07/29 01:07:48 | 000,000,308 | -HS- | M] () Unable to obtain MD5 -- C:\WINDOWS\Tasks\GVCQOA.job
< %systemroot%\System32\config\*.sav >
[2006/10/10 03:30:11 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/10/10 03:30:10 | 000,643,072 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006/10/10 03:30:10 | 000,909,312 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-22 08:53:11
========== Alternate Data Streams ==========
@Alternate Data Stream - 160 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6E643A51
@Alternate Data Stream - 1227 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:PlPfloqdhL6NP7DYYQR
@Alternate Data Stream - 1225 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:V4rXnZPM6mxDAhlUJGrk
@Alternate Data Stream - 1216 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:iYHwky9sirkIrg7Om26BQ89kKrmUu
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FEE5129B
@Alternate Data Stream - 1153 bytes -> C:\Program Files\Common Files\System:bQkBaPqhFDXbiCtVfSQXDSFJi
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C425C9C0
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
@Alternate Data Stream - 1013 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:pRaIg1P4H85poW0Y1I
< End of report >
sorry screwed up, no extras file...