I'm really stumped and hope you can help me.
OS - Windows Vista
HDD 60 Gb
Symptoms - All personal files missing
All installed apps missing
AVG virus checker finds little
Date problem was noticed 4th November at about 21:00
Recovery tool getdataback for NTFS
The problem:
My parents have dropped their PC over to me, as I work in IT they think I can fix anything :-)
They are not the most IT savvy people and I expect they have allowed some malware to run thinking it was a virus killer.
I can log on to the PC exactly the same as usual and it runs fine and accesses the internet OK.
The problem is that the computer has none of their personal files on either the desktop or in my documents or anywhere. I have also noticed that none of the their personal apps like skype or Office or email or Mozilla or favourites are there either.
It's like the computer was pretty much when they first got it.
I have had a look around their harddrive and noticed that some folders have access denied.
The next step I did was to run a virus scan, which did not show much info bar a couple of tracking cookies.
I have now put on a file recovery application and have found all of the folders like 'my docs' and 'xyz docs', but there is about 11 copies of the same file.
Also there is about 7 different NTFS instances to choose from and they all contain the same files. Given that the HDD is only 60 Gb the recovery estimation is in the terabytes, which seems a bit strange. I recovered their my documents from one of the NTFS instances but nearly all of the word documents are unreadable along with most of their pictures
It's like a virus has installed itself hidden/courrpted/encrypted all the my docs files and then deleted itself.
I have searched and searched the internet for a similar problem but to no avail, so any help or pointers you can give me would really help as I am out of ideas.
Thanks in advance,
Shane.
Data below – OTL.TXT
OTL logfile created on: 23/11/2010 23:06:15 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Louroy\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16386)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
894.00 Mb Total Physical Memory | 370.00 Mb Available Physical Memory | 41.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 33.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 49.46 Gb Total Space | 30.51 Gb Free Space | 61.68% Space Free | Partition Type: NTFS
Drive D: | 11.40 Gb Total Space | 11.31 Gb Free Space | 99.17% Space Free | Partition Type: NTFS
Drive E: | 178.25 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: LOUROY-PC | User Name: Louroy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Louroy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - c:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Launch Manager\OSD.exe (Wistron Corp.)
PRC - C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
PRC - C:\Program Files\Launch Manager\WisLMSvc.exe (Wistron Corp.)
PRC - C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
PRC - C:\Program Files\Launch Manager\WButton.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Users\Louroy\AppData\Local\Temp\GDB4NTFS.exe ()
PRC - C:\Program Files\Launch Manager\OSDCtrl.exe ()
PRC - C:\Program Files\Launch Manager\LaunchAp.exe ()
========== Modules (SafeList) ==========
MOD - C:\Users\Louroy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (OJRVCRBIEDHN) -- C:\Users\Louroy\AppData\Local\Temp\OJRVCRBIEDHN.exe (Sysinternals - www.sysinternals.com)
SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (avgwd) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgfws) -- C:\Program Files\AVG\AVG10\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (IviRegMgr) -- c:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (WisLMSvc) -- C:\Program Files\Launch Manager\WisLMSvc.exe (Wistron Corp.)
SRV - (TestHandler) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (AVGIDSEH) -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) -- C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) -- C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) -- C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) -- C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) -- C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) -- C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) -- C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgfwfd) -- C:\Windows\System32\drivers\avgfwd6x.sys (AVG Technologies CZ, s.r.o.)
DRV - (Lbd) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (SIS163u) -- C:\Windows\System32\drivers\sis163u.sys (Silicon Integrated Systems Corp.)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (RTL8023xp) -- C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (nvraid) NVIDIA nForce -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvatabus) -- C:\Windows\system32\drivers\nvatabus.sys (NVIDIA Corporation)
DRV - (iaStor) -- C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp)
DRV - (Hotkey) -- C:\Windows\System32\drivers\HOTKEY.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/11/06 13:47:30 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2006/09/18 21:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
O4 - HKLM..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe ()
O4 - HKLM..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe ()
O4 - HKLM..\Run: [LMgrVolOSD] C:\Program Files\Launch Manager\OSD.exe (Wistron Corp.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Wbutton] C:\Program Files\Launch Manager\Wbutton.exe ()
O4 - HKCU..\Run: [BrowserChoice] C:\Windows\System32\browserchoice.exe (Microsoft Corporation)
O4 - HKCU..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (Fujitsu Siemens Computers)
O4 - HKCU..\Run: [StartCCC] c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Louroy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/06/09 21:58:56 | 000,000,202 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{40af2356-e862-11df-881a-0016d363e5bc}\Shell - "" = AutoRun
O33 - MountPoints2\{40af2356-e862-11df-881a-0016d363e5bc}\Shell\AutoRun\command - "" = G:\Password.exe -- File not found
O33 - MountPoints2\{5e2c92b4-e894-11df-ad2b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{5e2c92b4-e894-11df-ad2b-806e6f6e6963}\Shell\AutoRun\command - "" = E:\HBCD\WinTools\Autorun.exe -- [2009/06/09 21:58:56 | 000,011,264 | R--- | M] (http://www.hiren.info)
O33 - MountPoints2\{5e2c92b4-e894-11df-ad2b-806e6f6e6963}\Shell\Option1\Command - "" = E:\HBCD\WinTools\Autorun.exe -- [2009/06/09 21:58:56 | 000,011,264 | R--- | M] (http://www.hiren.info)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/11/23 20:43:20 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Louroy\Desktop\OTL.exe
[2010/11/23 12:56:58 | 000,287,232 | ---- | C] (S!Ri.URZ) -- C:\Windows\System32\IEDFix.C.exe
[2010/11/23 12:56:58 | 000,283,648 | ---- | C] (S!Ri.URZ) -- C:\Windows\System32\404Fix.exe
[2010/11/23 12:56:58 | 000,275,968 | ---- | C] (S!Ri.URZ) -- C:\Windows\System32\o4Patch.exe
[2010/11/23 12:56:58 | 000,270,848 | ---- | C] (S!Ri.URZ) -- C:\Windows\System32\Agent.OMZ.Fix.exe
[2010/11/23 12:56:57 | 000,483,192 | ---- | C] (S!Ri) -- C:\Windows\System32\VCCLSID.exe
[2010/11/23 12:56:57 | 000,481,441 | ---- | C] (S!Ri) -- C:\Windows\System32\SrchSTS.exe
[2010/11/23 12:56:57 | 000,305,664 | ---- | C] (S!Ri.URZ) -- C:\Windows\System32\VACFix.exe
[2010/11/23 12:56:57 | 000,288,768 | ---- | C] (S!Ri.URZ) -- C:\Windows\System32\IEDFix.exe
[2010/11/23 12:56:57 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\System32\swxcacls.exe
[2010/11/23 12:56:56 | 000,414,208 | ---- | C] (SteelWerX) -- C:\Windows\System32\swreg.exe
[2010/11/23 12:56:56 | 000,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\Windows\System32\Process.exe
[2010/11/23 12:40:25 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/11/23 12:40:25 | 000,000,000 | ---D | C] -- C:\temp
[2010/11/23 12:39:25 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/11/23 12:35:50 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/11/23 12:35:50 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/11/23 12:35:50 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/11/23 12:35:50 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/11/23 12:06:37 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010/11/23 11:44:41 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/11/23 11:41:10 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/11/23 11:19:51 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010/11/06 18:09:03 | 000,000,000 | -H-D | C] -- C:\$AVG
[2010/11/06 14:48:39 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010/11/06 14:26:42 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2010/11/06 14:26:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2010/11/06 14:24:12 | 000,000,000 | -H-D | C] -- C:\ProgramData\{90FF8911-FC06-4E49-8959-C3CF1CA226BB}
[2010/11/06 14:22:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2010/11/06 14:22:48 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010/11/06 13:53:53 | 000,000,000 | ---D | C] -- C:\Users\Louroy\AppData\Roaming\AVG10
[2010/11/06 13:51:35 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2010/11/06 13:51:05 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Security Toolbar
[2010/11/06 13:46:26 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG10
[2010/11/06 13:46:26 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\AVG
[2010/11/06 13:45:12 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2010/11/06 13:32:26 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2010/11/06 13:32:03 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Louroy\Desktop\mbam-setup-1.46.exe
[2010/11/06 13:32:02 | 004,329,488 | ---- | C] (AVG Technologies) -- C:\Users\Louroy\Desktop\avg_isct_stb_all_2011_1153_free.exe
[2010/11/06 13:31:53 | 125,695,976 | ---- | C] (Lavasoft ) -- C:\Users\Louroy\Desktop\Ad-AwareInstall.exe
[2010/11/05 15:19:41 | 000,000,000 | ---D | C] -- C:\ATI
[2010/11/05 04:27:02 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2010/11/05 04:12:49 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2010/11/04 22:57:48 | 000,000,000 | ---D | C] -- C:\Users\Louroy\AppData\Local\VirtualStore
[2010/11/04 21:52:17 | 000,000,000 | ---D | C] -- C:\ProgramData\fsc-reg
[2010/11/04 21:51:58 | 000,000,000 | ---D | C] -- C:\Users\Louroy\AppData\Roaming\Adobe
[2010/11/04 21:51:57 | 000,000,000 | ---D | C] -- C:\Users\Louroy\AppData\Roaming\ATI
[2010/11/04 21:51:57 | 000,000,000 | ---D | C] -- C:\Users\Louroy\AppData\Local\ATI
[2010/11/04 21:51:43 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Searches
[2010/11/04 21:51:33 | 000,000,000 | ---D | C] -- C:\Users\Louroy\AppData\Roaming\Identities
[2010/11/04 21:51:31 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Contacts
[2010/11/04 21:51:18 | 000,000,000 | --SD | C] -- C:\Users\Louroy\AppData\Roaming\Microsoft
[2010/11/04 21:51:18 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Videos
[2010/11/04 21:51:18 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Saved Games
[2010/11/04 21:51:18 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Pictures
[2010/11/04 21:51:18 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Music
[2010/11/04 21:51:18 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Links
[2010/11/04 21:51:18 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Favorites
[2010/11/04 21:51:18 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Downloads
[2010/11/04 21:51:18 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Documents
[2010/11/04 21:51:18 | 000,000,000 | R--D | C] -- C:\Users\Louroy\Desktop
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\AppData\Local\Temporary Internet Files
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\Templates
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\Start Menu
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\SendTo
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\Recent
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\PrintHood
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\NetHood
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\Documents\My Videos
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\Documents\My Pictures
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\Documents\My Music
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\My Documents
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\Local Settings
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\AppData\Local\History
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\Cookies
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\Application Data
[2010/11/04 21:51:18 | 000,000,000 | -HSD | C] -- C:\Users\Louroy\AppData\Local\Application Data
[2010/11/04 21:51:18 | 000,000,000 | -H-D | C] -- C:\Users\Louroy\AppData
[2010/11/04 21:51:18 | 000,000,000 | ---D | C] -- C:\Users\Louroy\AppData\Local\Temp
[2010/11/04 21:51:18 | 000,000,000 | ---D | C] -- C:\Users\Louroy\AppData\Local\Microsoft
[2010/11/04 21:51:18 | 000,000,000 | ---D | C] -- C:\Users\Louroy\AppData\Roaming\Media Center Programs
========== Files - Modified Within 30 Days ==========
[2010/11/23 22:13:22 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/23 22:13:22 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/23 21:09:18 | 000,623,342 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/11/23 21:09:18 | 000,108,526 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/11/23 20:43:23 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Louroy\Desktop\OTL.exe
[2010/11/23 20:13:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/11/23 14:27:13 | 099,926,758 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2010/11/23 12:57:34 | 000,001,160 | ---- | M] () -- C:\Windows\System32\tmp.reg
[2010/11/23 12:08:47 | 000,001,595 | ---- | M] () -- C:\Users\Public\Desktop\Browser Choice.lnk
[2010/11/23 12:06:42 | 000,238,080 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/11/23 12:06:37 | 113,494,409 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/11/23 12:05:26 | 937,672,704 | -HS- | M] () -- C:\hiberfil.sys
[2010/11/23 12:03:18 | 000,632,241 | ---- | M] () -- C:\Windows\System32\drivers\AVG\iavifw.avm
[2010/11/06 14:48:29 | 000,098,392 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010/11/06 14:24:08 | 000,001,037 | ---- | M] () -- C:\Users\Louroy\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/11/06 14:24:08 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/11/06 13:50:20 | 000,000,836 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2010/11/06 12:44:13 | 004,329,488 | ---- | M] (AVG Technologies) -- C:\Users\Louroy\Desktop\avg_isct_stb_all_2011_1153_free.exe
[2010/11/05 04:27:28 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\UMDF\Msft_User_WpdFs_01_00_00.Wdf
[2010/11/04 21:56:33 | 000,000,949 | ---- | M] () -- C:\Users\Louroy\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/11/04 21:52:16 | 000,001,406 | ---- | M] () -- C:\Users\Louroy\Desktop\First Steps.lnk
========== Files Created - No Company Name ==========
[2010/11/23 14:27:13 | 099,926,758 | ---- | C] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2010/11/23 12:57:34 | 000,001,160 | ---- | C] () -- C:\Windows\System32\tmp.reg
[2010/11/23 12:56:57 | 000,267,264 | ---- | C] () -- C:\Windows\System32\WS2Fix.exe
[2010/11/23 12:56:57 | 000,091,136 | ---- | C] () -- C:\Windows\System32\swsc.exe
[2010/11/23 12:56:57 | 000,051,200 | ---- | C] () -- C:\Windows\System32\dumphive.exe
[2010/11/23 12:35:50 | 000,155,136 | ---- | C] () -- C:\Windows\PEV.exe
[2010/11/23 12:35:50 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/11/23 12:35:50 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/11/23 12:35:50 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/11/23 12:08:47 | 000,001,595 | ---- | C] () -- C:\Users\Public\Desktop\Browser Choice.lnk
[2010/11/23 12:06:17 | 113,494,409 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/11/23 12:03:18 | 000,632,241 | ---- | C] () -- C:\Windows\System32\drivers\AVG\iavifw.avm
[2010/11/06 14:24:08 | 000,001,037 | ---- | C] () -- C:\Users\Louroy\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/11/06 14:24:08 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/11/06 13:50:20 | 000,000,836 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2010/11/05 04:23:07 | 937,672,704 | -HS- | C] () -- C:\hiberfil.sys
[2010/11/04 21:56:33 | 000,000,949 | ---- | C] () -- C:\Users\Louroy\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/11/04 21:52:16 | 000,001,406 | ---- | C] () -- C:\Users\Louroy\Desktop\First Steps.lnk
[2010/11/04 21:51:18 | 000,000,258 | ---- | C] () -- C:\Users\Louroy\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/11/04 21:51:18 | 000,000,240 | ---- | C] () -- C:\Users\Louroy\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2007/04/04 17:19:18 | 000,135,168 | ---- | C] () -- C:\Windows\System32\property.dll
[2007/04/04 16:53:10 | 000,009,867 | ---- | C] () -- C:\Windows\System32\drivers\HOTKEY.sys
[2006/11/02 12:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 10:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006/11/02 07:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/08/11 16:52:02 | 000,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll
========== LOP Check ==========
[2010/11/06 13:53:53 | 000,000,000 | ---D | M] -- C:\Users\Louroy\AppData\Roaming\AVG10
[2010/11/06 14:28:56 | 000,004,792 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >