Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virus and Malware Found


  • Please log in to reply

#1
simplee55

simplee55

    Member

  • Member
  • PipPipPip
  • 539 posts
Hello Ev-1:


I'm editing this Post because I totally forgot that I should have gone to the Malware Self Help Guide 1st. Let me add, I've been visiting my friend for the Holidays and am going back home tomorrow morning, she and I live in different States. I hope we can accomplish something before I leave.

The reason I'm troubleshooting her PC is because she does not understand any thing Technical and I noticed that her PC was running very sluggish to the point that I thought she was running Dial-up, but in fact, she has Satellite.

So I came here to download some of the Tools to run on her PC that were used on my PC when I was having problems. One of the Tools I ran was Malwarebytes. The program found 56 Infections, two (2) of which are Trojans.

Before I ran Malwarebytes, I ran the REVO Uninstaller and found that she had all kinds of Toolbars on the PC and also MyWebSearch. Which stands to reason why the PC is so sluggish.

Although the System is running a tad bit faster, why, because I cleaned out all Files and Folders with the Tools that I download. I also ran AutoRuns and deleted all the "Files/Folders Not Found".

One more thing I forgot to mention is, her System appears to be "Out-of-Sinc", trying to catch up with itself.

That's pretty much it.

She's running Win-XP

Thank U for any help you can give !!!

simplee55


Here is the OLT Log requested.


OTL logfile created on: 11/26/2010 9:53:56 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Regina\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

382.00 Mb Total Physical Memory | 109.00 Mb Available Physical Memory | 28.00% Memory free
920.00 Mb Paging File | 525.00 Mb Available in Paging File | 57.00% Paging File free
Paging file location(s): C:\pagefile.sys 576 1152 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 27.95 Gb Total Space | 15.78 Gb Free Space | 56.47% Space Free | Partition Type: NTFS

Computer Name: FRANCIS-64108EE | User Name: Regina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Regina\My Documents\Downloads\OTL (2).exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Documents and Settings\Regina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - C:\Program Files\TightVNC\WinVNC.exe (TightVNC Group)
PRC - C:\Program Files\Verizon\SmartBridge\MotiveSB.exe (Motive Communications, Inc.)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\ltmsg.exe (Agere Systems)
PRC - C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Regina\My Documents\Downloads\OTL (2).exe (OldTimer Tools)
MOD - C:\Program Files\Verizon\SmartBridge\SBHook.dll (Motive Communications, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (Iomega Activity Disk2) -- File not found
SRV - (HidServ) -- C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (LiveUpdate Notice Service) -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (winvnc) -- C:\Program Files\TightVNC\WinVNC.exe (TightVNC Group)
SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (Iomega App Services) -- C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)


========== Driver Services (SafeList) ==========

DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (aswTdi) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMon2) -- C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) -- C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (ppa3) -- C:\WINDOWS\system32\DRIVERS\ppa3.sys (Microsoft Corporation)
DRV - (hamachi_oem) -- C:\WINDOWS\system32\drivers\gan_adapter.sys (Applied Networking Inc.)
DRV - (MREMPR5) -- C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5) -- C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (SE2Bobex) -- C:\WINDOWS\system32\drivers\SE2Bobex.sys (MCCI)
DRV - (SE2Bmgmt) Sony Ericsson Device 043 USB WMC Device Management Drivers (WDM) -- C:\WINDOWS\system32\drivers\SE2Bmgmt.sys (MCCI)
DRV - (SE2Bmdm) -- C:\WINDOWS\system32\drivers\SE2Bmdm.sys (MCCI)
DRV - (SE2Bmdfl) -- C:\WINDOWS\system32\drivers\SE2Bmdfl.sys (MCCI)
DRV - (SE2Bbus) Sony Ericsson Device 043 Driver driver (WDM) -- C:\WINDOWS\system32\drivers\SE2Bbus.sys (MCCI)
DRV - (se2Bnd5) Sony Ericsson Device 043 USB Ethernet Emulation SEMC43 (NDIS) -- C:\WINDOWS\system32\drivers\se2Bnd5.sys (MCCI)
DRV - (se2Bunic) Sony Ericsson Device 043 USB Ethernet Emulation SEMC43 (WDM) -- C:\WINDOWS\system32\drivers\se2Bunic.sys (MCCI)
DRV - (dfmirage) -- C:\WINDOWS\system32\drivers\dfmirage.sys (DemoForge, LLC)
DRV - (AN983) -- C:\WINDOWS\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (iAimFP4) -- C:\WINDOWS\system32\drivers\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimFP3) -- C:\WINDOWS\system32\drivers\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimTV5) -- C:\WINDOWS\system32\drivers\wATV10nt.sys (Intel® Corporation)
DRV - (iAimTV4) -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys (Intel® Corporation)
DRV - (iAimTV6) -- C:\WINDOWS\system32\drivers\wATV06nt.sys (Intel® Corporation)
DRV - (iAimTV3) -- C:\WINDOWS\system32\drivers\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV1) -- C:\WINDOWS\system32\drivers\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV0) -- C:\WINDOWS\system32\drivers\wATV01nt.sys (Intel® Corporation)
DRV - (iAimFP7) -- C:\WINDOWS\system32\drivers\wADV09NT.sys (Intel® Corporation)
DRV - (iAimFP5) -- C:\WINDOWS\system32\drivers\wADV07nt.sys (Intel® Corporation)
DRV - (iAimFP6) -- C:\WINDOWS\system32\drivers\wADV08NT.sys (Intel® Corporation)
DRV - (i81x) -- C:\WINDOWS\system32\drivers\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0) -- C:\WINDOWS\system32\drivers\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1) -- C:\WINDOWS\system32\drivers\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2) -- C:\WINDOWS\system32\drivers\wADV05NT.sys (Intel® Corporation)
DRV - (ltmodem5) -- C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (iomdisk) -- C:\WINDOWS\System32\DRIVERS\iomdisk.sys (Iomega Corporation)
DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (ac97intc) Intel® 82801 Audio Driver Install Service (WDM) -- C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://home.peoplepc.com/search

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ww2.cox.com/m...arbara/home.cox
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2006/12/23 10:06:19 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2006/12/23 10:22:13 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2006/12/23 10:21:35 | 000,066,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\jar50.dll
[2006/12/23 10:21:36 | 000,054,352 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2006/12/23 10:21:36 | 000,034,928 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\myspell.dll
[2006/12/23 10:21:41 | 000,046,696 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2006/12/23 10:21:41 | 000,172,120 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\xpinstal.dll
[2006/04/15 10:21:28 | 001,312,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll

O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Verizon Broadband Toolbar) - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll ()
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (no name) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Verizon Broadband Toolbar) - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Verizon Broadband Toolbar) - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll ()
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [LTMSG] C:\WINDOWS\ltmsg.exe (Agere Systems)
O4 - HKLM..\Run: [Motive SmartBridge] C:\Program Files\Verizon\SmartBridge\MotiveSB.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [WinVNC] C:\Program Files\TightVNC\WinVNC.exe (TightVNC Group)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyds...DSL/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akama...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} https://quicken.ehos...s/custappx3.cab (Talisma NetAgent Customer ActiveX Control version 3)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.micros...ontent/opuc.cab (Office Update Installation Engine)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1127754157117 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} http://photos.msn.co....cab?10,0,910,0 (DigWebHelper Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Regina\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Regina\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/02/12 11:49:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/25 19:00:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2010/11/25 17:39:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2010/11/25 17:39:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2010/11/25 17:39:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2010/11/25 17:39:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2010/11/25 17:07:07 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2010/11/25 17:06:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\EHome
[2010/11/25 16:37:28 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Regina\IETldCache
[2010/11/25 15:35:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010/11/25 15:26:09 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/11/24 16:10:17 | 004,651,904 | ---- | C] (Auslogics Software Pty Ltd ) -- C:\Documents and Settings\Regina\Desktop\disk-defrag-setup.exe
[2010/11/24 16:08:03 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Regina\Desktop\TFC.exe
[2010/11/24 15:06:48 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2010/11/24 15:06:26 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/11/24 14:51:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Regina\Local Settings\Application Data\Sunbelt Software
[2010/11/24 14:49:06 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{E961CE1B-C3EA-4882-9F67-F859B555D097}
[2010/11/24 14:45:56 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010/11/24 14:45:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/11/23 22:50:49 | 000,017,744 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/11/23 22:50:48 | 000,165,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010/11/23 22:50:45 | 000,023,376 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/11/23 22:50:42 | 000,046,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/11/23 22:50:37 | 000,100,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/11/23 22:50:37 | 000,094,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010/11/23 22:50:35 | 000,028,880 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/11/23 22:49:21 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010/11/23 22:49:19 | 000,167,592 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010/11/23 22:48:31 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010/11/23 22:48:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/11/23 21:52:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
[2010/11/23 21:19:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Regina\Desktop\DIFFERENT PROGRAMS !!!
[2010/11/23 20:45:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Regina\Application Data\Malwarebytes
[2010/11/23 20:44:42 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/23 20:44:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/11/23 20:44:38 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/23 20:44:38 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/23 15:38:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Regina\Local Settings\Application Data\VS Revo Group
[2010/11/23 15:37:28 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2010/11/03 12:01:40 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/26 09:27:09 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-57989841-1993962763-1060284298-1007UA.job
[2010/11/26 08:54:23 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/11/26 08:50:33 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/26 08:48:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/26 08:48:51 | 401,133,568 | -HS- | M] () -- C:\hiberfil.sys
[2010/11/25 19:12:14 | 000,002,314 | ---- | M] () -- C:\Documents and Settings\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/11/25 19:12:11 | 000,000,928 | ---- | M] () -- C:\Documents and Settings\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/11/25 19:06:38 | 000,441,454 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/25 19:06:38 | 000,071,264 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/11/25 18:58:17 | 000,130,096 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/25 17:24:11 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/11/25 16:38:13 | 000,000,858 | ---- | M] () -- C:\Documents and Settings\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/11/25 15:11:40 | 000,002,314 | ---- | M] () -- C:\Documents and Settings\Regina\Desktop\Google Chrome.lnk
[2010/11/25 15:11:37 | 000,000,928 | ---- | M] () -- C:\Documents and Settings\Regina\Desktop\Ad-Aware.lnk
[2010/11/25 15:10:50 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Outlook.lnk
[2010/11/25 15:09:43 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Regina\Desktop\Outlook.lnk
[2010/11/25 15:09:31 | 000,000,843 | ---- | M] () -- C:\Documents and Settings\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/11/24 16:09:41 | 004,651,904 | ---- | M] (Auslogics Software Pty Ltd ) -- C:\Documents and Settings\Regina\Desktop\disk-defrag-setup.exe
[2010/11/24 16:04:28 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Regina\Desktop\TFC.exe
[2010/11/24 15:06:19 | 000,098,392 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/11/24 14:48:58 | 000,000,910 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/11/23 22:50:51 | 000,001,743 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/11/23 22:50:38 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/11/23 22:27:02 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-57989841-1993962763-1060284298-1007Core.job
[2010/11/23 21:34:29 | 000,000,383 | ---- | M] () -- C:\Documents and Settings\Regina\Desktop\My Documents.lnk
[2010/11/23 21:34:24 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Regina\Desktop\My Computer.lnk
[2010/11/23 21:27:42 | 000,000,960 | ---- | M] () -- C:\Documents and Settings\Regina\Desktop\Revo Uninstaller.lnk
[2010/11/03 12:26:33 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/11/03 12:26:33 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/10/31 08:12:47 | 000,004,184 | ---- | M] () -- C:\Documents and Settings\Regina\My Documents\FW Trust final dist.htm
[2010/10/31 01:02:00 | 000,015,128 | ---- | M] () -- C:\Documents and Settings\Regina\My Documents\Completed Notice Regarding the Trust.docx
[2010/10/31 01:02:00 | 000,012,975 | ---- | M] () -- C:\Documents and Settings\Regina\My Documents\Final Distribution checks.docx
[2010/10/28 13:01:57 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Regina\My Documents\PD- #A-200.doc
[2010/10/28 12:41:36 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\Regina\My Documents\FM - Peggy Wentz #C-304.doc
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/25 19:12:14 | 000,002,314 | ---- | C] () -- C:\Documents and Settings\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/11/25 19:12:11 | 000,000,928 | ---- | C] () -- C:\Documents and Settings\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/11/25 16:38:13 | 000,000,858 | ---- | C] () -- C:\Documents and Settings\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/11/25 15:10:50 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Outlook.lnk
[2010/11/25 15:10:07 | 000,000,846 | ---- | C] () -- C:\Documents and Settings\Regina\Desktop\Internet Explorer.lnk
[2010/11/25 15:09:31 | 000,000,843 | ---- | C] () -- C:\Documents and Settings\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/11/24 15:12:26 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/11/24 14:48:58 | 000,000,928 | ---- | C] () -- C:\Documents and Settings\Regina\Desktop\Ad-Aware.lnk
[2010/11/24 14:48:58 | 000,000,910 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/11/24 09:22:07 | 000,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
[2010/11/24 09:19:33 | 000,001,261 | ---- | C] () -- C:\WINDOWS\System32\pid.inf
[2010/11/24 09:18:15 | 000,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2010/11/24 09:17:45 | 000,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
[2010/11/23 22:50:51 | 000,001,743 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/11/23 22:15:13 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Regina\Desktop\Outlook.lnk
[2010/11/23 21:34:29 | 000,000,383 | ---- | C] () -- C:\Documents and Settings\Regina\Desktop\My Documents.lnk
[2010/11/23 21:34:24 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Regina\Desktop\My Computer.lnk
[2010/11/23 21:27:42 | 000,000,960 | ---- | C] () -- C:\Documents and Settings\Regina\Desktop\Revo Uninstaller.lnk
[2010/10/31 08:12:47 | 000,004,184 | ---- | C] () -- C:\Documents and Settings\Regina\My Documents\FW Trust final dist.htm
[2010/10/31 01:02:00 | 000,015,128 | ---- | C] () -- C:\Documents and Settings\Regina\My Documents\Completed Notice Regarding the Trust.docx
[2010/10/31 01:02:00 | 000,012,975 | ---- | C] () -- C:\Documents and Settings\Regina\My Documents\Final Distribution checks.docx
[2010/10/28 10:51:24 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\Regina\My Documents\FM - Peggy Wentz #C-304.doc
[2010/10/28 10:14:30 | 000,022,016 | ---- | C] () -- C:\Documents and Settings\Regina\My Documents\PD- #A-200.doc
[2009/07/26 12:50:51 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Regina\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/04 12:41:31 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2008/02/04 12:37:40 | 000,001,697 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/01/26 11:50:02 | 000,006,048 | ---- | C] () -- C:\WINDOWS\System32\MCC16.dll
[2007/01/13 14:42:31 | 000,000,253 | ---- | C] () -- C:\WINDOWS\_delis43.ini
[2006/10/06 14:35:26 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\nicmgr.dll
[2006/09/26 23:30:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\mngui.INI
[2006/07/02 20:04:42 | 000,000,395 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2005/09/26 11:25:58 | 000,002,014 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2005/07/04 18:14:17 | 000,012,062 | ---- | C] () -- C:\WINDOWS\System32\drivers\MTiCtwl.sys
[2005/05/08 19:56:19 | 000,001,060 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2005/05/03 21:22:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2005/04/23 17:59:32 | 000,000,052 | ---- | C] () -- C:\WINDOWS\intuprof.ini
[2005/03/11 17:12:10 | 000,000,059 | ---- | C] () -- C:\WINDOWS\INTUIT.INI
[2005/02/14 21:30:50 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2005/02/14 21:29:19 | 000,000,021 | ---- | C] () -- C:\WINDOWS\CS_setup.ini
[2005/02/14 11:28:00 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2005/02/14 11:14:22 | 000,000,196 | ---- | C] () -- C:\WINDOWS\EPSON 1260_1660 Installer.ini
[2005/02/12 21:14:55 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/02/12 19:40:25 | 000,000,028 | ---- | C] () -- C:\WINDOWS\ICOA.INI
[2005/02/12 19:39:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QFN.ini
[2005/02/12 19:39:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QDQICK.ini
[2005/02/12 19:05:43 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\CNMVS3m.DLL
[2005/02/11 13:27:31 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2001/07/07 03:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[1999/01/22 10:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2010/11/23 22:48:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2007/03/27 10:39:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/11/24 14:49:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{E961CE1B-C3EA-4882-9F67-F859B555D097}
[2010/10/19 11:16:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Regina\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/08/24 18:35:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Regina\Application Data\PDF Viewer
[2010/11/26 08:54:23 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========

< End of report >

Edited by simplee55, 26 November 2010 - 01:38 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP