Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

virus in computer


  • Please log in to reply

#1
jerichoy2j

jerichoy2j

    Member

  • Member
  • PipPip
  • 38 posts
all the buttons and shortcuts on pc have disspeared and pc keeps crashing
also all the files on my hard drives are set as hidden files even the avis and everything
all the programs have dissapeared from the start menu - programs


OTL logfile created on: 30/04/2011 20:18:22 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Ric\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 64.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1397.17 Gb Total Space | 1345.19 Gb Free Space | 96.28% Space Free | Partition Type: NTFS
Drive D: | 1863.01 Gb Total Space | 1.16 Gb Free Space | 0.06% Space Free | Partition Type: NTFS
Drive E: | 1863.01 Gb Total Space | 0.09 Gb Free Space | 0.00% Space Free | Partition Type: NTFS
Drive F: | 1863.01 Gb Total Space | 1.52 Gb Free Space | 0.08% Space Free | Partition Type: NTFS
Drive G: | 1863.01 Gb Total Space | 2.40 Gb Free Space | 0.13% Space Free | Partition Type: NTFS
Drive H: | 1863.01 Gb Total Space | 0.27 Gb Free Space | 0.01% Space Free | Partition Type: NTFS
Drive I: | 1863.01 Gb Total Space | 0.21 Gb Free Space | 0.01% Space Free | Partition Type: NTFS
Drive J: | 1863.01 Gb Total Space | 370.71 Gb Free Space | 19.90% Space Free | Partition Type: NTFS
Drive K: | 1863.01 Gb Total Space | 483.69 Gb Free Space | 25.96% Space Free | Partition Type: NTFS
Drive L: | 1863.01 Gb Total Space | 482.20 Gb Free Space | 25.88% Space Free | Partition Type: NTFS
Drive M: | 1397.26 Gb Total Space | 672.40 Gb Free Space | 48.12% Space Free | Partition Type: NTFS
Drive N: | 1397.26 Gb Total Space | 1397.13 Gb Free Space | 99.99% Space Free | Partition Type: NTFS
Drive O: | 1397.26 Gb Total Space | 1397.13 Gb Free Space | 99.99% Space Free | Partition Type: NTFS
Drive P: | 1397.26 Gb Total Space | 1397.13 Gb Free Space | 99.99% Space Free | Partition Type: NTFS
Drive R: | 1397.26 Gb Total Space | 1397.12 Gb Free Space | 99.99% Space Free | Partition Type: NTFS
Drive S: | 1397.26 Gb Total Space | 1308.92 Gb Free Space | 93.68% Space Free | Partition Type: NTFS
Drive W: | 1397.26 Gb Total Space | 336.64 Gb Free Space | 24.09% Space Free | Partition Type: NTFS
Drive X: | 1397.26 Gb Total Space | 298.86 Gb Free Space | 21.39% Space Free | Partition Type: NTFS
Drive Y: | 1397.26 Gb Total Space | 1218.87 Gb Free Space | 87.23% Space Free | Partition Type: NTFS
Drive Z: | 931.51 Gb Total Space | 647.40 Gb Free Space | 69.50% Space Free | Partition Type: NTFS

Computer Name: HD-SERVER | User Name: Ric | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/30 20:18:07 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Ric\Desktop\OTL.exe
PRC - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/12/20 18:08:56 | 000,443,728 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2010/06/28 22:50:36 | 000,075,048 | -H-- | M] (cyberlink) -- C:\Program Files (x86)\CyberLink\Shared files\brs.exe
PRC - [2010/04/27 03:09:52 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2010/04/12 09:40:16 | 000,180,224 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
PRC - [2010/02/03 00:08:56 | 000,087,336 | -H-- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2009/12/28 15:22:09 | 003,214,272 | ---- | M] (SlySoft, Inc.) -- C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe


========== Modules (SafeList) ==========

MOD - [2011/04/30 20:18:07 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Ric\Desktop\OTL.exe
MOD - [2009/07/14 02:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
MOD - [2009/02/13 17:22:35 | 000,117,696 | ---- | M] (SlySoft, Inc.) -- C:\Program Files (x86)\SlySoft\AnyDVD\ADvdDiscHlp.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/06 02:58:48 | 000,203,776 | ---- | M] (AMD) [Auto | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/04/05 22:13:54 | 000,365,568 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2010/10/28 11:14:30 | 000,357,456 | -H-- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 14:37:14 | 000,517,096 | -H-- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/07/14 02:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2009/07/14 02:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2009/07/14 02:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/04/06 05:11:44 | 009,323,520 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2011/04/06 05:11:44 | 009,323,520 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/04/06 02:21:42 | 000,304,128 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/02/18 17:36:58 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011/01/15 17:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2010/12/20 18:08:40 | 000,024,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2010/12/16 23:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010/11/17 13:04:32 | 000,115,216 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010/08/24 18:29:32 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2010/08/24 18:29:10 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2010/07/21 17:59:28 | 000,045,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2010/04/27 02:30:52 | 000,184,968 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010/04/27 02:29:54 | 000,083,080 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010/02/18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2010/02/12 08:10:12 | 000,066,608 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GenericMount.sys -- (GenericMount)
DRV:64bit: - [2009/12/22 03:26:36 | 000,038,456 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2009/12/19 19:22:10 | 000,121,280 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
DRV:64bit: - [2009/07/14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 21:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/05/05 02:00:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/03/02 00:05:32 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2008/05/06 16:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2008/04/14 13:50:32 | 000,022,056 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SiWinAcc.sys -- (SiFilter)
DRV:64bit: - [2008/04/14 13:50:14 | 000,082,984 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SI3114.sys -- (SI3114)
DRV:64bit: - [2007/10/04 21:47:50 | 000,133,672 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SI3114r.sys -- (SI3114r)
DRV - [2010/06/28 22:50:22 | 000,146,928 | -H-- | M] (CyberLink Corp.) [2011/03/31 21:18:48] [Kernel | Auto | Running] -- C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl -- ({1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC})
DRV - [2009/12/19 19:22:10 | 000,121,280 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 19 E0 5F B4 D6 81 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird


O1 HOSTS File: ([2010/12/17 05:34:42 | 000,000,866 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr.../swdir8d204.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{26fcb3fd-564d-11e0-81f3-1c6f654881dd}\Shell - "" = AutoRun
O33 - MountPoints2\{26fcb3fd-564d-11e0-81f3-1c6f654881dd}\Shell\AutoRun\command - "" = "U:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\U\Shell - "" = AutoRun
O33 - MountPoints2\U\Shell\AutoRun\command - "" = "U:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/30 20:18:06 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Ric\Desktop\OTL.exe
[2011/04/30 18:30:02 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2011/04/30 18:29:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2011/04/30 18:29:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2011/04/30 18:29:13 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2011/04/30 18:28:31 | 000,000,000 | ---D | C] -- C:\Windows\LastGood
[2011/04/30 17:13:54 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/04/30 17:13:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/30 17:13:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/04/30 17:11:55 | 000,000,000 | ---D | C] -- C:\Users\Ric\Desktop\MBAMPRO__1.50.1.1100
[2011/04/30 16:31:16 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\%LOCALAPPDATA%
[2011/04/30 16:30:48 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Roaming\Zoqy
[2011/04/30 16:30:48 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Roaming\Qapee
[2011/04/30 16:30:47 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Roaming\Opemo
[2011/04/30 16:30:47 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Roaming\Acexc
[2011/04/30 14:22:46 | 000,000,000 | ---D | C] -- C:\Dell
[2011/04/30 14:21:54 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell Inc
[2011/04/30 14:21:33 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Local\Deployment
[2011/04/30 14:21:33 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Local\Apps
[2011/04/30 13:32:09 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011/04/27 16:10:06 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Roaming\TOMY
[2011/04/27 16:09:58 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOMY
[2011/04/27 16:09:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TOMY
[2011/04/13 21:59:02 | 000,051,712 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/04/11 11:40:34 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Youtube Music Downloader
[2011/04/11 11:40:33 | 000,000,000 | ---D | C] -- C:\YoutubeMusicDownloader
[2011/04/09 00:00:22 | 000,000,000 | -H-D | C] -- C:\Program Files\DVDFab 8
[2011/04/08 13:45:34 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\SWF Studio
[2011/04/08 13:45:31 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\theRenamer
[2011/04/08 13:45:31 | 000,000,000 | ---D | C] -- C:\Users\Ric\Documents\theRenamer
[2011/04/08 13:45:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\theRenamer
[2011/04/06 02:59:24 | 000,480,256 | ---- | C] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2011/04/06 02:58:48 | 000,203,776 | ---- | C] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2011/04/06 02:57:36 | 000,120,320 | ---- | C] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2011/04/06 02:56:56 | 000,016,384 | ---- | C] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2011/04/06 02:28:02 | 000,058,880 | ---- | C] (AMD) -- C:\Windows\SysNative\coinst.dll
[2011/04/05 22:09:34 | 000,053,760 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/04/04 13:59:22 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Local\Western Digital
[2011/03/31 21:20:01 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Local\Cyberlink
[2011/03/31 21:19:16 | 000,000,000 | -H-D | C] -- C:\Users\Ric\AppData\Roaming\CyberLink
[2011/03/31 21:19:16 | 000,000,000 | ---D | C] -- C:\Users\Ric\Documents\CyberLink
[2011/03/31 21:18:55 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2011/03/31 21:18:47 | 000,000,000 | RH-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 10
[2011/03/31 21:18:31 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\CyberLink
[2011/03/31 21:17:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CyberLink
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/30 20:18:07 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Ric\Desktop\OTL.exe
[2011/04/30 18:31:13 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/30 18:31:13 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/30 18:30:14 | 000,857,112 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/04/30 18:30:14 | 000,721,704 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/04/30 18:30:14 | 000,144,004 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/04/30 18:26:11 | 000,000,306 | -HS- | M] () -- C:\Windows\tasks\Crlxzt.job
[2011/04/30 18:26:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/04/30 18:26:03 | 3219,288,064 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/30 17:13:54 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/30 17:11:13 | 008,936,384 | ---- | M] () -- C:\Users\Ric\Desktop\MBAMPRO__1.50.1.1100.rar
[2011/04/30 16:58:49 | 416,536,545 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/04/30 16:56:01 | 001,006,778 | -H-- | M] () -- C:\Users\Ric\Desktop\rkill.com
[2011/04/30 16:30:48 | 000,135,168 | RHS- | M] () -- C:\Windows\SysWow64\dnsapil.dll
[2011/04/30 16:29:10 | 000,000,946 | -H-- | M] () -- C:\Users\Ric\AppData\Local\7F68A003.il
[2011/04/30 16:29:10 | 000,000,280 | -H-- | M] () -- C:\Users\Ric\AppData\Local\IndexIE_7F68A003.il
[2011/04/30 14:12:05 | 001,046,470 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2011/04/30 13:43:30 | 000,003,635 | -H-- | M] () -- C:\Users\Ric\Desktop\blue bloods 1.5.s2d
[2011/04/30 13:40:56 | 000,003,606 | -H-- | M] () -- C:\Users\Ric\Desktop\CSI- NY 7.5.s2d
[2011/04/21 20:29:10 | 000,000,116 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2011/04/13 21:59:14 | 000,059,904 | ---- | M] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/04/13 21:59:02 | 000,051,712 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/04/11 11:44:54 | 000,000,000 | -H-- | M] () -- C:\Users\Ric\AppData\Roaming\chrtmp
[2011/04/09 00:00:24 | 000,000,824 | -H-- | M] () -- C:\Users\Ric\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2011/04/08 16:18:24 | 000,000,132 | -H-- | M] () -- C:\Users\Ric\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/04/06 22:35:12 | 000,090,899 | -H-- | M] () -- C:\Users\Ric\Desktop\avforums.jpg
[2011/04/06 14:21:20 | 000,006,656 | -H-- | M] () -- C:\Users\Ric\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/06 03:04:00 | 000,156,408 | ---- | M] () -- C:\Windows\SysNative\atiapfxx.blb
[2011/04/06 02:59:24 | 000,480,256 | ---- | M] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2011/04/06 02:58:48 | 000,203,776 | ---- | M] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2011/04/06 02:57:36 | 000,120,320 | ---- | M] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2011/04/06 02:56:56 | 000,016,384 | ---- | M] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2011/04/06 02:31:42 | 000,916,704 | ---- | M] () -- C:\Windows\SysNative\atiumd6a.cap
[2011/04/06 02:28:02 | 000,058,880 | ---- | M] (AMD) -- C:\Windows\SysNative\coinst.dll
[2011/04/06 02:26:16 | 000,916,704 | ---- | M] () -- C:\Windows\SysWow64\atiumdva.cap
[2011/04/05 22:09:50 | 000,061,952 | ---- | M] () -- C:\Windows\SysNative\OVDecode64.dll
[2011/04/05 22:09:34 | 000,053,760 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/04/05 15:26:27 | 000,000,450 | RHS- | M] () -- C:\Users\Ric\ntuser.pol
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/30 17:13:54 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/30 17:11:00 | 008,936,384 | ---- | C] () -- C:\Users\Ric\Desktop\MBAMPRO__1.50.1.1100.rar
[2011/04/30 16:55:59 | 001,006,778 | -H-- | C] () -- C:\Users\Ric\Desktop\rkill.com
[2011/04/30 16:30:48 | 000,135,168 | RHS- | C] () -- C:\Windows\SysWow64\dnsapil.dll
[2011/04/30 16:30:48 | 000,000,306 | -HS- | C] () -- C:\Windows\tasks\Crlxzt.job
[2011/04/30 13:43:30 | 000,003,635 | -H-- | C] () -- C:\Users\Ric\Desktop\blue bloods 1.5.s2d
[2011/04/30 13:40:55 | 000,003,606 | -H-- | C] () -- C:\Users\Ric\Desktop\CSI- NY 7.5.s2d
[2011/04/30 13:32:05 | 416,536,545 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/04/13 21:59:14 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/04/11 11:44:54 | 000,000,000 | -H-- | C] () -- C:\Users\Ric\AppData\Roaming\chrtmp
[2011/04/09 00:00:24 | 000,000,824 | -H-- | C] () -- C:\Users\Ric\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2011/04/06 22:35:55 | 000,090,899 | -H-- | C] () -- C:\Users\Ric\Desktop\avforums.jpg
[2011/04/06 03:04:00 | 000,156,408 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2011/04/06 02:31:42 | 000,916,704 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2011/04/06 02:26:16 | 000,916,704 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2011/04/05 22:09:50 | 000,061,952 | ---- | C] () -- C:\Windows\SysNative\OVDecode64.dll
[2011/04/05 15:26:27 | 000,000,450 | RHS- | C] () -- C:\Users\Ric\ntuser.pol
[2011/03/07 16:38:47 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011/03/01 18:07:08 | 000,003,949 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/02/15 01:32:12 | 000,000,132 | -H-- | C] () -- C:\Users\Ric\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/01/04 16:24:51 | 000,819,200 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011/01/04 16:24:51 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2010/12/21 15:23:23 | 000,108,032 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2010/11/30 19:56:58 | 000,006,656 | -H-- | C] () -- C:\Users\Ric\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/17 12:14:57 | 000,000,082 | -H-- | C] () -- C:\Users\Ric\AppData\Roaming\22.cmd
[2010/11/16 01:53:16 | 000,842,580 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/11/12 02:04:22 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010/11/12 00:59:40 | 000,000,946 | -H-- | C] () -- C:\Users\Ric\AppData\Local\7F68A003.il
[2010/11/12 00:59:40 | 000,000,280 | -H-- | C] () -- C:\Users\Ric\AppData\Local\IndexIE_7F68A003.il
[2010/11/11 20:54:34 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/03/03 19:48:14 | 000,215,144 | R--- | C] () -- C:\Windows\pw32a.dll
[2010/03/03 19:48:14 | 000,215,144 | R--- | C] () -- C:\Windows\patchw32.dll
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2002/10/15 23:54:04 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll

========== LOP Check ==========

[2011/04/30 17:19:13 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\Acexc
[2010/11/13 00:14:20 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\Acronis
[2010/11/16 10:53:12 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\BDREBUILDER
[2011/04/26 21:21:31 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\BitTorrent
[2010/11/11 23:01:29 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\Epson
[2010/12/13 23:43:19 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\ImgBurn
[2010/11/12 01:37:11 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\Leadertech
[2010/11/19 02:24:47 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\mkvtoolnix
[2010/11/12 01:02:32 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\NewsLeecher
[2010/12/18 01:12:03 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\Nord
[2010/12/18 00:52:18 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\Notepad++
[2011/04/30 16:31:49 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\Opemo
[2011/04/30 16:49:58 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\Qapee
[2010/11/15 20:11:19 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\SupRip
[2011/04/27 16:10:06 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\TOMY
[2010/12/13 22:24:58 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\TVRename
[2010/12/18 02:40:27 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\YANFOE
[2011/04/30 17:19:13 | 000,000,000 | -H-D | M] -- C:\Users\Ric\AppData\Roaming\Zoqy
[2011/04/30 18:26:11 | 000,000,306 | -HS- | M] () -- C:\Windows\Tasks\Crlxzt.job
[2011/04/30 16:51:49 | 000,032,556 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

Edited by jerichoy2j, 30 April 2011 - 01:31 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP