when i click on a google link it keeps redirecting me to other random websites..
i have done a scan with avg free and malwarebytes and they arent picking anything up..
super anti spyware is picking up an adware tracking cookie but seems to be unable to get rid of it because its there again when i do another scan..
its not doing it all the time,but most of the time,enough to be very annoying
any help would be much appreciated thanks...
heres the(updated) OTL log...
OTL logfile created on: 27/06/2011 3:48:41 PM - Run 3
OTL by OldTimer - Version 3.2.24.1 Folder = E:\Documents and Settings\Troy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1023.48 Mb Total Physical Memory | 471.79 Mb Available Physical Memory | 46.10% Memory free
2.90 Gb Paging File | 2.23 Gb Available in Paging File | 76.68% Paging File free
Paging file location(s): E:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = E: | %SystemRoot% = E:\WINDOWS | %ProgramFiles% = E:\Program Files
Drive C: | 111.79 Gb Total Space | 102.55 Gb Free Space | 91.74% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive E: | 104.01 Gb Total Space | 13.48 Gb Free Space | 12.96% Space Free | Partition Type: NTFS
Drive F: | 361.75 Gb Total Space | 32.77 Gb Free Space | 9.06% Space Free | Partition Type: NTFS
Drive I: | 931.51 Gb Total Space | 4.40 Gb Free Space | 0.47% Space Free | Partition Type: NTFS
Computer Name: TROY | User Name: Troy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/06/27 15:48:13 | 000,579,072 | ---- | M] (OldTimer Tools) -- E:\Documents and Settings\Troy\Desktop\OTL.exe
PRC - [2011/06/24 20:06:10 | 000,924,632 | ---- | M] (Mozilla Corporation) -- E:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/06/01 14:10:00 | 000,821,080 | ---- | M] (IObit) -- E:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
PRC - [2011/06/01 14:09:58 | 004,385,112 | ---- | M] (IObit) -- E:\Program Files\IObit\IObit Malware Fighter\IMF.exe
PRC - [2011/05/30 16:50:20 | 003,378,688 | ---- | M] (IObit) -- E:\Program Files\IObit\Advanced SystemCare 4\ASC.exe
PRC - [2011/05/28 14:46:56 | 000,803,728 | ---- | M] (IObit) -- E:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
PRC - [2011/05/28 14:46:56 | 000,412,560 | ---- | M] (IObit) -- E:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
PRC - [2011/05/28 14:46:56 | 000,353,168 | ---- | M] (IObit) -- E:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
PRC - [2010/04/29 15:39:34 | 000,304,464 | ---- | M] (Malwarebytes Corporation) -- E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2011/06/27 15:48:13 | 000,579,072 | ---- | M] (OldTimer Tools) -- E:\Documents and Settings\Troy\Desktop\OTL.exe
MOD - [2010/08/24 02:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/06/01 14:10:00 | 000,821,080 | ---- | M] (IObit) [Auto | Running] -- E:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
SRV - [2011/05/28 14:46:56 | 000,353,168 | ---- | M] (IObit) [Auto | Running] -- E:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe -- (AdvancedSystemCareService)
SRV - [2010/04/29 15:39:34 | 000,304,464 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
========== Driver Services (SafeList) ==========
DRV - [2011/04/27 19:18:34 | 000,239,472 | ---- | M] () [File_System | On_Demand | Running] -- E:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys -- (FileMonitor)
DRV - [2011/03/23 01:00:08 | 000,016,080 | ---- | M] (IObit.com) [Kernel | On_Demand | Running] -- E:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys -- (UrlFilter)
DRV - [2011/03/23 01:00:06 | 000,030,368 | ---- | M] (IObit.com) [Kernel | On_Demand | Running] -- E:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys -- (RegFilter)
DRV - [2011/02/23 17:04:32 | 000,013,496 | ---- | M] () [Kernel | Boot | Running] -- E:\WINDOWS\System32\Drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2010/05/18 15:54:57 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- E:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- E:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2009/06/17 22:24:15 | 000,092,544 | ---- | M] (Midiman/M-Audio) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\deltafw.sys -- (DELTAFW)
DRV - [2009/06/17 22:24:15 | 000,013,312 | ---- | M] (Midiman/M-Audio) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\mafwboot.sys -- (MAFWBOOT) Bootloader Service for M-Audio FW Driver (WDM)
DRV - [2008/12/22 11:06:02 | 000,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- E:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2008/12/22 11:06:00 | 000,008,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- E:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2008/12/22 11:05:58 | 000,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- E:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2008/08/01 18:36:26 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008/08/01 18:36:20 | 000,054,784 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008/05/06 16:01:50 | 000,016,512 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- E:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [2008/04/14 00:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008/01/24 16:36:16 | 004,127,488 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2007/04/16 21:46:00 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2005/10/28 06:46:14 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [2005/10/27 20:46:44 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2005/09/30 03:01:51 | 000,066,048 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- E:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2005/08/10 22:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- E:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005/05/16 23:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- E:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yoower.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "MyAshampoo Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=642886"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.jzip.com/"
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}:3.2.5.2
FF - prefs.js..keyword.URL: "http://search.yahoo....type=642886&p="
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2011/06/24 20:06:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2011/02/12 17:38:12 | 000,000,000 | ---D | M]
[2009/06/09 06:35:38 | 000,000,000 | ---D | M] (No name found) -- E:\Documents and Settings\Troy\Application Data\Mozilla\Extensions
[2011/06/24 21:20:43 | 000,000,000 | ---D | M] (No name found) -- E:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\xt0rtjsz.default\extensions
[2009/09/02 09:22:05 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- E:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\xt0rtjsz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/09 19:26:12 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- E:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\xt0rtjsz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/06/24 21:20:40 | 000,000,000 | ---D | M] (Softonic-Eng7 Community Toolbar) -- E:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\xt0rtjsz.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
[2011/06/24 21:20:41 | 000,000,000 | ---D | M] (MyAshampoo Community Toolbar) -- E:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\xt0rtjsz.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
[2011/06/24 21:20:43 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- E:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\xt0rtjsz.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/06/15 16:49:48 | 000,000,000 | ---D | M] (Conduit Engine) -- E:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\xt0rtjsz.default\extensions\[email protected]
[2011/05/25 16:15:26 | 000,000,923 | ---- | M] () -- E:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\xt0rtjsz.default\searchplugins\conduit.xml
[2009/06/23 19:26:18 | 000,001,632 | ---- | M] () -- E:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\xt0rtjsz.default\searchplugins\live-search.xml
[2009/07/11 10:56:50 | 000,001,196 | ---- | M] () -- E:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\xt0rtjsz.default\searchplugins\winamp-search.xml
[2011/03/06 20:38:43 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2011/06/24 20:06:10 | 000,142,296 | ---- | M] (Mozilla Foundation) -- E:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 18:00:00 | 000,001,538 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 18:00:00 | 000,002,252 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 18:00:00 | 000,000,947 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 18:00:00 | 000,001,180 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/03/06 20:38:17 | 000,002,050 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchdesktop.xml
[2010/01/01 18:00:00 | 000,001,135 | ---- | M] () -- E:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2011/06/23 16:16:47 | 000,000,098 | ---- | M]) - E:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - No CLSID value found.
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - E:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - E:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [NvCplDaemon] E:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] E:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] E:\WINDOWS\System32\nwiz.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O15 - HKCU\..Trusted Domains: msn.com ([www] http in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1244489369402 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O20 - AppInit_DLLs: (E:\PROGRA~1\WINDOW~3\Datamngr\datamngr.dll) - File not found
O20 - AppInit_DLLs: (E:\PROGRA~1\WINDOW~3\Datamngr\IEBHO.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - E:\Program Files\SUPERAntiSpyware\SASWINLO.dll - E:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: E:\Documents and Settings\Troy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: E:\Documents and Settings\Troy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{004b3f73-95dc-11de-a6c5-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{004b3f73-95dc-11de-a6c5-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{004b3f73-95dc-11de-a6c5-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNAUT~1\autorun.pif
O33 - MountPoints2\{004b3f74-95dc-11de-a6c5-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{004b3f74-95dc-11de-a6c5-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{004b3f74-95dc-11de-a6c5-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe W32PT.dll.vbs
O33 - MountPoints2\{40728aa4-0a8c-11e0-a86d-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{40728aa4-0a8c-11e0-a86d-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{40728aa4-0a8c-11e0-a86d-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe W32PT.dll.vbs
O33 - MountPoints2\{7399548e-d766-11df-a840-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{7399548e-d766-11df-a840-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7399548e-d766-11df-a840-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe W32PT.dll.vbs
O33 - MountPoints2\{7e030862-5b33-11de-9e75-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{7e030862-5b33-11de-9e75-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7e030862-5b33-11de-9e75-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe W32PT.dll.vbs
O33 - MountPoints2\{7f64555e-c2b0-11df-a833-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{7f64555e-c2b0-11df-a833-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7f64555e-c2b0-11df-a833-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe W32PT.dll.vbs
O33 - MountPoints2\{85e8d6da-9b2d-11de-a6d3-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{85e8d6da-9b2d-11de-a6d3-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{85e8d6da-9b2d-11de-a6d3-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe W32PT.dll.vbs
O33 - MountPoints2\{b6c18256-9b06-11de-a6d2-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{b6c18256-9b06-11de-a6d2-044b80808003}\Shell\1\Command - "" = RUNAUT~1\autorun.pif
O33 - MountPoints2\{b6c18256-9b06-11de-a6d2-044b80808003}\Shell\2\Command - "" = RUNAUT~1\autorun.pif
O33 - MountPoints2\{b6c18256-9b06-11de-a6d2-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b6c18256-9b06-11de-a6d2-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNAUT~1\autorun.pif
O33 - MountPoints2\{c2a90220-be0a-11de-a717-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{c2a90220-be0a-11de-a717-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c2a90220-be0a-11de-a717-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe W32PT.dll.vbs
O33 - MountPoints2\{c34a905e-d282-11de-a734-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{c34a905e-d282-11de-a734-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c34a905e-d282-11de-a734-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe W32PT.dll.vbs
O33 - MountPoints2\{dc5c31ed-69e1-11de-a65f-044b80808003}\Shell - "" = AutoRun
O33 - MountPoints2\{dc5c31ed-69e1-11de-a65f-044b80808003}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{dc5c31ed-69e1-11de-a65f-044b80808003}\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe W32PT.dll.vbs
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\M\Shell\AutoRun\command - "" = E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe W32PT.dll.vbs
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/27 15:48:12 | 000,579,072 | ---- | C] (OldTimer Tools) -- E:\Documents and Settings\Troy\Desktop\OTL.exe
[2011/06/27 13:52:29 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Desktop\smart defrag 2
[2011/06/27 11:33:57 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Application Data\IObit
[2011/06/27 11:27:02 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Local Settings\Application Data\MyAshampoo
[2011/06/27 11:23:47 | 000,000,000 | RH-D | C] -- E:\Documents and Settings\Troy\Recent
[2011/06/26 18:17:10 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Desktop\Metaphorical Cloud - Morphing - MP3 320
[2011/06/26 09:59:46 | 000,000,000 | ---D | C] -- E:\WINDOWS\System32\winrm
[2011/06/26 09:59:46 | 000,000,000 | ---D | C] -- E:\WINDOWS\System32\WindowsPowerShell
[2011/06/26 09:59:46 | 000,000,000 | ---D | C] -- E:\WINDOWS\System32\GroupPolicy
[2011/06/26 09:59:38 | 000,000,000 | -H-D | C] -- E:\WINDOWS\$968930Uinstall_KB968930$
[2011/06/26 09:46:59 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Start Menu\Programs\IObit Malware Fighter
[2011/06/26 09:46:36 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare 4
[2011/06/26 09:46:34 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Application Data\IObit
[2011/06/26 09:45:21 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Start Menu\Programs\Smart Defrag 2
[2011/06/26 09:45:19 | 000,000,000 | ---D | C] -- E:\Program Files\IObit
[2011/06/26 09:16:35 | 000,000,000 | ---D | C] -- E:\WINDOWS\pss
[2011/06/25 18:46:49 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Desktop\Tone2.VST.Bundle.Suite.Various.Crack.Teams
[2011/06/24 11:46:21 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Application Data\NCH Swift Sound
[2011/06/23 16:16:45 | 000,000,000 | ---D | C] -- E:\_OTM
[2011/06/23 16:14:52 | 000,000,000 | ---D | C] -- E:\WINDOWS\ERDNT
[2011/06/23 15:54:49 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Start Menu\Programs\Sonnox Plugins
[2011/06/23 15:54:48 | 000,000,000 | ---D | C] -- E:\Program Files\Sonnox
[2011/06/23 15:10:59 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/06/23 15:10:55 | 000,000,000 | ---D | C] -- E:\Program Files\Spybot - Search & Destroy
[2011/06/23 14:48:06 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Start Menu\Programs\Google Chrome
[2011/06/23 13:20:03 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Local Settings\Application Data\MediaGet2
[2011/06/21 02:48:16 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Desktop\gate-sp-00
[2011/06/20 19:43:56 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Start Menu\Programs\Xilisoft
[2011/06/20 09:38:24 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/20 09:38:22 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- E:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/06/20 09:38:17 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- E:\WINDOWS\System32\drivers\mbam.sys
[2011/06/20 09:38:17 | 000,000,000 | ---D | C] -- E:\Program Files\Malwarebytes' Anti-Malware
[2011/06/18 10:11:02 | 000,000,000 | ---D | C] -- E:\Documents and Settings\NetworkService\Local Settings\Application Data\MyAshampoo
[2011/06/14 18:06:48 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Start Menu\Programs\Ashampoo
[2011/06/14 18:06:40 | 000,000,000 | ---D | C] -- E:\Program Files\Ashampoo
[2011/06/14 18:00:48 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Application Data\WinZip
[2011/06/14 09:08:03 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Local Settings\Application Data\Xilisoft
[2011/06/14 09:08:00 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Application Data\Xilisoft
[2011/06/12 19:45:10 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\My Documents\Soulseek Chat Logs
[2011/06/10 11:13:03 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\Application Data\iZotope
[2011/06/10 11:06:48 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Troy\My Documents\iZotope Nectar
[2011/06/10 11:06:48 | 000,000,000 | ---D | C] -- E:\Program Files\iZotope
[2011/06/03 11:51:31 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Start Menu\Programs\Cool Edit Pro 2.1
[2011/06/03 11:43:13 | 000,000,000 | ---D | C] -- E:\Program Files\coolpro2
========== Files - Modified Within 30 Days ==========
[2011/06/27 15:48:13 | 000,579,072 | ---- | M] (OldTimer Tools) -- E:\Documents and Settings\Troy\Desktop\OTL.exe
[2011/06/27 15:30:04 | 000,308,350 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\gg.flp
[2011/06/27 14:52:01 | 000,000,922 | ---- | M] () -- E:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-220523388-436374069-725345543-1003Core.job
[2011/06/27 14:52:00 | 000,000,974 | ---- | M] () -- E:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-220523388-436374069-725345543-1003UA.job
[2011/06/27 14:49:17 | 000,311,885 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\aaa.flp
[2011/06/27 13:50:54 | 000,000,278 | ---- | M] () -- E:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/06/27 13:02:01 | 000,215,383 | ---- | M] () -- E:\WINDOWS\System32\nvapps.xml
[2011/06/27 13:01:58 | 000,002,206 | ---- | M] () -- E:\WINDOWS\System32\wpa.dbl
[2011/06/27 13:01:57 | 000,000,268 | ---- | M] () -- E:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/06/27 12:55:49 | 000,000,304 | -HS- | M] () -- E:\WINDOWS\tasks\igofhhdr.job
[2011/06/27 12:55:43 | 000,002,048 | --S- | M] () -- E:\WINDOWS\bootstat.dat
[2011/06/27 11:19:50 | 000,332,071 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\vvvv.flp
[2011/06/27 02:00:00 | 000,000,340 | ---- | M] () -- E:\WINDOWS\tasks\AdobeAAMUpdater-1.0-TROY-Troy.job
[2011/06/26 12:35:02 | 000,000,016 | ---- | M] () -- E:\WINDOWS\System32\w3data.vss
[2011/06/26 12:35:02 | 000,000,016 | ---- | M] () -- E:\WINDOWS\System32\msvcsv60.dll
[2011/06/26 12:35:02 | 000,000,016 | ---- | M] () -- E:\WINDOWS\msocreg32.dat
[2011/06/26 09:46:59 | 000,000,832 | ---- | M] () -- E:\Documents and Settings\All Users\Desktop\IObit Malware Fighter.lnk
[2011/06/26 09:46:36 | 000,000,898 | ---- | M] () -- E:\Documents and Settings\Troy\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/06/26 09:46:36 | 000,000,880 | ---- | M] () -- E:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk
[2011/06/26 09:45:21 | 000,000,829 | ---- | M] () -- E:\Documents and Settings\All Users\Desktop\Smart Defrag 2.lnk
[2011/06/26 09:03:38 | 004,295,472 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\Kenji Kawai - Ghost In The Shell - Original Soundtrack - 01 - M01 Making of Cyborg (Chant I).MP3
[2011/06/25 19:54:48 | 000,930,517 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\jjjj.flp
[2011/06/25 13:24:28 | 000,296,070 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\gggggggg.flp
[2011/06/25 10:11:00 | 000,000,284 | ---- | M] () -- E:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/24 12:58:55 | 000,173,470 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\fast one.flp
[2011/06/23 16:16:47 | 000,000,098 | ---- | M] () -- E:\WINDOWS\System32\drivers\etc\Hosts
[2011/06/23 16:08:10 | 000,592,045 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\verynice1.flp
[2011/06/23 15:10:59 | 000,000,939 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\Spybot - Search & Destroy.lnk
[2011/06/23 14:48:08 | 000,002,283 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\Google Chrome.lnk
[2011/06/23 14:48:08 | 000,002,261 | ---- | M] () -- E:\Documents and Settings\Troy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/06/21 03:04:17 | 000,432,356 | ---- | M] () -- E:\WINDOWS\System32\perfh009.dat
[2011/06/21 03:04:17 | 000,067,312 | ---- | M] () -- E:\WINDOWS\System32\perfc009.dat
[2011/06/20 19:43:56 | 000,001,772 | ---- | M] () -- E:\Documents and Settings\Troy\Application Data\Microsoft\Internet Explorer\Quick Launch\Xilisoft DVD Creator 6.lnk
[2011/06/20 19:43:56 | 000,001,754 | ---- | M] () -- E:\Documents and Settings\All Users\Desktop\Xilisoft DVD Creator 6.lnk
[2011/06/20 13:10:54 | 000,507,644 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\ccc.flp
[2011/06/20 09:38:24 | 000,000,702 | ---- | M] () -- E:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/17 08:49:37 | 000,126,976 | RHS- | M] () -- E:\WINDOWS\System32\vbisurfn.dll
[2011/06/16 11:49:34 | 000,000,854 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\Adobe Photoshop CS5.1.lnk
[2011/06/15 11:44:18 | 000,183,157 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\Itinerary.pdf
[2011/06/14 18:06:49 | 000,000,872 | ---- | M] () -- E:\Documents and Settings\All Users\Desktop\Ashampoo Burning Studio 2010.lnk
[2011/06/14 17:41:49 | 000,034,308 | ---- | M] () -- E:\Documents and Settings\All Users\Application Data\mazuki.dll
[2011/06/06 14:32:51 | 000,000,354 | ---- | M] () -- E:\WINDOWS\System32\q3p20qj.tgz
[2011/06/06 14:32:50 | 000,000,114 | ---- | M] () -- E:\WINDOWS\System32\prsgrc.tgz
[2011/06/06 14:32:50 | 000,000,100 | ---- | M] () -- E:\WINDOWS\System32\prsgrc.dll
[2011/06/06 14:32:50 | 000,000,086 | ---- | M] () -- E:\WINDOWS\System32\ssprs.tgz
[2011/06/05 19:56:31 | 000,389,217 | ---- | M] () -- E:\Documents and Settings\Troy\Desktop\Allen Carr-Easy Way To Stop Smoking.pdf
[2011/06/03 11:51:31 | 000,000,688 | ---- | M] () -- E:\Documents and Settings\All Users\Desktop\Cool Edit Pro 2.1.lnk
========== Files Created - No Company Name ==========
[2011/06/27 14:49:17 | 000,311,885 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\aaa.flp
[2011/06/27 12:41:54 | 000,308,350 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\gg.flp
[2011/06/26 12:04:14 | 000,332,071 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\vvvv.flp
[2011/06/26 10:00:45 | 000,225,262 | ---- | C] () -- E:\WINDOWS\System32\dllcache\msimain.sdb
[2011/06/26 09:46:59 | 000,000,832 | ---- | C] () -- E:\Documents and Settings\All Users\Desktop\IObit Malware Fighter.lnk
[2011/06/26 09:46:52 | 000,000,268 | ---- | C] () -- E:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/06/26 09:46:36 | 000,000,898 | ---- | C] () -- E:\Documents and Settings\Troy\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/06/26 09:46:36 | 000,000,880 | ---- | C] () -- E:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk
[2011/06/26 09:46:03 | 000,000,278 | ---- | C] () -- E:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/06/26 09:45:23 | 000,029,520 | ---- | C] () -- E:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/06/26 09:45:22 | 000,013,496 | ---- | C] () -- E:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/06/26 09:45:21 | 000,000,829 | ---- | C] () -- E:\Documents and Settings\All Users\Desktop\Smart Defrag 2.lnk
[2011/06/26 09:00:33 | 004,295,472 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\Kenji Kawai - Ghost In The Shell - Original Soundtrack - 01 - M01 Making of Cyborg (Chant I).MP3
[2011/06/25 14:53:01 | 000,930,517 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\jjjj.flp
[2011/06/24 20:57:02 | 000,296,070 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\gggggggg.flp
[2011/06/23 15:10:59 | 000,000,939 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\Spybot - Search & Destroy.lnk
[2011/06/23 14:48:08 | 000,002,283 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\Google Chrome.lnk
[2011/06/23 14:48:08 | 000,002,261 | ---- | C] () -- E:\Documents and Settings\Troy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/06/23 14:47:17 | 000,000,974 | ---- | C] () -- E:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-220523388-436374069-725345543-1003UA.job
[2011/06/23 14:47:17 | 000,000,922 | ---- | C] () -- E:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-220523388-436374069-725345543-1003Core.job
[2011/06/22 19:47:18 | 000,592,045 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\verynice1.flp
[2011/06/21 20:31:59 | 000,000,340 | ---- | C] () -- E:\WINDOWS\tasks\AdobeAAMUpdater-1.0-TROY-Troy.job
[2011/06/21 20:07:19 | 000,000,860 | ---- | C] () -- E:\Documents and Settings\All Users\Start Menu\Programs\Adobe Photoshop CS5.lnk
[2011/06/21 13:18:14 | 000,173,470 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\fast one.flp
[2011/06/20 19:43:56 | 000,001,772 | ---- | C] () -- E:\Documents and Settings\Troy\Application Data\Microsoft\Internet Explorer\Quick Launch\Xilisoft DVD Creator 6.lnk
[2011/06/20 19:43:56 | 000,001,754 | ---- | C] () -- E:\Documents and Settings\All Users\Desktop\Xilisoft DVD Creator 6.lnk
[2011/06/20 09:38:24 | 000,000,702 | ---- | C] () -- E:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/17 12:13:25 | 000,507,644 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\ccc.flp
[2011/06/17 08:49:37 | 000,126,976 | RHS- | C] () -- E:\WINDOWS\System32\vbisurfn.dll
[2011/06/17 08:49:37 | 000,000,304 | -HS- | C] () -- E:\WINDOWS\tasks\igofhhdr.job
[2011/06/15 11:44:18 | 000,183,157 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\Itinerary.pdf
[2011/06/14 18:06:49 | 000,000,872 | ---- | C] () -- E:\Documents and Settings\All Users\Desktop\Ashampoo Burning Studio 2010.lnk
[2011/06/14 17:37:40 | 000,034,308 | ---- | C] () -- E:\Documents and Settings\All Users\Application Data\mazuki.dll
[2011/06/05 20:03:18 | 000,389,217 | ---- | C] () -- E:\Documents and Settings\Troy\Desktop\Allen Carr-Easy Way To Stop Smoking.pdf
[2011/06/03 11:51:31 | 000,000,688 | ---- | C] () -- E:\Documents and Settings\All Users\Desktop\Cool Edit Pro 2.1.lnk
[2011/05/27 16:47:25 | 000,000,132 | ---- | C] () -- E:\Documents and Settings\Troy\Application Data\Adobe PNG Format CS5 Prefs
[2011/05/20 20:32:57 | 000,000,016 | ---- | C] () -- E:\WINDOWS\Wininit.ini
[2011/05/20 20:32:50 | 000,035,328 | ---- | C] () -- E:\WINDOWS\INETWH32.DLL
[2011/05/20 20:32:50 | 000,009,136 | ---- | C] () -- E:\WINDOWS\INETWH16.DLL
[2011/05/20 20:32:50 | 000,004,528 | ---- | C] () -- E:\WINDOWS\SETBROWS.EXE
[2011/05/20 20:19:13 | 000,002,791 | ---- | C] () -- E:\WINDOWS\BlacBox2.INI
[2011/02/14 20:25:24 | 000,000,016 | ---- | C] () -- E:\WINDOWS\System32\msvcsv60.dll
[2011/02/14 20:25:24 | 000,000,016 | ---- | C] () -- E:\WINDOWS\msocreg32.dat
[2010/06/08 17:52:47 | 000,000,066 | ---- | C] () -- E:\WINDOWS\Ahead DVD Ripper.INI
[2010/05/22 22:15:20 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggonfe.ini
[2010/05/17 16:32:31 | 000,111,932 | ---- | C] () -- E:\WINDOWS\System32\EPPICPrinterDB.dat
[2010/05/17 16:32:31 | 000,031,053 | ---- | C] () -- E:\WINDOWS\System32\EPPICPattern131.dat
[2010/05/17 16:32:31 | 000,027,417 | ---- | C] () -- E:\WINDOWS\System32\EPPICPattern121.dat
[2010/05/17 16:32:31 | 000,026,154 | ---- | C] () -- E:\WINDOWS\System32\EPPICPattern1.dat
[2010/05/17 16:32:31 | 000,024,903 | ---- | C] () -- E:\WINDOWS\System32\EPPICPattern3.dat
[2010/05/17 16:32:31 | 000,021,390 | ---- | C] () -- E:\WINDOWS\System32\EPPICPattern5.dat
[2010/05/17 16:32:31 | 000,020,148 | ---- | C] () -- E:\WINDOWS\System32\EPPICPattern2.dat
[2010/05/17 16:32:31 | 000,011,811 | ---- | C] () -- E:\WINDOWS\System32\EPPICPattern4.dat
[2010/05/17 16:32:31 | 000,004,943 | ---- | C] () -- E:\WINDOWS\System32\EPPICPattern6.dat
[2010/05/17 16:32:31 | 000,001,146 | ---- | C] () -- E:\WINDOWS\System32\EPPICPresetData_DU.dat
[2010/05/17 16:32:31 | 000,001,139 | ---- | C] () -- E:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010/05/17 16:32:31 | 000,001,139 | ---- | C] () -- E:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010/05/17 16:32:31 | 000,001,136 | ---- | C] () -- E:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010/05/17 16:32:31 | 000,001,129 | ---- | C] () -- E:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010/05/17 16:32:31 | 000,001,129 | ---- | C] () -- E:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010/05/17 16:32:31 | 000,001,120 | ---- | C] () -- E:\WINDOWS\System32\EPPICPresetData_IT.dat
[2010/05/17 16:32:31 | 000,001,107 | ---- | C] () -- E:\WINDOWS\System32\EPPICPresetData_GE.dat
[2010/05/17 16:32:31 | 000,001,104 | ---- | C] () -- E:\WINDOWS\System32\EPPICPresetData_EN.dat
[2010/05/17 16:32:31 | 000,000,097 | ---- | C] () -- E:\WINDOWS\System32\PICSDK.ini
[2010/03/26 13:29:46 | 000,000,028 | ---- | C] () -- E:\WINDOWS\System32\autoscan.dll
[2010/03/19 11:31:36 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggonmn.ini
[2010/03/19 11:31:36 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggonjm.ini
[2010/03/13 12:57:33 | 000,002,892 | ---- | C] () -- E:\WINDOWS\System32\audcon.sys
[2010/03/13 12:57:16 | 000,000,045 | ---- | C] () -- E:\WINDOWS\System32\SYNSOPOS.exe.cfg
[2010/03/13 12:57:15 | 000,086,016 | ---- | C] () -- E:\WINDOWS\System32\SYNSOPOS.exe
[2009/10/27 16:11:12 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggonlh.ini
[2009/10/27 16:11:12 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggoneg.ini
[2009/09/02 08:37:12 | 000,514,016 | ---- | C] () -- E:\Documents and Settings\Troy\Application Data\f789f2056a146661cc1c1dffd88320ff-i686.cache-2
[2009/08/25 12:19:24 | 000,000,412 | ---- | C] () -- E:\WINDOWS\AoADVDRipper.INI
[2009/08/04 21:58:39 | 000,002,756 | ---- | C] () -- E:\WINDOWS\System32\sslibkh.dll
[2009/08/04 21:58:38 | 000,002,756 | ---- | C] () -- E:\WINDOWS\System32\ssolekuy.dll
[2009/08/04 21:58:38 | 000,002,756 | ---- | C] () -- E:\WINDOWS\System32\ssoleht.dll
[2009/08/04 21:58:38 | 000,002,756 | ---- | C] () -- E:\WINDOWS\System32\ssolefw.dll
[2009/08/04 21:58:38 | 000,002,756 | ---- | C] () -- E:\WINDOWS\System32\solegeh.dll
[2009/08/04 21:58:38 | 000,002,756 | ---- | C] () -- E:\WINDOWS\System32\slibgs.dll
[2009/08/04 21:58:38 | 000,002,756 | ---- | C] () -- E:\WINDOWS\System32\slibfg.dll
[2009/07/25 09:29:37 | 000,000,056 | -H-- | C] () -- E:\WINDOWS\System32\ezsidmv.dat
[2009/07/11 17:06:36 | 000,000,604 | ---- | C] () -- E:\Documents and Settings\Troy\Local Settings\Application Data\Notes.stt
[2009/07/11 17:06:36 | 000,000,117 | ---- | C] () -- E:\Documents and Settings\Troy\Local Settings\Application Data\Reminders.stt
[2009/06/20 15:47:51 | 000,002,240 | ---- | C] () -- E:\WINDOWS\LENDIG.sys
[2009/06/18 16:55:58 | 000,121,344 | ---- | C] () -- E:\Documents and Settings\Troy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/18 12:57:40 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggonnd.ini
[2009/06/18 12:54:40 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggonha.ini
[2009/06/18 12:54:40 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggonad.ini
[2009/06/18 11:39:55 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggonoe.ini
[2009/06/18 11:39:55 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggonmi.ini
[2009/06/18 11:39:55 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggonif.ini
[2009/06/18 11:39:55 | 000,000,005 | ---- | C] () -- E:\WINDOWS\obggondi.ini
[2009/06/18 01:18:53 | 000,165,376 | ---- | C] () -- E:\Program Files\UNWISE.EXE
[2009/06/18 01:18:53 | 000,000,058 | ---- | C] () -- E:\Program Files\Native Instruments Homepage.url
[2009/06/17 21:40:12 | 000,000,008 | ---- | C] () -- E:\WINDOWS\System32\nvModes.dat
[2009/06/09 06:35:39 | 000,000,000 | ---- | C] () -- E:\WINDOWS\nsreg.dat
[2009/06/09 06:28:43 | 000,004,984 | ---- | C] () -- E:\WINDOWS\System32\drivers\nvphy.bin
[2009/06/08 22:53:50 | 000,004,161 | ---- | C] () -- E:\WINDOWS\ODBCINST.INI
[2009/06/08 22:51:00 | 003,431,136 | ---- | C] () -- E:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/08 14:33:04 | 000,040,960 | ---- | C] () -- E:\WINDOWS\System32\ChCfg.exe
[2009/06/08 14:33:04 | 000,000,164 | ---- | C] () -- E:\WINDOWS\avrack.ini
[2009/06/08 14:14:15 | 000,147,456 | R--- | C] () -- E:\WINDOWS\System32\RTLCPAPI.dll
[2009/06/08 13:05:06 | 000,002,048 | --S- | C] () -- E:\WINDOWS\bootstat.dat
[2009/06/08 12:59:47 | 000,021,640 | ---- | C] () -- E:\WINDOWS\System32\emptyregdb.dat
[2009/05/01 00:31:10 | 001,657,376 | ---- | C] () -- E:\WINDOWS\System32\nwiz.exe
[2009/05/01 00:31:08 | 000,449,056 | ---- | C] () -- E:\WINDOWS\System32\nvappbar.exe
[2009/05/01 00:31:08 | 000,436,768 | ---- | C] () -- E:\WINDOWS\System32\keystone.exe
[2009/05/01 00:31:06 | 001,724,416 | ---- | C] () -- E:\WINDOWS\System32\nvwdmcpl.dll
[2009/05/01 00:31:06 | 001,507,328 | ---- | C] () -- E:\WINDOWS\System32\nview.dll
[2009/05/01 00:31:06 | 001,101,824 | ---- | C] () -- E:\WINDOWS\System32\nvwimg.dll
[2009/05/01 00:31:06 | 000,466,944 | ---- | C] () -- E:\WINDOWS\System32\nvshell.dll
[2009/04/30 22:02:00 | 001,579,630 | ---- | C] () -- E:\WINDOWS\System32\nvdata.bin
[2009/03/28 00:03:00 | 001,346,080 | ---- | C] () -- E:\WINDOWS\System32\nvdspsch.exe
[2008/10/07 09:13:30 | 000,197,912 | ---- | C] () -- E:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelFrench.dll
[2004/08/04 01:07:22 | 000,001,804 | ---- | C] () -- E:\WINDOWS\System32\dcache.bin
[2004/08/04 00:56:44 | 000,001,024 | ---- | C] () -- E:\WINDOWS\System32\v2gyt5w.dll
[2004/08/04 00:56:44 | 000,001,024 | ---- | C] () -- E:\WINDOWS\System32\grcauth2.dll
[2004/08/04 00:56:44 | 000,001,024 | ---- | C] () -- E:\WINDOWS\System32\grcauth1.dll
[2004/08/04 00:56:44 | 000,001,024 | ---- | C] () -- E:\WINDOWS\System32\clauth2.dll
[2004/08/04 00:56:44 | 000,001,024 | ---- | C] () -- E:\WINDOWS\System32\clauth1.dll
[2004/08/04 00:56:44 | 000,000,340 | ---- | C] () -- E:\WINDOWS\System32\q3p20qj.dll
[2004/08/04 00:56:44 | 000,000,100 | ---- | C] () -- E:\WINDOWS\System32\prsgrc.dll
[2004/08/04 00:56:44 | 000,000,072 | ---- | C] () -- E:\WINDOWS\System32\ssprs.dll
[2004/08/04 00:56:44 | 000,000,016 | -H-- | C] () -- E:\WINDOWS\System32\gyyo050.dll
[2004/08/02 14:20:40 | 000,004,569 | ---- | C] () -- E:\WINDOWS\System32\secupd.dat
[2003/10/09 05:18:10 | 000,143,360 | ---- | C] () -- E:\WINDOWS\System32\mafwTray.exe
[2003/10/09 05:18:10 | 000,013,824 | ---- | C] () -- E:\WINDOWS\System32\mafwpnl.dll
[2001/08/23 22:00:00 | 013,107,200 | ---- | C] () -- E:\WINDOWS\System32\oembios.bin
[2001/08/23 22:00:00 | 000,673,088 | ---- | C] () -- E:\WINDOWS\System32\mlang.dat
[2001/08/23 22:00:00 | 000,432,356 | ---- | C] () -- E:\WINDOWS\System32\perfh009.dat
[2001/08/23 22:00:00 | 000,272,128 | ---- | C] () -- E:\WINDOWS\System32\perfi009.dat
[2001/08/23 22:00:00 | 000,218,003 | ---- | C] () -- E:\WINDOWS\System32\dssec.dat
[2001/08/23 22:00:00 | 000,067,312 | ---- | C] () -- E:\WINDOWS\System32\perfc009.dat
[2001/08/23 22:00:00 | 000,046,258 | ---- | C] () -- E:\WINDOWS\System32\mib.bin
[2001/08/23 22:00:00 | 000,028,626 | ---- | C] () -- E:\WINDOWS\System32\perfd009.dat
[2001/08/23 22:00:00 | 000,004,463 | ---- | C] () -- E:\WINDOWS\System32\oembios.dat
[2001/08/23 22:00:00 | 000,000,741 | ---- | C] () -- E:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/02/12 18:22:57 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\ArtsAcoustic
[2009/06/17 23:31:08 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\ashampoo
[2011/02/17 22:19:03 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\Audio Damage
[2011/02/11 07:44:25 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\AVG10
[2011/01/04 14:21:14 | 000,000,000 | -H-D | M] -- E:\Documents and Settings\All Users\Application Data\Common Files
[2010/03/13 13:39:45 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\eLicenser
[2011/06/26 10:02:26 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\IObit
[2009/06/18 01:09:41 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\iZotope
[2011/02/10 22:35:56 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\MFAData
[2011/06/24 14:43:55 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/05/18 19:27:20 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\Note
[2011/03/06 20:38:43 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\PageshotsPro
[2010/05/18 17:53:05 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\Panasonic
[2011/01/18 19:01:08 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\PreSonus
[2009/08/02 14:06:23 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2011/05/21 15:20:39 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\Redfield
[2011/06/21 20:17:32 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/06/26 08:59:39 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\Soulseek
[2011/06/26 09:58:32 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\Spectrasonics
[2010/03/13 12:57:33 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\Syncrosoft
[2010/07/31 17:02:48 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\System Doctor
[2010/06/09 18:49:26 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/08 11:02:39 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/05/24 23:14:06 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\VertusTech
[2009/06/18 12:53:42 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\Wave Arts
[2011/06/14 18:00:48 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Application Data\WinZip
[2011/06/14 17:38:46 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\Ashampoo
[2011/01/04 14:23:38 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\AVG10
[2009/06/18 11:02:30 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\BitZipper
[2010/05/18 15:06:04 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\DAEMON Tools Pro
[2011/06/25 12:20:17 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\FabFilter
[2009/06/18 09:36:44 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\ImgBurn
[2011/06/27 13:07:28 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\IObit
[2011/06/10 11:13:03 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\iZotope
[2011/02/12 18:57:25 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\jziptoolbar
[2011/02/11 15:05:31 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\Leadertech
[2011/06/24 11:46:21 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\NCH Swift Sound
[2009/06/09 08:35:01 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\OpenOffice.org
[2011/01/18 19:01:06 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\PreSonus
[2009/08/02 14:24:41 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\Propellerhead Software
[2011/05/24 20:29:53 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/02/05 16:19:39 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\Stellarium
[2010/07/31 17:03:16 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\System Doctor
[2010/07/08 11:02:47 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\TuneUp Software
[2011/05/24 18:12:44 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\Ultra Fractal 4
[2011/06/26 00:10:27 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\uTorrent
[2010/03/17 11:35:22 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\Waldorf
[2009/08/05 18:21:39 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\Waves Audio
[2011/06/14 09:08:00 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\Xilisoft
[2011/05/23 19:38:36 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Troy\Application Data\Xilisoft Corporation
[2011/06/27 13:01:57 | 000,000,268 | ---- | M] () -- E:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/06/27 12:55:49 | 000,000,304 | -HS- | M] () -- E:\WINDOWS\Tasks\igofhhdr.job
[2011/06/27 13:50:54 | 000,000,278 | ---- | M] () -- E:\WINDOWS\Tasks\SmartDefrag_Startup.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 200 bytes -> E:\Documents and Settings\All Users\Application Data\TEMP:30FD0CBD
@Alternate Data Stream - 134 bytes -> E:\Documents and Settings\All Users\Application Data\TEMP:FB198ECA
@Alternate Data Stream - 129 bytes -> E:\Documents and Settings\All Users\Application Data\TEMP:8CE646EE
@Alternate Data Stream - 125 bytes -> E:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
Edited by sonicpulse, 27 June 2011 - 12:17 AM.