Intell Pentium 4
74.5 GB HD (15% used), 382 MB RAM
XP Home, SP 2
Arsenal: Avast, Malwarebytes
I took on helping my friend with her computer ails, after she'd lent it to other people who let the Norton expire and gave it back to her with the complaint that "it has a mind of its own."
Immediately I stopped needless start up communication, ran CCleaner, uninstalled Limewire and Itunes w/Revo, installed/performed full (day-long) scans with Avast and Malwarebytes. Avast first found dozens of infected files, folders, registry entries--adware, keylogger, trojan, rootkit-- which are now in the vault. Malwarebytes' last full scan showed dozens of issues supposedly deleted that the Avast scan did not catch--many associated with WIN32.
I then ran Avast and Malwarebytes quick scans and nothing turned up, but there are still major issues going on with this computer:
- loud, constant beeps when booting
- "v's" typed into fields automatically
- other times cannot enter any text into fields
- adware still visible (green underlined words)
- navigating windows directories takes forever
- overall performance is slow
These are the same issues that I encountered when taking the computer on. I know very limited about what I am doing, but something tells me that this computer still has something infectious. Please help.
OTL logfile created on: 7/2/2011 9:23:50 AM - Run 1
OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\Kahikina\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
382.98 Mb Total Physical Memory | 91.82 Mb Available Physical Memory | 23.98% Memory free
1.51 Gb Paging File | 1.16 Gb Available in Paging File | 76.66% Paging File free
Paging file location(s): C:\pagefile.sys 1200 1400 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 61.52 Gb Free Space | 82.56% Space Free | Partition Type: NTFS
Computer Name: PUA | User Name: Kahikina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/07/02 09:20:33 | 000,580,096 | ---- | M] (OldTimer vvvvv-- C:\Documents and Settings\Kahikina\My
PRC - [2011/05/29 09:11:22 | 001,047,656 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2011/05/10 02:10:58 | 003,459,712 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/05/10 02:10:57 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/04/14 06:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2007/06/13 00:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002/09/20 13:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
========== Modules (SafeList) ==========
MOD - [2011/07/02 09:20:33 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\XXX\My Documents\Downloads\OTL.exe
MOD - [2011/05/10 02:10:55 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2006/08/25 05:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (Ati HotKey Poller)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/05/10 02:10:57 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2004/03/18 16:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2002/09/20 13:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))
========== Driver Services (SafeList) ==========
DRV - [2011/05/10 02:03:54 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/05/10 02:03:44 | 000,307,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/05/10 02:02:37 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/05/10 02:02:25 | 000,102,616 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/05/10 01:59:56 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/05/10 01:59:37 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/05/10 01:59:35 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/02/11 02:01:43 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2008/12/01 22:26:00 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PCASp50.sys -- (PCASp50)
DRV - [2008/06/02 16:28:50 | 000,222,720 | ---- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NWADIenum.sys -- (NWADI)
DRV - [2008/05/09 11:08:40 | 000,174,336 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nwusbser2.sys -- (NWUSBPort2)
DRV - [2008/05/09 11:08:40 | 000,174,336 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nwusbser.sys -- (NWUSBPort)
DRV - [2008/05/09 11:08:40 | 000,174,336 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nwusbmdm.sys -- (NWUSBModem)
DRV - [2005/02/23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2004/08/24 01:19:00 | 001,268,204 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2004/08/04 08:05:20 | 000,341,760 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2004/04/14 07:52:22 | 000,005,632 | R--- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\atiide.sys -- (atiide)
DRV - [2004/04/14 06:36:50 | 000,007,432 | ---- | M] (Hewlett-Packard Company) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\eabfiltr.sys -- (eabfiltr)
DRV - [2004/03/25 12:54:24 | 000,680,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2003/10/23 05:11:00 | 000,046,976 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\R8139n51.sys -- (rtl8139)
DRV - [2003/10/07 17:40:00 | 000,094,601 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2003/08/08 14:00:00 | 000,008,448 | ---- | M] (Texas Instruments Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\tiumflt.sys -- (DevUpper)
DRV - [2003/06/06 10:46:16 | 000,005,220 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EabUsb.sys -- (eabusb)
DRV - [2003/04/23 05:06:40 | 000,013,174 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\atisgkaf.sys -- (caboagp)
DRV - [2003/02/18 14:00:00 | 000,042,092 | ---- | M] (Texas Instruments Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tiumfwl.sys -- (tiumfwl)
DRV - [2001/08/17 10:10:28 | 000,035,913 | ---- | M] (SMC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [email protected]:20110101
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/07/02 07:52:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/08 05:33:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/08 05:33:16 | 000,000,000 | ---D | M]
[2009/11/02 20:47:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\XXX\Application Data\Mozilla\Extensions
[2009/11/02 20:47:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\XXX\Application Data\Mozilla\Firefox\Profiles\p0u0x2mc.default\extensions
[2011/05/08 05:24:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2011/07/02 07:52:17 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2011/04/14 06:26:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/12/31 22:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2004/08/03 22:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {2711FB4B-C463-45CA-B7A3-E7FE6B91BBC6} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7D3AAC71-D954-44A8-93A0-03B76128A237} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {9479191E-D5DF-A222-D17C-8DADDDC220C7} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (no name) - {B1EF246F-DB94-4C7C-9431-19C379CE475E} - No CLSID value found.
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (no name) - {CD98D247-AEF6-46DC-A243-E3F9D6B8D248} - No CLSID value found.
O2 - BHO: (no name) - {DA4F8BA1-C2DE-45FE-AEF5-DB133B265A1F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {DF4E7A0C-E233-4906-B4C1-A404356541FF} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\NPJPI150_09.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_05)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 24.25.227.55 209.18.47.61
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll ()
O20 - Winlogon\Notify\edxwnase: DllName - edxwnase.dll - File not found
O20 - Winlogon\Notify\gebya: DllName - C:\WINDOWS\system32\gebya.dll - File not found
O20 - Winlogon\Notify\geedb: DllName - C:\WINDOWS\system32\geedb.dll - File not found
O20 - Winlogon\Notify\jkkjj: DllName - C:\WINDOWS\system32\jkkjj.dll - File not found
O20 - Winlogon\Notify\pmkjj: DllName - C:\WINDOWS\system32\pmkjj.dll - File not found
O20 - Winlogon\Notify\ssqpn: DllName - C:\WINDOWS\system32\ssqpn.dll - File not found
O20 - Winlogon\Notify\ssqqnoo: DllName - ssqqnoo.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\KahikiXXXX\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/07/02 07:39:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2011/07/02 07:39:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2011/07/02 07:38:25 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie7
[2011/07/02 07:38:00 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
[2011/07/02 07:37:19 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
[2011/07/02 05:50:51 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Kahikina\Recent
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2000 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/07/02 08:12:59 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/02 07:54:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/07/02 07:54:32 | 401,657,856 | -HS- | M] () -- C:\hiberfil.sys
[2011/07/02 07:52:24 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/07/02 07:44:20 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\XXX\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/02 07:38:03 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/07/02 05:54:46 | 000,026,512 | ---- | M] () -- C:\Documents and Settings\XXX\My Documents\.reg
[2011/07/02 05:05:58 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2000 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/07/02 07:36:28 | 000,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/07/02 05:54:39 | 000,026,512 | ---- | C] () -- C:\Documents and Settings\XXXXX\My Documents\.reg
[2009/11/03 11:10:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iplayer.INI
[2009/11/02 20:47:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/06/14 19:00:37 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/03/07 14:53:32 | 001,578,343 | -HS- | C] () -- C:\WINDOWS\System32\mokcuvfr.ini
[2008/03/06 10:54:17 | 001,286,441 | -HS- | C] () -- C:\WINDOWS\System32\xerolyvg.ini
[2008/03/06 09:51:20 | 001,286,321 | -HS- | C] () -- C:\WINDOWS\System32\soupcqfn.ini
[2008/03/05 13:13:50 | 001,286,261 | -HS- | C] () -- C:\WINDOWS\System32\bdgtyygf.ini
[2008/03/05 12:07:54 | 001,286,201 | -HS- | C] () -- C:\WINDOWS\System32\iaklewhr.ini
[2008/02/20 18:32:12 | 000,025,312 | -HS- | C] () -- C:\WINDOWS\System32\edxwnase.dllbox
[2008/02/14 15:48:44 | 001,286,141 | -HS- | C] () -- C:\WINDOWS\System32\yilaqhkj.ini
[2008/02/11 11:52:34 | 001,603,037 | -HS- | C] () -- C:\WINDOWS\System32\hjllm.ini2
[2008/02/04 03:02:15 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/11/23 08:06:19 | 000,776,553 | -HS- | C] () -- C:\WINDOWS\System32\oyjhhgos.ini
[2007/10/15 19:13:37 | 000,000,078 | ---- | C] () -- C:\WINDOWS\System32\wtkytwvf.dll
[2007/10/12 12:31:36 | 000,006,527 | -HS- | C] () -- C:\WINDOWS\System32\bdeeg.ini
[2007/10/08 18:13:59 | 000,693,538 | -HS- | C] () -- C:\WINDOWS\System32\jigvtufe.ini
[2007/10/08 16:51:20 | 000,693,477 | -HS- | C] () -- C:\WINDOWS\System32\cissbgvk.ini
[2007/10/08 15:44:34 | 000,693,538 | -HS- | C] () -- C:\WINDOWS\System32\gccwtseg.ini
[2007/10/07 21:47:21 | 000,693,468 | -HS- | C] () -- C:\WINDOWS\System32\raupcqrq.ini
[2007/09/26 07:07:10 | 000,694,007 | -HS- | C] () -- C:\WINDOWS\System32\tjmflhgw.ini
[2007/09/26 06:14:52 | 000,693,827 | -HS- | C] () -- C:\WINDOWS\System32\lwljqdtn.ini
[2007/09/25 23:52:49 | 000,693,707 | -HS- | C] () -- C:\WINDOWS\System32\pmimuttw.ini
[2007/09/23 17:50:43 | 000,693,587 | -HS- | C] () -- C:\WINDOWS\System32\fayvtupx.ini
[2007/09/23 17:41:01 | 000,693,467 | -HS- | C] () -- C:\WINDOWS\System32\mvvrfqjs.ini
[2007/09/17 15:43:54 | 000,695,876 | -HS- | C] () -- C:\WINDOWS\System32\gmmwafvt.ini
[2007/09/17 09:36:27 | 000,695,774 | -HS- | C] () -- C:\WINDOWS\System32\vioculqg.ini
[2007/09/17 08:03:10 | 000,695,645 | -HS- | C] () -- C:\WINDOWS\System32\unuenawf.ini
[2007/09/16 23:31:38 | 000,695,525 | -HS- | C] () -- C:\WINDOWS\System32\eexmrbkm.ini
[2007/09/16 12:20:41 | 000,695,396 | -HS- | C] () -- C:\WINDOWS\System32\ctwsyego.ini
[2007/09/15 22:21:06 | 000,695,225 | -HS- | C] () -- C:\WINDOWS\System32\adblnbeg.ini
[2007/09/15 14:09:41 | 000,695,105 | -HS- | C] () -- C:\WINDOWS\System32\myhdpgbr.ini
[2007/09/15 09:02:19 | 000,695,003 | -HS- | C] () -- C:\WINDOWS\System32\pkvmmfcm.ini
[2007/09/14 22:53:00 | 000,694,865 | -HS- | C] () -- C:\WINDOWS\System32\asmtojhf.ini
[2007/09/13 23:21:54 | 000,694,753 | -HS- | C] () -- C:\WINDOWS\System32\ougfcrri.ini
[2007/09/13 14:24:00 | 000,694,629 | -HS- | C] () -- C:\WINDOWS\System32\xkfgjgmx.ini
[2007/09/13 12:29:09 | 000,694,436 | -HS- | C] () -- C:\WINDOWS\System32\sjgideda.ini
[2007/09/13 09:10:26 | 000,694,333 | -HS- | C] () -- C:\WINDOWS\System32\dbverbxe.ini
[2007/09/13 06:52:37 | 000,694,204 | -HS- | C] () -- C:\WINDOWS\System32\xiryrsmg.ini
[2007/09/12 23:17:49 | 000,694,084 | -HS- | C] () -- C:\WINDOWS\System32\ggarqyws.ini
[2007/09/12 18:55:12 | 000,693,964 | -HS- | C] () -- C:\WINDOWS\System32\artpfeam.ini
[2007/09/11 22:18:49 | 000,693,845 | -HS- | C] () -- C:\WINDOWS\System32\crexfiiy.ini
[2007/09/08 16:49:19 | 000,693,716 | -HS- | C] () -- C:\WINDOWS\System32\ojljgtoh.ini
[2007/09/07 23:32:25 | 000,693,535 | -HS- | C] () -- C:\WINDOWS\System32\mdowgknc.ini
[2007/09/07 17:03:27 | 000,693,555 | -HS- | C] () -- C:\WINDOWS\System32\ntkrewwc.ini
[2007/09/07 13:20:45 | 000,627,679 | -HS- | C] () -- C:\WINDOWS\System32\munfykrk.ini
[2007/09/07 13:11:21 | 001,602,160 | -HS- | C] () -- C:\WINDOWS\System32\hjllm.ini
[2007/08/15 12:40:44 | 001,282,402 | -HS- | C] () -- C:\WINDOWS\System32\witifffd.ini
[2007/07/31 00:21:18 | 001,282,677 | -HS- | C] () -- C:\WINDOWS\System32\qjqihyfi.ini
[2007/07/27 21:14:46 | 001,253,251 | -HS- | C] () -- C:\WINDOWS\System32\ysebellh.ini
[2007/07/25 14:06:25 | 001,248,416 | -HS- | C] () -- C:\WINDOWS\System32\fhpslulp.ini
[2007/07/24 09:44:41 | 001,208,306 | -HS- | C] () -- C:\WINDOWS\System32\vfemyure.ini
[2007/07/22 23:40:38 | 000,000,608 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/07/22 21:17:46 | 000,006,737 | -HS- | C] () -- C:\WINDOWS\System32\aybeg.ini
[2007/07/06 09:08:01 | 001,138,412 | -HS- | C] () -- C:\WINDOWS\System32\vyelaedm.ini
[2007/05/08 07:18:19 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/01/05 14:04:52 | 000,060,565 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2007/01/05 14:04:52 | 000,029,114 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2007/01/05 14:04:52 | 000,021,021 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2007/01/05 14:04:52 | 000,015,670 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2007/01/05 14:04:52 | 000,013,280 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2007/01/05 14:04:52 | 000,010,673 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2007/01/05 14:04:52 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2007/01/05 14:04:52 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2007/01/05 14:04:52 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2007/01/05 14:04:52 | 000,001,137 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2007/01/05 14:04:52 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2007/01/05 14:04:52 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2007/01/05 14:04:52 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2007/01/05 14:04:52 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2007/01/05 14:02:27 | 000,000,044 | ---- | C] () -- C:\WINDOWS\EPCX3800.ini
[2005/06/07 15:21:12 | 000,001,772 | ---- | C] () -- C:\Documents and Settings\XXXa\Application Data\wklnhst.dat
[2005/06/07 08:09:15 | 000,040,960 | ---- | C] () -- C:\Documents and Settings\XXX\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/02/28 08:25:00 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\XXX\Local Settings\Application Data\fusioncache.dat
[2005/02/28 07:57:11 | 000,104,279 | ---- | C] () -- C:\WINDOWS\hpoins04.dat
[2005/02/28 07:57:11 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat
[2005/02/27 02:31:27 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2004/11/18 15:56:54 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/11/18 15:36:39 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2004/08/16 02:42:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/07 03:16:54 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/07 03:16:44 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/08/07 03:10:30 | 000,383,492 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/07 03:10:30 | 000,053,806 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/07 03:10:08 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/07 03:02:54 | 000,229,592 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/07 02:57:54 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/07 02:54:58 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/03 22:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/03 22:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/03 22:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/03 22:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/03 22:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/03 22:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/03 22:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/03 22:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/03/25 12:53:08 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
[2004/03/15 21:28:00 | 000,048,865 | ---- | C] () -- C:\WINDOWS\System32\drivers\tiumfw.bin
[2003/01/07 13:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/05/27 22:55:42 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2002/05/27 22:54:40 | 000,004,605 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
========== LOP Check ==========
[2011/05/07 12:17:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kahikina\Application Data\DriverCure
[2006/11/02 00:15:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kahikina\Application Data\InterVideo
[2007/01/05 14:07:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kahikina\Application Data\Leadertech
[2005/06/07 15:21:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kahikina\Application Data\Template
[2011/05/07 12:17:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kahikina\Application Data\Total PC Health
[2011/05/07 11:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2004/11/18 16:09:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/11/02 17:57:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Novatel Wireless
[2007/09/27 00:42:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/08 18:20:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Total PC Health
[2009/05/26 11:54:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2007/10/22 08:28:34 | 000,000,000 | ---D | M](C:\WINDOWS\S?mantec) -- C:\WINDOWS\Sуmantec
[2007/09/27 21:33:59 | 000,000,000 | ---D | M](C:\WINDOWS\M?crosoft) -- C:\WINDOWS\Mіcrosoft
[2007/09/27 21:33:59 | 000,000,000 | ---D | C](C:\WINDOWS\M?crosoft) -- C:\WINDOWS\Mіcrosoft
[2007/09/27 21:33:42 | 000,000,000 | ---D | M](C:\WINDOWS\S?mantec\S?mantec) -- C:\WINDOWS\Sуmantec\Sуmantec
[2007/09/27 21:33:23 | 000,000,000 | ---D | C](C:\WINDOWS\S?mantec) -- C:\WINDOWS\Sуmantec
========== Alternate Data Streams ==========
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CAAA7DD7
< End of report >
Edited by Poochure, 02 July 2011 - 03:28 PM.