I am using window xp and AVG anti virus.
Recently avg keep coming out with below found.
-tracking cookies.serving-sys
-trojan horse fakealert.po
-tracking cookies.overture
and etc
My pc has been slowing down since then.. I have moved the finding to vault in AVG but it didnt solve the problem. I have also tried using spybot, ad-aware and running AVG in safemode. It didnt solve too.
Below is the OTL log.
Thanks for your help!
OTL logfile created on: 3/1/2012 1:03:06 PM - Run 1
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Documents and Settings\winxp\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.09 Gb Total Physical Memory | 0.22 Gb Available Physical Memory | 19.67% Memory free
1.71 Gb Paging File | 0.86 Gb Available in Paging File | 50.66% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.41 Gb Total Space | 8.46 Gb Free Space | 34.66% Space Free | Partition Type: NTFS
Drive D: | 12.85 Gb Total Space | 4.23 Gb Free Space | 32.92% Space Free | Partition Type: NTFS
Computer Name: HEMA | User Name: winxp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/03/01 13:03:02 | 000,583,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\winxp\Desktop\OTL.exe
PRC - [2012/02/15 07:03:14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\winxp\Application Data\Dropbox\bin\Dropbox.exe
PRC - [2011/10/18 09:05:28 | 002,042,208 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/08/22 09:19:25 | 000,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/08/22 09:19:24 | 000,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2009/08/22 09:19:18 | 000,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/08/22 09:19:11 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/08/22 09:19:08 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/06/10 04:27:04 | 000,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
PRC - [2008/04/14 08:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2008/04/14 08:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 08:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2006/01/19 12:33:38 | 000,078,336 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL
MOD - [2003/07/29 05:45:10 | 000,078,336 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBRPP5C.DLL
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2009/08/22 09:19:11 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc)
SRV - [2009/08/22 09:19:08 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd)
========== Driver Services (SafeList) ==========
DRV - [2009/10/20 18:47:46 | 000,113,280 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009/10/12 15:21:54 | 000,100,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbdev.sys -- (hwusbdev)
DRV - [2009/09/10 14:55:52 | 000,102,528 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009/08/22 09:19:25 | 000,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2009/08/22 09:19:24 | 000,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2009/05/12 08:48:55 | 000,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2008/04/14 02:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2007/03/10 13:32:46 | 000,076,560 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2004/08/04 06:29:52 | 000,166,912 | ---- | M] (S3 Graphics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\s3gnbm.sys -- (S3SavageNB)
DRV - [2001/08/17 22:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/01/04 16:13:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/22 16:17:34 | 000,000,000 | ---D | M]
[2010/03/22 13:51:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\winxp\Application Data\Mozilla\Extensions
[2010/10/07 11:46:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\winxp\Application Data\Mozilla\Firefox\Profiles\sbnokl62.default\extensions
[2012/02/29 11:54:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\winxp\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\winxp\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Gmail = C:\Documents and Settings\winxp\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2004/08/04 20:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\winxp\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\winxp\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = [binary data]
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{379F3389-7EF6-4C5C-8C1A-D94EB280DC2C}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\DOCUME~1\ALLUSE~1\APPLIC~1\MICROS~1\Windows\mspdb11.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/11/24 21:19:45 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\##Victor#E\Shell - "" = AutoRun
O33 - MountPoints2\##Victor#E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\##Victor#E\Shell\AutoRun\command - "" = Z:\Setup.EXE
O33 - MountPoints2\{4d89af3c-ef4b-11dd-b902-00115ba712e5}\Shell\Auto\command - "" = F:\RavMonE.exe e
O33 - MountPoints2\{4d89af3c-ef4b-11dd-b902-00115ba712e5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4d89af3c-ef4b-11dd-b902-00115ba712e5}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
O33 - MountPoints2\{589fc974-c29a-11de-884d-00115ba712e5}\Shell\AutoRun\command - "" = F:\PMB_P.exe
O33 - MountPoints2\{589fc977-c29a-11de-884d-00115ba712e5}\Shell - "" = AutoRun
O33 - MountPoints2\{589fc977-c29a-11de-884d-00115ba712e5}\Shell\Auto\Command - "" = F:\IntelM
O33 - MountPoints2\{589fc977-c29a-11de-884d-00115ba712e5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{589fc977-c29a-11de-884d-00115ba712e5}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL IntelM
O33 - MountPoints2\{6ebf3b9a-81c1-11e0-8a4a-00115ba712e5}\Shell - "" = AutoRun
O33 - MountPoints2\{6ebf3b9a-81c1-11e0-8a4a-00115ba712e5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6ebf3b9a-81c1-11e0-8a4a-00115ba712e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{8f7f0bfc-8b2b-11e0-8a57-00115ba712e5}\Shell - "" = AutoRun
O33 - MountPoints2\{8f7f0bfc-8b2b-11e0-8a57-00115ba712e5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8f7f0bfc-8b2b-11e0-8a57-00115ba712e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{a8189b90-e917-11dd-b8fe-00115ba712e5}\Shell\Auto\command - "" = F:\RavMonE.exe e
O33 - MountPoints2\{a8189b90-e917-11dd-b8fe-00115ba712e5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a8189b90-e917-11dd-b8fe-00115ba712e5}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
O33 - MountPoints2\{c53b00ff-81cb-11e0-8a4b-d82c64c6caae}\Shell - "" = AutoRun
O33 - MountPoints2\{c53b00ff-81cb-11e0-8a4b-d82c64c6caae}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c53b00ff-81cb-11e0-8a4b-d82c64c6caae}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{c53b010a-81cb-11e0-8a4b-00115ba712e5}\Shell - "" = AutoRun
O33 - MountPoints2\{c53b010a-81cb-11e0-8a4b-00115ba712e5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c53b010a-81cb-11e0-8a4b-00115ba712e5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{d3a49d4e-ee3d-11dc-b7c5-00115ba712e5}\Shell\Auto\command - "" = RavMonE.exe e
O33 - MountPoints2\{d3a49d4e-ee3d-11dc-b7c5-00115ba712e5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d3a49d4e-ee3d-11dc-b7c5-00115ba712e5}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
O33 - MountPoints2\{f923adcb-f45d-11db-b685-00115ba712e5}\Shell\Auto\command - "" = G:\RavMonE.exe e
O33 - MountPoints2\{f923adcb-f45d-11db-b685-00115ba712e5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f923adcb-f45d-11db-b685-00115ba712e5}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2012/03/01 13:02:44 | 000,583,680 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\winxp\Desktop\OTL.exe
[2012/02/29 17:38:14 | 000,000,000 | R--D | C] -- C:\Documents and Settings\winxp\My Documents\Dropbox
[2012/02/29 17:35:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\winxp\Start Menu\Programs\Dropbox
[2012/02/29 17:34:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\winxp\Application Data\Dropbox
[2012/02/24 15:06:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2012/02/24 14:59:27 | 000,000,000 | ---D | C] -- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
[2012/02/24 14:59:25 | 000,000,000 | ---D | C] -- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[2012/02/24 14:59:23 | 000,000,000 | ---D | C] -- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2012/02/24 14:59:22 | 000,000,000 | ---D | C] -- C:\Program Files\SDHelper (Spybot - Search & Destroy)
[2012/02/22 11:15:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\winxp\My Documents\pic artwork
[2012/02/18 13:55:10 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\winxp\Recent
[2012/02/10 15:30:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2012/02/10 15:27:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2012/02/10 15:25:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\winxp\Local Settings\Application Data\Temp
[2012/02/10 15:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2012/02/10 15:25:00 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2012/02/10 15:25:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\winxp\Local Settings\Application Data\Google
[2012/02/06 11:59:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\winxp\My Documents\customer contact details
[2012/02/04 10:58:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\RENEE
[2012/02/03 17:28:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Scissor report
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/03/01 13:03:02 | 000,583,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\winxp\Desktop\OTL.exe
[2012/03/01 10:59:32 | 090,813,946 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2012/03/01 08:58:23 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/03/01 08:58:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/03/01 08:58:20 | 1173,938,176 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/29 17:38:14 | 000,000,994 | ---- | M] () -- C:\Documents and Settings\winxp\Desktop\Dropbox.lnk
[2012/02/29 17:35:44 | 000,000,994 | ---- | M] () -- C:\Documents and Settings\winxp\Start Menu\Programs\Startup\Dropbox.lnk
[2012/02/29 12:15:26 | 001,918,745 | ---- | M] () -- C:\Documents and Settings\winxp\My Documents\1655796-ciseaux.pdf
[2012/02/27 15:36:22 | 000,244,668 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-27-2012 03;36;09PM.pdf
[2012/02/27 10:30:57 | 000,253,359 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-27-2012 10;30;04AM.pdf
[2012/02/27 10:16:42 | 000,677,607 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-27-2012 10;16;18AM.pdf
[2012/02/24 15:06:57 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\winxp\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/02/24 15:06:57 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\winxp\Desktop\Spybot - Search & Destroy.lnk
[2012/02/24 14:51:25 | 000,314,508 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/02/24 14:51:25 | 000,040,836 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/02/23 17:44:36 | 000,211,487 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-23-2012 05;44;22PM.pdf
[2012/02/23 16:49:28 | 000,227,540 | ---- | M] () -- C:\Documents and Settings\winxp\My Documents\IMG_23022012_094907.png
[2012/02/20 11:50:58 | 000,481,483 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-20-2012 11;50;35AM.pdf
[2012/02/20 11:44:34 | 000,507,750 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-20-2012 11;44;14AM.pdf
[2012/02/20 08:53:12 | 000,196,960 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/14 16:39:52 | 001,160,664 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\P1010014.JPG
[2012/02/14 12:47:36 | 000,829,033 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-14-2012 12;47;07PM.pdf
[2012/02/13 10:54:38 | 000,268,913 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-13-2012 10;54;23AM.pdf
[2012/02/13 10:52:14 | 000,074,157 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\TT slip-philip.jpg
[2012/02/09 17:54:51 | 000,643,800 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-09-2012 05;54;39PM.pdf
[2012/02/06 12:45:55 | 000,639,092 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-06-2012 12;45;37PM.pdf
[2012/02/04 09:48:29 | 000,096,107 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\zoo-page 2.jpg
[2012/02/04 09:46:55 | 000,099,726 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\zoo.jpg
[2012/02/02 10:48:39 | 001,198,078 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-02-2012 10;48;16AM.pdf
[2012/02/01 09:52:06 | 000,431,098 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\02-01-2012 09;51;54AM.pdf
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/29 17:38:14 | 000,000,994 | ---- | C] () -- C:\Documents and Settings\winxp\Desktop\Dropbox.lnk
[2012/02/29 17:35:44 | 000,000,994 | ---- | C] () -- C:\Documents and Settings\winxp\Start Menu\Programs\Startup\Dropbox.lnk
[2012/02/29 12:15:26 | 001,918,745 | ---- | C] () -- C:\Documents and Settings\winxp\My Documents\1655796-ciseaux.pdf
[2012/02/27 15:36:22 | 000,244,668 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-27-2012 03;36;09PM.pdf
[2012/02/27 10:30:57 | 000,253,359 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-27-2012 10;30;04AM.pdf
[2012/02/27 10:16:41 | 000,677,607 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-27-2012 10;16;18AM.pdf
[2012/02/25 12:24:33 | 1173,938,176 | -HS- | C] () -- C:\hiberfil.sys
[2012/02/24 15:06:57 | 000,000,951 | ---- | C] () -- C:\Documents and Settings\winxp\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/02/24 15:06:57 | 000,000,933 | ---- | C] () -- C:\Documents and Settings\winxp\Desktop\Spybot - Search & Destroy.lnk
[2012/02/23 17:44:36 | 000,211,487 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-23-2012 05;44;22PM.pdf
[2012/02/23 16:49:18 | 000,227,540 | ---- | C] () -- C:\Documents and Settings\winxp\My Documents\IMG_23022012_094907.png
[2012/02/20 11:50:58 | 000,481,483 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-20-2012 11;50;35AM.pdf
[2012/02/20 11:44:34 | 000,507,750 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-20-2012 11;44;14AM.pdf
[2012/02/20 08:53:12 | 000,196,960 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/18 13:59:34 | 000,000,881 | ---- | C] () -- C:\Documents and Settings\winxp\Start Menu\Programs\Ad-Aware.lnk
[2012/02/18 13:59:05 | 000,000,807 | ---- | C] () -- C:\Documents and Settings\winxp\Start Menu\Programs\SpybotSD.lnk
[2012/02/15 12:35:56 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/15 12:35:56 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/14 16:39:19 | 001,160,664 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\P1010014.JPG
[2012/02/14 12:47:36 | 000,829,033 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-14-2012 12;47;07PM.pdf
[2012/02/13 10:54:38 | 000,268,913 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-13-2012 10;54;23AM.pdf
[2012/02/13 10:52:09 | 000,074,157 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\TT slip-philip.jpg
[2012/02/10 14:54:25 | 000,000,717 | ---- | C] () -- C:\Documents and Settings\winxp\Start Menu\Programs\avgtray.lnk
[2012/02/10 14:52:31 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\winxp\Start Menu\Programs\ccleaner.lnk
[2012/02/09 17:54:51 | 000,643,800 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-09-2012 05;54;39PM.pdf
[2012/02/06 12:45:55 | 000,639,092 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-06-2012 12;45;37PM.pdf
[2012/02/04 09:49:10 | 000,099,726 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\zoo.jpg
[2012/02/04 09:49:10 | 000,096,107 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\zoo-page 2.jpg
[2012/02/02 10:48:38 | 001,198,078 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-02-2012 10;48;16AM.pdf
[2012/02/01 09:52:06 | 000,431,098 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\02-01-2012 09;51;54AM.pdf
[2010/03/22 13:51:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/03/22 08:48:01 | 000,012,028 | -HS- | C] () -- C:\Documents and Settings\winxp\Local Settings\Application Data\4Jp87e378L
[2010/03/22 08:48:01 | 000,012,028 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\4Jp87e378L
========== LOP Check ==========
[2007/05/28 12:00:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Emjysoft
[2012/03/01 12:51:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\winxp\Application Data\Dropbox
[2012/02/01 15:47:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\winxp\Application Data\Ludoofx
[2012/01/13 10:00:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\winxp\Application Data\Uvob
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012/02/01 15:33:55 | 002,923,879 | ---- | C] ()(C:\Documents and Settings\winxp\Desktop\1015??.rar) -- C:\Documents and Settings\winxp\Desktop\1015唛头.rar
[2012/02/01 15:24:38 | 002,923,879 | ---- | M] ()(C:\Documents and Settings\winxp\Desktop\1015??.rar) -- C:\Documents and Settings\winxp\Desktop\1015唛头.rar
[2010/12/31 17:49:35 | 002,175,820 | ---- | M] ()(C:\Documents and Settings\winxp\Desktop\88131-NEWArt-tray&adaptor (OP)_????12-31.jpg) -- C:\Documents and Settings\winxp\Desktop\88131-NEWArt-tray&adaptor (OP)_复制副本12-31.jpg
[2010/12/31 17:33:51 | 002,175,820 | ---- | C] ()(C:\Documents and Settings\winxp\Desktop\88131-NEWArt-tray&adaptor (OP)_????12-31.jpg) -- C:\Documents and Settings\winxp\Desktop\88131-NEWArt-tray&adaptor (OP)_复制副本12-31.jpg
< End of report >