OTL logfile created on: 13/02/2013 15:59:10 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\phil\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy
2,75 Gb Total Physical Memory | 1,72 Gb Available Physical Memory | 62,70% Memory free
5,50 Gb Paging File | 4,15 Gb Available in Paging File | 75,43% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,79 Gb Total Space | 215,96 Gb Free Space | 92,77% Space Free | Partition Type: NTFS
Computer Name: PHIL-PC | User Name: phil | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_6_602_168.exe (Adobe Systems, Inc.)
PRC - C:\Users\phil\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\UnHackMe\hackmon.exe (Greatis Software)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\Comodo\COMODO Internet Security\cis.exe (COMODO)
PRC - C:\Program Files\Comodo\COMODO Internet Security\CisTray.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (COMODO)
PRC - C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe (Uniblue Systems Ltd)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Program Files\Comodo\GeekBuddy\unit_manager.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
PRC - C:\Program Files\AntiLogger\AntiLogger.exe (Zemana Ltd.)
PRC - C:\Program Files\Comodo\Dragon\dragon_updater.exe ()
PRC - C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe (PC Tools)
PRC - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ========== MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_6_602_168.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\PC Tools\PC Tools Security\SpamMonitor\SMPlugin.dll ()
MOD - C:\Program Files\PC Tools\PC Tools Security\pctui\PCTUI.DLL ()
========== Services (SafeList) ========== SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (cmdAgent) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (cmdvirth) -- C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe (COMODO)
SRV - (CLPSLauncher) -- C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
SRV - (DragonUpdater) -- C:\Program Files\Comodo\Dragon\dragon_updater.exe ()
SRV - (GeekBuddyRSP) -- C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
SRV - (sdCoreService) -- C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) -- C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (Browser Defender Update Service) -- C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (HsfXAudioService) -- C:\Windows\System32\XAudio32.dll (Conexant Systems, Inc.)
========== Driver Services (SafeList) ========== DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Qualcomm Atheros Communications, Inc.)
DRV - (iusb3hcs) -- C:\Windows\System32\drivers\iusb3hcs.sys (Intel Corporation)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (RSUSBSTOR) -- C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (Partizan) -- C:\Windows\System32\drivers\Partizan.sys (Greatis Software)
DRV - (inspect) -- C:\Windows\System32\drivers\inspect.sys (COMODO)
DRV - (cmdHlp) -- C:\Windows\System32\drivers\cmdhlp.sys (COMODO)
DRV - (cmdGuard) -- C:\Windows\System32\drivers\cmdguard.sys (COMODO)
DRV - (cmderd) -- C:\Windows\System32\drivers\cmderd.sys (COMODO)
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (pctplfw) -- C:\Windows\System32\drivers\pctplfw.sys (PC Tools)
DRV - (pctplsm) -- C:\Windows\System32\drivers\pctplsm.sys (PC Tools)
DRV - (pctplsg) -- C:\Windows\System32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) -- C:\Windows\System32\drivers\PCTSD.sys (PC Tools)
DRV - (pctgntdi) -- C:\Windows\System32\drivers\pctgntdi.sys (PC Tools)
DRV - (PCTBD) -- C:\Windows\System32\drivers\PCTBD.sys (PC Tools)
DRV - (PCTCore) -- C:\Windows\System32\drivers\PCTCore.sys (PC Tools)
DRV - (PCTAppEvent) -- C:\Windows\System32\drivers\PCTAppEvent.sys (PC Tools)
DRV - (pctNdisLW) -- C:\Windows\System32\drivers\pctNdisLW.sys (PC Tools)
DRV - (PCTFW-PacketFilter) -- C:\Windows\System32\drivers\pctNdis-PacketFilter.sys (PC Tools)
DRV - (CFRMD) -- C:\Windows\System32\drivers\CFRMD.sys (Windows ® Win 7 DDK provider)
DRV - (pctDS) -- C:\Windows\System32\drivers\pctDS.sys (PC Tools)
DRV - (AntiLog32) -- C:\Windows\System32\drivers\AntiLog32.sys (Zemana Ltd.)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (dmvsc) -- C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) -- C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (NVNET) -- C:\Windows\System32\drivers\nvmf6232.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio32.sys (Conexant Systems, Inc.)
DRV - (CnxtHdAudService) -- C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...ms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://fr.msn.com/?ocid=iehpIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 9E 33 1A 96 09 CE 01 [binary data]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...Box&FORM=IE8SRCIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.google.fr/"FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.4.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_168.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\ [2013/02/13 09:34:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/12 15:58:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/02/12 15:58:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\phil\AppData\Roaming\mozilla\Extensions
[2013/02/13 04:10:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\phil\AppData\Roaming\mozilla\Firefox\Profiles\krngak3h.default\extensions
[2013/02/13 04:09:51 | 000,533,536 | ---- | M] () (No name found) -- C:\Users\phil\AppData\Roaming\mozilla\firefox\profiles\krngak3h.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/02/13 04:10:16 | 000,817,973 | ---- | M] () (No name found) -- C:\Users\phil\AppData\Roaming\mozilla\firefox\profiles\krngak3h.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/02/12 15:58:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2013/02/01 19:21:57 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/02/01 20:18:09 | 000,001,609 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2013/02/01 20:18:09 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/02/01 20:18:09 | 000,002,035 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml
[2013/02/01 20:18:09 | 000,001,476 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2013/02/01 20:18:09 | 000,001,399 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2013/02/01 20:18:09 | 000,001,169 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml
O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [AntiLogger] C:\Program Files\AntiLogger\AntiLogger.exe (Zemana Ltd.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe (COMODO)
O4 - HKLM..\Run: [gbrspcontrol] C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe (PC Tools)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1D3689F-46BD-4FE0-B67B-6BA907E93430}: NameServer = 109.0.66.10,109.0.66.20
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (Partizan)
O34 - HKLM BootExecute: (ootExecute settings...)
O34 - HKLM BootExecute: (ount)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ========== [2013/02/13 15:02:31 | 000,000,000 | ---D | C] -- C:\SwSetup
[2013/02/13 14:33:01 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\WinRAR
[2013/02/13 14:33:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/02/13 14:33:00 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/02/13 14:32:58 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2013/02/13 11:34:18 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\PC Tools
[2013/02/13 11:34:13 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Spam Monitor
[2013/02/13 09:34:46 | 000,062,688 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTBD.sys
[2013/02/13 09:34:45 | 002,280,568 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2013/02/13 09:34:45 | 001,690,744 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2013/02/13 09:34:45 | 000,150,648 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2013/02/13 09:33:58 | 000,909,728 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctEFA.sys
[2013/02/13 09:33:58 | 000,342,168 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctDS.sys
[2013/02/13 09:33:57 | 000,260,760 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2013/02/13 09:33:57 | 000,178,584 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2013/02/13 09:33:55 | 000,368,616 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2013/02/13 09:33:55 | 000,163,288 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2013/02/13 09:33:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2013/02/13 09:33:53 | 000,202,280 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2013/02/13 09:33:53 | 000,019,464 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctBTFix.sys
[2013/02/13 09:33:52 | 000,577,176 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfSysMon.sys
[2013/02/13 09:33:52 | 000,055,008 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfFsMon.sys
[2013/02/13 09:33:52 | 000,036,456 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfNetMon.sys
[2013/02/13 09:33:43 | 000,128,024 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplfw.sys
[2013/02/13 09:33:43 | 000,092,608 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2013/02/13 09:33:43 | 000,060,128 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdisLW.sys
[2013/02/13 09:33:43 | 000,033,512 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdis-DNS.sys
[2013/02/13 09:33:41 | 000,071,752 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2013/02/13 09:33:41 | 000,068,272 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsm.sys
[2013/02/13 09:33:32 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
[2013/02/13 09:33:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2013/02/13 09:20:21 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2013/02/13 09:20:19 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2013/02/13 09:20:17 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\TestApp
[2013/02/13 09:02:25 | 000,032,032 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2013/02/13 09:02:25 | 000,021,792 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2013/02/13 09:02:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013
[2013/02/13 09:02:13 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\TuneUp Software
[2013/02/13 09:02:01 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2013
[2013/02/13 09:01:56 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2013/02/13 09:01:47 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2013/02/13 09:01:47 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2013/02/13 08:52:05 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2013/02/13 08:45:07 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\phil\Desktop\tdsskiller.exe
[2013/02/13 07:01:44 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Local\ElevatedDiagnostics
[2013/02/13 06:59:10 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Local\Diagnostics
[2013/02/13 06:43:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/02/13 06:43:35 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013/02/13 06:35:45 | 000,000,000 | --SD | C] -- C:\ProgramData\Shared Space
[2013/02/13 06:34:20 | 000,000,000 | ---D | C] -- C:\ProgramData\COMODO
[2013/02/13 06:34:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Comodo
[2013/02/13 06:34:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2013/02/13 06:34:06 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Local\Comodo
[2013/02/13 06:34:04 | 000,042,760 | ---- | C] (COMODO CA Limited) -- C:\Windows\System32\certsentry.dll
[2013/02/13 06:33:56 | 000,000,000 | ---D | C] -- C:\Program Files\Comodo
[2013/02/13 06:33:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo Downloader
[2013/02/13 06:28:23 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Macromedia
[2013/02/13 06:28:23 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Local\Macromedia
[2013/02/13 06:28:23 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Adobe
[2013/02/13 06:28:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2013/02/13 05:57:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIDA32 - Personal System Information
[2013/02/13 05:57:35 | 000,000,000 | ---D | C] -- C:\Program Files\AIDA32 - Personal System Information
[2013/02/13 05:44:59 | 000,000,000 | ---D | C] -- C:\Users\phil\Desktop\Tgl0beSCRIPT
[2013/02/13 05:21:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2013/02/13 05:14:44 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2013/02/13 05:10:04 | 003,078,656 | ---- | C] (Qualcomm Atheros Communications, Inc.) -- C:\Windows\System32\drivers\athr.sys
[2013/02/13 04:58:34 | 000,000,000 | ---D | C] -- C:\Windows\System32\sda
[2013/02/13 04:46:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Uniblue
[2013/02/13 04:46:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2013/02/13 04:46:44 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Uniblue
[2013/02/13 04:46:44 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2013/02/13 04:10:47 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Users\phil\Desktop\TFC.exe
[2013/02/13 04:03:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
[2013/02/13 04:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\ZHPDiag
[2013/02/13 03:59:42 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/02/13 03:59:40 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2013/02/13 03:59:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\phil\Desktop\OTL.exe
[2013/02/13 03:58:18 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2013/02/13 03:58:08 | 000,000,000 | ---D | C] -- C:\ZHP
[2013/02/13 03:57:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHPFix 1.3
[2013/02/13 03:57:37 | 000,000,000 | ---D | C] -- C:\Program Files\ZHPFix
[2013/02/13 03:55:21 | 000,124,928 | ---- | C] (Tigzy) -- C:\Users\phil\Desktop\LogAnalyzer.exe
[2013/02/13 03:55:01 | 000,000,000 | ---D | C] -- C:\Program Files\CONEXANT
[2013/02/13 03:38:40 | 000,000,000 | ---D | C] -- C:\ProgramData\RegRun
[2013/02/13 03:38:39 | 000,035,816 | ---- | C] (Greatis Software) -- C:\Windows\System32\drivers\Partizan.sys
[2013/02/13 03:38:34 | 000,000,000 | ---D | C] -- C:\Users\phil\Documents\RegRun2
[2013/02/13 03:38:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnHackMe
[2013/02/13 03:38:33 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\regruninfo
[2013/02/13 03:38:32 | 000,012,800 | ---- | C] (Greatis Software, LLC.) -- C:\Windows\System32\drivers\UnHackMeDrv.sys
[2013/02/13 03:38:28 | 000,000,000 | ---D | C] -- C:\Program Files\UnHackMe
[2013/02/13 03:34:56 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2013/02/13 03:31:59 | 000,000,000 | ---D | C] -- C:\Windows\System32\Wat
[2013/01/24 22:43:02 | 000,354,752 | ---- | C] (COMODO) -- C:\Windows\System32\guard32.dll
[2013/01/24 22:43:02 | 000,035,488 | ---- | C] (COMODO) -- C:\Windows\System32\cmdcsr.dll
[2013/01/24 22:42:50 | 000,263,888 | ---- | C] (COMODO) -- C:\Windows\System32\cmdvrt32.dll
[2013/01/24 22:42:50 | 000,040,656 | ---- | C] (COMODO) -- C:\Windows\System32\cmdkbd32.dll
[2013/01/16 19:51:44 | 000,084,416 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\inspect.sys
[2013/01/16 19:51:44 | 000,043,728 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmdhlp.sys
[2013/01/16 19:51:42 | 000,576,768 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmdguard.sys
[2013/01/16 19:51:42 | 000,020,072 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmderd.sys
========== Files - Modified Within 30 Days ========== [2013/02/13 15:58:53 | 001,072,881 | ---- | M] () -- C:\Windows\System32\drivers\sfi.dat
[2013/02/13 15:46:00 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/13 15:16:12 | 000,031,312 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/13 15:16:12 | 000,031,312 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/13 15:15:01 | 000,704,480 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2013/02/13 15:15:01 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/02/13 15:15:01 | 000,130,754 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2013/02/13 15:15:01 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/02/13 15:09:40 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\dsmonitor.job
[2013/02/13 15:08:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/02/13 15:08:42 | 2213,351,424 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/13 09:33:54 | 000,002,193 | ---- | M] () -- C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2013/02/13 09:02:23 | 000,002,171 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Maintenance en 1 clic.lnk
[2013/02/13 09:02:23 | 000,002,135 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2013/02/13 08:45:19 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\phil\Desktop\tdsskiller.exe
[2013/02/13 06:53:42 | 000,268,256 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/02/13 06:43:39 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/02/13 06:36:10 | 000,001,993 | ---- | M] () -- C:\Users\Public\Desktop\Virtual Comodo Dragon.lnk
[2013/02/13 06:36:10 | 000,001,838 | ---- | M] () -- C:\Users\Public\Desktop\COMODO Internet Security.lnk
[2013/02/13 06:36:10 | 000,000,593 | ---- | M] () -- C:\Users\Public\Desktop\Shared Space.lnk
[2013/02/13 06:34:15 | 000,002,017 | ---- | M] () -- C:\Users\Public\Desktop\AntiError.lnk
[2013/02/13 06:34:15 | 000,002,013 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/02/13 06:34:15 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\GeekBuddy.lnk
[2013/02/13 06:34:07 | 000,001,074 | ---- | M] () -- C:\Users\Public\Desktop\Comodo Dragon.lnk
[2013/02/13 06:34:04 | 000,042,760 | ---- | M] (COMODO CA Limited) -- C:\Windows\System32\certsentry.dll
[2013/02/13 05:57:36 | 000,001,041 | ---- | M] () -- C:\Users\phil\Desktop\AIDA32.lnk
[2013/02/13 05:14:20 | 000,013,153 | ---- | M] () -- C:\Windows\System32\nvinfo.pb
[2013/02/13 05:10:04 | 003,078,656 | ---- | M] (Qualcomm Atheros Communications, Inc.) -- C:\Windows\System32\drivers\athr.sys
[2013/02/13 05:09:10 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_iusb3hcs_01009.Wdf
[2013/02/13 04:46:46 | 000,001,171 | ---- | M] () -- C:\Users\phil\Application Data\Microsoft\Internet Explorer\Quick Launch\DriverScanner.lnk
[2013/02/13 04:46:46 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\DriverScanner.lnk
[2013/02/13 04:10:48 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Users\phil\Desktop\TFC.exe
[2013/02/13 04:07:32 | 000,000,000 | ---- | M] () -- C:\Users\phil\Desktop\LogAnalyZer.ini
[2013/02/13 04:05:07 | 000,000,512 | ---- | M] () -- C:\PhysicalDisk0_MBR.bin
[2013/02/13 04:03:38 | 000,000,956 | ---- | M] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2013/02/13 04:03:38 | 000,000,949 | ---- | M] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2013/02/13 04:03:38 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2013/02/13 03:59:04 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\phil\Desktop\OTL.exe
[2013/02/13 03:58:24 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2013/02/13 03:55:22 | 000,124,928 | ---- | M] (Tigzy) -- C:\Users\phil\Desktop\LogAnalyzer.exe
[2013/02/13 03:38:39 | 000,035,816 | ---- | M] (Greatis Software) -- C:\Windows\System32\drivers\Partizan.sys
[2013/02/13 03:38:36 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2013/02/13 03:38:36 | 000,001,688 | ---- | M] () -- C:\Windows\System32\autoexec.nt
[2013/02/13 03:38:36 | 000,000,002 | RHS- | M] () -- C:\Windows\winstart.bat
[2013/02/13 03:38:34 | 000,000,913 | ---- | M] () -- C:\Users\phil\Desktop\UnHackMe.lnk
[2013/02/13 03:09:49 | 000,001,036 | ---- | M] () -- C:\Users\phil\Desktop\BiosAgent Plus.lnk
[2013/02/12 14:06:22 | 000,012,800 | ---- | M] (Greatis Software, LLC.) -- C:\Windows\System32\drivers\UnHackMeDrv.sys
[2013/01/31 10:52:14 | 000,032,032 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2013/01/31 10:52:10 | 000,021,792 | ---- | M] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2013/01/24 22:43:02 | 000,354,752 | ---- | M] (COMODO) -- C:\Windows\System32\guard32.dll
[2013/01/24 22:43:02 | 000,035,488 | ---- | M] (COMODO) -- C:\Windows\System32\cmdcsr.dll
[2013/01/24 22:42:50 | 000,263,888 | ---- | M] (COMODO) -- C:\Windows\System32\cmdvrt32.dll
[2013/01/24 22:42:50 | 000,040,656 | ---- | M] (COMODO) -- C:\Windows\System32\cmdkbd32.dll
[2013/01/16 19:51:44 | 000,084,416 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\inspect.sys
[2013/01/16 19:51:44 | 000,043,728 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmdhlp.sys
[2013/01/16 19:51:42 | 000,576,768 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmdguard.sys
[2013/01/16 19:51:42 | 000,020,072 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmderd.sys
========== Files Created - No Company Name ========== [2013/02/13 09:34:45 | 000,769,144 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2013/02/13 09:34:45 | 000,003,488 | ---- | C] () -- C:\Windows\UDB.zip
[2013/02/13 09:34:45 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2013/02/13 09:34:45 | 000,000,879 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2013/02/13 09:34:45 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2013/02/13 09:33:54 | 000,002,193 | ---- | C] () -- C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2013/02/13 09:02:23 | 000,002,171 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Maintenance en 1 clic.lnk
[2013/02/13 09:02:23 | 000,002,135 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2013/02/13 09:02:22 | 000,002,147 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk
[2013/02/13 06:53:24 | 000,268,256 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/02/13 06:43:39 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/02/13 06:36:10 | 000,001,993 | ---- | C] () -- C:\Users\Public\Desktop\Virtual Comodo Dragon.lnk
[2013/02/13 06:36:10 | 000,001,838 | ---- | C] () -- C:\Users\Public\Desktop\COMODO Internet Security.lnk
[2013/02/13 06:36:09 | 000,000,593 | ---- | C] () -- C:\Users\Public\Desktop\Shared Space.lnk
[2013/02/13 06:36:04 | 001,072,881 | ---- | C] () -- C:\Windows\System32\drivers\sfi.dat
[2013/02/13 06:34:15 | 000,002,017 | ---- | C] () -- C:\Users\Public\Desktop\AntiError.lnk
[2013/02/13 06:34:15 | 000,002,013 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/02/13 06:34:15 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\GeekBuddy.lnk
[2013/02/13 06:34:07 | 000,001,074 | ---- | C] () -- C:\Users\Public\Desktop\Comodo Dragon.lnk
[2013/02/13 06:28:01 | 000,001,002 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/13 05:57:36 | 000,001,041 | ---- | C] () -- C:\Users\phil\Desktop\AIDA32.lnk
[2013/02/13 05:14:20 | 000,013,153 | ---- | C] () -- C:\Windows\System32\nvinfo.pb
[2013/02/13 05:09:10 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_iusb3hcs_01009.Wdf
[2013/02/13 04:46:48 | 000,000,326 | ---- | C] () -- C:\Windows\tasks\dsmonitor.job
[2013/02/13 04:46:46 | 000,001,171 | ---- | C] () -- C:\Users\phil\Application Data\Microsoft\Internet Explorer\Quick Launch\DriverScanner.lnk
[2013/02/13 04:46:46 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\DriverScanner.lnk
[2013/02/13 04:05:07 | 000,000,512 | ---- | C] () -- C:\PhysicalDisk0_MBR.bin
[2013/02/13 04:03:38 | 000,000,956 | ---- | C] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2013/02/13 04:03:38 | 000,000,949 | ---- | C] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2013/02/13 03:59:40 | 000,011,164 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2013/02/13 03:58:24 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2013/02/13 03:57:38 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2013/02/13 03:55:50 | 000,000,000 | ---- | C] () -- C:\Users\phil\Desktop\LogAnalyZer.ini
[2013/02/13 03:38:36 | 000,000,002 | RHS- | C] () -- C:\Windows\winstart.bat
[2013/02/13 03:38:34 | 000,000,913 | ---- | C] () -- C:\Users\phil\Desktop\UnHackMe.lnk
[2013/02/13 03:09:49 | 000,001,036 | ---- | C] () -- C:\Users\phil\Desktop\BiosAgent Plus.lnk
[2013/02/13 03:08:18 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/02/13 03:07:36 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2011/04/12 02:35:45 | 000,704,480 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2011/04/12 02:35:45 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2011/04/12 02:35:45 | 000,130,754 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2011/04/12 02:35:45 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
========== ZeroAccess Check ========== [2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2013/02/13 11:34:13 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\Spam Monitor
[2013/02/13 09:20:17 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\TestApp
[2013/02/13 09:02:13 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\TuneUp Software
[2013/02/13 04:46:44 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\Uniblue
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 202 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
< End of report >