Hello Again
a couple of things
1. unable to copy both OTPLstd and OTPLnet to same disk as second download asks to delete the first.
2. ran the OTPLstd but didnt get asked for Remote Memory Registry,
OTL txt from this scan attached below.
Q ? - should I repeat the above using the OTPLnet boot disk and paste results ?
pls advise
regards
K
OTL logfile created on: 2/27/2014 12:41:51 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1,015.00 Mb Total Physical Memory | 785.00 Mb Available Physical Memory | 77.00% Memory free
903.00 Mb Paging File | 814.00 Mb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.61 Gb Total Space | 0.93 Gb Free Space | 4.98% Space Free | Partition Type: NTFS
Drive X: | 284.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ========== SRV - [2014/02/10 06:35:22 | 001,444,120 | ---- | M] (Trusteer Ltd.) [Auto] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2013/11/19 20:54:20 | 000,283,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe -- (avgwd)
SRV - [2013/07/04 09:53:10 | 004,939,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- C:\Program Files\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2012/10/03 09:51:04 | 000,725,400 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009/12/16 15:09:34 | 000,049,152 | ---- | M] (Sage (UK) Limited) [Auto] -- C:\Program Files\Common Files\Sage SData\Sage.SData.Service.exe -- (Sage SData Service)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (smwdm)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - File not found [Kernel | On_Demand] -- -- (aeaudio)
DRV - [2014/02/10 06:35:40 | 000,228,888 | ---- | M] (Trusteer Ltd.) [Kernel | System] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2014/02/10 06:35:40 | 000,155,704 | ---- | M] (Trusteer Ltd.) [Kernel | System] -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys -- (RapportEI)
DRV - [2014/02/10 06:35:40 | 000,107,256 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2013/12/13 03:01:17 | 000,340,432 | ---- | M] () [Kernel | System] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_59849.sys -- (RapportCerberus_59849)
DRV - [2012/11/28 10:42:28 | 000,136,520 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\bkrwbus.sys -- (bkrwbus)
DRV - [2012/11/28 10:42:28 | 000,083,400 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\bkrwbk.sys -- (bkrwbk)
DRV - [2012/06/11 08:17:44 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2012/06/11 08:17:44 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2011/08/17 03:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011/08/17 03:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2001/08/17 07:11:18 | 000,020,160 | ---- | M] (ADMtek Incorporated) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ADM8511.SYS -- (ADM8511)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://start.mysearc...r=971255584&ir= IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www2.delta-se...913_c1&tsp=5010IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\systemprofile_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
O1 HOSTS File: ([2008/04/14 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - File not found
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - File not found
O4 - HKLM..\Run: [AML Registry Cleaner] File not found
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\RunOnce: [*Restore] C:\WINDOWS\System32\restore\rstrui.exe (Microsoft Corporation)
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\systemprofile_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\TEMP_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 0.0.0.0
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/12/19 09:00:07 | 000,000,040 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2014/02/25 16:44:12 | 000,000,000 | ---D | C] -- C:\FRST
[2014/02/25 08:00:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MRT
[2014/02/25 05:02:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Sage
[2014/02/25 04:58:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Trusteer
[2014/02/25 04:55:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Google
[2014/02/25 04:30:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Avg2013
[2014/02/25 04:30:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\MFAData
[2014/02/25 03:53:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Trusteer
[2014/02/25 03:47:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Microsoft
[2014/02/10 06:35:40 | 000,107,256 | ---- | C] (Trusteer Ltd.) -- C:\WINDOWS\System32\drivers\RapportKELL.sys
[2010/02/09 06:32:16 | 000,184,320 | R--- | C] ( ) -- C:\WINDOWS\System32\SgE.interop.MSXML2.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2014/02/27 04:23:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/02/27 04:23:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\BitGuard.job
[2014/02/27 03:52:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014/02/27 03:45:00 | 000,001,010 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1214440339-1644491937-500UA.job
[2014/02/26 08:45:00 | 000,000,958 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1214440339-1644491937-500Core.job
[2014/02/25 09:28:31 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2014/02/25 05:03:35 | 000,000,679 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2014/02/25 04:41:00 | 000,161,936 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014/02/24 10:40:24 | 000,002,489 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Word.lnk
[2014/02/24 06:38:27 | 000,000,640 | ---- | M] () -- C:\WINDOWS\System32\SGLCH32.USR
[2014/02/24 03:22:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Trusteer Endpoint Protection
[2014/02/18 06:04:31 | 000,002,487 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Excel.lnk
[2014/02/14 13:04:14 | 000,541,014 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2014/02/14 13:04:14 | 000,096,742 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2014/02/14 12:23:46 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2014/02/10 06:35:40 | 000,107,256 | ---- | M] (Trusteer Ltd.) -- C:\WINDOWS\System32\drivers\RapportKELL.sys
[2014/02/05 22:54:08 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe
[2014/02/05 22:54:08 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2014/02/05 18:26:52 | 000,920,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
[2014/02/05 18:26:51 | 000,759,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vgx.dll
[2014/02/05 18:26:50 | 001,216,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll
[2014/02/05 18:26:49 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mstime.dll
[2014/02/05 18:26:49 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
[2014/02/05 18:26:49 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll
[2014/02/05 18:26:49 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll
[2014/02/05 18:26:49 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll
[2014/02/05 18:26:48 | 006,021,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2014/02/05 18:26:48 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll
[2014/02/05 18:26:44 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedsbs.dll
[2014/02/05 18:26:44 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2014/02/05 18:26:43 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll
[2014/02/05 18:26:43 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2014/02/05 18:26:43 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\licmgr10.dll
[2014/02/05 18:26:43 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\licmgr10.dll
[2014/02/05 18:26:43 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll
[2014/02/05 18:26:43 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll
[2014/02/05 18:26:42 | 002,006,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2014/02/05 18:26:42 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl
[2014/02/05 18:26:42 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2014/02/05 18:26:42 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2014/02/05 18:26:41 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iepeers.dll
[2014/02/05 18:26:41 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll
[2014/02/05 18:26:40 | 011,113,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2014/02/05 18:26:38 | 000,743,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2014/02/05 18:26:37 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll
[2014/02/05 18:26:37 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2014/02/05 18:26:37 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\corpol.dll
[2014/02/05 18:26:37 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\corpol.dll
[2014/02/05 17:24:05 | 000,385,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\html.iec
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2014/02/25 08:48:39 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/07/04 10:56:28 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\UKCpInfo.sys
[2013/06/17 12:52:21 | 000,000,096 | ---- | C] () -- C:\WINDOWS\CPS.INI
[2013/03/12 04:39:42 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc
[2013/03/07 04:23:37 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/03/01 05:42:55 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2013/02/21 10:08:15 | 000,000,062 | ---- | C] () -- C:\WINDOWS\Trick.INI
[2011/12/16 06:42:23 | 000,000,679 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2011/12/16 05:32:41 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\e1000msg.dll
[2011/12/15 11:04:16 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/12/15 10:56:21 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/12/15 10:31:45 | 000,004,629 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/12/15 10:30:23 | 000,161,936 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/02/09 06:33:54 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\SgELauncher.dll
[2010/02/09 06:33:14 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\SgEData.dll
[2009/12/24 07:11:10 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\SGList32.dll
[2009/12/24 07:11:04 | 000,278,528 | ---- | C] () -- C:\WINDOWS\System32\SGTool32.dll
[2009/12/24 07:11:00 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\SGIntl32.dll
[2009/12/24 07:10:58 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\SGHelp32.dll
[2009/12/24 07:10:58 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\SGDt32.dll
[2009/12/24 07:10:52 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeXml.dll
[2009/12/24 07:10:44 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeXP.dll
[2009/12/24 07:10:40 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeDefault.dll
[2009/12/24 07:10:34 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeManager.dll
[2009/12/24 07:10:28 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\SGCom32.dll
[2009/12/24 07:09:52 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\SGSTDREG.dll
[2009/12/24 07:09:48 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\SGRegister.dll
[2009/12/24 07:09:44 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\SGWebBrowser.dll
[2009/07/27 10:15:32 | 000,001,205 | ---- | C] () -- C:\WINDOWS\SAGEINTL.INI
[2008/12/22 05:28:06 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SageFolderBrowser.dll
[2008/12/01 10:37:00 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\SageEventHandler.exe
[2008/12/01 10:36:12 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\SGCtrlEx.dll
[2008/12/01 10:36:06 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\SGTBAR32.DLL
[2008/12/01 10:36:02 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SGSTAT32.DLL
[2008/12/01 10:36:02 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SGLOGO32.DLL
[2008/12/01 10:36:00 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\SGJPEG32.dll
[2008/12/01 10:35:56 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\SGCDLG32.DLL
[2008/12/01 10:35:36 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SGAPPBAR.DLL
[2008/12/01 10:35:34 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SG3D32.DLL
[2008/04/14 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/04/14 07:00:00 | 000,541,014 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/04/14 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/04/14 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/04/14 07:00:00 | 000,096,742 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/04/14 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/04/14 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/04/14 07:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/04/14 07:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/04/14 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/11/01 11:41:24 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\SGLCH32.DLL
[2006/11/01 11:41:16 | 001,712,128 | ---- | C] () -- C:\WINDOWS\System32\SGRep32.dll
[2005/08/23 08:12:36 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\SDOApp.dll
[2005/08/22 03:32:00 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\REPDES32.EXE
[2005/04/15 11:52:33 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005/04/15 11:52:33 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/06/09 05:57:12 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\Install.exe
[2002/04/16 06:27:54 | 000,000,005 | -HS- | C] () -- C:\WINDOWS\System32\CdI5T.drv
[1999/10/25 04:53:58 | 000,015,917 | ---- | C] () -- C:\WINDOWS\Sage.ini
[1998/03/25 19:12:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\SgHmZLib.dll
========== LOP Check ========== [2013/05/09 10:03:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Babylon
[2012/11/14 10:57:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TeamViewer
[2012/11/21 05:19:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TuneUp Software
[2013/11/13 05:15:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AGM
[2013/01/23 04:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG January 2013 Campaign
[2012/11/21 05:13:50 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/07/17 06:16:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2014/02/25 04:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2012/10/19 03:57:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
[2011/12/19 11:00:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sage
[2013/07/24 07:20:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2013/09/19 07:30:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2013/01/16 09:59:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2014/02/27 04:23:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\Tasks\BitGuard.job
[2013/01/23 04:09:57 | 000,000,374 | ---- | M] () -- C:\WINDOWS\Tasks\ROC_REG_JAN_DELETE.job
========== Purity Check ========== ========== Custom Scans ========== < +OTL logfile created on: 2/27/2014 10:22:39 AM - Run >Invalid Switch: 2014 10:22:39 AM - Run
< OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE > < Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM > < Internet Explorer (Version = 8.0.6001.18702) > < Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy >Invalid Switch: yyyy
< 1,015.00 Mb Total Physical Memory | 827.00 Mb Available Physical Memory | 81.00% Memory free > < 903.00 Mb Paging File | 848.00 Mb Available in Paging File | 94.00% Paging File free > < Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] > < %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files > < Drive C: | 18.61 Gb Total Space | 0.93 Gb Free Space | 4.98% Space Free | Partition Type: NTFS > < Drive X: | 284.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS > < Computer Name: REATOGO | User Name: SYSTEM > < Boot Mode: Normal | Scan Mode: All users > < Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days > < Using ControlSet: ControlSet001 > < ========== Win32 Services (SafeList) ========== >Invalid Switch: color]
< SRV - [2014/02/10 06:35:22 | 001,444,120 | ---- | M] (Trusteer Ltd.) [Auto] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService) >Invalid Switch: 10 06:35:22 | 001,444,120 | ---- | M] (Trusteer Ltd.) [Auto] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
< SRV - [2013/11/19 20:54:20 | 000,283,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe -- (avgwd) >Invalid Switch: 19 20:54:20 | 000,283,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe -- (avgwd)
< SRV - [2013/07/04 09:53:10 | 004,939,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- C:\Program Files\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent) >Invalid Switch: 04 09:53:10 | 004,939,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- C:\Program Files\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent)
< SRV - [2012/10/03 09:51:04 | 000,725,400 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) >Invalid Switch: 03 09:51:04 | 000,725,400 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
< SRV - [2009/12/16 15:09:34 | 000,049,152 | ---- | M] (Sage (UK) Limited) [Auto] -- C:\Program Files\Common Files\Sage SData\Sage.SData.Service.exe -- (Sage SData Service) >Invalid Switch: 16 15:09:34 | 000,049,152 | ---- | M] (Sage (UK) Limited) [Auto] -- C:\Program Files\Common Files\Sage SData\Sage.SData.Service.exe -- (Sage SData Service)
< ========== Driver Services (SafeList) ========== >Invalid Switch: color]
< DRV - File not found [Kernel | On_Demand] -- -- (WDICA) > < DRV - File not found [Kernel | On_Demand] -- -- (smwdm) > < DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME) > < DRV - File not found [Kernel | On_Demand] -- -- (PDRELI) > < DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME) > < DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP) > < DRV - File not found [Kernel | System] -- -- (PCIDump) > < DRV - File not found [Kernel | System] -- -- (lbrtfdc) > < DRV - File not found [Kernel | System] -- -- (i2omgmt) > < DRV - File not found [Kernel | System] -- -- (Changer) > < DRV - File not found [Kernel | On_Demand] -- -- (aeaudio) > < DRV - [2014/02/10 06:35:40 | 000,228,888 | ---- | M] (Trusteer Ltd.) [Kernel | System] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG) >Invalid Switch: 10 06:35:40 | 000,228,888 | ---- | M] (Trusteer Ltd.) [Kernel | System] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
< DRV - [2014/02/10 06:35:40 | 000,155,704 | ---- | M] (Trusteer Ltd.) [Kernel | System] -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys -- (RapportEI) >Invalid Switch: 10 06:35:40 | 000,155,704 | ---- | M] (Trusteer Ltd.) [Kernel | System] -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys -- (RapportEI)
< DRV - [2014/02/10 06:35:40 | 000,107,256 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RapportKELL.sys -- (RapportKELL) >Invalid Switch: 10 06:35:40 | 000,107,256 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RapportKELL.sys -- (RapportKELL)
< DRV - [2013/12/13 03:01:17 | 000,340,432 | ---- | M] () [Kernel | System] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_59849.sys -- (RapportCerberus_59849) >Invalid Switch: 13 03:01:17 | 000,340,432 | ---- | M] () [Kernel | System] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_59849.sys -- (RapportCerberus_59849)
< DRV - [2012/11/28 10:42:28 | 000,136,520 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\bkrwbus.sys -- (bkrwbus) >Invalid Switch: 28 10:42:28 | 000,136,520 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\bkrwbus.sys -- (bkrwbus)
< DRV - [2012/11/28 10:42:28 | 000,083,400 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\bkrwbk.sys -- (bkrwbk) >Invalid Switch: 28 10:42:28 | 000,083,400 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\bkrwbk.sys -- (bkrwbk)
< DRV - [2012/06/11 08:17:44 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu) >Invalid Switch: 11 08:17:44 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
< DRV - [2012/06/11 08:17:44 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc) >Invalid Switch: 11 08:17:44 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
< DRV - [2011/08/17 03:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) >Invalid Switch: 17 03:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
< DRV - [2011/08/17 03:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev) >Invalid Switch: 17 03:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
< DRV - [2001/08/17 07:11:18 | 000,020,160 | ---- | M] (ADMtek Incorporated) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ADM8511.SYS -- (ADM8511) >Invalid Switch: 17 07:11:18 | 000,020,160 | ---- | M] (ADMtek Incorporated) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ADM8511.SYS -- (ADM8511)
< ========== Standard Registry (SafeList) ========== >Invalid Switch: color]
< ========== Internet Explorer ========== >Invalid Switch: color]
< IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...r=971255584&ir= >Invalid Switch: ?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzutDtDtDzzyByEtCtA0AtCyBzytDtA0E0CtN0D0Tzu0CyDyBtDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=971255584&ir=
< IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 > < IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.delta-se...913_c1&tsp=5010 >Invalid Switch: ?babsrc=HP_ss&mntrId=286800087413A179&affID=120107&tt=160913_c1&tsp=5010
< IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 > < IE - HKU\systemprofile_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 > < FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) >Invalid Switch: pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
< FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) >Invalid Switch: NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
< FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) >Invalid Switch: WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
< FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) >Invalid Switch: pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
< FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) >Invalid Switch: pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
< FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) >Invalid Switch: Google Update;version=3: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
< FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) >Invalid Switch: Google Update;version=9: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
< O1 HOSTS File: ([2008/04/14 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts >Invalid Switch: 14 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
< O1 - Hosts: 127.0.0.1 localhost > < O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - File not found > < O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - File not found > < O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. > < O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - File not found > < O4 - HKLM..\Run: [AML Registry Cleaner] File not found > < O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) > < O4 - HKLM..\Run: [KernelFaultCheck] File not found > < O4 - HKLM..\RunOnce: [*Restore] C:\WINDOWS\System32\restore\rstrui.exe (Microsoft Corporation) > < O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 > < O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 > < O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 > < O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 > < O7 - HKU\systemprofile_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 > < O7 - HKU\TEMP_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149 > < O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 0.0.0.0 > < O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) > < O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation) > < O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp > < O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp > < O32 - HKLM CDRom: AutoRun - 1 > < O32 - AutoRun File - [2011/12/19 09:00:07 | 000,000,040 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] >Invalid Switch: 19 09:00:07 | 000,000,040 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
< O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] >Invalid Switch: 24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
< O34 - HKLM BootExecute: (autocheck autochk *) - File not found > < O35 - HKLM\..comfile [open] -- "%1" %* > < O35 - HKLM\..exefile [open] -- "%1" %* > < O37 - HKLM\...com [@ = comfile] -- "%1" %* > < O37 - HKLM\...exe [@ = exefile] -- "%1" %* > < ========== Files/Folders - Created Within 30 Days ========== >Invalid Switch: color]
< [2014/02/25 16:44:12 | 000,000,000 | ---D | C] -- C:\FRST >Invalid Switch: 25 16:44:12 | 000,000,000 | ---D | C] -- C:\FRST
< [2014/02/25 08:00:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MRT >Invalid Switch: 25 08:00:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MRT
< [2014/02/25 05:02:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Sage >Invalid Switch: 25 05:02:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Sage
< [2014/02/25 04:58:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Trusteer >Invalid Switch: 25 04:58:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Trusteer
< [2014/02/25 04:55:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Google >Invalid Switch: 25 04:55:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Google
< [2014/02/25 04:30:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Avg2013 >Invalid Switch: 25 04:30:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Avg2013
< [2014/02/25 04:30:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\MFAData >Invalid Switch: 25 04:30:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\MFAData
< [2014/02/25 03:53:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Trusteer >Invalid Switch: 25 03:53:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Trusteer
< [2014/02/25 03:47:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Microsoft >Invalid Switch: 25 03:47:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Microsoft
< [2014/02/10 06:35:40 | 000,107,256 | ---- | C] (Trusteer Ltd.) -- C:\WINDOWS\System32\drivers\RapportKELL.sys >Invalid Switch: 10 06:35:40 | 000,107,256 | ---- | C] (Trusteer Ltd.) -- C:\WINDOWS\System32\drivers\RapportKELL.sys
< [2010/02/09 06:32:16 | 000,184,320 | R--- | C] ( ) -- C:\WINDOWS\System32\SgE.interop.MSXML2.dll >Invalid Switch: 09 06:32:16 | 000,184,320 | R--- | C] ( ) -- C:\WINDOWS\System32\SgE.interop.MSXML2.dll
< [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] > < [2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ] > < [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] > < ========== Files - Modified Within 30 Days ========== >Invalid Switch: color]
< [2014/02/27 04:23:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat >Invalid Switch: 27 04:23:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
< [2014/02/27 04:23:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\BitGuard.job >Invalid Switch: 27 04:23:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\BitGuard.job
< [2014/02/27 03:52:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl >Invalid Switch: 27 03:52:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
< [2014/02/27 03:45:00 | 000,001,010 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1214440339-1644491937-500UA.job >Invalid Switch: 27 03:45:00 | 000,001,010 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1214440339-1644491937-500UA.job
< [2014/02/26 08:45:00 | 000,000,958 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1214440339-1644491937-500Core.job >Invalid Switch: 26 08:45:00 | 000,000,958 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1214440339-1644491937-500Core.job
< [2014/02/25 09:28:31 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat >Invalid Switch: 25 09:28:31 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
< [2014/02/25 05:03:35 | 000,000,679 | ---- | M] () -- C:\WINDOWS\ODBC.INI >Invalid Switch: 25 05:03:35 | 000,000,679 | ---- | M] () -- C:\WINDOWS\ODBC.INI
< [2014/02/25 04:41:00 | 000,161,936 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT >Invalid Switch: 25 04:41:00 | 000,161,936 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
< [2014/02/24 10:40:24 | 000,002,489 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Word.lnk >Invalid Switch: 24 10:40:24 | 000,002,489 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Word.lnk
< [2014/02/24 06:38:27 | 000,000,640 | ---- | M] () -- C:\WINDOWS\System32\SGLCH32.USR >Invalid Switch: 24 06:38:27 | 000,000,640 | ---- | M] () -- C:\WINDOWS\System32\SGLCH32.USR
< [2014/02/24 03:22:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Trusteer Endpoint Protection >Invalid Switch: 24 03:22:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Trusteer Endpoint Protection
< [2014/02/18 06:04:31 | 000,002,487 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Excel.lnk >Invalid Switch: 18 06:04:31 | 000,002,487 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Excel.lnk
< [2014/02/14 13:04:14 | 000,541,014 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat >Invalid Switch: 14 13:04:14 | 000,541,014 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
< [2014/02/14 13:04:14 | 000,096,742 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat >Invalid Switch: 14 13:04:14 | 000,096,742 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
< [2014/02/14 12:23:46 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK >Invalid Switch: 14 12:23:46 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
< [2014/02/10 06:35:40 | 000,107,256 | ---- | M] (Trusteer Ltd.) -- C:\WINDOWS\System32\drivers\RapportKELL.sys >Invalid Switch: 10 06:35:40 | 000,107,256 | ---- | M] (Trusteer Ltd.) -- C:\WINDOWS\System32\drivers\RapportKELL.sys
< [2014/02/05 22:54:08 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe >Invalid Switch: 05 22:54:08 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe
< [2014/02/05 22:54:08 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ie4uinit.exe >Invalid Switch: 05 22:54:08 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ie4uinit.exe
< [2014/02/05 18:26:52 | 000,920,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll >Invalid Switch: 05 18:26:52 | 000,920,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
< [2014/02/05 18:26:51 | 000,759,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vgx.dll >Invalid Switch: 05 18:26:51 | 000,759,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vgx.dll
< [2014/02/05 18:26:50 | 001,216,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll >Invalid Switch: 05 18:26:50 | 001,216,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll
< [2014/02/05 18:26:49 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mstime.dll >Invalid Switch: 05 18:26:49 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mstime.dll
< [2014/02/05 18:26:49 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll >Invalid Switch: 05 18:26:49 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
< [2014/02/05 18:26:49 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll >Invalid Switch: 05 18:26:49 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll
< [2014/02/05 18:26:49 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll >Invalid Switch: 05 18:26:49 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll
< [2014/02/05 18:26:49 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll >Invalid Switch: 05 18:26:49 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll
< [2014/02/05 18:26:48 | 006,021,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll >Invalid Switch: 05 18:26:48 | 006,021,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
< [2014/02/05 18:26:48 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll >Invalid Switch: 05 18:26:48 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll
< [2014/02/05 18:26:44 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedsbs.dll >Invalid Switch: 05 18:26:44 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedsbs.dll
< [2014/02/05 18:26:44 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll >Invalid Switch: 05 18:26:44 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
< [2014/02/05 18:26:43 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll >Invalid Switch: 05 18:26:43 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll
< [2014/02/05 18:26:43 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll >Invalid Switch: 05 18:26:43 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
< [2014/02/05 18:26:43 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\licmgr10.dll >Invalid Switch: 05 18:26:43 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\licmgr10.dll
< [2014/02/05 18:26:43 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\licmgr10.dll >Invalid Switch: 05 18:26:43 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\licmgr10.dll
< [2014/02/05 18:26:43 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll >Invalid Switch: 05 18:26:43 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll
< [2014/02/05 18:26:43 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll >Invalid Switch: 05 18:26:43 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll
< [2014/02/05 18:26:42 | 002,006,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll >Invalid Switch: 05 18:26:42 | 002,006,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
< [2014/02/05 18:26:42 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl >Invalid Switch: 05 18:26:42 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl
< [2014/02/05 18:26:42 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl >Invalid Switch: 05 18:26:42 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl
< [2014/02/05 18:26:42 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsdbgui.dll >Invalid Switch: 05 18:26:42 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsdbgui.dll
< [2014/02/05 18:26:41 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iepeers.dll >Invalid Switch: 05 18:26:41 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iepeers.dll
< [2014/02/05 18:26:41 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll >Invalid Switch: 05 18:26:41 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll
< [2014/02/05 18:26:40 | 011,113,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll >Invalid Switch: 05 18:26:40 | 011,113,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
< [2014/02/05 18:26:38 | 000,743,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll >Invalid Switch: 05 18:26:38 | 000,743,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
< [2014/02/05 18:26:37 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll >Invalid Switch: 05 18:26:37 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll
< [2014/02/05 18:26:37 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll >Invalid Switch: 05 18:26:37 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll
< [2014/02/05 18:26:37 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\corpol.dll >Invalid Switch: 05 18:26:37 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\corpol.dll
< [2014/02/05 18:26:37 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\corpol.dll >Invalid Switch: 05 18:26:37 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\corpol.dll
< [2014/02/05 17:24:05 | 000,385,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\html.iec >Invalid Switch: 05 17:24:05 | 000,385,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\html.iec
< [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] > < [2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ] > < [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] > < ========== Files Created - No Company Name ========== >Invalid Switch: color]
< [2014/02/25 08:48:39 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat >Invalid Switch: 25 08:48:39 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
< [2013/07/04 10:56:28 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\UKCpInfo.sys >Invalid Switch: 04 10:56:28 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\UKCpInfo.sys
< [2013/06/17 12:52:21 | 000,000,096 | ---- | C] () -- C:\WINDOWS\CPS.INI >Invalid Switch: 17 12:52:21 | 000,000,096 | ---- | C] () -- C:\WINDOWS\CPS.INI
< [2013/03/12 04:39:42 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc >Invalid Switch: 12 04:39:42 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc
< [2013/03/07 04:23:37 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini >Invalid Switch: 07 04:23:37 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
< [2013/03/01 05:42:55 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll >Invalid Switch: 01 05:42:55 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
< [2013/02/21 10:08:15 | 000,000,062 | ---- | C] () -- C:\WINDOWS\Trick.INI >Invalid Switch: 21 10:08:15 | 000,000,062 | ---- | C] () -- C:\WINDOWS\Trick.INI
< [2011/12/16 06:42:23 | 000,000,679 | ---- | C] () -- C:\WINDOWS\ODBC.INI >Invalid Switch: 16 06:42:23 | 000,000,679 | ---- | C] () -- C:\WINDOWS\ODBC.INI
< [2011/12/16 05:32:41 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\e1000msg.dll >Invalid Switch: 16 05:32:41 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\e1000msg.dll
< [2011/12/15 11:04:16 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat >Invalid Switch: 15 11:04:16 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
< [2011/12/15 10:56:21 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat >Invalid Switch: 15 10:56:21 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
< [2011/12/15 10:31:45 | 000,004,629 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI >Invalid Switch: 15 10:31:45 | 000,004,629 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
< [2011/12/15 10:30:23 | 000,161,936 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT >Invalid Switch: 15 10:30:23 | 000,161,936 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
< [2010/02/09 06:33:54 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\SgELauncher.dll >Invalid Switch: 09 06:33:54 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\SgELauncher.dll
< [2010/02/09 06:33:14 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\SgEData.dll >Invalid Switch: 09 06:33:14 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\SgEData.dll
< [2009/12/24 07:11:10 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\SGList32.dll >Invalid Switch: 24 07:11:10 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\SGList32.dll
< [2009/12/24 07:11:04 | 000,278,528 | ---- | C] () -- C:\WINDOWS\System32\SGTool32.dll >Invalid Switch: 24 07:11:04 | 000,278,528 | ---- | C] () -- C:\WINDOWS\System32\SGTool32.dll
< [2009/12/24 07:11:00 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\SGIntl32.dll >Invalid Switch: 24 07:11:00 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\SGIntl32.dll
< [2009/12/24 07:10:58 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\SGHelp32.dll >Invalid Switch: 24 07:10:58 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\SGHelp32.dll
< [2009/12/24 07:10:58 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\SGDt32.dll >Invalid Switch: 24 07:10:58 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\SGDt32.dll
< [2009/12/24 07:10:52 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeXml.dll >Invalid Switch: 24 07:10:52 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeXml.dll
< [2009/12/24 07:10:44 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeXP.dll >Invalid Switch: 24 07:10:44 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeXP.dll
< [2009/12/24 07:10:40 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeDefault.dll >Invalid Switch: 24 07:10:40 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeDefault.dll
< [2009/12/24 07:10:34 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeManager.dll >Invalid Switch: 24 07:10:34 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeManager.dll
< [2009/12/24 07:10:28 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\SGCom32.dll >Invalid Switch: 24 07:10:28 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\SGCom32.dll
< [2009/12/24 07:09:52 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\SGSTDREG.dll >Invalid Switch: 24 07:09:52 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\SGSTDREG.dll
< [2009/12/24 07:09:48 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\SGRegister.dll >Invalid Switch: 24 07:09:48 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\SGRegister.dll
< [2009/12/24 07:09:44 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\SGWebBrowser.dll >Invalid Switch: 24 07:09:44 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\SGWebBrowser.dll
< [2009/07/27 10:15:32 | 000,001,205 | ---- | C] () -- C:\WINDOWS\SAGEINTL.INI >Invalid Switch: 27 10:15:32 | 000,001,205 | ---- | C] () -- C:\WINDOWS\SAGEINTL.INI
< [2008/12/22 05:28:06 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SageFolderBrowser.dll >Invalid Switch: 22 05:28:06 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SageFolderBrowser.dll
< [2008/12/01 10:37:00 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\SageEventHandler.exe >Invalid Switch: 01 10:37:00 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\SageEventHandler.exe
< [2008/12/01 10:36:12 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\SGCtrlEx.dll >Invalid Switch: 01 10:36:12 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\SGCtrlEx.dll
< [2008/12/01 10:36:06 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\SGTBAR32.DLL >Invalid Switch: 01 10:36:06 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\SGTBAR32.DLL
< [2008/12/01 10:36:02 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SGSTAT32.DLL >Invalid Switch: 01 10:36:02 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SGSTAT32.DLL
< [2008/12/01 10:36:02 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SGLOGO32.DLL >Invalid Switch: 01 10:36:02 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SGLOGO32.DLL
< [2008/12/01 10:36:00 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\SGJPEG32.dll >Invalid Switch: 01 10:36:00 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\SGJPEG32.dll
< [2008/12/01 10:35:56 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\SGCDLG32.DLL >Invalid Switch: 01 10:35:56 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\SGCDLG32.DLL
< [2008/12/01 10:35:36 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SGAPPBAR.DLL >Invalid Switch: 01 10:35:36 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SGAPPBAR.DLL
< [2008/12/01 10:35:34 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SG3D32.DLL >Invalid Switch: 01 10:35:34 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SG3D32.DLL
< [2008/04/14 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat >Invalid Switch: 14 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
< [2008/04/14 07:00:00 | 000,541,014 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat >Invalid Switch: 14 07:00:00 | 000,541,014 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
< [2008/04/14 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat >Invalid Switch: 14 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
< [2008/04/14 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat >Invalid Switch: 14 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
< [2008/04/14 07:00:00 | 000,096,742 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat >Invalid Switch: 14 07:00:00 | 000,096,742 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
< [2008/04/14 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin >Invalid Switch: 14 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
< [2008/04/14 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat >Invalid Switch: 14 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
< [2008/04/14 07:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat >Invalid Switch: 14 07:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
< [2008/04/14 07:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin >Invalid Switch: 14 07:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
< [2008/04/14 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat >Invalid Switch: 14 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
< [2006/11/01 11:41:24 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\SGLCH32.DLL >Invalid Switch: 01 11:41:24 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\SGLCH32.DLL
< [2006/11/01 11:41:16 | 001,712,128 | ---- | C] () -- C:\WINDOWS\System32\SGRep32.dll >Invalid Switch: 01 11:41:16 | 001,712,128 | ---- | C] () -- C:\WINDOWS\System32\SGRep32.dll
< [2005/08/23 08:12:36 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\SDOApp.dll >Invalid Switch: 23 08:12:36 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\SDOApp.dll
< [2005/08/22 03:32:00 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\REPDES32.EXE >Invalid Switch: 22 03:32:00 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\REPDES32.EXE
< [2005/04/15 11:52:33 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin >Invalid Switch: 15 11:52:33 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
< [2005/04/15 11:52:33 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat >Invalid Switch: 15 11:52:33 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
< [2004/06/09 05:57:12 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\Install.exe >Invalid Switch: 09 05:57:12 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\Install.exe
< [2002/04/16 06:27:54 | 000,000,005 | -HS- | C] () -- C:\WINDOWS\System32\CdI5T.drv >Invalid Switch: 16 06:27:54 | 000,000,005 | -HS- | C] () -- C:\WINDOWS\System32\CdI5T.drv
< [1999/10/25 04:53:58 | 000,015,917 | ---- | C] () -- C:\WINDOWS\Sage.ini >Invalid Switch: 25 04:53:58 | 000,015,917 | ---- | C] () -- C:\WINDOWS\Sage.ini
< [1998/03/25 19:12:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\SgHmZLib.dll >Invalid Switch: 25 19:12:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\SgHmZLib.dll
< ========== LOP Check ========== >Invalid Switch: color]
< [2013/05/09 10:03:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Babylon >Invalid Switch: 09 10:03:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Babylon
< [2012/11/14 10:57:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TeamViewer >Invalid Switch: 14 10:57:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TeamViewer
< [2012/11/21 05:19:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TuneUp Software >Invalid Switch: 21 05:19:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TuneUp Software
< [2013/11/13 05:15:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AGM >Invalid Switch: 13 05:15:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AGM
< [2013/01/23 04:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG January 2013 Campaign >Invalid Switch: 23 04:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG January 2013 Campaign
< [2012/11/21 05:13:50 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files >Invalid Switch: 21 05:13:50 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
< [2012/07/17 06:16:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IsolatedStorage >Invalid Switch: 17 06:16:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IsolatedStorage
< [2014/02/25 04:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData >Invalid Switch: 25 04:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
< [2012/10/19 03:57:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache >Invalid Switch: 19 03:57:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
< [2011/12/19 11:00:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sage >Invalid Switch: 19 11:00:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sage
< [2013/07/24 07:20:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tarma Installer >Invalid Switch: 24 07:20:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tarma Installer
< [2013/09/19 07:30:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP >Invalid Switch: 19 07:30:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
< [2013/01/16 09:59:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer >Invalid Switch: 16 09:59:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
< [2014/02/27 04:23:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\Tasks\BitGuard.job >Invalid Switch: 27 04:23:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\Tasks\BitGuard.job
< [2013/01/23 04:09:57 | 000,000,374 | ---- | M] () -- C:\WINDOWS\Tasks\ROC_REG_JAN_DELETE.job >Invalid Switch: 23 04:09:57 | 000,000,374 | ---- | M] () -- C:\WINDOWS\Tasks\ROC_REG_JAN_DELETE.job
< ========== Purity Check ========== >Invalid Switch: color]
< < End of report > >< End of report >
I hope this helps
regds
K