OTL logfile created on: 2/6/2010 4:34:17 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Downloads\software
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 83.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 34.13 Gb Free Space | 7.33% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 465.68 Gb Free Space | 99.98% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KTENG
Current User Name: Kevin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/02/04 22:00:33 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Downloads\software\OTL.exe
PRC - [2010/02/03 13:02:22 | 001,217,808 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\steam.exe
PRC - [2010/01/22 16:59:30 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/12/22 00:48:32 | 002,127,408 | ---- | M] (Trend Media Corporation Limited) -- C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe
PRC - [2009/11/19 22:12:14 | 000,623,960 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
PRC - [2009/03/02 12:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008/07/23 00:51:26 | 016,804,864 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe
PRC - [2008/06/18 02:01:56 | 000,077,824 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SoundMan.exe
PRC - [2007/02/03 18:38:24 | 000,274,432 | ---- | M] (SillySot Software) -- C:\Program Files\Iconoid\iconoid.exe
PRC - [2006/08/01 14:35:36 | 000,067,112 | ---- | M] (America Online, Inc.) -- C:\Program Files\AIM\aim.exe
PRC - [2004/08/03 23:56:58 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
PRC - [2004/08/03 23:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ========== MOD - [2010/02/04 22:00:33 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Downloads\software\OTL.exe
MOD - [2006/08/25 07:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (RoxLiveShare9)
SRV - File not found [Disabled | Stopped] -- -- (IDriverT)
SRV - [2010/02/04 19:02:21 | 001,181,328 | ---- | M] (Lavasoft) [Disabled | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/01/28 15:15:33 | 002,431,024 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\rswin_3647.dll -- (Akamai)
SRV - [2010/01/11 22:17:44 | 000,154,216 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\nvsvc32.exe -- (nvsvc)
SRV - [2009/12/11 15:47:44 | 000,036,352 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2009/11/12 09:08:00 | 003,403,420 | ---- | M] (INCA Internet Co., Ltd.) [Disabled | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2009/11/03 15:13:44 | 000,295,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\termsrv32.dll -- (TermService)
SRV - [2009/10/11 04:17:35 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Disabled | Stopped] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009/07/21 13:34:33 | 000,185,089 | ---- | M] (Avira GmbH) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009/05/13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2008/11/04 01:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/10/25 11:44:08 | 000,065,888 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2008/09/25 00:35:14 | 000,068,136 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service)
SRV - [2007/11/06 12:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [Disabled | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/04/19 21:29:44 | 000,411,168 | ---- | M] (Acronis) [Disabled | Stopped] -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2007/01/04 13:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Disabled | Stopped] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2006/10/26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [1999/12/13 00:01:00 | 000,044,032 | ---- | M] (Creative Technology Ltd) [Disabled | Stopped] -- C:\WINDOWS\system32\CTSVCCDA.EXE -- (Creative Service for CDROM Access)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll (DeviceVM Inc.)
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\..\URLSearchHook: {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll (America Online, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledItems: {DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}:1.0
FF - prefs.js..extensions.enabledItems: {a756d17a-5a4c-4417-813c-c8cd0151e486}:1.3.2
FF - prefs.js..extensions.enabledItems:
[email protected]:1.5.1
FF - prefs.js..extensions.enabledItems:
[email protected]:1.4
FF - HKLM\software\mozilla\Flock 2.0.3\extensions\\Plugins: C:\Program Files\Flock\plugins [2009/11/01 10:34:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/26 15:09:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/22 16:59:42 | 000,000,000 | ---D | M]
[2009/11/09 14:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions
[2009/05/17 21:28:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2009/11/09 14:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions\
[email protected][2010/02/06 00:10:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\g3z0emxl.default\extensions
[2010/01/04 13:54:44 | 000,000,000 | ---D | M] (Open Profile Folder) -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\g3z0emxl.default\extensions\{a756d17a-5a4c-4417-813c-c8cd0151e486}
[2010/01/01 12:57:05 | 000,000,000 | ---D | M] (flashget3 Extension) -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\g3z0emxl.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}
[2009/05/21 22:45:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\g3z0emxl.default\extensions\
[email protected][2010/02/06 00:10:44 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009/07/03 00:34:44 | 000,083,376 | ---- | M] (NHN USA Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
[2010/02/04 17:13:50 | 000,238,776 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2007/04/16 09:07:12 | 000,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2009/10/31 12:42:43 | 000,000,759 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 live.refx.net
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (FGCatchUrl) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll (www.flashget.com)
O2 - BHO: (AOLSearchHook Class) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll (America Online, Inc.)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Documents and Settings\Kevin\Application Data\FlashGetBHO\FlashGetBHO3.dll (Trend Media Group)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (FlashGet GetFlash Class) - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll (www.flashget.com)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl File not found
O4 - HKCU..\Run: [FlashGet 3] C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe (Trend Media Corporation Limited)
O4 - HKCU..\Run: [Iconoid] C:\Program Files\Iconoid\iconoid.exe (SillySot Software)
O4 - HKCU..\Run: [Steam] c:\program files\steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\JC_ALL.HTM ()
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\JC_LINK.HTM ()
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Download All By FlashGet3 - C:\Documents and Settings\Kevin\Application Data\FlashGetBHO\GetAllUrl.htm ()
O8 - Extra context menu item: Download By FlashGet3 - C:\Documents and Settings\Kevin\Application Data\FlashGetBHO\GetUrl.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O9 - Extra Button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/19 21:48:43 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{2de08cb2-c715-11de-acd9-001fd080e29d}\Shell - "" = AutoRun
O33 - MountPoints2\{2de08cb2-c715-11de-acd9-001fd080e29d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2de08cb2-c715-11de-acd9-001fd080e29d}\Shell\AutoRun\command - "" = F:\Torchlight_Setup.exe -- File not found
O33 - MountPoints2\{fd84b14a-c720-11de-acda-001fd080e29d}\Shell - "" = AutoRun
O33 - MountPoints2\{fd84b14a-c720-11de-acda-001fd080e29d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{fd84b14a-c720-11de-acda-001fd080e29d}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2010/01/03 04:54:33 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (53765113575899136)
========== Files/Folders - Created Within 14 Days ========== [2010/02/04 18:41:45 | 000,000,000 | ---D | C] -- C:\Program Files\Debugging Tools for Windows (x86)
[2010/02/04 17:41:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kevin\Desktop\Steam Hack v12
[2010/02/04 17:35:51 | 000,000,000 | ---D | C] -- C:\Program Files\gPotato
[2010/02/03 21:03:34 | 003,550,592 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\Kevin\Desktop\procexp.exe
[2010/02/03 14:59:36 | 000,096,104 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2010/02/03 14:59:36 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/02/03 14:59:36 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/02/03 14:59:35 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/02/03 14:59:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2010/02/03 13:45:23 | 000,000,000 | ---D | C] -- C:\Program Files\Driver Cleaner Pro
[2010/02/03 13:42:01 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2010/02/03 13:25:19 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Kevin\Recent
[2010/02/01 21:18:39 | 000,000,000 | ---D | C] -- C:\Program Files\OpenVPN
[2010/01/23 23:04:03 | 000,000,000 | --SD | C] -- C:\Program Files\HLSW
[2010/01/23 23:04:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kevin\Application Data\HLSW
[2010/01/23 21:58:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/01/23 21:06:50 | 000,000,000 | ---D | C] -- C:\Program Files\WebEx
[2010/01/23 21:03:05 | 000,000,000 | ---D | C] -- C:\CC Get MAC Address
[2009/05/30 10:52:06 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/05/29 15:56:07 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/04/19 21:53:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[1 C:\Documents and Settings\Kevin\Desktop\*.tmp files -> C:\Documents and Settings\Kevin\Desktop\*.tmp -> ]
========== Files - Modified Within 14 Days ========== [2010/02/06 16:33:50 | 000,012,904 | ---- | M] () -- C:\WINDOWS\System32\secushr.dat
[2010/02/06 16:29:47 | 000,267,982 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010/02/06 16:29:30 | 000,000,312 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2010/02/06 16:29:28 | 000,012,644 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/02/06 16:28:58 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/02/06 16:28:47 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/02/06 16:28:41 | 3487,805,440 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2010/02/06 16:02:15 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/02/06 13:02:10 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2010/02/06 07:02:12 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2010/02/06 01:02:21 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2010/02/06 00:37:32 | 000,014,601 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\Kevin's Fitness Plan.docx
[2010/02/05 23:57:33 | 015,466,496 | ---- | M] () -- C:\Documents and Settings\Kevin\ntuser.dat
[2010/02/05 23:57:33 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Kevin\ntuser.ini
[2010/02/05 23:49:54 | 000,000,633 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/02/05 23:49:54 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/02/05 23:47:11 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Kevin\Desktop\~$vin's Fitness Plan.docx
[2010/02/05 23:42:50 | 000,027,648 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\Workout.xls
[2010/02/05 22:02:05 | 000,002,096 | ---- | M] () -- C:\WINDOWS\System32\secustat.dat
[2010/02/05 19:02:24 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2010/02/04 22:34:37 | 009,231,414 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\74004-esea_match_1548100.zip
[2010/02/04 21:23:26 | 011,389,564 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\56077-esea_match_1540169.zip
[2010/02/04 19:06:27 | 000,000,334 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\XP Shell State.zip
[2010/02/04 17:38:37 | 000,045,518 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\SteamHackv12.rar
[2010/02/04 17:38:32 | 000,001,710 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\AikaOnline.lnk
[2010/02/04 17:25:22 | 447,960,356 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\AikaOnlineInstaller.exe
[2010/02/04 15:00:26 | 000,056,816 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/02/04 13:56:26 | 000,272,576 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/02/03 22:52:28 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/02/03 21:37:25 | 000,095,558 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\
[email protected]@G31.2.rar
[2010/02/03 21:07:23 | 000,255,542 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\F0RBiDD3N.rar
[2010/02/03 14:59:55 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/02/03 14:53:39 | 000,071,240 | ---- | M] () -- C:\Documents and Settings\Kevin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/02/03 14:52:41 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/02/03 13:29:06 | 000,133,632 | ---- | M] () -- C:\Documents and Settings\Kevin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/02 17:57:30 | 040,235,720 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\esea_match_1537129.dem
[2010/02/01 21:18:51 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\OpenVPN GUI.lnk
[2010/01/31 01:02:10 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/01/30 22:48:19 | 005,464,068 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\63129-esea_match_1544445.zip
[2010/01/30 19:38:24 | 000,000,430 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\Shortcut to CS Stuff.lnk
[2010/01/24 02:20:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\Driver Robot.job
[2010/01/23 23:04:10 | 000,000,626 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\HLSW.lnk
[2010/01/23 21:06:46 | 008,892,928 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\atscie.msi
[2010/01/23 19:47:34 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\nuke_1.1.1.3.bmp
[2010/01/23 19:47:22 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\Kevin\Desktop\nuke_1.1.1.2.bmp
[1 C:\Documents and Settings\Kevin\Desktop\*.tmp files -> C:\Documents and Settings\Kevin\Desktop\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/02/05 23:47:11 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Kevin\Desktop\~$vin's Fitness Plan.docx
[2010/02/05 23:47:02 | 000,014,601 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\Kevin's Fitness Plan.docx
[2010/02/04 22:34:25 | 009,231,414 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\74004-esea_match_1548100.zip
[2010/02/04 21:23:15 | 011,389,564 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\56077-esea_match_1540169.zip
[2010/02/04 19:06:27 | 000,000,334 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\XP Shell State.zip
[2010/02/04 17:38:32 | 000,001,710 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\AikaOnline.lnk
[2010/02/04 17:16:15 | 447,960,356 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\AikaOnlineInstaller.exe
[2010/02/03 21:37:25 | 000,095,558 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\
[email protected]@G31.2.rar
[2010/02/03 21:07:23 | 000,255,542 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\F0RBiDD3N.rar
[2010/02/03 14:59:55 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/02/02 22:00:19 | 040,235,720 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\esea_match_1537129.dem
[2010/02/01 21:18:51 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\OpenVPN GUI.lnk
[2010/01/30 22:48:18 | 005,464,068 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\63129-esea_match_1544445.zip
[2010/01/30 19:38:24 | 000,000,430 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\Shortcut to CS Stuff.lnk
[2010/01/23 23:04:10 | 000,000,626 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\HLSW.lnk
[2010/01/23 21:06:44 | 008,892,928 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\atscie.msi
[2010/01/23 19:47:34 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\nuke_1.1.1.3.bmp
[2010/01/23 19:47:21 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\Kevin\Desktop\nuke_1.1.1.2.bmp
[2010/01/01 21:56:55 | 000,000,143 | ---- | C] () -- C:\WINDOWS\GKLauncherInfo.ini
[2010/01/01 02:22:38 | 000,000,025 | ---- | C] () -- C:\WINDOWS\libem.INI
[2009/12/31 17:45:55 | 000,327,168 | ---- | C] () -- C:\WINDOWS\System32\cutil32.dll
[2009/11/01 11:57:45 | 000,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2009/11/01 11:57:45 | 000,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2009/09/07 11:02:28 | 000,000,000 | ---- | C] () -- C:\Program Files\AstonWriteTest.txt
[2009/07/29 23:53:32 | 000,031,616 | ---- | C] () -- C:\WINDOWS\System32\drivers\vrtaucbl.sys
[2009/07/14 17:15:00 | 000,178,432 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2009/05/29 17:01:42 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Kevin\Local Settings\Application Data\fusioncache.dat
[2009/05/04 22:45:33 | 000,000,024 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/05/02 15:19:41 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\jfwapi.dll
[2009/04/30 15:08:39 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/04/26 12:54:27 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/04/22 21:02:55 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\IPPCPUID.DLL
[2009/04/22 21:02:08 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmsbfn32.dll
[2009/04/22 20:41:39 | 000,000,416 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2009/04/20 13:08:08 | 000,133,632 | ---- | C] () -- C:\Documents and Settings\Kevin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/07 08:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/11/06 12:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2006/11/10 05:08:50 | 000,024,064 | ---- | C] () -- C:\WINDOWS\System32\drivers\ATITool.sys
[2004/07/17 10:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[1996/04/03 11:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ========== [2009/12/09 20:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2DBoy
[2010/01/03 23:56:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ableton
[2009/04/20 12:33:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2009/04/20 12:33:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AIM Toolbar
[2009/04/22 20:39:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/11/01 11:09:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2009/04/21 21:51:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DFX
[2010/01/15 13:41:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/12/11 15:22:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NexonUS
[2009/10/09 14:26:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PassMark
[2010/02/04 17:16:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2009/10/13 12:24:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2010/01/18 22:17:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2009/04/22 20:41:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/01/03 18:17:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2009/10/23 22:04:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2010/01/01 23:49:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/04/21 13:47:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/02/02 17:11:17 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
[2010/01/03 23:56:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Ableton
[2009/04/20 12:34:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\acccore
[2009/04/21 13:48:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Aim
[2009/09/07 11:02:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Aston
[2010/02/06 16:30:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\BITS
[2009/08/22 13:47:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Blitware
[2010/01/04 19:37:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Canon
[2009/05/30 11:02:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\DAEMON Tools Lite
[2009/11/01 11:09:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\DAEMON Tools Pro
[2010/01/11 23:47:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\DragonicaSCB
[2010/01/01 02:19:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\FlashGet
[2010/01/01 02:19:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\FlashGetBHO
[2009/05/17 21:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Flock
[2009/09/24 17:01:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\GetRightToGo
[2010/01/03 02:22:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\GlarySoft
[2010/01/25 22:59:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\HLSW
[2009/04/21 16:11:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\InfraRecorder
[2010/01/02 21:48:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\LimeWire
[2009/12/11 17:12:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\NeopleLauncherDFO
[2009/04/22 21:10:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\NewSoft
[2009/11/14 00:24:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Notepad++
[2009/10/23 17:45:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\OpenCandy
[2009/05/17 21:44:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Opera
[2009/09/10 19:19:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Orbit
[2009/10/13 13:13:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Propellerhead Software
[2009/10/23 22:16:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Publish Providers
[2010/01/19 00:13:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Research In Motion
[2010/02/02 17:11:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\runic games
[2009/04/22 20:41:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\ScanSoft
[2009/10/23 22:17:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Sony
[2009/12/29 12:35:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\StarVault
[2009/10/23 21:53:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\Steinberg
[2010/02/05 15:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kevin\Application Data\uTorrent
[2010/02/06 01:02:21 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2010/02/06 07:02:12 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2010/02/06 13:02:10 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2010/02/05 19:02:24 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2010/01/31 01:02:10 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/01/24 02:20:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\Tasks\Driver Robot.job
[2010/02/06 16:29:30 | 000,000,312 | ---- | M] () -- C:\WINDOWS\Tasks\GlaryInitialize.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe >[2007/11/07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< MD5 for: AGP440.SYS >[2004/08/04 01:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\0b55f15d5d26161f7d256509\i386\sp2.cab:AGP440.sys
[2004/08/04 00:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >[2004/08/04 01:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\0b55f15d5d26161f7d256509\i386\sp2.cab:atapi.sys
[2004/08/04 00:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\atapi.sys
[2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/13 16:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\eventlog.dll
[2004/08/03 23:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004/08/03 23:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >[2008/04/13 16:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/03 23:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004/08/03 23:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >[2004/08/03 23:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004/08/03 23:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\scecli.dll
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2010/01/03 04:58:32 | 000,524,288 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010/01/03 12:48:50 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2010/01/03 04:58:32 | 031,195,136 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010/01/03 04:58:32 | 007,077,888 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ========== @Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D06A4C76
< End of report >