First off thanks for all the great work you guys do here. Anyways here's the situation. This is my mom's laptop which is likely full of viruses (which ones i have no idea). She plays a lot of social games (farmville, petville, etc) and has undoubtedly clicked on many malicious links. Her email has been infected and spams to her contact list and her computer lags very badly. Sorry i can't be more specific. Thanks in advance!
OTL logfile created on: 5/7/2011 10:30:50 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Admin-do not use\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 378.00 Mb Available Physical Memory | 37.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.31 Gb Total Space | 64.91 Gb Free Space | 75.21% Space Free | Partition Type: NTFS
Drive D: | 6.83 Gb Total Space | 4.77 Gb Free Space | 69.87% Space Free | Partition Type: FAT32
Computer Name: YOUR-555E3BEF9C | User Name: Admin-do not use | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/07 10:30:05 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Admin-do not use\My Documents\Downloads\OTL.exe
PRC - [2011/04/30 11:23:28 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Owner.YOUR-555E3BEF9C\Local Settings\Application Data\Google\Update\1.3.21.53\GoogleCrashHandler.exe
PRC - [2011/03/15 15:59:40 | 002,071,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/11/24 10:34:43 | 000,725,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/09/23 15:13:08 | 000,621,920 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/08/03 12:18:19 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/07/16 13:41:17 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/07/16 13:41:01 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/07/16 13:39:50 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/11/21 12:09:13 | 000,172,032 | ---- | M] (New Boundary Technologies, Inc.) -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
PRC - [2006/05/23 20:22:36 | 000,573,440 | ---- | M] (Motorola Inc.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
PRC - [2005/12/27 11:20:14 | 000,413,696 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2005/10/12 13:30:42 | 000,139,264 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2005/10/12 13:30:24 | 000,086,140 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2004/11/05 08:47:00 | 000,098,394 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
========== Modules (SafeList) ==========
MOD - [2011/05/07 10:30:05 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Admin-do not use\My Documents\Downloads\OTL.exe
MOD - [2010/08/23 09:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2004/11/05 08:47:00 | 000,069,722 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/10/06 11:31:48 | 000,517,448 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2010/07/16 13:41:01 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2006/11/21 12:09:13 | 000,172,032 | ---- | M] (New Boundary Technologies, Inc.) [Auto | Running] -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS -- (PrismXL)
SRV - [2005/10/12 13:30:24 | 000,086,140 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMon) Intel®
========== Driver Services (SafeList) ==========
DRV - [2011/05/05 15:20:01 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/07/16 13:40:12 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/06/13 12:46:16 | 000,029,584 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2009/07/18 16:14:56 | 000,054,416 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWBus.sys -- (PTUMWBus)
DRV - [2009/07/18 16:14:36 | 000,160,400 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWVsp.sys -- (PTUMWVsp)
DRV - [2009/07/18 16:14:32 | 000,160,400 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWNSP.sys -- (PTUMWNSP)
DRV - [2009/07/18 16:14:28 | 000,114,192 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWNET.sys -- (PTUMWNET)
DRV - [2009/07/18 16:14:16 | 000,160,400 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWMdm.sys -- (PTUMWMdm)
DRV - [2009/07/18 16:14:08 | 000,012,048 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWFLT.sys -- (PTUMWFLT)
DRV - [2009/07/18 16:14:04 | 000,160,400 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWCSP.sys -- (PTUMWCSP)
DRV - [2009/03/20 19:03:36 | 000,032,408 | ---- | M] (Smith Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Verizon Wireless\VZAccess Manager\SMSIVZAM5.sys -- (SMSIVZAM5)
DRV - [2006/08/02 02:27:48 | 000,012,544 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/06/15 16:28:04 | 001,179,784 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/05/23 20:30:06 | 000,893,952 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smserial.sys -- (smserial)
DRV - [2006/01/22 17:50:00 | 000,244,480 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2005/09/21 01:30:56 | 000,162,432 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2004/11/10 18:30:18 | 000,024,832 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k)
DRV - [2004/11/10 18:27:34 | 000,044,288 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp)
DRV - [2003/01/10 14:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.c...ys=PTB&M=MX6959
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.c...ys=PTB&M=MX6959
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: [email protected]:6.010.006.004
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/11/24 10:35:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVG\AVG9\Toolbar\Firefox\[email protected] [2010/10/26 00:54:41 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/07 10:24:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/18 17:32:18 | 000,000,000 | ---D | M]
[2011/05/07 10:24:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin-do not use\Application Data\Mozilla\Extensions
[2011/05/07 10:24:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin-do not use\Application Data\Mozilla\Firefox\Profiles\j64vit5d.default\extensions
[2011/05/07 10:24:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin-do not use\Application Data\Mozilla\Firefox\Profiles\j64vit5d.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/07 10:24:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin-do not use\Application Data\Mozilla\Firefox\Profiles\j64vit5d.default\extensions\staged-xpis
[2009/11/20 01:43:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/24 10:35:39 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG9\FIREFOX
[2010/10/26 00:54:41 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:id="[email protected]" em:name="AVG Security Toolbar" em:version="6.010.006.004" em:displayname="AVG Security Toolbar" em:iconURL="chrome://tavgp/skin/logo.ico" em:creator="AVG Technologies" em:description="AVG Security Toolbar" em:homepageURL="http://www.avg.com" >) -- C:\PROGRAM FILES\AVG\AVG9\TOOLBAR\FIREFOX\[email protected]
O1 HOSTS File: ([2004/08/10 12:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\WINDOWS\system32\bae.dll (Gateway Inc.)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [Power2GoExpress] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_02)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 68.238.64.12
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Gateway.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Gateway.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/06/17 02:41:16 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004/09/13 13:15:24 | 000,000,053 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/07 10:30:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\My Documents\Downloads
[2011/05/07 10:26:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Application Data\Macromedia
[2011/05/07 10:26:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Application Data\Adobe
[2011/05/07 10:25:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Local Settings\Application Data\AVG Security Toolbar
[2011/05/07 10:23:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Local Settings\Application Data\Mozilla
[2011/05/07 10:23:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Application Data\Mozilla
[2011/04/16 21:42:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Application Data\Apple Computer
[2011/04/16 21:42:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Local Settings\Application Data\Apple Computer
[2011/04/16 21:41:34 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Admin-do not use\Application Data\Microsoft
[2011/04/16 21:41:34 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Admin-do not use\SendTo
[2011/04/16 21:41:34 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Admin-do not use\Recent
[2011/04/16 21:41:34 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Admin-do not use\Application Data
[2011/04/16 21:41:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Admin-do not use\Start Menu\Programs\Startup
[2011/04/16 21:41:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Admin-do not use\Start Menu
[2011/04/16 21:41:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Admin-do not use\My Documents\My Pictures
[2011/04/16 21:41:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Admin-do not use\My Documents\My Music
[2011/04/16 21:41:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Admin-do not use\My Documents
[2011/04/16 21:41:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Admin-do not use\Favorites
[2011/04/16 21:41:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Admin-do not use\Start Menu\Programs\Accessories
[2011/04/16 21:41:34 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Admin-do not use\Cookies
[2011/04/16 21:41:34 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Admin-do not use\Templates
[2011/04/16 21:41:34 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Admin-do not use\PrintHood
[2011/04/16 21:41:34 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Admin-do not use\NetHood
[2011/04/16 21:41:34 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Admin-do not use\Local Settings
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Application Data\You've Got Pictures Screensaver
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\WINDOWS
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Local Settings\Application Data\Wildtangent
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Start Menu\Programs\System Recovery
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Application Data\SampleView
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Local Settings\Application Data\Microsoft
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Application Data\Intel
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Application Data\Identities
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Local Settings\Application Data\Google
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Desktop
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Local Settings\Application Data\ApplicationHistory
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Start Menu\Programs\America Online
[2011/04/16 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin-do not use\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150020}
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/07 10:28:16 | 000,001,010 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1600235818-4258184071-1634653983-1006UA.job
[2011/05/07 10:27:00 | 075,688,043 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/05/07 10:20:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/07 10:20:42 | 1063,440,384 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/05 15:20:01 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2011/05/01 11:28:02 | 000,000,958 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1600235818-4258184071-1634653983-1006Core.job
[2011/04/19 21:01:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/16 21:41:57 | 000,000,779 | ---- | M] () -- C:\Documents and Settings\Admin-do not use\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/16 21:41:52 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\Admin-do not use\Desktop\Windows Media Player.lnk
[2011/04/16 21:41:50 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\Admin-do not use\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2011/04/15 06:50:47 | 000,161,136 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/14 23:34:52 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/04/14 23:32:22 | 000,441,692 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/04/14 23:32:22 | 000,071,462 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/16 21:41:52 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Start Menu\Programs\Windows Media Player.lnk
[2011/04/16 21:41:52 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Desktop\Windows Media Player.lnk
[2011/04/16 21:41:38 | 000,000,669 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Application Data\Microsoft\Internet Explorer\Quick Launch\America Online 9.0.lnk
[2011/04/16 21:41:37 | 000,002,104 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Application Data\Microsoft\Internet Explorer\Quick Launch\Play Games.lnk
[2011/04/16 21:41:37 | 000,001,478 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2011/04/16 21:41:37 | 000,000,779 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/16 21:41:37 | 000,000,746 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Application Data\Microsoft\Internet Explorer\Quick Launch\Gateway Games.lnk
[2011/04/16 21:41:37 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2011/04/16 21:41:37 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/04/16 21:41:35 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Start Menu\Programs\Remote Assistance.lnk
[2011/04/16 21:41:35 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Start Menu\Programs\Internet Explorer.lnk
[2011/04/16 21:41:35 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\Admin-do not use\Start Menu\Programs\Outlook Express.lnk
[2009/05/02 20:28:36 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/02/13 17:49:02 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/11/21 12:14:41 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\jesterss.dll
[2006/11/21 12:06:37 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/11/21 12:04:54 | 000,000,004 | ---- | C] () -- C:\WINDOWS\Pix11.dat
[2006/11/21 12:01:57 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/06/21 02:48:15 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/06/21 02:12:42 | 000,352,256 | ---- | C] () -- C:\WINDOWS\System32\HotlineClient.exe
[2006/06/17 02:44:22 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/06/17 02:37:18 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/06/17 02:24:58 | 000,001,280 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/06/17 02:24:57 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\emver.ini
[2006/06/17 02:23:25 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/06/17 02:23:22 | 000,441,692 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/06/17 02:23:22 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/06/17 02:23:22 | 000,071,462 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/06/17 02:23:22 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/06/17 02:23:20 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/06/17 02:23:20 | 000,005,151 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/06/17 02:23:20 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/06/17 02:23:19 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/06/17 02:23:19 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/06/17 02:23:16 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/06/17 02:23:08 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/06/16 19:31:45 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/06/16 19:30:47 | 000,161,136 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/05 21:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2006/11/21 12:08:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin-do not use\Application Data\SampleView
[2010/06/12 12:23:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/06/12 12:20:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 16:01:31 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2009/02/13 17:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2006/11/21 12:07:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/02/13 17:58:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/11/18 17:39:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/02/13 18:41:08 | 000,000,258 | ---- | M] () -- C:\WINDOWS\Tasks\ISP signup reminder 2.job
[2009/02/13 18:41:08 | 000,000,258 | ---- | M] () -- C:\WINDOWS\Tasks\ISP signup reminder 3.job
========== Purity Check ==========
< End of report >