OTL.txt #2
O1 HOSTS File: (307262 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1
www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1
www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1
www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1
www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1
www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
www.10sek.com
O1 - Hosts: 127.0.0.1
www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123haustiereundmehr.com
O1 - Hosts: 10573 more lines...
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Windows\System32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe ()
O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKLM..\RunOnce: [Spybot - Search & Destroy] C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe (Safer Networking Limited)
O4 - HKLM..\RunOnce: [SpybotDeletingA9228] C:\Windows\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingC1030] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingB5085] C:\Windows\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingD1518] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.64.150 68.87.75.198
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/20 11:42:25 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/06/22 21:59:26 | 00,512,512 | ---- | C] (OldTimer Tools) -- C:\Users\[me]\Desktop\OTL.exe
[2009/06/22 19:43:24 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\Apple
[2009/06/22 19:43:16 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\Apple Computer
[2009/06/22 19:30:13 | 00,000,000 | ---D | C] -- C:\32788R22FWJFW
[2009/06/22 19:16:51 | 00,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmd.execf
[2009/06/22 19:10:07 | 03,038,734 | ---- | C] () -- C:\Users\[me]\Desktop\ComboFix.exe
[2009/06/22 18:58:48 | 00,056,680 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\rpcnet.dll_old
[2009/06/19 19:49:03 | 00,001,809 | ---- | C] () -- C:\Users\[me]\Desktop\Medieval II Total War Kingdoms.lnk
[2009/06/19 19:43:03 | 02,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2009/06/19 13:17:57 | 02,342,522 | -H-- | C] () -- C:\Users\[me]\AppData\Local\IconCache.db
[2009/06/19 11:45:14 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/18 23:18:02 | 00,000,000 | ---D | C] -- C:\VundoFix Backups
[2009/06/18 22:50:50 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/06/18 22:30:00 | 00,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2009/06/18 22:30:00 | 00,000,000 | RHS- | C] () -- C:\IO.SYS
[2009/06/18 14:09:43 | 00,000,582 | ---- | C] () -- C:\Windows\wininit.ini
[2009/06/13 10:32:26 | 00,000,000 | ---D | C] -- C:\Program Files\PowerISO
[2009/06/12 17:09:20 | 00,001,646 | ---- | C] () -- C:\Users\[me]\Desktop\Starcraft.lnk
[2009/06/12 16:52:45 | 00,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2009/06/12 16:52:43 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar
[2009/06/12 16:50:03 | 00,721,904 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009/06/12 16:49:38 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\DAEMON Tools Lite
[2009/06/12 16:44:48 | 00,094,208 | ---- | C] (Blizzard Entertainment) -- C:\Windows\ScUnin.exe
[2009/06/12 16:44:48 | 00,012,782 | ---- | C] () -- C:\Windows\scunin.dat
[2009/06/12 16:44:48 | 00,000,967 | ---- | C] () -- C:\Windows\ScUnin.pif
[2009/06/12 16:42:16 | 00,000,000 | ---D | C] -- C:\Program Files\Starcraft
[2009/06/12 16:35:12 | 00,000,000 | ---D | C] -- C:\Users\[me]\Desktop\RonGold
[2009/06/11 15:22:35 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\Foxit
[2009/06/11 15:22:17 | 00,000,000 | ---D | C] -- C:\Program Files\Foxit Software
[2009/06/11 00:58:02 | 00,011,142 | ---- | C] () -- C:\Users\[me]\Desktop\summer.docx
[2009/06/07 18:32:45 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\ElevatedDiagnostics
[2009/06/07 01:10:45 | 00,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2009/06/05 07:28:58 | 03,920,612 | ---- | C] () -- C:\Users\[me]\Desktop\P6050001.JPG
[2009/06/03 23:00:45 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\dvdcss
[2009/06/03 21:00:01 | 00,122,440 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2009/06/03 17:24:10 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\Cooliris
[2009/06/01 14:36:47 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/06/01 01:39:13 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2009/06/01 01:39:02 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2009/06/01 01:38:52 | 00,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2009/06/01 01:38:52 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2009/06/01 01:37:41 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\Microsoft Help
[2009/06/01 01:37:38 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2009/06/01 01:37:37 | 00,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2009/06/01 01:37:09 | 00,000,000 | RH-D | C] -- C:\MSOCache
[2009/06/01 00:38:45 | 00,000,000 | ---D | C] -- C:\Users\[me]\Desktop\MSOffice
[2009/05/31 23:58:06 | 00,000,000 | ---D | C] -- C:\Users\[me]\Desktop\Desktop
[2009/05/31 23:39:39 | 00,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
[2009/05/31 22:19:04 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\Adobe
[2009/05/31 22:16:48 | 00,000,000 | ---D | C] -- C:\Program Files\Project64 1.6
[2009/05/31 22:15:43 | 00,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2009/05/31 02:10:16 | 00,002,429 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2009/05/31 02:10:01 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/05/31 02:10:00 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/05/31 02:08:55 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2009/05/31 01:40:19 | 01,907,712 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2009/05/31 01:40:19 | 00,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2009/05/31 01:40:19 | 00,014,848 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2009/05/31 01:40:19 | 00,009,728 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2009/05/31 01:40:19 | 00,003,072 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2009/05/31 01:40:07 | 00,000,000 | ---D | C] -- C:\Program Files\EASEUS
[2009/05/31 01:30:48 | 00,000,000 | ---D | C] -- C:\Users\[me]\Desktop\More Music
[2009/05/31 01:30:38 | 00,000,000 | ---D | C] -- C:\Users\[me]\Desktop\Shamanism
[2009/05/31 01:28:00 | 00,001,791 | ---- | C] () -- C:\Users\[me]\Desktop\Medieval II Total War.lnk
[2009/05/31 01:24:34 | 00,001,064 | ---- | C] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2009/05/31 01:24:34 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine
[2009/05/31 01:24:16 | 00,000,000 | ---D | C] -- C:\Program Files\JGoodies
[2009/05/31 01:24:01 | 00,000,000 | ---D | C] -- C:\Windows\System32\IOSUBSYS
[2009/05/31 01:22:27 | 00,000,000 | ---D | C] -- C:\Program Files\WinDirStat
[2009/05/31 01:18:42 | 00,000,000 | ---D | C] -- C:\Users\[me]\Desktop\[me]'s Folder
[2009/05/31 01:16:52 | 00,001,934 | ---- | C] () -- C:\Users\[me]\Desktop\Rise of Nations Gold.lnk
[2009/05/31 01:15:22 | 00,001,827 | ---- | C] () -- C:\Users\[me]\Desktop\Team Fortress 2.lnk
[2009/05/31 01:12:03 | 00,000,000 | R--D | C] -- C:\Users\[me]\Desktop\Downloads
[2009/05/31 00:56:28 | 00,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2009/05/31 00:56:27 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\skypePM
[2009/05/31 00:55:12 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\Skype
[2009/05/31 00:53:19 | 00,002,503 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2009/05/31 00:53:15 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2009/05/31 00:53:13 | 00,000,000 | R--D | C] -- C:\Program Files\Skype
[2009/05/31 00:52:45 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\Macromedia
[2009/05/31 00:52:41 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\Google
[2009/05/31 00:52:29 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
[2009/05/31 00:52:28 | 00,002,513 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2009/05/31 00:52:27 | 00,000,000 | ---D | C] -- C:\Program Files\Steam
[2009/05/31 00:52:22 | 00,000,000 | ---D | C] -- C:\Program Files\Google
[2009/05/31 00:52:05 | 00,000,000 | ---D | C] -- C:\ProgramData\Skype
[2009/05/31 00:48:15 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\vlc
[2009/05/31 00:47:19 | 00,000,000 | ---D | C] -- C:\Users\[me]\Documents\Chats
[2009/05/31 00:46:19 | 00,000,000 | ---D | C] -- C:\Users\[me]\Documents\Non-School Work
[2009/05/31 00:46:12 | 00,000,000 | ---D | C] -- C:\Users\[me]\Documents\Wallpapers
[2009/05/31 00:44:50 | 00,000,000 | ---D | C] -- C:\Users\[me]\Documents\Schoolwork
[2009/05/31 00:41:58 | 00,000,000 | ---D | C] -- C:\Program Files\Cisco
[2009/05/31 00:41:30 | 00,744,740 | ---- | C] () -- C:\Windows\System32\oem11.inf
[2009/05/31 00:40:52 | 02,682,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vcredist_x86.exe
[2009/05/31 00:40:52 | 00,001,591 | ---- | C] () -- C:\Windows\System32\Uninst_EAPModules.bat
[2009/05/31 00:40:52 | 00,000,416 | ---- | C] () -- C:\Windows\System32\vcredist_x86.bat
[2009/05/31 00:40:51 | 00,054,784 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2009/05/31 00:40:50 | 00,024,064 | ---- | C] () -- C:\Windows\System32\WLTRYSVC.EXE
[2009/05/31 00:40:49 | 01,044,472 | ---- | C] (Broadcom Corp.) -- C:\Windows\System32\drivers\BCMWL6.SYS
[2009/05/31 00:40:00 | 00,021,469 | ---- | C] () -- C:\newkey
[2009/05/31 00:40:00 | 00,021,469 | ---- | C] () -- C:\newfile.enc
[2009/05/31 00:39:42 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\InstallShield
[2009/05/31 00:37:30 | 00,000,000 | ---D | C] -- C:\Program Files\Broadcom
[2009/05/31 00:34:44 | 00,043,520 | ---- | C] (REDC) -- C:\Windows\System32\drivers\rimsptsk.sys
[2009/05/31 00:34:44 | 00,037,376 | ---- | C] (REDC) -- C:\Windows\System32\drivers\rixdptsk.sys
[2009/05/31 00:34:44 | 00,032,256 | ---- | C] (REDC) -- C:\Windows\System32\drivers\rimmptsk.sys
[2009/05/31 00:34:44 | 00,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2009/05/31 00:28:57 | 00,000,000 | ---D | C] -- C:\Windows\System32\vmm32
[2009/05/31 00:28:57 | 00,000,000 | ---D | C] -- C:\Program Files\Dell
[2009/05/31 00:25:43 | 00,000,000 | ---D | C] -- C:\Windows\Minidump
[2009/05/31 00:24:47 | 00,010,872 | ---- | C] () -- C:\Windows\System32\drivers\AvgAsCln.sys
[2009/05/31 00:24:46 | 00,000,000 | ---D | C] -- C:\ProgramData\Grisoft
[2009/05/31 00:24:46 | 00,000,000 | ---D | C] -- C:\Program Files\Grisoft
[2009/05/31 00:22:50 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\Malwarebytes
[2009/05/31 00:22:46 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/05/31 00:22:45 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/05/31 00:22:45 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/05/31 00:22:44 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/31 00:21:46 | 00,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2009/05/31 00:21:46 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/05/31 00:17:08 | 00,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2009/05/31 00:15:38 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\Apple Computer
[2009/05/31 00:15:17 | 00,000,000 | ---D | C] -- C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/05/31 00:14:54 | 00,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2009/05/31 00:14:35 | 00,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2009/05/31 00:14:27 | 00,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2009/05/31 00:13:58 | 00,000,000 | ---D | C] -- C:\ProgramData\Apple
[2009/05/31 00:13:58 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2009/05/31 00:09:43 | 00,000,913 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MozyHome Status.lnk
[2009/05/31 00:09:32 | 00,053,240 | ---- | C] (Mozy, Inc.) -- C:\Windows\System32\drivers\mozy.sys
[2009/05/31 00:09:31 | 00,056,680 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\rpcnet.exe
[2009/05/31 00:09:31 | 00,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2009/05/31 00:09:31 | 00,000,000 | ---D | C] -- C:\Program Files\MozyHome
[2009/05/31 00:08:53 | 00,013,160 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\Upgrd.exe
[2009/05/31 00:08:49 | 00,000,000 | -HSD | C] -- C:\Windows\Installer
[2009/05/30 23:52:58 | 00,000,000 | ---D | C] -- C:\Windows\Panther
[2009/05/30 23:52:08 | 00,078,863 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/05/30 23:52:08 | 00,078,863 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/05/30 23:46:10 | 00,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2009/05/30 22:56:20 | 00,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2009/05/30 22:55:15 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2009/05/30 22:54:13 | 00,017,408 | ---- | C] () -- C:\Windows\System32\rpcnetp.dll
[2009/05/30 22:54:13 | 00,000,000 | ---D | C] -- C:\Windows\Prefetch
[2009/05/30 22:53:30 | 28,170,32192 | -HS- | C] () -- C:\hiberfil.sys
[2009/05/30 22:53:30 | 00,000,000 | -HSD | C] -- C:\System Volume Information
[2009/05/30 22:53:29 | 00,017,408 | ---- | C] () -- C:\Windows\System32\rpcnetp.exe
[2009/05/30 20:43:02 | 00,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2009/05/30 20:43:01 | 00,168,208 | ---- | C] () -- C:\Windows\System32\guard32.dll
[2009/05/30 20:43:01 | 00,130,080 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmdguard.sys
[2009/05/30 20:43:01 | 00,068,640 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\inspect.sys
[2009/05/30 20:43:01 | 00,028,704 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmdhlp.sys
[2009/05/30 20:43:01 | 00,000,000 | ---D | C] -- C:\Program Files\COMODO
[2009/05/30 20:42:36 | 00,000,913 | ---- | C] () -- C:\Users\[me]\Desktop\Audacity.lnk
[2009/05/30 20:42:35 | 00,000,000 | ---D | C] -- C:\Program Files\Audacity
[2009/05/30 20:41:49 | 00,001,024 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2009/05/30 20:41:43 | 00,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2009/05/30 20:34:44 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\Diagnostics
[2009/05/30 20:28:11 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
[2009/05/30 20:27:59 | 00,000,000 | ---D | C] -- C:\Program Files\Apoint2K
[2009/05/30 20:27:44 | 01,419,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WdfCoInstaller01005.dll
[2009/05/30 20:26:13 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\WinRAR
[2009/05/30 20:25:48 | 00,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2009/05/30 20:24:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2009/05/30 20:24:10 | 00,795,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpinst.exe
[2009/05/30 20:24:10 | 00,169,773 | ---- | C] () -- C:\Windows\System32\nvapps.xml
[2009/05/30 20:24:10 | 00,025,494 | ---- | C] () -- C:\Windows\System32\nvwsapps.xml
[2009/05/30 20:24:10 | 00,007,542 | ---- | C] () -- C:\Windows\System32\nvdisp.nvu
[2009/05/30 20:24:09 | 00,000,000 | ---D | C] -- C:\Dell
[2009/05/30 20:18:13 | 00,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\System32\CSVer.dll
[2009/05/30 20:18:13 | 00,000,000 | ---D | C] -- C:\Program Files\Intel
[2009/05/30 20:18:05 | 00,000,000 | ---D | C] -- C:\Intel
[2009/05/30 20:16:52 | 00,000,000 | ---D | C] -- C:\Users\[me]\Desktop\Utilities
[2009/05/30 20:14:48 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2009/05/30 20:14:48 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2009/05/30 20:14:46 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2009/05/30 20:14:46 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\Windows\System32\AvastSS.scr
[2009/05/30 20:14:46 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2009/05/30 20:14:32 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2009/05/30 20:14:32 | 01,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFC71.dll
[2009/05/30 20:14:32 | 00,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSVCP71.dll
[2009/05/30 20:14:32 | 00,380,928 | ---- | C] () -- C:\Windows\System32\actskin4.ocx
[2009/05/30 20:14:32 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSVCR71.dll
[2009/05/30 20:14:32 | 00,051,792 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2009/05/30 20:14:31 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/05/30 20:13:37 | 00,002,022 | ---- | C] () -- C:\Users\[me]\Desktop\Trillian.lnk
[2009/05/30 20:13:24 | 00,000,000 | ---D | C] -- C:\Program Files\Trillian
[2009/05/30 20:13:20 | 00,063,944 | ---- | C] () -- C:\Users\[me]\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/05/30 20:13:20 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\RadarSync
[2009/05/30 20:13:19 | 00,000,000 | ---D | C] -- C:\Program Files\RadarSync
[2009/05/30 20:10:50 | 00,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/05/30 20:10:49 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\Mozilla
[2009/05/30 20:10:49 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\Mozilla
[2009/05/30 20:10:48 | 00,001,885 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/05/30 20:10:46 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2009/05/30 20:01:20 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\Identities
[2009/05/30 20:01:10 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\VirtualStore
[2009/05/30 20:01:09 | 00,000,000 | --SD | C] -- C:\Users\[me]\AppData\Roaming\Microsoft
[2009/05/30 20:01:09 | 00,000,000 | -HSD | C] -- C:\Users\[me]\Documents\My Videos
[2009/05/30 20:01:09 | 00,000,000 | -HSD | C] -- C:\Users\[me]\Documents\My Pictures
[2009/05/30 20:01:09 | 00,000,000 | -HSD | C] -- C:\Users\[me]\Documents\My Music
[2009/05/30 20:01:09 | 00,000,000 | -HSD | C] -- C:\Users\[me]\AppData\Local\Temporary Internet Files
[2009/05/30 20:01:09 | 00,000,000 | -HSD | C] -- C:\Users\[me]\AppData\Local\History
[2009/05/30 20:01:09 | 00,000,000 | -HSD | C] -- C:\Users\[me]\AppData\Local\Application Data
[2009/05/30 20:01:09 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Roaming\Media Center Programs
[2009/05/30 20:01:09 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\Temp
[2009/05/30 20:01:09 | 00,000,000 | ---D | C] -- C:\Users\[me]\AppData\Local\Microsoft
[2009/05/30 20:00:53 | 00,000,000 | -HSD | C] -- C:\Recovery
[2009/04/22 01:58:02 | 00,000,403 | ---- | C] () -- C:\Windows\win.ini
[2009/04/22 01:58:02 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2009/04/21 23:50:07 | 00,073,216 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/04/21 23:40:32 | 00,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2008/10/10 10:57:26 | 00,003,584 | ---- | C] () -- C:\Windows\System32\wceprv.dll
========== Files - Modified Within 30 Days ==========
[2009/06/22 21:59:27 | 00,512,512 | ---- | M] (OldTimer Tools) -- C:\Users\[me]\Desktop\OTL.exe
[2009/06/22 21:01:11 | 00,000,582 | ---- | M] () -- C:\Windows\wininit.ini
[2009/06/22 20:19:55 | 00,307,262 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2009/06/22 19:47:08 | 00,802,140 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/06/22 19:47:08 | 00,167,062 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/06/22 19:47:08 | 00,004,522 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/06/22 19:34:09 | 00,002,022 | ---- | M] () -- C:\Users\[me]\Desktop\Trillian.lnk
[2009/06/22 19:30:23 | 00,301,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cmd.execf
[2009/06/22 19:10:12 | 03,038,734 | ---- | M] () -- C:\Users\[me]\Desktop\ComboFix.exe
[2009/06/22 19:05:58 | 00,013,408 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2009/06/22 19:05:58 | 00,013,408 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2009/06/22 18:59:46 | 00,078,863 | ---- | M] () -- C:\ProgramData\nvModes.001
[2009/06/22 18:58:50 | 00,017,408 | ---- | M] () -- C:\Windows\System32\rpcnetp.exe
[2009/06/22 18:58:48 | 00,056,680 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\rpcnet.dll_old
[2009/06/22 18:58:46 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/06/22 18:58:40 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/06/22 18:58:35 | 28,170,32192 | -HS- | M] () -- C:\hiberfil.sys
[2009/06/22 18:57:43 | 00,001,954 | ---- | M] () -- C:\Windows\mozy.blk
[2009/06/22 18:57:43 | 00,000,074 | ---- | M] () -- C:\Windows\mozy.flt
[2009/06/22 18:57:35 | 02,342,522 | -H-- | M] () -- C:\Users\[me]\AppData\Local\IconCache.db
[2009/06/22 16:56:40 | 00,078,863 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2009/06/21 13:39:41 | 00,011,142 | ---- | M] () -- C:\Users\[me]\Desktop\summer.docx
[2009/06/19 19:49:03 | 00,001,809 | ---- | M] () -- C:\Users\[me]\Desktop\Medieval II Total War Kingdoms.lnk
[2009/06/19 03:08:05 | 00,017,408 | ---- | M] () -- C:\Windows\System32\rpcnetp.dll
[2009/06/18 23:18:49 | 00,307,262 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20090622-201955.backup
[2009/06/18 23:18:00 | 00,307,262 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20090618-231848.backup
[2009/06/18 22:30:00 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009/06/18 22:30:00 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/06/18 12:51:41 | 00,307,262 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20090618-231800.backup
[2009/06/17 11:27:56 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/06/12 17:09:20 | 00,001,646 | ---- | M] () -- C:\Users\[me]\Desktop\Starcraft.lnk
[2009/06/12 16:50:03 | 00,721,904 | ---- | M] () -- C:\Windows\System32\drivers\sptd.sys
[2009/06/12 16:44:48 | 00,094,208 | ---- | M] (Blizzard Entertainment) -- C:\Windows\ScUnin.exe
[2009/06/12 16:44:48 | 00,012,782 | ---- | M] () -- C:\Windows\scunin.dat
[2009/06/12 16:44:48 | 00,000,967 | ---- | M] () -- C:\Windows\ScUnin.pif
[2009/06/11 02:22:30 | 00,307,247 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20090618-125141.backup
[2009/06/05 07:28:58 | 03,920,612 | ---- | M] () -- C:\Users\[me]\Desktop\P6050001.JPG
[2009/06/03 21:00:01 | 00,122,440 | -H-- | M] () -- C:\Windows\System32\mlfcache.dat
[2009/06/03 18:08:40 | 00,307,233 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20090611-022230.backup
[2009/06/01 15:27:59 | 00,306,823 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20090603-180840.backup
[2009/06/01 15:26:54 | 00,306,823 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20090601-152759.backup
[2009/06/01 15:23:08 | 00,063,944 | ---- | M] () -- C:\Users\[me]\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/06/01 14:13:34 | 00,296,376 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/05/31 02:10:16 | 00,002,429 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2009/05/31 01:28:00 | 00,001,791 | ---- | M] () -- C:\Users\[me]\Desktop\Medieval II Total War.lnk
[2009/05/31 01:24:34 | 00,001,064 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2009/05/31 01:15:22 | 00,001,827 | ---- | M] () -- C:\Users\[me]\Desktop\Team Fortress 2.lnk
[2009/05/31 00:56:28 | 00,000,056 | -H-- | M] () -- C:\Windows\System32\ezsidmv.dat
[2009/05/31 00:53:19 | 00,002,503 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2009/05/31 00:52:28 | 00,002,513 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2009/05/31 00:41:14 | 00,744,740 | ---- | M] () -- C:\Windows\System32\oem11.inf
[2009/05/31 00:40:00 | 00,021,469 | ---- | M] () -- C:\newkey
[2009/05/31 00:40:00 | 00,021,469 | ---- | M] () -- C:\newfile.enc
[2009/05/31 00:09:43 | 00,000,913 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MozyHome Status.lnk
[2009/05/31 00:09:08 | 00,013,160 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\Upgrd.exe
[2009/05/31 00:08:51 | 00,056,680 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\rpcnet.exe
[2009/05/30 22:55:15 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2009/05/30 20:43:01 | 00,168,208 | ---- | M] () -- C:\Windows\System32\guard32.dll
[2009/05/30 20:43:01 | 00,130,080 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmdguard.sys
[2009/05/30 20:43:01 | 00,068,640 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\inspect.sys
[2009/05/30 20:43:01 | 00,028,704 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmdhlp.sys
[2009/05/30 20:42:36 | 00,000,913 | ---- | M] () -- C:\Users\[me]\Desktop\Audacity.lnk
[2009/05/30 20:41:49 | 00,001,024 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2009/05/30 20:28:11 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
[2009/05/30 20:14:45 | 00,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2009/05/30 20:10:50 | 00,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2009/05/30 20:10:48 | 00,001,885 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/05/30 19:57:37 | 00,028,965 | ---- | M] () -- C:\Windows\System32\license.rtf
========== LOP Check ==========
[2009/06/12 16:49:38 | 00,000,000 | ---D | M] -- C:\Users\[me]\AppData\Roaming
[2009/06/12 16:53:27 | 00,000,000 | ---D | M] -- C:\Users\[me]\AppData\Roaming\DAEMON Tools Lite
[2009/06/21 22:28:43 | 00,000,000 | ---D | M] -- C:\Users\[me]\AppData\Roaming\dvdcss
[2009/06/11 15:22:35 | 00,000,000 | ---D | M] -- C:\Users\[me]\AppData\Roaming\Foxit
[2009/04/22 06:24:12 | 00,000,000 | ---D | M] -- C:\Users\[me]\AppData\Roaming\Media Center Programs
[2009/06/22 18:58:46 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/04/22 04:27:21 | 00,013,324 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >