O1 HOSTS File: ([2012/01/29 23:52:05 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\Program Files\OpenSubtitlesPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.)
O3 - HKU\S-1-5-21-861567501-926492609-839522115-1003\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-861567501-926492609-839522115-1003..\Run: [ALLUpdate] C:\Program Files\OpenSubtitlesPlayer\ALLUpdate.exe ()
O4 - HKU\S-1-5-21-861567501-926492609-839522115-1003..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\REALTEK 11n USB Wireless LAN Utility.lnk = C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe (Dell Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-861567501-926492609-839522115-1003\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-861567501-926492609-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-861567501-926492609-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-861567501-926492609-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Alexa Web Search... -
http://tbar.alexa.com/9.0.0.31/contextmenu/search.htm File not found
O8 - Extra context menu item: Get Alexa Data... -
http://tbar.alexa.com/9.0.0.31/contextmenu/sitedata.htm File not found
O8 - Extra context menu item: See Related Links... -
http://tbar.alexa.com/9.0.0.31/contextmenu/related.htm File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - Reg Error: Value error. File not found
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1256427816825 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F}
http://systemrequirementslab.com.s3.amazonaws.com/iduu/bin/srldetect_intel.cab (SysInfo Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{52CA22F8-D201-4D57-A2D5-CF6BC6041D8F}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\PRISMAPI.DLL: DllName - (PRISMAPI.DLL) - C:\WINDOWS\System32\PRISMAPI.dll (Conexant Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Mendy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mendy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/11/22 23:54:43 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2009/10/13 19:49:12 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-861567501-926492609-839522115-1003..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\system32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/29 23:46:17 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/01/29 23:21:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012/01/29 23:18:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2012/01/29 23:08:13 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/01/29 23:04:40 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/01/29 23:04:40 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/01/29 23:04:40 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/01/29 23:04:40 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/01/29 23:04:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/01/29 23:04:28 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/29 17:20:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Mendy\Start Menu\Programs\Administrative Tools
[2012/01/29 17:20:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2012/01/25 23:38:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mendy\Local Settings\Application Data\Babylon
[2012/01/25 23:38:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mendy\Application Data\Babylon
[2012/01/25 23:38:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2012/01/25 23:38:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ALLConverter PRO
[2012/01/25 23:38:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mendy\Local Settings\Application Data\ALLConverter
[2012/01/25 23:38:17 | 000,000,000 | ---D | C] -- C:\Program Files\ALLConverter PRO
[2012/01/25 23:38:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\OpenSubtitlesPlayer
[2012/01/25 23:38:07 | 000,865,904 | ---- | C] (Babylon Ltd.) -- C:\Program Files\toolbar2.exe
[2012/01/25 23:37:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mendy\Local Settings\Application Data\ALLPlayer
[2012/01/25 23:37:46 | 000,000,000 | ---D | C] -- C:\Program Files\OpenSubtitlesPlayer
[2012/01/25 18:49:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mendy\Start Menu\Programs\HiJackThis
[2012/01/25 18:49:46 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2012/01/24 15:02:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mendy\Application Data\Kernel for Windows Data Recovery
[2012/01/24 14:48:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Kernel for Windows Data Recovery
[2012/01/24 14:48:01 | 000,000,000 | ---D | C] -- C:\Program Files\Kernel for Windows Data Recovery
[2012/01/24 14:02:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mendy\Application Data\001-software
[2012/01/24 14:02:51 | 000,000,000 | ---D | C] -- C:\Program Files\001-Software
[2012/01/23 18:32:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\REALTEK 11n USB Wireless LAN Utility
[2012/01/23 18:13:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\OPTIONS
[2012/01/23 18:13:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\RtlGina
[2012/01/23 18:13:25 | 000,000,000 | ---D | C] -- C:\Program Files\REALTEK
[2012/01/23 17:16:56 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2011/09/26 17:48:24 | 000,730,192 | ---- | C] (How Inc.) -- C:\Program Files\Common Files\ZugoInstaller.exe
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Mendy\Desktop\*.tmp files -> C:\Documents and Settings\Mendy\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/29 23:58:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/29 23:52:05 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/01/29 23:45:56 | 000,000,660 | ---- | M] () -- C:\Documents and Settings\Mendy\Desktop\Shortcut to ComboFix.lnk
[2012/01/29 23:45:04 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/01/29 23:17:11 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-861567501-926492609-839522115-1003.job
[2012/01/29 23:17:05 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-861567501-926492609-839522115-1003.job
[2012/01/29 23:15:28 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/29 23:15:27 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-861567501-926492609-839522115-1006.job
[2012/01/29 23:15:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/29 23:08:17 | 000,000,325 | RHS- | M] () -- C:\boot.ini
[2012/01/29 22:25:22 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Mendy\Desktop\Microsoft Office Word 2007.lnk
[2012/01/29 22:14:58 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Mendy\Desktop\MBR.dat
[2012/01/29 15:32:02 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Mendy\My Documents\fun00kmw.exe
[2012/01/28 22:47:13 | 000,000,024 | ---- | M] () -- C:\Documents and Settings\Mendy\jagexappletviewer.preferences
[2012/01/28 18:31:45 | 000,000,040 | ---- | M] () -- C:\Documents and Settings\Mendy\jagex_cl_runescape_LIVE.dat
[2012/01/28 18:26:38 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/25 23:38:20 | 000,000,791 | ---- | M] () -- C:\Documents and Settings\Mendy\Application Data\Microsoft\Internet Explorer\Quick Launch\ALLConverter PRO.lnk
[2012/01/25 23:38:20 | 000,000,773 | ---- | M] () -- C:\Documents and Settings\Mendy\My Documents\ALLConverter PRO.lnk
[2012/01/25 23:38:10 | 000,001,662 | ---- | M] () -- C:\Documents and Settings\Mendy\Desktop\OpenSubtitlesPlayer V4.7.lnk
[2012/01/25 21:30:33 | 000,001,852 | ---- | M] () -- C:\Documents and Settings\Mendy\Desktop\Veoh Web Player.lnk
[2012/01/25 19:13:29 | 000,000,836 | ---- | M] () -- C:\Documents and Settings\Mendy\My Documents\Shortcut to Crusty.exe.lnk
[2012/01/23 18:32:41 | 000,001,910 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\REALTEK 11n USB Wireless LAN Utility.lnk
[2012/01/23 16:59:49 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012/01/23 16:59:49 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012/01/23 14:36:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/15 07:44:00 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-861567501-926492609-839522115-1006.job
[2012/01/08 07:40:11 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/05 23:25:35 | 564,856,416 | ---- | M] () -- C:\Documents and Settings\Mendy\My Documents\Movie Production.veg.1.sfap0
[2012/01/05 22:44:13 | 564,856,416 | ---- | M] () -- C:\Documents and Settings\Mendy\My Documents\Movie Production.veg.sfap0
[2012/01/05 21:47:53 | 000,741,112 | ---- | M] () -- C:\Documents and Settings\Mendy\My Documents\Movie Production.veg
[2012/01/05 21:46:57 | 000,742,376 | ---- | M] () -- C:\Documents and Settings\Mendy\My Documents\Movie Production.veg.bak
[2012/01/05 21:33:05 | 564,856,416 | ---- | M] () -- C:\Documents and Settings\Mendy\My Documents\Movie Production.veg.2.sfap0
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Mendy\Desktop\*.tmp files -> C:\Documents and Settings\Mendy\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/29 23:45:56 | 000,000,660 | ---- | C] () -- C:\Documents and Settings\Mendy\Desktop\Shortcut to ComboFix.lnk
[2012/01/29 23:45:04 | 000,000,424 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/01/29 23:08:17 | 000,000,209 | ---- | C] () -- C:\Boot.bak
[2012/01/29 23:08:13 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/01/29 23:04:40 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/01/29 23:04:40 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/01/29 23:04:40 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/01/29 23:04:40 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/01/29 23:04:40 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/01/29 22:14:58 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Mendy\Desktop\MBR.dat
[2012/01/29 15:31:48 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Mendy\My Documents\fun00kmw.exe
[2012/01/25 23:38:20 | 000,000,791 | ---- | C] () -- C:\Documents and Settings\Mendy\Application Data\Microsoft\Internet Explorer\Quick Launch\ALLConverter PRO.lnk
[2012/01/25 23:38:20 | 000,000,773 | ---- | C] () -- C:\Documents and Settings\Mendy\My Documents\ALLConverter PRO.lnk
[2012/01/25 23:38:10 | 000,001,662 | ---- | C] () -- C:\Documents and Settings\Mendy\Desktop\OpenSubtitlesPlayer V4.7.lnk
[2012/01/25 23:37:54 | 000,797,184 | ---- | C] () -- C:\WINDOWS\System32\ac3filter.ax
[2012/01/25 23:37:54 | 000,644,608 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2012/01/25 23:37:54 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\libFLAC.dll
[2012/01/25 21:30:33 | 000,001,852 | ---- | C] () -- C:\Documents and Settings\Mendy\Desktop\Veoh Web Player.lnk
[2012/01/25 19:13:29 | 000,000,836 | ---- | C] () -- C:\Documents and Settings\Mendy\My Documents\Shortcut to Crusty.exe.lnk
[2012/01/23 18:14:11 | 000,001,910 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\REALTEK 11n USB Wireless LAN Utility.lnk
[2012/01/23 18:13:24 | 000,451,072 | ---- | C] () -- C:\WINDOWS\System32\ISSRemoveSP.exe
[2012/01/05 21:27:03 | 564,856,416 | ---- | C] () -- C:\Documents and Settings\Mendy\My Documents\Movie Production.veg.2.sfap0
[2012/01/05 21:22:21 | 564,856,416 | ---- | C] () -- C:\Documents and Settings\Mendy\My Documents\Movie Production.veg.sfap0
[2011/12/10 23:14:33 | 000,000,144 | ---- | C] () -- C:\WINDOWS\Eudcedit.ini
[2011/07/13 17:39:01 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Mendy\Application Data\Adobe GIF Format CS5 Prefs
[2011/06/21 19:13:15 | 000,020,552 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2011/06/12 19:58:28 | 000,013,708 | -HS- | C] () -- C:\Documents and Settings\Mendy\Local Settings\Application Data\8eer11n1je2c4362t6la57g75uh86c2717e3lh51063v8b
[2011/06/12 19:58:28 | 000,013,708 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\8eer11n1je2c4362t6la57g75uh86c2717e3lh51063v8b
[2011/05/30 14:59:12 | 000,013,906 | -HS- | C] () -- C:\Documents and Settings\Mendy\Local Settings\Application Data\621g73w1t32s28rbr6d2q484sxtka4h075t2
[2011/05/30 14:59:12 | 000,013,906 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\621g73w1t32s28rbr6d2q484sxtka4h075t2
[2011/05/12 19:57:29 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\sqdkq.sys
[2011/05/12 19:29:39 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mendy\Local Settings\Application Data\{FB21B8A1-4C03-4858-AA82-514876BB2E8A}
[2011/05/11 20:58:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\afunozabulam.dll
[2011/05/11 19:39:54 | 000,014,252 | -HS- | C] () -- C:\Documents and Settings\Mendy\Local Settings\Application Data\t5h3710btkyvc7ysrur63f5pk32e0x8r082s66
[2011/05/11 19:39:54 | 000,014,252 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\t5h3710btkyvc7ysrur63f5pk32e0x8r082s66
[2011/05/11 19:30:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ocoxipugofore.dll
[2011/03/27 14:52:34 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Cmopetunuxafuj.dat
[2011/03/27 14:52:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Uboziv.bin
[2011/02/03 18:20:20 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2011/02/03 18:19:58 | 000,000,946 | ---- | C] () -- C:\WINDOWS\ATICIM.INI
[2011/02/03 18:19:35 | 000,114,630 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2010/12/29 03:18:19 | 000,831,640 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/28 09:46:47 | 000,000,118 | ---- | C] () -- C:\WINDOWS\Podcasts.INI
[2010/11/28 09:30:38 | 000,000,032 | ---- | C] () -- C:\WINDOWS\Menu.INI
[2010/07/18 19:29:19 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\WinVd32.sys
[2010/07/18 19:29:19 | 000,006,024 | -HS- | C] () -- C:\WINDOWS\System32\sys_drv.dat
[2010/07/18 19:29:19 | 000,005,020 | -HS- | C] () -- C:\WINDOWS\System32\sys_drv_2.dat
[2010/07/18 19:29:18 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\WinFLsrv.exe
[2010/07/18 19:29:18 | 000,000,990 | -HS- | C] () -- C:\Documents and Settings\Mendy\Application Data\systemfl.$dk
[2010/04/07 09:20:28 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/01/02 19:49:49 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
[2009/11/25 13:40:50 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/11/07 19:09:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/10/25 17:32:48 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2009/10/18 18:45:03 | 000,034,816 | ---- | C] () -- C:\Documents and Settings\Mendy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/14 20:25:22 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\StopSrvr.exe
[2009/10/14 18:34:08 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Mendy\Local Settings\Application Data\fusioncache.dat
[2009/10/13 21:15:20 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/10/13 19:52:09 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/10/13 19:45:54 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/10/13 12:39:39 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/10/13 12:38:41 | 003,574,672 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/10/25 05:24:22 | 000,020,594 | ---- | C] () -- C:\WINDOWS\System32\DELS3L3.DLL
[2005/08/05 13:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/03/22 14:38:24 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005/03/22 14:38:24 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/10 03:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 03:00:00 | 000,506,074 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 03:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 03:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 03:00:00 | 000,089,346 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 03:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 03:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 03:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 03:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/10 03:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/01/16 15:25:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Affinegy
[2010/11/23 00:12:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2011/05/30 17:30:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/05/30 17:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2012/01/25 23:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2011/01/15 20:23:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Belkin
[2011/01/11 23:53:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2011/05/13 16:45:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/02/01 22:29:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Boost
[2011/01/06 00:00:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Medic
[2011/03/10 14:30:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2011/07/06 14:15:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Giraffic
[2011/06/21 19:16:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2011/07/23 23:19:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2011/05/30 17:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/12/26 18:28:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MySQL
[2011/09/21 17:46:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/06/12 22:25:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\oO28258LlOmP28258
[2011/05/16 17:49:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/10/25 16:38:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/12/31 15:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC-Doctor
[2009/12/31 15:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCDr
[2011/05/12 19:30:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pP06509GmKnN06509
[2009/10/14 20:25:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Prism
[2010/11/28 09:40:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RapidSolution
[2011/07/07 00:56:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/12/29 13:21:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Screentime
[2011/07/10 16:36:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2011/05/12 19:53:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2012/01/23 17:24:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2011/08/11 20:25:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUpMedia
[2010/08/26 08:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/01/24 22:04:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\001-software
[2009/12/14 15:05:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Audacity
[2010/11/23 00:12:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Autodesk
[2011/05/15 12:57:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\AVG10
[2012/01/25 23:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Babylon
[2010/01/06 19:31:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Blender Foundation
[2009/10/25 16:50:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Blitware
[2010/11/22 20:35:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/07 00:21:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/05/16 07:06:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\DriverCure
[2011/01/08 19:05:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\DriverFinder
[2011/07/23 22:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Easeware
[2011/06/19 18:03:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Facebook
[2010/11/28 19:08:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\FILEminimizerPictures
[2011/07/23 23:13:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\IObit
[2012/01/24 15:02:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Kernel for Windows Data Recovery
[2009/11/16 21:45:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\MSNInstaller
[2011/09/14 17:45:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\NCH Swift Sound
[2011/07/18 16:21:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\OpenCandy
[2011/05/16 07:06:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\ParetoLogic
[2011/05/20 15:58:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Publish Providers
[2009/11/10 20:20:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Reg Tool
[2010/07/05 00:10:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Registry Mechanic
[2011/03/10 18:29:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\simppulltoolbar
[2011/07/18 15:56:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Sony
[2011/02/21 09:53:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Sony Creative Software Inc
[2009/11/16 21:51:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\SystemRequirementsLab
[2011/08/11 20:27:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\TuneUpMedia
[2011/02/12 19:08:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\Uniblue
[2012/01/26 03:09:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\uTorrent
[2011/03/10 14:30:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mendy\Application Data\WeatherBug
[2011/05/13 17:17:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Parents\Application Data\AVG
[2011/05/13 16:47:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Parents\Application Data\AVG10
[2012/01/29 23:45:04 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/09/26 17:45:00 | 000,000,278 | ---- | M] () -- C:\WINDOWS\Tasks\switchShakeIcon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/01/18 17:57:31 | 000,021,494 | ---- | M] () -- C:\0x0409.ini
[2011/01/18 17:57:31 | 000,003,584 | ---- | M] () -- C:\1033.MST
[2009/10/13 19:49:12 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2011/01/18 17:57:32 | 003,812,864 | ---- | M] () -- C:\Belkin Connect Wireless USB Adapter.msi
[2011/06/13 00:15:04 | 000,000,209 | ---- | M] () -- C:\Boot.bak
[2012/01/29 23:08:17 | 000,000,325 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2012/01/29 23:56:34 | 000,020,007 | ---- | M] () -- C:\ComboFix.txt
[2009/10/13 19:49:12 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/10/13 19:49:12 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/06/06 14:08:29 | 000,000,455 | -H-- | M] () -- C:\IPH.PH
[2009/10/13 19:49:12 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/10 03:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/10/24 15:51:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2012/01/29 23:15:12 | 3219,128,320 | -HS- | M] () -- C:\pagefile.sys
[2012/01/23 18:32:41 | 000,000,212 | ---- | M] () -- C:\setup.log
[2010/12/12 18:50:50 | 000,000,755 | ---- | M] () -- C:\Sys_LogWin.log
[2011/06/12 23:35:38 | 000,038,746 | ---- | M] () -- C:\TDSSKiller.2.5.1.0_12.06.2011_23.34.40_log.txt
[2011/06/16 11:46:47 | 000,000,412 | ---- | M] () -- C:\TDSSKiller.2.5.1.0_16.06.2011_11.46.40_log.txt
[2011/06/16 17:46:11 | 000,000,412 | ---- | M] () -- C:\TDSSKiller.2.5.1.0_16.06.2011_17.46.02_log.txt
[2011/06/16 12:17:17 | 000,038,210 | ---- | M] () -- C:\TDSSKiller.2.5.5.0_16.06.2011_11.47.17_log.txt
[2011/06/16 17:49:06 | 000,073,758 | ---- | M] () -- C:\TDSSKiller.2.5.5.0_16.06.2011_17.46.35_log.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/10/13 19:48:51 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/09/18 00:57:22 | 000,019,456 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\DELS3pc.dll
[2008/07/06 04:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 18:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 02:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/07/30 13:52:51 | 000,001,666 | -H-- | M] () -- C:\Documents and Settings\Mendy\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2011/11/24 02:21:26 | 000,865,904 | ---- | M] (Babylon Ltd.) -- C:\Program Files\toolbar2.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/10/13 12:37:37 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2009/10/13 12:37:37 | 000,659,456 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2009/10/13 12:37:37 | 000,913,408 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/24 15:54:14 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/10/24 16:03:02 | 000,000,170 | -HS- | M] () -- C:\Documents and Settings\Mendy\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/10/13 21:31:33 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Mendy\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
[2011/09/02 13:03:28 | 000,730,192 | ---- | M] (How Inc.) -- C:\Program Files\Common Files\ZugoInstaller.exe
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
[2011/01/05 23:26:46 | 000,288,088 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Mendy\My Documents\dxwebsetup.exe
[2012/01/29 15:32:02 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Mendy\My Documents\fun00kmw.exe
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2009/10/24 16:03:02 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Mendy\Favorites\Desktop.ini
[2011/09/14 17:46:03 | 000,000,262 | ---- | M] () -- C:\Documents and Settings\Mendy\Favorites\NCH Software Download Site.lnk
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2012/01/29 23:57:09 | 000,032,768 | -HS- | M] () -- C:\Documents and Settings\Mendy\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2007/06/26 21:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
[2008/04/13 16:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
[2004/08/04 00:06:34 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
[2004/08/04 00:06:34 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
[2008/05/02 06:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
[2008/04/13 09:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
[2008/04/13 16:12:28 | 001,695,232 | -HS- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
[2007/04/02 10:07:23 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
[2007/04/02 10:07:23 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
[2007/04/02 10:07:24 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
[2004/08/04 00:06:36 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
[2004/08/04 00:06:36 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2010/12/29 09:02:00 | 000,000,000 | ---D | M](C:\Documents and Settings\Mendy\Favorites\?£sorted Bookmarks) -- C:\Documents and Settings\Mendy\Favorites\ᄨ£sorted Bookmarks
[2010/01/27 10:01:50 | 000,000,000 | ---D | M](C:\Documents and Settings\Mendy\Favorites\?£sorted Bookmarks) -- C:\Documents and Settings\Mendy\Favorites\顸£sorted Bookmarks
[2009/12/31 15:50:08 | 000,000,000 | ---D | M](C:\Documents and Settings\Mendy\Favorites\?£sorted Bookmarks) -- C:\Documents and Settings\Mendy\Favorites\硸£sorted Bookmarks
< End of report >