========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Satan\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Satan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Satan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Satan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Satan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Troll Emoticons = C:\Users\Satan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hndllphbhpadfpoikpaofkkkpkpnmjik\4.6.7_0\
CHR - Extension: Skype Click to Call = C:\Users\Satan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Gmail = C:\Users\Satan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/03/15 20:36:52 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Softonic-EngUSA_ Toolbar) - {6d474053-6aea-476f-af1a-840e7bbd0edb} - C:\Program Files\Softonic-EngUSA_\prxtbSoft.dll (Conduit Ltd.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Softonic-EngUSA_ Toolbar) - {6d474053-6aea-476f-af1a-840e7bbd0edb} - C:\Program Files\Softonic-EngUSA_\prxtbSoft.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-4050984951-2095670543-4058770262-1000\..\Toolbar\WebBrowser: (Softonic-EngUSA_ Toolbar) - {6D474053-6AEA-476F-AF1A-840E7BBD0EDB} - C:\Program Files\Softonic-EngUSA_\prxtbSoft.dll (Conduit Ltd.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [HWSetup] \HWSetup.exe hwSetUP File not found
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KeNotify] C:\Program Files\Toshiba\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKU\S-1-5-21-4050984951-2095670543-4058770262-1000..\Run: [Facebook Update] C:\Users\Satan\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-4050984951-2095670543-4058770262-1000..\Run: [TOSCDSPD] C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe ()
O4 - HKU\S-1-5-21-4050984951-2095670543-4058770262-1000..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4050984951-2095670543-4058770262-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4050984951-2095670543-4058770262-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{39811BFD-A031-4F2C-9911-CDF8F9763AED}: NameServer = 68.87.76.178,66.240.48.9
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C65B8B4F-0AA9-42EE-A7BD-57B516133DA6}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Satan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Satan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/03/16 18:49:51 | 000,594,944 | ---- | C] (OldTimer Tools) -- C:\Users\Satan\Desktop\OTL.exe
[2012/03/15 20:47:08 | 000,000,000 | ---D | C] -- C:\Users\Satan\AppData\Local\temp
[2012/03/15 20:37:01 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/03/15 20:32:42 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/03/15 20:18:10 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/03/15 20:18:10 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/03/15 20:18:10 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/03/15 20:18:03 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/03/15 20:18:02 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/03/15 20:17:58 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/03/15 20:09:40 | 004,436,988 | R--- | C] (Swearware) -- C:\Users\Satan\Desktop\ComboFix.exe
[2012/03/15 19:53:56 | 000,000,000 | ---D | C] -- C:\Users\Satan\Desktop\bootkit_remover
[2012/03/15 19:15:58 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Satan\Desktop\aswMBR.exe
[2012/03/14 21:15:29 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/03/14 21:13:16 | 000,000,000 | ---D | C] -- C:\Users\Satan\Desktop\tdsskiller
[2012/03/13 19:45:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/13 19:45:35 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/03/13 19:25:23 | 009,502,424 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Satan\Desktop\mbam-setup-1.60.1.1000.exe
[2012/03/12 20:09:44 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/03/11 18:03:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intuit
[2012/03/11 18:03:11 | 000,000,000 | ---D | C] -- C:\Program Files\Quicken
[2012/03/11 18:03:11 | 000,000,000 | ---D | C] -- C:\Users\Satan\AppData\Roaming\Intuit
[2012/03/11 18:02:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Intuit
[2012/03/09 14:56:45 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch
[2012/03/07 21:22:17 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2012/03/06 21:43:46 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/03/05 22:04:27 | 000,000,000 | ---D | C] -- C:\Users\Satan\AppData\Roaming\Malwarebytes
[2012/03/05 22:03:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/03/16 18:49:51 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\Satan\Desktop\OTL.exe
[2012/03/16 18:44:01 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4050984951-2095670543-4058770262-1000UA.job
[2012/03/16 18:31:04 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/16 17:58:10 | 000,643,600 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/03/16 17:58:10 | 000,119,760 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/03/16 17:51:17 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/16 17:51:06 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/16 17:51:06 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/16 17:50:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/16 17:50:37 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/15 20:36:52 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/03/15 20:09:42 | 004,436,988 | R--- | M] (Swearware) -- C:\Users\Satan\Desktop\ComboFix.exe
[2012/03/15 19:53:03 | 000,044,607 | ---- | M] () -- C:\Users\Satan\Desktop\bootkit_remover.zip
[2012/03/15 19:47:36 | 000,000,512 | ---- | M] () -- C:\Users\Satan\Desktop\MBR.dat
[2012/03/15 19:17:55 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Satan\Desktop\aswMBR.exe
[2012/03/15 18:19:35 | 000,405,112 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/03/14 21:44:01 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4050984951-2095670543-4058770262-1000Core.job
[2012/03/14 21:11:53 | 002,044,822 | ---- | M] () -- C:\Users\Satan\Desktop\tdsskiller.zip
[2012/03/13 20:29:57 | 000,302,592 | ---- | M] () -- C:\Users\Satan\Desktop\vc0mo67b.exe
[2012/03/13 19:45:41 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/13 19:25:24 | 009,502,424 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Satan\Desktop\mbam-setup-1.60.1.1000.exe
[2012/03/13 19:00:24 | 173,479,987 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/03/12 21:33:59 | 000,001,982 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012/02/25 13:08:22 | 000,000,954 | ---- | M] () -- C:\Users\Satan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/23 10:40:17 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
[2012/02/23 10:40:16 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
[2012/02/23 10:39:19 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/03/15 20:18:10 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/03/15 20:18:10 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/03/15 20:18:10 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/03/15 20:18:10 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/03/15 20:18:10 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/03/15 19:53:02 | 000,044,607 | ---- | C] () -- C:\Users\Satan\Desktop\bootkit_remover.zip
[2012/03/15 19:47:36 | 000,000,512 | ---- | C] () -- C:\Users\Satan\Desktop\MBR.dat
[2012/03/14 21:11:52 | 002,044,822 | ---- | C] () -- C:\Users\Satan\Desktop\tdsskiller.zip
[2012/03/13 20:29:51 | 000,302,592 | ---- | C] () -- C:\Users\Satan\Desktop\vc0mo67b.exe
[2012/03/13 19:45:41 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/13 19:10:21 | 2137,448,448 | -HS- | C] () -- C:\hiberfil.sys
[2012/03/12 20:09:29 | 173,479,987 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/02/23 10:39:19 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2011/07/23 22:26:48 | 000,153,648 | ---- | C] () -- C:\Windows\Snap.dat
[2010/04/30 14:37:02 | 000,003,276 | ---- | C] () -- C:\Windows\System32\NVTBM.ini
========== LOP Check ==========
[2010/11/26 19:12:42 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\.minecraft
[2012/03/12 20:02:02 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Luvin Poker
[2011/07/27 23:03:23 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Qualcomm
[2011/05/31 18:58:15 | 000,000,000 | ---D | M] -- C:\Users\Satan\AppData\Roaming\.minecraft
[2011/05/21 15:50:31 | 000,000,000 | ---D | M] -- C:\Users\Satan\AppData\Roaming\AnvSoft
[2012/01/11 22:02:50 | 000,000,000 | ---D | M] -- C:\Users\Satan\AppData\Roaming\Leadertech
[2009/04/07 02:21:05 | 000,000,000 | ---D | M] -- C:\Users\Satan\AppData\Roaming\Qualcomm
[2011/06/07 11:18:03 | 000,000,000 | ---D | M] -- C:\Users\Satan\AppData\Roaming\TerrariaWorldViewer
[2012/03/14 21:44:01 | 000,000,906 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4050984951-2095670543-4058770262-1000Core.job
[2012/03/16 18:44:01 | 000,000,928 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4050984951-2095670543-4058770262-1000UA.job
[2012/03/15 21:26:29 | 000,032,576 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 14:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2011/07/22 21:24:41 | 000,000,032 | ---- | M] () -- C:\BMSetup.log
[2009/04/10 23:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2008/02/18 18:31:45 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2012/03/15 20:47:06 | 000,013,183 | ---- | M] () -- C:\ComboFix.txt
[2006/09/18 14:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2012/03/16 17:50:37 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/16 17:50:35 | 2451,247,104 | -HS- | M] () -- C:\pagefile.sys
[2012/03/14 21:15:50 | 000,077,896 | ---- | M] () -- C:\TDSSKiller.2.7.20.0_14.03.2012_21.14.26_log.txt
[2012/03/15 19:14:18 | 000,075,098 | ---- | M] () -- C:\TDSSKiller.2.7.20.0_15.03.2012_19.10.04_log.txt
< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/11/24 11:09:54 | 000,037,665 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2011/07/14 09:28:04 | 001,332,736 | ---- | M] (Hewlett-Packard) -- C:\Windows\system32\spool\prtprocs\w32x86\hpbfpp1101.dll
[2006/11/02 05:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/02/18 18:31:33 | 012,820,480 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008/02/18 18:31:27 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008/02/18 18:31:33 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2008/02/18 18:31:40 | 017,186,816 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2008/02/18 18:31:42 | 006,635,520 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/25 13:08:22 | 000,000,574 | -HS- | M] () -- C:\Users\Satan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/03/15 19:17:55 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Satan\Desktop\aswMBR.exe
[2012/03/15 20:09:42 | 004,436,988 | R--- | M] (Swearware) -- C:\Users\Satan\Desktop\ComboFix.exe
[2012/03/13 19:25:24 | 009,502,424 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Satan\Desktop\mbam-setup-1.60.1.1000.exe
[2012/03/16 18:49:51 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\Satan\Desktop\OTL.exe
[2012/03/13 20:29:57 | 000,302,592 | ---- | M] () -- C:\Users\Satan\Desktop\vc0mo67b.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/03/14 21:44:01 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4050984951-2095670543-4058770262-1000Core.job
[2012/03/16 18:44:01 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4050984951-2095670543-4058770262-1000UA.job
[2012/03/16 17:51:17 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/16 18:31:04 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/16 17:50:48 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/03/15 21:26:29 | 000,032,576 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2011/07/22 21:55:09 | 000,000,402 | -HS- | M] () -- C:\Users\Satan\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2009/06/21 13:04:20 | 000,002,945 | ---- | M] () -- C:\ProgramData\LUUnInstall.LiveUpdate
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >