OTL.txt
OTL logfile created on: 4/29/2011 11:11:20 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Jason Boos\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Trinidad and Tobago | Language: ENT | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 185.55 Gb Total Space | 91.78 Gb Free Space | 49.46% Space Free | Partition Type: NTFS
Drive E: | 112.53 Gb Total Space | 69.37 Gb Free Space | 61.65% Space Free | Partition Type: NTFS
Computer Name: JASONBOOS-PC | User Name: Jason Boos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/04/29 23:09:38 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Jason Boos\Downloads\OTL.exe
PRC - [2010/09/22 18:11:26 | 000,640,440 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2010/05/14 11:44:46 | 000,501,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2009/09/15 06:26:48 | 000,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/09/15 06:26:43 | 000,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/09/15 06:26:28 | 000,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/09/15 06:24:13 | 000,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/09/15 06:19:40 | 000,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/08/03 01:05:50 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/07/13 20:44:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/02/23 19:43:12 | 000,576,000 | ---- | M] (MagicISO, Inc.) -- C:\Program Files\MagicDisc\MagicDisc.exe
PRC - [2008/05/19 12:13:20 | 000,057,344 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\System32\ASTSRV.EXE
PRC - [2007/03/29 15:41:26 | 000,222,128 | ---- | M] (Macrovision Corporation) -- C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
PRC - [2006/09/19 09:07:28 | 000,827,392 | ---- | M] () -- C:\Windows\vsnpstd3.exe
PRC - [2006/01/17 16:57:26 | 000,294,912 | ---- | M] () -- C:\Windows\System32\ATWTUSB.EXE
PRC - [2005/06/17 19:09:08 | 000,061,440 | ---- | M] (WALTOP International Corp.) -- C:\Windows\System32\TBLMOUSE.EXE
========== Modules (SafeList) ==========
MOD - [2011/04/29 23:09:38 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Jason Boos\Downloads\OTL.exe
MOD - [2010/08/21 00:51:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/04/24 23:48:14 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/12/12 13:10:19 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/09/15 06:26:43 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009/09/15 06:26:28 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009/09/15 06:24:13 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009/09/15 06:19:40 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2009/07/13 20:46:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 20:46:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 20:45:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/05/19 12:13:20 | 000,057,344 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\System32\ASTSRV.EXE -- (ASTSRV)
========== Driver Services (SafeList) ==========
DRV - [2010/05/01 20:41:28 | 000,217,600 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sis163u.sys -- (SIS163u)
DRV - [2009/09/27 23:12:22 | 009,509,832 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/09/15 06:25:30 | 000,114,768 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2009/09/15 06:25:19 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009/09/15 06:25:09 | 000,053,328 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2009/09/15 06:24:30 | 000,052,368 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009/09/15 06:24:21 | 000,023,152 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009/07/13 20:49:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 20:49:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 20:49:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 19:24:16 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2009/07/13 18:58:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 18:58:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/13 17:32:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009/02/24 18:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2007/06/29 14:47:34 | 000,034,304 | ---- | M] (AMD, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AmdLLD.sys -- (AmdLLD)
DRV - [2007/06/26 09:45:12 | 000,286,208 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WMP54Gv41x86.sys -- (rt61x86)
DRV - [2007/03/27 18:19:36 | 010,252,544 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)
DRV - [2005/12/23 12:13:54 | 000,022,656 | ---- | M] (Pen Pad) [Kernel | System | Running] -- C:\Windows\System32\drivers\aiptektp.sys -- (aiptektp)
DRV - [2004/08/13 09:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4257196180-1364586872-4245516868-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-tt
IE - HKU\S-1-5-21-4257196180-1364586872-4245516868-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 2E 1C CA A8 83 CB 01 [binary data]
IE - HKU\S-1-5-21-4257196180-1364586872-4245516868-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4257196180-1364586872-4245516868-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/27 23:09:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/27 23:09:14 | 000,000,000 | ---D | M]
[2010/08/02 18:23:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jason Boos\AppData\Roaming\Mozilla\Extensions
[2010/08/02 18:23:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jason Boos\AppData\Roaming\Mozilla\Firefox\Profiles\jajzdzpw.default\extensions
[2011/04/22 16:05:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/15 10:25:00 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2011/04/28 20:23:43 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-4257196180-1364586872-4245516868-1001\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [atwtusb] C:\Windows\System32\ATWTUSB.EXE ()
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
O4 - HKU\S-1-5-21-4257196180-1364586872-4245516868-1001..\Run: [Adobe Acrobat Synchronizer] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-21-4257196180-1364586872-4245516868-1001..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation)
O4 - Startup: C:\Users\Jason Boos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4257196180-1364586872-4245516868-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4257196180-1364586872-4245516868-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4257196180-1364586872-4245516868-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 200.1.104.36 200.1.104.35
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\Windows\System32\acaptuser32.dll) - C:\Windows\System32\acaptuser32.dll (Adobe Systems Incorporated)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/11/04 23:18:29 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2009/06/10 17:12:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - ff_vfw.dll File not found
Drivers32: vidc.tscc - C:\PROGRA~1\MpcStar\Codecs\tscc\tsccvid.dll File not found
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (
www.helixcommunity.org)
========== Files/Folders - Created Within 30 Days ==========
[2011/04/28 20:23:48 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2011/04/28 20:14:02 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011/04/28 05:33:57 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/04/28 04:23:26 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/04/28 04:23:26 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/04/28 04:23:26 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/04/28 04:23:18 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/04/28 04:21:35 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/28 03:01:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2011/04/27 19:43:43 | 001,377,112 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Jason Boos\Desktop\TDSSKiller.exe
[2011/04/22 22:00:00 | 000,000,000 | ---D | C] -- C:\Program Files\HijackThis
[2011/04/17 01:52:18 | 000,000,000 | ---D | C] -- C:\Users\Jason Boos\Documents\Activision
[2011/04/17 01:52:18 | 000,000,000 | ---D | C] -- C:\Users\Jason Boos\AppData\Local\Activision
[2011/04/17 00:29:45 | 000,000,000 | RHSD | C] -- C:\Program Files\Media
[2011/04/09 18:13:23 | 000,000,000 | ---D | C] -- C:\Users\Jason Boos\AppData\Roaming\cYo
[2011/04/09 18:13:23 | 000,000,000 | ---D | C] -- C:\Users\Jason Boos\AppData\Local\cYo
[2011/04/09 18:02:35 | 000,000,000 | ---D | C] -- C:\Program Files\ComicRack
[2011/04/06 02:16:21 | 000,000,000 | ---D | C] -- C:\Users\Jason Boos\AppData\Roaming\AMPSoft
[2011/04/06 02:16:03 | 000,000,000 | ---D | C] -- C:\Users\Jason Boos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMP Font Viewer
[2011/04/06 02:16:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMP Font Viewer
[2011/04/06 02:16:03 | 000,000,000 | ---D | C] -- C:\Program Files\AMP Font Viewer
[2011/04/06 00:45:00 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2011/04/02 14:58:39 | 000,000,000 | ---D | C] -- C:\Users\Jason Boos\AppData\Roaming\bizarre creations
[2011/04/02 14:50:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blur(TM)
[2009/12/12 10:58:24 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Jason Boos\AppData\Roaming\pcouffin.sys
[2007/03/12 11:41:52 | 000,061,440 | ---- | C] ( ) -- C:\Windows\System32\vsnpstd3.dll
[2005/11/23 12:55:32 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnpstd3.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/29 23:03:41 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/29 23:03:41 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/29 23:02:03 | 000,003,811 | ---- | M] () -- C:\Windows\aiptbl.ini
[2011/04/29 23:00:40 | 000,630,928 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/04/29 23:00:40 | 000,111,052 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/04/29 22:56:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/04/29 22:56:15 | 2415,370,240 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/29 06:19:00 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4257196180-1364586872-4245516868-1001UA.job
[2011/04/29 04:19:01 | 000,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4257196180-1364586872-4245516868-1001Core.job
[2011/04/28 20:23:43 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/04/28 20:13:52 | 004,332,535 | R--- | M] () -- C:\Users\Jason Boos\Desktop\ComboFix.exe
[2011/04/27 19:40:48 | 297,488,533 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/04/26 22:59:59 | 000,001,745 | ---- | M] () -- C:\Users\Jason Boos\Desktop\Japan-flag.png
[2011/04/25 21:42:24 | 000,000,017 | ---- | M] () -- C:\Users\Jason Boos\Desktop\stinger10101535.opt
[2011/04/22 08:57:32 | 000,001,908 | ---- | M] () -- C:\Windows\diagwrn.xml
[2011/04/22 08:57:32 | 000,001,908 | ---- | M] () -- C:\Windows\diagerr.xml
[2011/04/06 00:18:20 | 000,001,095 | ---- | M] () -- C:\Users\Jason Boos\Desktop\Adobe Photoshop CS4.lnk
[2011/04/03 14:20:57 | 000,002,430 | ---- | M] () -- C:\Users\Jason Boos\Desktop\Google Chrome.lnk
[2011/04/02 14:50:59 | 000,001,970 | ---- | M] () -- C:\Users\Public\Desktop\Blur(TM).lnk
[2011/04/01 00:32:18 | 000,087,968 | ---- | M] () -- C:\Users\Jason Boos\Documents\Darren 31-3-11.dwg
[2011/04/01 00:21:31 | 000,087,456 | ---- | M] () -- C:\Users\Jason Boos\Documents\Darren 31-3-11.bak
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/28 04:23:26 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/04/28 04:23:26 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/04/28 04:23:26 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/04/28 04:23:26 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/04/28 04:23:26 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/04/28 04:20:31 | 004,332,535 | R--- | C] () -- C:\Users\Jason Boos\Desktop\ComboFix.exe
[2011/04/27 19:40:48 | 297,488,533 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/04/26 23:00:04 | 000,001,745 | ---- | C] () -- C:\Users\Jason Boos\Desktop\Japan-flag.png
[2011/04/25 21:42:24 | 000,000,017 | ---- | C] () -- C:\Users\Jason Boos\Desktop\stinger10101535.opt
[2011/04/22 08:48:03 | 000,001,908 | ---- | C] () -- C:\Windows\diagwrn.xml
[2011/04/22 08:48:03 | 000,001,908 | ---- | C] () -- C:\Windows\diagerr.xml
[2011/04/06 00:18:20 | 000,001,095 | ---- | C] () -- C:\Users\Jason Boos\Desktop\Adobe Photoshop CS4.lnk
[2011/04/02 14:50:59 | 000,001,970 | ---- | C] () -- C:\Users\Public\Desktop\Blur(TM).lnk
[2011/03/31 21:47:33 | 000,087,968 | ---- | C] () -- C:\Users\Jason Boos\Documents\Darren 31-3-11.dwg
[2011/03/31 21:47:33 | 000,087,456 | ---- | C] () -- C:\Users\Jason Boos\Documents\Darren 31-3-11.bak
[2011/01/18 04:53:23 | 000,052,992 | ---- | C] () -- C:\Windows\System32\drivers\gvmeaey.sys
[2011/01/02 19:54:29 | 000,000,032 | ---- | C] () -- C:\ProgramData\io.ini
[2011/01/02 19:54:29 | 000,000,000 | ---- | C] () -- C:\ProgramData\hge5hyelujwwm76663v8i2ylkaf914xp.ini
[2010/11/09 18:26:57 | 000,002,694 | ---- | C] () -- C:\Windows\CD_SearchHistory.INI
[2010/11/09 18:26:57 | 000,000,049 | ---- | C] () -- C:\Windows\SW_Win3112X32.DLL
[2010/10/19 03:44:04 | 000,001,024 | ---- | C] () -- C:\Windows\System32\grcauth2.dll
[2010/10/19 03:44:04 | 000,001,024 | ---- | C] () -- C:\Windows\System32\grcauth1.dll
[2010/10/19 03:44:04 | 000,000,100 | ---- | C] () -- C:\Windows\System32\prsgrc.dll
[2010/10/14 01:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2010/07/15 12:48:55 | 000,004,608 | ---- | C] () -- C:\Users\Jason Boos\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/08 22:33:12 | 000,001,025 | ---- | C] () -- C:\Windows\System32\sysprs7.dll
[2010/07/08 22:33:12 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth2.dll
[2010/07/08 22:33:12 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth1.dll
[2010/07/08 22:33:12 | 000,000,205 | ---- | C] () -- C:\Windows\System32\lsprst7.dll
[2010/07/08 22:33:12 | 000,000,073 | ---- | C] () -- C:\Windows\System32\ssprs.dll
[2010/07/08 22:33:12 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2010/06/17 17:11:37 | 002,373,712 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2010/06/07 17:57:24 | 000,052,864 | R--- | C] () -- C:\Windows\System32\SetupWizard.exe
[2010/05/09 15:50:25 | 000,012,288 | ---- | C] () -- C:\Windows\impborl.dll
[2010/04/21 18:29:40 | 000,451,072 | ---- | C] () -- C:\Windows\System32\ISSRemoveSP.exe
[2010/03/22 20:48:11 | 000,002,516 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010/03/22 20:48:11 | 000,000,008 | RHS- | C] () -- C:\ProgramData\420CCA7691.sys
[2010/02/08 22:43:47 | 000,234,760 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2010/01/24 16:28:53 | 000,000,433 | ---- | C] () -- C:\Windows\crackpdf.INI
[2010/01/16 23:11:37 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010/01/05 10:20:31 | 000,720,896 | ---- | C] () -- C:\Windows\EAInstall.dll
[2009/12/31 18:05:59 | 000,294,912 | ---- | C] () -- C:\Windows\System32\ATWTUSB.EXE
[2009/12/31 18:05:59 | 000,090,112 | ---- | C] () -- C:\Windows\RmTablet.exe
[2009/12/31 18:05:59 | 000,049,152 | ---- | C] () -- C:\Windows\System32\Funckey.dll
[2009/12/31 18:05:58 | 000,003,811 | ---- | C] () -- C:\Windows\aiptbl.ini
[2009/12/22 00:58:04 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009/12/22 00:58:04 | 000,022,328 | ---- | C] () -- C:\Users\Jason Boos\AppData\Roaming\PnkBstrK.sys
[2009/12/22 00:57:40 | 000,103,736 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2009/12/22 00:57:39 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2009/12/14 21:33:23 | 000,000,671 | ---- | C] () -- C:\Users\Jason Boos\AppData\Roaming\vso_ts_preview.xml
[2009/12/13 18:49:31 | 000,000,151 | ---- | C] () -- C:\Windows\PhotoSnapViewer.INI
[2009/12/12 23:55:01 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2009/12/12 23:55:00 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2009/12/12 10:58:24 | 000,007,887 | ---- | C] () -- C:\Users\Jason Boos\AppData\Roaming\pcouffin.cat
[2009/12/12 10:58:24 | 000,001,144 | ---- | C] () -- C:\Users\Jason Boos\AppData\Roaming\pcouffin.inf
[2009/12/11 19:16:57 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/07/14 00:27:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:03:53 | 002,439,224 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 21:35:48 | 000,630,928 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 21:35:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 21:35:48 | 000,111,052 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 21:35:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 21:35:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 21:34:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 19:49:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 19:25:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:21:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:12:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/19 20:06:22 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2009/06/19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2009/06/19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2009/06/19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2009/06/19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2009/06/19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2009/06/19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2009/06/19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2009/06/19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2009/06/19 20:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2009/06/10 16:56:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2007/06/12 10:55:54 | 000,000,920 | ---- | C] () -- C:\Windows\System32\WLAN.INI
[2006/09/19 09:07:28 | 000,827,392 | ---- | C] () -- C:\Windows\vsnpstd3.exe
[2005/01/06 14:04:00 | 000,049,152 | ---- | C] () -- C:\Windows\System32\unwlsdrv.exe
[2004/08/13 09:56:20 | 000,005,810 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[2004/02/27 16:36:18 | 000,015,498 | ---- | C] () -- C:\Windows\snpstd3.ini
========== LOP Check ==========
[2009/12/22 07:10:50 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\Alien Skin
[2011/04/06 02:16:21 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\AMPSoft
[2011/03/26 16:09:58 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\Autodesk
[2011/04/02 14:58:39 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\bizarre creations
[2011/04/09 18:13:23 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\cYo
[2010/01/12 18:36:11 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\HatchKit Demo 2.7
[2009/12/31 00:06:44 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\Leadertech
[2010/06/06 14:35:25 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\MAXON
[2010/01/31 00:13:24 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\SharePod
[2010/08/17 23:58:59 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\Softland
[2010/04/21 18:07:18 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\SoundSpectrum
[2010/07/15 12:36:34 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\TigerPlayer
[2010/03/18 23:44:25 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\UClick
[2010/11/09 23:38:31 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\Unity
[2011/04/27 23:09:17 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\uTorrent
[2011/02/09 21:53:19 | 000,000,000 | ---D | M] -- C:\Users\Jason Boos\AppData\Roaming\Vso
[2011/04/02 11:05:14 | 000,032,644 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:12:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009/04/02 06:22:15 | 000,000,232 | -H-- | M] () -- C:\Boot.BAK
[2009/12/11 21:42:10 | 000,000,376 | RHS- | M] () -- C:\Boot.ini.saved
[2009/07/13 21:08:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2009/12/11 21:42:11 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2011/04/28 20:27:51 | 000,012,251 | ---- | M] () -- C:\ComboFix.txt
[2009/06/10 17:12:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2009/12/06 13:34:42 | 000,000,000 | ---- | M] () -- C:\dump_dvd.vob
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2009/12/11 18:29:25 | 000,203,836 | RHS- | M] () -- C:\grldr
[2011/04/29 22:56:15 | 2415,370,240 | -HS- | M] () -- C:\hiberfil.sys
[2009/12/03 21:09:10 | 000,000,525 | ---- | M] () -- C:\hpfr3420.xml
[2009/12/03 21:09:10 | 000,091,358 | ---- | M] () -- C:\hpfr3425.log
[2009/12/01 18:01:10 | 000,001,292 | -H-- | M] () -- C:\hpothb07.dat
[2009/12/01 18:01:10 | 000,002,473 | -H-- | M] () -- C:\hpothb07.tif
[2010/01/16 23:19:56 | 000,230,424 | ---- | M] () -- C:\img2-001.raw
[2010/01/16 23:36:29 | 000,230,424 | ---- | M] () -- C:\img2-002.raw
[2007/11/07 08:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2009/02/18 19:49:16 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/01/31 10:34:23 | 003,058,216 | ---- | M] () -- C:\ituneslib.itl
[2009/05/11 17:43:36 | 000,000,477 | ---- | M] () -- C:\LOG3C.log
[2009/05/11 18:11:07 | 000,000,477 | ---- | M] () -- C:\LOG77.log
[2009/02/18 19:49:16 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/03/20 13:02:18 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/03/20 14:53:58 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2011/04/29 22:56:23 | 3220,496,384 | -HS- | M] () -- C:\pagefile.sys
[2011/04/27 18:56:36 | 000,066,956 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_27.04.2011_18.56.02_log.txt
[2011/04/27 19:44:53 | 000,067,706 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_27.04.2011_19.43.49_log.txt
[2011/04/27 19:53:35 | 000,067,066 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_27.04.2011_19.47.25_log.txt
[2009/11/17 22:46:08 | 000,000,216 | ---- | M] () -- C:\temp.txt
[2007/11/07 08:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI
[2009/12/11 18:29:25 | 000,000,000 | RHS- | M] () -- C:\winx.ld
< %systemroot%\Fonts\*.com >
[2009/07/14 00:22:25 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:22:25 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:22:25 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:22:25 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 17:01:19 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 20:45:05 | 000,071,168 | ---- | M] (CANON INC.) -- C:\Windows\System32\spool\prtprocs\w32x86\CNBPP4.DLL
[2009/06/22 18:58:20 | 000,089,600 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2009/07/13 20:45:35 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/13 20:46:19 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:11:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/11 19:05:33 | 000,000,221 | -HS- | M] () -- C:\Users\Jason Boos\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/04/28 20:13:52 | 004,332,535 | R--- | M] () -- C:\Users\Jason Boos\Desktop\ComboFix.exe
[2011/03/10 12:27:50 | 001,377,112 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Jason Boos\Desktop\TDSSKiller.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2004/02/27 16:36:18 | 000,013,023 | ---- | M] () -- C:\Windows\snpstd3.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 16:50:04 | 000,000,802 | ---- | M] () -- C:\Windows\addins\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2010/08/03 20:12:09 | 000,000,402 | -HS- | M] () -- C:\Users\Jason Boos\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2010/03/22 20:48:11 | 000,000,008 | RHS- | M] () -- C:\ProgramData\420CCA7691.sys
[2011/01/02 19:54:29 | 000,000,000 | ---- | M] () -- C:\ProgramData\hge5hyelujwwm76663v8i2ylkaf914xp.ini
[2010/01/05 13:11:41 | 000,000,202 | ---- | M] () -- C:\ProgramData\hpzinstall.log
[2011/01/02 19:54:29 | 000,000,032 | ---- | M] () -- C:\ProgramData\io.ini
[2010/08/14 11:46:48 | 000,002,516 | -HS- | M] () -- C:\ProgramData\KGyGaAvL.sys
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:C8B8CEBD
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP

4BB0AD6
< End of report >