Heres the
OTL text
OTL logfile created on: 04/12/2011 5:05:03 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\LifeTravel\Downloads
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
4.00 Gb Total Physical Memory | 2.32 Gb Available Physical Memory | 58.01% Memory free
8.00 Gb Paging File | 6.10 Gb Available in Paging File | 76.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 794.20 Gb Free Space | 85.27% Space Free | Partition Type: NTFS
Computer Name: LIFETRAVEL-PC | User Name: LifeTravel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/04 16:59:13 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\LifeTravel\Downloads\OTL.exe
PRC - [2011/09/29 20:57:12 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/01/17 18:08:58 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011/01/17 18:08:58 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2011/01/12 16:41:42 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
PRC - [2009/10/23 19:24:54 | 001,085,440 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
PRC - [2009/07/10 10:23:54 | 000,036,864 | R--- | M] (Realtek) -- C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
========== Modules (No Company Name) ==========
MOD - [2011/09/23 12:04:19 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2011/09/23 12:04:19 | 000,170,496 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxslt.dll
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2011/09/08 17:29:56 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:
64bit: - [2011/09/08 12:42:32 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:
64bit: - [2011/06/30 08:37:30 | 002,528,096 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV:
64bit: - [2011/01/12 16:44:02 | 000,042,360 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV:
64bit: - [2011/01/12 16:41:42 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV:
64bit: - [2009/07/14 01:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009/07/14 01:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:
64bit: - [2009/07/09 17:48:34 | 001,044,648 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\dldtcoms.exe -- (dldt_device)
SRV - [2011/11/13 14:40:05 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/09/29 20:57:12 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/07/10 10:23:54 | 000,036,864 | R--- | M] (Realtek) [Auto | Running] -- C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe -- (Realtek11nSU)
SRV - [2009/06/10 21:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2011/09/08 18:27:22 | 010,203,648 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:
64bit: - [2011/09/08 18:27:22 | 010,203,648 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:
64bit: - [2011/09/08 16:52:40 | 000,310,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:
64bit: - [2011/08/31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:
64bit: - [2011/08/26 12:14:36 | 000,270,912 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:
64bit: - [2011/07/28 17:37:10 | 000,052,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB)
DRV:
64bit: - [2011/06/24 05:31:02 | 000,055,424 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.01)
DRV:
64bit: - [2011/06/06 22:07:00 | 000,231,440 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:
64bit: - [2011/03/11 06:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011/03/11 06:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2010/12/21 15:04:06 | 000,170,640 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:
64bit: - [2010/12/21 15:04:06 | 000,141,264 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:
64bit: - [2010/12/21 13:47:38 | 000,125,296 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:
64bit: - [2010/11/09 14:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:
64bit: - [2010/02/18 08:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:
64bit: - [2009/10/14 17:31:58 | 000,674,304 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192su.sys -- (RTL8192su)
DRV:
64bit: - [2009/08/23 14:02:30 | 000,120,336 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:
64bit: - [2009/07/14 01:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/14 01:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/14 01:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2009/07/14 01:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/06/10 20:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:
64bit: - [2009/06/10 20:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 20:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 20:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 20:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/14 01:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2270658081-143835805-282498064-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/12 04:26:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/11/30 13:51:05 | 000,000,000 | ---D | M]
[2011/07/28 14:18:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\LifeTravel\AppData\Roaming\Mozilla\Extensions
[2011/11/29 13:38:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\LifeTravel\AppData\Roaming\Mozilla\Firefox\Profiles\g8grsfhs.default\extensions
[2011/11/12 04:26:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\LIFETRAVEL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G8GRSFHS.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/12 04:26:54 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/05 19:26:38 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/10/05 19:26:38 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/10/05 19:26:38 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/10/05 19:26:38 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/10/05 19:26:38 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2011/12/04 11:46:23 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4:
64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4:
64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - Startup: C:\Users\LifeTravel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2270658081-143835805-282498064-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2270658081-143835805-282498064-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A9D9089-CCCF-427E-917D-B70CEE870DD9}: DhcpNameServer = 192.168.0.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O20:
64bit: - AppInit_DLLs: (C:\Windows\System32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) -C:\Windows\SysWOW64\guard32.dll (COMODO)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs:
64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:
64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/04 11:48:51 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/12/04 11:46:25 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2011/12/04 11:36:33 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/12/04 11:36:33 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/12/04 11:36:33 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/12/04 11:32:06 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/12/04 11:27:51 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/12/04 11:14:02 | 004,326,668 | R--- | C] (Swearware) -- C:\Users\LifeTravel\Desktop\ComboFix.exe
[2011/12/04 01:53:46 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Roaming\Malwarebytes
[2011/12/04 01:53:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/04 01:53:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/12/04 01:53:40 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/12/04 01:53:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/12/02 03:56:45 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{52038CA8-97C8-48EA-B899-89A4B8FEB2C2}
[2011/12/02 03:56:31 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{C94C94E1-82E6-433F-8C8C-4DA1BF8F7C86}
[2011/12/01 13:12:50 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\Desktop\super_secret
[2011/12/01 01:53:22 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{47543DB9-9A23-4198-AC34-05FFC7B73DCB}
[2011/12/01 01:53:10 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{D90ADB86-A97C-4E6C-ADF6-36CB085B9672}
[2011/11/30 13:52:41 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{C37AEB8D-08D8-4FE0-B455-84038502C066}
[2011/11/30 13:51:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2011/11/30 13:51:04 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2011/11/30 13:51:04 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/11/30 13:50:24 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{89187912-F91A-4FBE-87EF-83E7ED219879}
[2011/11/30 13:43:24 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{85D0A3E5-EB3A-4B1F-9805-30A5D4792BAB}
[2011/11/29 10:25:31 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{0960BDD4-D5D4-4EB5-85DC-A01C7CE6CC1D}
[2011/11/29 10:25:12 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{79085551-5362-4C68-8E3E-455A018FC029}
[2011/11/28 08:40:43 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\201280
[2011/11/28 05:13:32 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\Documents\Deus Ex - Invisible War
[2011/11/28 01:47:52 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{EC6F047D-FCC9-49B5-864E-C9FA464D189C}
[2011/11/28 01:47:40 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{7DEF06A1-59BD-43F0-A1B4-641A89E93F43}
[2011/11/27 00:10:11 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{BBF54515-957B-42FD-93B5-D4446C953C5A}
[2011/11/27 00:09:29 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{2A634BBF-E6AC-4BD4-A11A-76D88786E09E}
[2011/11/26 05:58:21 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{3C1AF670-F11A-434A-84FF-6A5326DD0C74}
[2011/11/25 08:23:22 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{2522126C-1E1E-49BA-ABC5-D78B9DF8CAF0}
[2011/11/25 08:23:11 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{9F939BDE-DAF1-4EF8-A775-275B4A089332}
[2011/11/25 06:07:02 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{C65E2AF3-1749-44F1-82FF-156CD4B56EE9}
[2011/11/25 06:06:51 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{CA9D30D3-E852-415F-BACB-95692ED90482}
[2011/11/24 14:47:22 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{DE87506F-5F8F-41ED-8293-1B1B5E372714}
[2011/11/24 14:47:04 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{05314E9F-FF3F-41A6-A49D-D36E13AF911A}
[2011/11/23 17:21:39 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{37E486E1-80AB-4BF3-854A-24BAF482E398}
[2011/11/23 17:21:27 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{582B82E8-FF2B-4121-A8D2-4D53A306C14B}
[2011/11/23 02:28:45 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{D9F36A2C-56C3-4D4D-90F1-69A2F3A4949B}
[2011/11/23 02:28:32 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{DB60B466-5302-4E78-837C-179EC91AFE7F}
[2011/11/22 08:09:52 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Roaming\fltk.org
[2011/11/22 08:09:52 | 000,000,000 | ---D | C] -- C:\ProgramData\fltk.org
[2011/11/22 08:08:10 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\Documents\Amnesia
[2011/11/21 22:51:42 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{98FCCC85-BEF7-4F51-858A-6E715A943E8E}
[2011/11/21 22:51:11 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{B2F58137-3503-4279-A94C-9661A95D8A43}
[2011/11/21 09:50:35 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{78A0B904-F664-4ACE-BCF3-82C556B0BC9C}
[2011/11/21 09:50:15 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{3F61F2BE-E454-4381-AEA5-1D96890EFC08}
[2011/11/20 05:02:29 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{47250E7F-4AD0-4D80-8768-E002C812E288}
[2011/11/20 05:02:18 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{26BCEC32-507E-4353-B742-97FB16341E9A}
[2011/11/19 17:01:52 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{C2FC0A55-4575-47CF-983D-62EC29E819BA}
[2011/11/19 17:01:33 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{85AC3BD2-2D87-4F14-98F3-F3E1B25B2EDD}
[2011/11/19 11:56:24 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{93D7A376-956E-4C04-8E64-37A4FD800923}
[2011/11/17 15:58:54 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{94A9D353-487E-4431-962D-16B19B1AACC0}
[2011/11/17 15:58:38 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{AA33891C-68C9-41EE-AFC1-C1A4D522AE17}
[2011/11/16 10:40:47 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{B687B446-FE8E-4644-BD22-A22C17CB25E7}
[2011/11/15 21:50:00 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\Desktop\Notes
[2011/11/15 06:54:22 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{5C233950-964C-4442-953A-774A9B01D2E4}
[2011/11/15 06:54:10 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{B6299CB8-3C01-49FC-B700-84F039B36374}
[2011/11/15 03:39:54 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{3FC1DDB1-F980-4AFA-B255-1958B0ED1079}
[2011/11/14 14:16:36 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{E690DB9E-57D4-4C29-B53F-7DF9E447A12F}
[2011/11/14 14:16:22 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{80BD81DC-A975-46F6-9ACA-3B7683F348DD}
[2011/11/13 20:27:03 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\Documents\WBGames
[2011/11/13 05:03:34 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{237BEA1F-23FD-4496-899F-C6849522D266}
[2011/11/13 05:03:22 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{4A68A2A8-A406-4876-93AA-6218ECB78A66}
[2011/11/12 00:55:13 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{2521F2C7-8CF5-4F4F-A102-E05BF39866E1}
[2011/11/12 00:54:34 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{3809A187-384A-4F75-A9AE-1C84FDA468DD}
[2011/11/12 00:52:46 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{75A914DF-B3F0-4489-9501-1A1F78F8C44F}
[2011/11/11 10:32:14 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{DBE2AD8E-46A7-4AA8-BEB0-36C11EC4983D}
[2011/11/10 12:47:27 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{1E3835D6-EC9E-43DD-9C15-CDEBF7C9DB73}
[2011/11/10 12:47:14 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{9176D33F-5339-4894-993D-B4895DE406CC}
[2011/11/09 14:23:36 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{2DEC16AF-1C79-43ED-A5CA-997DA8A9CAB4}
[2011/11/09 14:22:48 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{4383C09D-84FE-4A88-A3B1-FFB74066872D}
[2011/11/08 13:24:43 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{436EDC31-44BE-49C6-A7A8-46B0DE3E2C0F}
[2011/11/08 13:24:28 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{E826EDB7-48BA-462A-816B-8BB4AF7074F8}
[2011/11/07 12:49:32 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{11DBA03E-33E3-4583-80C2-676088B9B6E5}
[2011/11/06 12:28:53 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{1847C9F0-51DC-4CBC-BCE9-66BB333D59A6}
[2011/11/06 12:28:00 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{72C7C6F5-ECDE-4D59-BB5A-7910E8A3E275}
[2011/11/05 10:56:56 | 000,000,000 | ---D | C] -- C:\Users\LifeTravel\AppData\Local\{5622E258-9EEE-4771-9289-122E7A69F073}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/04 16:15:39 | 000,012,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/04 16:15:39 | 000,012,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/04 12:17:56 | 001,972,886 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/12/04 12:17:56 | 000,775,642 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/12/04 12:17:56 | 000,005,152 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/04 12:13:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/04 12:13:18 | 3220,037,632 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/04 11:55:03 | 001,008,114 | ---- | M] () -- C:\Users\LifeTravel\Desktop\rkill.exe
[2011/12/04 11:46:23 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/12/04 11:16:52 | 000,095,603 | ---- | M] () -- C:\Users\LifeTravel\Desktop\top.png
[2011/12/04 11:14:30 | 004,326,668 | R--- | M] (Swearware) -- C:\Users\LifeTravel\Desktop\ComboFix.exe
[2011/12/04 11:13:50 | 000,000,512 | ---- | M] () -- C:\Users\LifeTravel\Desktop\MBR.dat
[2011/12/04 03:27:37 | 000,112,306 | ---- | M] () -- C:\Users\LifeTravel\Desktop\eset.png
[2011/12/04 01:53:44 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/04 01:00:32 | 000,090,200 | ---- | M] () -- C:\Users\LifeTravel\Desktop\Untitled.png
[2011/12/04 00:42:39 | 000,167,583 | ---- | M] () -- C:\Users\LifeTravel\Desktop\Trojan.png
[2011/12/03 23:46:21 | 000,023,199 | ---- | M] () -- C:\Users\LifeTravel\Desktop\Economics.odt
[2011/11/30 14:19:35 | 000,000,122 | ---- | M] () -- C:\delwpa.bat
[2011/11/16 14:43:42 | 000,001,100 | ---- | M] () -- C:\Users\LifeTravel\Desktop\OpenOffice.org Writer.lnk
[2011/11/13 06:30:29 | 001,161,257 | ---- | M] () -- C:\Users\LifeTravel\Desktop\understand-pure-o.pdf.pdf
[2011/11/10 15:50:43 | 000,097,925 | ---- | M] () -- C:\Users\LifeTravel\Desktop\solidus.png
[2011/11/10 12:46:35 | 000,292,728 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/09 01:02:08 | 000,491,158 | ---- | M] () -- C:\Users\LifeTravel\Desktop\LOL.png
[2011/11/05 20:36:19 | 000,000,871 | ---- | M] () -- C:\Users\LifeTravel\.recently-used.xbel
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/04 11:54:55 | 001,008,114 | ---- | C] () -- C:\Users\LifeTravel\Desktop\rkill.exe
[2011/12/04 11:36:33 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/12/04 11:36:33 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/12/04 11:36:33 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/12/04 11:36:33 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/12/04 11:36:33 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/12/04 11:16:39 | 000,095,603 | ---- | C] () -- C:\Users\LifeTravel\Desktop\top.png
[2011/12/04 11:13:50 | 000,000,512 | ---- | C] () -- C:\Users\LifeTravel\Desktop\MBR.dat
[2011/12/04 03:27:37 | 000,112,306 | ---- | C] () -- C:\Users\LifeTravel\Desktop\eset.png
[2011/12/04 01:53:44 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/04 01:00:32 | 000,090,200 | ---- | C] () -- C:\Users\LifeTravel\Desktop\Untitled.png
[2011/12/04 00:42:39 | 000,167,583 | ---- | C] () -- C:\Users\LifeTravel\Desktop\Trojan.png
[2011/11/30 19:05:49 | 000,023,199 | ---- | C] () -- C:\Users\LifeTravel\Desktop\Economics.odt
[2011/11/30 14:19:35 | 000,000,122 | ---- | C] () -- C:\delwpa.bat
[2011/11/16 14:43:42 | 000,001,100 | ---- | C] () -- C:\Users\LifeTravel\Desktop\OpenOffice.org Writer.lnk
[2011/11/13 06:30:09 | 001,161,257 | ---- | C] () -- C:\Users\LifeTravel\Desktop\understand-pure-o.pdf.pdf
[2011/11/10 15:50:43 | 000,097,925 | ---- | C] () -- C:\Users\LifeTravel\Desktop\solidus.png
[2011/11/09 01:02:08 | 000,491,158 | ---- | C] () -- C:\Users\LifeTravel\Desktop\LOL.png
[2011/11/05 20:36:19 | 000,000,871 | ---- | C] () -- C:\Users\LifeTravel\.recently-used.xbel
[2011/10/14 12:11:54 | 000,010,240 | ---- | C] () -- C:\Windows\SysWow64\vidx16.dll
[2011/09/29 20:57:14 | 000,280,904 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/09/29 20:57:12 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/09/14 10:47:40 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/09/08 17:39:44 | 018,534,912 | ---- | C] () -- C:\Windows\SysWow64\atioglxx.dll
[2011/07/28 13:39:48 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2011/07/28 13:35:46 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/03/17 17:51:44 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2009/07/23 15:41:04 | 000,782,336 | ---- | C] () -- C:\Windows\SysWow64\dldtdrs.dll
[2009/07/14 05:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 02:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 02:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 00:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 23:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 21:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 21:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/05/14 12:57:38 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\dldtcaps.dll
[2008/01/22 01:05:12 | 000,077,906 | ---- | C] () -- C:\Windows\SysWow64\dldtcfg.dll
[2007/11/13 18:13:10 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\dldtcnv4.dll
========== LOP Check ==========
[2011/08/26 13:04:50 | 000,000,000 | ---D | M] -- C:\Users\LifeTravel\AppData\Roaming\DAEMON Tools Lite
[2011/11/22 08:09:52 | 000,000,000 | ---D | M] -- C:\Users\LifeTravel\AppData\Roaming\fltk.org
[2011/11/05 20:38:40 | 000,000,000 | ---D | M] -- C:\Users\LifeTravel\AppData\Roaming\gtk-2.0
[2011/09/23 12:06:20 | 000,000,000 | ---D | M] -- C:\Users\LifeTravel\AppData\Roaming\OpenOffice.org
[2011/11/25 00:31:06 | 000,000,000 | ---D | M] -- C:\Users\LifeTravel\AppData\Roaming\uTorrent
[2011/11/30 13:42:48 | 000,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/12/04 11:48:50 | 000,017,829 | ---- | M] () -- C:\ComboFix.txt
[2011/11/30 14:19:35 | 000,000,122 | ---- | M] () -- C:\delwpa.bat
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2011/12/04 12:13:18 | 3220,037,632 | -HS- | M] () -- C:\hiberfil.sys
[2007/11/07 08:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2006/12/01 22:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2011/12/04 12:13:20 | 4293,386,240 | -HS- | M] () -- C:\pagefile.sys
[2011/12/04 12:10:46 | 000,000,395 | ---- | M] () -- C:\rkill.log
[2007/11/07 08:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/14 05:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 20:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 04:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/28 14:12:17 | 000,000,221 | -HS- | M] () -- C:\Users\LifeTravel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/12/04 11:14:30 | 004,326,668 | R--- | M] (Swearware) -- C:\Users\LifeTravel\Desktop\ComboFix.exe
[2011/12/04 11:55:03 | 001,008,114 | ---- | M] () -- C:\Users\LifeTravel\Desktop\rkill.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 21:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2011/07/28 14:57:48 | 000,000,402 | -HS- | M] () -- C:\Users\LifeTravel\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[1998/09/02 08:46:12 | 000,075,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >