Вы находитесь на странице: 1из 13

OTL logfile created on: 15/08/2011 21:16:40 - Run 1

OTL by OldTimer - Version 3.2.26.4


Folder = C:\Users\Jacob\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/
yyyy
3.68 Gb Total Physical Memory | 2.86 Gb Available Physical Memory | 77.88% Memor
y free
7.35 Gb Paging File | 6.52 Gb Available in Paging File | 88.62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Fil
es (x86)
Drive C: | 283.99 Gb Total Space | 255.66 Gb Free Space | 90.02% Space Free | Pa
rtition Type: NTFS
Drive E: | 1.84 Gb Total Space | 0.11 Gb Free Space | 5.71% Space Free | Partiti
on Type: FAT
Computer Name: 5745PG | User Name: Jacob | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Sc
ans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitel
ist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2011/08/15 21:15:20 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\User
s\Jacob\Desktop\OTL.exe
PRC - [2011/07/06 19:52:38 | 001,047,656 | ---- | M] (Malwarebytes Corporation)
-- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV:[b]64bit:[/b] - [2010/04/22 18:39:54 | 000,171,040 | ---- | M] (Acer Incorpo
rated) [Auto | Stopped] -- C:\Program Files\Acer\Optical Drive Power Management\
ODDPWRSvc.exe -- (ODDPwrSvc)
SRV:[b]64bit:[/b] - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group)
[Auto | Stopped] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Up
dater Service)
SRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,244,840 | ---- | M] (McAfee, Inc.
) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.ex
e -- (mfefire)
SRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,199,032 | ---- | M] () [Unknown |
Stopped] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (M
cShield)
SRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,148,520 | ---- | M] (McAfee, Inc.
) [Unknown | Running] -- C:\Program Files\Common Files\mcafee\systemcore\mfevtps
.exe -- (mfevtp)
SRV:[b]64bit:[/b] - [2009/12/31 02:13:18 | 000,509,416 | ---- | M] (McAfee, Inc.
) [On_Demand | Stopped] -- C:\Program Files\mcafee\VirusScan\mcods.exe -- (McODS
)
SRV:[b]64bit:[/b] - [2009/12/15 05:08:40 | 000,355,440 | ---- | M] (McAfee, Inc.
) [Auto | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.ex
e -- (MSK80Service)
SRV:[b]64bit:[/b] - [2009/12/15 05:08:40 | 000,355,440 | ---- | M] (McAfee, Inc.

) [Auto | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.ex


e -- (McProxy)
SRV:[b]64bit:[/b] - [2009/12/15 05:08:40 | 000,355,440 | ---- | M] (McAfee, Inc.
) [Disabled | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHos
t.exe -- (McOobeSv)
SRV:[b]64bit:[/b] - [2009/12/15 05:08:40 | 000,355,440 | ---- | M] (McAfee, Inc.
) [Auto | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.ex
e -- (McNASvc)
SRV:[b]64bit:[/b] - [2009/12/15 05:08:40 | 000,355,440 | ---- | M] (McAfee, Inc.
) [Auto | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.ex
e -- (McNaiAnn)
SRV:[b]64bit:[/b] - [2009/12/15 05:08:40 | 000,355,440 | ---- | M] (McAfee, Inc.
) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.ex
e -- (mcmscsvc)
SRV:[b]64bit:[/b] - [2009/12/15 05:08:40 | 000,355,440 | ---- | M] (McAfee, Inc.
) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.ex
e -- (McMPFSvc)
SRV:[b]64bit:[/b] - [2009/12/15 05:08:40 | 000,355,440 | ---- | M] (McAfee, Inc.
) [Auto | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.ex
e -- (McAfee SiteAdvisor Service)
SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Co
rporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (W
inDefend)
SRV - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation)
[Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservic
e.exe -- (MBAMService)
SRV - [2010/05/10 08:44:57 | 000,332,272 | ---- | M] (Google Inc.) [On_Demand |
Stopped] -- C:\ProgramData\Partner\Partner.exe -- (Partner Service)
SRV - [2010/04/17 06:56:48 | 000,305,520 | ---- | M] (Egis Technology Inc.) [On_
Demand | Stopped] -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.e
xe -- (MWLService)
SRV - [2010/04/08 05:18:40 | 000,312,400 | ---- | M] (Dritek System Inc.) [Auto
| Stopped] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIServic
e)
SRV - [2010/03/09 00:58:24 | 000,250,368 | ---- | M] (NewTech Infosystems, Inc.)
[Auto | Stopped] -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Mana
ger\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2010/03/04 04:16:06 | 000,013,336 | ---- | M] (Intel Corporation) [Auto |
Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IASt
orDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2010/01/08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto |
Stopped] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGServic
e)
SRV - [2009/09/30 19:34:22 | 002,314,240 | ---- | M] (Intel Corporation) [Auto |
Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\
UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2009/09/30 19:33:08 | 000,262,144 | ---- | M] (Intel Corporation) [Auto |
Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\
LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Au
to | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (
clr_optimization_v2.0.50727_32)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV:[b]64bit:[/b] - [2011/07/06 19:52:42 | 000,025,912 | ---- | M] (Malwarebytes
Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\driver
s\mbam.sys -- (MBAMProtector)
DRV:[b]64bit:[/b] - [2010/05/03 04:30:38 | 004,170,304 | ---- | M] (Broadcom Cor

poration) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL66


4.SYS -- (BCM43XX)
DRV:[b]64bit:[/b] - [2010/04/21 08:47:50 | 000,076,912 | ---- | M] (Atheros Comm
unications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers
\L1C62x64.sys -- (L1C)
DRV:[b]64bit:[/b] - [2010/03/11 13:17:42 | 000,316,464 | ---- | M] (Synaptics In
corporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP
.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2010/03/04 03:51:40 | 000,540,696 | ---- | M] (Intel Corpor
ation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (
iaStor)
DRV:[b]64bit:[/b] - [2010/02/10 08:02:00 | 000,158,720 | ---- | M] (Intel Corpor
ation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys
-- (Impcd)
DRV:[b]64bit:[/b] - [2010/01/28 00:25:04 | 000,086,120 | ---- | M] (NVIDIA Corpo
ration) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvhda64v.
sys -- (NVHDA)
DRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,528,232 | ---- | M] (McAfee, Inc.
) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfeh
idk)
DRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,440,688 | ---- | M] (McAfee, Inc.
) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -(mfefirek)
DRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,279,752 | ---- | M] (McAfee, Inc.
) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfew
fpk)
DRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,189,880 | ---- | M] (McAfee, Inc.
) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mfeavfk.sys -(mfeavfk)
DRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,121,504 | ---- | M] (McAfee, Inc.
) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mfeapfk.sys -(mfeapfk)
DRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,093,840 | ---- | M] (McAfee, Inc.
) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -(mferkdet)
DRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,075,288 | ---- | M] (McAfee, Inc.
) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfenlfk.sys -- (mf
enlfk)
DRV:[b]64bit:[/b] - [2010/01/06 02:04:02 | 000,062,416 | ---- | M] (McAfee, Inc.
) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cfwids.sys -- (
cfwids)
DRV:[b]64bit:[/b] - [2009/09/17 12:54:54 | 000,056,344 | ---- | M] (Intel Corpor
ation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sy
s -- (HECIx64) Intel(R)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,106,576 | ---- | M] (Advanced Mic
ro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsa
ta.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,028,752 | ---- | M] (Advanced Mic
ro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sy
s -- (amdxata)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technolo
gies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs
.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporat
ion) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys
-- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Pack
ard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSA
MD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Tech

nology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.


sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Cor
poration) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.s
ys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Cor
poration) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.
sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Cor
poration) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60
a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Co
mputer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drive
rs\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2009/06/03 03:15:30 | 000,060,464 | ---- | M] (Egis Technol
ogy Inc.) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\mwlPSDVDis
k.sys -- (mwlPSDVDisk)
DRV:[b]64bit:[/b] - [2009/06/03 03:15:30 | 000,022,576 | ---- | M] (Egis Technol
ogy Inc.) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\mwlPS
DFilter.sys -- (mwlPSDFilter)
DRV:[b]64bit:[/b] - [2009/06/03 03:15:30 | 000,020,016 | ---- | M] (Egis Technol
ogy Inc.) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\mwlPSDNser
v.sys -- (mwlPSDNServ)
DRV:[b]64bit:[/b] - [2009/05/26 21:32:38 | 000,040,448 | ---- | M] (Alcor Micro,
Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.s
ys -- (AmUStor)
DRV:[b]64bit:[/b] - [2009/05/05 09:46:08 | 000,018,432 | ---- | M] (NewTech Info
systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NT
IDrvr.sys -- (NTIDrvr)
DRV:[b]64bit:[/b] - [2009/05/05 09:46:08 | 000,016,896 | ---- | M] (NewTech Info
systems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\driv
ers\UBHelper.sys -- (UBHelper)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [Fi
le_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -(WIMMount)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_U
RL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_5745pg&r=27360811e
406l0483z155t4631m249
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = h
ttp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_5745pg&r=27360811e406l04
83z155t4631m249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ho
mepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_5745pg&r=27360811e406l0483z155t4
631m249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysW
OW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage
.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_5745pg&r=27360811e406l0483z155t4631m24
9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ho
mepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_5745pg&r=27360811e406l0483z155t4
631m249

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage


.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_5745pg&r=27360811e406l0483z155t4631m24
9
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program
Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEna
ble" = 0
[color=#E56717]========== FireFox ==========[/color]
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,ve
rsion=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/05/10 08:36:42 | 000,0
00,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program
Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll ( Microsoft Corporation
)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\
Program Files (x86)\Virtual Earth 3D\ [2010/05/10 08:36:42 | 000,000,000 | ---D
| M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872
-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/08/15 14:22
:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Compo
nents: C:\Program Files (x86)\Mozilla Firefox\components [2011/08/15 18:54:43 |
000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Plugi
ns: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/08/15 18:57:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jacob
\AppData\Roaming\Mozilla\Extensions
[2011/08/15 18:54:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Fil
es (x86)\Mozilla Firefox\extensions
File not found (No name found) -[2011/07/08 08:31:28 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Progra
m Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/01/01 09:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozi
lla firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozi
lla firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozi
lla firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 09:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozi
lla firefox\searchplugins\eBay-en-GB.xml
[2010/01/01 09:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozi
lla firefox\searchplugins\yahoo-en-GB.xml
Hosts file not found
O2:[b]64bit:[/b] - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8A
FE6163AB} - c:\Program Files\mcafee\msk\mskapbho64.dll ()
O2:[b]64bit:[/b] - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20100510004128.dll (Mc
Afee, Inc.)
O2:[b]64bit:[/b] - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E
5C4} - C:\ProgramData\Partner\Partner64.dll (Google Inc.)
O2:[b]64bit:[/b] - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF105
77473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Go
ogle Inc.)
O2:[b]64bit:[/b] - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA

-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg


64.dll (Google Inc.)
O2:[b]64bit:[/b] - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0
E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, I
nc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:
\Program Files\mcafee\msk\mskapbho.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Fi
les (x86)\Common Files\mcafee\SystemCore\ScriptSn.20100510004128.dll (McAfee, In
c.)
O2 - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\Prog
ramData\Partner\Partner.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
- C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Go
ogle Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:
\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD
4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPl
g.dll (McAfee, Inc.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dl
l (Google Inc.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-51
6ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc
.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:[b]64bit:[/b] - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965
-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleTo
olbar_64.dll (Google Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSing
Lun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Int
el Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Int
el Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinL
ocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVI
DIA Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [ODDPwr] C:\Program Files\Acer\Optical Drive Powe
r Management\ODDPwr.exe (Acer Incorporated)
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (
Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVB
g64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAV
Cpl64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [Trigger New Acer AlaunchX] c:\OEM\Preload\Comman
d\AlaunchX\AppInRun.exe ()
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\
Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate
.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Egis Technology Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storag
e Technology\IAStorIcon.exe (Intel Corporation)

O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (


Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebyte
s' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files (x86)\Ma
lwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfe
e, Inc.)
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Acer\Acer Touch Suite\MediaSh
ow Espresso\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\No
rton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86
\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTor
rent, Inc.)
O4:[b]64bit:[/b] - HKLM..\RunOnce: [New Acer AlaunchX] c:\OEM\Preload\Command\Al
aunchX\LaunchAlaunchX.exe (Acer Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveD
esktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveD
esktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentProm
ptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentProm
ptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/
download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windo
ws Genuine Advantage Validation Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:[b]64bit:[/b] - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E
91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.
)
O18:[b]64bit:[/b] - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC
5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Pr
ogram Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Progra
m Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.
exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe)
- C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (
Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C
:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C
LSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File n
ot found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*


O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhof
er Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut I
ntegrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Error creating restore point.
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/col
or]
[2011/08/15 22:50:38 | 000,000,000 | ---D | C] -- C:\Windows\NAPP_Dism_Log
[2011/08/15 21:15:14 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\Jaco
b\Desktop\OTL.exe
[2011/08/15 21:02:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windo
ws\Start Menu\Programs\McAfee
[2011/08/15 20:38:16 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Users\Jaco
b\Desktop\TFC.exe
[2011/08/15 20:00:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows Genuine
Advantage
[2011/08/15 19:38:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorren
t
[2011/08/15 19:28:18 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Roaming
\uTorrent
[2011/08/15 19:28:18 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Local\u
Torrent
[2011/08/15 18:54:56 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Roaming
\Mozilla
[2011/08/15 18:54:56 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Local\M
ozilla
[2011/08/15 18:54:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla
Firefox
[2011/08/15 16:15:32 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Roaming
\Malwarebytes
[2011/08/15 16:15:15 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\
Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/08/15 16:15:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windo
ws\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/08/15 16:15:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/08/15 16:15:11 | 000,025,912 | ---- | C] (Malwarebytes Corporation) -- C:\
Windows\SysNative\drivers\mbam.sys
[2011/08/15 16:15:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malware
bytes' Anti-Malware
[2011/08/15 15:41:32 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011/08/15 14:32:05 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/08/15 14:31:34 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Local\C
yberlink
[2011/08/15 14:31:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cyberli
nk
[2011/08/15 14:29:58 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2011/08/15 14:29:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[2011/08/15 14:26:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common

Files\postureAgent
[2011/08/15 14:26:40 | 000,056,344 | ---- | C] (Intel Corporation) -- C:\Windows
\SysNative\drivers\HECIx64.sys
[2011/08/15 14:26:38 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Roaming
\InstallShield
[2011/08/15 14:25:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windo
ws\Start Menu\Programs\Acer Crystal Eye webcam
[2011/08/15 14:24:11 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2011/08/15 14:23:31 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Roaming
\Macromedia
[2011/08/15 14:23:03 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Roaming
\Adobe
[2011/08/15 14:21:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Launch
Manager
[2011/08/15 14:21:13 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Roaming
\Google
[2011/08/15 14:21:08 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Local\G
oogle
[2011/08/15 14:20:49 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Roaming
\Intel Corporation
[2011/08/15 14:20:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windo
ws\Start Menu\Programs\AcerSystem
[2011/08/15 14:20:34 | 000,000,000 | ---D | C] -- C:\book
[2011/08/15 14:20:26 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Local\E
gisTec IPS
[2011/08/15 14:20:23 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2011/08/15 14:19:56 | 000,000,000 | R--D | C] -- C:\Users\Jacob\AppData\Roaming
\Microsoft\Windows\Start Menu\Programs\Startup
[2011/08/15 14:19:56 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Searches
[2011/08/15 14:19:56 | 000,000,000 | R--D | C] -- C:\Users\Jacob\AppData\Roaming
\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/08/15 14:19:56 | 000,000,000 | -H-D | C] -- C:\Users\Jacob\Application Dat
a\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/08/15 14:19:48 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Roaming
\Identities
[2011/08/15 14:19:45 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Contacts
[2011/08/15 14:19:44 | 000,000,000 | ---D | C] -- C:\Users\Jacob\AppData\Local\V
irtualStore
[2011/08/15 14:17:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OEM
[2011/08/15 14:17:40 | 000,000,000 | ---D | C] -- C:\Program Files\Acer Accessor
y Store
[2011/08/15 14:13:58 | 000,000,000 | --SD | C] -- C:\Users\Jacob\AppData\Roaming
\Microsoft
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Videos
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Saved Games
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Pictures
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Music
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\AppData\Roaming
\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Links
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Favorites
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Downloads
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Documents
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\Desktop
[2011/08/15 14:13:58 | 000,000,000 | R--D | C] -- C:\Users\Jacob\AppData\Roaming
\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/08/15 14:13:58 | 000,000,000 | -HSD | C] -- C:\Users\Jacob\AppData\Local\T
emporary Internet Files
[2011/08/15 14:13:58 | 000,000,000 | -HSD | C] -- C:\Users\Jacob\Templates
[2011/08/15 14:13:58 | 000,000,000 | -HSD | C] -- C:\Users\Jacob\Start Menu

[2011/08/15 14:13:58 | 000,000,000


[2011/08/15 14:13:58 | 000,000,000
[2011/08/15 14:13:58 | 000,000,000
[2011/08/15 14:13:58 | 000,000,000
[2011/08/15 14:13:58 | 000,000,000
deos
[2011/08/15 14:13:58 | 000,000,000
ctures
[2011/08/15 14:13:58 | 000,000,000
sic
[2011/08/15 14:13:58 | 000,000,000
[2011/08/15 14:13:58 | 000,000,000
[2011/08/15 14:13:58 | 000,000,000
istory
[2011/08/15 14:13:58 | 000,000,000
[2011/08/15 14:13:58 | 000,000,000
a
[2011/08/15 14:13:58 | 000,000,000
pplication Data
[2011/08/15 14:13:58 | 000,000,000
[2011/08/15 14:13:58 | 000,000,000
emp
[2011/08/15 14:13:58 | 000,000,000
icrosoft
[2011/08/15 14:13:58 | 000,000,000
\Media Center Programs
[2011/08/15 14:12:50 | 000,000,000
[2011/08/15 14:04:37 | 000,659,048
s\SysNative\nvuninst.exe
[2011/08/15 14:04:17 | 000,000,000
n
[2011/08/15 14:03:26 | 000,000,000
ation
[2011/08/15 13:59:40 | 000,000,000

|
|
|
|
|

-HSD
-HSD
-HSD
-HSD
-HSD

|
|
|
|
|

C]
C]
C]
C]
C]

------

C:\Users\Jacob\SendTo
C:\Users\Jacob\Recent
C:\Users\Jacob\PrintHood
C:\Users\Jacob\NetHood
C:\Users\Jacob\Documents\My Vi

| -HSD | C] -- C:\Users\Jacob\Documents\My Pi
| -HSD | C] -- C:\Users\Jacob\Documents\My Mu
| -HSD | C] -- C:\Users\Jacob\My Documents
| -HSD | C] -- C:\Users\Jacob\Local Settings
| -HSD | C] -- C:\Users\Jacob\AppData\Local\H
| -HSD | C] -- C:\Users\Jacob\Cookies
| -HSD | C] -- C:\Users\Jacob\Application Dat
| -HSD | C] -- C:\Users\Jacob\AppData\Local\A
| -H-D | C] -- C:\Users\Jacob\AppData
| ---D | C] -- C:\Users\Jacob\AppData\Local\T
| ---D | C] -- C:\Users\Jacob\AppData\Local\M
| ---D | C] -- C:\Users\Jacob\AppData\Roaming
| -HSD | C] -- C:\Recovery
| ---- | C] (NVIDIA Corporation) -- C:\Window
| ---D | C] -- C:\Windows\SoftwareDistributio
| ---D | C] -- C:\Program Files\NVIDIA Corpor
| -HSD | C] -- C:\System Volume Information

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]


[2011/08/15 22:50:37 | 000,011,453 | ---- | M] () -- C:\Windows\ChangeLang_Done.
tag
[2011/08/15 21:15:20 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Jaco
b\Desktop\OTL.exe
[2011/08/15 21:02:39 | 000,001,832 | ---- | M] () -- C:\Users\Public\Desktop\McA
fee Internet Security Suite.lnk
[2011/08/15 21:00:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/08/15 20:59:12 | 2962,239,488 | -HS- | M] () -- C:\hiberfil.sys
[2011/08/15 20:38:23 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Users\Jaco
b\Desktop\TFC.exe
[2011/08/15 19:38:19 | 000,000,975 | ---- | M] () -- C:\Users\Jacob\Application
Data\Microsoft\Internet Explorer\Quick Launch\Torrent.lnk
[2011/08/15 19:38:19 | 000,000,951 | ---- | M] () -- C:\Users\Public\Desktop\Torr
ent.lnk
[2011/08/15 19:37:22 | 000,001,024 | RH-- | M] () -- C:\Users\Public\Documents\N
TILiveUpdate.dll
[2011/08/15 18:55:28 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2011/08/15 18:54:44 | 000,001,146 | ---- | M] () -- C:\Users\Public\Desktop\Moz
illa Firefox.lnk
[2011/08/15 17:51:45 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfSt
ringBackup.INI
[2011/08/15 17:51:45 | 000,619,206 | ---- | M] () -- C:\Windows\SysNative\perfh0
09.dat

[2011/08/15 17:51:45 | 000,107,388 | ---- | M] () -- C:\Windows\SysNative\perfc0


09.dat
[2011/08/15 17:41:46 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\driver
s\Msft_User_WpdFs_01_09_00.Wdf
[2011/08/15 16:15:15 | 000,001,117 | ---- | M] () -- C:\Users\Public\Desktop\Mal
warebytes' Anti-Malware.lnk
[2011/08/15 15:40:38 | 238,941,386 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/08/15 15:31:37 | 000,000,641 | ---- | M] () -- C:\Users\Public\Desktop\sp.
lnk
[2011/08/15 15:06:49 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296F
B0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/15 15:06:49 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296F
B0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/15 15:01:51 | 000,002,143 | ---- | M] () -- C:\Users\Public\Desktop\Ace
r TouchPortal.lnk
[2011/08/15 14:24:40 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
[2011/08/15 14:24:40 | 000,000,302 | ---- | M] () -- C:\Windows\PidList_C.ini
[2011/08/15 14:24:17 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\driver
s\Msft_Kernel_SynTP_01009.Wdf
[2011/08/15 14:21:41 | 000,000,000 | ---- | M] () -- C:\Windows\Setup.INI
[2011/08/15 14:21:40 | 000,000,184 | ---- | M] () -- C:\Windows\LMv4.UNI
[2011/08/15 14:20:35 | 000,001,445 | ---- | M] () -- C:\Users\Jacob\Application
Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.l
nk
[2011/08/15 14:17:58 | 000,002,609 | ---- | M] () -- C:\Users\Public\Desktop\eBa
y.lnk
[2011/08/15 14:17:43 | 000,001,976 | ---- | M] () -- C:\Users\Public\Desktop\Ace
r Accessory Store.lnk
[2011/08/15 14:12:30 | 000,039,252 | ---- | M] () -- C:\Windows\SysWow64\license
.rtf
[2011/08/15 14:12:30 | 000,039,252 | ---- | M] () -- C:\Windows\SysNative\licens
e.rtf
[2011/08/15 14:11:04 | 000,274,320 | ---- | M] () -- C:\Windows\SysNative\FNTCAC
HE.DAT
[2011/08/15 14:08:04 | 000,000,003 | ---- | M] () -- C:\Windows\SysNative\PLD_Fr
amework.cmd
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2011/08/15 22:51:59 | 000,011,453 | ---- | C] () -- C:\Windows\ChangeLang_Done.
tag
[2011/08/15 19:38:19 | 000,000,975 | ---- | C] () -- C:\Users\Jacob\Application
Data\Microsoft\Internet Explorer\Quick Launch\Torrent.lnk
[2011/08/15 19:38:19 | 000,000,951 | ---- | C] () -- C:\Users\Public\Desktop\Torr
ent.lnk
[2011/08/15 18:55:28 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/08/15 18:54:44 | 000,001,158 | ---- | C] () -- C:\ProgramData\Microsoft\Wi
ndows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/08/15 18:54:44 | 000,001,146 | ---- | C] () -- C:\Users\Public\Desktop\Moz
illa Firefox.lnk
[2011/08/15 17:41:46 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\driver
s\Msft_User_WpdFs_01_09_00.Wdf
[2011/08/15 16:15:15 | 000,001,117 | ---- | C] () -- C:\Users\Public\Desktop\Mal
warebytes' Anti-Malware.lnk
[2011/08/15 15:40:38 | 238,941,386 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/08/15 15:31:37 | 000,000,641 | ---- | C] () -- C:\Users\Public\Desktop\sp.
lnk
[2011/08/15 14:29:15 | 000,002,143 | ---- | C] () -- C:\Users\Public\Desktop\Ace
r TouchPortal.lnk
[2011/08/15 14:25:09 | 000,206,208 | ---- | C] () -- C:\Windows\PLFSetI.exe

[2011/08/15 14:25:09 | 000,113,264 | ---- | C] () -- C:\Windows\FixUVC.exe


[2011/08/15 14:25:09 | 000,000,302 | ---- | C] () -- C:\Windows\PidList_C.ini
[2011/08/15 14:24:17 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\driver
s\Msft_Kernel_SynTP_01009.Wdf
[2011/08/15 14:21:41 | 000,000,000 | ---- | C] () -- C:\Windows\Setup.INI
[2011/08/15 14:21:40 | 000,000,184 | ---- | C] () -- C:\Windows\LMv4.UNI
[2011/08/15 14:20:35 | 000,001,445 | ---- | C] () -- C:\Users\Jacob\Application
Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.l
nk
[2011/08/15 14:20:02 | 000,001,417 | ---- | C] () -- C:\Users\Jacob\AppData\Roam
ing\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/08/15 14:19:58 | 000,001,451 | ---- | C] () -- C:\Users\Jacob\AppData\Roam
ing\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/08/15 14:17:58 | 000,002,609 | ---- | C] () -- C:\Users\Public\Desktop\eBa
y.lnk
[2011/08/15 14:17:43 | 000,001,976 | ---- | C] () -- C:\Users\Public\Desktop\Ace
r Accessory Store.lnk
[2011/08/15 14:13:58 | 000,000,290 | ---- | C] () -- C:\Users\Jacob\Application
Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/08/15 14:13:58 | 000,000,272 | ---- | C] () -- C:\Users\Jacob\Application
Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/08/15 14:08:04 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\PLD_Fr
amework.cmd
[2011/08/15 13:59:41 | 2962,239,488 | -HS- | C] () -- C:\hiberfil.sys
[2010/05/10 08:59:36 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng5
75.bin
[2010/05/10 08:59:36 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip
32.dll
[2010/05/10 08:59:36 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp3
2.dll
[2010/05/10 08:59:35 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg57
5m.bin
[2010/05/10 08:59:33 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompk
rng575.bin
[2010/05/10 08:28:27 | 000,131,472 | ---- | C] () -- C:\ProgramData\FullRemove.e
xe
[2010/04/16 18:58:04 | 001,060,864 | ---- | C] () -- C:\Windows\SysWow64\MFC71.d
ll
[2010/04/16 18:58:04 | 001,047,552 | ---- | C] () -- C:\Windows\SysWow64\MFC71u.
dll
[2010/04/16 18:58:04 | 000,499,712 | ---- | C] () -- C:\Windows\SysWow64\msvcp71
.dll
[2010/04/16 18:58:04 | 000,348,160 | ---- | C] () -- C:\Windows\SysWow64\msvcr71
.dll
[2010/04/16 18:58:04 | 000,089,088 | ---- | C] () -- C:\Windows\SysWow64\atl71.d
ll
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.D
AT
[2009/07/14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.d
at
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWConte
xtHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetol
edb40.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.d
at
[color=#E56717]========== LOP Check ==========[/color]

[2011/08/15 20:28:01 | 000,000,000 | ---D | M] -- C:\Users\Jacob\AppData\Roaming


\uTorrent
[2009/07/14 06:08:49 | 000,003,614 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.T
XT
[color=#E56717]========== Purity Check ==========[/color]

[color=#E56717]========== Custom Scans ==========[/color]


[color=#A23BEC]<
[2010/05/10 09:01:06
[2011/08/15 20:59:12
[2010/02/23 06:55:06
[2010/02/12 05:21:49
[2011/08/15 20:59:18
[2010/05/10 08:17:21

|
|
|
|
|
|

%SYSTEMDRIVE%\*.* >[/color]
000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
2962,239,488 | -HS- | M] () -- C:\hiberfil.sys
000,002,296 | ---- | M] () -- C:\MOD01SET0J000N000S.enc
000,002,168 | ---- | M] () -- C:\MOD01SET7B000G001X.enc
3949,654,016 | -HS- | M] () -- C:\pagefile.sys
000,002,282 | ---- | M] () -- C:\RHDSetup.log

[color=#A23BEC]<

%systemroot%\*. /mp /s >[/color]

[color=#A23BEC]<

%systemroot%\System32\config\*.sav >[/color]

[color=#A23BEC]<
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Wi
ndowsUpdate\AU >[/color]
[color=#A23BEC]<
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
ion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >[/color]
[color=#A23BEC]< >[/color]
< End of report >

Вам также может понравиться