Gringo
OTL downloaded and options set as you specified before running from the
desktop.
A copy of OTL.txt follows below:
Regards
Peter
OTL logfile created on: 28/11/2011 23:01:58 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\BCWork\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
511.46 Mb Total Physical Memory | 255.91 Mb Available Physical Memory | 50.03% Memory free
1.22 Gb Paging File | 0.73 Gb Available in Paging File | 59.43% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 21.83 Gb Free Space | 58.60% Space Free | Partition Type: NTFS
Drive D: | 58.59 Gb Total Space | 27.97 Gb Free Space | 47.73% Space Free | Partition Type: NTFS
Drive E: | 55.90 Gb Total Space | 45.16 Gb Free Space | 80.79% Space Free | Partition Type: NTFS
Computer Name: PAVILION | User Name: BCWork | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\BCWork\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Documents and Settings\Peter\Local Settings\Application Data\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\Office\WINWORD.EXE ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\js3250.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\Microsoft Office\Office\MSO97.DLL ()
MOD - C:\Program Files\Common Files\Microsoft Shared\VBA\VBE.DLL ()
MOD - C:\Program Files\Microsoft Office\Office\DISTMON.DLL ()
MOD - C:\Program Files\Microsoft Office\Office\WINWORD.EXE ()
MOD - C:\Program Files\Microsoft Office\Office\WWINTL32.DLL ()
MOD - C:\Program Files\Common Files\Microsoft Shared\Proof\MSSP232.DLL ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) -- File not found
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE (SEIKO EPSON CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (MREMP50) -- C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) -- C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (Nbf) -- C:\WINDOWS\system32\drivers\NBF.SYS (Microsoft Corporation)
DRV - (RTL8023xp) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (TotRec8) -- C:\WINDOWS\system32\drivers\TotRec8.sys (High Criteria inc.)
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (pccsmcfd) -- C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (rtl8139) Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (es1371) Creative AudioPCI (ES1371,ES1373) (WDM) -- C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/cs/*http://uk.docs.yahoo.com/info/bt_side.html
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-823518204-1202660629-1900996195-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-823518204-1202660629-1900996195-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-823518204-1202660629-1900996195-1071\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-823518204-1202660629-1900996195-1071\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 20 75 59 C8 4D A9 CC 01 [binary data]
IE - HKU\S-1-5-21-823518204-1202660629-1900996195-1071\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: bkmrksync@nokia.com:1.0.0.736
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@yverinfo.yahoo.com/YahooVersionInfoPlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYVerInfo.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2011/03/19 08:04:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/22 16:34:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/21 00:45:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/12/29 19:56:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2011/11/22 16:34:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\BCWork\Application Data\Mozilla\Extensions
[2011/11/28 15:44:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\BCWork\Application Data\Mozilla\Firefox\Profiles\1yqjv1s9.default\extensions
[2011/11/28 12:25:21 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\BCWork\Application Data\Mozilla\Firefox\Profiles\1yqjv1s9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/27 11:28:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/03/19 08:04:31 | 000,000,000 | ---D | M] (PC Sync 2 Synchronisation Extension) -- C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC
[2011/10/27 16:17:24 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/10/27 16:17:25 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/10/27 16:17:26 | 000,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/10/27 16:17:26 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2011/11/28 17:58:48 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKU\S-1-5-21-823518204-1202660629-1900996195-1003\..\Toolbar\WebBrowser: (no name) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKU\S-1-5-21-823518204-1202660629-1900996195-1003..\Run: [{6FA87BC6-C067-83E6-FD5E-C4C61205DD86}] C:\Documents and Settings\Peter\Application Data\Enab\argyka.exe ()
O4 - HKU\S-1-5-21-823518204-1202660629-1900996195-1003..\Run: [advEventmm] C:\Documents and Settings\Peter\Local Settings\Application Data\DRMmappnp\advEventmm.dll ()
O4 - HKU\S-1-5-21-823518204-1202660629-1900996195-1003..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background File not found
O4 - HKU\S-1-5-21-823518204-1202660629-1900996195-1003..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-823518204-1202660629-1900996195-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-823518204-1202660629-1900996195-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-823518204-1202660629-1900996195-1071\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-823518204-1202660629-1900996195-1071\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-823518204-1202660629-1900996195-1071\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-823518204-1202660629-1900996195-1071\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8E0E0E42-A93E-4E1E-9BF5-68F530998DC9}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/11 00:10:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/28 22:59:05 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\BCWork\Desktop\OTL.exe
[2011/11/28 22:11:25 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Documents and Settings\BCWork\Desktop\aswMBR.exe
[2011/11/28 21:23:21 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/11/28 21:22:49 | 001,566,512 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\BCWork\Desktop\tdsskiller.exe
[2011/11/28 18:04:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/11/28 17:40:37 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/11/28 17:37:20 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/11/28 17:37:20 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/11/28 17:37:20 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/11/28 17:37:20 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/11/28 17:37:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/11/28 17:36:53 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/11/28 17:32:14 | 004,310,219 | R--- | C] (Swearware) -- C:\Documents and Settings\BCWork\Desktop\ComboFix.exe
[2011/11/28 15:04:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\Application Data\Avira
[2011/11/28 12:32:24 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\BCWork\Desktop\dds.scr
[2011/11/22 19:35:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\Application Data\Macromedia
[2011/11/22 19:34:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\Application Data\Adobe
[2011/11/22 19:34:44 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\BCWork\PrivacIE
[2011/11/22 16:49:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\Desktop\gmer
[2011/11/22 16:38:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\BCWork\My Documents\My Videos
[2011/11/22 16:38:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\BCWork\Start Menu\Programs\Administrative Tools
[2011/11/22 16:34:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\My Documents\Downloads
[2011/11/22 16:34:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\Local Settings\Application Data\Mozilla
[2011/11/22 16:34:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\Application Data\Mozilla
[2011/11/22 16:30:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\Application Data\Identities
[2011/11/22 16:29:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\BCWork\My Documents\My Music
[2011/11/22 16:29:53 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\BCWork\IETldCache
[2011/11/22 16:29:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\Application Data\PC Suite
[2011/11/22 16:29:42 | 000,000,000 | --SD | C] -- C:\Documents and Settings\BCWork\Application Data\Microsoft
[2011/11/22 16:29:42 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\BCWork\SendTo
[2011/11/22 16:29:42 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\BCWork\Recent
[2011/11/22 16:29:42 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\BCWork\Application Data
[2011/11/22 16:29:42 | 000,000,000 | R--D | C] -- C:\Documents and Settings\BCWork\Start Menu\Programs\Startup
[2011/11/22 16:29:42 | 000,000,000 | R--D | C] -- C:\Documents and Settings\BCWork\Start Menu
[2011/11/22 16:29:42 | 000,000,000 | R--D | C] -- C:\Documents and Settings\BCWork\My Documents\My Pictures
[2011/11/22 16:29:42 | 000,000,000 | R--D | C] -- C:\Documents and Settings\BCWork\My Documents
[2011/11/22 16:29:42 | 000,000,000 | R--D | C] -- C:\Documents and Settings\BCWork\Favorites
[2011/11/22 16:29:42 | 000,000,000 | R--D | C] -- C:\Documents and Settings\BCWork\Start Menu\Programs\Accessories
[2011/11/22 16:29:42 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\BCWork\Cookies
[2011/11/22 16:29:42 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\BCWork\Templates
[2011/11/22 16:29:42 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\BCWork\PrintHood
[2011/11/22 16:29:42 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\BCWork\NetHood
[2011/11/22 16:29:42 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\BCWork\Local Settings
[2011/11/22 16:29:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\Local Settings\Application Data\Microsoft
[2011/11/22 16:29:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\BCWork\Desktop
[2011/11/22 16:19:03 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\BCWork\Desktop\dds.1st.scr
[2011/11/21 23:30:42 | 000,064,512 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2011/11/21 23:30:05 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2011/11/19 22:05:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2011/11/19 21:57:52 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2011/11/19 21:52:22 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011/11/17 18:09:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/11/17 18:09:10 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/11/17 18:08:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2011/11/17 18:07:23 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2011/11/15 13:07:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/11/02 09:34:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/28 22:59:05 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\BCWork\Desktop\OTL.exe
[2011/11/28 22:42:50 | 000,008,536 | ---- | M] () -- C:\WINDOWS\BCWork8.xlb
[2011/11/28 22:39:19 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\BCWork\Desktop\MBR.dat
[2011/11/28 22:11:34 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Documents and Settings\BCWork\Desktop\aswMBR.exe
[2011/11/28 21:22:52 | 001,566,512 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\BCWork\Desktop\tdsskiller.exe
[2011/11/28 17:58:48 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/11/28 17:40:50 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/11/28 17:32:15 | 004,310,219 | R--- | M] (Swearware) -- C:\Documents and Settings\BCWork\Desktop\ComboFix.exe
[2011/11/28 15:41:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/28 15:41:00 | 536,379,392 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/28 12:58:59 | 000,139,264 | ---- | M] () -- C:\Documents and Settings\BCWork\Desktop\RKUnhookerLE.EXE
[2011/11/28 12:32:24 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\BCWork\Desktop\dds.scr
[2011/11/28 12:29:08 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\BCWork\defogger_reenable
[2011/11/28 12:27:52 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\BCWork\Desktop\Defogger.exe
[2011/11/28 12:23:54 | 000,035,262 | ---- | M] () -- C:\WINDOWS\BCWork.acl
[2011/11/28 09:46:11 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/23 00:40:44 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/11/22 16:48:26 | 000,294,216 | ---- | M] () -- C:\Documents and Settings\BCWork\Desktop\gmer.zip
[2011/11/22 16:30:36 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\BCWork\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/11/22 16:30:31 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\BCWork\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/11/22 16:19:04 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\BCWork\Desktop\dds.1st.scr
[2011/11/22 09:27:27 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/11/21 23:38:17 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/11/21 23:06:31 | 000,008,536 | ---- | M] () -- C:\WINDOWS\Admin8.xlb
[2011/11/21 00:56:20 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/19 22:02:49 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/11/07 01:18:28 | 002,207,744 | ---- | M] () -- C:\WINDOWS\System32\HomePlanet.scr
[2011/11/03 12:06:56 | 000,064,512 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2011/10/30 10:44:28 | 000,472,562 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/10/30 10:44:28 | 000,075,530 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/28 22:42:50 | 000,008,536 | ---- | C] () -- C:\WINDOWS\BCWork8.xlb
[2011/11/28 22:39:19 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\BCWork\Desktop\MBR.dat
[2011/11/28 17:40:50 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/11/28 17:40:45 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/11/28 17:37:20 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/11/28 17:37:20 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/11/28 17:37:20 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/11/28 17:37:20 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/11/28 17:37:20 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/11/28 12:58:59 | 000,139,264 | ---- | C] () -- C:\Documents and Settings\BCWork\Desktop\RKUnhookerLE.EXE
[2011/11/28 12:29:08 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\BCWork\defogger_reenable
[2011/11/28 12:27:50 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\BCWork\Desktop\Defogger.exe
[2011/11/28 12:23:54 | 000,035,262 | ---- | C] () -- C:\WINDOWS\BCWork.acl
[2011/11/22 16:48:24 | 000,294,216 | ---- | C] () -- C:\Documents and Settings\BCWork\Desktop\gmer.zip
[2011/11/22 16:30:36 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\BCWork\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/11/22 16:30:36 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\BCWork\Start Menu\Programs\Internet Explorer.lnk
[2011/11/22 16:30:31 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\BCWork\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/11/22 16:30:14 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\BCWork\Start Menu\Programs\Outlook Express.lnk
[2011/11/22 16:29:42 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\BCWork\Start Menu\Programs\Remote Assistance.lnk
[2011/11/22 16:29:42 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\BCWork\Start Menu\Programs\Windows Media Player.lnk
[2011/11/21 23:31:00 | 000,000,486 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/11/21 00:56:20 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/19 22:02:35 | 000,001,393 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/11/07 01:22:04 | 002,207,744 | ---- | C] () -- C:\WINDOWS\System32\HomePlanet.scr
[2011/10/14 11:39:30 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2011/10/14 11:36:40 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2011/03/05 19:37:35 | 000,000,707 | ---- | C] () -- C:\WINDOWS\System32\updater.ini
[2011/03/05 19:37:31 | 000,000,142 | ---- | C] () -- C:\WINDOWS\System32\platform.ini
[2011/03/05 19:37:27 | 001,016,280 | ---- | C] () -- C:\WINDOWS\System32\js3250.dll
[2011/03/05 19:37:25 | 000,003,803 | ---- | C] () -- C:\WINDOWS\System32\crashreporter.ini
[2011/03/05 19:37:25 | 000,000,583 | ---- | C] () -- C:\WINDOWS\System32\crashreporter-override.ini
[2011/03/05 19:37:20 | 000,002,129 | ---- | C] () -- C:\WINDOWS\System32\application.ini
[2010/12/27 11:29:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/08/13 23:17:08 | 000,000,419 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2010/08/13 23:17:08 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2010/08/13 23:16:05 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\bridf08a.dat
[2010/08/13 23:15:51 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll
[2010/05/14 23:14:05 | 000,061,440 | ---- | C] () -- C:\WINDOWS\SSEUninstaller.exe
[2010/05/14 22:56:30 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\QTUninst.dll
[2010/05/14 22:09:02 | 000,000,120 | ---- | C] () -- C:\WINDOWS\MSMAIL32.INI
[2010/05/13 07:11:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2010/05/13 07:09:50 | 000,000,252 | ---- | C] () -- C:\WINDOWS\ADAM.INI
[2010/05/13 07:09:50 | 000,000,198 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2010/05/13 07:09:50 | 000,000,116 | ---- | C] () -- C:\WINDOWS\cap_pi.ini
[2010/05/13 07:09:24 | 000,001,392 | ---- | C] () -- C:\WINDOWS\ACROCAT.INI
[2010/05/13 07:09:07 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2010/05/13 07:09:05 | 000,000,192 | ---- | C] () -- C:\WINDOWS\ACROEXCH.INI
[2010/05/13 00:14:42 | 000,000,022 | ---- | C] () -- C:\WINDOWS\exchng.ini
[2010/05/12 23:59:16 | 000,000,864 | ---- | C] () -- C:\WINDOWS\ACROREAD.INI
[2010/05/12 09:05:51 | 000,000,061 | ---- | C] () -- C:\WINDOWS\fpstart.ini
[2010/05/12 08:34:09 | 000,004,793 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/05/12 08:34:09 | 000,000,482 | ---- | C] () -- C:\WINDOWS\lotus.ini
[2010/05/12 08:34:07 | 000,004,758 | ---- | C] () -- C:\WINDOWS\ORG2.INI
[2010/05/11 10:03:45 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2010/05/11 07:59:17 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2010/05/11 07:59:17 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2010/05/11 07:59:17 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2010/05/11 07:59:17 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2010/05/11 07:59:17 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2010/05/11 07:59:17 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2010/05/11 07:59:17 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2010/05/11 07:59:17 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2010/05/11 07:59:17 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2010/05/11 07:59:17 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2010/05/11 07:59:17 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010/05/11 07:59:17 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010/05/11 07:59:17 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010/05/11 07:59:17 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010/05/11 07:59:17 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010/05/11 07:59:17 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2010/05/11 07:59:17 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2010/05/11 07:59:17 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2010/05/11 07:59:17 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2010/05/11 07:55:13 | 000,000,027 | ---- | C] () -- C:\WINDOWS\CDE SPR265DEFGIPS.ini
[2010/05/11 00:44:22 | 000,004,822 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/05/11 00:42:44 | 000,153,176 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/11 00:15:22 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/05/11 00:04:51 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/04 00:07:22 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/02 13:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001/08/23 03:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 03:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 03:00:00 | 000,472,562 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 03:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 03:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 03:00:00 | 000,075,530 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 03:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 03:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 03:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 03:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[1998/04/27 00:23:00 | 006,150,961 | ---- | C] () -- C:\WINDOWS\System32\jre116.exe
[1998/04/06 23:00:00 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\ODBCMON.DLL
[1996/11/20 23:00:00 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\WRKGADM.EXE
[1996/11/20 23:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
[1996/11/20 23:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1996/11/20 23:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1994/07/25 00:23:00 | 000,014,928 | ---- | C] () -- C:\WINDOWS\System32\wingen.drv
[1994/04/07 00:23:00 | 000,000,462 | ---- | C] () -- C:\WINDOWS\lodbf13.ini
[1994/04/07 00:23:00 | 000,000,462 | ---- | C] () -- C:\WINDOWS\lodbf09.ini
< End of report >