OTL.txt
OTL logfile created on: 8/27/2014 9:43:48 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Liquid\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.43 Mb Total Physical Memory | 339.32 Mb Available Physical Memory | 66.35% Memory free
1.40 Gb Paging File | 1.15 Gb Available in Paging File | 82.02% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.62 Gb Total Space | 2.07 Gb Free Space | 11.14% Space Free | Partition Type: NTFS
Computer Name: LIQUID-EDE81A | User Name: Liquid | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\AVAST Software\Avast\avastui.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Documents and Settings\Liquid\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2014\avgmfapx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\AVAST Software\Avast\defs\14082700\algo.dll ()
MOD - C:\Program Files\AVAST Software\Avast\libcef.dll ()
MOD - C:\Program Files\AVAST Software\Avast\aswProperty.dll ()
========== Services (SafeList) ==========
SRV - (UpdaterSvcfocusbase) -- C:\Program Files\focusbase\updater.exe File not found
SRV - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
========== Driver Services (SafeList) ==========
DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (cpuz134) -- C:\DOCUME~1\Liquid\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys File not found
DRV - (Changer) -- File not found
DRV - (cerc6) -- File not found
DRV - (Avgtdix) -- system32\DRIVERS\avgtdix.sys File not found
DRV - (Avgrkx86) -- system32\DRIVERS\avgrkx86.sys File not found
DRV - (AVGIDSShim) -- system32\DRIVERS\avgidsshimx.sys File not found
DRV - (AVGIDSHX) -- system32\DRIVERS\avgidshx.sys File not found
DRV - (AVGIDSDriverl) -- system32\DRIVERS\avgidsdriverlx.sys File not found
DRV - (ddwrd) -- C:\WINDOWS\system32\drivers\xpdvio.sys (Malwarebytes Corporation)
DRV - (aswSP) -- C:\WINDOWS\system32\drivers\aswsp.sys (AVAST Software)
DRV - (aswTdi) -- C:\WINDOWS\system32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSnx) -- C:\WINDOWS\system32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswVmm) -- C:\WINDOWS\System32\drivers\aswVmm.sys ()
DRV - (aswRvrt) -- C:\WINDOWS\System32\drivers\aswRvrt.sys ()
DRV - (aswMonFlt) -- C:\WINDOWS\system32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswHwid) -- C:\WINDOWS\system32\drivers\aswHwid.sys ()
DRV - (aswRdr) -- C:\WINDOWS\system32\drivers\aswRdr.sys (AVAST Software)
DRV - (Avgdiskx) -- C:\WINDOWS\system32\drivers\avgdiskx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Linksys_adapter_H) -- C:\WINDOWS\system32\drivers\AE1200xp.sys (Broadcom Corporation)
DRV - (USBModem) -- C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) -- C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) -- C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (SISNIC) -- C:\WINDOWS\system32\drivers\sisnic.sys (SiS Corporation)
DRV - (OMCI) -- C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (EL90XBC) -- C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)
DRV - (SMCIRDA) -- C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: 4zffxtbr%40VideoDownloadConverter_4z.com:6.66.4.33738
FF - prefs.js..extensions.enabledAddons: e38c01fb-ffb2-4c7e-b4c7-1f47c844d855%40gmail.com:0.95.27
FF - prefs.js..extensions.enabledAddons: %7B037A8456-0903-427E-B5E0-7D95FDD598AE%7D:1.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:31.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014/08/25 16:48:25 | 000,000,000 | ---D | M]
[2014/07/03 08:03:57 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Liquid\Application Data\Mozilla\Extensions
[2014/08/25 13:41:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Liquid\Application Data\Mozilla\Firefox\Profiles\l3sh7dcg.default\extensions
[2014/08/17 05:00:39 | 000,000,000 | ---D | M] ("enterprise 1.1") -- C:\Documents and Settings\Liquid\Application Data\Mozilla\Firefox\Profiles\l3sh7dcg.default\extensions\e38c01fb-ffb2-4c7e-b4c7-1f47c844d855@gmail.com
[2014/08/17 05:00:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Liquid\Application Data\Mozilla\Firefox\Profiles\l3sh7dcg.default\extensions\e38c01fb-ffb2-4c7e-b4c7-1f47c844d855@gmail.com\extensionData
[2014/08/17 05:00:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Liquid\Application Data\Mozilla\Firefox\Profiles\l3sh7dcg.default\extensions\e38c01fb-ffb2-4c7e-b4c7-1f47c844d855@gmail.com\extensionData\plugins
[2014/08/17 05:00:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Liquid\Application Data\Mozilla\Firefox\Profiles\l3sh7dcg.default\extensions\e38c01fb-ffb2-4c7e-b4c7-1f47c844d855@gmail.com\extensionData\userCode
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LIQUID\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\L3SH7DCG.DEFAULT\EXTENSIONS\{037A8456-0903-427E-B5E0-7D95FDD598AE}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LIQUID\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\L3SH7DCG.DEFAULT\EXTENSIONS\4ZFFXTBR@VIDEODOWNLOADCONVERTER_4Z.COM
[2014/07/07 03:07:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
========== Chrome ==========
CHR - homepage:
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Documents and Settings\Liquid\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = C:\Documents and Settings\Liquid\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Documents and Settings\Liquid\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: YouTube = C:\Documents and Settings\Liquid\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Documents and Settings\Liquid\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Wallet = C:\Documents and Settings\Liquid\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Documents and Settings\Liquid\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2008/04/14 00:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\DadApp.exe ()
O4 - HKCU..\Run: [Itibiti.exe] C:\Program Files\Itibiti Soft Phone\Itibiti.exe File not found
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe (Malwarebytes Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.3.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A4B935D4-06FE-4090-B904-56322E228216}: DhcpNameServer = 192.168.3.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/05/06 18:46:40 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{437374d0-d5a4-11e3-9c87-00065b0e056d}\Shell - "" = AutoRun
O33 - MountPoints2\{437374d0-d5a4-11e3-9c87-00065b0e056d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{437374d0-d5a4-11e3-9c87-00065b0e056d}\Shell\AutoRun\command - "" = E:\TL_Bootstrap.exe
O33 - MountPoints2\{95d69b77-87ee-11d7-9c7d-00065b0e056d}\Shell - "" = AutoRun
O33 - MountPoints2\{95d69b77-87ee-11d7-9c7d-00065b0e056d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{95d69b77-87ee-11d7-9c7d-00065b0e056d}\Shell\AutoRun\command - "" = E:\TL_Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2014\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014/08/26 23:36:22 | 000,052,440 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\xpdvio.sys
[2014/08/26 22:49:17 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
[2014/08/26 22:44:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2014/08/26 22:43:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/08/26 22:39:49 | 000,053,208 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2014/08/26 22:39:38 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2014/08/26 22:39:25 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2014/08/26 22:39:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2014/08/26 18:06:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2014/08/26 16:13:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Desktop\saminside
[2014/08/26 07:54:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ophcrack
[2014/08/26 07:54:01 | 000,000,000 | ---D | C] -- C:\Program Files\ophcrack
[2014/08/25 17:17:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Local Settings\Application Data\Temp
[2014/08/25 17:02:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Application Data\AVAST Software
[2014/08/25 16:52:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\jumpshot.com
[2014/08/25 16:51:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Avast
[2014/08/25 16:49:23 | 000,057,800 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2014/08/25 16:49:20 | 000,779,536 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2014/08/25 16:49:18 | 000,414,520 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswsp.sys
[2014/08/25 16:49:15 | 000,067,824 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2014/08/25 16:49:10 | 000,055,112 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2014/08/25 16:48:39 | 000,276,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2014/08/25 16:47:16 | 000,043,152 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2014/08/25 16:33:35 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014/08/25 15:51:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2014/08/25 13:32:00 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/08/24 07:37:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Application Data\vlc
[2014/08/24 07:30:05 | 000,000,000 | ---D | C] -- C:\Program Files\WhoCrashed
[2014/08/24 07:04:21 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2014/08/23 18:40:41 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Liquid\Recent
[2014/08/23 18:16:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014/08/23 07:59:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MRT
[2014/08/23 07:54:32 | 000,000,000 | ---D | C] -- C:\ac966342dac78647c83a26741a
[2014/08/22 22:12:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Application Data\AVG2014
[2014/08/22 22:08:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Application Data\TuneUp Software
[2014/08/22 22:04:19 | 000,000,000 | -H-D | C] -- C:\$AVG
[2014/08/22 22:04:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG2014
[2014/08/22 22:01:58 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2014/08/22 21:34:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Local Settings\Application Data\MFAData
[2014/08/22 21:34:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2014/08/22 21:34:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Local Settings\Application Data\Avg2014
[2014/08/22 21:32:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Insight Software Solutions
[2014/08/22 21:32:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
[2014/08/22 21:32:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Insight Software
[2014/08/22 21:32:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Insight Software
[2014/08/22 21:30:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Insight Software Solutions
[2014/08/22 21:29:40 | 000,000,000 | ---D | C] -- C:\Program Files\Macro Express3
[2014/08/22 19:48:56 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Liquid\PrivacIE
[2014/08/22 19:18:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Local Settings\Application Data\SmartFTP
[2014/08/22 19:09:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Application Data\SmartFTP
[2014/08/22 19:08:12 | 000,000,000 | ---D | C] -- C:\Program Files\SmartFTP Client
[2014/08/18 04:27:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Desktop\site
[2014/08/17 05:02:00 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2014/08/17 04:53:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\My Documents\CoffeeCup Software
[2014/08/17 04:48:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Application Data\CoffeeCup Software
[2014/08/04 08:15:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\AVG
[2014/08/04 08:15:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\AVG
[2014/08/04 08:00:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Local Settings\Application Data\AVG
[2014/08/04 08:00:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Application Data\AVG
[2014/08/04 07:51:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG
[2014/08/04 07:49:31 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
[2014/08/04 07:47:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2014/08/04 07:45:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Local Settings\Application Data\AOL
[2014/08/01 01:59:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\BlueStacksSetup
[2014/08/01 01:58:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Local Settings\Application Data\Bluestacks
[2014/07/31 06:33:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Desktop\online dat
[2014/07/30 03:17:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Local Settings\Application Data\Skype
[2014/07/30 03:16:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Application Data\Skype
[2014/07/30 03:14:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2014/07/30 03:14:16 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2014/07/30 03:13:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Skype
[2014/07/29 18:37:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Liquid\Desktop\prof
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/08/27 09:41:34 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/08/27 04:51:13 | 000,000,364 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2014/08/26 23:36:24 | 000,052,440 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\xpdvio.sys
[2014/08/26 22:51:16 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
[2014/08/26 22:43:49 | 000,000,777 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2014/08/26 20:42:44 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/08/26 20:42:43 | 000,000,224 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Logon.job
[2014/08/26 20:42:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/08/26 20:42:18 | 536,342,528 | -HS- | M] () -- C:\hiberfil.sys
[2014/08/26 07:54:11 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ophcrack.lnk
[2014/08/25 19:55:25 | 000,414,520 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswsp.sys
[2014/08/25 16:51:53 | 000,001,733 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2014/08/25 16:47:59 | 000,057,800 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2014/08/25 16:47:58 | 000,779,536 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2014/08/25 16:47:58 | 000,192,352 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2014/08/25 16:47:53 | 000,049,944 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2014/08/25 16:47:52 | 000,067,824 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2014/08/25 16:47:51 | 000,024,184 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswHwid.sys
[2014/08/25 16:47:48 | 000,055,112 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2014/08/25 16:47:16 | 000,043,152 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2014/08/25 16:47:15 | 000,276,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2014/08/24 22:42:27 | 000,767,035 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\c.png
[2014/08/24 08:16:57 | 000,000,199 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\site.html
[2014/08/24 07:43:02 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\Google Chrome.lnk
[2014/08/24 07:30:17 | 000,000,706 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\WhoCrashed.lnk
[2014/08/24 07:19:18 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2014/08/23 21:08:10 | 001,388,159 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\Civil.pdf
[2014/08/23 18:57:21 | 000,000,000 | ---- | M] () -- C:\Cookies
[2014/08/23 18:17:39 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2014/08/22 21:38:02 | 000,000,163 | ---- | M] () -- C:\WINDOWS\Reimage.ini
[2014/08/22 21:33:18 | 000,000,093 | ---- | M] () -- C:\Documents and Settings\Liquid\My Documents\swpkey.mes
[2014/08/22 21:33:16 | 000,004,640 | ---- | M] () -- C:\Documents and Settings\Liquid\My Documents\macex_bak000.~mex
[2014/08/22 21:33:16 | 000,004,640 | ---- | M] () -- C:\Documents and Settings\Liquid\My Documents\macex.mex
[2014/08/22 15:57:06 | 000,101,888 | ---- | M] () -- C:\Documents and Settings\Liquid\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/08/21 05:11:14 | 000,006,176 | ---- | M] () -- C:\WINDOWS\System32\ScanResults.xml
[2014/08/21 05:04:33 | 000,000,464 | ---- | M] () -- C:\WINDOWS\System32\ScannerSettings
[2014/08/20 11:55:44 | 000,176,980 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\bank.JPG
[2014/08/20 05:12:17 | 000,004,097 | ---- | M] () -- C:\WINDOWS\System32\dummy.000
[2014/08/17 05:36:51 | 000,000,013 | ---- | M] () -- C:\WINDOWS\System32\WinSys32.crc
[2014/08/14 15:47:03 | 000,002,501 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\Microsoft Word 2010.lnk
[2014/08/08 17:44:16 | 000,002,523 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\judaism.rtf
[2014/08/08 15:00:01 | 000,000,218 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Monthly.job
[2014/08/05 22:23:33 | 000,647,321 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\Ammendment.pdf
[2014/08/05 21:00:20 | 002,347,285 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\1023.pdf
[2014/08/05 12:06:11 | 000,200,818 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\i1023.pdf
[2014/08/04 12:14:08 | 000,031,814 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\Articles.tif
[2014/08/04 11:18:02 | 000,052,156 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\1023checklist.pdf
[2014/08/03 20:07:33 | 000,060,599 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\irs8718.pdf
[2014/08/03 15:11:18 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014/08/02 13:04:39 | 000,002,459 | ---- | M] () -- C:\Documents and Settings\Liquid\Desktop\Microsoft Excel 2010.lnk
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/08/26 22:43:49 | 000,000,777 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2014/08/26 20:42:18 | 536,342,528 | -HS- | C] () -- C:\hiberfil.sys
[2014/08/26 07:54:11 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ophcrack.lnk
[2014/08/25 16:51:53 | 000,001,733 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2014/08/25 16:51:13 | 000,000,364 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2014/08/25 16:49:22 | 000,192,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2014/08/25 16:49:17 | 000,049,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2014/08/25 16:49:13 | 000,024,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswHwid.sys
[2014/08/24 22:42:27 | 000,767,035 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\c.png
[2014/08/24 07:43:02 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\Google Chrome.lnk
[2014/08/24 07:30:17 | 000,000,706 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\WhoCrashed.lnk
[2014/08/24 07:19:18 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2014/08/23 21:07:28 | 001,388,159 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\Civil.pdf
[2014/08/23 18:57:21 | 000,000,000 | ---- | C] () -- C:\Cookies
[2014/08/23 18:48:48 | 000,001,825 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome.lnk
[2014/08/23 18:22:26 | 000,000,886 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/08/23 18:22:18 | 000,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/08/23 18:17:38 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2014/08/22 22:08:38 | 000,000,714 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2014.lnk
[2014/08/22 21:33:47 | 000,004,640 | ---- | C] () -- C:\Documents and Settings\Liquid\My Documents\macex_bak000.~mex
[2014/08/22 21:33:23 | 000,102,362 | ---- | C] () -- C:\Documents and Settings\Liquid\My Documents\samples.mex
[2014/08/22 21:33:18 | 000,000,093 | ---- | C] () -- C:\Documents and Settings\Liquid\My Documents\swpkey.mes
[2014/08/22 21:33:16 | 000,004,640 | ---- | C] () -- C:\Documents and Settings\Liquid\My Documents\macex.mex
[2014/08/22 21:32:37 | 000,000,718 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Macro Express 3.lnk
[2014/08/22 19:08:44 | 000,001,998 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\SmartFTP Client.lnk
[2014/08/21 05:11:14 | 000,006,176 | ---- | C] () -- C:\WINDOWS\System32\ScanResults.xml
[2014/08/20 11:54:19 | 000,176,980 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\bank.JPG
[2014/08/20 05:11:58 | 000,004,097 | ---- | C] () -- C:\WINDOWS\System32\dummy.000
[2014/08/20 05:05:11 | 000,000,464 | ---- | C] () -- C:\WINDOWS\System32\ScannerSettings
[2014/08/17 05:01:25 | 000,000,013 | ---- | C] () -- C:\WINDOWS\System32\WinSys32.crc
[2014/08/13 07:03:00 | 000,000,199 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\site.html
[2014/08/05 12:05:22 | 000,200,818 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\i1023.pdf
[2014/08/04 12:43:41 | 000,647,321 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\Ammendment.pdf
[2014/08/04 12:13:44 | 000,031,814 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\Articles.tif
[2014/08/04 11:21:37 | 002,347,285 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\1023.pdf
[2014/08/04 11:17:48 | 000,052,156 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\1023checklist.pdf
[2014/08/04 07:46:09 | 000,001,074 | ---- | C] () -- C:\Documents and Settings\Liquid\Start Menu\Programs\AIM.lnk
[2014/08/03 20:07:29 | 000,060,599 | ---- | C] () -- C:\Documents and Settings\Liquid\Desktop\irs8718.pdf
[2014/07/30 03:14:38 | 000,001,686 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype.lnk
[2014/07/03 19:24:37 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2014/07/03 18:15:56 | 000,000,163 | ---- | C] () -- C:\WINDOWS\Reimage.ini
[2014/05/14 06:32:03 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2014/05/10 03:17:16 | 000,036,466 | ---- | C] () -- C:\WINDOWS\INSTALL.DAT
[2014/05/06 20:05:01 | 000,000,218 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2013/05/06 18:53:18 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013/05/06 18:41:01 | 000,022,720 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2013/05/06 11:22:06 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2013/05/06 11:20:28 | 000,198,552 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/05/16 06:13:09 | 000,101,888 | ---- | C] () -- C:\Documents and Settings\Liquid\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2014/07/03 10:15:20 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2014/02/24 20:30:52 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 05:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 00:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014/08/25 16:33:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2014/08/04 08:02:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG
[2014/08/22 23:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2014
[2014/08/01 01:59:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BlueStacksSetup
[2014/05/06 20:05:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2014/08/04 07:47:20 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2014/08/22 21:32:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Insight Software
[2014/08/22 21:32:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
[2014/08/26 22:00:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2014/07/13 20:00:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Netscape ISP Dialer
[2014/08/04 07:50:32 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
[2003/05/16 06:13:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liquid\Application Data\AnvSoft
[2014/08/25 17:02:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liquid\Application Data\AVAST Software
[2014/08/04 08:00:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liquid\Application Data\AVG
[2014/08/22 22:12:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liquid\Application Data\AVG2014
[2014/08/22 19:50:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liquid\Application Data\CoffeeCup Software
[2014/07/14 17:15:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liquid\Application Data\Foxit Software
[2014/06/08 14:11:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liquid\Application Data\MOVAVI
[2014/07/03 10:08:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liquid\Application Data\Netscape ISP Dialer
[2014/08/22 22:08:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liquid\Application Data\TuneUp Software
========== Purity Check ==========
< End of report >