OTL logfile created on: 9/12/2010 7:58:32 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\ALONSO PAJON\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
447.00 Mb Total Physical Memory | 219.00 Mb Available Physical Memory | 49.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 153.38 Gb Total Space | 114.27 Gb Free Space | 74.50% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 63.32 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: ALONSO
Current User Name: ALONSO PAJON
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/09/12 19:56:50 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALONSO PAJON\Desktop\OTL.exe
PRC - [2010/08/13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/07/01 21:39:08 | 000,357,096 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
PRC - [2010/07/01 21:34:46 | 000,129,720 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe
PRC - [2004/08/04 03:56:49 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2003/08/06 20:58:26 | 001,376,360 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\acsd.exe
PRC - [2003/01/10 21:13:04 | 000,065,536 | ---- | M] (America Online, Inc.) -- C:\WINDOWS\wanmpsvc.exe
========== Modules (SafeList) ========== MOD - [2010/09/12 19:56:50 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALONSO PAJON\Desktop\OTL.exe
MOD - [2004/08/04 03:57:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2004/08/04 02:01:17 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/08/13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/07/01 21:39:08 | 000,357,096 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe -- (AVP)
SRV - [2003/08/06 20:58:26 | 001,376,360 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\acsd.exe -- (AOL ACS)
SRV - [2003/01/10 21:13:04 | 000,065,536 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:\WINDOWS\wanmpsvc.exe -- (WANMiniportService) WAN Miniport (ATW)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\WPRO_40_1340.sys -- (WPRO_40_1340) WinPcap Packet Driver (WPRO_40_1340)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2010/09/10 23:40:01 | 000,482,392 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2010/09/10 20:01:35 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ute0mzyy.sys -- (ute0mzyy)
DRV - [2010/06/09 17:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2)
DRV - [2010/06/09 17:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\kl1.sys -- (KL1)
DRV - [2010/05/07 12:06:26 | 000,032,856 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2009/11/02 20:27:24 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009/10/22 12:54:18 | 000,037,392 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\30072332.sys -- (30072332)
DRV - [2009/09/25 16:59:42 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\30072331.sys -- (30072331)
DRV - [2008/09/24 10:40:22 | 004,122,368 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2006/10/22 12:22:00 | 003,994,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2005/04/13 11:34:02 | 000,414,464 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvapu.sys -- (nvnforce) Service for NVIDIA(R) nForce(TM)
DRV - [2005/04/13 11:32:42 | 000,053,376 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvax.sys -- (nvax) Service for NVIDIA(R) nForce(TM)
DRV - [2005/02/02 04:15:14 | 000,196,409 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\V0060Vid.sys -- (V0060VID)
DRV - [2004/08/04 01:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2003/11/13 22:19:48 | 000,210,304 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2003/11/13 22:18:36 | 000,679,808 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2003/11/13 22:17:00 | 001,042,816 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2003/11/10 15:24:24 | 000,039,532 | ---- | M] (Alcor Micro Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Sunkfilt.sys -- (SunkFilt)
DRV - [2003/08/15 22:22:16 | 000,072,771 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENET.sys -- (NVENET)
DRV - [2003/03/19 18:51:00 | 000,018,688 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys -- (nv_agp)
DRV - [2003/01/10 21:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2003/01/04 06:01:11 | 000,008,552 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1A 3C 91 64 17 52 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\:
FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\Components: C:\Program Files\Common Files\csshare\plugins0942 [2010/09/10 15:35:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\CompuServe 7.0\Extensions\\Plugins: C:\Program Files\Common Files\csshare\plugins0942 [2010/09/10 15:35:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape 6 6.2.1\Extensions\\Components: C:\Program Files\Netscape\Netscape 6\Components [2010/09/10 15:35:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape 6 6.2.1\Extensions\\Plugins: C:\Program Files\Netscape\Netscape 6\Plugins [2010/09/10 15:35:29 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\THBExt [2010/09/10 23:41:23 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2010/08/18 14:49:55 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [VF0060 STISvc] C:\WINDOWS\System32\V0060Pin.dll (Creative Technology Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe ()
O9 - Extra 'Tools' menuitem : ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe ()
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232585551609 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1251145133163 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/1.3.1/jinstall-131-win.cab (Java Plug-in 1.3.1)
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/1.3.1/jinstall-131_02-win.cab (Java Plug-in 1.3.1_02)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 207.69.188.185 207.69.188.186 207.69.188.187
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop WallPaper: C:\Documents and Settings\ALONSO PAJON\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\ALONSO PAJON\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/02/09 21:01:42 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/09/12 19:56:30 | 000,576,000 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ALONSO PAJON\Desktop\OTL.exe
[2010/09/12 19:50:51 | 000,000,000 | ---D | C] -- C:\Program Files\Essentials Codec Pack
[2010/09/12 12:20:07 | 075,220,144 | ---- | C] ( ) -- C:\Documents and Settings\ALONSO PAJON\Desktop\kaspersky removal tool.exe
[2010/09/11 19:48:35 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\ALONSO PAJON\Recent
[2010/09/11 19:48:31 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/09/11 12:50:58 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2010/09/10 23:40:32 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
[2010/09/10 23:40:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2010/09/10 23:40:01 | 000,482,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2010/09/10 23:38:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2010/09/10 23:37:44 | 111,997,584 | ---- | C] (Kaspersky Lab) -- C:\Documents and Settings\ALONSO PAJON\Desktop\kis2011_11.0.1.401en_us.exe
[2010/09/10 20:24:02 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/09/10 18:33:49 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\3007233.sys
[2010/09/10 18:33:49 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\30072331.sys
[2010/09/10 18:33:49 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\30072332.sys
[2010/09/10 15:37:31 | 000,107,368 | ---- | C] (GEAR Software Inc.) -- C:\WINDOWS\System32\GEARAspi.dll
[2010/09/10 15:36:38 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/09/10 15:36:10 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/09/10 15:34:47 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/09/10 15:33:15 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/09/10 15:28:58 | 074,840,872 | ---- | C] (Apple Inc.) -- C:\Documents and Settings\ALONSO PAJON\Desktop\iTunesSetup.exe
[2010/09/10 15:03:38 | 003,427,248 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\ALONSO PAJON\Desktop\ccsetup235.exe
[2010/08/29 15:28:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/08/29 15:23:24 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010/08/27 13:34:00 | 007,487,104 | ---- | C] (IObit ) -- C:\Documents and Settings\ALONSO PAJON\Desktop\asc-setup370.exe
[2010/08/18 19:06:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALONSO PAJON\Local Settings\Application Data\Conduit
[2010/08/18 19:06:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ALONSO PAJON\Application Data\Malwarebytes
[2010/08/18 19:05:58 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/18 19:05:56 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/18 19:05:56 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/18 19:05:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/18 19:05:20 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\ALONSO PAJON\Desktop\mbam-setup-1.46.exe
[2010/08/18 13:57:47 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/08/18 13:48:35 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/08/18 13:48:35 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/08/18 13:48:35 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/08/18 13:48:35 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/08/18 13:48:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/08/18 13:47:57 | 000,000,000 | ---D | C] -- C:\Qoobox
========== Files - Modified Within 30 Days ========== [2010/09/12 20:09:01 | 000,000,362 | ---- | M] () -- C:\WINDOWS\tasks\Windows Codec Update Service.job
[2010/09/12 19:56:50 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALONSO PAJON\Desktop\OTL.exe
[2010/09/12 19:51:14 | 000,000,829 | ---- | M] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\Media Player Classic.lnk
[2010/09/12 19:49:46 | 016,030,841 | ---- | M] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\WECPSetup.exe
[2010/09/12 17:40:42 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/09/12 16:33:59 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/09/12 16:33:38 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/09/12 16:33:34 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/09/12 16:33:31 | 469,291,008 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/12 16:32:20 | 004,718,592 | -H-- | M] () -- C:\Documents and Settings\ALONSO PAJON\NTUSER.DAT
[2010/09/12 16:32:20 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\ALONSO PAJON\ntuser.ini
[2010/09/12 16:32:06 | 006,944,202 | -H-- | M] () -- C:\Documents and Settings\ALONSO PAJON\Local Settings\Application Data\IconCache.db
[2010/09/12 12:20:44 | 075,220,144 | ---- | M] ( ) -- C:\Documents and Settings\ALONSO PAJON\Desktop\kaspersky removal tool.exe
[2010/09/11 19:49:11 | 000,007,138 | ---- | M] () -- C:\Documents and Settings\ALONSO PAJON\My Documents\cc_20100911_194903.reg
[2010/09/11 16:25:01 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/09/11 16:07:16 | 003,842,655 | R--- | M] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\ComboFix.exe
[2010/09/11 00:05:33 | 000,002,415 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/09/10 23:42:32 | 000,113,933 | ---- | M] () -- C:\WINDOWS\System32\drivers\klin.dat
[2010/09/10 23:42:32 | 000,097,549 | ---- | M] () -- C:\WINDOWS\System32\drivers\klick.dat
[2010/09/10 23:40:01 | 000,482,392 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2010/09/10 23:38:07 | 111,997,584 | ---- | M] (Kaspersky Lab) -- C:\Documents and Settings\ALONSO PAJON\Desktop\kis2011_11.0.1.401en_us.exe
[2010/09/10 22:05:54 | 000,000,757 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/09/10 20:01:35 | 000,007,168 | ---- | M] () -- C:\WINDOWS\System32\drivers\ute0mzyy.sys
[2010/09/10 15:35:11 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/09/10 15:30:14 | 074,840,872 | ---- | M] (Apple Inc.) -- C:\Documents and Settings\ALONSO PAJON\Desktop\iTunesSetup.exe
[2010/09/10 15:14:54 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/09/10 15:06:26 | 000,034,156 | ---- | M] () -- C:\Documents and Settings\ALONSO PAJON\My Documents\cc_20100910_150617.reg
[2010/09/10 15:04:22 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\CCleaner.lnk
[2010/09/10 15:03:51 | 003,427,248 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\ALONSO PAJON\Desktop\ccsetup235.exe
[2010/09/03 19:34:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/02 14:12:23 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/08/27 13:34:13 | 007,487,104 | ---- | M] (IObit ) -- C:\Documents and Settings\ALONSO PAJON\Desktop\asc-setup370.exe
[2010/08/20 10:39:58 | 000,126,885 | ---- | M] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\clamwin-update-0.96.2-0.96.2.1.exe
[2010/08/18 19:06:01 | 000,000,714 | ---- | M] () -- C:\Documents and Settings\ALONSO PAJON\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/18 19:06:01 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/18 19:05:30 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\ALONSO PAJON\Desktop\mbam-setup-1.46.exe
[2010/08/18 19:01:33 | 001,064,730 | ---- | M] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\clamwin-update-0.96.1-0.96.2.exe
[2010/08/18 14:49:55 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
========== Files Created - No Company Name ========== [2010/09/12 19:51:45 | 000,000,362 | ---- | C] () -- C:\WINDOWS\tasks\Windows Codec Update Service.job
[2010/09/12 19:51:14 | 000,000,829 | ---- | C] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\Media Player Classic.lnk
[2010/09/12 19:49:41 | 016,030,841 | ---- | C] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\WECPSetup.exe
[2010/09/12 16:43:26 | 012,403,212 | ---- | C] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\Unknown Artist - Unknown Album - Belly Dance fusion w_ Tambourine by Viktori.mp4
[2010/09/11 19:49:06 | 000,007,138 | ---- | C] () -- C:\Documents and Settings\ALONSO PAJON\My Documents\cc_20100911_194903.reg
[2010/09/10 23:42:32 | 000,113,933 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2010/09/10 23:42:32 | 000,097,549 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2010/09/10 20:28:50 | 469,291,008 | -HS- | C] () -- C:\hiberfil.sys
[2010/09/10 20:01:34 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\ute0mzyy.sys
[2010/09/10 15:37:35 | 000,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/09/10 15:35:11 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/09/10 15:06:23 | 000,034,156 | ---- | C] () -- C:\Documents and Settings\ALONSO PAJON\My Documents\cc_20100910_150617.reg
[2010/08/20 10:39:55 | 000,126,885 | ---- | C] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\clamwin-update-0.96.2-0.96.2.1.exe
[2010/08/18 19:06:01 | 000,000,714 | ---- | C] () -- C:\Documents and Settings\ALONSO PAJON\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/18 19:06:01 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/18 19:01:27 | 001,064,730 | ---- | C] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\clamwin-update-0.96.1-0.96.2.exe
[2010/08/18 13:57:58 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/08/18 13:57:54 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/08/18 13:48:35 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/08/18 13:48:35 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/08/18 13:48:35 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/08/18 13:48:35 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/08/18 13:48:35 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/08/18 13:47:26 | 003,842,655 | R--- | C] () -- C:\Documents and Settings\ALONSO PAJON\Desktop\ComboFix.exe
[2010/07/11 13:11:26 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2009/01/21 20:30:43 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\ALONSO PAJON\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/10/22 12:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/10/22 12:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/10/22 12:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2004/08/04 03:56:42 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 03:56:42 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 03:56:42 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2003/07/27 14:05:51 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2003/07/27 14:05:51 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
[2003/02/09 19:46:30 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2003/02/09 19:46:29 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2003/02/09 19:46:27 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2003/02/09 19:46:26 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2003/02/09 19:46:17 | 000,001,094 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/02/09 19:46:17 | 000,000,465 | ---- | C] () -- C:\WINDOWS\System32\emver.ini
[2003/02/09 19:45:36 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2003/01/04 07:46:07 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/01/04 07:13:31 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/01/04 07:12:34 | 000,532,544 | ---- | C] () -- C:\WINDOWS\PIC.dll
[2003/01/04 07:12:34 | 000,024,576 | ---- | C] () -- C:\WINDOWS\HKNTDLL.dll
[2003/01/04 05:58:11 | 000,000,132 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2003/01/04 05:57:30 | 000,000,310 | ---- | C] () -- C:\WINDOWS\net2fone.ini
========== Alternate Data Streams ========== @Alternate Data Stream - 2628 bytes -> C:\WINDOWS\System32\OEMLOGO.BMP:Q30lsldxJoudresxAaaqpcawXc
< End of report >