========== LOP Check ==========
[2010/06/09 20:01:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/01 14:25:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AusLogics
[2008/06/04 15:56:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Cakewalk
[2008/12/31 16:29:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Foxit
[2009/03/18 14:55:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2009/03/10 10:34:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GlarySoft
[2010/05/17 14:15:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ICQ
[2009/03/06 13:23:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IObit
[2010/06/09 19:21:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Orca Profiles
[2009/02/17 13:16:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uTorrent
[2009/01/15 09:59:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\YuLeech
[2010/05/31 00:15:47 | 000,000,384 | ---- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job
[2010/06/09 14:00:00 | 000,000,310 | ---- | M] () – C:\WINDOWS\Tasks\ydthjdmd.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%*.* >
[2008/05/18 14:21:25 | 000,000,000 | ---- | M] () – C:\AUTOEXEC.BAT
[2009/02/09 10:38:10 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/05/18 14:21:25 | 000,000,000 | ---- | M] () – C:\CONFIG.SYS
[2008/05/18 14:21:25 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/01 13:19:48 | 000,000,109 | ---- | M] () – C:\mbam-error.txt
[2008/05/18 14:21:25 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/05/18 15:31:03 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/06/09 13:38:37 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2008/05/29 08:15:05 | 000,000,232 | -H-- | M] () – C:\sqmdata00.sqm
[2008/05/29 09:30:51 | 000,000,232 | -H-- | M] () – C:\sqmdata01.sqm
[2008/05/29 08:15:05 | 000,000,244 | -H-- | M] () – C:\sqmnoopt00.sqm
[2008/05/29 09:30:51 | 000,000,244 | -H-- | M] () – C:\sqmnoopt01.sqm
< MD5 for: AGP440.SYS >
[2006/02/28 07:00:00 | 018,738,937 | ---- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/05/18 15:27:36 | 023,852,652 | ---- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/05/18 15:27:36 | 023,852,652 | ---- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2006/02/28 07:00:00 | 018,738,937 | ---- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/05/18 15:27:36 | 023,852,652 | ---- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/05/18 15:27:36 | 023,852,652 | ---- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2006/02/28 07:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2006/02/28 07:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2006/02/28 07:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006/02/28 07:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< MD5 for: VIAMRAID.SYS >
[2005/04/26 11:22:40 | 000,060,928 | ---- | M] (VIA Technologies inc,.ltd) MD5=0363E216E4EB5052969C96608934DBDE – C:\WINDOWS\system32\drivers\viamraid.sys
< c:\windows\system32*.dll /lockedfiles >
[2010/02/10 23:46:14 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 – C:\WINDOWS\system32\ATIDEMGX.dll
< c:\windows\system32\drivers*.sys /lockedfiles >
< %systemroot%*. /mp /s >
< %systemroot%\system32\drivers*.sys /90 >
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 498 bytes → C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 134 bytes → C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B
@Alternate Data Stream - 120 bytes → C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B
@Alternate Data Stream - 104 bytes → C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >