Jump to content

Welcome Guest to Geeks to Go - Register now for FREE
Geeks To Go is a helpful hub, where thousands of friendly volunteers serve up answers and support. Get free advice from the experts. Feel free to browse the site as a guest. However, you must log in to reply to existing topics or start a new topic of your own, and enjoy all this forum has to offer. Additionally, if you can assist another member by sharing your knowledge, please post a reply! Best of all - Registration and all assistance, is FREE! Learn more about How it Works. Infected? Malware Cleaning Guide. What are you waiting for?
Create an Account Login to Account

Cannot Delete File [Solved]


  • This topic is locked This topic is locked

#1
crazychilean7

crazychilean7

    Member

  • Member
  • PipPip
  • 30 posts
Hi, I have files and folders I cannot delete on my computer. Every time I try to delete the files I get the error message "Cannot delete file: Cannot read from the source file or disk.". I've tried using two programs called unlocker and killbox and neither were able to get rid of the files.

I tried going into command prompt and deleting it through there and i get an error message that says "the filename, directory name, or volume label syntax is incorrect".

All the files and folders are in some weird gibberish that look like this " =2╚u¡.í" and .3ⁿ%╝â.8¬m. They are all big files (around 2 or 3 gigs) and are taking up a lot of space on my computer. Please help me delete these files.

Jason
  • 0

Advertisement


#2
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
still need help ?
  • 0

#3
crazychilean7

crazychilean7

    Member

  • Member
  • PipPip
  • 30 posts
Yes its been a week and a half and this is the first reply I've gotten...please help
  • 0

#4
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
can you give me the full file path of the things you want deleted


  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %systemroot%\System32\antiwpa.dll
    %systemroot%\SYSTEM32\wpa.dll
    %systemroot%\setup\scripts\biestart.exe
    %systemroot%\system32\drivers\royal.sys
    %systemroot%\system32\oobe\AntiWPA_Crypt.dll
    %TEMP%\antiwpa_crypt.dll
    %TEMP%\antiwpa.dll /s
    %PROGRAMFILES%\antiwpa.dll /s
    %systemroot%\system32\crypt.dll
    %TEMP%\crypt.dll
    %SYSTEMDRIVE%\*.
    %SYSTEMDRIVE%\*.*
    %PROGRAMFILES%\*.
    %systemroot%\system32\drivers\*.dat
    %PROGRAMFILES%\*.*
    %PROGRAMFILES%\*.exe
    %DESKTOP%\*.exe
    %USERNAME%\*.exe
    %USERPROFILE%\*.exe
    %ALLUSERSPROFILE%\*.exe
    %SYSTEMDRIVE%\*.exe
    %SYSTEMROOT%\*.exe
    %systemroot%\system32\drivers\*.exe
    %systemroot%\system\*.exe
    %systemroot%\AppPatch\*.exe
    %systemroot%\Cache\*.exe
    %systemroot%\Downloaded Program Files\*.exe
    %systemroot%\Fonts\*.exe
    %systemroot%\Help\*.exe
    %APPDATA%\*.exe
    %APPDATA%\Google\*.exe
    %systemroot%\system32\inf\*.exe
    %APPDATA%\Opera\Opera\profile\widgets\*.exe
    %PROGRAMFILES%\Opera\program\plugins\*.exe
    %APPDATA%\Opera\Opera\profile\toolbar\*.exe
    %systemroot%\Web\*.exe
    %systemroot%\Wbem\*.exe
    %systemroot%\twain_32\*.exe
    %systemroot%\WinSxS\*.exe
    %systemroot%\Sun\*.exe
    %systemroot%\srchasst\*.exe
    %systemroot%\Shellnew\*.exe
    %systemroot%\Security\*.exe
    %systemroot%\Resources\*.exe
    %systemroot%\Repair\*.exe
    %systemroot%\Registration\*.exe
    %systemroot%\RegisteredPackages\*.exe
    %systemroot%\pss\*.exe
    %systemroot%\Provisioning\*.exe
    %systemroot%\PIF\*.exe
    %systemroot%\PeerNet\*.exe
    %systemroot%\PcTel\*.exe
    %systemroot%\Offline Web Pages\*.exe
    %systemroot%\network diagnostic\*.exe
    %systemroot%\mui\*.exe
    %systemroot%\msapps\*.exe
    %systemroot%\msagent\*.exe
    %systemroot%\minidump\*.exe
    %systemroot%\media\*.exe
    %systemroot%\Help\*.exe
    %systemroot%\ie7\*.exe
    %systemroot%\ie7updates\*.exe
    %systemroot%\ime\*.exe
    %systemroot%\installer\*.exe
    %systemroot%\internet logs\*.exe
    %systemroot%\Cursors\*.exe
    %systemroot%\Config\*.exe
    %systemroot%\internet logs\*.exe
    %systemroot%\Assembly\*.exe
    %systemroot%\internet logs\*.exe
    %systemroot%\AppPatch\*.exe
    %systemroot%\l2schemas\*.exe
    %systemroot%\Debug\*.exe
    %systemroot%\ehome\*.exe
    %systemroot%\Connection Wizard\*.exe
    %systemroot%\system32\1025\*.exe
    %systemroot%\system32\1028\*.exe
    %systemroot%\system32\1031\*.exe
    %systemroot%\system32\1033\*.exe
    %systemroot%\system32\1037\*.exe
    %systemroot%\system32\1041\*.exe
    %systemroot%\system32\1042\*.exe
    %systemroot%\system32\1054\*.exe
    %systemroot%\system32\2052\*.exe
    %systemroot%\system32\3076\*.exe
    %systemroot%\system32\appmgmt\*.exe
    %systemroot%\system32\bits\*.exe
    %systemroot%\system32\catroot\*.exe
    %systemroot%\system32\catroot2\*.exe
    %systemroot%\system32\com\*.exe
    %systemroot%\system32\config\*.exe
    %systemroot%\system32\dhcp\*.exe
    %systemroot%\system32\DirectX\*.exe
    %systemroot%\system32\drvstore\*.exe
    %systemroot%\system32\en\*.exe
    %systemroot%\system32\en-us\*.exe
    %systemroot%\system32\export\*.exe
    %systemroot%\system32\GroupPolicy\*.exe
    %systemroot%\system32\ias\*.exe
    %systemroot%\system32\icsxml\*.exe
    %systemroot%\system32\ime\*.exe
    %systemroot%\system32\inetsrv\*.exe
    %systemroot%\system32\LogFiles\*.exe
    %systemroot%\system32\Macromed\*.exe
    %systemroot%\system32\Microsoft\*.exe
    %systemroot%\system32\Msdtc\*.exe
    %systemroot%\system32\Mui\*.exe
    %systemroot%\system32\npp\*.exe
    %systemroot%\system32\NtMsData\*.exe
    %systemroot%\system32\oobe\*.exe
    %systemroot%\system32\PreInstall\*.exe
    %systemroot%\system32\ras\*.exe
    %systemroot%\system32\ReInstallBackups\*.exe
    %systemroot%\system32\Restore\*.exe
    %systemroot%\system32\Scripting\*.exe
    %systemroot%\system32\Setup\*.exe
    %systemroot%\system32\ShellExt\*.exe
    %systemroot%\system32\SoftwareDistribution\*.exe
    %systemroot%\system32\URTTEmp\*.exe
    %systemroot%\system32\USMT\*.exe
    %systemroot%\system32\Wbem\*.exe
    %systemroot%\system32\Wins\*.exe
    %systemroot%\system32\Xircom\*.exe
    %systemroot%\system32\XPSViewer\*.exe
    %COMMONPROGRAMFILES%\*.exe
    %APPDATA%\*.*
    %TEMP%\*.*
    set /c

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

  • 0

#5
crazychilean7

crazychilean7

    Member

  • Member
  • PipPip
  • 30 posts
Will it matter if the folder is on an external hard drive?
  • 0

#6
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
not really, but you will need to plug the external HD in for it
  • 0

#7
crazychilean7

crazychilean7

    Member

  • Member
  • PipPip
  • 30 posts
Here are the Scans...

OTL.Txt
OTL logfile created on: 10/8/2009 2:10:09 PM - Run 1
OTL by OldTimer - Version 3.0.18.4 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.48 Mb Total Physical Memory | 463.29 Mb Available Physical Memory | 45.27% Memory free
1.66 Gb Paging File | 0.88 Gb Available in Paging File | 53.37% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.34 Gb Total Space | 3.75 Gb Free Space | 3.50% Space Free | Partition Type: NTFS
Drive D: | 4.43 Gb Total Space | 0.68 Gb Free Space | 15.23% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 1.83 Gb Total Space | 1.73 Gb Free Space | 94.26% Space Free | Partition Type: FAT
Drive M: | 521.62 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive N: | 232.83 Gb Total Space | 14.38 Gb Free Space | 6.17% Space Free | Partition Type: FAT32

Computer Name: HARVEY
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe (Orb Networks, Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Softex\OmniPass\Omniserv.exe ()
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\HP\KBD\KBD.EXE (Hewlett-Packard Company)
PRC - C:\Program Files\WildTangent\Apps\GameChannel.exe (WildTangent)
PRC - C:\Program Files\ClamWin\bin\ClamTray.exe (alch)
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\WinZip E-Mail Companion\loadwzco.exe (Nektra S.A./WinZip Computing, S.L.)
PRC - C:\Documents and Settings\Owner\Desktop\My Stuff\Unlocker\UnlockerAssistant.exe ()
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
PRC - C:\Program Files\Desktop Calendar\Desktop Calendar.exe (Home)
PRC - C:\Program Files\Starfield\Desktop Notifier\wben.exe (Starfield Technologies, Inc.)
PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe ()
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe (The Linksys Group, Inc.)
PRC - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe (interMute, Inc.)
PRC - C:\WINDOWS\System32\HPZipm12.exe (HP)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe (Adobe Systems Incorporated)
PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (ACDaemon [Auto | Running]) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe ()
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Autodesk Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk, Inc.)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CLTNetCnService [Auto | Stopped]) -- File not found
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (getPlus® Helper [On_Demand | Stopped]) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakDigitalDisplayService [Auto | Running]) -- C:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe (Orb Networks, Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (LiveUpdate Notice Ex [Auto | Stopped]) -- File not found
SRV - (LiveUpdate Notice Service [Auto | Running]) -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (omniserv [Auto | Running]) -- C:\Program Files\Softex\OmniPass\Omniserv.exe ()
SRV - (Pml Driver HPZ12 [On_Demand | Running]) -- C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (StarWindServiceAE [Auto | Running]) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AFS2K [System | Running]) -- C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (drvmcdb [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\drvmcdb.sys (VERITAS Software, Inc.)
DRV - (fasttx2k [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (ialm [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (IPN2120 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\LSIPNDS.sys (Inprocomm, Inc.)
DRV - (ltmodem5 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (MxlW2k [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (pfc [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (Ps2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (RT2500 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\RT2500.sys (Ralink Technology Inc.)
DRV - (rtl8139 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (S3Psddr [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (viaagp1 [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://srch-us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://us8.hpwis.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;localhost;*.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 36
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.2
FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:3.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:7
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - prefs.js..network.proxy.no_proxies_on: "127.0.0.1,localhost"

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/03/24 13:30:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 15:00:37 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/09/28 15:56:35 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/10 17:52:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/09/10 17:52:29 | 00,000,000 | ---D | M]

[2009/05/26 22:40:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2009/05/26 22:40:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/10/05 14:41:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\eycu23b2.default\extensions
[2009/09/10 17:52:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\eycu23b2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/29 21:14:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\eycu23b2.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/07/14 14:19:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\eycu23b2.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2009/09/29 21:14:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\eycu23b2.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2009/10/05 14:41:18 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/09/10 17:52:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/24 13:30:35 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/13 20:18:27 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/10 16:57:20 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/08/05 17:30:42 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/09/10 17:52:18 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/10 17:52:18 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/02/24 14:34:32 | 01,044,480 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\mozilla firefox\plugins\libdivx.dll
[2007/08/29 16:47:44 | 00,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\mozilla firefox\plugins\npbittorrent.dll
[2009/07/25 05:23:01 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/02/24 14:34:14 | 01,337,648 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2009/02/24 14:34:22 | 00,098,304 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2007/10/11 15:17:50 | 01,435,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/09/10 17:52:23 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/10/08 14:00:30 | 00,266,240 | ---- | M] ( Starfield Technologies, Inc.) -- C:\Program Files\mozilla firefox\plugins\npoff.dll
[2009/02/27 12:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/09/09 00:48:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/09/09 00:48:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/09/09 00:48:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/09/09 00:48:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/09/09 00:48:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/09/09 00:48:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/09/09 00:48:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2007/04/16 12:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2009/07/08 14:22:12 | 00,032,456 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\mozilla firefox\plugins\np_gp.dll
[2009/02/24 14:34:32 | 00,200,704 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\mozilla firefox\plugins\ssldivx.dll
[2009/08/24 10:23:09 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/24 10:23:09 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/24 10:23:09 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/24 10:23:09 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/24 10:23:09 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/24 10:23:09 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ClamWin] C:\Program Files\ClamWin\bin\ClamTray.exe (alch)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KBD.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\System32\ps2.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Documents and Settings\Owner\Desktop\My Stuff\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [WinZip E-Mail Companion OEAPI] C:\Program Files\WinZip E-Mail Companion\loadwzco.exe (Nektra S.A./WinZip Computing, S.L.)
O4 - HKLM..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe (WildTangent)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Desktop Calendar] C:\Program Files\Desktop Calendar\Desktop Calendar.exe (Home)
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [wben] C:\Program Files\Starfield\Desktop Notifier\wben.exe (Starfield Technologies, Inc.)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless PCI Card Configuration Utility.lnk = C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe (The Linksys Group, Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe (interMute, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...tes/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.ado...obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.59.247.45 208.59.247.46
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\opxpgina.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/04/10 00:19:17 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2002/09/11 04:02:32 | 00,000,045 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2003/05/18 13:54:20 | 00,061,440 | R--- | M] () - M:\autoplay.exe -- [ CDFS ]
O32 - AutoRun File - [2008/08/01 13:48:28 | 00,000,049 | R--- | M] () - M:\autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2007/08/25 01:26:54 | 00,000,000 | ---D | M] - N:\autorun -- [ FAT32 ]
O32 - AutoRun File - [2005/11/15 11:08:04 | 00,000,036 | -H-- | M] () - N:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{1193d2ac-a274-11de-8a65-000c7600366c}\Shell - "" = AutoRun
O33 - MountPoints2\{1193d2ac-a274-11de-8a65-000c7600366c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1193d2ac-a274-11de-8a65-000c7600366c}\Shell\AutoRun\command - "" = M:\Install.bat -- [2008/08/04 13:22:19 | 00,001,347 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)


SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608555} - Internet Explorer Classes for Java
ActiveX: {0E9A3196-39EA-409D-8EB4-20D7FABC191A} - Microsoft .NET Framework 1.0 Hotfix (KB928367)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {14303301-758B-402B-9A0D-2C6A591680DB} - Microsoft .NET Framework 1.0 Service Pack 3 (KB867461)
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4d64f3ba-f112-4efe-a02e-96680859937c} - KB918899
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5b7bf89d-d196-4c32-a303-a57b8ab7f18d} - KB918439
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {78705f0d-e8db-4b2d-8193-982bdda15ecd} - .NET Framework
ActiveX: {81B52903-4C11-11D6-B6E1-00B0D049139F} - Microsoft .NET Framework 1.0 Service Pack 2 (KB867461)
ActiveX: {871F8A30-15A2-11D6-8711-0002B3281F8B} - Microsoft .NET Framework 1.0 Service Pack 1 (KB867461)
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {8D1D0E9A-C799-4D28-9E29-0061D1E66E43} - Microsoft .NET Framework 1.1 Hotfix (KB928366)
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {A82D26BA-3D43-623A-7436-154A90003870} - DirectAnimation
ActiveX: {AE5B6306-BE23-30D5-462F-499B7BB440B8} - Outlook Express
ActiveX: {B7D1820B-C2DA-4DEC-6B71-2B48BFEC570F} - Internet Explorer
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D193F810-70A0-63AA-BE18-453AC3FCBD73} - Internet Explorer Classes for Java
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {dd772a76-bef3-44d7-8b39-502c8504c1f1} - KB925486
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {f15ee071-deb7-4cbb-951f-431c98338d8e} - KB911567
ActiveX: {F7DF37F8-6CCA-3F40-88D9-076DE0911AD5} - Themes Setup
ActiveX: {F9A316CA-5C41-EA35-7E01-D23DA68F1A7A} - NetShow
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCODCCMP.DLL (LEAD Technologies, Inc.)
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2009/09/28 15:56:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2009/09/15 22:51:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/09/09 14:19:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/09/28 15:52:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\AVG8
[2009/09/15 22:44:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\DAEMON Tools Lite
[2009/09/15 23:00:14 | 00,000,000 | ---D | C] -- C:\Program Files\Alcohol Soft
[2009/09/28 15:56:35 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/09/15 22:50:19 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2009/09/15 22:50:32 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar
[2009/09/28 15:49:16 | 00,000,000 | ---D | C] -- C:\Program Files\File Shredder
[2009/10/08 01:01:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2009/09/28 16:15:33 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2009/09/28 15:57:23 | 00,011,952 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/09/28 15:57:22 | 00,108,552 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/09/28 15:57:15 | 00,335,240 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/09/28 15:57:14 | 00,027,784 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/09/28 15:56:49 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2009/09/28 12:09:34 | 00,000,000 | ---D | C] -- C:\!KillBox
[2009/09/18 12:27:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\New Folder
[2009/09/15 23:46:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Warcraft III
[2009/09/15 23:22:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\Alcohol 120%
[2009/09/15 23:08:18 | 00,139,264 | ---- | C] (Blizzard Entertainment) -- C:\WINDOWS\War3Unin.exe
[2009/09/09 22:28:20 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\triedit.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2009/10/08 09:37:59 | 00,007,438 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Dream Log.wpd
[2009/10/08 08:40:14 | 42,506,178 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/10/07 18:26:39 | 00,009,342 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/10/07 16:02:42 | 00,000,249 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.dat
[2009/10/07 16:02:40 | 00,000,390 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2009/10/07 16:02:12 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/07 16:01:59 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/07 16:01:57 | 10,732,70784 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/07 13:28:26 | 00,000,523 | ---- | M] () -- C:\hpfr3420.xml
[2009/10/07 01:36:25 | 00,168,448 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/07 01:06:38 | 00,055,312 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\7319_920831000150_1932279_52478078_3350618_n.jpg
[2009/10/07 00:32:20 | 00,035,100 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Katie Brown 23 F.jpg
[2009/10/07 00:31:51 | 00,230,995 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Katie Brown 23 F.pdf
[2009/10/03 14:35:05 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/09/30 18:05:33 | 00,492,629 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/09/30 16:23:41 | 00,000,436 | ---- | M] () -- C:\WINDOWS\tasks\EasyShare Registration Task.job
[2009/09/29 22:47:24 | 02,644,044 | -H-- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/09/28 15:57:23 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/09/28 15:57:23 | 00,001,518 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/09/28 15:57:22 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/09/28 15:57:15 | 00,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/09/28 15:57:14 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/09/28 15:56:52 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/09/15 23:57:26 | 00,125,724 | ---- | M] () -- C:\WINDOWS\War3Unin.dat
[2009/09/15 23:56:42 | 00,001,568 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Frozen Throne.lnk
[2009/09/15 23:56:35 | 00,139,264 | ---- | M] (Blizzard Entertainment) -- C:\WINDOWS\War3Unin.exe
[2009/09/15 23:56:35 | 00,002,829 | ---- | M] () -- C:\WINDOWS\War3Unin.pif
[2009/09/15 23:50:03 | 00,001,561 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Warcraft III.lnk
[2009/09/15 23:00:18 | 00,000,844 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Alcohol 120%.lnk
[2009/09/15 22:50:27 | 00,001,624 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\DAEMON Tools Lite.lnk
[2009/09/15 22:44:33 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/09/11 15:41:11 | 00,099,588 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Jason.jpg
[2009/09/11 12:43:19 | 00,100,920 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
[2009/09/10 15:02:28 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/09/10 00:45:15 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk

========== Files - No Company Name ==========
[2009/10/07 01:05:03 | 00,055,312 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\7319_920831000150_1932279_52478078_3350618_n.jpg
[2009/10/07 00:32:13 | 00,035,100 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Katie Brown 23 F.jpg
[2009/10/07 00:31:42 | 00,230,995 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Katie Brown 23 F.pdf
[2009/09/28 15:57:23 | 00,001,518 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/09/28 15:56:56 | 42,506,178 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/09/28 15:56:54 | 00,009,342 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/09/28 15:56:52 | 00,492,629 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/09/28 15:56:49 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/09/15 23:56:42 | 00,001,568 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Frozen Throne.lnk
[2009/09/15 23:11:27 | 00,001,561 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Warcraft III.lnk
[2009/09/15 23:08:19 | 00,125,724 | ---- | C] () -- C:\WINDOWS\War3Unin.dat
[2009/09/15 23:08:18 | 00,002,829 | ---- | C] () -- C:\WINDOWS\War3Unin.pif
[2009/09/15 23:00:18 | 00,000,844 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Alcohol 120%.lnk
[2009/09/15 22:50:27 | 00,001,624 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\DAEMON Tools Lite.lnk
[2009/09/15 22:44:31 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/09/11 15:41:07 | 00,099,588 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Jason.jpg
[2009/08/03 02:06:10 | 00,100,920 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
[2009/05/15 12:40:16 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/05/04 21:32:59 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/05/04 21:32:54 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/05/04 21:32:53 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/05/04 21:32:52 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/05/04 21:32:44 | 00,084,480 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/04/14 12:41:17 | 00,003,087 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate
[2009/02/16 11:08:27 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/01/30 15:37:22 | 00,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2008/12/01 23:31:28 | 00,000,000 | ---- | C] () -- C:\WINDOWS\mtstack16.INI
[2008/07/27 20:54:53 | 00,000,290 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\iPod Access v4 Prefs
[2008/07/27 20:54:11 | 00,000,011 | -H-- | C] () -- C:\Documents and Settings\Owner\Application Data\iPodAccess_Time
[2008/03/24 23:05:43 | 00,061,678 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB
[2008/03/24 23:05:43 | 00,012,358 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
[2008/03/22 19:06:38 | 00,168,448 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/03/19 22:32:20 | 00,100,920 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/03/19 22:16:35 | 00,000,128 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2008/03/18 23:24:47 | 00,000,265 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/03/17 21:46:24 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2004/02/12 21:43:02 | 00,000,309 | ---- | C] () -- C:\WINDOWS\LProST.ini
[2003/04/10 06:35:00 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/04/10 06:34:24 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\iAlmcoin.dll
[2003/04/10 06:21:36 | 00,000,051 | ---- | C] () -- C:\WINDOWS\System32\mshrml.ini
[2003/04/10 03:51:07 | 00,000,438 | ---- | C] () -- C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 03:51:07 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\sunistlog.ini
[2003/04/10 02:32:34 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 02:32:34 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 02:06:10 | 00,167,936 | ---- | C] () -- C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 02:03:38 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2003/04/10 02:03:38 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\syscontr.dll
[2003/04/10 01:57:15 | 00,000,052 | ---- | C] () -- C:\WINDOWS\intuprof.ini
[2003/04/10 01:57:04 | 00,000,608 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2003/04/10 01:16:44 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/04/10 00:55:02 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/04/10 00:51:19 | 02,644,044 | -H-- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2003/04/10 00:44:58 | 00,299,073 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/10 00:44:58 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/10 00:44:29 | 00,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2003/04/10 00:23:21 | 00,000,802 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/04/10 00:22:36 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Owner\Application Data\desktop.ini
[2003/04/10 00:05:45 | 00,000,659 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 00:05:33 | 00,000,689 | ---- | C] () -- C:\WINDOWS\win.ini
[2003/04/10 00:05:31 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/04/09 17:10:07 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2003/03/19 18:50:18 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/03/09 22:31:04 | 00,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2002/05/24 10:00:00 | 00,208,896 | ---- | C] () -- C:\WINDOWS\System32\lockout.dll
[2002/05/24 10:00:00 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\lockres.dll
[2002/01/20 13:04:28 | 00,667,648 | ---- | C] () -- C:\WINDOWS\System32\Dtwain32.dll
[2001/08/14 20:47:08 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\vxpsapi.dll

========== LOP Check ==========

[2009/09/28 15:56:33 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/03/13 00:51:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2008/10/06 19:37:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/05/11 01:13:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/08/05 16:36:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ArcSoft
[2008/03/19 22:32:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/09/15 22:51:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/02/03 14:01:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2009/08/05 17:15:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KEDDS
[2008/03/18 23:35:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Macrovision
[2003/04/10 02:12:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive
[2009/08/05 17:13:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OrbNetworks
[2003/04/10 00:24:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2009/09/09 14:19:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/03/25 22:45:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/04/03 20:33:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/12 16:47:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZipEC
[2009/09/28 15:52:28 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Owner\Application Data
[2008/03/31 22:15:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\.clamwin
[2008/03/25 22:46:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\acccore
[2009/08/05 16:36:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ArcSoft
[2008/03/19 22:36:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Autodesk
[2009/09/29 22:47:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\BitTorrent
[2008/07/27 17:37:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\CopyTrans
[2008/03/24 23:05:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Corel
[2009/09/15 22:55:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\DAEMON Tools Lite
[2009/04/23 13:18:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Desktopicon
[2009/01/17 20:40:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\DNA
[2009/02/02 22:14:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Download Manager
[2009/01/17 20:56:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\GlarySoft
[2003/04/10 06:21:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\interMute
[2003/04/10 01:52:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\InterTrust
[2008/03/22 19:06:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\InterVideo
[2009/08/05 17:18:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\KEDDS
[2009/09/07 10:46:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\LimeWire
[2009/06/27 19:28:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Move Networks
[2009/05/18 15:12:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Red Kawa
[2003/04/10 02:04:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SampleView
[2003/04/10 01:27:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Share-to-Web Upload Folder
[2009/08/05 17:15:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Skinux
[2008/07/26 16:18:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/03/25 22:50:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Viewpoint
[2009/06/13 14:57:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Walgreens
[2009/10/03 14:35:05 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 14:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/09/30 16:23:41 | 00,000,436 | ---- | M] () -- C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2008/07/02 22:28:03 | 00,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1205901545.job
[2009/10/07 16:02:40 | 00,000,390 | ---- | M] () -- C:\WINDOWS\Tasks\GlaryInitialize.job
[2009/10/07 16:02:12 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Custom Scans ==========


< %systemroot%\System32\antiwpa.dll >

< %systemroot%\SYSTEM32\wpa.dll >

< %systemroot%\setup\scripts\biestart.exe >

< %systemroot%\system32\drivers\royal.sys >

< %systemroot%\system32\oobe\AntiWPA_Crypt.dll >

< %TEMP%\antiwpa_crypt.dll >

< %TEMP%\antiwpa.dll /s >

< %PROGRAMFILES%\antiwpa.dll /s >

< %systemroot%\system32\crypt.dll >

< %TEMP%\crypt.dll >

< %SYSTEMDRIVE%\*. >
[2009/07/14 00:08:11 | 00,000,000 | ---D | M] -- C:
[2009/09/28 12:09:34 | 00,000,000 | ---D | M] -- C:\!KillBox
[2009/10/08 06:29:42 | 00,000,000 | -H-D | M] -- C:\$AVG8.VAULT$
[2009/02/02 19:45:55 | 00,000,000 | ---D | M] -- C:\6in1ico
[2009/08/15 15:06:13 | 00,000,000 | ---D | M] -- C:\9f5b6dbca7425d277963e37ae56db791
[2008/03/17 21:51:30 | 00,000,000 | RHSD | M] -- C:\cmdcons
[2009/08/05 17:13:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings
[2009/02/02 19:45:33 | 00,000,000 | -H-D | M] -- C:\hp
[2009/02/02 19:45:45 | 00,000,000 | ---D | M] -- C:\I386
[2009/05/05 14:54:34 | 00,000,000 | ---D | M] -- C:\keep
[2009/09/28 15:56:35 | 00,000,000 | R--D | M] -- C:\Program Files
[2003/04/10 00:45:09 | 00,000,000 | -H-D | M] -- C:\Python22
[2008/03/17 21:52:11 | 00,000,000 | -HSD | M] -- C:\RECYCLER
[2008/03/20 23:52:51 | 00,000,000 | -HSD | M] -- C:\System Volume Information
[2003/04/10 00:44:29 | 00,000,000 | -H-D | M] -- C:\system.sav
[2008/03/19 22:31:06 | 00,000,000 | ---D | M] -- C:\temp
[2009/10/08 01:01:07 | 00,000,000 | ---D | M] -- C:\WINDOWS
[2008/03/17 21:50:12 | 00,000,000 | ---D | M] -- C:\WUTemp

< %SYSTEMDRIVE%\*.* >
[2003/04/10 00:19:17 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2008/03/20 23:11:13 | 00,000,283 | RHS- | M] () -- C:\boot.ini
[2002/08/29 07:00:00 | 00,245,920 | RHS- | M] () -- C:\cmldr
[2003/04/10 00:19:17 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/10/07 16:01:57 | 10,732,70784 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/07 13:28:26 | 00,000,523 | ---- | M] () -- C:\hpfr3420.xml
[2009/10/07 13:28:26 | 00,097,050 | ---- | M] () -- C:\hpfr3425.log
[2009/02/02 19:45:56 | 00,000,661 | -H-- | M] () -- C:\hpothb07.dat
[2009/02/02 19:44:36 | 00,001,243 | -H-- | M] () -- C:\hpothb07.tif
[2003/04/10 00:19:17 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2008/03/25 22:46:03 | 00,000,444 | -H-- | M] () -- C:\IPH.PH
[2009/03/31 00:10:25 | 00,000,032 | ---- | M] () -- C:\IS0.log
[2003/04/10 00:19:17 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/03/20 23:04:10 | 00,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/09/15 20:57:42 | 00,250,048 | RHS- | M] () -- C:\ntldr
[2009/10/07 16:01:55 | 80,530,6368 | -HS- | M] () -- C:\pagefile.sys
[2008/03/17 21:50:02 | 00,000,556 | ---- | M] () -- C:\remind.log

< %PROGRAMFILES%\*. >
[2009/09/28 15:56:35 | 00,000,000 | R--D | M] -- C:\Program Files
[2008/03/31 22:54:02 | 00,000,000 | ---D | M] -- C:\Program Files\3DO
[2009/04/03 20:21:49 | 00,000,000 | ---D | M] -- C:\Program Files\7-Zip
[2009/01/30 15:36:56 | 00,000,000 | ---D | M] -- C:\Program Files\Acro Software
[2009/09/09 18:40:57 | 00,000,000 | ---D | M] -- C:\Program Files\Adobe
[2008/03/25 22:46:02 | 00,000,000 | ---D | M] -- C:\Program Files\AIM6
[2009/09/15 23:00:14 | 00,000,000 | ---D | M] -- C:\Program Files\Alcohol Soft
[2008/03/19 22:15:47 | 00,000,000 | ---D | M] -- C:\Program Files\AnswerWorks 4.0
[2009/03/27 13:32:30 | 00,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2009/08/05 16:35:20 | 00,000,000 | ---D | M] -- C:\Program Files\ArcSoft
[2008/03/19 22:16:53 | 00,000,000 | ---D | M] -- C:\Program Files\AutoCAD 2005
[2008/03/19 22:17:24 | 00,000,000 | ---D | M] -- C:\Program Files\Autodesk
[2009/09/28 15:56:35 | 00,000,000 | ---D | M] -- C:\Program Files\AVG
[2009/05/15 13:01:51 | 00,000,000 | ---D | M] -- C:\Program Files\AviSynth 2.5
[2003/04/10 06:22:08 | 00,000,000 | ---D | M] -- C:\Program Files\AWS
[2003/04/10 02:03:59 | 00,000,000 | ---D | M] -- C:\Program Files\BackWeb
[2008/08/03 19:36:03 | 00,000,000 | ---D | M] -- C:\Program Files\BitTorrent
[2009/03/13 00:36:01 | 00,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2008/03/31 22:13:48 | 00,000,000 | ---D | M] -- C:\Program Files\ClamWin
[2009/08/05 16:35:19 | 00,000,000 | ---D | M] -- C:\Program Files\Common Files
[2003/04/10 00:15:53 | 00,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2003/04/10 01:54:19 | 00,000,000 | ---D | M] -- C:\Program Files\Corel
[2009/09/15 22:50:33 | 00,000,000 | ---D | M] -- C:\Program Files\DAEMON Tools Lite
[2009/09/15 22:50:32 | 00,000,000 | ---D | M] -- C:\Program Files\DAEMON Tools Toolbar
[2009/07/25 18:06:37 | 00,000,000 | ---D | M] -- C:\Program Files\Dearborn
[2009/06/11 10:47:57 | 00,000,000 | ---D | M] -- C:\Program Files\Desktop Calendar
[2008/03/31 22:22:12 | 00,000,000 | ---D | M] -- C:\Program Files\directx
[2009/04/04 11:10:36 | 00,000,000 | ---D | M] -- C:\Program Files\DivX
[2008/08/30 16:13:06 | 00,000,000 | ---D | M] -- C:\Program Files\DNA
[2008/04/16 22:08:28 | 00,000,000 | ---D | M] -- C:\Program Files\Easy Internet signup
[2009/09/28 15:49:17 | 00,000,000 | ---D | M] -- C:\Program Files\File Shredder
[2008/04/12 11:39:40 | 00,000,000 | ---D | M] -- C:\Program Files\Google
[2009/01/30 15:39:05 | 00,000,000 | ---D | M] -- C:\Program Files\GPLGS
[2003/04/10 01:26:34 | 00,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2003/04/10 02:12:29 | 00,000,000 | ---D | M] -- C:\Program Files\HP Instant Support
[2003/04/10 01:23:02 | 00,000,000 | ---D | M] -- C:\Program Files\HP Photosmart 11
[2008/03/24 19:03:26 | 00,000,000 | ---D | M] -- C:\Program Files\IEAK
[2009/08/05 16:37:25 | 00,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2003/04/10 01:51:34 | 00,000,000 | ---D | M] -- C:\Program Files\IntelliMover Data Transfer Demo
[2003/04/10 06:21:36 | 00,000,000 | ---D | M] -- C:\Program Files\interMute
[2009/07/29 15:07:45 | 00,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2003/04/10 01:34:26 | 00,000,000 | ---D | M] -- C:\Program Files\InterVideo
[2009/06/18 19:53:14 | 00,000,000 | ---D | M] -- C:\Program Files\iPod
[2009/06/18 19:53:41 | 00,000,000 | ---D | M] -- C:\Program Files\iTunes
[2009/08/05 17:30:10 | 00,000,000 | ---D | M] -- C:\Program Files\Java
[2009/05/04 21:34:16 | 00,000,000 | ---D | M] -- C:\Program Files\K-Lite Codec Pack
[2009/08/05 16:34:40 | 00,000,000 | ---D | M] -- C:\Program Files\Kodak
[2009/06/29 17:30:55 | 00,000,000 | ---D | M] -- C:\Program Files\LabelCreator Pro
[2008/03/27 22:01:54 | 00,000,000 | ---D | M] -- C:\Program Files\LimeWire
[2009/03/31 00:10:17 | 00,000,000 | ---D | M] -- C:\Program Files\Linksys
[2009/02/11 16:20:30 | 00,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/09/16 00:33:54 | 00,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/05/15 12:38:33 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2003/04/10 00:19:32 | 00,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2009/07/14 13:03:26 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2009/09/10 15:12:56 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2008/09/15 21:10:11 | 00,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2009/10/07 16:09:23 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009/08/15 15:06:45 | 00,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2009/07/14 13:03:00 | 00,000,000 | ---D | M] -- C:\Program Files\MSECache
[2003/04/10 02:39:46 | 00,000,000 | ---D | M] -- C:\Program Files\MSN
[2003/04/10 00:14:54 | 00,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2008/03/21 19:20:25 | 00,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2003/04/10 01:38:24 | 00,000,000 | ---D | M] -- C:\Program Files\MUSICMATCH
[2008/09/15 21:03:33 | 00,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2009/04/14 12:41:22 | 00,000,000 | ---D | M] -- C:\Program Files\Norton 360
[2009/02/02 12:11:59 | 00,000,000 | ---D | M] -- C:\Program Files\NOS
[2003/04/10 02:41:11 | 00,000,000 | ---D | M] -- C:\Program Files\Online Services
[2009/03/03 09:46:30 | 00,000,000 | ---D | M] -- C:\Program Files\Orban
[2008/03/24 19:02:46 | 00,000,000 | ---D | M] -- C:\Program Files\ORKTools
[2009/08/13 15:04:22 | 00,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2003/04/10 02:33:00 | 00,000,000 | ---D | M] -- C:\Program Files\PC-Doctor for Windows
[2009/06/05 16:38:15 | 00,000,000 | ---D | M] -- C:\Program Files\PokerStars
[2009/04/14 13:01:15 | 00,000,000 | ---D | M] -- C:\Program Files\Quicken
[2009/06/18 19:51:36 | 00,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2003/04/10 01:36:49 | 00,000,000 | ---D | M] -- C:\Program Files\Real
[2003/04/10 01:35:19 | 00,000,000 | ---D | M] -- C:\Program Files\RecordNow
[2009/05/15 13:01:43 | 00,000,000 | ---D | M] -- C:\Program Files\Red Kawa
[2009/08/15 15:06:29 | 00,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2009/05/15 13:01:55 | 00,000,000 | ---D | M] -- C:\Program Files\Regensoft
[2003/04/10 01:49:39 | 00,000,000 | ---D | M] -- C:\Program Files\Simple Backup for My Pictures
[2003/04/10 06:20:31 | 00,000,000 | ---D | M] -- C:\Program Files\Softex
[2009/07/02 16:55:33 | 00,000,000 | ---D | M] -- C:\Program Files\Starfield
[2009/04/14 12:41:14 | 00,000,000 | ---D | M] -- C:\Program Files\Symantec
[2008/07/27 17:04:36 | 00,000,000 | ---D | M] -- C:\Program Files\Tansee iPod Transfer
[2008/03/19 22:17:33 | 00,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2003/04/10 02:04:00 | 00,000,000 | ---D | M] -- C:\Program Files\Updates from HP
[2008/03/25 22:45:51 | 00,000,000 | ---D | M] -- C:\Program Files\Viewpoint
[2003/04/10 01:40:47 | 00,000,000 | ---D | M] -- C:\Program Files\WildTangent
[2008/07/31 19:55:09 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2008/09/15 21:03:26 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/09/15 21:03:25 | 00,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2008/03/17 22:39:40 | 00,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2009/02/12 16:47:05 | 00,000,000 | ---D | M] -- C:\Program Files\WinZip E-Mail Companion
[2003/04/10 00:19:32 | 00,000,000 | ---D | M] -- C:\Program Files\xerox

< %systemroot%\system32\drivers\*.dat >

< %PROGRAMFILES%\*.* >

< %PROGRAMFILES%\*.exe >

Invalid Environment Variable: DESKTOP

< %USERNAME%\*.exe >

< %USERPROFILE%\*.exe >

< %ALLUSERSPROFILE%\*.exe >

< %SYSTEMDRIVE%\*.exe >

< %SYSTEMROOT%\*.exe >
[2004/09/07 14:47:52 | 00,057,344 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\ALCXMNTR.EXE
[2003/04/10 02:03:59 | 00,090,112 | R--- | M] () -- C:\WINDOWS\bwUnin-6.2.3.66.exe
[2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2008/04/13 19:12:21 | 00,010,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\hh.exe
[2002/11/14 10:09:12 | 00,036,864 | ---- | M] () -- C:\WINDOWS\hpfsched.exe
[1998/10/29 23:45:06 | 00,306,688 | ---- | M] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[2008/04/13 19:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
[2008/04/13 19:12:32 | 00,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\regedit.exe
[2003/02/28 19:26:30 | 00,046,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\setdebug.exe
[2008/04/13 19:12:35 | 00,032,866 | ---- | M] (Smart Link) -- C:\WINDOWS\slrundll.exe
[2002/08/29 07:00:00 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE
[2002/08/29 07:00:00 | 00,049,680 | ---- | M] (Twain Working Group) -- C:\WINDOWS\twunk_16.exe
[2002/08/29 07:00:00 | 00,025,600 | ---- | M] (Twain Working Group) -- C:\WINDOWS\twunk_32.exe
[2009/09/15 23:56:35 | 00,139,264 | ---- | M] (Blizzard Entertainment) -- C:\WINDOWS\War3Unin.exe
[2002/08/29 07:00:00 | 00,256,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winhelp.exe
[2008/04/13 19:12:39 | 00,283,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winhlp32.exe
[1 C:\WINDOWS\*.tmp files]

< %systemroot%\system32\drivers\*.exe >

< %systemroot%\system\*.exe >
[1998/05/07 18:04:38 | 00,052,736 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system\hpsysdrv.exe

< %systemroot%\AppPatch\*.exe >

< %systemroot%\Cache\*.exe >

< %systemroot%\Downloaded Program Files\*.exe >
[2007/11/20 17:04:32 | 01,523,536 | ---- | M] () -- C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
[2008/03/25 22:45:33 | 00,038,428 | ---- | M] () -- C:\WINDOWS\Downloaded Program Files\unagiuninst.exe

< %systemroot%\Fonts\*.exe >

< %systemroot%\Help\*.exe >

< %APPDATA%\*.exe >

< %APPDATA%\Google\*.exe >

< %systemroot%\system32\inf\*.exe >

< %APPDATA%\Opera\Opera\profile\widgets\*.exe >

< %PROGRAMFILES%\Opera\program\plugins\*.exe >

< %APPDATA%\Opera\Opera\profile\toolbar\*.exe >

< %systemroot%\Web\*.exe >

< %systemroot%\Wbem\*.exe >

< %systemroot%\twain_32\*.exe >

< %systemroot%\WinSxS\*.exe >

< %systemroot%\Sun\*.exe >

< %systemroot%\srchasst\*.exe >

< %systemroot%\Shellnew\*.exe >

< %systemroot%\Security\*.exe >

< %systemroot%\Resources\*.exe >

< %systemroot%\Repair\*.exe >

< %systemroot%\Registration\*.exe >

< %systemroot%\RegisteredPackages\*.exe >

< %systemroot%\pss\*.exe >

< %systemroot%\Provisioning\*.exe >

< %systemroot%\PIF\*.exe >

< %systemroot%\PeerNet\*.exe >

< %systemroot%\PcTel\*.exe >

< %systemroot%\Offline Web Pages\*.exe >

< %systemroot%\network diagnostic\*.exe >
[2008/04/13 13:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\network diagnostic\xpnetdiag.exe

< %systemroot%\mui\*.exe >

< %systemroot%\msapps\*.exe >

< %systemroot%\msagent\*.exe >
[2008/04/13 19:12:12 | 00,256,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\msagent\agentsvr.exe

< %systemroot%\minidump\*.exe >

< %systemroot%\media\*.exe >

< %systemroot%\Help\*.exe >

< %systemroot%\ie7\*.exe >

< %systemroot%\ie7updates\*.exe >

< %systemroot%\ime\*.exe >

< %systemroot%\installer\*.exe >

< %systemroot%\internet logs\*.exe >

< %systemroot%\Cursors\*.exe >

< %systemroot%\Config\*.exe >

< %systemroot%\internet logs\*.exe >

< %systemroot%\Assembly\*.exe >

< %systemroot%\internet logs\*.exe >

< %systemroot%\AppPatch\*.exe >

< %systemroot%\l2schemas\*.exe >

< %systemroot%\Debug\*.exe >

< %systemroot%\ehome\*.exe >

< %systemroot%\Connection Wizard\*.exe >

< %systemroot%\system32\1025\*.exe >

< %systemroot%\system32\1028\*.exe >

< %systemroot%\system32\1031\*.exe >

< %systemroot%\system32\1033\*.exe >

< %systemroot%\system32\1037\*.exe >

< %systemroot%\system32\1041\*.exe >

< %systemroot%\system32\1042\*.exe >

< %systemroot%\system32\1054\*.exe >

< %systemroot%\system32\2052\*.exe >

< %systemroot%\system32\3076\*.exe >

< %systemroot%\system32\appmgmt\*.exe >

< %systemroot%\system32\bits\*.exe >

< %systemroot%\system32\catroot\*.exe >

< %systemroot%\system32\catroot2\*.exe >

< %systemroot%\system32\com\*.exe >
[2008/04/13 19:12:15 | 00,009,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\com\comrepl.exe
[2008/04/13 19:12:15 | 00,006,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\com\comrereg.exe

< %systemroot%\system32\config\*.exe >

< %systemroot%\system32\dhcp\*.exe >

< %systemroot%\system32\DirectX\*.exe >

< %systemroot%\system32\drvstore\*.exe >

< %systemroot%\system32\en\*.exe >

< %systemroot%\system32\en-us\*.exe >

< %systemroot%\system32\export\*.exe >

< %systemroot%\system32\GroupPolicy\*.exe >

< %systemroot%\system32\ias\*.exe >

< %systemroot%\system32\icsxml\*.exe >

< %systemroot%\system32\ime\*.exe >

< %systemroot%\system32\inetsrv\*.exe >

< %systemroot%\system32\LogFiles\*.exe >

< %systemroot%\system32\Macromed\*.exe >

< %systemroot%\system32\Microsoft\*.exe >

< %systemroot%\system32\Msdtc\*.exe >

< %systemroot%\system32\Mui\*.exe >

< %systemroot%\system32\npp\*.exe >
[2008/04/13 19:12:29 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\npp\nppagent.exe

< %systemroot%\system32\NtMsData\*.exe >

< %systemroot%\system32\oobe\*.exe >
[2008/04/13 19:12:28 | 00,029,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oobe\msoobe.exe
[2008/04/13 19:12:31 | 00,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oobe\oobebaln.exe

< %systemroot%\system32\PreInstall\*.exe >

< %systemroot%\system32\ras\*.exe >

< %systemroot%\system32\ReInstallBackups\*.exe >

< %systemroot%\system32\Restore\*.exe >
[2008/04/13 19:12:33 | 00,380,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Restore\rstrui.exe
[2002/08/29 07:00:00 | 00,047,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Restore\srdiag.exe

< %systemroot%\system32\Scripting\*.exe >

< %systemroot%\system32\Setup\*.exe >

< %systemroot%\system32\ShellExt\*.exe >

< %systemroot%\system32\SoftwareDistribution\*.exe >

< %systemroot%\system32\URTTEmp\*.exe >
[2003/02/21 06:16:08 | 00,049,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\URTTEmp\regtlib.exe

< %systemroot%\system32\USMT\*.exe >
[2008/04/13 19:12:25 | 00,103,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\USMT\migload.exe
[2008/04/13 19:12:25 | 00,245,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\USMT\migwiz.exe
[2008/04/13 19:12:25 | 00,241,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\USMT\migwiza.exe
[2004/08/04 02:56:51 | 00,236,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\USMT\migwiz_a.exe

< %systemroot%\system32\Wbem\*.exe >
[2008/04/13 19:12:26 | 00,016,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\mofcomp.exe
[2008/04/13 19:12:34 | 00,036,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\scrcons.exe
[2002/08/29 07:00:00 | 00,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\unsecapp.exe
[2008/04/13 19:12:39 | 00,116,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\wbemtest.exe
[2002/08/29 07:00:00 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\winmgmt.exe
[2008/04/13 19:12:40 | 00,196,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\wmiadap.exe
[2008/04/13 19:12:40 | 00,126,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\wmiapsrv.exe
[2009/02/06 05:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Wbem\wmiprvse.exe

< %systemroot%\system32\Wins\*.exe >

< %systemroot%\system32\Xircom\*.exe >

< %systemroot%\system32\XPSViewer\*.exe >
[2008/07/29 21:26:06 | 00,301,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\XPSViewer\XPSViewer.exe

< %COMMONPROGRAMFILES%\*.exe >

< %APPDATA%\*.* >
[2003/04/09 17:10:07 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Owner\Application Data\desktop.ini
[2009/09/11 12:43:19 | 00,100,920 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
[2008/07/27 20:54:53 | 00,000,290 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\iPod Access v4 Prefs
[2008/07/27 20:54:11 | 00,000,011 | -H-- | M] () -- C:\Documents and Settings\Owner\Application Data\iPodAccess_Time
[2008/03/24 23:05:43 | 00,012,358 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
[2008/03/24 23:05:43 | 00,061,678 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB

< %TEMP%\*.* >
[2009/09/11 12:20:07 | 00,015,830 | R--- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\06207175.cab
[2009/07/25 18:06:41 | 00,212,992 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\2890.rra
[2009/06/10 00:24:34 | 00,000,690 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\4_4900.CSV
[2009/06/10 16:54:57 | 00,537,600 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\5fa655.mst
[2009/08/05 16:23:25 | 01,179,648 | ---- | M] (Eastman Kodak Company) -- C:\DOCUME~1\Owner\LOCALS~1\Temp\7.6.20.1-EasyShrx.Dll
[2009/08/05 16:24:01 | 01,187,840 | ---- | M] (Eastman Kodak Company) -- C:\DOCUME~1\Owner\LOCALS~1\Temp\8.0.20.1-EasyShrx.Dll
[2009/06/10 00:23:03 | 00,020,937 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\A$C4CFB5B50.DWG
[2009/06/09 23:41:07 | 00,050,999 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\A$C578435DC.DWG
[2009/08/04 18:07:04 | 00,046,080 | ---- | M] (Macrovision Europe Ltd.) -- C:\DOCUME~1\Owner\LOCALS~1\Temp\AdskCleanup.0001
[2009/09/15 15:33:57 | 00,045,012 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\alm.log
[2009/09/15 15:33:57 | 00,049,274 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\amt.log
[2009/08/27 14:04:03 | 00,000,328 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\amtconfig.log
[2009/05/15 12:53:09 | 00,005,144 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ASPNETSetup_00000.log
[2009/09/28 15:57:33 | 00,064,731 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\avg8inst.log
[2009/08/05 17:25:20 | 01,780,224 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\b9e4e.mst
[2009/07/22 23:03:40 | 00,000,051 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Briska-02-FINAL-072209-updated_1_1_0560.dwl
[2009/07/22 23:14:00 | 00,340,670 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Briska-02-FINAL-072209-updated_1_1_0560.sv$
[2009/07/22 21:06:11 | 00,313,080 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Briska-02-FINAL-072209_1_1_5372.bak
[2009/10/07 21:13:08 | 00,000,706 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ClamWin1.log
[2009/10/07 15:11:19 | 00,000,714 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ClamWin3.log
[2009/10/07 16:48:49 | 00,000,012 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ClamWin_CheckVer_Info
[2009/10/07 16:48:49 | 00,000,012 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ClamWin_CheckVer_Time
[2009/10/07 21:13:04 | 00,000,013 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ClamWin_Scheduler_Info
[2009/10/07 21:13:04 | 00,000,013 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ClamWin_Upadte_Time
[2009/07/14 00:07:11 | 01,642,443 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\CLF-contract-JPEG-070409-1.jpg
[2009/07/14 00:06:17 | 01,830,598 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\CLF-process-JPEG-070409.jpg
[2009/09/15 23:57:01 | 00,036,864 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\CmdLineExt02.dll
[2009/07/14 13:03:42 | 01,264,246 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Compatibility Pack for the 2007 Office system (0).log
[2009/05/15 12:55:32 | 04,991,158 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\dd_netfx20MSI4650.txt
[2009/05/15 13:01:42 | 00,020,620 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\dd_netfx20UI4650.txt
[2009/06/09 23:37:38 | 00,000,049 | -H-- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Drawing1_1_1_0717.dwl
[2009/06/09 23:37:38 | 00,022,637 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Drawing1_1_1_0717.sv$
[2009/05/21 10:01:46 | 00,026,317 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Drawing1_1_1_2583.bak
[2009/06/10 00:33:58 | 00,000,051 | -H-- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Drawing2_1_1_8328.dwl
[2009/06/10 00:33:58 | 00,044,398 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Drawing2_1_1_8328.sv$
[2009/09/21 23:25:38 | 00,000,000 | -H-- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_fqnHlUF2rlvhZoyZhowq
[2009/05/12 01:23:48 | 00,000,000 | -H-- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_jzeBdt3PFpiRgquWh1JX
[2009/05/11 23:21:00 | 00,001,024 | -H-- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_keKzinOWDHzGbAHh6asW
[2009/05/12 01:24:03 | 00,000,512 | -H-- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_keKzinOWDHzGbAHh6asW-journal
[2008/02/15 03:44:34 | 00,452,916 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\free-downloads.xpi
[2003/04/10 02:03:59 | 00,024,576 | ---- | M] (BackWeb) -- C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll
[2009/04/14 12:39:52 | 00,002,600 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\IDSinst.LOG
[2009/06/18 20:10:46 | 00,002,025 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\iTunesSetupCE8.log
[2009/10/07 01:34:30 | 00,028,341 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\java_install_reg.log
[2009/08/05 17:25:46 | 00,002,603 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\java_install_sp.log
[2009/08/05 17:24:14 | 00,000,934 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\jinstall.cfg
[2009/05/22 22:33:55 | 00,236,440 | ---- | M] (Sun Microsystems, Inc.) -- C:\DOCUME~1\Owner\LOCALS~1\Temp\jre-6u14-windows-i586-iftw-rv.exe
[2009/08/01 12:29:47 | 00,714,528 | ---- | M] (Sun Microsystems, Inc.) -- C:\DOCUME~1\Owner\LOCALS~1\Temp\jre-6u15-windows-i586-iftw.exe
[2009/10/08 09:30:20 | 00,156,484 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\jusched.log
[2009/08/18 13:54:58 | 00,084,119 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\moz-screenshot-1.jpg
[2009/06/19 09:22:49 | 00,015,194 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\moz-screenshot.jpg
[2009/10/07 00:29:07 | 00,452,111 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\moz-screenshot.png
[2009/04/28 21:48:38 | 00,001,294 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\MSIc52c4.LOG
[2009/04/28 21:49:49 | 00,000,494 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\MSIc52c5.LOG
[2009/04/28 23:20:02 | 00,000,494 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\MSIc52c6.LOG
[2009/04/14 12:41:22 | 07,231,834 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Norton 360 4-14-2009 12h32m35s.log
[2009/04/14 13:00:04 | 00,297,136 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Norton Setup 1,3,0 4-14-2009 12h32m26s.log
[2009/05/15 12:36:40 | 00,034,057 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\offcln10.log
[2009/05/15 12:44:48 | 00,004,224 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Office XP Professional with FrontPage Setup(0001).txt
[2009/05/15 12:40:19 | 11,437,136 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Office XP Professional with FrontPage Setup(0001)_Task(0001).txt
[2009/09/21 23:58:53 | 00,016,384 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_224.dat
[2009/05/05 15:08:47 | 00,016,384 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_22c.dat
[2009/05/11 09:17:28 | 00,016,384 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_2f8.dat
[2009/05/05 21:58:39 | 00,016,384 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_7c4.dat
[2009/05/04 21:35:41 | 00,016,384 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_7e8.dat
[2009/10/07 16:03:01 | 00,016,384 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_adc.dat
[2009/09/21 22:28:19 | 00,016,384 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_e4.dat
[2009/05/12 23:09:45 | 15,122,4320 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Photoshop Temp8040278
[2009/08/17 18:13:30 | 00,013,716 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\QTInstallCode.log
[2009/09/09 00:48:04 | 00,004,053 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\qtplugin.log
[2009/07/08 16:02:34 | 00,054,960 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\RDlMzX40.jpg.part
[2009/06/10 00:15:52 | 00,000,000 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\REDO.ac$
[2009/08/13 17:48:13 | 00,044,032 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SARTZ Application Form.doc
[2009/08/13 17:57:28 | 00,031,744 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Sartz Letter.doc
[2009/05/04 21:34:16 | 00,070,169 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Setup Log 2009-05-04 #001.txt
[2009/05/11 01:11:31 | 00,000,085 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SetupAdmin1FC.log
[2009/06/18 19:51:55 | 05,469,900 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SetupAdminD00.log
[2009/07/22 12:57:53 | 00,001,918 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Silverlight0.log
[2009/07/22 12:57:53 | 00,467,356 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SilverlightMSI.log
[2009/09/15 23:57:01 | 00,012,067 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SIntf16.dll
[2009/09/15 23:57:01 | 00,019,924 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SIntf32.dll
[2009/09/15 23:57:01 | 00,024,516 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SIntfNT.dll
[2009/06/11 02:27:06 | 00,162,998 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SketchUpUndo0.log
[2009/04/14 12:40:03 | 00,005,188 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SNDunin.log
[2008/06/04 00:43:35 | 00,000,284 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\srtspse.dat
[2008/06/04 00:43:35 | 00,002,204 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\srtspso.dat
[2008/06/04 00:43:35 | 00,000,524 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\srtspsp.dat
[2009/04/14 12:35:41 | 00,009,830 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\srtUnin.log
[2009/06/09 23:49:45 | 00,000,049 | -H-- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Stinsa_1_1_4998.dwl
[2009/06/09 23:49:45 | 01,771,772 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Stinsa_1_1_4998.sv$
[2009/06/10 00:26:58 | 00,000,051 | -H-- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SWAMP_1_1_5008.dwl
[2009/06/10 00:26:58 | 00,129,772 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SWAMP_1_1_5008.sv$
[2009/06/09 23:51:30 | 00,000,049 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SWAMP_1_1_5244.dwl
[2009/06/09 23:37:22 | 00,000,049 | -H-- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SWAMP_1_1_7088.dwl
[2009/06/11 19:20:00 | 00,092,571 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SWAMP_1_1_7617.bak
[2009/06/18 19:02:00 | 00,032,768 | ---- | M] (Eclipse Foundation) -- C:\DOCUME~1\Owner\LOCALS~1\Temp\swt-awt-win32-3346.dll
[2009/06/18 19:01:59 | 00,307,200 | ---- | M] (Eclipse Foundation) -- C:\DOCUME~1\Owner\LOCALS~1\Temp\swt-win32-3346.dll
[2009/09/15 15:33:54 | 00,012,603 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\swtag.log
[2009/04/14 12:41:16 | 00,013,975 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SYMEVENT.LOG
[2009/04/14 12:38:07 | 01,174,664 | ---- | M] (Symantec Corporation) -- C:\DOCUME~1\Owner\LOCALS~1\Temp\SymLCSVC.EXE
[2009/10/07 00:30:04 | 00,001,101 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\TWAIN.LOG
[2009/10/07 00:30:04 | 00,000,004 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Twain001.Mtx
[2009/10/07 00:30:03 | 00,000,156 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Twunk001.MTX
[2009/04/24 22:32:07 | 00,000,000 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\Twunk002.MTX
[2009/06/09 23:38:19 | 00,000,000 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\UND6B2B4.ac$
[2009/06/10 15:09:49 | 00,372,602 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\UNDB595A.ac$
[2009/06/10 00:23:09 | 00,000,000 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\UNDD6569.ac$
[2009/07/22 23:22:18 | 00,409,600 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\UNDE31DD.ac$
[2009/06/09 13:11:07 | 00,000,000 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\UNDO.ac$
[2009/08/05 16:24:02 | 00,057,344 | ---- | M] (WinAbility® Software Corporation) -- C:\DOCUME~1\Owner\LOCALS~1\Temp\VistaLib32_1.dll
[2006/10/11 14:10:06 | 00,000,041 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\walgreens_cache_dir_name.txt
[2009/10/05 14:24:58 | 00,001,668 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\wmplog00.sqm
[2009/05/26 12:12:30 | 00,000,101 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ws_ProdProf_20090521_0.log
[2009/06/09 13:11:11 | 00,000,152 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ws_ProdProf_20090609_0.log
[2009/06/10 23:58:32 | 00,000,202 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ws_ProdProf_20090610_0.log
[2009/06/11 19:41:57 | 00,000,101 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ws_ProdProf_20090611_0.log
[2009/07/01 00:57:35 | 00,000,101 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ws_ProdProf_20090630_0.log
[2009/07/17 13:32:06 | 00,000,101 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ws_ProdProf_20090717_0.log
[2009/07/22 23:23:05 | 00,000,101 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ws_ProdProf_20090722_0.log
[2009/08/04 23:43:52 | 00,000,101 | ---- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\ws_ProdProf_20090804_0.log
[2009/08/13 17:51:18 | 00,000,162 | -H-- | M] () -- C:\DOCUME~1\Owner\LOCALS~1\Temp\~$FMCustom.dot
[899 C:\DOCUME~1\Owner\LOCALS~1\Temp\*.tmp files]

< set /c >
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Owner\Application Data
CLASSPATH=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=HARVEY
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Owner
LOGONSERVER=\\HARVEY
MOZ_CRASHREPORTER_DATA_DIRECTORY=C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Crash Reports
MOZ_CRASHREPORTER_RESTART_ARG_0=C:\Program Files\Mozilla Firefox\firefox.exe
MOZ_CRASHREPORTER_STRINGS_OVERRIDE=C:\Program Files\Mozilla Firefox\crashreporter-override.ini
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\plug_ins;C:\Program Files\Adobe\Acrobat 9.0\Acrobat\;C:\Program Files\Mozilla Firefox;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\Common Files\Autodesk Shared\;C:\Program Files\Common Files\DivX Shared\;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PCToolsDir=C:\Documents and Settings\All Users\Start Menu\Programs\Hewlett-Packard\HP Pavilion PC Tools
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 7, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0207
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Owner\LOCALS~1\Temp
TMP=C:\DOCUME~1\Owner\LOCALS~1\Temp
USERDOMAIN=HARVEY
USERNAME=Owner
USERPROFILE=C:\Documents and Settings\Owner
windir=C:\WINDOWS
< End of report >



Extras.Txt
OTL Extras logfile created on: 10/8/2009 2:10:09 PM - Run 1
OTL by OldTimer - Version 3.0.18.4 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.48 Mb Total Physical Memory | 463.29 Mb Available Physical Memory | 45.27% Memory free
1.66 Gb Paging File | 0.88 Gb Available in Paging File | 53.37% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.34 Gb Total Space | 3.75 Gb Free Space | 3.50% Space Free | Partition Type: NTFS
Drive D: | 4.43 Gb Total Space | 0.68 Gb Free Space | 15.23% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 1.83 Gb Total Space | 1.73 Gb Free Space | 94.26% Space Free | Partition Type: FAT
Drive M: | 521.62 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive N: | 232.83 Gb Total Space | 14.38 Gb Free Space | 6.17% Space Free | Partition Type: FAT32

Computer Name: HARVEY
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.scr [@ = AutoCADScriptFile] -- C:\WINDOWS\notepad.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- ()
"C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe" = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe:*:Disabled:BackWeb-137903 -- ()
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\Kodak\Digital Display\KodakDigitalDisplaySoftware.exe" = C:\Program Files\Kodak\Digital Display\KodakDigitalDisplaySoftware.exe:*:Enabled:Kodak digital display software -- (Orb Networks, Inc.)
"C:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe" = C:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe:*:Enabled:KodakDigitalDisplayService -- (Orb Networks, Inc.)
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare -- (Eastman Kodak Company)
"C:\Documents and Settings\Owner\Desktop\Warcraft III\Warcraft III\Warcraft III.exe" = C:\Documents and Settings\Owner\Desktop\Warcraft III\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- File not found
"C:\Documents and Settings\Owner\Desktop\Warcraft III\Warcraft III.exe" = C:\Documents and Settings\Owner\Desktop\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- (Blizzard Entertainment)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary -- (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{0613467F-A45E-4CB1-9ECE-1F3DD79FB927}" = easy Internet sign-up
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{1028298A-31E5-4881-BF14-749E1822D95B}" = Desktop Notifier
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 15
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Productivity Pack
"{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E90FA5-2CB4-4039-A8BB-BE1B9DB94E21}" = HP Memories Disc
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{47D4AF7B-EDE6-4ADB-8D2F-0BDA25C7321F}" = HP Digital Imaging Album Printing 1.0
"{48BD24F5-13DE-493A-A7CE-28A85113FF0C}" = HP Deskjet printer preloaded drivers
"{4F5FC172-F0E7-4EA5-902F-8D005DF9F000}" = HP Photo and Imaging 1.2 - Photosmart Cameras
"{4FCC384C-18EA-4E25-9281-A06AE006D219}" = Weblink
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{5783F2D7-0301-0409-0002-0060B0CE6BBA}" = AutoCAD 2005 - English
"{5C6956F3-B586-4674-BCD0-CCF7EC1DF766}" = Wireless PCI Card Configuration Utility
"{5D601655-6D54-4384-B52C-17EC5385FBBD}" = iTunes
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{60E80B13-8649-4A69-85E2-1AE99E061F43}" = ShowBiz DVD
"{60E971B7-51A0-48CA-8687-C6B8F094A409}" = Simple Backup for My Pictures
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{8214CC02-6271-4DC8-B8DD-779933450264}" = RecordNow
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{96BB10E8-85D4-45A8-862C-5A068C90157C}" = Online File Folder Edit Tool v12
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD Player
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{9E88DAA4-1352-4272-BA3A-897668408400}" = HP Photosmart printers preloaded drivers
"{9E9AEBE7-58A9-11D8-80AE-00036D10F3B7}" = LabelCreator Pro
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}_913" = Adobe Acrobat 9.1.3 - CPSID_49522
"{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}" = Google SketchUp 6
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C7B99334-41CC-445A-AF7B-A210691A72AD}" = KEDDS
"{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DB0A8A2A-4EA7-4FE3-802E-8A6DEE32696C}_is1" = Orban/Coding Technologies AAC/aacPlus Player Plugin™ 1.0
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DDBB28C8-B2AA-45A1-8DCE-059A798509FB}" = MobileMe Control Panel
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{EEF397AC-DAEF-4C04-90A9-5B2BD31875DC}" = Simple Installer - Multilanguage Version
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}" = OmniPass
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FA6D2A38-0653-4518-B17E-46F6BAF0AEEB}" = Series 7 Drill and Practice
"1ABC286C-DE10-4590-BEFF-4D0DFF5EA1EC" = GemMaster 3 from Hewlett-Packard Desktops (remove only)
"28BA89E7-2F60-4BE7-BAA2-7949EB3FE527" = BlasterBall Wild from Hewlett-Packard Desktops (remove only)
"357ECB62-CD36-4B63-B57E-769D0CA174F4" = Blasterball 2 from Hewlett-Packard Desktops (remove only)
"3EA6838C-5C34-4F9C-A8DA-434D65DD1356" = Men In Black II CROSSFIRE from Hewlett-Packard Desktops (remove only)
"4F0AE1FB-4082-4A27-8363-05D292D92FB0" = Virtual Warfare from Hewlett-Packard Desktops (remove only)
"5415BC25-6D6C-46C4-B34C-EA8470FE56D5" = Blackhawk Striker from Hewlett-Packard Desktops (remove only)
"63272979-21F0-48EF-9B97-A83DBC05BE39" = Disney`s Lilo and Stitch Pinball from Hewlett-Packard Desktops (remove only)
"753FE96B-D926-4B6C-BCFB-CC59153D004A" = Snowboard Extreme from Hewlett-Packard Desktops (remove only)
"7841B68B-B7DD-408E-8B45-D5CA39608185" = Dark Orbit from Hewlett-Packard Desktops (remove only)
"7-Zip" = 7-Zip 4.65
"9FA01E11-9015-4140-B10A-5C6AA949B2FC" = Space Rocks from Hewlett-Packard Desktops (remove only)
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIM_6" = AIM 6
"ArcSoft Software Suite" = ArcSoft Picture Software
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"AVG8Uninstall" = AVG Free 8.5
"AviSynth" = AviSynth 2.5
"BackWeb-137903 Uninstaller" = Updates from HP
"ClamWin Free Antivirus_is1" = ClamWin Free Antivirus 0.92
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CutePDF Writer Installation" = CutePDF Writer 2.7
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Desktop Calendar_is1" = Desktop Calendar 0.42b
"DF479CEA-34C0-460F-9B56-93BCE4CD4086" = Excavation from Hewlett-Packard Desktops (remove only)
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"File Shredder_is1" = File Shredder 2.0
"GameChannel" = WildTangent GameChannel (remove only)
"Heroes Chronicles Warlords of the Wasteland" = Heroes Chronicles: Warlords of the Wasteland
"hp instant support" = HP Instant Support
"HP PSC 1200 Series" = HP Photo and Imaging 2.0 - hp psc 1200 series
"HPTOOLKIT" = toolkit
"ie8" = Windows Internet Explorer 8
"IEAK5" = Microsoft Internet Explorer Administration Kit 5
"InstallShield_{0613467F-A45E-4CB1-9ECE-1F3DD79FB927}" = easy Internet sign-up
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.8.0
"LimeWire" = LimeWire 4.16.6
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"MagicTracer 2.0" = MagicTracer 2.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"PokerStars" = PokerStars
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"RealPlayer 6.0" = RealOne Player
"S3Display" = S3Display
"S3Gamma2" = S3Gamma2
"S3Info2" = S3Info2
"S3Overlay" = S3Overlay
"SpamSubtract" = SpamSubtract
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Unlocker" = Unlocker 1.8.7
"Videora iPod Converter" = Videora iPod Converter 4.07
"ViewpointMediaPlayer" = Viewpoint Media Player
"virtualPhotographer_is1" = virtualPhotographer 1.5.6
"WeatherBug" = WeatherBug
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip E-Mail Companion" = WinZip E-Mail Companion
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WordPerfect Productivity Pack" = WordPerfect Productivity Pack
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YouTube Downloader App" = YouTube Downloader App 1.02

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
"Move Media Player" = Move Media Player
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/21/2009 4:09:24 PM | Computer Name = HARVEY | Source = Application Error | ID = 1000
Description = Faulting application softwareupdate.exe, version 2.0.2.92, faulting
module scriptingobjectmodel.dll, version 2.1.1.116, fault address 0x00005476.

Error - 3/22/2009 7:57:57 PM | Computer Name = HARVEY | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.8.20081.21709, faulting
module firefox.exe, version 1.8.20081.21709, fault address 0x00190667.

Error - 4/3/2009 12:24:45 PM | Computer Name = HARVEY | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 8.1.0.51, faulting module
3ivxqtvideocodec.qtx, version 5.0.2.280, fault address 0x0000373c.

Error - 4/14/2009 12:40:49 PM | Computer Name = HARVEY | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft Office XP Professional with FrontPage -- Error
25003. Microsoft Office setup cannot continue because the installation source has
been corrupted

Error - 4/14/2009 12:55:26 PM | Computer Name = HARVEY | Source = Application Hang | ID = 1002
Description = Hanging application ImageReady.exe, version 8.0.0.117, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/28/2009 10:48:28 PM | Computer Name = HARVEY | Source = MsiInstaller | ID = 11308
Description = Product: HP Photo and Imaging 2.0 - All-in-One Drivers -- Error 1308.Source
file not found: C:\Documents and Settings\Owner\Desktop\My Stuff\HP PSC 1210xi
Printer Driver\Drivers\Scanner\hpqgends.tmp. Verify that the file exists and that
you can access it.

Error - 4/28/2009 10:48:29 PM | Computer Name = HARVEY | Source = MsiInstaller | ID = 11308
Description = Product: HP Photo and Imaging 2.0 - All-in-One Drivers -- Error 1308.Source
file not found: C:\Documents and Settings\Owner\Desktop\My Stuff\HP PSC 1210xi
Printer Driver\Drivers\Scanner\hpqgends.tmp. Verify that the file exists and that
you can access it.

Error - 4/28/2009 10:48:34 PM | Computer Name = HARVEY | Source = MsiInstaller | ID = 11308
Description = Product: HP Photo and Imaging 2.0 - All-in-One Drivers -- Error 1308.Source
file not found: C:\Documents and Settings\Owner\Desktop\My Stuff\HP PSC 1210xi
Printer Driver\Drivers\Scanner\hpqgends.tmp. Verify that the file exists and that
you can access it.

Error - 4/28/2009 10:49:46 PM | Computer Name = HARVEY | Source = MsiInstaller | ID = 11308
Description = Product: HP Photo and Imaging 2.0 - All-in-One Drivers -- Error 1308.Source
file not found: C:\Documents and Settings\Owner\Desktop\My Stuff\HP PSC 1210xi
Printer Driver\Drivers\Scanner\hpqgends.tmp. Verify that the file exists and that
you can access it.

Error - 4/29/2009 12:20:01 AM | Computer Name = HARVEY | Source = MsiInstaller | ID = 11308
Description = Product: HP Photo and Imaging 2.0 - All-in-One Drivers -- Error 1308.Source
file not found: C:\Documents and Settings\Owner\Desktop\My Stuff\HP PSC 1210xi
Printer Driver\Drivers\Scanner\hpqgends.tmp. Verify that the file exists and that
you can access it.

[ System Events ]
Error - 10/6/2009 6:37:44 AM | Computer Name = HARVEY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0012178C70D7. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 10/6/2009 9:37:18 AM | Computer Name = HARVEY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0012178C70D7. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 10/6/2009 9:37:58 AM | Computer Name = HARVEY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0012178C70D7. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 10/6/2009 9:43:25 AM | Computer Name = HARVEY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0012178C70D7. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 10/7/2009 5:24:38 PM | Computer Name = HARVEY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0012178C70D7. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 10/7/2009 5:36:23 PM | Computer Name = HARVEY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0012178C70D7. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 10/7/2009 5:36:41 PM | Computer Name = HARVEY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0012178C70D7. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 10/7/2009 6:00:13 PM | Computer Name = HARVEY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0012178C70D7. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 10/7/2009 6:14:43 PM | Computer Name = HARVEY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0012178C70D7. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 10/7/2009 10:54:25 PM | Computer Name = HARVEY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0012178C70D7. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.


< End of report >


Let me know what to do next...
  • 0

#8
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
do you have the file path to what you want deleted ? Your log is clean from malware it seems

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O33 - MountPoints2\{1193d2ac-a274-11de-8a65-000c7600366c}\Shell - "" = AutoRun
    O33 - MountPoints2\{1193d2ac-a274-11de-8a65-000c7600366c}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{1193d2ac-a274-11de-8a65-000c7600366c}\Shell\AutoRun\command - "" = M:\Install.bat -- [2008/08/04 13:22:19 | 00,001,347 | R--- | M] ()
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done



Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean




Please download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

  • 0

#9
crazychilean7

crazychilean7

    Member

  • Member
  • PipPip
  • 30 posts
N:\Jason\Videos\SouthPark

That's folder I want deleted
  • 0

#10
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
ok plug your external hard drive in and add this into the OTL script

:Files
N:\Jason\Videos\SouthPark
  • 0
<

Advertisement


#11
crazychilean7

crazychilean7

    Member

  • Member
  • PipPip
  • 30 posts
I did the first thing you said and when I rebooted my computer it ran a scan and after about an hour and a half my computer booted up and I had this word pad text file...

All processes killed
Error: Unable to interpret <[emptytemp]> in the current context!
Error: Unable to interpret <[Reboot]> in the current context!

OTL by OldTimer - Version 3.0.18.4 log created on 10082009_144255

Files\Folders moved on Reboot...
File\Folder M:\Install.bat not found!
C:\Documents and Settings\kodak\Local Settings\Temp\Perflib_Perfdata_69c.dat moved successfully.
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\FP0LF06K\TNSOTCAPFA2OOCA7ASKZKCAAP02RECAE2F3HOCA3HSC1HCAN5AMLACAX8Q4WMCA7QAY5BCAH6NYTCCAOEE1PXCASB0M62CA66DAC5CAQNPSCNCAACK9
BACAW88W2RCAM7JA76CAPLF5SDCA1RT6QCCAVZ91NGCAEB2F3XCA4XHSA6.htm not found!
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\B9LDN797\15023591@Bottom[1].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\ad01@Right[6].htm moved successfully.
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\JYOKMCANH3KYOCA1GBN1FCA71S7T5CA1K048OCAM2KBEACAQAA32SCAIUE2BPCA6N7VPHCAUGF0YWCA1M3749CA0T8HSFCAM0SW7WCAKVW10SCAWQHL
8LCA0AA7FGCAVL3UT1CAAVIMR0CAQKKHCACAIMWCY3CA3512KPCASTC8R5.htm not found!
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\MGIPDCADS3RMGCACJLO30CA3WHJK6CA0WF0NVCA6BBI0TCAIBVZUFCAMUCQANCAUVK0B1CADXV1TMCAYUJX6TCAY3YQ5GCA0GLGZMCALEXPWACAMG6F
WRCALO4PI5CAFGUWNSCAJM0PVFCARLYIL3CA7XKQUECAG9809TCAINVS1D.htm not found!
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\U114KCAVYAV6DCA7UQD6HCAZ61KKGCAI1STI3CA0VREGRCA8PUYOOCAUQ51RMCAQQ5D8UCAOMUWY2CAR6T5X9CANM2L1OCATFR8TWCABY6GSQCA2OIF
5XCATDU85SCAQYVKLTCASS6J1QCAH4UU7ZCAI2STBFCAH00DVQCAA5N76Z.htm not found!
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\XNTFXCARQ7RH2CA4AOK7DCAVAVZWQCAROBYO8CAXSINTVCAH2EXOWCAJ8HWO4CAJQA3H8CA3SQI1UCA7IV6L5CAXGD6BSCAKG6KV0CA4X2PNTCAMGCI
HICA0A2XEXCABJ16GDCAIUAN7BCAIA323NCAA2EI4DCA1STZNHCAYLDND6.htm not found!
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\3ZG73OB0\controlpanel[3].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\3ZG73OB0\w1050@Middle[5].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\2ME5V8R2\23523587@Top[1].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\ClamWin1.log moved successfully.
DllUnregisterServer procedure not found in C:\Documents and Settings\Owner\Local Settings\Temp\IadHide4.dll
C:\Documents and Settings\Owner\Local Settings\Temp\IadHide4.dll NOT unregistered.
C:\Documents and Settings\Owner\Local Settings\Temp\IadHide4.dll moved successfully.
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_a0c.dat not found!
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_adc.dat not found!
C:\Documents and Settings\Owner\Local Settings\Temp\~DFC880.tmp moved successfully.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_66c.dat not found!

Registry entries deleted on Reboot...


When you said "ok plug your external hard drive in and add this into the OTL script

:Files
N:\Jason\Videos\SouthPark"

Did you mean to just run OTL make the same changes as before and then in the "Custom Scans/Fixes" enter the

":Files
N:\Jason\Videos\SouthPark"

and then hit Run Scan or something else?
  • 0

#12
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
do this

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    
    :Services
    
    :Reg
    
    :Files
    N:\Jason\Videos\SouthPark
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

  • 0

#13
crazychilean7

crazychilean7

    Member

  • Member
  • PipPip
  • 30 posts
When it rebooted this text file popped up...

All processes killed
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File\Folder N:\Jason\Videos\SouthPark not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: kodak
File delete failed. C:\Documents and Settings\kodak\Local Settings\Temp\Perflib_Perfdata_628.dat scheduled to be deleted on reboot.
->Temp folder emptied: 16384 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 16786 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Owner
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\ZBCVJ1XS\ad01@Right[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\ZBCVJ1XS\w1050@Middle[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\WDRFWPCP\21916700@Top[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\UDTAUUZD\21916700@Bottom[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\FNB8NC9D\controlpanel[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\JYOKMCANH3KYOCA1GBN1FCA71S7T5CA1K048OCAM2KBEACAQAA32SCAIUE2BPCA6N7VPHCAUGF0YWCA1M3749CA0T8HSFCAM0SW7WCAKVW10SCAWQHL
8LCA0AA7FGCAVL3UT1CAAVIMR0CAQKKHCACAIMWCY3CA3512KPCASTC8R5.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\MGIPDCADS3RMGCACJLO30CA3WHJK6CA0WF0NVCA6BBI0TCAIBVZUFCAMUCQANCAUVK0B1CADXV1TMCAYUJX6TCAY3YQ5GCA0GLGZMCALEXPWACAMG6F
WRCALO4PI5CAFGUWNSCAJM0PVFCARLYIL3CA7XKQUECAG9809TCAINVS1D.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\U114KCAVYAV6DCA7UQD6HCAZ61KKGCAI1STI3CA0VREGRCA8PUYOOCAUQ51RMCAQQ5D8UCAOMUWY2CAR6T5X9CANM2L1OCATFR8TWCABY6GSQCA2OIF
5XCATDU85SCAQYVKLTCASS6J1QCAH4UU7ZCAI2STBFCAH00DVQCAA5N76Z.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\XNTFXCARQ7RH2CA4AOK7DCAVAVZWQCAROBYO8CAXSINTVCAH2EXOWCAJ8HWO4CAJQA3H8CA3SQI1UCA7IV6L5CAXGD6BSCAKG6KV0CA4X2PNTCAMGCI
HICA0A2XEXCABJ16GDCAIUAN7BCAIA323NCAA2EI4DCA1STZNHCAYLDND6.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\ClamWin1.log scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\IadHide4.dll scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_a70.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DF1B0E.tmp scheduled to be deleted on reboot.
->Temp folder emptied: 318325 bytes
->Temporary Internet Files folder emptied: 134 bytes
->Java cache emptied: 0 bytes
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\XUL.mfl scheduled to be deleted on reboot.
->FireFox cache emptied: 24009912 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5c8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 23.30 mb


OTL by OldTimer - Version 3.0.18.4 log created on 10082009_165958

Files\Folders moved on Reboot...
C:\Documents and Settings\kodak\Local Settings\Temp\Perflib_Perfdata_628.dat moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\ZBCVJ1XS\ad01@Right[1].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\ZBCVJ1XS\w1050@Middle[1].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\WDRFWPCP\21916700@Top[1].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\UDTAUUZD\21916700@Bottom[1].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\FNB8NC9D\controlpanel[1].htm moved successfully.
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\JYOKMCANH3KYOCA1GBN1FCA71S7T5CA1K048OCAM2KBEACAQAA32SCAIUE2BPCA6N7VPHCAUGF0YWCA1M3749CA0T8HSFCAM0SW7WCAKVW10SCAWQHL
8LCA0AA7FGCAVL3UT1CAAVIMR0CAQKKHCACAIMWCY3CA3512KPCASTC8R5.htm not found!
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\MGIPDCADS3RMGCACJLO30CA3WHJK6CA0WF0NVCA6BBI0TCAIBVZUFCAMUCQANCAUVK0B1CADXV1TMCAYUJX6TCAY3YQ5GCA0GLGZMCALEXPWACAMG6F
WRCALO4PI5CAFGUWNSCAJM0PVFCARLYIL3CA7XKQUECAG9809TCAINVS1D.htm not found!
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\U114KCAVYAV6DCA7UQD6HCAZ61KKGCAI1STI3CA0VREGRCA8PUYOOCAUQ51RMCAQQ5D8UCAOMUWY2CAR6T5X9CANM2L1OCATFR8TWCABY6GSQCA2OIF
5XCATDU85SCAQYVKLTCASS6J1QCAH4UU7ZCAI2STBFCAH00DVQCAA5N76Z.htm not found!
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\9C8LLCI7\XNTFXCARQ7RH2CA4AOK7DCAVAVZWQCAROBYO8CAXSINTVCAH2EXOWCAJ8HWO4CAJQA3H8CA3SQI1UCA7IV6L5CAXGD6BSCAKG6KV0CA4X2PNTCAMGCI
HICA0A2XEXCABJ16GDCAIUAN7BCAIA323NCAA2EI4DCA1STZNHCAYLDND6.htm not found!
C:\Documents and Settings\Owner\Local Settings\Temp\ClamWin1.log moved successfully.
DllUnregisterServer procedure not found in C:\Documents and Settings\Owner\Local Settings\Temp\IadHide4.dll
C:\Documents and Settings\Owner\Local Settings\Temp\IadHide4.dll NOT unregistered.
C:\Documents and Settings\Owner\Local Settings\Temp\IadHide4.dll moved successfully.
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_a70.dat not found!
C:\Documents and Settings\Owner\Local Settings\Temp\~DF1B0E.tmp moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\eycu23b2.default\XUL.mfl moved successfully.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_5c8.dat not found!

Registry entries deleted on Reboot...


I went and looked at the external hard drive and now all the files inside of "Jason" are gone and its all the gibberish files that look like "∩≈ƒ⌠tÅ╫.ax╫"
  • 0

#14
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
can you do the mbam and kaspersky step in my previous post
  • 0

#15
crazychilean7

crazychilean7

    Member

  • Member
  • PipPip
  • 30 posts
Here's the report from the Kasperksy when I scanned just the external hard drive...

Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 5.1.2600 Service Pack 3

10/9/2009 1:13:11 AM
mbam-log-2009-10-09 (01-13-11).txt

Scan type: Full Scan (C:\|K:\|)
Objects scanned: 250397
Time elapsed: 7 hour(s), 40 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Malwarebytes is still scanning and has been for the past 8 hours...I'll put that report up when it finishes
  • 0

Advertisement




Similar Topics: Cannot Delete File [Solved]     x


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured