Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Kaspersky brings up dodgy files - false positives, or need to remove?


  • Please log in to reply

#1
vayshti

vayshti

    Member

  • Member
  • PipPip
  • 40 posts
Got scared I'd transferred something across from an already infected machine (thread <a href="http://www.geekstogo...70313">here</a> - and it is running slow. Can someone please take a look at these logs and tell me they're okay/help me fix?

I've run all the prelim steps advised.

Below is the Kapersky log that bothered me, and the first OTL log. Let me know if you want to see there others.

Kapersky log:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, July 14, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, July 14, 2010 13:11:18
Records in database: 4223551
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\

Scan statistics:
Objects scanned: 48566
Threats found: 2
Infected objects found: 5
Suspicious objects found: 0
Scan duration: 02:15:06


File name / Threat / Threats count
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\39\22d5faa7-3b7d44ae Infected: Exploit.Java.Agent.f 1
C:\Documents and Settings\Matthew\Local Settings\Temp\mirc635.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1
C:\Documents and Settings\Matthew\Local Settings\Temporary Internet Files\Content.IE5\2OVV15H2\mirc635[1].exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1
C:\Documents and Settings\Matthew\Local Settings\Temporary Internet Files\Content.IE5\SNPXH1MW\992[1].jar Infected: Exploit.Java.Agent.f 1
E:\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1

Selected area has been scanned.


OTL Log:

OTL logfile created on: 14/07/2010 9:03:38 PM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Matthew\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

639.00 Mb Total Physical Memory | 170.00 Mb Available Physical Memory | 27.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 960 1920 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 20.76 Gb Total Space | 12.42 Gb Free Space | 59.84% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 9.77 Gb Total Space | 9.26 Gb Free Space | 94.79% Space Free | Partition Type: NTFS
Drive F: | 6.73 Gb Total Space | 5.01 Gb Free Space | 74.45% Space Free | Partition Type: NTFS
Drive G: | 124.72 Mb Total Space | 114.96 Mb Free Space | 92.18% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TARDIS
Current User Name: Matthew
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/07/14 20:24:48 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthew\Desktop\OTL.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/10/30 17:29:58 | 000,136,448 | ---- | M] (Panda Security, S.L.) -- E:\Panda Security\Panda Cloud Antivirus\PSANHost.exe
PRC - [2009/10/30 17:29:02 | 000,361,728 | ---- | M] (Panda Security, S.L.) -- E:\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/05/20 21:52:40 | 000,488,448 | ---- | M] () -- C:\WINDOWS\system32\ASWL2K.exe
PRC - [2004/05/06 12:21:04 | 000,496,640 | ---- | M] () -- C:\WINDOWS\system32\ASWLSVC.exe
PRC - [2003/07/30 10:08:58 | 000,143,360 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
PRC - [2002/09/20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


========== Modules (SafeList) ==========

MOD - [2010/07/14 20:24:48 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthew\Desktop\OTL.exe
MOD - [2008/04/14 01:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/10/30 17:29:58 | 000,136,448 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- E:\Panda Security\Panda Cloud Antivirus\PSANHost.exe -- (NanoServiceMain)
SRV - [2004/05/06 12:21:04 | 000,496,640 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\ASWLSVC.exe -- (ASWLSVC)
SRV - [2002/09/20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))


========== Driver Services (SafeList) ==========

DRV - [2009/10/30 16:18:02 | 000,146,952 | ---- | M] (Panda Security, S.L.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINAflt.sys -- (PSINAflt)
DRV - [2009/10/13 15:50:56 | 000,114,312 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PSINKNC.sys -- (PSINKNC)
DRV - [2009/10/13 15:50:56 | 000,101,512 | ---- | M] (Panda Security, S.L.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINProc.sys -- (PSINProc)
DRV - [2009/10/13 15:50:56 | 000,095,880 | ---- | M] (Panda Security, S.L.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINFile.sys -- (PSINFile)
DRV - [2003/12/11 17:09:26 | 000,043,136 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2003/11/20 15:40:00 | 000,619,520 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2003/11/20 15:40:00 | 000,013,174 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\atisgkaf.sys -- (caboagp)
DRV - [2003/07/17 16:40:06 | 000,265,728 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2002/09/09 19:54:06 | 000,016,269 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\ASNDIS5.sys -- (ASNDIS5)
DRV - [2001/08/17 14:57:56 | 000,006,784 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\smbhc.sys -- (SMBHC)
DRV - [2001/08/17 14:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



O1 HOSTS File: ([2002/08/29 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PSUNMain] E:\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\Matthew\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Matthew\Application Data\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Documents and Settings\Matthew\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus....ek_sys_ctrl.cab (asusTek_sysctrl Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.co...ploader_v10.cab (PopCapLoader Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/11 12:23:26 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{c46119b0-5d50-11df-aaa0-000ea6b4609b}\Shell - "" = AutoRun
O33 - MountPoints2\{c46119b0-5d50-11df-aaa0-000ea6b4609b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c46119b0-5d50-11df-aaa0-000ea6b4609b}\Shell\AutoRun\command - "" = G:\WD SmartWare.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: MIDI1 - C:\WINDOWS\System32\Syncor11.dll (SoundMAX)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - E:\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 90 Days ==========

[2010/07/14 20:24:44 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Matthew\Desktop\OTL.exe
[2010/07/14 19:53:58 | 000,000,000 | ---D | C] -- C:\Malwarebytes' Anti-Malware
[2010/07/14 19:52:39 | 006,153,384 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Matthew\Desktop\mbam-setup.exe
[2010/07/14 19:51:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/07/14 19:51:35 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/07/14 19:50:27 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Matthew\Desktop\erunt_setup.exe
[2010/07/14 19:22:01 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Matthew\Desktop\TFC.exe
[2010/07/14 09:05:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2010/07/14 09:05:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/07/14 09:05:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/07/14 09:01:34 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2010/07/14 09:00:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Sun
[2010/07/12 01:07:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Media Player Classic
[2010/07/11 22:50:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\mIRC
[2010/07/10 17:14:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\WinRAR
[2010/07/10 17:14:23 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2010/07/10 15:46:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/07/10 15:42:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9 Installer
[2010/07/10 15:41:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2010/07/10 15:41:17 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010/07/10 15:41:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2010/07/10 15:38:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Local Settings\Application Data\Adobe
[2010/07/10 15:38:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS
[2010/07/09 23:04:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Malwarebytes
[2010/07/09 23:04:49 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/09 23:04:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/09 23:04:47 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/09 00:05:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Local Settings\Application Data\Identities
[2010/07/02 22:18:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Matthew\My Documents\My Videos
[2010/06/18 12:58:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2010/06/02 18:13:46 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2010/06/02 18:10:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2010/06/02 18:10:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2010/05/18 21:04:46 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Matthew\IECompatCache
[2010/05/18 20:37:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2010/05/18 08:42:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2010/05/18 08:42:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2010/05/18 08:42:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2010/05/18 08:27:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic
[2010/05/18 07:45:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010/05/18 07:42:43 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Matthew\PrivacIE
[2010/05/18 07:02:15 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Matthew\IETldCache
[2010/05/17 23:12:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010/05/17 23:11:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2010/05/17 23:10:11 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/05/17 23:10:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2010/05/17 17:48:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Local Settings\Application Data\Spotify
[2010/05/17 17:48:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Spotify
[2010/05/17 17:47:54 | 000,000,000 | ---D | C] -- C:\Program Files\Spotify
[2010/05/17 17:20:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\ICAClient
[2010/05/17 17:19:44 | 000,000,000 | ---D | C] -- C:\Program Files\Citrix
[2010/05/11 23:59:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Local Settings\Application Data\Western Digital
[2010/05/11 18:57:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Apple Computer
[2010/05/11 18:56:07 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/05/11 18:55:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/05/11 18:54:47 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/05/11 18:54:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/05/11 18:54:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Local Settings\Application Data\Apple
[2010/05/11 18:54:26 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010/05/11 18:54:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2010/05/11 18:53:49 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/05/11 18:53:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010/05/11 18:53:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2010/05/11 18:50:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Panda Security
[2010/05/11 18:49:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Panda Security
[2010/05/11 17:44:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\peernet
[2010/05/11 17:44:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\provisioning
[2010/05/11 17:41:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2010/05/11 17:32:41 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2010/05/11 17:32:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\EHome
[2010/05/11 17:26:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Local Settings\Application Data\Help
[2010/05/11 17:26:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Help
[2010/05/11 16:56:21 | 001,285,632 | ---- | C] (Analog Devices) -- C:\WINDOWS\System32\SMMedia.dll
[2010/05/11 16:56:21 | 000,030,208 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\wdmioctl.dll
[2010/05/11 16:56:19 | 000,991,232 | ---- | C] (Sensaura) -- C:\WINDOWS\System32\virtear.dll
[2010/05/11 16:56:19 | 000,049,152 | ---- | C] (SoundMAX) -- C:\WINDOWS\System32\S11thk32.dll
[2010/05/11 16:56:19 | 000,040,820 | ---- | C] (SoundMAX) -- C:\WINDOWS\System32\Syncor11.dll
[2010/05/11 16:56:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\VirtualEar
[2010/05/11 16:56:18 | 000,049,152 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\DSndUp.exe
[2010/05/11 16:56:18 | 000,045,056 | ---- | C] (adi) -- C:\WINDOWS\System32\CleanUp.exe
[2010/05/11 16:56:18 | 000,000,000 | ---D | C] -- C:\Program Files\Analog Devices
[2010/05/11 16:15:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2010/05/11 16:10:54 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2010/05/11 15:48:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Dropbox
[2010/05/11 15:47:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Local Settings\Application Data\Apple Computer
[2010/05/11 15:32:06 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/05/11 15:23:08 | 000,212,992 | ---- | C] (Dart Communications) -- C:\WINDOWS\System32\dartsock.dll
[2010/05/11 15:23:08 | 000,176,128 | ---- | C] (Dart Communications) -- C:\WINDOWS\System32\DartSnmp.dll
[2010/05/11 15:17:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2010/05/11 15:16:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2010/05/11 15:15:27 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2010/05/11 15:14:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2010/05/11 15:14:39 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2010/05/11 15:10:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2010/05/11 15:09:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2010/05/11 14:52:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Macromedia
[2010/05/11 14:52:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Adobe
[2010/05/11 13:50:03 | 000,061,440 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\ASUSW32N50.dll
[2010/05/11 13:50:03 | 000,016,269 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\ASNDIS5.sys
[2010/05/11 13:50:02 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2010/05/11 13:48:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2010/05/11 13:46:00 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Matthew\UserData
[2010/05/11 12:57:21 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2010/05/11 12:41:05 | 000,000,000 | ---D | C] -- C:\temp
[2010/05/11 12:29:46 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2010/05/11 12:29:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Application Data\Identities
[2010/05/11 12:29:34 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2010/05/11 12:29:32 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Matthew\My Documents\My Pictures
[2010/05/11 12:29:32 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Matthew\My Documents\My Music
[2010/05/11 12:29:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft
[2010/05/11 12:29:28 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Matthew\Application Data\Microsoft
[2010/05/11 12:29:28 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Matthew\SendTo
[2010/05/11 12:29:28 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Matthew\Recent
[2010/05/11 12:29:28 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Matthew\Application Data
[2010/05/11 12:29:28 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Matthew\Start Menu
[2010/05/11 12:29:28 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Matthew\My Documents
[2010/05/11 12:29:28 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Matthew\Favorites
[2010/05/11 12:29:28 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Matthew\Cookies
[2010/05/11 12:29:28 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Matthew\Templates
[2010/05/11 12:29:28 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Matthew\PrintHood
[2010/05/11 12:29:28 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Matthew\NetHood
[2010/05/11 12:29:28 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Matthew\Local Settings
[2010/05/11 12:29:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Desktop
[2010/05/11 12:28:01 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2010/05/11 12:27:57 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/05/11 12:27:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/05/11 12:27:56 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/05/11 12:27:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/05/11 12:25:52 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2010/05/11 12:25:52 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2010/05/11 12:24:28 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2010/05/11 12:23:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2010/05/11 12:23:53 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2010/05/11 12:23:53 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2010/05/11 12:22:19 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM
[2010/05/11 12:22:05 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2010/05/11 12:22:05 | 000,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2010/05/11 12:21:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2010/05/11 12:20:53 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2010/05/11 12:20:49 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2010/05/11 12:20:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2010/05/11 12:20:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2010/05/11 12:20:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2010/05/11 12:20:40 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2010/05/11 12:20:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\PCHealth
[2010/05/11 12:20:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2010/05/11 12:20:32 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2010/05/11 12:20:31 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2010/05/11 12:20:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2010/05/11 12:20:21 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2010/05/11 12:20:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2010/05/11 12:20:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2010/05/11 12:19:38 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2010/05/11 12:19:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2010/05/11 12:19:21 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2010/05/11 12:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services
[2010/05/11 12:19:19 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2010/05/11 12:19:09 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2010/05/11 12:19:05 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2010/05/11 12:18:29 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2010/05/11 12:18:29 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2010/05/11 12:18:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2010/05/11 12:18:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2010/05/11 12:18:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2010/05/11 12:05:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2010/05/11 12:05:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2010/05/11 12:05:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2010/05/11 12:05:19 | 000,000,000 | R--D | C] -- C:\Program Files
[2010/05/11 12:05:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2010/05/11 12:04:54 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu
[2010/05/11 12:04:54 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents
[2010/05/11 12:04:54 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates
[2010/05/11 12:04:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2010/05/11 12:04:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop
[2010/05/11 12:04:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2010/05/11 12:04:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2010/05/11 12:04:35 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2010/05/11 12:04:35 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data
[2010/05/11 12:04:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings
[2010/05/11 11:59:48 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2010/05/11 11:59:48 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2010/05/11 11:59:48 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web
[2010/05/11 11:59:48 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2010/05/11 11:59:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2010/05/11 11:59:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config

========== Files - Modified Within 90 Days ==========

[2010/07/14 20:24:48 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthew\Desktop\OTL.exe
[2010/07/14 20:12:13 | 000,284,915 | ---- | M] () -- C:\Documents and Settings\Matthew\Desktop\gmer.zip
[2010/07/14 19:52:59 | 006,153,384 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Matthew\Desktop\mbam-setup.exe
[2010/07/14 19:51:43 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\Matthew\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/07/14 19:51:35 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\Matthew\Desktop\NTREGOPT.lnk
[2010/07/14 19:51:35 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Matthew\Desktop\ERUNT.lnk
[2010/07/14 19:51:12 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Matthew\Desktop\erunt_setup.exe
[2010/07/14 19:47:49 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/14 19:47:18 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/14 19:47:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/14 19:45:11 | 002,097,152 | -H-- | M] () -- C:\Documents and Settings\Matthew\NTUSER.DAT
[2010/07/14 19:45:11 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Matthew\ntuser.ini
[2010/07/14 19:22:49 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthew\Desktop\TFC.exe
[2010/07/13 02:22:05 | 004,814,910 | -H-- | M] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\IconCache.db
[2010/07/12 21:09:28 | 000,003,584 | ---- | M] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/11 22:59:05 | 000,020,516 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/07/10 16:31:29 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/07/10 15:42:17 | 000,000,732 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Acrobat_com.lnk
[2010/06/25 12:58:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/20 21:22:21 | 000,000,800 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/06/14 11:31:46 | 000,097,456 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/14 10:48:53 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/06/04 19:54:52 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/06/04 19:54:52 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/06/02 18:13:58 | 000,000,517 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/02 18:11:09 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/05/22 05:58:45 | 000,312,172 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/05/22 05:58:45 | 000,040,394 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/05/22 05:58:44 | 000,356,120 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/18 20:42:20 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2010/05/18 08:26:32 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/05/18 07:02:23 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/05/18 07:02:17 | 000,001,503 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Browser Choice.lnk
[2010/05/17 17:47:57 | 000,000,666 | ---- | M] () -- C:\Documents and Settings\Matthew\Desktop\Spotify.lnk
[2010/05/11 23:48:22 | 000,000,022 | ---- | M] () -- C:\WINDOWS\System32\ati64hlp.stb
[2010/05/11 18:50:18 | 000,000,236 | ---- | M] () -- C:\WINDOWS\System32\PSUNCpl.dat
[2010/05/11 18:38:12 | 000,000,022 | ---- | M] () -- C:\WINDOWS\System32\ati64hl2.stb
[2010/05/11 18:37:30 | 000,020,072 | ---- | M] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/05/11 17:46:01 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2010/05/11 17:37:40 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010/05/11 16:56:18 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\msssc.dll
[2010/05/11 15:51:38 | 000,001,002 | ---- | M] () -- C:\Documents and Settings\Matthew\Start Menu\Programs\Startup\Dropbox.lnk
[2010/05/11 15:51:36 | 000,001,002 | ---- | M] () -- C:\Documents and Settings\Matthew\Desktop\Dropbox.lnk
[2010/05/11 15:41:42 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
[2010/05/11 15:31:43 | 000,000,267 | ---- | M] () -- C:\ASWL2K.ini
[2010/05/11 12:29:53 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2010/05/11 12:29:44 | 000,025,065 | ---- | M] () -- C:\WINDOWS\System32\wmpscheme.xml
[2010/05/11 12:27:34 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2010/05/11 12:26:38 | 000,000,261 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2010/05/11 12:23:26 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/05/11 12:23:26 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/05/11 12:23:26 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/05/11 12:23:26 | 000,000,000 | ---- | M] () -- C:\WINDOWS\control.ini
[2010/05/11 12:23:26 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/05/11 12:23:26 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/05/11 12:23:23 | 000,299,552 | ---- | M] () -- C:\WINDOWS\WMSysPrx.prx
[2010/05/11 12:23:12 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2010/05/11 12:22:05 | 000,000,488 | RH-- | M] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2010/05/11 12:22:05 | 000,000,488 | RH-- | M] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\WindowsShell.Manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2010/05/11 12:19:51 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010/05/11 12:19:35 | 000,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini
[2010/05/11 12:19:35 | 000,000,036 | ---- | M] () -- C:\WINDOWS\vb.ini
[2010/05/11 12:05:19 | 000,000,231 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2010/07/14 20:16:19 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Matthew\Desktop\gmer.exe
[2010/07/14 20:12:12 | 000,284,915 | ---- | C] () -- C:\Documents and Settings\Matthew\Desktop\gmer.zip
[2010/07/14 19:51:43 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\Matthew\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/07/14 19:51:35 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\Matthew\Desktop\NTREGOPT.lnk
[2010/07/14 19:51:35 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Matthew\Desktop\ERUNT.lnk
[2010/07/12 20:15:45 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/11 22:59:05 | 000,020,516 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/07/10 15:51:11 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/07/10 15:42:17 | 000,000,732 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Acrobat_com.lnk
[2010/06/02 18:11:09 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/05/18 07:02:17 | 000,001,503 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Browser Choice.lnk
[2010/05/17 18:11:16 | 000,010,457 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.hta
[2010/05/17 18:11:16 | 000,001,771 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.css
[2010/05/17 18:11:16 | 000,000,855 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpocm.inf
[2010/05/17 18:11:15 | 000,613,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.chm
[2010/05/17 18:11:15 | 000,000,420 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmploc.js
[2010/05/17 18:11:14 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud7.wav
[2010/05/17 18:11:14 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud6.wav
[2010/05/17 18:11:14 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud9.wav
[2010/05/17 18:11:14 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud8.wav
[2010/05/17 18:11:14 | 000,069,612 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.adm
[2010/05/17 18:11:14 | 000,023,195 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplay.chm
[2010/05/17 18:11:13 | 000,354,468 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud1.wav
[2010/05/17 18:11:13 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud3.wav
[2010/05/17 18:11:13 | 000,086,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud5.wav
[2010/05/17 18:11:13 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud4.wav
[2010/05/17 18:11:13 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud2.wav
[2010/05/17 18:11:12 | 000,029,070 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmp.inf
[2010/05/17 18:11:09 | 000,006,769 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmfsdk.inf
[2010/05/17 18:11:08 | 000,017,272 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmdm.inf
[2010/05/17 18:11:08 | 000,008,677 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm7.gif
[2010/05/17 18:11:08 | 000,007,892 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm9.gif
[2010/05/17 18:11:08 | 000,007,636 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm2.gif
[2010/05/17 18:11:08 | 000,007,369 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm4.gif
[2010/05/17 18:11:08 | 000,006,241 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm3.gif
[2010/05/17 18:11:08 | 000,006,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm6.gif
[2010/05/17 18:11:08 | 000,005,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm1.gif
[2010/05/17 18:11:08 | 000,004,193 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm8.gif
[2010/05/17 18:11:08 | 000,002,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm5.gif
[2010/05/17 18:11:02 | 000,300,969 | ---- | C] () -- C:\WINDOWS\System32\dllcache\viz.wmv
[2010/05/17 18:11:02 | 000,017,489 | ---- | C] () -- C:\WINDOWS\System32\dllcache\videobg.gif
[2010/05/17 18:11:02 | 000,005,290 | ---- | C] () -- C:\WINDOWS\System32\dllcache\vidsamp.gif
[2010/05/17 18:10:54 | 000,023,829 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tourbg.gif
[2010/05/17 18:10:54 | 000,003,187 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tour.js
[2010/05/17 18:10:54 | 000,002,469 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplay.gif
[2010/05/17 18:10:54 | 000,002,450 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpause.gif
[2010/05/17 18:10:54 | 000,002,375 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplayh.gif
[2010/05/17 18:10:54 | 000,002,371 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpauseh.gif
[2010/05/17 18:10:51 | 000,001,398 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taon.gif
[2010/05/17 18:10:51 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taonh.gif
[2010/05/17 18:10:51 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoff.gif
[2010/05/17 18:10:51 | 000,001,367 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoffh.gif
[2010/05/17 18:10:42 | 000,001,148 | ---- | C] () -- C:\WINDOWS\System32\dllcache\snd.htm
[2010/05/17 18:10:39 | 000,000,908 | ---- | C] () -- C:\WINDOWS\System32\dllcache\skins.inf
[2010/05/17 18:10:31 | 000,572,557 | ---- | C] () -- C:\WINDOWS\System32\dllcache\rtuner.wmv
[2010/05/17 18:10:29 | 000,066,725 | ---- | C] () -- C:\WINDOWS\System32\dllcache\revert.wmz
[2010/05/17 18:10:22 | 000,077,307 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plyr_err.chm
[2010/05/17 18:10:22 | 000,001,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst6.wpl
[2010/05/17 18:10:22 | 000,001,046 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst7.wpl
[2010/05/17 18:10:22 | 000,001,036 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst8.wpl
[2010/05/17 18:10:22 | 000,000,784 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst9.wpl
[2010/05/17 18:10:21 | 000,001,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst5.wpl
[2010/05/17 18:10:21 | 000,001,474 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst3.wpl
[2010/05/17 18:10:21 | 000,001,451 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst12.wpl
[2010/05/17 18:10:21 | 000,001,448 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst4.wpl
[2010/05/17 18:10:21 | 000,001,250 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst1.wpl
[2010/05/17 18:10:21 | 000,001,049 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst2.wpl
[2010/05/17 18:10:21 | 000,000,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst11.wpl
[2010/05/17 18:10:21 | 000,000,787 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst10.wpl
[2010/05/17 18:10:21 | 000,000,783 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst13.wpl
[2010/05/17 18:10:21 | 000,000,775 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst14.wpl
[2010/05/17 18:10:21 | 000,000,733 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst15.wpl
[2010/05/17 18:10:13 | 000,375,519 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nuskin.wmv
[2010/05/17 18:10:07 | 000,022,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npds.zip
[2010/05/17 18:10:07 | 000,000,403 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npdrmv2.zip
[2010/05/17 18:09:39 | 000,844,314 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msdxm.ocx
[2010/05/17 18:09:39 | 000,004,126 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msdxmlc.dll
[2010/05/17 18:09:30 | 000,097,117 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.hlp
[2010/05/17 18:09:30 | 000,018,286 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.inf
[2010/05/17 18:09:30 | 000,002,778 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogoh.gif
[2010/05/17 18:09:30 | 000,002,545 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogo.gif
[2010/05/17 18:09:29 | 000,001,885 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.cnt
[2010/05/17 18:09:21 | 000,457,607 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mdlib.wmv
[2010/05/17 18:08:52 | 000,000,974 | ---- | C] () -- C:\WINDOWS\System32\pid.inf
[2010/05/17 18:08:30 | 000,005,971 | ---- | C] () -- C:\WINDOWS\System32\dllcache\events.js
[2010/05/17 18:08:27 | 000,498,742 | ---- | C] () -- C:\WINDOWS\System32\dllcache\dxmasf.dll
[2010/05/17 18:08:12 | 000,381,425 | ---- | C] () -- C:\WINDOWS\System32\dllcache\copycd.wmv
[2010/05/17 18:08:12 | 000,009,585 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.css
[2010/05/17 18:08:12 | 000,008,298 | ---- | C] () -- C:\WINDOWS\System32\dllcache\contents.htm
[2010/05/17 18:08:12 | 000,006,878 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.js
[2010/05/17 18:08:11 | 000,184,959 | ---- | C] () -- C:\WINDOWS\System32\dllcache\compact.wmz
[2010/05/17 18:08:10 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnth.gif
[2010/05/17 18:08:10 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnt.gif
[2010/05/17 18:08:10 | 000,000,772 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cntd.gif
[2010/05/17 18:08:10 | 000,000,760 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapph.gif
[2010/05/17 18:08:10 | 000,000,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapp.gif
[2010/05/17 18:08:03 | 000,000,999 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bktrh.gif
[2010/05/17 17:47:57 | 000,000,666 | ---- | C] () -- C:\Documents and Settings\Matthew\Desktop\Spotify.lnk
[2010/05/11 23:48:22 | 000,000,022 | ---- | C] () -- C:\WINDOWS\System32\ati64hlp.stb
[2010/05/11 18:54:33 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/11 18:50:18 | 000,000,236 | ---- | C] () -- C:\WINDOWS\System32\PSUNCpl.dat
[2010/05/11 18:38:12 | 000,000,022 | ---- | C] () -- C:\WINDOWS\System32\ati64hl2.stb
[2010/05/11 17:45:44 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2010/05/11 16:56:18 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2010/05/11 16:07:41 | 000,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
[2010/05/11 16:07:41 | 000,007,208 | ---- | C] () -- C:\WINDOWS\System32\secupd.sig
[2010/05/11 16:07:41 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2010/05/11 15:51:38 | 000,001,002 | ---- | C] () -- C:\Documents and Settings\Matthew\Start Menu\Programs\Startup\Dropbox.lnk
[2010/05/11 15:51:36 | 000,001,002 | ---- | C] () -- C:\Documents and Settings\Matthew\Desktop\Dropbox.lnk
[2010/05/11 15:41:43 | 000,013,646 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak
[2010/05/11 13:51:49 | 000,000,267 | ---- | C] () -- C:\ASWL2K.ini
[2010/05/11 13:50:03 | 000,496,640 | ---- | C] () -- C:\WINDOWS\System32\ASWLSVC.exe
[2010/05/11 13:50:03 | 000,488,448 | ---- | C] () -- C:\WINDOWS\System32\ASWL2K.exe
[2010/05/11 13:50:03 | 000,159,827 | ---- | C] () -- C:\WINDOWS\System32\RemSvc.exe
[2010/05/11 13:50:03 | 000,141,824 | ---- | C] () -- C:\WINDOWS\System32\ClientCpl.cpl
[2010/05/11 13:50:03 | 000,015,577 | ---- | C] () -- C:\WINDOWS\System32\ASNDIS3.vxd
[2010/05/11 12:29:53 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2010/05/11 12:29:40 | 000,000,800 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/05/11 12:29:34 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/05/11 12:29:29 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\Matthew\ntuser.dat.LOG
[2010/05/11 12:29:29 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Matthew\ntuser.ini
[2010/05/11 12:29:28 | 002,097,152 | -H-- | C] () -- C:\Documents and Settings\Matthew\NTUSER.DAT
[2010/05/11 12:27:34 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2010/05/11 12:26:38 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/05/11 12:23:26 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/05/11 12:23:26 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2010/05/11 12:23:26 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2010/05/11 12:23:26 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2010/05/11 12:23:26 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2010/05/11 12:23:25 | 000,025,065 | ---- | C] () -- C:\WINDOWS\System32\wmpscheme.xml
[2010/05/11 12:23:24 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/05/11 12:23:24 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/05/11 12:23:23 | 000,299,552 | ---- | C] () -- C:\WINDOWS\WMSysPrx.prx
[2010/05/11 12:22:05 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2010/05/11 12:22:05 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\WindowsShell.Manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2010/05/11 12:21:57 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2010/05/11 12:21:37 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
[2010/05/11 12:21:02 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2010/05/11 12:21:02 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2010/05/11 12:20:56 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2010/05/11 12:19:51 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010/05/11 12:18:51 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2010/05/11 12:18:50 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
[2010/05/11 12:18:50 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
[2010/05/11 12:18:50 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
[2010/05/11 12:18:50 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
[2010/05/11 12:18:50 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
[2010/05/11 12:18:50 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
[2010/05/11 12:18:50 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
[2010/05/11 12:18:50 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
[2010/05/11 12:18:50 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
[2010/05/11 12:18:50 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
[2010/05/11 12:18:49 | 000,093,702 | ---- | C] () -- C:\WINDOWS\System32\subrange.uce
[2010/05/11 12:18:49 | 000,060,458 | ---- | C] () -- C:\WINDOWS\System32\ideograf.uce
[2010/05/11 12:18:49 | 000,024,006 | ---- | C] () -- C:\WINDOWS\System32\gb2312.uce
[2010/05/11 12:18:49 | 000,022,984 | ---- | C] () -- C:\WINDOWS\System32\bopomofo.uce
[2010/05/11 12:18:49 | 000,016,740 | ---- | C] () -- C:\WINDOWS\System32\shiftjis.uce
[2010/05/11 12:18:49 | 000,012,876 | ---- | C] () -- C:\WINDOWS\System32\korean.uce
[2010/05/11 12:18:49 | 000,008,484 | ---- | C] () -- C:\WINDOWS\System32\kanji_2.uce
[2010/05/11 12:18:49 | 000,006,948 | ---- | C] () -- C:\WINDOWS\System32\kanji_1.uce
[2010/05/11 12:18:47 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2010/05/11 12:18:47 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2010/05/11 12:18:45 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2010/05/11 12:18:34 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2010/05/11 12:14:08 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2010/05/11 12:14:06 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2010/05/11 12:14:01 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2010/05/11 12:14:00 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2010/05/11 12:13:58 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\korwbrkr.lex
[2010/05/11 12:13:58 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2010/05/11 12:13:58 | 000,001,486 | ---- | C] () -- C:\WINDOWS\System32\noise.kor
[2010/05/11 12:13:57 | 000,002,060 | ---- | C] () -- C:\WINDOWS\System32\noise.jpn
[2010/05/11 12:13:48 | 000,211,938 | ---- | C] () -- C:\WINDOWS\System32\lcphrase.tbl
[2010/05/11 12:13:48 | 000,146,126 | ---- | C] () -- C:\WINDOWS\System32\array30.tab
[2010/05/11 12:13:48 | 000,116,285 | ---- | C] () -- C:\WINDOWS\System32\msdayi.tbl
[2010/05/11 12:13:48 | 000,110,566 | ---- | C] () -- C:\WINDOWS\System32\arphr.tbl
[2010/05/11 12:13:48 | 000,044,370 | ---- | C] () -- C:\WINDOWS\System32\acode.tbl
[2010/05/11 12:13:48 | 000,043,242 | ---- | C] () -- C:\WINDOWS\System32\phoncode.tbl
[2010/05/11 12:13:48 | 000,024,114 | ---- | C] () -- C:\WINDOWS\System32\lcptr.tbl
[2010/05/11 12:13:48 | 000,018,600 | ---- | C] () -- C:\WINDOWS\System32\arrayhw.tab
[2010/05/11 12:13:48 | 000,016,312 | ---- | C] () -- C:\WINDOWS\System32\arptr.tbl
[2010/05/11 12:13:48 | 000,004,071 | ---- | C] () -- C:\WINDOWS\System32\phon.tbl
[2010/05/11 12:13:48 | 000,002,714 | ---- | C] () -- C:\WINDOWS\System32\phonptr.tbl
[2010/05/11 12:13:48 | 000,000,700 | ---- | C] () -- C:\WINDOWS\System32\dayiptr.tbl
[2010/05/11 12:13:48 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\dayiphr.tbl
[2010/05/11 12:13:47 | 000,195,618 | ---- | C] () -- C:\WINDOWS\System32\c_10002.nls
[2010/05/11 12:13:47 | 000,082,172 | ---- | C] () -- C:\WINDOWS\System32\bopomofo.nls
[2010/05/11 12:13:47 | 000,066,728 | ---- | C] () -- C:\WINDOWS\System32\big5.nls
[2010/05/11 12:13:47 | 000,044,370 | ---- | C] () -- C:\WINDOWS\System32\a234.tbl
[2010/05/11 12:13:47 | 000,016,254 | ---- | C] () -- C:\WINDOWS\System32\PINTLPAE.HLP
[2010/05/11 12:13:47 | 000,014,821 | ---- | C] () -- C:\WINDOWS\System32\PINTLPAD.HLP
[2010/05/11 12:13:47 | 000,001,460 | ---- | C] () -- C:\WINDOWS\System32\a15.tbl
[2010/05/11 12:13:41 | 001,223,500 | ---- | C] () -- C:\WINDOWS\System32\WINZM.MB
[2010/05/11 12:13:40 | 001,783,864 | ---- | C] () -- C:\WINDOWS\System32\WINPY.MB
[2010/05/11 12:13:40 | 001,564,868 | ---- | C] () -- C:\WINDOWS\System32\WINSP.MB
[2010/05/11 12:13:40 | 000,083,748 | ---- | C] () -- C:\WINDOWS\System32\prcp.nls
[2010/05/11 12:13:40 | 000,083,748 | ---- | C] () -- C:\WINDOWS\System32\prc.nls
[2010/05/11 12:13:39 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\c_10008.nls
[2010/05/11 12:13:36 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2010/05/11 12:13:36 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2010/05/11 12:13:29 | 000,189,986 | ---- | C] () -- C:\WINDOWS\System32\c_1361.nls
[2010/05/11 12:13:29 | 000,177,698 | ---- | C] () -- C:\WINDOWS\System32\c_10003.nls
[2010/05/11 12:13:29 | 000,047,066 | ---- | C] () -- C:\WINDOWS\System32\ksc.nls
[2010/05/11 12:13:23 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2010/05/11 12:13:04 | 000,180,770 | ---- | C] () -- C:\WINDOWS\System32\c_20932.nls
[2010/05/11 12:13:04 | 000,180,258 | ---- | C] () -- C:\WINDOWS\System32\c_20000.nls
[2010/05/11 12:13:04 | 000,177,698 | ---- | C] () -- C:\WINDOWS\System32\c_20949.nls
[2010/05/11 12:13:04 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\c_20936.nls
[2010/05/11 12:13:04 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_21027.nls
[2010/05/11 12:13:03 | 000,162,850 | ---- | C] () -- C:\WINDOWS\System32\c_10001.nls
[2010/05/11 12:13:03 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_20290.nls
[2010/05/11 12:13:03 | 000,028,288 | ---- | C] () -- C:\WINDOWS\System32\xjis.nls
[2010/05/11 12:05:30 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010/05/11 12:05:21 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2010/05/11 12:05:21 | 000,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2010/05/11 12:05:21 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2010/05/11 12:05:20 | 000,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2010/05/11 12:05:19 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls
[2010/05/11 12:05:17 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_857.nls
[2010/05/11 12:05:17 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28599.nls
[2010/05/11 12:05:17 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10081.nls
[2010/05/11 12:05:15 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28595.NLS
[2010/05/11 12:05:15 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10017.nls
[2010/05/11 12:05:15 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10007.nls
[2010/05/11 12:05:13 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_869.nls
[2010/05/11 12:05:13 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_737.nls
[2010/05/11 12:05:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_875.nls
[2010/05/11 12:05:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28597.NLS
[2010/05/11 12:05:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10006.nls
[2010/05/11 12:05:12 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_866.nls
[2010/05/11 12:05:12 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_855.nls
[2010/05/11 12:05:12 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28594.NLS
[2010/05/11 12:05:10 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_852.nls
[2010/05/11 12:05:10 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10082.nls
[2010/05/11 12:05:10 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10029.nls
[2010/05/11 12:05:10 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10010.nls
[2010/05/11 12:05:09 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_20127.nls
[2010/05/11 12:05:05 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2010/05/11 12:04:53 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2010/05/11 12:04:53 | 000,657,548 | ---- | C] () -- C:\WINDOWS\System32\dllcache\CLASSES.CAT
[2010/05/11 12:04:53 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2010/05/11 12:04:53 | 000,390,168 | ---- | C] () -- C:\WINDOWS\System32\dllcache\WFC.CAT
[2010/05/11 12:04:53 | 000,056,081 | ---- | C] () -- C:\WINDOWS\System32\dllcache\DAJAVAC.CAT
[2010/05/11 12:04:53 | 000,052,311 | ---- | C] () -- C:\WINDOWS\System32\dllcache\DX3.CAT
[2010/05/11 12:04:53 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2010/05/11 12:04:53 | 000,022,151 | ---- | C] () -- C:\WINDOWS\System32\dllcache\TCLASSES.CAT
[2010/05/11 12:04:53 | 000,021,281 | ---- | C] () -- C:\WINDOWS\System32\dllcache\XMLDSOC.CAT
[2010/05/11 12:04:53 | 000,014,031 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSJDBC.CAT
[2010/05/11 12:04:53 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2010/05/11 12:04:53 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2010/05/11 12:04:53 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2010/05/11 12:04:11 | 000,097,456 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/11 12:03:22 | 000,000,211 | RHS- | C] () -- C:\boot.ini
[2010/05/11 12:03:17 | 000,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2003/11/20 15:40:00 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll

========== LOP Check ==========

[2010/05/11 18:49:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Panda Security
[2010/05/11 16:15:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2010/05/11 18:57:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/07/14 19:47:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Dropbox
[2010/05/17 20:29:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\ICAClient
[2010/05/11 18:50:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Panda Security
[2010/07/10 15:46:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Spotify

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/05/11 15:31:43 | 000,000,267 | ---- | M] () -- C:\ASWL2K.ini
[2010/05/11 12:23:26 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/05/11 17:46:01 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2010/05/11 12:23:26 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/05/11 12:23:26 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/05/11 12:23:26 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/05/11 17:37:40 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010/05/18 08:26:32 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/07/14 19:47:11 | 1006,632,960 | -HS- | M] () -- C:\pagefile.sys

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/05/11 12:22:58 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2010/05/11 12:03:20 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010/05/11 12:03:20 | 000,626,688 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010/05/11 12:03:20 | 000,417,792 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/14 01:12:08 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B -- C:\WINDOWS\system32\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/14 01:12:10 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/14 01:12:10 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 -- C:\WINDOWS\system32\ws2help.dll

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-06-14 09:49:05
< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP