OTL.txt:
----------------------------------------------------------
OTL logfile created on: 09/08/2010 21:20:25 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\admin\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 181.91 Gb Total Space | 9.77 Gb Free Space | 5.37% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: STELLASTARH
Current User Name: admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/08/09 21:18:57 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin\Desktop\OTL.exe
PRC - [2010/02/25 10:43:46 | 000,306,296 | ---- | M] (Sony Ericsson Mobile Communications) -- C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe
PRC - [2010/02/25 10:43:46 | 000,162,936 | ---- | M] (Sony Ericsson Mobile Communications) -- C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe
PRC - [2010/02/18 11:43:20 | 000,490,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2009/11/08 22:09:32 | 000,095,232 | ---- | M] () -- C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
PRC - [2009/04/30 13:23:26 | 000,090,112 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
PRC - [2008/08/29 15:20:56 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008/07/18 16:23:10 | 002,449,408 | ---- | M] (SEC) -- C:\Program Files\MagicTune Premium\MagicTune.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/22 02:54:02 | 000,114,688 | ---- | M] () -- C:\Program Files\MultiScreen\MultiScreen.exe
PRC - [2007/08/23 15:05:00 | 000,045,056 | ---- | M] () -- C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
PRC - [2007/08/09 08:27:52 | 000,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2007/05/29 20:41:34 | 000,910,896 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007/05/29 20:41:16 | 000,149,040 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2007/05/24 18:38:10 | 001,226,288 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe
PRC - [2006/06/13 05:20:00 | 000,127,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXE
PRC - [2006/03/30 14:31:24 | 000,296,488 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\MPS\mscifapp.exe
PRC - [2005/11/11 18:00:56 | 001,005,096 | ---- | M] (McAfee Security) -- C:\Program Files\McAfee.com\Personal Firewall\MpfTray.exe
PRC - [2005/11/11 17:43:04 | 000,548,864 | ---- | M] (McAfee Corporation) -- C:\Program Files\McAfee.com\Personal Firewall\MpfService.exe
PRC - [2005/11/11 17:42:12 | 000,524,288 | ---- | M] (McAfee Security) -- C:\Program Files\McAfee.com\Personal Firewall\MpfAgent.exe
PRC - [2005/10/13 20:56:16 | 000,126,976 | ---- | M] (McAfee, Inc) -- c:\Program Files\McAfee.com\Agent\Mcdetect.exe
PRC - [2005/08/24 17:01:04 | 000,122,368 | ---- | M] (McAfee, Inc) -- c:\Program Files\McAfee.com\Agent\McTskshd.exe
PRC - [2005/08/11 23:02:44 | 000,053,248 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\VSO\oasclnt.exe
PRC - [2005/08/10 12:22:02 | 000,221,184 | ---- | M] (McAfee Inc.) -- c:\Program Files\McAfee.com\VSO\McShield.exe
PRC - [2005/07/12 19:10:18 | 000,963,072 | ---- | M] (McAfee Inc.) -- C:\Program Files\McAfee\SpamKiller\MSKSrvr.exe
PRC - [2005/07/08 19:18:22 | 000,151,552 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\VSO\mcmnhdlr.exe
PRC - [2005/07/08 19:16:16 | 000,483,328 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee.com\VSO\McVSEscn.exe
PRC - [2005/02/17 15:18:58 | 000,110,592 | ---- | M] (Cyberlink, Corp.) -- C:\Program Files\CyberLink\PowerStarter\PowerBar.exe
PRC - [2005/01/14 19:22:52 | 000,737,379 | ---- | M] (Cyberlink) -- C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
PRC - [2005/01/14 19:22:50 | 000,024,576 | ---- | M] (Cyberlink) -- C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
PRC - [2005/01/14 19:22:26 | 000,110,711 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
PRC - [2005/01/14 19:22:24 | 000,172,153 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
PRC - [2004/11/29 18:17:28 | 000,505,856 | ---- | M] () -- C:\WINDOWS\system32\ASWL2K.exe
PRC - [2004/05/06 13:21:04 | 000,496,640 | ---- | M] () -- C:\WINDOWS\system32\ASWLSVC.exe
========== Modules (SafeList) ========== MOD - [2010/08/09 21:18:57 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin\Desktop\OTL.exe
MOD - [2008/04/14 01:11:56 | 001,028,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42.dll
MOD - [2008/02/22 02:53:18 | 000,036,864 | ---- | M] () -- C:\Program Files\MultiScreen\ServiceHook.dll
MOD - [2006/05/03 22:53:54 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\framedyn.dll
MOD - [2005/09/26 19:12:52 | 000,098,304 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee.com\VSO\McVSSkt.Dll
MOD - [1999/03/29 02:34:06 | 000,106,768 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Windows Script\Windows Script Control\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/02/25 10:43:46 | 000,306,296 | ---- | M] (Sony Ericsson Mobile Communications) [Auto | Running] -- C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe -- (EmmaDevMgmtSvc)
SRV - [2010/02/25 10:43:46 | 000,162,936 | ---- | M] (Sony Ericsson Mobile Communications) [Auto | Running] -- C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe -- (EmmaUpdMgmtSvc)
SRV - [2009/11/14 00:07:36 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/04/30 13:23:26 | 000,090,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- (OMSI download service)
SRV - [2008/08/29 15:20:56 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2007/08/23 15:05:00 | 000,045,056 | ---- | M] () [Auto | Running] -- C:\Program Files\MagicTune Premium\MagicTuneEngine.exe -- (MagicTuneEngine)
SRV - [2007/08/09 08:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2007/01/19 13:54:14 | 000,097,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc)
SRV - [2005/11/11 17:43:04 | 000,548,864 | ---- | M] (McAfee Corporation) [Auto | Running] -- C:\Program Files\McAfee.com\Personal Firewall\MpfService.exe -- (MpfService)
SRV - [2005/10/13 20:56:16 | 000,126,976 | ---- | M] (McAfee, Inc) [Auto | Running] -- c:\Program Files\McAfee.com\Agent\Mcdetect.exe -- (McDetect.exe)
SRV - [2005/08/24 17:01:04 | 000,122,368 | ---- | M] (McAfee, Inc) [Auto | Running] -- c:\Program Files\McAfee.com\Agent\McTskshd.exe -- (McTskshd.exe)
SRV - [2005/08/10 12:22:02 | 000,221,184 | ---- | M] (McAfee Inc.) [Auto | Running] -- c:\Program Files\McAfee.com\VSO\McShield.exe -- (McShield)
SRV - [2005/07/12 19:10:18 | 000,963,072 | ---- | M] (McAfee Inc.) [Auto | Running] -- C:\Program Files\McAfee\SpamKiller\MSKSrvr.exe -- (MskService)
SRV - [2005/07/01 20:22:50 | 000,245,760 | ---- | M] (McAfee, Inc) [On_Demand | Stopped] -- C:\Program Files\McAfee.com\Agent\mcupdmgr.exe -- (mcupdmgr.exe)
SRV - [2005/01/14 19:22:50 | 000,024,576 | ---- | M] (Cyberlink) [Auto | Running] -- C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe -- (CyberLink Media Library Service)
SRV - [2005/01/14 19:22:26 | 000,110,711 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe -- (CLSched) CyberLink Task Scheduler (CTS)
SRV - [2005/01/14 19:22:24 | 000,172,153 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe -- (CLCapSvc) CyberLink Background Capture Service (CBCS)
SRV - [2004/05/06 13:21:04 | 000,496,640 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\ASWLSVC.exe -- (ASWLSVC)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\rt73.sys -- (RT73)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\svchost.com1669s\catchme.sys -- (catchme)
DRV - [2010/07/31 00:35:33 | 000,032,352 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\UimBus.sys -- (UimBus)
DRV - [2010/07/30 23:57:33 | 000,038,448 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\hotcore3.sys -- (hotcore3)
DRV - [2009/04/06 10:13:52 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2009/04/06 10:13:52 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggflt.sys -- (ggflt)
DRV - [2008/11/02 21:15:19 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2008/04/13 19:46:20 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\61883.sys -- (61883)
DRV - [2008/04/13 19:46:20 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avc.sys -- (Avc)
DRV - [2008/04/13 19:46:09 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msdv.sys -- (MSDV)
DRV - [2008/04/13 19:46:08 | 000,049,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mstape.sys -- (MSTAPE)
DRV - [2008/04/13 19:46:07 | 000,013,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avcstrm.sys -- (AVCSTRM)
DRV - [2008/04/13 19:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 19:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 19:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 17:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/12/10 14:22:22 | 000,110,120 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3017unic.sys -- (s3017unic) Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM)
DRV - [2007/12/10 14:22:22 | 000,100,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3017obex.sys -- (s3017obex)
DRV - [2007/12/10 14:22:20 | 000,104,616 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3017mgmt.sys -- (s3017mgmt) Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM)
DRV - [2007/12/10 14:22:20 | 000,025,512 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3017nd5.sys -- (s3017nd5) Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS)
DRV - [2007/12/10 14:22:18 | 000,110,632 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3017mdm.sys -- (s3017mdm)
DRV - [2007/12/10 14:22:18 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3017mdfl.sys -- (s3017mdfl)
DRV - [2007/12/10 14:22:14 | 000,083,880 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3017bus.sys -- (s3017bus) Sony Ericsson Device 3017 driver (WDM)
DRV - [2007/03/30 00:49:38 | 000,131,456 | ---- | M] (Paragon) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Uim_IM.sys -- (Uim_IM)
DRV - [2006/11/02 07:00:08 | 000,039,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB)
DRV - [2006/08/28 17:12:04 | 000,013,312 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\MTictwl.sys -- (NCPro)
DRV - [2006/08/28 17:12:04 | 000,013,312 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MTictwl.sys -- (MagicTune)
DRV - [2006/06/13 05:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/06/13 05:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/06/13 05:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/06/13 05:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/06/13 05:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/06/13 05:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/06/13 05:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2006/06/12 03:30:00 | 000,089,264 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS -- (DRVMCDB)
DRV - [2006/03/17 08:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/03/17 08:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2006/03/17 05:20:00 | 000,040,544 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS -- (DRVNDDM)
DRV - [2005/11/11 17:43:52 | 000,080,640 | ---- | M] (McAfee) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\MpFirewall.sys -- (MPFIREWL)
DRV - [2005/10/10 22:49:00 | 003,530,432 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2005/08/30 17:59:00 | 000,094,000 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2005/08/30 17:58:56 | 000,008,304 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2005/08/30 17:57:18 | 000,058,320 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)
DRV - [2005/08/10 12:22:10 | 000,114,464 | ---- | M] (McAfee Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\naiavf5x.sys -- (NaiAvFilter1)
DRV - [2005/07/29 17:11:04 | 000,012,928 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/07/29 17:11:02 | 000,034,048 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005/06/29 17:21:24 | 000,019,328 | R--- | M] (WideView Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DTV_Loader_2X1.sys -- (DTV_Loader_2X1)
DRV - [2005/06/08 18:51:56 | 000,311,936 | ---- | M] (Marvell Semiconductor, Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mrv8k51.sys -- (W8100PCI)
DRV - [2005/02/23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2005/02/05 08:00:00 | 000,085,888 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\m5287.sys -- (m5287)
DRV - [2004/12/01 11:49:00 | 000,051,840 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\m5289.sys -- (m5289)
DRV - [2004/10/27 16:21:30 | 000,145,920 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService)
DRV - [2004/09/06 20:40:04 | 000,018,432 | R--- | M] (Computer & Entertainment, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DTV_Capture_2X0.sys -- (DTV_Capture_2X0)
DRV - [2004/08/13 11:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004/05/20 20:47:22 | 000,258,560 | ---- | M] (Marvell Semiconductor, Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mrv8ka51.sys -- (W8100XP)
DRV - [2004/04/20 11:13:00 | 000,472,960 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2004/03/02 10:26:58 | 000,050,007 | ---- | M] (Analog Deivces) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\adildr.sys -- (ADILOADER) General Purpose USB Driver (adildr.sys)
DRV - [2004/03/02 10:24:16 | 000,127,065 | ---- | M] (Analog Devices Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\adiusbaw.sys -- (adiusbaw)
DRV - [2003/08/06 10:43:00 | 000,159,744 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\fasttx2k.sys -- (fasttx2k)
DRV - [2002/09/09 20:54:06 | 000,016,269 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\ASNDIS5.sys -- (ASNDIS5)
DRV - [2002/07/17 10:05:10 | 000,016,512 | ---- | M] (Adaptec) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (ASPI)
DRV - [2002/05/07 10:44:04 | 000,081,700 | ---- | M] (FUJI PHOTO FILM CO.,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\V4CB011D.SYS -- (FINEPIX_PCC)
DRV - [2001/11/24 22:11:54 | 000,081,924 | ---- | M] (FUJI PHOTO FILM CO.,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VC4CB104.SYS -- (VC4CB104)
DRV - [2001/08/17 15:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 14:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
DRV - [2001/02/01 03:00:00 | 000,147,872 | R--- | M] (Nogatech Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nuvvid2.sys -- (nuvvid2)
DRV - [2000/05/31 15:20:34 | 000,034,712 | ---- | M] (Marimba, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\MrtRate.sys -- (mrtRate)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.comIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://en-GB.start.m...en-GB:official"FF - prefs.js..extensions.enabledItems:
[email protected]:1.19
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems:
[email protected]:4.0.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/24 20:58:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/24 20:58:14 | 000,000,000 | ---D | M]
[2008/09/03 20:10:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Mozilla\Extensions
[2010/08/05 03:44:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\mtzxz5mg.default\extensions
[2010/05/09 22:47:05 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\mtzxz5mg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/02/10 00:50:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\mtzxz5mg.default\extensions\
[email protected][2009/10/03 12:00:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\mtzxz5mg.default\extensions\
[email protected][2009/06/08 18:40:21 | 000,002,164 | ---- | M] () -- C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\mtzxz5mg.default\searchplugins\bing.xml
[2010/08/05 03:44:28 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2007/12/16 22:54:35 | 000,468,480 | ---- | M] (Clickteam) -- C:\Program Files\Mozilla Firefox\plugins\npcnc32.dll
[2007/12/10 18:40:06 | 006,275,816 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\ScorchPDFWrapper.dll
[2010/03/14 20:15:08 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/03/14 20:15:08 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/03/14 20:15:08 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/03/14 20:15:08 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2010/08/09 18:18:26 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee VirusScan) - {BA52B914-B692-46c4-B683-905236F6F655} - c:\Program Files\McAfee.com\VSO\mcvsshl.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [MCAgentExe] c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc)
O4 - HKLM..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe File not found
O4 - HKLM..\Run: [MPFExe] C:\Program Files\McAfee.com\Personal Firewall\MpfTray.exe (McAfee Security)
O4 - HKLM..\Run: [MPSExe] c:\Program Files\McAfee.com\MPS\mscifapp.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSKAGENTEXE] C:\Program Files\McAfee\SpamKiller\MSKAGE~1.exe (McAfee Inc.)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MultiScreen] C:\Program Files\MultiScreen\MultiScreen.exe ()
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Ptipbmf] C:\WINDOWS\System32\ptipbmf.dll (Promise Technology, Inc.)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [TkBellExe] File not found
O4 - HKLM..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe (McAfee, Inc.)
O4 - HKLM..\Run: [VSOCheckTask] C:\Program Files\McAfee.com\VSO\mcmnhdlr.exe (McAfee, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [PowerBar] C:\Program Files\CyberLink\PowerStarter\PowerBar.exe (Cyberlink, Corp.)
O4 - Startup: C:\Documents and Settings\admin\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk = C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000065 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O16 - DPF: {00000000-A6C3-4023-AE3A-22F2983D851D}
https://authenticate...olInstaller.CAB (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
http://download.mcaf...01/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - Reg Error: Key error. File not found
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/25 10:00:41 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
MsConfig - StartUpReg:
Adobe Photo Downloader - hkey= - key= - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg:
Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg:
Google Update - hkey= - key= - C:\Documents and Settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
MsConfig - StartUpReg:
HP Component Manager - hkey= - key= - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company)
MsConfig - StartUpReg:
HP Software Update - hkey= - key= - C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
MsConfig - StartUpReg:
iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg:
NBKeyScan - hkey= - key= - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe (Nero AG)
MsConfig - StartUpReg:
PCMService - hkey= - key= - C:\Program Files\CyberLink\PowerCinema\PCMService.exe (CyberLink Corp.)
MsConfig - StartUpReg:
PowerBar - hkey= - key= - C:\Program Files\CyberLink\PowerStarter\PowerBar.exe (Cyberlink, Corp.)
MsConfig - StartUpReg:
QAGENT - hkey= - key= - C:\QUICKENW\qagent.exe ()
MsConfig - StartUpReg:
QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg:
RemoteControl - hkey= - key= - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
MsConfig - StartUpReg:
Sony Ericsson PC Suite - hkey= - key= - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
MsConfig - StartUpReg:
{1290A33C-85F5-4164-A1BE-7DD299D4986A} - hkey= - key= - C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe (CyberLink Corp.)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error.
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {0E9A3196-39EA-409D-8EB4-20D7FABC191A} - Microsoft .NET Framework 1.0 Hotfix (KB928367)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {14303301-758B-402B-9A0D-2C6A591680DB} - Microsoft .NET Framework 1.0 Service Pack 3 (KB867461)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {78705f0d-e8db-4b2d-8193-982bdda15ecd} - .NET Framework
ActiveX: {81B52903-4C11-11D6-B6E1-00B0D049139F} - Microsoft .NET Framework 1.0 Service Pack 2 (KB867461)
ActiveX: {871F8A30-15A2-11D6-8711-0002B3281F8B} - Microsoft .NET Framework 1.0 Service Pack 1 (KB867461)
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Drivers32: msacm.clmp3enc - C:\Program Files\CyberLink\Power2Go\CLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.dvacm - C:\WINDOWS\System32\DVACM.acm ()
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corp.)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: VIDC.NTN1 - C:\WINDOWS\System32\NUVision.ax (Nogatech Ltd.)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)
========== Files/Folders - Created Within 90 Days ========== [2010/08/09 21:18:56 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\admin\Desktop\OTL.exe
[2010/08/09 18:16:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/08/09 18:04:44 | 000,000,000 | ---D | C] -- C:\svchost.com1669s
[2010/08/03 18:05:15 | 000,000,000 | ---D | C] -- C:\svchost.com6578s
[2010/08/03 15:14:47 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/08/03 15:10:55 | 000,520,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\admin\Desktop\OTM.exe
[2010/08/03 01:13:05 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/08/01 17:20:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/08/01 17:20:49 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/08/01 17:20:49 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/08/01 17:20:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/08/01 17:17:18 | 000,000,000 | ---D | C] -- C:\svchost.com19763s
[2010/08/01 17:17:04 | 000,000,000 | ---D | C] -- C:\svchost.com
[2010/07/31 20:45:17 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/07/30 23:52:48 | 001,170,256 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\admin\Desktop\TDSSKiller.exe
[2010/07/30 09:30:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/07/30 09:20:40 | 009,190,248 | ---- | C] (SUPERAntiSpyware.com) -- C:\Documents and Settings\admin\Desktop\SUPERAntiSpyware.exe
[2010/07/29 10:14:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/29 10:14:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/07/29 10:14:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/29 10:14:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/07 14:16:35 | 000,000,000 | ---D | C] -- C:\Program Files\Multimedia Fusion 2
[2010/06/14 21:34:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Application Data\Facebook
[2010/06/12 16:05:16 | 000,000,000 | ---D | C] -- C:\f859e356c3222e907d
[2010/05/21 21:15:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Local Settings\Application Data\Yahoo!
[2010/05/19 21:12:59 | 000,000,000 | ---D | C] -- C:\Medion
[2010/05/18 07:25:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2010/05/17 22:21:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Application Data\Ulead Systems
[2010/05/17 22:10:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Ulead Systems
[2010/05/17 22:09:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2010/05/15 22:00:15 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
========== Files - Modified Within 90 Days ========== [2010/08/09 21:18:57 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin\Desktop\OTL.exe
[2010/08/09 20:58:32 | 000,000,759 | ---- | M] () -- C:\Documents and Settings\admin\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk
[2010/08/09 20:58:13 | 000,287,584 | ---- | M] () -- C:\WINDOWS\System32\Status.MPF
[2010/08/09 20:57:48 | 000,039,291 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/08/09 20:56:44 | 000,012,700 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/08/09 20:55:43 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/08/09 20:55:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/08/09 18:57:05 | 011,272,192 | ---- | M] () -- C:\Documents and Settings\admin\ntuser.dat
[2010/08/09 18:52:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/09 18:36:00 | 000,000,976 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-844380032-2981759145-68477085-1006UA.job
[2010/08/09 18:19:30 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/08/09 18:18:26 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/09 18:16:41 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\admin\ntuser.ini
[2010/08/09 16:22:54 | 003,817,853 | R--- | M] () -- C:\Documents and Settings\admin\Desktop\svchost.com.exe
[2010/08/08 21:44:54 | 000,527,522 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/08 21:44:54 | 000,445,238 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/08/08 21:44:54 | 000,072,634 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/08/08 20:51:23 | 000,004,314 | ---- | M] () -- C:\Documents and Settings\admin\Desktop\DrWeb-log.csv
[2010/08/08 19:52:00 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/06 23:36:00 | 000,000,924 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-844380032-2981759145-68477085-1006Core.job
[2010/07/31 00:35:33 | 000,032,352 | ---- | M] () -- C:\WINDOWS\System32\drivers\UimBus.sys
[2010/07/30 23:57:33 | 000,038,448 | ---- | M] (Paragon Software Group) -- C:\WINDOWS\System32\drivers\hotcore3.sys
[2010/07/30 21:00:48 | 001,108,900 | ---- | M] () -- C:\Documents and Settings\admin\Desktop\tdsskiller.zip
[2010/07/30 09:23:54 | 009,190,248 | ---- | M] (SUPERAntiSpyware.com) -- C:\Documents and Settings\admin\Desktop\SUPERAntiSpyware.exe
[2010/07/30 08:55:11 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee SpamKiller.lnk
[2010/07/29 10:14:12 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/07/28 09:51:08 | 000,110,592 | ---- | M] () -- C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/25 21:03:01 | 000,024,576 | ---- | M] () -- C:\Documents and Settings\admin\My Documents\We fly to Hamburg on LH4791.doc
[2010/07/25 09:22:02 | 000,001,314 | ---- | M] () -- C:\WINDOWS\QUICKEN.INI
[2010/07/23 16:30:24 | 000,000,020 | ---- | M] () -- C:\WINDOWS\hppsapp.INI
[2010/07/22 16:11:12 | 001,170,256 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\admin\Desktop\TDSSKiller.exe
[2010/07/21 22:30:45 | 000,112,520 | ---- | M] () -- C:\Documents and Settings\admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/21 22:29:30 | 001,621,408 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/14 18:11:03 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/07/14 18:03:27 | 000,000,489 | ---- | M] () -- C:\WINDOWS\Caligari.ini
[2010/07/13 14:25:22 | 000,000,003 | ---- | M] () -- C:\WINDOWS\Twain001.Mtx
[2010/07/13 14:25:19 | 000,000,156 | ---- | M] () -- C:\WINDOWS\Twunk001.MTX
[2010/07/13 14:21:44 | 000,003,507 | ---- | M] () -- C:\WINDOWS\Ulead32.ini
[2010/07/08 17:58:33 | 000,000,759 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Multimedia Fusion 2 - HWA.lnk
[2010/07/07 14:16:49 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Multimedia Fusion 2.lnk
[2010/05/18 07:52:13 | 000,001,922 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/05/18 07:25:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/17 23:34:00 | 000,001,801 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ulead DVD Workshop.lnk
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/08/09 16:22:49 | 003,817,853 | R--- | C] () -- C:\Documents and Settings\admin\Desktop\svchost.com.exe
[2010/08/01 17:20:49 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/08/01 17:20:49 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/08/01 17:20:49 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/08/01 17:20:49 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/08/01 17:20:49 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/07/30 21:00:45 | 001,108,900 | ---- | C] () -- C:\Documents and Settings\admin\Desktop\tdsskiller.zip
[2010/07/25 21:03:01 | 000,024,576 | ---- | C] () -- C:\Documents and Settings\admin\My Documents\We fly to Hamburg on LH4791.doc
[2010/07/23 21:49:04 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee SpamKiller.lnk
[2010/07/08 17:58:33 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Multimedia Fusion 2 - HWA.lnk
[2010/07/07 14:16:49 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Multimedia Fusion 2.lnk
[2010/05/18 07:52:13 | 000,001,922 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/05/17 22:10:58 | 000,001,801 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ulead DVD Workshop.lnk
[2010/02/16 01:29:07 | 000,000,075 | ---- | C] () -- C:\WINDOWS\tidevctl.ini
[2009/07/15 18:52:57 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\drivers\MTictwl.sys
[2009/06/24 21:11:50 | 000,000,172 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/06/08 21:39:41 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/06/07 19:25:20 | 000,004,767 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2009/05/18 21:19:54 | 000,000,227 | ---- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2009/05/18 21:16:30 | 000,000,234 | ---- | C] () -- C:\WINDOWS\PrnHlpLogConfig.ini
[2009/05/18 21:16:15 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_InstantSHareJPG.ini
[2009/05/18 20:57:22 | 000,000,217 | ---- | C] () -- C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini
[2009/05/18 20:55:57 | 000,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2008/10/23 19:59:59 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2008/09/16 10:59:01 | 000,000,901 | ---- | C] () -- C:\WINDOWS\VIEWS.INI
[2008/08/01 15:43:02 | 004,874,240 | ---- | C] () -- C:\WINDOWS\System32\DSE2_DFT.dll
[2008/07/25 20:43:26 | 000,032,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\UimBus.sys
[2008/07/25 20:43:26 | 000,011,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\UimFIO.sys
[2008/07/25 20:43:25 | 000,247,824 | ---- | C] () -- C:\WINDOWS\System32\prgiso.dll
[2008/07/25 20:43:24 | 004,245,008 | ---- | C] () -- C:\WINDOWS\System32\qtp-mt334.dll
[2008/06/15 20:17:47 | 000,000,020 | ---- | C] () -- C:\WINDOWS\hppsapp.INI
[2008/02/07 14:56:09 | 000,000,290 | ---- | C] () -- C:\WINDOWS\KNP.INI
[2008/01/19 20:21:25 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\UKCpInfo.sys
[2007/12/21 23:31:14 | 000,000,489 | ---- | C] () -- C:\WINDOWS\Caligari.ini
[2007/09/22 17:44:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MusicEditor.INI
[2007/09/22 17:42:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Muma60.INI
[2007/08/01 18:31:35 | 000,000,092 | ---- | C] () -- C:\WINDOWS\NogaTw.INI
[2007/06/27 16:13:51 | 000,516,096 | ---- | C] () -- C:\WINDOWS\System32\RegisterDialog.dll
[2007/06/21 20:19:39 | 000,000,050 | ---- | C] () -- C:\WINDOWS\TLTitleData.ini
[2007/06/18 19:49:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\FileMgrExe.INI
[2007/06/17 22:18:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PanelExe.INI
[2007/06/17 22:17:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\AlbumExe.INI
[2007/06/08 08:10:38 | 000,319,488 | ---- | C] () -- C:\WINDOWS\System32\LS3Renderer.dll
[2007/04/13 10:50:23 | 000,471,040 | ---- | C] () -- C:\WINDOWS\dbengine.dll
[2007/04/13 10:50:23 | 000,303,104 | ---- | C] () -- C:\WINDOWS\spy.dll
[2007/04/13 10:50:23 | 000,184,320 | ---- | C] () -- C:\WINDOWS\keyboard.dll
[2007/04/13 10:50:23 | 000,094,208 | ---- | C] () -- C:\WINDOWS\guidll.dll
[2007/04/13 10:50:23 | 000,057,344 | ---- | C] () -- C:\WINDOWS\vxddll.dll
[2007/04/13 10:50:23 | 000,032,768 | ---- | C] () -- C:\WINDOWS\commhook.dll
[2007/04/13 10:50:23 | 000,020,480 | ---- | C] () -- C:\WINDOWS\commque.dll
[2007/04/13 10:50:20 | 000,245,760 | ---- | C] () -- C:\WINDOWS\dialogs.dll
[2007/02/09 22:38:26 | 000,000,016 | ---- | C] () -- C:\WINDOWS\jgcspc2.ini
[2007/01/07 22:37:18 | 000,087,800 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2006/10/02 15:18:40 | 000,000,087 | ---- | C] () -- C:\WINDOWS\msdevctl.ini
[2006/10/02 15:17:39 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2006/10/02 15:17:03 | 000,000,113 | ---- | C] () -- C:\WINDOWS\dswplug.ini
[2006/10/02 15:17:02 | 000,003,507 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
[2006/07/09 11:31:45 | 000,000,632 | ---- | C] () -- C:\WINDOWS\Sofplat.INI
[2006/03/31 13:10:14 | 000,000,018 | ---- | C] () -- C:\WINDOWS\gfact.ini
[2006/03/22 22:08:10 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\hpgt34.dll
[2006/03/22 22:05:38 | 000,091,136 | ---- | C] () -- C:\WINDOWS\System32\Lfkodak.dll
[2006/03/22 22:05:37 | 000,308,224 | ---- | C] () -- C:\WINDOWS\System32\Lffpx7.dll
[2006/03/21 19:57:38 | 000,000,043 | ---- | C] () -- C:\WINDOWS\INTUIT.INI
[2006/03/08 22:51:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2006/03/01 21:23:36 | 000,000,238 | ---- | C] () -- C:\WINDOWS\QHI.INI
[2006/03/01 21:21:12 | 000,000,028 | ---- | C] () -- C:\WINDOWS\ICOA.INI
[2006/03/01 21:21:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QFN.ini
[2006/03/01 21:21:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QDQICK.ini
[2006/02/22 18:29:15 | 000,012,157 | ---- | C] () -- C:\WINDOWS\hpdj5700.ini
[2006/02/22 18:17:44 | 000,000,185 | ---- | C] () -- C:\WINDOWS\intuprof.ini
[2006/02/22 18:17:15 | 000,001,314 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2006/02/21 17:53:24 | 000,000,154 | ---- | C] () -- C:\WINDOWS\adidsl.ini
[2006/02/21 17:53:24 | 000,000,021 | ---- | C] () -- C:\WINDOWS\Fast800.ini
[2006/02/21 17:53:21 | 000,000,342 | ---- | C] () -- C:\WINDOWS\adiras.ini
[2006/02/21 17:53:18 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\coclassfast.dll
[2006/02/21 17:53:18 | 000,046,892 | ---- | C] () -- C:\WINDOWS\System32\adadix16.dll
[2006/02/17 15:16:29 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/11/25 17:40:21 | 000,005,810 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2005/11/25 10:16:30 | 000,000,636 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/11/25 10:14:41 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2005/11/25 10:03:53 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/10/10 22:49:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2005/10/10 22:49:00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2005/10/10 22:49:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2005/10/10 22:49:00 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2005/10/10 22:49:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2005/10/10 22:49:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2005/10/10 22:49:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005/09/09 23:03:52 | 000,002,679 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/04/27 23:38:00 | 000,372,736 | ---- | C] () -- C:\WINDOWS\System32\hpzidi01.dll
[2005/04/27 23:37:49 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/01/06 01:25:18 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\atsdrve.dll
========== LOP Check ========== [2009/05/13 00:28:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Azureus
[2009/11/08 22:09:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2010/07/07 14:18:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Clickteam
[2010/06/14 21:34:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Facebook
[2010/04/07 12:09:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\FMZilla
[2009/07/19 18:29:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\FUJIFILM
[2009/10/18 16:42:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\GrabPro
[2009/02/28 13:12:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\ImTOO Software Studio
[2006/09/24 20:36:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\iView
[2006/03/19 10:52:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Leadertech
[2007/04/05 20:55:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\MobileAction
[2009/06/07 18:46:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\MSNInstaller
[2008/12/23 21:42:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\OpenOffice.org
[2009/10/18 16:56:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Orbit
[2008/01/03 19:36:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Poser 7
[2008/12/03 19:05:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Publish Providers
[2009/10/23 14:58:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Quark
[2008/12/12 19:54:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Samsung
[2006/08/27 21:23:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Serif
[2008/12/03 19:04:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Sony
[2008/12/03 18:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Sony Setup
[2006/02/20 22:54:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Template
[2010/04/07 12:50:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Thinstall
[2010/05/17 22:21:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Ulead Systems
[2010/08/01 17:03:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\uTorrent
[2009/01/25 17:11:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/09/10 21:52:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KKPro
[2006/02/21 18:32:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MCA3C.tmp
[2006/03/26 22:22:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/11/06 00:33:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Quark
[2008/12/03 18:52:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2010/07/13 14:29:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/08 22:18:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TreeDraw
[2010/05/17 22:21:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/06/05 20:56:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >[2006/08/04 17:30:21 | 000,000,177 | ---- | M] () -- C:\ASWL2K.ini
[2005/11/25 10:00:41 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/10/18 10:53:47 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2002/01/01 11:58:28 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2009/07/25 19:35:19 | 343,785,472 | ---- | M] () -- C:\CAPTURE.AVI
[2004/08/04 00:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2008/10/23 20:18:31 | 000,000,074 | ---- | M] () -- C:\CMLoader.log
[2010/08/09 18:30:40 | 000,030,845 | ---- | M] () -- C:\ComboFix.txt
[2005/11/25 10:00:41 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/05/19 21:14:04 | 000,000,000 | ---- | M] () -- C:\debug1.txt
[2008/08/02 20:09:14 | 000,000,139 | ---- | M] () -- C:\drmHeader.bin
[2007/06/22 22:04:20 | 000,000,231 | ---- | M] () -- C:\DrvInst (1).log
[2007/06/22 22:04:18 | 000,000,231 | ---- | M] () -- C:\DrvInst (2).log
[2007/06/22 22:04:22 | 000,000,231 | ---- | M] () -- C:\DrvInst.log
[2006/10/12 20:33:58 | 000,003,054 | ---- | M] () -- C:\dshell.txt
[2006/09/22 23:29:15 | 000,013,824 | ---- | M] () -- C:\dvb.GRF
[2009/11/29 18:42:57 | 000,082,024 | ---- | M] () -- C:\exts.fdb
[2010/05/19 21:14:04 | 000,000,008 | ---- | M] () -- C:\GetFlashID.txt
[2007/04/14 09:18:01 | 000,048,164 | ---- | M] () -- C:\HKCU.reg.txt
[2007/04/14 09:18:01 | 000,048,019 | ---- | M] () -- C:\HKLM.reg.txt
[2006/12/17 20:03:57 | 000,190,937 | ---- | M] () -- C:\hpfr5700.log
[2007/06/22 22:03:47 | 000,001,034 | ---- | M] () -- C:\Install (1).log
[2007/06/21 20:17:05 | 000,001,080 | ---- | M] () -- C:\Install (2).log
[2007/06/22 22:04:40 | 000,000,373 | ---- | M] () -- C:\Install.log
[2005/11/25 10:00:41 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/08/09 14:14:08 | 000,000,000 | ---- | M] () -- C:\Log.txt
[2005/11/25 10:00:41 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/04 13:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/09/03 20:24:57 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/08/09 20:55:27 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2007/05/06 19:10:02 | 000,013,030 | ---- | M] () -- C:\PDOXUSRS.NET
[2009/09/24 16:03:18 | 000,045,056 | ---- | M] () -- C:\QHI.IDB
[2006/02/17 11:59:12 | 000,000,087 | ---- | M] () -- C:\setup.log
[2006/02/21 17:53:24 | 000,000,184 | ---- | M] () -- C:\setuplog.exe
[2008/10/24 12:27:00 | 000,000,232 | -H-- | M] () -- C:\sqmdata00.sqm
[2008/10/25 11:10:13 | 000,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2008/12/24 16:47:03 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2009/05/22 17:18:13 | 000,000,232 | -H-- | M] () -- C:\sqmdata03.sqm
[2009/05/28 09:19:26 | 000,000,232 | -H-- | M] () -- C:\sqmdata04.sqm
[2006/12/09 00:11:56 | 000,000,232 | -H-- | M] () -- C:\sqmdata05.sqm
[2006/12/09 00:12:31 | 000,000,232 | -H-- | M] () -- C:\sqmdata06.sqm
[2006/12/11 04:04:51 | 000,000,232 | -H-- | M] () -- C:\sqmdata07.sqm
[2006/12/25 12:25:19 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2006/12/29 20:21:36 | 000,000,232 | -H-- | M] () -- C:\sqmdata09.sqm
[2007/04/20 17:13:24 | 000,000,232 | -H-- | M] () -- C:\sqmdata10.sqm
[2007/12/08 11:45:40 | 000,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2007/12/24 10:01:13 | 000,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2007/12/26 14:55:25 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2007/12/27 11:35:51 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2008/10/05 13:47:45 | 000,000,232 | -H-- | M] () -- C:\sqmdata15.sqm
[2008/10/07 18:20:25 | 000,000,232 | -H-- | M] () -- C:\sqmdata16.sqm
[2008/10/12 13:35:16 | 000,000,232 | -H-- | M] () -- C:\sqmdata17.sqm
[2008/10/18 14:02:12 | 000,000,232 | -H-- | M] () -- C:\sqmdata18.sqm
[2008/10/24 00:56:18 | 000,000,232 | -H-- | M] () -- C:\sqmdata19.sqm
[2008/10/24 12:27:00 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2008/10/25 11:10:13 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2008/12/24 16:47:03 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2009/05/22 17:18:13 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2009/05/28 09:19:26 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2006/12/09 00:11:56 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2006/12/09 00:12:31 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2006/12/11 04:04:51 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2006/12/25 12:25:18 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2006/12/29 20:21:35 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2007/04/20 17:13:24 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2007/12/08 11:45:39 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2007/12/24 10:01:12 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2007/12/26 14:55:25 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2007/12/27 11:35:51 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2008/10/05 13:47:45 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2008/10/07 18:20:25 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2008/10/12 13:35:16 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2008/10/18 14:02:12 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2008/10/24 00:56:18 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2010/08/09 14:17:56 | 018,554,470 | ---- | M] () -- C:\stub.log
[2007/04/14 09:18:01 | 000,000,794 | ---- | M] () -- C:\sysInfo.txt
[2010/07/30 23:55:24 | 000,063,180 | ---- | M] () -- C:\TDSSKiller.2.4.0.0_30.07.2010_23.53.08_log.txt
[2010/07/31 00:07:46 | 000,063,156 | ---- | M] () -- C:\TDSSKiller.2.4.0.0_31.07.2010_00.05.28_log.txt
[2010/07/31 00:14:53 | 000,063,144 | ---- | M] () -- C:\TDSSKiller.2.4.0.0_31.07.2010_00.12.21_log.txt
[2010/07/31 00:22:28 | 000,063,144 | ---- | M] () -- C:\TDSSKiller.2.4.0.0_31.07.2010_00.20.19_log.txt
[2010/07/31 00:33:48 | 000,063,306 | ---- | M] () -- C:\TDSSKiller.2.4.0.0_31.07.2010_00.31.30_log.txt
[2010/07/31 01:11:56 | 000,063,144 | ---- | M] () -- C:\TDSSKiller.2.4.0.0_31.07.2010_00.40.09_log.txt
[2010/07/31 10:16:39 | 000,061,492 | ---- | M] () -- C:\TDSSKiller.2.4.0.0_31.07.2010_10.11.43_log.txt
[2007/04/13 10:49:05 | 000,000,229 | ---- | M] () -- C:\tmp.ini
[2009/05/18 21:21:57 | 000,000,536 | ---- | M] () -- C:\updatedatfix.log
< %systemroot%\system32\Spool\prtprocs\w32x86\*.* >[2008/07/06 13:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/05/10 21:48:48 | 000,067,072 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2003/06/18 18:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\*. /mp /s > < %systemroot%\System32\config\*.sav >[2005/11/25 09:53:37 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2005/11/25 09:53:37 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2005/11/25 09:53:37 | 000,868,352 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.wt > < %systemroot%\system32\*.ruy > < %systemroot%\Fonts\*.dll >[2005/05/12 00:36:48 | 000,012,288 | ---- | M] (Hewlett-Packard Co.) -- C:\WINDOWS\Fonts\RandFont.dll
< %systemroot%\Fonts\*.com >[2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.exe > < %systemroot%\Fonts\*.ini >[2005/11/25 10:00:19 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 > < %systemroot%\REPAIR\*.bak1 > < %systemroot%\REPAIR\*.ini > < %systemroot%\system32\*.jpg > < %systemroot%\*.jpg > < %systemroot%\*.png > < %systemroot%\*.scr > < %systemroot%\*._sy > < %APPDATA%\Adobe\Update\*.* > < %APPDATA%\Microsoft\*.* >[2007/09/10 20:51:09 | 000,001,610 | -H-- | M] () -- C:\Documents and Settings\admin\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* > < %ALLUSERSPROFILE%\Favorites\*.* > < %APPDATA%\Update\*.* > < %PROGRAMFILES%\*. >[2007/01/07 22:37:10 | 000,000,000 | ---D | M] -- C:\Program Files\Acro Software
[2009/11/14 00:18:45 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/11/14 00:18:23 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe Media Player
[2005/11/25 10:19:19 | 000,000,000 | ---D | M] -- C:\Program Files\aod
[2008/12/03 20:42:44 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2008/09/18 14:07:31 | 000,000,000 | ---D | M] -- C:\Program Files\ArcSoft
[2006/02/17 11:59:18 | 000,000,000 | ---D | M] -- C:\Program Files\ASUS
[2008/01/05 20:20:17 | 000,000,000 | ---D | M] -- C:\Program Files\Audacity
[2010/01/27 22:04:11 | 000,000,000 | ---D | M] -- C:\Program Files\Avanquest update
[2008/11/30 18:58:58 | 000,000,000 | ---D | M] -- C:\Program Files\AviSynth 2.5
[2010/08/01 05:21:31 | 000,000,000 | ---D | M] -- C:\Program Files\Azureus
[2009/11/08 22:09:46 | 000,000,000 | ---D | M] -- C:\Program Files\BBC iPlayer Desktop
[2008/05/15 15:06:59 | 000,000,000 | ---D | M] -- C:\Program Files\Blender Foundation
[2009/06/05 20:55:55 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2009/06/27 14:11:37 | 000,000,000 | ---D | M] -- C:\Program Files\CASIO
[2008/12/26 23:49:36 | 000,000,000 | ---D | M] -- C:\Program Files\CDisplay
[2010/08/09 18:13:48 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2005/11/25 09:58:50 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2008/10/20 20:33:34 | 000,000,000 | ---D | M] -- C:\Program Files\CoreCodec
[2008/03/06 23:23:07 | 000,000,000 | ---D | M] -- C:\Program Files\Coupon Printer
[2005/11/25 10:18:55 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2009/10/17 17:37:17 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2006/02/22 20:48:02 | 000,000,000 | ---D | M] -- C:\Program Files\DTV
[2008/01/03 19:36:19 | 000,000,000 | ---D | M] -- C:\Program Files\e frontier(2)
[2007/09/22 16:49:07 | 000,000,000 | ---D | M] -- C:\Program Files\emagic
[2009/07/19 18:45:25 | 000,000,000 | ---D | M] -- C:\Program Files\FinePixViewer
[2007/02/09 22:38:07 | 000,000,000 | ---D | M] -- C:\Program Files\FOCUSMM
[2010/02/03 01:58:33 | 000,000,000 | ---D | M] -- C:\Program Files\fragMOTION 1.0.0
[2010/04/07 12:23:38 | 000,000,000 | ---D | M] -- C:\Program Files\Free Music Zilla
[2009/07/31 23:32:44 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2007/01/07 22:39:03 | 000,000,000 | ---D | M] -- C:\Program Files\GPLGS
[2007/06/17 20:41:33 | 000,000,000 | ---D | M] -- C:\Program Files\GraphicView32
[2008/10/20 20:33:49 | 000,000,000 | ---D | M] -- C:\Program Files\Haali
[2009/05/18 21:21:44 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2005/11/25 10:14:22 | 000,000,000 | ---D | M] -- C:\Program Files\HighMAT CD Writing Wizard
[2006/12/19 20:46:51 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2010/05/17 22:10:04 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2006/08/27 21:20:36 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information old
[2007/10/05 14:57:07 | 000,000,000 | ---D | M] -- C:\Program Files\Intelligent
[2006/03/08 22:40:27 | 000,000,000 | ---D | M] -- C:\Program Files\InterActual
[2005/11/25 10:14:52 | 000,000,000 | ---D | M] -- C:\Program Files\Internet
[2010/06/08 22:26:38 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2009/06/05 20:56:17 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2010/01/30 17:44:43 | 000,000,000 | ---D | M] -- C:\Program Files\Ipswitch
[2009/06/05 20:56:49 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2006/09/24 20:33:35 | 000,000,000 | ---D | M] -- C:\Program Files\iView Media
[2010/04/07 15:35:17 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2009/06/07 18:40:12 | 000,000,000 | ---D | M] -- C:\Program Files\Kith and Kin Pro
[2010/05/22 21:30:59 | 000,000,000 | ---D | M] -- C:\Program Files\Kith and Kin Pro V3
[2007/03/15 20:21:25 | 000,000,000 | ---D | M] -- C:\Program Files\LDS_CD
[2009/04/16 21:58:12 | 000,000,000 | ---D | M] -- C:\Program Files\LooksBuilder
[2007/01/15 17:19:21 | 000,000,000 | ---D | M] -- C:\Program Files\Macromedia
[2008/05/31 00:56:36 | 000,000,000 | ---D | M] -- C:\Program Files\MagicISO
[2009/07/15 18:52:57 | 000,000,000 | ---D | M] -- C:\Program Files\MagicTune Premium
[2002/01/01 00:32:42 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/05/31 00:58:50 | 000,000,000 | ---D | M] -- C:\Program Files\MAXON
[2006/02/21 18:05:15 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee
[2006/02/21 18:05:01 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee.com
[2006/08/27 21:01:26 | 000,000,000 | ---D | M] -- C:\Program Files\Mesh Online
[2008/09/03 20:38:10 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2005/11/25 10:15:49 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2005/11/25 10:00:50 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2010/05/15 22:00:49 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2009/04/13 13:19:22 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2006/08/27 21:37:51 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Windows Script
[2005/11/25 10:16:55 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2005/11/25 10:15:16 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2007/09/22 17:42:20 | 000,000,000 | ---D | M] -- C:\Program Files\mmg6_deLuxe
[2007/06/17 22:14:17 | 000,000,000 | ---D | M] -- C:\Program Files\Mobile Action
[2010/03/10 23:09:27 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/07/25 20:43:58 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2008/12/03 18:48:40 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2010/05/15 22:00:15 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2009/06/07 18:46:57 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2005/11/25 09:58:12 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2008/10/05 13:21:27 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Messenger
[2006/11/16 10:30:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2010/07/08 17:58:33 | 000,000,000 | ---D | M] -- C:\Program Files\Multimedia Fusion 2
[2009/11/26 14:17:45 | 000,000,000 | ---D | M] -- C:\Program Files\Multimedia Fusion Developer 2
[2010/08/03 18:18:39 | 000,000,000 | ---D | M] -- C:\Program Files\MultiScreen
[2006/10/12 22:20:48 | 000,000,000 | ---D | M] -- C:\Program Files\MyFamily.com
[2010/02/20 20:32:17 | 000,000,000 | ---D | M] -- C:\Program Files\Nero
[2009/07/20 16:36:36 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2005/11/25 09:58:19 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2008/12/23 21:38:26 | 000,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 3
[2010/05/12 13:38:12 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2008/07/25 20:43:02 | 000,000,000 | ---D | M] -- C:\Program Files\Paragon Software
[2009/10/23 14:53:05 | 000,000,000 | ---D | M] -- C:\Program Files\Quark
[2010/08/01 17:43:12 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2005/11/25 10:19:13 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2005/11/25 10:14:30 | 000,000,000 | ---D | M] -- C:\Program Files\Recovery
[2008/09/11 16:57:25 | 000,000,000 | ---D | M] -- C:\Program Files\Red Kawa
[2008/12/03 18:45:51 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2010/03/06 14:47:20 | 000,000,000 | ---D | M] -- C:\Program Files\REGSHAVE
[2006/12/18 21:22:55 | 000,000,000 | ---D | M] -- C:\Program Files\RFViewer
[2006/02/21 17:53:14 | 000,000,000 | ---D | M] -- C:\Program Files\SAGEM
[2008/12/12 19:54:41 | 000,000,000 | ---D | M] -- C:\Program Files\Samsung
[2009/07/15 18:55:32 | 000,000,000 | ---D | M] -- C:\Program Files\SEC
[2006/08/27 21:21:06 | 000,000,000 | ---D | M] -- C:\Program Files\Serif
[2008/01/06 01:25:00 | 000,000,000 | ---D | M] -- C:\Program Files\Sibelius Software
[2008/03/03 13:52:54 | 000,000,000 | ---D | M] -- C:\Program Files\SmartFTP Client
[2008/03/03 13:52:28 | 000,000,000 | ---D | M] -- C:\Program Files\SmartFTP Client 2.5 Setup Files
[2009/06/24 21:11:47 | 000,000,000 | ---D | M] -- C:\Program Files\Sonic
[2009/06/24 21:07:03 | 000,000,000 | ---D | M] -- C:\Program Files\Sony
[2010/03/18 21:40:32 | 000,000,000 | ---D | M] -- C:\Program Files\Sony Ericsson
[2008/12/03 18:37:13 | 000,000,000 | ---D | M] -- C:\Program Files\Sony Setup
[2008/01/07 20:23:48 | 000,000,000 | ---D | M] -- C:\Program Files\Soulseek-Test
[2007/04/13 10:50:26 | 000,000,000 | ---D | M] -- C:\Program Files\TalkItTypeIt Deluxe
[2007/06/21 20:19:00 | 000,000,000 | ---D | M] -- C:\Program Files\Teaching-you
[2006/02/20 23:55:18 | 000,000,000 | ---D | M] -- C:\Program Files\Tiscali Broadband
[2009/06/05 20:18:53 | 000,000,000 | ---D | M] -- C:\Program Files\TreeDraw
[2010/07/14 18:03:27 | 000,000,000 | ---D | M] -- C:\Program Files\truespace6
[2007/12/21 23:32:16 | 000,000,000 | ---D | M] -- C:\Program Files\trueSpace7
[2010/05/17 23:30:19 | 000,000,000 | ---D | M] -- C:\Program Files\Ulead Systems
[2005/11/25 10:02:54 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010/03/06 14:50:29 | 000,000,000 | ---D | M] -- C:\Program Files\USB Driver Vers. 3.2
[2009/12/07 23:23:11 | 000,000,000 | ---D | M] -- C:\Program Files\VCG
[2009/10/18 10:47:08 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2008/06/22 14:36:26 | 000,000,000 | ---D | M] -- C:\Program Files\vixy.net
[2008/08/01 15:55:26 | 000,000,000 | ---D | M] -- C:\Program Files\VOCALOID2
[2008/12/03 18:53:07 | 000,000,000 | ---D | M] -- C:\Program Files\Vstplugins
[2006/12/28 17:37:37 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect
[2006/12/28 17:40:22 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2009/10/15 22:03:52 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/09/03 20:29:33 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2009/06/07 19:21:55 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Sidebar
[2005/11/25 09:59:34 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2008/07/14 12:54:23 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2006/08/03 21:52:51 | 000,000,000 | ---D | M] -- C:\Program Files\WinZip
[2008/08/15 14:10:42 | 000,000,000 | ---D | M] -- C:\Program Files\Wisdom-soft AutoScreenRecorder
[2005/11/25 10:00:50 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2006/09/19 20:38:47 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!
[2008/05/19 20:36:45 | 000,000,000 | ---D | M] -- C:\Program Files\YHBPM
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-05 02:10:22
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < set /c >ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\admin\Application Data
CLASSPATH=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=STELLASTARH
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\admin
LOGONSERVER=\\STELLASTARH
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\Samsung\Samsung PC Studio 3;C:\Program Files\Common Files\DivX Shared;C:\Program Files\QuickTime\QTSystem;C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 35 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=2302
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\QuickTime\QTSystem\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\admin\LOCALS~1\Temp
TMP=C:\DOCUME~1\admin\LOCALS~1\Temp
USERDOMAIN=STELLASTARH
USERNAME=admin
USERPROFILE=C:\Documents and Settings\admin
VLIGHT_ROOT=C:\Program Files\trueSpace7\tS\VirtuaLight
windir=C:\WINDOWS
< %PROGRAMFILES%|bak;true;false;false /fp > < %systemroot%\system32|bak;true;false;false /fp > ========== Alternate Data Streams ========== @Alternate Data Stream - 4348 bytes -> C:\WINDOWS\MESH_SKY.BMP:$Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
< End of report >