Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Active Directory Desktop


  • Please log in to reply

#1
Gothos

Gothos

    Member

  • Member
  • PipPip
  • 34 posts
Hi All

I have an active directory desktop that has a "button" to restore the desktop. I've see this before on other machines and it's usually some type of hijack. Did a system scan (1 instance found) with Avast, and a full scan (20+ instance) with MBAM. Also a registry clean with CCleaner and saved the registry changes. Something keeps "starting" because I can see the original desktop wallpaper, then it pops over to this active desktop screen. The system seems to be working OK, although it is a little slow on opening things up, like IE, Outlook, or Firefox for example.

Below is the latest HJC

OTListIt logfile created on: 11/13/2010 7:35:37 AM - Run 2
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\user\Desktop\Security
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.28 Mb Total Physical Memory | 636.77 Mb Available Physical Memory | 62.23% Memory free
1.88 Gb Paging File | 1.62 Gb Available in Paging File | 86.02% Paging File free
Paging file location(s): C:\pagefile.sys 1000 3000;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.68 Gb Total Space | 1.66 Gb Free Space | 2.17% Space Free | Partition Type: NTFS
Drive D: | 647.47 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 843.93 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: RACKEY
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
PRC - C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe (Belkin)
PRC - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Companion\Installs\cpn\ytbb.exe (Yahoo! Inc.)
PRC - C:\Documents and Settings\user\Desktop\Security\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Autodesk Licensing Service [Auto | Running]) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe ()
SRV - (avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Web Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (gupdate [Auto | Stopped]) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [Auto | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (WMDM PMSP Service [Auto | Running]) -- C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Running]) -- C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (ac97intc [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (AegisP [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (ASPI32 [System | Running]) -- C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (aswFsBlk [Auto | Running]) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (aswMon2 [Auto | Running]) -- C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswSP [System | Running]) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi [System | Running]) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (BLKWGU(Belkin) [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\BLKWGU.sys (Belkin Corporation)
DRV - (ctac32k [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctljystk [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (ctprxy2k [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (d347bus [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\d347bus.sys ( )
DRV - (d347prt [Boot | Running]) -- C:\WINDOWS\System32\Drivers\d347prt.sys ( )
DRV - (E100B [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (emupia [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ES1370 [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ES1370MP.sys (Creative Technology Ltd.)
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (ha10kx2k [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hidgame [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\hidgame.sys (Microsoft Corporation)
DRV - (insektxp [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\InsektXp.sys (Captain RED)
DRV - (LwAdiHid [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LwAdiHid.sys (Logitech Inc.)
DRV - (msgame [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\msgame.sys (Microsoft Corporation)
DRV - (ntgrip [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ntgrip.sys (Kensington Technology Group)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (ossrv [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PfModNT [Auto | Running]) -- C:\WINDOWS\System32\PfModNT.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (RT73 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\rt73.sys (Ralink Technology, Corp.)
DRV - (Secdrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (WFsys [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\wfsys.sys (Leadtek Research Inc.)
DRV - (GTNDIS5 [On_Demand | Running]) -- C:\Program Files\Belkin\F5D7050v3\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft...er=6&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft...=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...B_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page_bak = http://www.microsoft...=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant_bak =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/firefox"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}:6.0.19
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.8
FF - prefs.js..extensions.enabledItems: {fd2f951f-77ea-4938-9493-0c892c027a13}:0.9.7

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/04/13 10:07:38 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2010/08/06 16:19:13 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2010/07/26 09:55:58 | 00,000,000 | ---D | M]

[2008/09/17 20:27:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\mozilla\Extensions
[2008/09/17 20:27:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010/11/12 09:07:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\mozilla\Firefox\Profiles\dnnydk1q.default\extensions
[2010/06/29 20:04:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\mozilla\Firefox\Profiles\dnnydk1q.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2010/07/27 02:48:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\mozilla\Firefox\Profiles\dnnydk1q.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/02/20 02:40:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\mozilla\Firefox\Profiles\dnnydk1q.default\extensions\{fd2f951f-77ea-4938-9493-0c892c027a13}
[2010/02/20 02:40:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\mozilla\Firefox\Profiles\dnnydk1q.default\extensions\{fd2f951f-77ea-4938-9493-0c892c027a13}\chrome\mozapps\extensions
[2010/11/12 09:07:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2010/07/26 09:55:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/13 10:07:55 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/09/18 16:36:35 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/11/06 12:39:05 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010/03/31 10:17:06 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
[2010/06/27 11:16:11 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/01 10:09:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/07/26 09:55:52 | 00,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2010/07/26 09:55:52 | 00,138,712 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2010/03/12 23:04:51 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2010/03/12 23:04:51 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2010/03/12 23:04:51 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2010/03/12 23:04:51 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2010/03/12 23:04:51 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2010/03/12 23:04:51 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2010/03/12 23:04:51 | 00,001,096 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (728 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui (AVAST Software)
O4 - HKLM..\Run: [F5D7050v3] C:\Program Files\Belkin\F5D7050v3\Belkinwcui.exe (Belkin)
O4 - HKLM..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" ()
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WINDVDPatch] CTHELPER.EXE (Creative Technology Ltd)
O4 - HKCU..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Download with &DAP - C:\DAP\dapextie.htm ()
O8 - Extra context menu item: Download &all with DAP - C:\DAP\dapextie2.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html (Google Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...ector/swdir.cab (Shockwave ActiveX Control)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.micros...386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} http://a1540.g.akama...meInstaller.exe (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-sec...m/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - D:\Autorun.exe () - [ CDFS ]
O32 - Autorun File - D:\Autorun.inf () - [ CDFS ]
O32 - Autorun File - X:\Autorun.exe (Taleworlds Entertainment) - [ CDFS ]
O32 - Autorun File - X:\Autorun.inf () - [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[2010/11/13 07:21:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Yahoo!
[2010/11/13 07:21:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2010/11/13 07:21:29 | 00,000,000 | ---D | C] -- C:\CCleaner
[2010/11/13 07:06:13 | 00,001,392 | ---- | C] () -- C:\Documents and Settings\user\Desktop\HijackThis.lnk
[2010/11/13 07:06:12 | 00,000,000 | ---D | C] -- C:\HijackThis
[2010/11/13 07:02:00 | 00,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2010/11/13 06:54:38 | 10,730,57792 | -HS- | C] () -- C:\hiberfil.sys
[2010/11/12 19:50:29 | 00,000,564 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/07 10:01:25 | 00,315,903 | ---- | C] () -- C:\Documents and Settings\user\Desktop\minecraft blocks.png
[2010/11/05 21:00:14 | 02,359,350 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Slash's Minecraft Castle.bmp
[2010/11/01 12:56:16 | 00,000,177 | ---- | C] () -- C:\Documents and Settings\user\Desktop\server.properties
[2010/10/31 09:51:11 | 00,451,968 | ---- | C] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\drivers\rt73.sys
[2010/10/31 09:51:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2010/10/31 09:51:09 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\UpdateDriver.exe
[2010/10/31 09:51:09 | 00,001,684 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Belkin Wireless Networking Utility.lnk
[2010/10/31 09:51:08 | 00,005,224 | ---- | C] () -- C:\WINDOWS\System32\ucuiinfo.ini
[2010/10/31 09:50:58 | 00,000,000 | ---D | C] -- C:\Program Files\Belkin
[2010/10/31 09:50:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\InstallShield
[2010/10/29 20:06:34 | 00,232,501 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Minecraft.exe
[2009/09/09 02:04:20 | 00,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/08/07 21:43:46 | 00,000,032 | ---- | C] () -- C:\WINDOWS\System32\thxcfg.ini
[2008/04/21 14:23:46 | 00,133,120 | ---- | C] () -- C:\WINDOWS\hvdi.dll
[2008/03/29 22:45:06 | 00,000,149 | ---- | C] () -- C:\WINDOWS\SCXEdit.ini
[2008/02/11 08:39:26 | 00,253,952 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008/02/11 08:39:18 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008/02/08 12:53:46 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerLang.dll
[2007/11/15 20:43:06 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/11/10 15:17:30 | 00,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2007/11/10 15:17:30 | 00,000,125 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2007/07/27 13:49:02 | 00,225,355 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 13:49:02 | 00,196,683 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiA.dll
[2007/03/12 18:58:52 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2006/12/22 09:01:36 | 00,059,392 | R--- | C] () -- C:\WINDOWS\System32\streamhlp.dll
[2006/11/06 15:17:33 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2006/08/10 23:44:05 | 00,358,963 | ---- | C] () -- C:\WINDOWS\System32\mfclibary.dll
[2006/04/17 12:50:01 | 00,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2006/03/06 21:46:27 | 00,011,776 | ---- | C] () -- C:\WINDOWS\System32\ZPORT4AS.dll
[2005/12/23 17:43:25 | 00,000,148 | ---- | C] () -- C:\WINDOWS\srwsipx.drv
[2005/12/12 12:35:06 | 00,037,727 | ---- | C] () -- C:\WINDOWS\System32\Emu10kx.ini
[2005/12/12 12:35:06 | 00,000,029 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2005/12/12 12:35:00 | 00,000,180 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI
[2005/12/12 12:34:59 | 00,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[2005/12/05 18:25:22 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 11:37:10 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\lnod32upd.dll
[2005/07/17 08:47:45 | 00,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys
[2005/07/17 08:47:45 | 00,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys
[2005/07/12 13:44:42 | 00,015,872 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD64.DLL
[2005/06/03 08:18:01 | 00,050,176 | ---- | C] () -- C:\WINDOWS\System32\annihilator.dll
[2005/02/24 07:32:00 | 00,540,672 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2005/02/01 20:09:34 | 00,000,046 | ---- | C] () -- C:\WINDOWS\VID_DirectX.INI
[2005/01/18 18:41:52 | 00,000,055 | ---- | C] () -- C:\WINDOWS\rdrive.ini
[2004/12/17 13:52:53 | 00,364,544 | ---- | C] () -- C:\WINDOWS\System32\js32.dll
[2004/12/03 18:17:39 | 00,000,092 | ---- | C] () -- C:\WINDOWS\setihome.ini
[2004/11/11 14:15:39 | 00,000,045 | ---- | C] () -- C:\WINDOWS\BBFDGFJK.ini
[2004/09/06 20:45:49 | 00,000,214 | ---- | C] () -- C:\WINDOWS\MP32WAV.INI
[2004/09/06 20:29:26 | 00,000,005 | ---- | C] () -- C:\WINDOWS\gsatcmp.ini
[2004/08/22 16:04:56 | 00,069,120 | ---- | C] () -- C:\WINDOWS\daemon.dll
[2004/08/15 22:24:42 | 00,000,000 | ---- | C] () -- C:\WINDOWS\EQZoneViewer.INI
[2004/08/15 22:18:56 | 00,000,000 | ---- | C] () -- C:\WINDOWS\EQZONE~1.INI
[2004/08/06 16:26:07 | 00,052,224 | ---- | C] () -- C:\WINDOWS\System32\EQInside.dll
[2004/07/31 17:43:56 | 00,000,281 | ---- | C] () -- C:\WINDOWS\quest.ini
[2004/06/20 22:12:50 | 00,000,327 | ---- | C] () -- C:\WINDOWS\alchem.ini
[2004/06/20 21:31:21 | 00,308,709 | ---- | C] () -- C:\WINDOWS\twaintec.ini
[2004/06/20 21:31:09 | 00,000,048 | ---- | C] () -- C:\WINDOWS\WinInit.Ini
[2004/06/20 21:30:57 | 00,000,648 | ---- | C] () -- C:\WINDOWS\System32\im64.dll
[2004/06/18 13:52:30 | 00,000,000 | ---- | C] () -- C:\WINDOWS\nwcontbuild.INI
[2004/06/11 19:17:30 | 00,000,801 | ---- | C] () -- C:\WINDOWS\QIII.INI
[2004/06/05 11:53:44 | 00,327,680 | ---- | C] () -- C:\WINDOWS\System32\dfxg11.dll
[2004/05/19 16:38:39 | 00,002,727 | ---- | C] () -- C:\WINDOWS\eqlsUIConfig.ini
[2004/05/07 11:04:44 | 00,000,162 | ---- | C] () -- C:\WINDOWS\STHVCD.INI
[2004/03/23 15:38:00 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD.dll
[2004/01/05 18:23:54 | 00,000,730 | ---- | C] () -- C:\WINDOWS\CoD.INI
[2003/10/17 15:08:07 | 00,401,408 | ---- | C] () -- C:\WINDOWS\System32\StepButtonS.dll
[2003/10/17 15:08:05 | 00,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2003/10/17 15:08:05 | 00,172,032 | ---- | C] () -- C:\WINDOWS\System32\MP2enc.dll
[2003/10/10 18:37:03 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2003/10/10 18:37:02 | 00,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2003/09/20 22:20:50 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/08/20 14:48:41 | 00,000,113 | ---- | C] () -- C:\WINDOWS\Inetreg.ini
[2003/06/09 21:33:33 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2003/06/09 21:33:33 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2003/06/09 21:33:33 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2003/05/29 08:20:51 | 00,056,320 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2003/05/18 13:28:03 | 00,217,088 | ---- | C] () -- C:\WINDOWS\System32\libmySQL.dll
[2003/05/18 13:28:03 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\TrackerNET.dll
[2003/05/05 20:07:20 | 00,000,821 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2003/04/25 06:37:30 | 00,001,125 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2003/04/25 06:36:47 | 00,212,992 | ---- | C] () -- C:\WINDOWS\System32\ddfxDll.dll
[2003/04/25 06:36:47 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\ddfxCro.dll
[2003/04/25 06:36:47 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\ddfxCom.dll
[2003/04/25 06:36:47 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\ddfxDw.dll
[2003/04/25 06:36:47 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\ddfxWeb.dll
[2003/04/25 06:36:46 | 00,015,040 | ---- | C] () -- C:\WINDOWS\System32\Mxmidi16.dll
[2003/04/23 00:59:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\TimeHUD.INI
[2003/04/04 18:56:26 | 00,182,272 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2003/02/03 05:26:18 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2002/10/03 13:42:27 | 00,000,034 | ---- | C] () -- C:\WINDOWS\Q3version.ini
[2002/08/29 05:00:00 | 00,001,466 | ---- | C] () -- C:\WINDOWS\win.ini
[2002/08/29 05:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2002/06/06 00:01:58 | 00,029,696 | ---- | C] () -- C:\WINDOWS\System32\asutl8.dll
[2001/05/13 18:23:56 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\SAWZip.dll
[2000/08/17 20:01:12 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2010/11/13 07:27:03 | 00,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2010/11/13 07:23:44 | 03,374,149 | ---- | M] () -- C:\WINDOWS\{00000002-00000000-0000000B-00001102-00000002-80651102}.CDF
[2010/11/13 07:23:44 | 03,374,149 | ---- | M] () -- C:\WINDOWS\{00000002-00000000-0000000B-00001102-00000002-80651102}.BAK
[2010/11/13 07:23:44 | 00,021,828 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/11/13 07:23:00 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/13 07:22:47 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/13 07:22:47 | 00,000,380 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2010/11/13 07:22:45 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/11/13 07:22:33 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/13 07:22:29 | 10,730,57792 | -HS- | M] () -- C:\hiberfil.sys
[2010/11/13 07:21:40 | 00,025,296 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-0000000B-00001102-00000002-80651102}.rfx
[2010/11/13 07:21:40 | 00,025,296 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-0000000B-00001102-00000002-80651102}.rfx
[2010/11/13 07:21:40 | 00,016,516 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-0000000B-00001102-00000002-80651102}.rfx
[2010/11/13 07:21:40 | 00,016,516 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000002-00000000-0000000B-00001102-00000002-80651102}.rfx
[2010/11/13 07:21:40 | 00,002,064 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2010/11/13 07:21:40 | 00,002,064 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2010/11/13 07:21:40 | 00,000,024 | ---- | M] () -- C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-0000000B-00001102-00000002-80651102}.dat
[2010/11/13 07:21:40 | 00,000,024 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000002-00000000-0000000B-00001102-00000002-80651102}.dat
[2010/11/13 07:19:53 | 03,343,508 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db
[2010/11/13 07:06:13 | 00,001,392 | ---- | M] () -- C:\Documents and Settings\user\Desktop\HijackThis.lnk
[2010/11/12 19:50:29 | 00,000,564 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/12 18:52:01 | 00,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/12 12:19:49 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010/11/12 03:00:51 | 35,758,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2010/11/11 21:36:07 | 00,356,120 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/11/11 21:36:07 | 00,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/11 21:36:07 | 00,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/11/11 20:43:37 | 00,001,700 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/11/11 20:43:35 | 00,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/11/07 10:01:26 | 00,315,903 | ---- | M] () -- C:\Documents and Settings\user\Desktop\minecraft blocks.png
[2010/11/05 21:00:14 | 02,359,350 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Slash's Minecraft Castle.bmp
[2010/11/01 12:56:18 | 00,000,177 | ---- | M] () -- C:\Documents and Settings\user\Desktop\server.properties
[2010/10/31 09:51:10 | 00,001,684 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Belkin Wireless Networking Utility.lnk
[2010/10/29 20:06:35 | 00,232,501 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Minecraft.exe
< End of report >


Thanks in advance for your assistance.

Mark
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP