Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

System Mem Usage is High~!


  • Please log in to reply

#1
Kyo_Yamagata

Kyo_Yamagata

    New Member

  • Member
  • Pip
  • 1 posts
The Memory usage of the System is above 70% not only that sometimes my Internet suddenly goes off ... I have to disable and enable just to make it active again. Also, My SandBoxie suddenly stopped working I don't know why.

OTL logfile created on: 2/14/2011 4:11:01 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

767.00 Mb Total Physical Memory | 118.00 Mb Available Physical Memory | 15.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 18.25 Gb Free Space | 62.29% Space Free | Partition Type: NTFS
Drive D: | 45.23 Gb Total Space | 35.73 Gb Free Space | 78.98% Space Free | Partition Type: NTFS
Drive E: | 74.53 Gb Total Space | 25.47 Gb Free Space | 34.18% Space Free | Partition Type: NTFS

Computer Name: LEOPOGI | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/14 16:09:47 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
PRC - [2011/02/14 07:55:53 | 002,007,832 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2011/02/10 11:14:59 | 000,994,872 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2011/02/07 13:39:48 | 004,772,720 | ---- | M] (BitTorrent, Inc.) -- D:\Program Files\BitTorrent\BitTorrent.exe
PRC - [2011/02/05 18:20:00 | 004,174,336 | ---- | M] () -- C:\Program Files\Flashnote\Flashnote.exe
PRC - [2011/01/12 22:35:54 | 000,405,736 | ---- | M] (SANDBOXIE L.T.D) -- D:\Program Files\Sandboxie\SbieCtrl.exe
PRC - [2010/12/20 18:08:46 | 000,963,976 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2010/08/20 00:14:40 | 000,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2010/08/20 00:14:32 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2010/03/06 08:40:53 | 000,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2010/03/06 08:40:53 | 000,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2010/03/06 08:40:52 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/10/18 19:12:00 | 001,983,816 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2005/10/15 17:07:16 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2011/02/14 16:09:47 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
MOD - [2005/10/16 21:55:06 | 001,053,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2649_x-ww_aac16c8b\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/01/12 22:35:52 | 000,069,864 | ---- | M] (SANDBOXIE L.T.D) [Disabled | Stopped] -- D:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/10/12 05:55:00 | 004,172,888 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2010/08/20 00:14:32 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd)
SRV - [2010/03/06 08:40:52 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc)
SRV - [2009/07/24 09:56:04 | 000,247,040 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\AVG\AVG8\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2009/06/19 10:23:48 | 000,618,944 | ---- | M] (Acronis) [Disabled | Stopped] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2002/09/21 06:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Disabled | Stopped] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))


========== Driver Services (SafeList) ==========

DRV - [2011/02/04 07:34:21 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011/01/12 22:35:48 | 000,125,672 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Stopped] -- D:\Program Files\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | Disabled | Running] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010/03/06 09:04:07 | 000,902,592 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\tdrpm228.sys -- (tdrpman228) Acronis Try&Decide and Restore Points filter (build 228)
DRV - [2010/03/06 09:04:04 | 000,540,000 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2010/03/06 09:04:04 | 000,044,704 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2010/03/06 09:03:54 | 000,138,208 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\snapman.sys -- (snapman)
DRV - [2010/03/06 08:41:03 | 000,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/03/06 08:40:58 | 000,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/03/06 08:40:58 | 000,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2008/10/08 05:33:00 | 006,133,856 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2005/04/02 00:25:00 | 000,230,272 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2005/03/02 04:01:40 | 000,392,704 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
DRV - [2004/09/15 04:55:44 | 000,088,960 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MidiSyn.sys -- (MidiSyn)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie_rsearch.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.co...www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\AV, = http://www.altavista...search/web?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\FM, = http://www.filemirro...rch.src?file=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSKB, = http://support.microsoft.com/?kbid=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = http://search.msn.com/results.asp?q=%s
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=;ftp=;https=;

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034"
FF - prefs.js..browser.search.selectedEngine: " "
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.condui...earchSource=13"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [email protected]:6.010.006.004
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {4D144BC3-23FB-47de-90C5-63CCB0139CCF}:1.0
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.4.0024
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:3.2.5.2
FF - prefs.js..keyword.URL: "http://search.avg.co...h&lng=en-US&q="
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2011/02/14 07:57:08 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVG\AVG8\Toolbar\Firefox\[email protected] [2011/01/18 17:01:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/01/27 14:34:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/01/27 14:34:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/30 21:24:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/24 01:56:05 | 000,000,000 | ---D | M]

[2010/08/20 11:54:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/02/07 13:43:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\extensions
[2011/01/20 05:41:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/24 15:14:07 | 000,000,000 | ---D | M] (TradeManager-Plugin) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\extensions\{4D144BC3-23FB-47de-90C5-63CCB0139CCF}
[2010/08/20 12:01:23 | 000,000,000 | ---D | M] (Zynga Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/02/07 13:43:53 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/02/04 07:33:51 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\extensions\[email protected]
[2011/02/07 13:43:54 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\extensions\[email protected]
[2011/02/04 22:49:57 | 000,000,000 | ---D | M] (Platinum Hide IP) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\extensions\[email protected]
[2011/01/23 10:19:05 | 000,002,566 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\searchplugins\askcom.xml
[2011/02/07 13:43:53 | 000,000,863 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\searchplugins\conduit.xml
[2011/02/04 07:33:36 | 000,002,059 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p6mh8mw2.default\searchplugins\daemon-search.xml
[2011/02/14 00:24:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/02/14 07:57:08 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG8\FIREFOX
[2011/01/18 17:01:00 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:id="[email protected]" em:name="AVG Security Toolbar" em:version="6.010.006.004" em:displayname="AVG Security Toolbar" em:iconURL="chrome://tavgp/skin/logo.ico" em:creator="AVG Technologies" em:description="AVG Security Toolbar" em:homepageURL="http://www.avg.com" >) -- C:\PROGRAM FILES\AVG\AVG8\TOOLBAR\FIREFOX\[email protected]
[2011/01/27 14:34:36 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO
[2011/01/27 14:34:36 | 000,000,000 | ---D | M] (DivX HiQ) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA

O1 HOSTS File: ([2001/08/24 01:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Ask Search Assistant BHO) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (Ask.com)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [BitTorrent] D:\Program Files\BitTorrent\BitTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [Flashnote] C:\Program Files\Flashnote\Flashnote.exe ()
O4 - HKLM..\RunOnce: [DCERegBootClean] C:\WINDOWS\RegBootClean.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10i_ActiveX.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCAD = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1282249012421 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 202.78.97.41 210.4.2.61
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/06 08:01:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{ca9a93e1-c44a-11df-bffd-001bfc957814}\Shell\AutoRun\command - "" = kaspersky/kaspersky32.exe
O33 - MountPoints2\{ca9a93e1-c44a-11df-bffd-001bfc957814}\Shell\explore\command - "" = .////////kaspersky/\\\\\kaspersky32.exe
O33 - MountPoints2\{ca9a93e1-c44a-11df-bffd-001bfc957814}\Shell\open\command - "" = kaspersky/////////kaspersky32.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/14 15:45:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/14 15:45:49 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/14 15:45:45 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/14 04:17:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Google
[2011/02/14 04:16:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2011/02/13 22:54:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2011/02/13 22:52:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/13 21:21:32 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
[2011/02/13 14:06:51 | 000,099,759 | ---- | C] (SANDBOXIE L.T.D) -- C:\Documents and Settings\Administrator\My Documents\SandboxieInstall.exe
[2011/02/13 02:46:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Flashnote
[2011/02/13 02:46:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Flashnote
[2011/02/13 02:45:51 | 000,000,000 | ---D | C] -- C:\Program Files\Flashnote
[2011/02/12 18:57:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2011/02/11 07:01:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Search Settings
[2011/02/11 06:51:10 | 000,000,000 | ---D | C] -- C:\Program Files\Search Settings
[2011/02/11 06:50:53 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
[2011/02/11 06:49:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Free Easy Burner
[2011/02/11 06:49:41 | 000,200,704 | ---- | C] (vbAccelerator) -- C:\WINDOWS\System32\vbalExpBar6.ocx
[2011/02/11 06:49:38 | 000,040,960 | ---- | C] (vbAccelerator) -- C:\WINDOWS\System32\SSubTmr6.dll
[2011/02/11 06:49:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\FreeBurner
[2011/02/11 06:49:35 | 000,000,000 | ---D | C] -- C:\Program Files\Free Easy Burner
[2011/02/11 06:42:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\Totally Free Burner
[2011/02/11 06:36:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\Kyo Yamagata's Payroll
[2011/02/07 10:27:11 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2011/02/07 10:08:50 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2011/02/07 09:12:41 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2011/02/07 08:09:12 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2011/02/06 18:46:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\VobSub
[2011/02/06 18:28:18 | 000,000,000 | ---D | C] -- C:\Program Files\Gabest
[2011/02/06 18:27:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2011/02/06 18:26:07 | 000,383,768 | ---- | C] (Headlight Software, Inc.) -- C:\Documents and Settings\Administrator\My Documents\download-vobsub_2.23.exe
[2011/02/06 13:59:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Help
[2011/02/06 13:59:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Help
[2011/02/05 20:06:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\RealHideIP
[2011/02/05 20:06:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\RealHideIP
[2011/02/05 20:06:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Real Hide IP
[2011/02/05 20:06:12 | 000,000,000 | ---D | C] -- C:\Program Files\RealHideIP
[2011/02/04 22:41:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PlatinumHideIP
[2011/02/04 22:41:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\PlatinumHideIP
[2011/02/04 07:34:21 | 000,218,688 | ---- | C] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys
[2011/02/04 07:33:36 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar
[2011/02/04 07:33:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DAEMON Tools Lite
[2011/02/04 07:33:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/02/04 07:33:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\DAEMON Tools Lite
[2011/02/03 08:44:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\Other
[2011/02/01 18:04:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Visual Studio 6.0
[2011/02/01 18:04:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\Microsoft Web Publishing
[2011/02/01 18:04:04 | 000,000,000 | ---D | C] -- C:\Program Files\Web Publish
[2011/01/31 11:50:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Kalydo
[2011/01/31 07:05:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\kylie minogue
[2011/01/31 07:01:34 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/01/31 07:00:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Canon
[2011/01/27 14:34:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Local
[2011/01/27 14:34:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\DivX
[2011/01/27 14:33:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DivX Plus
[2011/01/27 14:32:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DivX Shared
[2011/01/27 14:28:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[2011/01/27 14:26:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2011/01/27 14:21:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp
[2011/01/27 14:21:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2011/01/27 14:20:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Google
[2011/01/27 14:20:51 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2011/01/27 14:20:33 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2011/01/27 14:18:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DivX
[2011/01/27 14:18:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Media Player Classic
[2011/01/27 14:18:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Media Player Classic - Home Cinema
[2011/01/27 07:10:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\New Folder
[2011/01/26 20:29:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2011/01/25 06:47:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Canon Easy-PhotoPrint EX
[2011/01/24 12:00:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2011/01/24 08:59:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\BrowserPlus
[2011/01/24 08:59:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Yahoo!
[2011/01/24 08:21:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Impro-Visor
[2011/01/24 08:21:00 | 000,000,000 | ---D | C] -- C:\Program Files\impro-visor4.12
[2011/01/24 02:18:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/01/24 02:17:32 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/01/24 02:17:30 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/01/24 02:17:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/01/24 02:17:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2011/01/24 02:16:47 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/01/24 01:56:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2011/01/24 01:56:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/01/24 01:56:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2011/01/21 03:43:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\e-Sword
[2011/01/21 03:43:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\EzTools
[2011/01/20 21:27:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Sun
[2011/01/20 20:57:03 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2011/01/20 18:26:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Apple Computer
[2011/01/20 18:06:54 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/01/20 18:06:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Apple
[2011/01/20 18:06:09 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2011/01/20 18:06:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2011/01/20 18:05:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Apple Computer
[2011/01/20 04:39:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\BitTorrent
[2011/01/20 04:14:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/01/20 04:14:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2011/01/20 04:13:50 | 000,000,000 | ---D | C] -- C:\Program Files\DAP
[2011/01/20 04:13:50 | 000,000,000 | ---D | C] -- C:\Program Files\AskSBar
[2011/01/19 23:16:11 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2011/01/19 19:22:52 | 004,172,888 | ---- | C] (INCA Internet Co., Ltd.) -- C:\WINDOWS\System32\GameMon.des
[2011/01/19 19:20:11 | 000,004,682 | ---- | C] (INCA Internet Co., Ltd.) -- C:\WINDOWS\System32\npptNT2.sys
[2011/01/19 19:20:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\INCA Shared
[2011/01/19 09:29:46 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up
[2011/01/19 08:57:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\764393_files
[2011/01/19 08:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2011/01/19 08:18:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2011/01/19 08:18:06 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2011/01/19 08:17:55 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2011/01/19 08:13:27 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
[2011/01/19 08:03:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities
[2011/01/19 08:03:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Identities
[2011/01/18 18:43:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\AVG Security Toolbar
[2011/01/18 18:39:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak
[2011/01/18 18:10:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\CANON
[2011/01/18 18:08:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2011/01/18 18:07:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP250 series Manual
[2011/01/18 18:07:08 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/01/18 18:06:57 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2011/01/18 18:06:34 | 000,000,000 | -H-D | C] -- C:\Program Files\CanonBJ
[2011/01/18 18:01:49 | 000,000,000 | ---D | C] -- C:\Program Files\Canon
[2011/01/18 15:38:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\McAfee
[2011/01/18 15:23:54 | 001,912,872 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Administrator\Desktop\HousecallLauncher.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Administrator\*.tmp files -> C:\Documents and Settings\Administrator\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/14 16:09:01 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/14 15:45:50 | 000,000,650 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/14 14:29:07 | 000,002,139 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Macromedia Flash 8.lnk
[2011/02/14 14:11:54 | 000,001,294 | ---- | M] () -- C:\WINDOWS\RegBootClean.CFG
[2011/02/14 14:11:42 | 000,102,400 | ---- | M] () -- C:\WINDOWS\RegBootClean.exe
[2011/02/14 12:00:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/02/14 09:03:05 | 071,143,366 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/02/14 09:03:02 | 000,492,629 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2011/02/14 09:03:02 | 000,142,495 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2011/02/14 07:50:04 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/14 07:49:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/14 04:17:14 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/02/14 04:17:14 | 000,001,791 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/02/14 04:16:23 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011/02/13 19:42:19 | 000,000,438 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{FF691B74-EA3B-4FCE-97BB-C303E409EF01}.job
[2011/02/13 15:52:33 | 000,433,080 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/02/13 15:52:33 | 000,067,090 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/02/13 14:07:02 | 000,099,759 | ---- | M] (SANDBOXIE L.T.D) -- C:\Documents and Settings\Administrator\My Documents\SandboxieInstall.exe
[2011/02/13 02:46:08 | 000,000,726 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Flashnote.lnk
[2011/02/11 17:43:20 | 000,044,032 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Filipino.doc
[2011/02/11 06:49:42 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Free Easy Burner.lnk
[2011/02/11 06:49:42 | 000,000,768 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Free Easy Burner.lnk
[2011/02/11 06:42:11 | 000,000,658 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Totally Free Burner.lnk
[2011/02/10 16:15:45 | 000,062,976 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Quezon City Polytechnic University.doc
[2011/02/09 15:19:17 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\1KG of kamote.doc
[2011/02/09 12:09:11 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/09 10:56:45 | 003,111,424 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\indoc.doc
[2011/02/09 05:36:28 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/07 13:39:56 | 000,000,536 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\BitTorrent.lnk
[2011/02/07 13:39:56 | 000,000,536 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
[2011/02/07 10:26:14 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011/02/07 10:10:08 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/02/07 10:02:10 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/07 09:35:48 | 000,200,819 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011/02/07 09:02:14 | 000,073,488 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\cc_20110207_0902.reg
[2011/02/07 01:48:10 | 000,000,058 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\New WAVE Audio File.wav
[2011/02/06 20:32:21 | 000,001,083 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\DVDSubEdit.ini
[2011/02/06 18:46:43 | 000,180,428 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\vobsub223fix.zip
[2011/02/06 18:37:01 | 000,734,160 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\VobSub_2.23.exe
[2011/02/06 18:26:08 | 000,383,768 | ---- | M] (Headlight Software, Inc.) -- C:\Documents and Settings\Administrator\My Documents\download-vobsub_2.23.exe
[2011/02/06 17:21:42 | 000,001,490 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/05 20:06:15 | 000,000,706 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Real Hide IP.lnk
[2011/02/04 22:41:56 | 000,000,624 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Platinum Hide IP.lnk
[2011/02/04 07:34:21 | 000,218,688 | ---- | M] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys
[2011/02/04 07:33:30 | 000,000,717 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\DAEMON Tools Lite.lnk
[2011/02/03 14:09:06 | 000,064,856 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\What the....jpg
[2011/02/01 18:29:56 | 000,043,008 | ---- | M] () -- C:\WINDOWS\System32\TABCTL32.oca
[2011/02/01 18:29:56 | 000,037,888 | ---- | M] () -- C:\WINDOWS\System32\sysmon.oca
[2011/02/01 18:29:55 | 000,190,976 | ---- | M] () -- C:\WINDOWS\System32\wmp.oca
[2011/02/01 18:29:54 | 000,024,064 | ---- | M] () -- C:\WINDOWS\System32\rdchost.oca
[2011/02/01 18:29:54 | 000,020,992 | ---- | M] () -- C:\WINDOWS\System32\shimgvw.oca
[2011/02/01 18:29:54 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\regwizc.oca
[2011/02/01 00:56:46 | 000,215,613 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Chinn copy.jpg
[2011/01/27 20:23:54 | 001,138,804 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\IMG_0487.jpg
[2011/01/27 20:22:56 | 000,978,932 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\IMG_0486.jpg
[2011/01/27 20:21:52 | 001,559,709 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\IMG_0485.jpg
[2011/01/27 14:34:41 | 000,001,757 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\DivX Plus Converter.lnk
[2011/01/27 14:34:40 | 000,001,493 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\DivX Movies.lnk
[2011/01/27 14:34:19 | 000,000,777 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2011/01/27 14:28:38 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ETO GAMITIN PAG MAG DOWNLOAD.lnk
[2011/01/27 14:18:13 | 000,000,918 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Media Player Classic - Home Cinema.lnk
[2011/01/27 14:18:13 | 000,000,918 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Player Classic - Home Cinema.lnk
[2011/01/26 20:54:41 | 000,001,542 | ---- | M] () -- C:\WINDOWS\Sandboxie.ini
[2011/01/25 14:50:07 | 001,459,692 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Amagami SS Full Ending 3 - Anata Shika Mei nai.mp3
[2011/01/25 02:38:00 | 000,000,750 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Sandboxed Web Browser.lnk
[2011/01/24 02:54:18 | 000,259,840 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/24 02:18:20 | 000,001,542 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\iTunes.lnk
[2011/01/24 01:56:40 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2011/01/23 16:06:12 | 000,104,385 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\clannad.JPG
[2011/01/23 13:36:50 | 000,106,364 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\champagne_limousines.zip
[2011/01/21 23:17:56 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\SAKOP.doc
[2011/01/21 23:17:56 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Administrator\My Documents\~$SAKOP.doc
[2011/01/21 03:43:08 | 000,001,574 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\e-Sword.lnk
[2011/01/20 10:07:55 | 000,000,515 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\grandchase.lnk
[2011/01/19 08:57:46 | 000,036,246 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\764393.htm
[2011/01/19 07:49:39 | 000,006,896 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\cc_20110119_0749.reg
[2011/01/19 00:43:17 | 000,025,088 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\OBJECTIVE.doc
[2011/01/18 18:10:01 | 000,001,680 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Canon Solution Menu.lnk
[2011/01/18 18:09:50 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Canon Easy-PhotoPrint EX.lnk
[2011/01/18 18:08:45 | 000,001,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Canon MP Navigator EX 3.0.lnk
[2011/01/18 18:08:25 | 000,001,652 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Canon My Printer.lnk
[2011/01/18 18:08:09 | 000,001,967 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Canon MP250 series On-screen Manual.lnk
[2011/01/18 15:24:34 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\housecall.guid.cache
[2011/01/18 15:24:29 | 001,912,872 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Administrator\Desktop\HousecallLauncher.exe
[2011/01/18 15:18:41 | 000,031,089 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\cc_20110117_2318.reg
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Administrator\*.tmp files -> C:\Documents and Settings\Administrator\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/14 15:45:50 | 000,000,650 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/14 14:11:42 | 000,001,294 | ---- | C] () -- C:\WINDOWS\RegBootClean.CFG
[2011/02/14 04:17:14 | 000,001,813 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/02/14 04:16:23 | 000,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011/02/13 02:46:08 | 000,000,726 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Flashnote.lnk
[2011/02/11 17:43:13 | 000,044,032 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Filipino.doc
[2011/02/11 06:49:42 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Free Easy Burner.lnk
[2011/02/11 06:49:42 | 000,000,768 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Free Easy Burner.lnk
[2011/02/11 06:49:41 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\GIF89.DLL
[2011/02/11 06:49:35 | 000,484,352 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2011/02/11 06:42:11 | 000,000,658 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Totally Free Burner.lnk
[2011/02/10 16:15:45 | 000,062,976 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Quezon City Polytechnic University.doc
[2011/02/09 12:00:25 | 000,020,992 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\1KG of kamote.doc
[2011/02/09 10:56:44 | 003,111,424 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\indoc.doc
[2011/02/07 13:39:56 | 000,000,536 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\BitTorrent.lnk
[2011/02/07 13:39:56 | 000,000,536 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
[2011/02/07 10:20:22 | 000,000,438 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{FF691B74-EA3B-4FCE-97BB-C303E409EF01}.job
[2011/02/07 09:05:26 | 000,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/02/07 09:02:09 | 000,073,488 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\cc_20110207_0902.reg
[2011/02/07 01:48:10 | 000,000,058 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\New WAVE Audio File.wav
[2011/02/06 20:32:20 | 000,001,083 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\DVDSubEdit.ini
[2011/02/06 18:46:43 | 000,180,428 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\vobsub223fix.zip
[2011/02/06 18:36:02 | 000,734,160 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\VobSub_2.23.exe
[2011/02/05 20:06:15 | 000,000,706 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Real Hide IP.lnk
[2011/02/04 22:41:56 | 000,000,624 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Platinum Hide IP.lnk
[2011/02/04 07:33:30 | 000,000,717 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\DAEMON Tools Lite.lnk
[2011/02/03 14:09:05 | 000,064,856 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\What the....jpg
[2011/02/01 18:29:56 | 000,043,008 | ---- | C] () -- C:\WINDOWS\System32\TABCTL32.oca
[2011/02/01 18:29:56 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\sysmon.oca
[2011/02/01 18:29:55 | 000,190,976 | ---- | C] () -- C:\WINDOWS\System32\wmp.oca
[2011/02/01 18:29:54 | 000,024,064 | ---- | C] () -- C:\WINDOWS\System32\rdchost.oca
[2011/02/01 18:29:54 | 000,020,992 | ---- | C] () -- C:\WINDOWS\System32\shimgvw.oca
[2011/02/01 18:29:54 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\regwizc.oca
[2011/02/01 17:53:51 | 000,007,356 | ---- | C] () -- C:\WINDOWS\System32\javasup.vxd
[2011/02/01 17:53:51 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2011/02/01 17:53:40 | 000,000,113 | ---- | C] () -- C:\WINDOWS\System32\zonedon.reg
[2011/02/01 17:53:40 | 000,000,113 | ---- | C] () -- C:\WINDOWS\System32\zonedoff.reg
[2011/02/01 00:56:46 | 000,215,613 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Chinn copy.jpg
[2011/02/01 00:07:19 | 000,000,681 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe ImageReady 7.0.lnk
[2011/02/01 00:07:18 | 000,000,678 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Photoshop 7.0.lnk
[2011/01/27 20:23:54 | 001,138,804 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\IMG_0487.jpg
[2011/01/27 20:22:56 | 000,978,932 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\IMG_0486.jpg
[2011/01/27 20:21:52 | 001,559,709 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\IMG_0485.jpg
[2011/01/27 14:34:40 | 000,001,493 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\DivX Movies.lnk
[2011/01/27 14:34:19 | 000,000,777 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2011/01/27 14:33:16 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\DivX Plus Converter.lnk
[2011/01/27 14:28:38 | 000,001,813 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ETO GAMITIN PAG MAG DOWNLOAD.lnk
[2011/01/27 14:28:38 | 000,001,791 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/01/27 14:21:15 | 000,000,900 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/27 14:21:14 | 000,000,896 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/27 14:18:13 | 000,000,918 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Media Player Classic - Home Cinema.lnk
[2011/01/27 14:18:13 | 000,000,918 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Player Classic - Home Cinema.lnk
[2011/01/26 02:28:50 | 000,888,832 | ---- | C] () -- C:\WINDOWS\System32\securenet.dll
[2011/01/25 14:49:27 | 001,459,692 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Amagami SS Full Ending 3 - Anata Shika Mei nai.mp3
[2011/01/25 02:38:35 | 000,000,750 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Sandboxed Web Browser.lnk
[2011/01/24 02:18:20 | 000,001,542 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\iTunes.lnk
[2011/01/24 01:56:40 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2011/01/23 14:25:30 | 000,104,385 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\clannad.JPG
[2011/01/23 13:37:19 | 000,054,608 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Champagne & Limousines Italic.ttf
[2011/01/23 13:37:19 | 000,054,124 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Champagne & Limousines Bold Italic.ttf
[2011/01/23 13:37:19 | 000,053,996 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Champagne & Limousines.ttf
[2011/01/23 13:37:19 | 000,051,604 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Champagne & Limousines Bold.ttf
[2011/01/23 13:36:49 | 000,106,364 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\champagne_limousines.zip
[2011/01/21 23:17:56 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Administrator\My Documents\~$SAKOP.doc
[2011/01/21 23:17:55 | 000,020,992 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\SAKOP.doc
[2011/01/21 03:43:08 | 000,001,574 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\e-Sword.lnk
[2011/01/20 18:06:22 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/20 18:06:10 | 000,002,265 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/01/20 10:07:56 | 000,000,515 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\grandchase.lnk
[2011/01/19 19:20:11 | 000,005,174 | ---- | C] () -- C:\WINDOWS\System32\nppt9x.vxd
[2011/01/19 09:29:46 | 000,001,768 | ---- | C] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Install Clean Up.lnk
[2011/01/19 08:57:44 | 000,036,246 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\764393.htm
[2011/01/19 07:49:36 | 000,006,896 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\cc_20110119_0749.reg
[2011/01/19 00:43:17 | 000,025,088 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\OBJECTIVE.doc
[2011/01/18 22:57:26 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\CNC173AD.TBL
[2011/01/18 18:10:01 | 000,001,680 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Canon Solution Menu.lnk
[2011/01/18 18:09:50 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Canon Easy-PhotoPrint EX.lnk
[2011/01/18 18:08:45 | 000,001,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Canon MP Navigator EX 3.0.lnk
[2011/01/18 18:08:25 | 000,001,652 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Canon My Printer.lnk
[2011/01/18 18:08:09 | 000,001,967 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Canon MP250 series On-screen Manual.lnk
[2011/01/18 16:37:23 | 000,102,400 | ---- | C] () -- C:\WINDOWS\RegBootClean.exe
[2011/01/18 15:24:34 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\housecall.guid.cache
[2011/01/18 15:18:37 | 000,031,089 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\cc_20110117_2318.reg
[2010/08/21 20:02:36 | 000,001,542 | ---- | C] () -- C:\WINDOWS\Sandboxie.ini
[2010/08/20 08:55:01 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/06 09:30:18 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/03/05 23:49:59 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/10/08 05:33:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/10/08 05:33:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/10/08 05:33:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/10/08 05:33:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/10/08 05:33:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/01/15 04:31:00 | 000,000,530 | ---- | C] () -- C:\WINDOWS\System32\tx14_ic.ini
[2005/12/01 21:26:21 | 000,000,114 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/11/22 15:49:22 | 000,394,240 | ---- | C] () -- C:\WINDOWS\System32\HMTCD.dll
[2003/01/08 00:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/16 06:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2001/08/24 01:00:00 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\CopyToSendTo.dll

========== LOP Check ==========

[2011/01/30 22:15:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Acronis
[2011/02/14 16:24:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\BitTorrent
[2011/01/31 07:01:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Canon
[2011/02/04 07:36:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\DAEMON Tools Lite
[2011/02/14 13:12:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Flashnote
[2011/02/12 05:14:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\FreeBurner
[2011/02/06 18:28:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2011/01/31 11:50:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Kalydo
[2011/01/27 14:34:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Local
[2011/02/04 22:41:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PlatinumHideIP
[2011/02/11 07:01:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Search Settings
[2010/08/20 06:21:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SharePod
[2010/03/06 09:04:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acronis
[2011/01/18 17:01:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/01/18 18:07:08 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/02/07 08:09:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2011/01/31 07:01:34 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/02/04 07:33:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/02/05 05:01:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlatinumHideIP
[2011/01/26 20:43:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2011/01/26 20:43:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/01/24 02:18:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/02/13 19:42:19 | 000,000,438 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{FF691B74-EA3B-4FCE-97BB-C303E409EF01}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5BB923A2

< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP