New to this forum and need help in cleaning the infection.
Environment: Windows XP SP2, AVG Anti-Virus free Edition 2011 updated till date
AVG detects Win32/Sality, Heur and Virut infections however, doesn't completely cleans them. Every now and then I get a popups for the infections and the only option I have is to move the infected files to AVG Virus Vault.
OTL Logs from my machine have been given below for your reference
=============================
OTL.txt
OTL logfile created on: 5/5/2011 11:15:51 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\HomeUser\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.00 Mb Total Physical Memory | 101.00 Mb Available Physical Memory | 20.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 50.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.41 Gb Total Space | 17.45 Gb Free Space | 71.47% Space Free | Partition Type: NTFS
Drive D: | 39.06 Gb Total Space | 3.14 Gb Free Space | 8.04% Space Free | Partition Type: NTFS
Drive E: | 39.16 Gb Total Space | 0.63 Gb Free Space | 1.61% Space Free | Partition Type: NTFS
Drive F: | 46.41 Gb Total Space | 7.64 Gb Free Space | 16.47% Space Free | Partition Type: NTFS
Drive G: | 32.10 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 2.82 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: H1O2M3E4 | User Name: HomeUser | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/05 11:15:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HomeUser\My Documents\Downloads\OTL.exe
PRC - [2011/04/28 15:45:17 | 001,010,232 | ---- | M] (Google Inc.) -- C:\Documents and Settings\HomeUser\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/02/17 06:22:00 | 003,384,672 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgui.exe
PRC - [2011/02/17 06:21:58 | 002,190,688 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/02/15 05:38:06 | 007,421,280 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2011/02/11 06:25:52 | 001,080,672 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/02/10 07:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2011/02/08 05:33:20 | 000,658,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2011/02/08 05:32:48 | 000,351,072 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2011/02/08 05:32:46 | 000,656,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/12/16 15:38:20 | 000,138,584 | ---- | M] () -- C:\Program Files\TATA DOCOMO 3G\UIExec.exe
PRC - [2010/12/16 15:38:14 | 001,253,224 | ---- | M] () -- C:\Program Files\TATA DOCOMO 3G\TATA DOCOMO 3G.exe
PRC - [2010/12/16 15:37:56 | 000,718,176 | ---- | M] () -- C:\Program Files\TATA DOCOMO 3G\CMUpdater.exe
PRC - [2010/12/16 15:35:48 | 000,252,784 | ---- | M] () -- C:\Program Files\TATA DOCOMO 3G\AssistantServices.exe
PRC - [2004/08/04 00:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2011/05/05 11:15:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HomeUser\My Documents\Downloads\OTL.exe
MOD - [2004/08/04 00:57:02 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (szserver)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/02/15 05:38:06 | 007,421,280 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/12/16 15:35:48 | 000,252,784 | ---- | M] () [Auto | Running] -- C:\Program Files\TATA DOCOMO 3G\AssistantServices.exe -- (UI Assistant Service)
SRV - [2008/07/09 13:08:27 | 000,026,488 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\system32\spupdsvc.exe -- (spupdsvc)
========== Driver Services (SafeList) ==========
DRV - [2011/03/30 17:17:22 | 000,134,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/03/01 14:25:18 | 000,034,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/02/22 08:13:02 | 000,022,992 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/02/10 07:54:00 | 000,296,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/02/10 07:53:54 | 000,027,216 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/02/10 07:53:52 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/01/19 04:32:56 | 000,032,464 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/01/07 06:41:46 | 000,248,656 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/07/15 10:38:10 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZTEusbvoice.sys -- (ZTEusbvoice)
DRV - [2010/07/15 10:38:10 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2010/07/15 10:38:10 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2010/07/15 10:38:10 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2010/07/15 10:38:10 | 000,009,216 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter.sys -- (massfilter)
DRV - [2010/05/12 18:01:06 | 000,059,280 | R--- | M] (iS3, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\szkgfs.sys -- (szkgfs)
DRV - [2009/12/07 17:59:32 | 000,061,328 | R--- | M] (iS3 Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\szkg.sys -- (szkg5)
DRV - [2006/12/21 13:56:00 | 004,405,248 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/12/14 14:14:06 | 000,085,120 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2004/08/04 04:01:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/05/04 19:55:33 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2001/08/23 17:30:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [UIExec] C:\Program Files\TATA DOCOMO 3G\UIExec.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1304533556656 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/05/04 08:44:43 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/11/30 22:45:36 | 000,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/10/17 23:19:38 | 000,000,034 | R--- | M] () - G:\Autorun -- [ CDFS ]
O32 - AutoRun File - [2010/12/06 14:33:29 | 000,000,059 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{2e3fd5e9-7602-11e0-b2b8-0019211c8e3e}\Shell - "" = AutoRun
O33 - MountPoints2\{2e3fd5e9-7602-11e0-b2b8-0019211c8e3e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2e3fd5e9-7602-11e0-b2b8-0019211c8e3e}\Shell\AutoRun\command - "" = G:\Windows\AutoRun.exe -- [2010/12/12 02:56:13 | 000,370,000 | R--- | M] ()
O33 - MountPoints2\{7b60389d-7642-11e0-b2ba-9894e72c4a54}\Shell\AutoRun\command - "" = J:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{7b60389d-7642-11e0-b2ba-9894e72c4a54}\Shell\explore\Command - "" = J:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{7b60389d-7642-11e0-b2ba-9894e72c4a54}\Shell\open\command - "" = J:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{7b60389e-7642-11e0-b2ba-9894e72c4a54}\Shell\AutoRun\command - "" = K:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{7b60389e-7642-11e0-b2ba-9894e72c4a54}\Shell\explore\Command - "" = K:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{7b60389e-7642-11e0-b2ba-9894e72c4a54}\Shell\open\command - "" = K:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2011/05/05 10:51:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2011/05/05 10:40:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2011/05/05 01:01:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak
[2011/05/05 00:39:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2011/05/05 00:30:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2011/05/05 00:29:44 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2011/05/05 00:27:56 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2011/05/05 00:21:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2011/05/05 00:15:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\microsoft
[2011/05/04 23:58:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Start Menu\Programs\CleanUp!
[2011/05/04 23:58:01 | 000,000,000 | ---D | C] -- C:\Program Files\CleanUp!
[2011/05/04 23:30:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\DoctorWeb
[2011/05/04 23:27:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2011/05/04 23:15:57 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/05/04 23:12:34 | 000,000,000 | ---D | C] -- C:\Program Files\Win 32 Heur Removal Tool
[2011/05/04 23:01:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2011/05/04 22:59:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Local Settings\Application Data\NPE
[2011/05/04 22:32:03 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/05/04 22:31:23 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up
[2011/05/04 22:31:17 | 000,000,000 | ---D | C] -- C:\Program Files\MSECACHE
[2011/05/04 22:30:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2011/05/04 22:15:57 | 000,000,000 | ---D | C] -- C:\SDFix
[2011/05/04 21:06:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\iS3
[2011/05/04 21:05:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/05/04 21:00:27 | 000,000,000 | ---D | C] -- C:\VundoFix Backups
[2011/05/04 20:40:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
[2011/05/04 20:40:16 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2011/05/04 20:38:20 | 000,000,000 | -H-D | C] -- C:\$AVG
[2011/05/04 20:27:46 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2011/05/04 20:27:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Application Data\uTorrent
[2011/05/04 20:27:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Local Settings\Application Data\uTorrent
[2011/05/04 20:19:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Application Data\AVG10
[2011/05/04 19:56:12 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/05/04 19:55:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011
[2011/05/04 19:54:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2011/05/04 19:54:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2011/05/04 19:54:00 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2011/05/04 19:53:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\My Documents\Downloads
[2011/05/04 19:51:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Start Menu\Programs\Google Chrome
[2011/05/04 19:45:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/05/04 17:06:36 | 000,000,000 | --SD | C] -- C:\Documents and Settings\HomeUser\UserData
[2011/05/04 14:03:01 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2011/05/04 14:03:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2011/05/04 14:02:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2011/05/04 14:02:56 | 000,000,000 | R--D | C] -- C:\Program Files
[2011/05/04 14:02:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2011/05/04 14:02:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2011/05/04 14:02:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2011/05/04 14:02:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu
[2011/05/04 14:02:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents
[2011/05/04 14:02:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates
[2011/05/04 14:02:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2011/05/04 14:02:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop
[2011/05/04 14:02:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2011/05/04 14:02:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2011/05/04 14:02:04 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2011/05/04 14:02:04 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data
[2011/05/04 14:01:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings
[2011/05/04 14:01:40 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2011/05/04 13:54:53 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2011/05/04 13:54:53 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2011/05/04 13:54:53 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web
[2011/05/04 13:54:53 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\pchealth
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\ehome
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2011/05/04 13:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2011/05/04 09:24:52 | 000,105,088 | ---- | C] (ZTE Incorporated) -- C:\WINDOWS\System32\drivers\ZTEusbvoice.sys
[2011/05/04 09:24:52 | 000,105,088 | ---- | C] (ZTE Incorporated) -- C:\WINDOWS\System32\drivers\ZTEusbser6k.sys
[2011/05/04 09:24:52 | 000,105,088 | ---- | C] (ZTE Incorporated) -- C:\WINDOWS\System32\drivers\ZTEusbnmea.sys
[2011/05/04 09:24:52 | 000,105,088 | ---- | C] (ZTE Incorporated) -- C:\WINDOWS\System32\drivers\ZTEusbmdm6k.sys
[2011/05/04 09:24:52 | 000,009,216 | ---- | C] (ZTE Incorporated) -- C:\WINDOWS\System32\drivers\massfilter.sys
[2011/05/04 09:24:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\TATA DOCOMO 3G
[2011/05/04 09:24:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SupportAppCB
[2011/05/04 09:24:42 | 000,000,000 | ---D | C] -- C:\Program Files\TATA DOCOMO 3G
[2011/05/04 09:20:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
[2011/05/04 09:19:43 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2011/05/04 09:19:36 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2011/05/04 09:19:18 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2011/05/04 09:19:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2011/05/04 09:16:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Local Settings\Application Data\Adobe
[2011/05/04 09:16:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Application Data\Adobe
[2011/05/04 09:15:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2011/05/04 09:15:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Local Settings\Application Data\Microsoft Help
[2011/05/04 09:14:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2011/05/04 09:14:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2011/05/04 09:14:39 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2011/05/04 09:13:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Application Data\Macromedia
[2011/05/04 09:13:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Talk
[2011/05/04 09:13:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Local Settings\Application Data\Google
[2011/05/04 09:13:30 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2011/05/04 09:13:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\CutePDF
[2011/05/04 09:13:07 | 000,000,000 | ---D | C] -- C:\Program Files\Acro Software
[2011/05/04 09:12:53 | 000,000,000 | ---D | C] -- C:\Program Files\GPLGS
[2011/05/04 09:12:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
[2011/05/04 09:12:40 | 000,839,680 | ---- | C] (http://www.mp3dev.org/) -- C:\WINDOWS\System32\lameACM.acm
[2011/05/04 09:12:40 | 000,237,568 | ---- | C] (www.helixcommunity.org) -- C:\WINDOWS\System32\yv12vfw.dll
[2011/05/04 09:12:40 | 000,151,552 | ---- | C] (fccHandler) -- C:\WINDOWS\System32\ac3acm.acm
[2011/05/04 09:12:37 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack
[2011/05/04 09:10:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011/05/04 09:10:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2011/05/04 09:10:40 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011/05/04 09:06:35 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2011/05/04 09:06:35 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2011/05/04 09:06:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\RTCOM
[2011/05/04 09:05:28 | 002,808,832 | R--- | C] (RealTek Semicoductor Corp.) -- C:\WINDOWS\alcwzrd.exe
[2011/05/04 09:04:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2011/05/04 09:04:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang
[2011/05/04 09:02:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2011/05/04 09:02:12 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2011/05/04 09:01:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Tools
[2011/05/04 09:01:09 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2011/05/04 08:59:51 | 000,004,864 | R--- | C] (Windows ® Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\PortIo.sys
[2011/05/04 08:59:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Application Data\Identities
[2011/05/04 08:59:00 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2011/05/04 08:58:59 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HomeUser\My Documents\My Music
[2011/05/04 08:58:58 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HomeUser\My Documents\My Pictures
[2011/05/04 08:58:55 | 000,000,000 | --SD | C] -- C:\Documents and Settings\HomeUser\Application Data\Microsoft
[2011/05/04 08:58:55 | 000,000,000 | --SD | C] -- C:\Documents and Settings\HomeUser\Cookies
[2011/05/04 08:58:55 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\HomeUser\SendTo
[2011/05/04 08:58:55 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\HomeUser\Recent
[2011/05/04 08:58:55 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\HomeUser\Application Data
[2011/05/04 08:58:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HomeUser\Start Menu\Programs\Startup
[2011/05/04 08:58:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HomeUser\Start Menu
[2011/05/04 08:58:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HomeUser\My Documents
[2011/05/04 08:58:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HomeUser\Favorites
[2011/05/04 08:58:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\HomeUser\Start Menu\Programs\Accessories
[2011/05/04 08:58:55 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\HomeUser\Templates
[2011/05/04 08:58:55 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\HomeUser\PrintHood
[2011/05/04 08:58:55 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\HomeUser\NetHood
[2011/05/04 08:58:55 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\HomeUser\Local Settings
[2011/05/04 08:58:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Local Settings\Application Data\Microsoft
[2011/05/04 08:58:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HomeUser\Desktop
[2011/05/04 08:57:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2011/05/04 08:57:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2011/05/04 08:57:46 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2011/05/04 08:57:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2011/05/04 08:57:45 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2011/05/04 08:48:13 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2011/05/04 08:48:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2011/05/04 08:46:47 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2011/05/04 08:46:47 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2011/05/04 08:46:47 | 000,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2011/05/04 08:45:34 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2011/05/04 08:45:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2011/05/04 08:45:04 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2011/05/04 08:45:04 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2011/05/04 08:43:45 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM
[2011/05/04 08:43:33 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2011/05/04 08:43:33 | 000,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2011/05/04 08:43:22 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2011/05/04 08:42:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2011/05/04 08:42:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2011/05/04 08:42:07 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2011/05/04 08:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2011/05/04 08:41:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2011/05/04 08:41:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2011/05/04 08:41:43 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2011/05/04 08:41:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2011/05/04 08:41:21 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2011/05/04 08:41:16 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2011/05/04 08:41:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2011/05/04 08:41:01 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2011/05/04 08:41:00 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2011/05/04 08:40:41 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2011/05/04 08:40:32 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2011/05/04 08:40:26 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2011/05/04 08:40:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2011/05/04 08:40:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2011/05/04 08:40:19 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2011/05/04 08:40:19 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services
[2011/05/04 08:40:14 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2011/05/04 08:40:06 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2011/05/04 08:38:59 | 000,281,088 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe
[2011/05/04 08:38:59 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2011/05/04 08:38:57 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2011/05/04 08:38:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2011/05/04 08:38:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2011/05/04 08:38:35 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2011/05/04 08:38:08 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[2011/05/03 18:36:04 | 000,132,560 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3HTUI5.dll
[2011/05/03 18:36:02 | 000,546,256 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\SZComp5.dll
[2011/05/03 18:36:02 | 000,452,048 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\SZBase5.dll
[2011/05/03 18:36:02 | 000,022,992 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\SZIO5.dll
[2011/05/03 18:36:00 | 000,398,800 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3DBA5.dll
[2011/05/03 18:36:00 | 000,028,624 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3XDat5.dll
[2011/05/03 18:35:56 | 000,067,024 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Hks5.dll
[2011/05/03 18:35:54 | 000,099,792 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Svc5.dll
[2011/05/03 18:35:54 | 000,099,792 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Inet5.dll
[2011/05/03 18:35:52 | 000,390,608 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3UI5.dll
[2011/05/03 18:35:52 | 000,230,864 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Win325.dll
[2011/05/03 18:35:50 | 000,738,768 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Base5.dll
[52 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/05 11:07:39 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/05/05 11:03:51 | 000,000,190 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2011/05/05 10:54:08 | 000,000,990 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-884357618-839522115-1003UA.job
[2011/05/05 10:49:21 | 114,161,810 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/05/05 10:38:54 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/05/05 10:38:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/05 00:59:50 | 000,000,078 | ---- | M] () -- C:\WINDOWS\System32\asr_qtnle
[2011/05/05 00:30:00 | 000,000,078 | ---- | M] () -- C:\WINDOWS\System32\asr_lcnaa
[2011/05/05 00:29:46 | 000,000,078 | ---- | M] () -- C:\WINDOWS\System32\asr_lyhkj
[2011/05/05 00:15:54 | 000,000,798 | ---- | M] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/05/05 00:11:53 | 000,000,079 | ---- | M] () -- C:\WINDOWS\System32\asr_tvcdc
[2011/05/05 00:10:51 | 000,000,079 | ---- | M] () -- C:\WINDOWS\System32\asr_vahiv
[2011/05/05 00:07:59 | 000,314,838 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/05/05 00:07:59 | 000,041,040 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/05/04 23:57:09 | 000,000,079 | ---- | M] () -- C:\WINDOWS\System32\asr_nrhco
[2011/05/04 23:54:20 | 000,000,079 | ---- | M] () -- C:\WINDOWS\System32\asr_pxbio
[2011/05/04 22:46:37 | 000,000,080 | ---- | M] () -- C:\WINDOWS\System32\asr_ckshv
[2011/05/04 22:32:03 | 000,000,080 | ---- | M] () -- C:\WINDOWS\System32\asr_tyycy
[2011/05/04 21:15:11 | 000,000,078 | ---- | M] () -- C:\WINDOWS\System32\asr_czncs
[2011/05/04 21:00:55 | 000,000,077 | ---- | M] () -- C:\WINDOWS\System32\asr_ppwwd
[2011/05/04 20:27:55 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/05/04 19:54:01 | 000,000,938 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-884357618-839522115-1003Core.job
[2011/05/04 19:51:24 | 000,002,293 | ---- | M] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/05/04 18:16:34 | 000,018,944 | ---- | M] () -- C:\Documents and Settings\HomeUser\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/04 18:10:59 | 000,000,079 | ---- | M] () -- C:\WINDOWS\System32\asr_adiad
[2011/05/04 09:31:18 | 000,000,810 | ---- | M] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/05/04 09:24:48 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TATA DOCOMO 3G.lnk
[2011/05/04 09:22:25 | 000,940,794 | ---- | M] () -- C:\WINDOWS\System32\LoopyMusic.wav
[2011/05/04 09:22:25 | 000,146,650 | ---- | M] () -- C:\WINDOWS\System32\BuzzingBee.wav
[2011/05/04 09:22:05 | 000,263,024 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/04 08:59:10 | 000,000,779 | ---- | M] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/04 08:59:09 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/05/04 08:48:16 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2011/05/04 08:47:29 | 000,000,261 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/05/04 08:44:43 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/05/04 08:44:43 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2011/05/04 08:44:43 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2011/05/04 08:44:43 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2011/05/04 08:44:43 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2011/05/04 08:44:40 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2011/05/04 08:44:39 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/05/04 08:44:39 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/05/04 08:44:28 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2011/05/04 08:40:40 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/05/04 08:37:44 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011/05/03 18:36:04 | 000,132,560 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3HTUI5.dll
[2011/05/03 18:36:02 | 000,546,256 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\SZComp5.dll
[2011/05/03 18:36:02 | 000,452,048 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\SZBase5.dll
[2011/05/03 18:36:02 | 000,022,992 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\SZIO5.dll
[2011/05/03 18:36:00 | 000,398,800 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3DBA5.dll
[2011/05/03 18:36:00 | 000,028,624 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3XDat5.dll
[2011/05/03 18:35:56 | 000,067,024 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Hks5.dll
[2011/05/03 18:35:54 | 000,099,792 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Svc5.dll
[2011/05/03 18:35:54 | 000,099,792 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Inet5.dll
[2011/05/03 18:35:52 | 000,390,608 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3UI5.dll
[2011/05/03 18:35:52 | 000,230,864 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Win325.dll
[2011/05/03 18:35:50 | 000,738,768 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Base5.dll
[52 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/05 11:01:49 | 000,000,190 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2011/05/05 10:49:21 | 114,161,810 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/05/05 00:59:52 | 000,108,031 | ---- | C] () -- C:\WINDOWS\System32\asr_48037.exe
[2011/05/05 00:59:50 | 000,000,078 | ---- | C] () -- C:\WINDOWS\System32\asr_qtnle
[2011/05/05 00:30:00 | 000,000,078 | ---- | C] () -- C:\WINDOWS\System32\asr_lcnaa
[2011/05/05 00:29:46 | 000,000,078 | ---- | C] () -- C:\WINDOWS\System32\asr_lyhkj
[2011/05/05 00:15:54 | 000,000,798 | ---- | C] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/05/05 00:11:50 | 000,000,079 | ---- | C] () -- C:\WINDOWS\System32\asr_tvcdc
[2011/05/05 00:10:51 | 000,000,079 | ---- | C] () -- C:\WINDOWS\System32\asr_vahiv
[2011/05/04 23:57:08 | 000,000,079 | ---- | C] () -- C:\WINDOWS\System32\asr_nrhco
[2011/05/04 23:54:20 | 000,000,079 | ---- | C] () -- C:\WINDOWS\System32\asr_pxbio
[2011/05/04 22:46:37 | 000,000,080 | ---- | C] () -- C:\WINDOWS\System32\asr_ckshv
[2011/05/04 22:32:03 | 000,000,080 | ---- | C] () -- C:\WINDOWS\System32\asr_tyycy
[2011/05/04 22:31:23 | 000,002,333 | ---- | C] () -- C:\Documents and Settings\HomeUser\Start Menu\Programs\Windows Install Clean Up.lnk
[2011/05/04 21:15:11 | 000,000,078 | ---- | C] () -- C:\WINDOWS\System32\asr_czncs
[2011/05/04 21:00:55 | 000,000,077 | ---- | C] () -- C:\WINDOWS\System32\asr_ppwwd
[2011/05/04 20:27:55 | 000,000,654 | ---- | C] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/05/04 19:51:24 | 000,002,293 | ---- | C] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/05/04 19:49:09 | 000,000,990 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-884357618-839522115-1003UA.job
[2011/05/04 19:49:08 | 000,000,938 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-884357618-839522115-1003Core.job
[2011/05/04 18:10:59 | 000,000,079 | ---- | C] () -- C:\WINDOWS\System32\asr_adiad
[2011/05/04 14:03:04 | 000,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/05/04 14:03:00 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/05/04 14:02:58 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2011/05/04 14:02:58 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2011/05/04 14:02:57 | 000,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2011/05/04 14:02:57 | 000,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2011/05/04 14:02:33 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2011/05/04 14:02:23 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2011/05/04 14:02:23 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2011/05/04 14:02:23 | 000,141,702 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2011/05/04 14:02:23 | 000,110,116 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2011/05/04 14:02:23 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2011/05/04 14:02:23 | 000,031,965 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2011/05/04 14:02:23 | 000,031,281 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2011/05/04 14:02:23 | 000,024,209 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat
[2011/05/04 14:02:23 | 000,013,753 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2011/05/04 14:02:23 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2011/05/04 14:02:23 | 000,011,651 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat
[2011/05/04 14:02:23 | 000,009,581 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2011/05/04 14:02:23 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2011/05/04 14:02:23 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2011/05/04 14:02:23 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2011/05/04 14:02:23 | 000,007,245 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2011/05/04 14:02:22 | 002,012,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2011/05/04 14:02:22 | 001,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT
[2011/05/04 14:02:22 | 000,502,724 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2011/05/04 14:01:40 | 000,263,024 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/04 14:01:08 | 000,000,211 | -HS- | C] () -- C:\boot.ini
[2011/05/04 14:01:05 | 000,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/05/04 09:31:18 | 000,000,810 | ---- | C] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/05/04 09:27:44 | 000,000,630 | ---- | C] () -- C:\NetworkCfg.xml
[2011/05/04 09:24:43 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TATA DOCOMO 3G.lnk
[2011/05/04 09:22:25 | 000,940,794 | ---- | C] () -- C:\WINDOWS\System32\LoopyMusic.wav
[2011/05/04 09:22:25 | 000,146,650 | ---- | C] () -- C:\WINDOWS\System32\BuzzingBee.wav
[2011/05/04 09:13:10 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2011/05/04 09:12:41 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2011/05/04 09:12:41 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2011/05/04 09:12:40 | 000,631,808 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/05/04 09:12:40 | 000,243,200 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/05/04 09:12:40 | 000,000,414 | ---- | C] () -- C:\WINDOWS\System32\lame_acm.xml
[2011/05/04 09:12:39 | 000,080,896 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2011/05/04 09:11:26 | 000,018,944 | ---- | C] () -- C:\Documents and Settings\HomeUser\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/04 09:10:57 | 000,001,810 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 7.0.lnk
[2011/05/04 09:08:45 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\NoDfrgFAT.exe
[2011/05/04 09:06:53 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2011/05/04 09:04:38 | 000,655,842 | R--- | C] () -- C:\WINDOWS\System32\igxpxa32.cpa
[2011/05/04 09:04:38 | 000,200,704 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4704.dll
[2011/05/04 09:04:38 | 000,023,632 | R--- | C] () -- C:\WINDOWS\System32\igxpxs32.vp
[2011/05/04 09:04:38 | 000,002,096 | R--- | C] () -- C:\WINDOWS\System32\igxpxk32.vp
[2011/05/04 09:04:38 | 000,000,929 | R--- | C] () -- C:\WINDOWS\System32\igxpxa32.vp
[2011/05/04 09:04:21 | 000,121,232 | R--- | C] () -- C:\WINDOWS\System32\IScrNBR.bmp
[2011/05/04 09:04:21 | 000,121,232 | R--- | C] () -- C:\WINDOWS\System32\IScrNB.bmp
[2011/05/04 08:59:09 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/05/04 08:59:02 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\HomeUser\Start Menu\Programs\Outlook Express.lnk
[2011/05/04 08:59:01 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\HomeUser\Start Menu\Programs\Internet Explorer.lnk
[2011/05/04 08:59:00 | 000,000,779 | ---- | C] () -- C:\Documents and Settings\HomeUser\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/04 08:58:55 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\HomeUser\Start Menu\Programs\Remote Assistance.lnk
[2011/05/04 08:58:55 | 000,000,798 | ---- | C] () -- C:\Documents and Settings\HomeUser\Start Menu\Programs\Windows Media Player.lnk
[2011/05/04 08:48:16 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2011/05/04 08:47:29 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/05/04 08:46:40 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2011/05/04 08:46:20 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2011/05/04 08:46:12 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2011/05/04 08:46:11 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2011/05/04 08:46:09 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2011/05/04 08:46:00 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2011/05/04 08:45:53 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2011/05/04 08:45:49 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2011/05/04 08:45:37 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2011/05/04 08:44:43 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/05/04 08:44:43 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2011/05/04 08:44:43 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2011/05/04 08:44:43 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2011/05/04 08:44:43 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2011/05/04 08:44:39 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/05/04 08:44:39 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/05/04 08:44:38 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2011/05/04 08:43:22 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2011/05/04 08:43:10 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
[2011/05/04 08:42:26 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2011/05/04 08:42:26 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2011/05/04 08:42:16 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2011/05/04 08:41:51 | 000,004,639 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.exe
[2011/05/04 08:41:32 | 000,376,320 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msinfo.dll
[2011/05/04 08:40:41 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2011/05/04 08:40:40 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/05/04 08:40:19 | 000,001,986 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2011/05/04 08:39:38 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
[2011/05/04 08:39:38 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2011/05/04 08:39:37 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
[2011/05/04 08:39:37 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
[2011/05/04 08:39:37 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
[2011/05/04 08:39:37 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
[2011/05/04 08:39:37 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
[2011/05/04 08:39:37 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
[2011/05/04 08:39:36 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
[2011/05/04 08:39:36 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
[2011/05/04 08:39:36 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
[2011/05/04 08:39:32 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2011/05/04 08:39:31 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2011/05/04 08:39:30 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2011/05/04 08:39:15 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2004/08/04 01:07:22 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/02 14:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/07/17 11:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2001/08/23 17:30:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 17:30:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 17:30:00 | 000,314,838 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 17:30:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 17:30:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 17:30:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 17:30:00 | 000,041,040 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 17:30:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 17:30:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 17:30:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/05/04 23:27:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2011/05/04 19:56:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/05/04 20:19:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/05/04 21:35:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/05/04 20:19:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\HomeUser\Application Data\AVG10
[2011/05/04 23:17:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\HomeUser\Application Data\uTorrent
========== Purity Check ==========
< End of report >
=============================
Extras.txt
OTL Extras logfile created on: 5/5/2011 11:15:51 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\HomeUser\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.00 Mb Total Physical Memory | 101.00 Mb Available Physical Memory | 20.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 50.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.41 Gb Total Space | 17.45 Gb Free Space | 71.47% Space Free | Partition Type: NTFS
Drive D: | 39.06 Gb Total Space | 3.14 Gb Free Space | 8.04% Space Free | Partition Type: NTFS
Drive E: | 39.16 Gb Total Space | 0.63 Gb Free Space | 1.61% Space Free | Partition Type: NTFS
Drive F: | 46.41 Gb Total Space | 7.64 Gb Free Space | 16.47% Space Free | Partition Type: NTFS
Drive G: | 32.10 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 2.82 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: H1O2M3E4 | User Name: HomeUser | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.exe [@ = exefile] -- Reg Error: Key error. File not found
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk -- (Google)
"C:\WINDOWS\system32\crssc.exe" = C:\WINDOWS\system32\crssc.exe:*:Enabled:Microsoft Enabled
"C:\WINDOWS\System32\hnm5.exe" = C:\WINDOWS\System32\hnm5.exe:*:Enabled:Microsoft Enabled
"J:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe" = J:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe:*:Enabled:Microsoft Enabled
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{A64FF1D4-9CBC-467C-8D11-C1AFAA0B8AFF}" = AVG 2011
"{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}" = TATA DOCOMO 3G
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{D4E53304-1F6C-4111-9872-1BCD2CF5B642}" = AVG 2011
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"7-Zip" = 7-Zip 9.21beta
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG" = AVG 2011
"CleanUp!" = CleanUp!
"CutePDF Writer Installation" = CutePDF Writer 2.8
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HDMI" = Intel® Graphics Media Accelerator Driver
"KLiteCodecPack_is1" = K-Lite Codec Pack 7.1.0 (Full)
"uTorrent" = µTorrent
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/4/2011 7:42:01 AM | Computer Name = H1O2M3E4 | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/4/2011 8:39:53 AM | Computer Name = H1O2M3E4 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.2180, fault address 0x0012bd68.
Error - 5/4/2011 8:45:03 AM | Computer Name = H1O2M3E4 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0xdec0deba.
Error - 5/4/2011 11:19:25 AM | Computer Name = H1O2M3E4 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
chrome.dll, version 11.0.696.60, fault address 0x0032a2e2.
Error - 5/4/2011 12:38:30 PM | Computer Name = H1O2M3E4 | Source = Application Hang | ID = 1002
Description = Hanging application msiexec.exe, version 3.0.3790.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/4/2011 1:00:57 PM | Computer Name = H1O2M3E4 | Source = MsiInstaller | ID = 11500
Description = Product: Windows Installer Clean Up -- Error 1500. Another installation
is in progress. You must complete that installation before continuing this one.
Error - 5/4/2011 1:00:58 PM | Computer Name = H1O2M3E4 | Source = MsiInstaller | ID = 10005
Description = Product: Windows Installer Clean Up -- Internal Error 2755. 1601,
C:\Program Files\MSECACHE\WICU3\msicuu.msi
Error - 5/4/2011 1:01:43 PM | Computer Name = H1O2M3E4 | Source = VBRuntime | ID = 1
Description = The VB Application identified by the event source logged this Application
MSICUU: Thread ID: 212 ,Logged: Failed: C:\Program Files\Windows Installer Clean
Up\msizap.exe TW! {862ACB14-04CE-46BC-8652-9EA203178DD7}
Error - 5/4/2011 1:31:41 PM | Computer Name = H1O2M3E4 | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/4/2011 2:43:57 PM | Computer Name = H1O2M3E4 | Source = Application Error | ID = 1000
Description = Faulting application outlookconnector.exe, version 14.0.4730.1010,
faulting module outlookconnector.exe, version 14.0.4730.1010, fault address 0x000484f0.
[ System Events ]
Error - 5/4/2011 10:50:28 AM | Computer Name = H1O2M3E4 | Source = Service Control Manager | ID = 7031
Description = The Network Connections to Monitor service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
3000 milliseconds: Restart the service.
Error - 5/4/2011 10:50:31 AM | Computer Name = H1O2M3E4 | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Network Connections to Monitor
service, but this action failed with the following error: %%1058
Error - 5/4/2011 12:39:08 PM | Computer Name = H1O2M3E4 | Source = Service Control Manager | ID = 7034
Description = The Windows Installer service terminated unexpectedly. It has done
this 1 time(s).
Error - 5/4/2011 12:52:44 PM | Computer Name = H1O2M3E4 | Source = Service Control Manager | ID = 7034
Description = The Windows Installer service terminated unexpectedly. It has done
this 2 time(s).
Error - 5/4/2011 1:00:48 PM | Computer Name = H1O2M3E4 | Source = Service Control Manager | ID = 7034
Description = The Windows Installer service terminated unexpectedly. It has done
this 3 time(s).
Error - 5/4/2011 1:57:51 PM | Computer Name = H1O2M3E4 | Source = System Error | ID = 1003
Description = Error code 10000050, parameter1 f4726f5c, parameter2 00000000, parameter3
a2212481, parameter4 00000000.
Error - 5/4/2011 2:25:25 PM | Computer Name = H1O2M3E4 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 5/4/2011 2:50:13 PM | Computer Name = H1O2M3E4 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 5/4/2011 2:50:17 PM | Computer Name = H1O2M3E4 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 5/4/2011 2:50:20 PM | Computer Name = H1O2M3E4 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
< End of report >
=============================