I'll post the log to make it easier to analyze
OTL logfile created on: 6/21/2011 7:11:27 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\theonyxserpent\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
509.98 Mb Total Physical Memory | 68.57 Mb Available Physical Memory | 13.44% Memory free
1.21 Gb Paging File | 0.60 Gb Available in Paging File | 49.47% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 8.82 Gb Free Space | 23.67% Space Free | Partition Type: NTFS
Computer Name: THEONYXCOMPUTER | User Name: theonyxserpent | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/06/21 19:10:58 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\theonyxserpent\My Documents\Downloads\OTL.exe
PRC - [2011/06/19 15:06:41 | 000,180,736 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\Local Settings\temp\csrss.exe
PRC - [2011/06/16 17:32:32 | 000,184,832 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\Application Data\dwm.exe
PRC - [2011/06/16 17:32:07 | 000,176,128 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\Application Data\Microsoft\conhost.exe
PRC - [2011/05/30 18:05:11 | 000,768,512 | ---- | M] () -- C:\WINDOWS\system32\msctf32.exe
PRC - [2011/05/30 18:05:09 | 000,768,512 | ---- | M] () -- C:\WINDOWS\system32\msjtes4032.exe
PRC - [2011/05/30 18:05:09 | 000,768,512 | ---- | M] () -- C:\WINDOWS\system32\digest32.exe
PRC - [2011/05/30 18:05:09 | 000,768,512 | ---- | M] () -- C:\WINDOWS\system32\avifile32.exe
PRC - [2011/05/09 23:01:07 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/08/05 06:17:12 | 000,204,800 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Pro\DTProShellHlp.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/02/09 03:50:00 | 000,578,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\CCM\CcmExec.exe
PRC - [2006/02/09 03:50:00 | 000,248,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe
========== Modules (SafeList) ========== MOD - [2011/06/21 19:10:58 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\theonyxserpent\My Documents\Downloads\OTL.exe
MOD - [2006/08/25 11:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - [2011/05/30 18:05:11 | 000,768,512 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\msctf32.exe -- (WmdmPmSN32)
SRV - [2011/05/30 18:05:09 | 000,768,512 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\digest32.exe -- (VNCTEMP32)
SRV - [2011/05/30 18:05:09 | 000,768,512 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\avifile32.exe -- (Netlogon32)
SRV - [2009/06/16 18:18:45 | 000,469,504 | ---- | M] (Constantin Kaplinsky) [On_Demand | Stopped] -- C:\VNCTEMP\WinVNC.exe -- (VNCTEMP)
SRV - [2008/12/10 15:46:58 | 003,093,880 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2006/02/09 03:50:00 | 000,578,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\CCM\CcmExec.exe -- (CcmExec)
SRV - [2006/02/09 03:50:00 | 000,248,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe -- (Wuser32)
========== Driver Services (SafeList) ========== DRV - [2009/12/14 17:20:33 | 000,722,416 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2006/02/09 03:50:00 | 000,020,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\CCM\PrepDrv.sys -- (prepdrvr)
DRV - [2006/02/09 02:50:00 | 000,011,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\kbstuff5.sys -- (kbstuff)
DRV - [2006/02/09 02:50:00 | 000,008,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\idisw2km.sys -- (idisw2km)
DRV - [2005/11/24 19:51:38 | 000,245,248 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt73.sys -- (RT73)
DRV - [2005/02/01 18:18:38 | 000,017,992 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\bcm42rly.sys -- (BCM42RLY)
DRV - [2003/04/15 10:39:54 | 000,011,319 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\a302.sys -- ({E6759E0C-470B-44DC-A4A1-627E68BB3A85})
DRV - [2001/08/22 08:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 75 2B 18 06 84 C6 C5 4F 94 90 2C 04 01 93 77 62 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50202
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
http://start.mozilla...en-US:official"FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems:
[email protected]:1.10.01
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50202
FF - prefs.js..network.proxy.type: 1
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/09 23:01:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/09 23:01:35 | 000,000,000 | ---D | M]
[2009/12/13 16:09:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\theonyxserpent\Application Data\Mozilla\Extensions
[2004/09/29 02:32:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions
[2004/09/29 02:10:36 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Documents and Settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}
[2011/06/21 18:08:42 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Documents and Settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}
[2010/10/08 23:58:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
() (No name found) -- C:\DOCUMENTS AND SETTINGS\THEONYXSERPENT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OG0G7S2N.DEFAULT\EXTENSIONS\
[email protected][2009/12/12 18:47:36 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/09 23:01:05 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/05/09 23:01:17 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
Hosts file not found
O2 - BHO: (no name) - {06182B75-C684-4FC5-9490-2C0401937762} - C:\WINDOWS\system32\avifile32.dll (CrypKey Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (bc18472a) - {090C0182-31A9-0ECD-FF41-A9974AF03086} - C:\WINDOWS\system32\ole3232.dll (AIDEX Team)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (bc18472a) - {877C1DAE-9760-C59B-1953-F6490A4BEB0D} - C:\WINDOWS\system32\ole3232.dll (AIDEX Team)
O2 - BHO: (Burn4Free Toolbar Helper) - {D187A56B-A33F-4CBE-9D77-459FC0BAE012} - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll ()
O4 - HKLM..\Run: [conhost] C:\Documents and Settings\theonyxserpent\Application Data\Microsoft\conhost.exe ()
O4 - HKLM..\Run: [RandMAC] C:\extracted\MadMACs\MadMACs.exe ()
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTProAgent.exe (DT Soft Ltd)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
F3 - HKCU WinNT: Load - (C:\DOCUME~1\THEONY~1\LOCALS~1\Temp\csrss.exe) - C:\Documents and Settings\theonyxserpent\Local Settings\temp\csrss.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.micros...ntent/opuc2.cab (Office Update Installation Engine)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.mi...b?1232729059632 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = onyx
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\theonyxserpent\Application Data\dwm.exe) - C:\Documents and Settings\theonyxserpent\Application Data\dwm.exe ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/05/10 14:57:30 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/06/19 18:35:40 | 000,778,240 | ---- | C] (AIDEX Team) -- C:\Documents and Settings\theonyxserpent\0.7444794942552231.exe
[2011/06/19 15:51:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\theonyxserpent\Desktop\Weird Al
[2011/06/19 13:43:13 | 000,761,344 | ---- | C] (CrypKey Inc.) -- C:\Documents and Settings\theonyxserpent\0.8392963025605327.exe
[2011/06/18 00:33:24 | 000,764,416 | ---- | C] (CrypKey Inc.) -- C:\Documents and Settings\theonyxserpent\0.13213259864909277.exe
[2011/06/12 01:02:48 | 000,775,168 | ---- | C] (AIDEX Team) -- C:\Documents and Settings\theonyxserpent\0.51216886613992.exe
[2011/06/12 01:02:44 | 000,775,168 | ---- | C] (AIDEX Team) -- C:\Documents and Settings\theonyxserpent\0.030780498129318268.exe
[2011/06/08 23:18:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\theonyxserpent\Local Settings\Application Data\Identities
[2011/06/05 10:24:35 | 000,177,152 | ---- | C] (AIDEX Team) -- C:\WINDOWS\System32\ole323232.dll
[2011/06/04 23:13:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MpEngineStore
[2011/06/01 20:35:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\theonyxserpent\Start Menu\Programs\CleanUp!
[2011/06/01 20:35:25 | 000,000,000 | ---D | C] -- C:\Program Files\CleanUp!
[2011/06/01 20:32:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2011/05/30 22:27:02 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/05/30 22:09:48 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/30 18:05:39 | 000,177,152 | ---- | C] (AIDEX Team) -- C:\WINDOWS\System32\ole3232.dll
[2011/05/30 18:05:10 | 000,349,696 | ---- | C] (CrypKey Inc.) -- C:\WINDOWS\System32\avifile32.dll
[2011/05/29 08:42:15 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/05/29 08:35:04 | 000,000,000 | R--D | C] -- C:\Documents and Settings\theonyxserpent\Start Menu\Programs\Administrative Tools
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\theonyxserpent\*.tmp files -> C:\Documents and Settings\theonyxserpent\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/06/21 19:17:44 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/06/21 19:08:39 | 000,094,468 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\Application Data\47D2.A7B
[2011/06/21 18:15:55 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\0.1353540854083134.exe
[2011/06/20 21:34:12 | 000,045,056 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/20 12:24:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/19 19:52:23 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2011/06/19 18:35:43 | 000,778,240 | ---- | M] (AIDEX Team) -- C:\Documents and Settings\theonyxserpent\0.7444794942552231.exe
[2011/06/19 16:11:20 | 000,000,386 | ---- | M] () -- C:\WINDOWS\SMSCFG.ini
[2011/06/19 16:10:47 | 000,000,330 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2011/06/19 16:10:39 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/19 16:10:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/19 13:43:16 | 000,761,344 | ---- | M] (CrypKey Inc.) -- C:\Documents and Settings\theonyxserpent\0.8392963025605327.exe
[2011/06/19 12:16:00 | 000,000,419 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2011/06/19 02:58:58 | 000,783,360 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\0.15206404849377453.exe
[2011/06/18 23:19:09 | 000,783,360 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\0.28316220305451056.exe
[2011/06/18 03:21:41 | 000,769,536 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\0.7873924106824436.exe
[2011/06/18 00:33:27 | 000,764,416 | ---- | M] (CrypKey Inc.) -- C:\Documents and Settings\theonyxserpent\0.13213259864909277.exe
[2011/06/16 17:32:32 | 000,184,832 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\Application Data\dwm.exe
[2011/06/13 19:21:52 | 063,225,228 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\Desktop\CMOR DEMSEY.wav
[2011/06/13 19:21:03 | 000,022,170 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\Desktop\CMOR DEMSEY.aup
[2011/06/12 01:02:50 | 000,775,168 | ---- | M] (AIDEX Team) -- C:\Documents and Settings\theonyxserpent\0.51216886613992.exe
[2011/06/12 01:02:46 | 000,775,168 | ---- | M] (AIDEX Team) -- C:\Documents and Settings\theonyxserpent\0.030780498129318268.exe
[2011/06/10 23:25:58 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\0.9646917216924414.exe
[2011/06/10 23:25:57 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\0.8217498544660679.exe
[2011/06/05 10:24:37 | 000,000,097 | ---- | M] () -- C:\WINDOWS\System32\918880264
[2011/06/05 10:24:35 | 000,177,152 | ---- | M] (AIDEX Team) -- C:\WINDOWS\System32\ole323232.dll
[2011/06/01 20:35:43 | 000,000,687 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\Desktop\CleanUp!.lnk
[2011/05/30 22:09:48 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/30 18:05:39 | 000,177,152 | ---- | M] (AIDEX Team) -- C:\WINDOWS\System32\ole3232.dll
[2011/05/30 18:05:11 | 000,768,512 | ---- | M] () -- C:\WINDOWS\System32\msctf32.exe
[2011/05/30 18:05:11 | 000,768,512 | ---- | M] () -- C:\WINDOWS\System32\avicap3232.exe
[2011/05/30 18:05:10 | 000,349,696 | ---- | M] (CrypKey Inc.) -- C:\WINDOWS\System32\avifile32.dll
[2011/05/30 18:05:09 | 000,768,512 | ---- | M] () -- C:\WINDOWS\System32\msjtes4032.exe
[2011/05/30 18:05:09 | 000,768,512 | ---- | M] () -- C:\WINDOWS\System32\digest32.exe
[2011/05/30 18:05:09 | 000,768,512 | ---- | M] () -- C:\WINDOWS\System32\avifile32.exe
[2011/05/29 08:42:25 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/05/27 23:10:56 | 000,000,741 | ---- | M] () -- C:\Documents and Settings\theonyxserpent\Desktop\Glary Utilities.lnk
[2011/05/27 22:10:28 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/05/27 21:57:54 | 000,015,618 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\w70st7567b4372d
[2011/05/27 21:57:53 | 000,015,618 | -HS- | M] () -- C:\Documents and Settings\theonyxserpent\Local Settings\Application Data\w70st7567b4372d
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\theonyxserpent\*.tmp files -> C:\Documents and Settings\theonyxserpent\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/06/21 18:15:55 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\0.1353540854083134.exe
[2011/06/19 02:58:56 | 000,783,360 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\0.15206404849377453.exe
[2011/06/18 23:19:06 | 000,783,360 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\0.28316220305451056.exe
[2011/06/18 03:21:38 | 000,769,536 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\0.7873924106824436.exe
[2011/06/13 19:21:13 | 063,225,228 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\Desktop\CMOR DEMSEY.wav
[2011/06/12 22:09:23 | 000,184,832 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\Application Data\dwm.exe
[2011/06/10 23:25:58 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\0.9646917216924414.exe
[2011/06/10 23:25:57 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\0.8217498544660679.exe
[2011/06/05 10:24:37 | 000,768,512 | ---- | C] () -- C:\WINDOWS\System32\avifile32.exe
[2011/06/05 10:24:35 | 000,768,512 | ---- | C] () -- C:\WINDOWS\System32\msjtes4032.exe
[2011/06/05 10:24:35 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\918880264
[2011/06/01 20:35:43 | 000,000,687 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\Desktop\CleanUp!.lnk
[2011/05/30 18:05:41 | 000,768,512 | ---- | C] () -- C:\WINDOWS\System32\avicap3232.exe
[2011/05/30 18:05:24 | 000,768,512 | ---- | C] () -- C:\WINDOWS\System32\digest32.exe
[2011/05/30 18:05:15 | 000,768,512 | ---- | C] () -- C:\WINDOWS\System32\msctf32.exe
[2011/05/29 08:42:25 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/05/29 08:42:19 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/05/22 12:46:25 | 000,000,419 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2011/05/21 19:20:19 | 000,015,618 | -HS- | C] () -- C:\Documents and Settings\theonyxserpent\Local Settings\Application Data\w70st7567b4372d
[2011/05/21 19:20:19 | 000,015,618 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\w70st7567b4372d
[2011/05/21 19:19:55 | 000,094,468 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\Application Data\47D2.A7B
[2011/01/31 00:04:34 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2010/11/19 01:00:37 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/11/19 01:00:32 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/11/19 01:00:32 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/11/19 01:00:31 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010/11/19 01:00:30 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/10/15 21:39:54 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/12/12 17:49:31 | 000,002,733 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate
[2007/06/04 16:51:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2007/03/23 15:59:00 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/11/07 14:25:34 | 000,001,751 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/25 11:25:47 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\SVSetup.Exe
[2006/10/25 11:25:46 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\SVSetup.dll
[2006/10/25 11:25:45 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\SSCoInst.exe
[2006/10/25 11:25:44 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\SSCoInst.dll
[2006/10/25 11:25:31 | 000,020,594 | ---- | C] () -- C:\WINDOWS\System32\Dels3LMK.DLL
[2006/10/12 11:51:49 | 000,006,454 | ---- | C] () -- C:\WINDOWS\solomon.ini
[2006/10/12 11:25:50 | 000,100,352 | ---- | C] () -- C:\WINDOWS\System32\pg32conv.dll
[2006/10/12 11:25:29 | 001,128,448 | ---- | C] () -- C:\WINDOWS\System32\sbl.dll
[2006/10/12 11:25:27 | 000,496,640 | ---- | C] () -- C:\WINDOWS\System32\tls7012d.dll
[2005/05/10 16:41:41 | 000,000,546 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/05/10 16:24:15 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2005/05/10 16:24:09 | 000,099,965 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2005/05/10 16:24:00 | 000,004,147 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2005/05/10 15:43:28 | 000,000,386 | ---- | C] () -- C:\WINDOWS\SMSCFG.ini
[2005/05/10 15:40:10 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\e1000msg.dll
[2005/05/10 15:00:47 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/05/10 14:53:16 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/05/10 10:24:45 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/05/10 10:23:14 | 000,255,064 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/10/08 04:47:08 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2004/09/29 01:46:40 | 000,045,056 | ---- | C] () -- C:\Documents and Settings\theonyxserpent\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/08/04 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,384,976 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\netid.dll
[2004/08/04 08:00:00 | 000,054,184 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 08:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
< End of report >