Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

noob need help on detecting and killing what virus/malware infect me [


  • This topic is locked This topic is locked

#16
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
That was probably an orphan registry entry that was detected

To try and ease the startup try this

Download Startup Control Panel here select the standalone exe version
Instal and you will find a startup icon in the control panel - run this
  • In the HKLM tab, you may disable (be careful --> "disable") all the entries except your security software
  • In the HKCU tab, you may disable all entries.
  • In the StartUp tab, you may disable all entries.
Note : if you notice that some programs no longer run, you can enable them again by running Startup Control Panel, selecting the entry and choosing Run Now.
If you are in doubt with something, don't hesitate to ask :)

Once done let me know what problems remain
  • 0

Advertisements


#17
Tazeris

Tazeris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
okay I will run that program ASAP and if I may ask: that anti malware keep on downloading new patches everyday, is this necessary? also that it blocked all "unrecognized" IP entry :unsure: can I turn off the auto blocking or better not to? :)
  • 0

#18
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
The daily updates are due to the fast changing nature of malware, if the updates are not installed then it could well miss the next bad boy to appear.

the ip entry check is for malformed (i.e. infected) websites taht may download malware or redirect you to a malware site..

Once done could you let me know of the systems behaviour
  • 0

#19
Tazeris

Tazeris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
I downloaded startup control panel and then disabled HKLM tab except security and all in HKCU tab but I can't find nothing at startup tab to disable. :)
After that I dunno what to do since I can't find "run" button or any button to execute anything, except to close the program.

Remaining problems:
- after running for few hours computer still slowing down
- sometimes movie players and music players such as winamp and WMP crashed or freezes, symptom: when double clicking next file on my music folder or dragging to replay or fasten the program it freeze/crash
- the web still slow, recognizable easily when scrolling down or up the page
- flash player still slow (newest update already) especially on the web
- program crash sometimes especially heavy programs like games with high graphics
  • 0

#20
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Methinks we are in the realms of hardware now - how much RAM do you have ?

Download Speedfan (The download link is to the right), and install it. Once it's installed, run the program and post here the information it shows.
The information I want you to post is the stuff that is circled in the example picture I have attached.
To make sure we are getting all the correct information it would help us if you were to attach a screenshot like the one below of your Speedfan results.

To do a screenshot please have click on your Print Screen on your keyboard.
  • It is normally the key above your number pad between the F12 key and the Scroll Lock key
  • Now go to Start and then to All Programs
  • Scroll to Accessories and then click on Paint
  • In the Empty White Area click and hold the CTRL key and then click the V
  • Go to the File option at the top and click on Save as
  • Save as file type JPEG and save it to your Desktop
  • Attach it to your next reply

Posted Image
  • 0

#21
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#22
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi could you update me on the current situation and post a fresh OTL log
  • 0

#23
Tazeris

Tazeris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
hi and thanks a lot for reopening this for me :happy:
I m currently a little exhausted and sick after finishing my work so maybe this will take times to recheck so please don't close this yet..

I already reinstall my windows
currently xp sp 2

I downloaded avg yesterday and avg kill or revive almost all my .exe (it surprised me to see a lot of virus in my computer exe)

currently I have no OTL or other things but I will redownload it soon..
  • 0

#24
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OTL logfile created on: 12/22/2011 9:29:43 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Evan\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.42 Mb Total Physical Memory | 414.87 Mb Available Physical Memory | 40.58% Memory free
2.40 Gb Paging File | 1.96 Gb Available in Paging File | 81.61% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.55 Gb Total Space | 16.82 Gb Free Space | 68.51% Space Free | Partition Type: FAT32
Drive D: | 175.78 Gb Total Space | 16.67 Gb Free Space | 9.48% Space Free | Partition Type: NTFS
Drive E: | 97.74 Gb Total Space | 10.19 Gb Free Space | 10.42% Space Free | Partition Type: NTFS
Drive F: | 97.66 Gb Total Space | 1.07 Gb Free Space | 1.10% Space Free | Partition Type: NTFS
Drive G: | 51.39 Gb Total Space | 3.04 Gb Free Space | 5.91% Space Free | Partition Type: NTFS
Drive H: | 13.55 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: TAZERIS | User Name: Evan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/12/22 21:26:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Evan\Desktop\OTL.exe
PRC - [2011/10/08 11:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/04/21 06:25:38 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/01/13 10:42:06 | 000,232,896 | ---- | M] (Vuze Inc.) -- C:\Program Files\Vuze\Azureus.exe
PRC - [2009/11/09 10:17:50 | 000,180,224 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2009/10/26 15:54:00 | 000,139,264 | ---- | M] () -- C:\Program Files\GamingMouse\mousehid.exe
PRC - [2009/10/26 09:21:58 | 000,114,688 | ---- | M] () -- C:\Program Files\GamingMouse\trayicon.exe
PRC - [2007/04/15 21:22:04 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/08/03 05:12:36 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe


========== Modules (No Company Name) ==========

MOD - [2011/10/08 11:50:00 | 000,355,432 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nview\nvShell.dll
MOD - [2011/04/21 06:25:40 | 001,014,232 | ---- | M] () -- C:\Program Files\Mozilla Firefox\js3250.dll
MOD - [2010/01/13 10:55:14 | 000,072,704 | ---- | M] () -- C:\Program Files\Vuze\aereg.dll
MOD - [2009/10/28 09:28:26 | 000,249,856 | ---- | M] () -- C:\Program Files\GamingMouse\language.dll
MOD - [2009/10/26 15:54:00 | 000,139,264 | ---- | M] () -- C:\Program Files\GamingMouse\mousehid.exe
MOD - [2009/10/26 09:21:58 | 000,114,688 | ---- | M] () -- C:\Program Files\GamingMouse\trayicon.exe
MOD - [2009/08/16 17:06:04 | 000,141,312 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2008/10/05 10:24:02 | 003,695,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2008/07/09 16:05:50 | 000,421,888 | ---- | M] () -- C:\WINDOWS\system32\ac3filter.acm
MOD - [2004/03/31 22:24:52 | 000,081,920 | ---- | M] () -- C:\Program Files\NetLimiter\nl_lsp.dll
MOD - [2004/03/31 03:47:42 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\nl_msgc.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/10/08 11:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)


========== Driver Services (SafeList) ==========

DRV - [2011/12/22 17:08:04 | 000,010,872 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\apf001.sys -- (apf001)
DRV - [2009/11/13 13:56:36 | 000,012,544 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nmgms.sys -- (nmgmsFltr)
DRV - [2009/11/09 10:21:18 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007/04/16 16:46:34 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2006/09/20 15:01:12 | 004,019,072 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2006/07/01 22:39:40 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005/08/18 17:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005/04/06 03:22:30 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/04/06 03:22:28 | 000,033,536 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-21-1214440339-1229272821-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\S-1-5-21-1214440339-1229272821-1801674531-1003\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1214440339-1229272821-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1214440339-1229272821-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.8.1.0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.3: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/22 15:35:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/22 15:35:50 | 000,000,000 | ---D | M]

[2011/12/22 15:56:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Evan\Application Data\Mozilla\Extensions
[2011/12/22 15:56:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Evan\Application Data\Mozilla\Firefox\Profiles\62q4q3gx.default\extensions
[2011/12/22 18:26:42 | 000,000,000 | ---D | M] (Vuze Remote Community Toolbar) -- C:\Documents and Settings\Evan\Application Data\Mozilla\Firefox\Profiles\62q4q3gx.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/12/22 15:35:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2001/08/23 12:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [GamingMouse] C:\Program Files\GamingMouse\mousehid.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe (LockTime)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKU\S-1-5-21-1214440339-1229272821-1801674531-1003..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 File not found
O4 - HKU\S-1-5-18..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 File not found
O4 - HKU\S-1-5-19..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 File not found
O4 - HKU\S-1-5-20..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 File not found
O4 - HKU\S-1-5-21-1214440339-1229272821-1801674531-1004..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 File not found
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1214440339-1229272821-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1214440339-1229272821-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1608999B-6F95-49F3-8F46-6455FEE7C496}: NameServer = 203.130.196.5 222.124.204.34
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D30B1F3-5911-4B3F-9422-21C3E4BB4286}: DhcpNameServer = 192.168.1.1 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/12/22 15:24:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2009/06/01 11:22:38 | 000,000,000 | ---- | M] () - G:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2003/03/19 14:14:58 | 000,040,960 | R--- | M] (Microsoft Corporation) - H:\autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2002/03/26 07:00:12 | 000,000,048 | R--- | M] () - H:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{16edec0a-2ca0-11e1-abd6-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{16edec0a-2ca0-11e1-abd6-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{16edec0a-2ca0-11e1-abd6-806d6172696f}\Shell\AutoRun\command - "" = H:\autorun.exe -- [2003/03/19 14:14:58 | 000,040,960 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/22 21:25:56 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Evan\Desktop\OTL.exe
[2011/12/22 20:52:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang
[2011/12/22 20:52:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Media Player Classic
[2011/12/22 18:27:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2011/12/22 18:26:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Azureus
[2011/12/22 18:26:42 | 000,000,000 | ---D | C] -- C:\Program Files\Vuze
[2011/12/22 18:26:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\i4j_jres
[2011/12/22 18:26:30 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2011/12/22 18:26:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\Vuze_Remote
[2011/12/22 18:26:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\Temp
[2011/12/22 18:26:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\Conduit
[2011/12/22 18:26:28 | 000,000,000 | ---D | C] -- C:\Program Files\Vuze_Remote
[2011/12/22 17:07:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DirectX
[2011/12/22 16:44:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinnerInter
[2011/12/22 16:17:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Macromedia
[2011/12/22 16:17:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Adobe
[2011/12/22 15:56:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\My Documents\Downloads
[2011/12/22 15:56:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\Mozilla
[2011/12/22 15:56:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Mozilla
[2011/12/22 15:51:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2011/12/22 15:51:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Yahoo! Messenger
[2011/12/22 15:50:55 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2011/12/22 15:49:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\yoyo
[2011/12/22 15:49:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Waifu [Don Shigeru]
[2011/12/22 15:49:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Touhou - Koishi-chan no Ecchi na Hon ga Nai nara Watashi ga Kaku Shika Nai Janai!!
[2011/12/22 15:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\PowerISO
[2011/12/22 15:49:27 | 000,000,000 | ---D | C] -- C:\Program Files\PowerISO
[2011/12/22 15:49:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Smile Cat [Riki]
[2011/12/22 15:49:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\ShapeShifter_files
[2011/12/22 15:49:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\NetLimiter
[2011/12/22 15:49:13 | 000,000,000 | ---D | C] -- C:\Program Files\NetLimiter
[2011/12/22 15:49:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\LockTime
[2011/12/22 15:48:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Rapiere [Takaoka Motofumi]
[2011/12/22 15:48:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\mos2_01_2
[2011/12/22 15:48:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Cover depan tugas atma
[2011/12/22 15:48:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\[Crimson Comics] The Tragedy of Nami (English, Color)
[2011/12/22 15:47:12 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek Sound Manager
[2011/12/22 15:47:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Realtek Sound Manager
[2011/12/22 15:47:12 | 000,000,000 | ---D | C] -- C:\Program Files\AvRack
[2011/12/22 15:47:06 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek AC97
[2011/12/22 15:46:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\WinRAR
[2011/12/22 15:46:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Start Menu\Programs\XP Codec Pack 2.5.1
[2011/12/22 15:46:07 | 000,000,000 | ---D | C] -- C:\Program Files\XP Codec Pack
[2011/12/22 15:45:20 | 000,000,000 | -HSD | C] -- C:\Recycled
[2011/12/22 15:35:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/12/22 15:35:48 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011/12/22 15:35:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
[2011/12/22 15:35:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Start Menu\Programs\WinRAR
[2011/12/22 15:35:10 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2011/12/22 15:34:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NVIDIA
[2011/12/22 15:34:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
[2011/12/22 15:33:44 | 000,065,536 | ---- | C] (Khronos Group) -- C:\WINDOWS\System32\OpenCL.dll
[2011/12/22 15:33:25 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2011/12/22 15:33:05 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2011/12/22 15:31:59 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2011/12/22 15:31:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2011/12/22 15:31:49 | 000,000,000 | ---D | C] -- C:\Program Files\GamingMouse
[2011/12/22 15:31:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GamingMouse
[2011/12/22 15:30:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2011/12/22 15:30:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2011/12/22 15:30:39 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2011/12/22 15:30:39 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2011/12/22 15:30:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\InstallShield
[2011/12/22 15:29:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Identities
[2011/12/22 15:29:23 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\My Documents\My Music
[2011/12/22 15:29:23 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2011/12/22 15:29:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\My Documents\My Pictures
[2011/12/22 15:29:17 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\Microsoft
[2011/12/22 15:29:17 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Evan\Application Data\Microsoft
[2011/12/22 15:29:17 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Evan\SendTo
[2011/12/22 15:29:17 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Evan\Recent
[2011/12/22 15:29:17 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Evan\Application Data
[2011/12/22 15:29:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\Start Menu\Programs\Startup
[2011/12/22 15:29:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\Start Menu
[2011/12/22 15:29:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\My Documents
[2011/12/22 15:29:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\Favorites
[2011/12/22 15:29:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\Start Menu\Programs\Accessories
[2011/12/22 15:29:17 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Evan\Cookies
[2011/12/22 15:29:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Evan\Templates
[2011/12/22 15:29:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Evan\PrintHood
[2011/12/22 15:29:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Evan\NetHood
[2011/12/22 15:29:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Evan\Local Settings
[2011/12/22 15:29:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop
[2011/12/22 15:28:49 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2011/12/22 15:28:48 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2011/12/22 15:28:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2011/12/22 15:28:47 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2011/12/22 15:28:47 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2011/12/22 15:28:25 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2011/12/22 15:28:25 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2011/12/22 15:27:02 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2011/12/22 15:27:02 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2011/12/22 15:27:01 | 000,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2011/12/22 15:25:56 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2011/12/22 15:25:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2011/12/22 15:25:04 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2011/12/22 15:25:04 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2011/12/22 15:23:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM
[2011/12/22 15:23:28 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2011/12/22 15:23:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2011/12/22 15:22:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2011/12/22 15:22:37 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2011/12/22 15:22:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2011/12/22 15:22:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2011/12/22 15:22:25 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2011/12/22 15:22:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2011/12/22 15:22:13 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2011/12/22 15:22:10 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2011/12/22 15:22:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2011/12/22 15:21:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2011/12/22 15:21:29 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2011/12/22 15:21:13 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2011/12/22 15:21:08 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2011/12/22 15:21:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2011/12/22 15:21:03 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services
[2011/12/22 15:20:53 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2011/12/22 15:20:52 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2011/12/22 15:20:51 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2011/12/22 15:20:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Offline Web Pages
[2011/12/22 15:20:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\wbem
[2011/12/22 15:20:47 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2011/12/22 15:20:45 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2011/12/22 15:20:42 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2011/12/22 15:20:08 | 000,281,088 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe
[2011/12/22 15:20:08 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2011/12/22 15:20:07 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2011/12/22 15:20:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2011/12/22 15:20:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2011/12/22 15:19:49 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2011/12/22 15:19:30 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[2011/12/22 15:11:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2011/12/22 15:11:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2011/12/22 15:11:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu
[2011/12/22 15:11:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents
[2011/12/22 15:11:48 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates
[2011/12/22 15:11:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2011/12/22 15:11:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop
[2011/12/22 15:09:52 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2011/12/22 15:09:52 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data
[2011/12/22 13:34:46 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2011/12/22 13:34:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2011/12/22 13:34:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2011/12/22 13:34:42 | 000,000,000 | R--D | C] -- C:\Program Files
[2011/12/22 13:34:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2011/12/22 13:34:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2011/12/22 13:33:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2011/12/22 13:33:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2011/12/22 13:33:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings
[2011/12/22 13:28:30 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2011/12/22 13:28:30 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2011/12/22 13:28:30 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web
[2011/12/22 13:28:30 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\pchealth
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Network Diagnostic
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-us
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\ehome
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2004/11/25 02:25:52 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/22 21:26:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Evan\Desktop\OTL.exe
[2011/12/22 20:52:52 | 000,940,794 | ---- | M] () -- C:\WINDOWS\System32\LoopyMusic.wav
[2011/12/22 20:52:52 | 000,146,650 | ---- | M] () -- C:\WINDOWS\System32\BuzzingBee.wav
[2011/12/22 18:26:58 | 000,001,409 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2011/12/22 18:26:58 | 000,001,409 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Vuze.lnk
[2011/12/22 17:08:04 | 000,012,920 | ---- | M] () -- C:\WINDOWS\System32\apl001.sys
[2011/12/22 17:08:04 | 000,010,872 | ---- | M] () -- C:\WINDOWS\System32\apf001.sys
[2011/12/22 16:53:40 | 000,000,484 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\UndividedRO.lnk
[2011/12/22 16:44:38 | 000,000,501 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Kitsune Online.lnk
[2011/12/22 16:04:34 | 000,311,934 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/12/22 16:04:34 | 000,040,196 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/12/22 16:02:58 | 000,000,536 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Speedy.lnk
[2011/12/22 15:56:14 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2011/12/22 15:54:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/12/22 15:51:02 | 000,000,734 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2011/12/22 15:51:02 | 000,000,716 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2011/12/22 15:50:34 | 000,000,242 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\My Documents.lnk
[2011/12/22 15:49:30 | 000,000,586 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2011/12/22 15:49:16 | 000,001,508 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Netlimiter.lnk
[2011/12/22 15:49:16 | 000,001,490 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Netlimiter.lnk
[2011/12/22 15:47:58 | 000,285,176 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/12/22 15:47:58 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/12/22 15:47:14 | 000,001,423 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AvRack.lnk
[2011/12/22 15:46:12 | 000,000,659 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\Media Player Classic.lnk
[2011/12/22 15:45:42 | 000,004,608 | ---- | M] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/22 15:43:14 | 000,285,176 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/12/22 15:35:50 | 000,001,524 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/12/22 15:35:50 | 000,001,506 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/22 15:33:54 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvdrswr.lk
[2011/12/22 15:29:42 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/12/22 15:29:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/12/22 15:28:30 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2011/12/22 15:28:20 | 000,095,864 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/22 15:27:46 | 000,000,261 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/12/22 15:24:48 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/12/22 15:24:48 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2011/12/22 15:24:48 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2011/12/22 15:24:48 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2011/12/22 15:24:48 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2011/12/22 15:24:44 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/12/22 15:24:44 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/12/22 15:24:42 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2011/12/22 15:24:34 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2011/12/22 15:21:26 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/12/22 15:18:28 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011/12/22 13:34:50 | 000,001,362 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/12/21 23:29:14 | 000,018,756 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\Stronghold.3-SKIDROW-[tracker.BTARENA.org].iso.6770623.TPB.torrent
[2011/12/21 01:28:20 | 1297,678,166 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\KitsuneOnlineIN_1005.exe
[2011/11/27 00:30:28 | 000,006,532 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\41575_174225367792_6810_n.jpg
[2011/11/27 00:21:14 | 000,061,330 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\n522132253_2497396_1905.jpg
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/22 22:16:35 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2011/12/22 20:52:50 | 000,940,794 | ---- | C] () -- C:\WINDOWS\System32\LoopyMusic.wav
[2011/12/22 20:52:50 | 000,146,650 | ---- | C] () -- C:\WINDOWS\System32\BuzzingBee.wav
[2011/12/22 20:34:44 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2011/12/22 20:34:44 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2011/12/22 20:34:43 | 000,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2011/12/22 20:34:43 | 000,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2011/12/22 18:26:57 | 000,001,409 | ---- | C] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2011/12/22 18:26:57 | 000,001,409 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Vuze.lnk
[2011/12/22 18:26:57 | 000,001,409 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Vuze.lnk
[2011/12/22 17:08:03 | 000,012,920 | ---- | C] () -- C:\WINDOWS\System32\apl001.sys
[2011/12/22 17:08:03 | 000,010,872 | ---- | C] () -- C:\WINDOWS\System32\apf001.sys
[2011/12/22 16:53:20 | 000,000,484 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\UndividedRO.lnk
[2011/12/22 16:44:36 | 000,000,501 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Kitsune Online.lnk
[2011/12/22 16:02:57 | 000,000,536 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Speedy.lnk
[2011/12/22 15:56:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/12/22 15:51:00 | 000,000,734 | ---- | C] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2011/12/22 15:51:00 | 000,000,716 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2011/12/22 15:50:27 | 000,000,242 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\My Documents.lnk
[2011/12/22 15:49:28 | 000,000,586 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2011/12/22 15:49:15 | 000,001,508 | ---- | C] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Netlimiter.lnk
[2011/12/22 15:49:15 | 000,001,490 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Netlimiter.lnk
[2011/12/22 15:47:33 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2011/12/22 15:47:12 | 000,001,423 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AvRack.lnk
[2011/12/22 15:47:12 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2011/12/22 15:47:06 | 000,141,016 | ---- | C] () -- C:\WINDOWS\System32\alsndmgr.wav
[2011/12/22 15:47:05 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2011/12/22 15:46:11 | 000,421,888 | ---- | C] () -- C:\WINDOWS\System32\ac3filter.acm
[2011/12/22 15:46:11 | 000,000,659 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\Media Player Classic.lnk
[2011/12/22 15:45:40 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/22 15:35:49 | 000,001,524 | ---- | C] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/12/22 15:35:49 | 000,001,506 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/22 15:33:52 | 000,285,176 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/12/22 15:33:52 | 000,285,176 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/12/22 15:33:52 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/12/22 15:33:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvdrswr.lk
[2011/12/22 15:33:43 | 002,130,002 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2011/12/22 15:33:43 | 000,003,250 | ---- | C] () -- C:\WINDOWS\System32\nvinfo.pb
[2011/12/22 15:32:35 | 000,001,537 | ---- | C] () -- C:\WINDOWS\System32\nvide.nvu
[2011/12/22 15:32:23 | 000,003,596 | ---- | C] () -- C:\WINDOWS\System32\nvnrm.nvu
[2011/12/22 15:32:22 | 000,001,348 | R--- | C] () -- C:\WINDOWS\System32\nvsmb.nvu
[2011/12/22 15:31:49 | 000,012,544 | ---- | C] () -- C:\WINDOWS\System32\drivers\nmgms.sys
[2011/12/22 15:29:40 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/12/22 15:29:33 | 000,000,707 | ---- | C] () -- C:\Documents and Settings\Evan\Start Menu\Programs\Internet Explorer.lnk
[2011/12/22 15:29:26 | 000,000,642 | ---- | C] () -- C:\Documents and Settings\Evan\Start Menu\Programs\Outlook Express.lnk
[2011/12/22 15:29:17 | 000,001,503 | ---- | C] () -- C:\Documents and Settings\Evan\Start Menu\Programs\Remote Assistance.lnk
[2011/12/22 15:29:17 | 000,000,692 | ---- | C] () -- C:\Documents and Settings\Evan\Start Menu\Programs\Windows Media Player.lnk
[2011/12/22 15:28:28 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2011/12/22 15:27:44 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/12/22 15:26:09 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2011/12/22 15:24:46 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/12/22 15:24:46 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2011/12/22 15:24:46 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2011/12/22 15:24:46 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2011/12/22 15:24:46 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2011/12/22 15:24:42 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/12/22 15:24:42 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/12/22 15:24:40 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2011/12/22 15:23:27 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2011/12/22 15:23:16 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
[2011/12/22 15:22:48 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2011/12/22 15:22:48 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2011/12/22 15:22:42 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2011/12/22 15:22:30 | 000,004,639 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.exe
[2011/12/22 15:22:19 | 000,376,320 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msinfo.dll
[2011/12/22 15:21:29 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2011/12/22 15:21:25 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/12/22 15:21:03 | 000,001,890 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2011/12/22 15:20:51 | 000,001,988 | ---- | C] () -- C:\WINDOWS\System32\ticrf.rat
[2011/12/22 15:20:48 | 000,074,715 | ---- | C] () -- C:\WINDOWS\System32\IE7Eula.rtf
[2011/12/22 15:20:48 | 000,008,798 | ---- | C] () -- C:\WINDOWS\System32\icrav03.rat
[2011/12/22 15:20:29 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
[2011/12/22 15:20:29 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
[2011/12/22 15:20:29 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2011/12/22 15:20:28 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
[2011/12/22 15:20:28 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
[2011/12/22 15:20:28 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
[2011/12/22 15:20:28 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
[2011/12/22 15:20:28 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
[2011/12/22 15:20:28 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
[2011/12/22 15:20:28 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
[2011/12/22 15:20:28 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
[2011/12/22 15:20:25 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2011/12/22 15:20:25 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2011/12/22 15:20:24 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2011/12/22 15:20:18 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2011/12/22 15:16:34 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2011/12/22 15:16:30 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2011/12/22 15:16:28 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2011/12/22 15:16:27 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\korwbrkr.lex
[2011/12/22 15:16:27 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2011/12/22 15:16:27 | 000,002,060 | ---- | C] () -- C:\WINDOWS\System32\noise.jpn
[2011/12/22 15:16:27 | 000,001,486 | ---- | C] () -- C:\WINDOWS\System32\noise.kor
[2011/12/22 15:16:19 | 000,211,938 | ---- | C] () -- C:\WINDOWS\System32\lcphrase.tbl
[2011/12/22 15:16:19 | 000,146,126 | ---- | C] () -- C:\WINDOWS\System32\array30.tab
[2011/12/22 15:16:19 | 000,116,285 | ---- | C] () -- C:\WINDOWS\System32\msdayi.tbl
[2011/12/22 15:16:19 | 000,110,566 | ---- | C] () -- C:\WINDOWS\System32\arphr.tbl
[2011/12/22 15:16:19 | 000,044,370 | ---- | C] () -- C:\WINDOWS\System32\acode.tbl
[2011/12/22 15:16:19 | 000,044,370 | ---- | C] () -- C:\WINDOWS\System32\a234.tbl
[2011/12/22 15:16:19 | 000,043,242 | ---- | C] () -- C:\WINDOWS\System32\phoncode.tbl
[2011/12/22 15:16:19 | 000,024,114 | ---- | C] () -- C:\WINDOWS\System32\lcptr.tbl
[2011/12/22 15:16:19 | 000,018,600 | ---- | C] () -- C:\WINDOWS\System32\arrayhw.tab
[2011/12/22 15:16:19 | 000,016,312 | ---- | C] () -- C:\WINDOWS\System32\arptr.tbl
[2011/12/22 15:16:19 | 000,004,071 | ---- | C] () -- C:\WINDOWS\System32\phon.tbl
[2011/12/22 15:16:19 | 000,002,714 | ---- | C] () -- C:\WINDOWS\System32\phonptr.tbl
[2011/12/22 15:16:19 | 000,001,460 | ---- | C] () -- C:\WINDOWS\System32\a15.tbl
[2011/12/22 15:16:19 | 000,000,700 | ---- | C] () -- C:\WINDOWS\System32\dayiptr.tbl
[2011/12/22 15:16:19 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\dayiphr.tbl
[2011/12/22 15:16:14 | 001,223,500 | ---- | C] () -- C:\WINDOWS\System32\WINZM.MB
[2011/12/22 15:16:13 | 001,783,864 | ---- | C] () -- C:\WINDOWS\System32\WINPY.MB
[2011/12/22 15:16:13 | 001,564,868 | ---- | C] () -- C:\WINDOWS\System32\WINSP.MB
[2011/12/22 15:16:10 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2011/12/22 15:16:10 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2011/12/22 15:16:00 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2011/12/22 13:34:49 | 000,001,362 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/12/22 13:34:46 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/12/22 13:34:28 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2011/12/22 13:34:05 | 000,141,702 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2011/12/22 13:34:05 | 000,110,116 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2011/12/22 13:34:05 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2011/12/22 13:34:05 | 000,031,965 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2011/12/22 13:34:05 | 000,031,281 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2011/12/22 13:34:05 | 000,024,209 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat
[2011/12/22 13:34:05 | 000,013,753 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2011/12/22 13:34:05 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2011/12/22 13:34:05 | 000,011,651 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat
[2011/12/22 13:34:05 | 000,009,581 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2011/12/22 13:34:05 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2011/12/22 13:34:05 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2011/12/22 13:34:05 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2011/12/22 13:34:05 | 000,007,245 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2011/12/22 13:34:04 | 002,012,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2011/12/22 13:34:04 | 001,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT
[2011/12/22 13:34:04 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2011/12/22 13:34:04 | 000,502,724 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2011/12/22 13:34:04 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2011/12/22 13:33:28 | 000,095,864 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/22 13:32:43 | 000,000,211 | -HS- | C] () -- C:\boot.ini
[2011/12/22 13:32:40 | 000,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/12/21 23:29:44 | 000,018,756 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\Stronghold.3-SKIDROW-[tracker.BTARENA.org].iso.6770623.TPB.torrent
[2011/12/20 21:09:34 | 1297,678,166 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\KitsuneOnlineIN_1005.exe
[2011/12/18 12:32:30 | 1140,688,280 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\tokyoloadjav.SHKD357.avi
[2011/11/27 00:30:26 | 000,006,532 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\41575_174225367792_6810_n.jpg
[2011/11/27 00:21:12 | 000,061,330 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\n522132253_2497396_1905.jpg
[2008/12/19 22:15:58 | 004,338,246 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/12/18 00:41:18 | 000,884,237 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2008/12/18 00:22:58 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2008/12/18 00:22:48 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/12/18 00:17:34 | 000,239,247 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2008/12/17 23:59:54 | 000,560,802 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2006/11/02 23:10:16 | 000,080,912 | ---- | C] () -- C:\WINDOWS\System32\sherlock2.exe
[2004/10/04 00:50:54 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/08/04 00:07:22 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/02 13:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/03/31 03:47:44 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\nl_msgs.dll
[2004/03/31 03:47:41 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\nl_msgc.dll
[2001/08/23 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 12:00:00 | 000,311,934 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 12:00:00 | 000,040,196 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 12:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011/12/22 18:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2011/12/22 15:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Evan\Application Data\LockTime
[2011/12/22 18:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Evan\Application Data\Azureus

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %USERPROFILE%\..|smtmp;true;true;true /FP >


< MD5 for: EXPLORER.EXE >
[2007/04/15 21:22:04 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=42D32722B805D7DF42D30487A0BCBD78 -- C:\WINDOWS\explorer.exe
[2007/04/15 21:22:04 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=42D32722B805D7DF42D30487A0BCBD78 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: SVCHOST.EXE >
[2004/08/04 06:56:58 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2004/08/03 23:56:58 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/03 23:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\dllcache\userinit.exe
[2004/08/03 23:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 06:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2004/08/03 23:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /mp /s >

< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/04/21 06:25:34 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/04/21 06:25:34 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/04/21 06:25:34 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/04/21 06:25:38 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/04/21 06:25:38 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/04/21 06:25:38 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2007/04/15 21:24:28 | 000,056,832 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2007/04/15 21:24:28 | 000,056,832 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2007/04/15 21:24:28 | 000,056,832 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2007/04/16 04:24:38 | 000,623,616 | ---- | M] (Microsoft Corporation)

< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/04/21 06:25:34 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/04/21 06:25:34 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/04/21 06:25:34 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/04/21 06:25:38 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/04/21 06:25:38 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/04/21 06:25:38 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2007/04/15 21:24:28 | 000,056,832 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2007/04/15 21:24:28 | 000,056,832 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2007/04/15 21:24:28 | 000,056,832 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2007/04/16 04:24:38 | 000,623,616 | ---- | M] (Microsoft Corporation)

========== Files - Unicode (All) ==========
[2011/12/22 15:49:12 | 000,000,000 | ---D | M](C:\Documents and Settings\Evan\Desktop\sewen.org-?????????????691P) -- C:\Documents and Settings\Evan\Desktop\sewen.org-台湾童颜巨乳美女徐湘婷最全691P
[2011/12/22 15:49:11 | 000,000,000 | ---D | C](C:\Documents and Settings\Evan\Desktop\sewen.org-?????????????691P) -- C:\Documents and Settings\Evan\Desktop\sewen.org-台湾童颜巨乳美女徐湘婷最全691P

< End of report >
  • 0

#25
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
I would recommend that you now update to service pack 3

What are the current problems ?

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O4 - HKU\.DEFAULT..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 File not found
    O4 - HKU\S-1-5-18..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 File not found
    O4 - HKU\S-1-5-19..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 File not found
    O4 - HKU\S-1-5-20..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 File not found
    O4 - HKU\S-1-5-21-1214440339-1229272821-1801674531-1004..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 File not found

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

Advertisements


#26
Tazeris

Tazeris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
2 weeks ago I decide to reinstall my windows since I have time
but 4 days ago I have to reinstall again since something wrong happen with my computer,
I can't connect to the internet PROPERLY, I mean when I restart my computer I can connect to the internet, but only for 5-15 minutes
than the system showing win32 error and unable to connect to the modem
(my friend said it is maybe because the antivirus accidentally detected a part of my system infected or see it as virus and then move it to the V-Vault)

anyway..
I reinstalled and then now I m more worried if my computer have a bad sector since I rarely doing maintenance for like ages (since I m busy).
  • 0

#27
Tazeris

Tazeris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
OTL logfile created on: 12/25/2011 12:22:20 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Evan\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.42 Mb Total Physical Memory | 646.86 Mb Available Physical Memory | 63.27% Memory free
2.40 Gb Paging File | 2.13 Gb Available in Paging File | 88.87% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.55 Gb Total Space | 11.01 Gb Free Space | 44.84% Space Free | Partition Type: FAT32
Drive D: | 175.78 Gb Total Space | 23.68 Gb Free Space | 13.47% Space Free | Partition Type: NTFS
Drive E: | 97.74 Gb Total Space | 10.19 Gb Free Space | 10.42% Space Free | Partition Type: NTFS
Drive F: | 97.66 Gb Total Space | 1.07 Gb Free Space | 1.10% Space Free | Partition Type: NTFS
Drive G: | 51.39 Gb Total Space | 3.04 Gb Free Space | 5.91% Space Free | Partition Type: NTFS
Drive H: | 13.55 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: TAZERIS | User Name: Evan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/12/25 12:16:34 | 000,912,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/12/22 21:26:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Evan\Desktop\OTL.exe
PRC - [2011/10/08 11:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2009/11/09 10:17:50 | 000,180,224 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2009/10/26 15:54:00 | 000,139,264 | ---- | M] () -- C:\Program Files\GamingMouse\mousehid.exe
PRC - [2009/10/26 09:21:58 | 000,114,688 | ---- | M] () -- C:\Program Files\GamingMouse\trayicon.exe
PRC - [2007/04/15 21:22:04 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/08/03 05:12:36 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe


========== Modules (No Company Name) ==========

MOD - [2011/12/25 12:16:34 | 000,849,368 | ---- | M] () -- C:\Program Files\Mozilla Firefox\js3250.dll
MOD - [2011/12/22 18:26:42 | 000,101,376 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Mozilla\Firefox\Profiles\62q4q3gx.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCoreGecko19.dll
MOD - [2011/12/22 18:26:42 | 000,077,312 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Mozilla\Firefox\Profiles\62q4q3gx.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCoreGecko6.dll
MOD - [2011/12/22 18:26:42 | 000,076,800 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Mozilla\Firefox\Profiles\62q4q3gx.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCoreGecko9.dll
MOD - [2011/12/22 18:26:42 | 000,076,800 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Mozilla\Firefox\Profiles\62q4q3gx.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCoreGecko8.dll
MOD - [2011/12/22 18:26:42 | 000,076,800 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Mozilla\Firefox\Profiles\62q4q3gx.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCoreGecko7.dll
MOD - [2011/12/22 18:26:42 | 000,076,288 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Mozilla\Firefox\Profiles\62q4q3gx.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCoreGecko5.dll
MOD - [2011/10/08 11:50:00 | 000,355,432 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nview\nvShell.dll
MOD - [2009/10/28 09:28:26 | 000,249,856 | ---- | M] () -- C:\Program Files\GamingMouse\language.dll
MOD - [2009/10/26 15:54:00 | 000,139,264 | ---- | M] () -- C:\Program Files\GamingMouse\mousehid.exe
MOD - [2009/10/26 09:21:58 | 000,114,688 | ---- | M] () -- C:\Program Files\GamingMouse\trayicon.exe
MOD - [2008/10/05 10:24:02 | 003,695,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2004/03/31 22:24:52 | 000,081,920 | ---- | M] () -- C:\Program Files\NetLimiter\nl_lsp.dll
MOD - [2004/03/31 03:47:42 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\nl_msgc.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/10/08 11:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)


========== Driver Services (SafeList) ==========

DRV - [2011/12/22 17:08:04 | 000,010,872 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\apf001.sys -- (apf001)
DRV - [2009/11/13 13:56:36 | 000,012,544 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nmgms.sys -- (nmgmsFltr)
DRV - [2009/11/09 10:21:18 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007/04/16 16:46:34 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2006/09/20 15:01:12 | 004,019,072 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2006/07/01 22:39:40 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005/08/18 17:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005/04/06 03:22:30 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/04/06 03:22:28 | 000,033,536 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.8.1.0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.3: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/22 15:35:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/22 15:35:50 | 000,000,000 | ---D | M]

[2011/12/22 15:56:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Evan\Application Data\Mozilla\Extensions
[2011/12/22 15:56:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Evan\Application Data\Mozilla\Firefox\Profiles\62q4q3gx.default\extensions
[2011/12/22 18:26:42 | 000,000,000 | ---D | M] (Vuze Remote Community Toolbar) -- C:\Documents and Settings\Evan\Application Data\Mozilla\Firefox\Profiles\62q4q3gx.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/12/22 15:35:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2011/12/25 12:12:50 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [GamingMouse] C:\Program Files\GamingMouse\mousehid.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe (LockTime)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\NetLimiter\nl_lsp.dll ()
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D30B1F3-5911-4B3F-9422-21C3E4BB4286}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EDF4804B-B37A-42C0-9887-5B30F6834BCB}: NameServer = 203.130.196.5 222.124.204.34
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/12/22 15:24:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2009/06/01 11:22:38 | 000,000,000 | ---- | M] () - G:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2003/03/19 14:14:58 | 000,040,960 | R--- | M] (Microsoft Corporation) - H:\autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2002/03/26 07:00:12 | 000,000,048 | R--- | M] () - H:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/25 12:12:47 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/12/25 11:22:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\My Documents\My Spore Creations
[2011/12/25 11:22:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\My Documents\My Games
[2011/12/25 11:22:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\My Documents\democracy2
[2011/12/25 11:21:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\My Documents\BioWare
[2011/12/25 11:16:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\My Documents\Azureus Downloads
[2011/12/23 20:44:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\SKIDROW
[2011/12/23 20:44:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\My Documents\Stronghold 3
[2011/12/23 20:41:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2011/12/22 21:25:56 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Evan\Desktop\OTL.exe
[2011/12/22 20:52:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang
[2011/12/22 20:52:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Media Player Classic
[2011/12/22 18:27:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2011/12/22 18:26:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Azureus
[2011/12/22 18:26:42 | 000,000,000 | ---D | C] -- C:\Program Files\Vuze
[2011/12/22 18:26:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\i4j_jres
[2011/12/22 18:26:30 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2011/12/22 18:26:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\Vuze_Remote
[2011/12/22 18:26:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\Temp
[2011/12/22 18:26:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\Conduit
[2011/12/22 18:26:28 | 000,000,000 | ---D | C] -- C:\Program Files\Vuze_Remote
[2011/12/22 17:07:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DirectX
[2011/12/22 16:44:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinnerInter
[2011/12/22 16:17:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Macromedia
[2011/12/22 16:17:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Adobe
[2011/12/22 15:56:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\My Documents\Downloads
[2011/12/22 15:56:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\Mozilla
[2011/12/22 15:56:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Mozilla
[2011/12/22 15:51:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2011/12/22 15:51:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Yahoo! Messenger
[2011/12/22 15:50:55 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2011/12/22 15:49:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\yoyo
[2011/12/22 15:49:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Waifu [Don Shigeru]
[2011/12/22 15:49:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Touhou - Koishi-chan no Ecchi na Hon ga Nai nara Watashi ga Kaku Shika Nai Janai!!
[2011/12/22 15:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\PowerISO
[2011/12/22 15:49:27 | 000,000,000 | ---D | C] -- C:\Program Files\PowerISO
[2011/12/22 15:49:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Smile Cat [Riki]
[2011/12/22 15:49:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\ShapeShifter_files
[2011/12/22 15:49:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\NetLimiter
[2011/12/22 15:49:13 | 000,000,000 | ---D | C] -- C:\Program Files\NetLimiter
[2011/12/22 15:49:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\LockTime
[2011/12/22 15:48:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Rapiere [Takaoka Motofumi]
[2011/12/22 15:48:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\mos2_01_2
[2011/12/22 15:48:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Cover depan tugas atma
[2011/12/22 15:48:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\[Crimson Comics] The Tragedy of Nami (English, Color)
[2011/12/22 15:47:12 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek Sound Manager
[2011/12/22 15:47:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Realtek Sound Manager
[2011/12/22 15:47:12 | 000,000,000 | ---D | C] -- C:\Program Files\AvRack
[2011/12/22 15:47:06 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek AC97
[2011/12/22 15:46:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\WinRAR
[2011/12/22 15:46:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Start Menu\Programs\XP Codec Pack 2.5.1
[2011/12/22 15:46:07 | 000,000,000 | ---D | C] -- C:\Program Files\XP Codec Pack
[2011/12/22 15:45:20 | 000,000,000 | -HSD | C] -- C:\Recycled
[2011/12/22 15:35:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/12/22 15:35:48 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011/12/22 15:35:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
[2011/12/22 15:35:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Start Menu\Programs\WinRAR
[2011/12/22 15:35:10 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2011/12/22 15:34:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NVIDIA
[2011/12/22 15:34:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
[2011/12/22 15:33:44 | 000,065,536 | ---- | C] (Khronos Group) -- C:\WINDOWS\System32\OpenCL.dll
[2011/12/22 15:33:25 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2011/12/22 15:33:05 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2011/12/22 15:31:59 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2011/12/22 15:31:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2011/12/22 15:31:49 | 000,000,000 | ---D | C] -- C:\Program Files\GamingMouse
[2011/12/22 15:31:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GamingMouse
[2011/12/22 15:30:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2011/12/22 15:30:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2011/12/22 15:30:39 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2011/12/22 15:30:39 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2011/12/22 15:30:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\InstallShield
[2011/12/22 15:29:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Identities
[2011/12/22 15:29:23 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\My Documents\My Music
[2011/12/22 15:29:23 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2011/12/22 15:29:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\My Documents\My Pictures
[2011/12/22 15:29:17 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Evan\Local Settings\Application Data\Microsoft
[2011/12/22 15:29:17 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Evan\Application Data\Microsoft
[2011/12/22 15:29:17 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Evan\SendTo
[2011/12/22 15:29:17 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Evan\Recent
[2011/12/22 15:29:17 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Evan\Application Data
[2011/12/22 15:29:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\Start Menu\Programs\Startup
[2011/12/22 15:29:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\Start Menu
[2011/12/22 15:29:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\My Documents
[2011/12/22 15:29:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\Favorites
[2011/12/22 15:29:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Evan\Start Menu\Programs\Accessories
[2011/12/22 15:29:17 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Evan\Cookies
[2011/12/22 15:29:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Evan\Templates
[2011/12/22 15:29:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Evan\PrintHood
[2011/12/22 15:29:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Evan\NetHood
[2011/12/22 15:29:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Evan\Local Settings
[2011/12/22 15:29:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop
[2011/12/22 15:28:49 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2011/12/22 15:28:48 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2011/12/22 15:28:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2011/12/22 15:28:47 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2011/12/22 15:28:47 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2011/12/22 15:28:25 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2011/12/22 15:28:25 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2011/12/22 15:27:02 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2011/12/22 15:27:02 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2011/12/22 15:27:01 | 000,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2011/12/22 15:25:56 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2011/12/22 15:25:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2011/12/22 15:25:04 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2011/12/22 15:25:04 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2011/12/22 15:23:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM
[2011/12/22 15:23:28 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2011/12/22 15:23:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2011/12/22 15:22:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2011/12/22 15:22:37 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2011/12/22 15:22:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2011/12/22 15:22:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2011/12/22 15:22:25 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2011/12/22 15:22:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2011/12/22 15:22:13 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2011/12/22 15:22:10 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2011/12/22 15:22:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2011/12/22 15:21:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2011/12/22 15:21:29 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2011/12/22 15:21:13 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2011/12/22 15:21:08 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2011/12/22 15:21:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2011/12/22 15:21:03 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services
[2011/12/22 15:20:53 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2011/12/22 15:20:52 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2011/12/22 15:20:51 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2011/12/22 15:20:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Offline Web Pages
[2011/12/22 15:20:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\wbem
[2011/12/22 15:20:47 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2011/12/22 15:20:45 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2011/12/22 15:20:42 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2011/12/22 15:20:08 | 000,281,088 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe
[2011/12/22 15:20:08 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2011/12/22 15:20:07 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2011/12/22 15:20:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2011/12/22 15:20:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2011/12/22 15:19:49 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2011/12/22 15:19:30 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[2011/12/22 15:11:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2011/12/22 15:11:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2011/12/22 15:11:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu
[2011/12/22 15:11:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents
[2011/12/22 15:11:48 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates
[2011/12/22 15:11:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2011/12/22 15:11:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop
[2011/12/22 15:09:52 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2011/12/22 15:09:52 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data
[2011/12/22 13:34:46 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2011/12/22 13:34:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2011/12/22 13:34:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2011/12/22 13:34:42 | 000,000,000 | R--D | C] -- C:\Program Files
[2011/12/22 13:34:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2011/12/22 13:34:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2011/12/22 13:33:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2011/12/22 13:33:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2011/12/22 13:33:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings
[2011/12/22 13:28:30 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2011/12/22 13:28:30 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2011/12/22 13:28:30 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web
[2011/12/22 13:28:30 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\pchealth
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Network Diagnostic
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-us
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\ehome
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2011/12/22 13:28:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2004/11/25 02:25:52 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll

========== Files - Modified Within 30 Days ==========

[2011/12/25 12:15:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/12/25 12:15:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/12/25 12:12:50 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/12/23 15:58:14 | 000,097,456 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/23 13:28:34 | 000,003,584 | ---- | M] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/22 21:26:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Evan\Desktop\OTL.exe
[2011/12/22 20:52:52 | 000,940,794 | ---- | M] () -- C:\WINDOWS\System32\LoopyMusic.wav
[2011/12/22 20:52:52 | 000,146,650 | ---- | M] () -- C:\WINDOWS\System32\BuzzingBee.wav
[2011/12/22 18:26:58 | 000,001,409 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2011/12/22 18:26:58 | 000,001,409 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Vuze.lnk
[2011/12/22 17:08:04 | 000,012,920 | ---- | M] () -- C:\WINDOWS\System32\apl001.sys
[2011/12/22 17:08:04 | 000,010,872 | ---- | M] () -- C:\WINDOWS\System32\apf001.sys
[2011/12/22 16:53:40 | 000,000,484 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\UndividedRO.lnk
[2011/12/22 16:44:38 | 000,000,501 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Kitsune Online.lnk
[2011/12/22 16:04:34 | 000,311,934 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/12/22 16:04:34 | 000,040,196 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/12/22 16:02:58 | 000,000,536 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Speedy.lnk
[2011/12/22 15:56:14 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2011/12/22 15:51:02 | 000,000,734 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2011/12/22 15:51:02 | 000,000,716 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2011/12/22 15:50:34 | 000,000,242 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\My Documents.lnk
[2011/12/22 15:49:30 | 000,000,586 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2011/12/22 15:49:16 | 000,001,508 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Netlimiter.lnk
[2011/12/22 15:49:16 | 000,001,490 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Netlimiter.lnk
[2011/12/22 15:47:58 | 000,285,176 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/12/22 15:47:58 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/12/22 15:47:14 | 000,001,423 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AvRack.lnk
[2011/12/22 15:46:12 | 000,000,659 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\Media Player Classic.lnk
[2011/12/22 15:43:14 | 000,285,176 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/12/22 15:35:50 | 000,001,524 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/12/22 15:35:50 | 000,001,506 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/22 15:33:54 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvdrswr.lk
[2011/12/22 15:29:42 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/12/22 15:28:30 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2011/12/22 15:27:46 | 000,000,261 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/12/22 15:24:48 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/12/22 15:24:48 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2011/12/22 15:24:48 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2011/12/22 15:24:48 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2011/12/22 15:24:48 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2011/12/22 15:24:44 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/12/22 15:24:44 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/12/22 15:24:42 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2011/12/22 15:24:34 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2011/12/22 15:21:26 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/12/22 15:18:28 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011/12/22 13:34:50 | 000,001,362 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/11/27 00:30:28 | 000,006,532 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\41575_174225367792_6810_n.jpg
[2011/11/27 00:21:14 | 000,061,330 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\n522132253_2497396_1905.jpg

========== Files Created - No Company Name ==========

[2011/12/22 22:16:35 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2011/12/22 20:52:50 | 000,940,794 | ---- | C] () -- C:\WINDOWS\System32\LoopyMusic.wav
[2011/12/22 20:52:50 | 000,146,650 | ---- | C] () -- C:\WINDOWS\System32\BuzzingBee.wav
[2011/12/22 20:34:44 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2011/12/22 20:34:44 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2011/12/22 20:34:43 | 000,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2011/12/22 20:34:43 | 000,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2011/12/22 18:26:57 | 000,001,409 | ---- | C] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2011/12/22 18:26:57 | 000,001,409 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Vuze.lnk
[2011/12/22 18:26:57 | 000,001,409 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Vuze.lnk
[2011/12/22 17:08:03 | 000,012,920 | ---- | C] () -- C:\WINDOWS\System32\apl001.sys
[2011/12/22 17:08:03 | 000,010,872 | ---- | C] () -- C:\WINDOWS\System32\apf001.sys
[2011/12/22 16:53:20 | 000,000,484 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\UndividedRO.lnk
[2011/12/22 16:44:36 | 000,000,501 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Kitsune Online.lnk
[2011/12/22 16:02:57 | 000,000,536 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Speedy.lnk
[2011/12/22 15:56:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/12/22 15:51:00 | 000,000,734 | ---- | C] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2011/12/22 15:51:00 | 000,000,716 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2011/12/22 15:50:27 | 000,000,242 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\My Documents.lnk
[2011/12/22 15:49:28 | 000,000,586 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2011/12/22 15:49:15 | 000,001,508 | ---- | C] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Netlimiter.lnk
[2011/12/22 15:49:15 | 000,001,490 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Netlimiter.lnk
[2011/12/22 15:47:33 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2011/12/22 15:47:12 | 000,001,423 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AvRack.lnk
[2011/12/22 15:47:12 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2011/12/22 15:47:06 | 000,141,016 | ---- | C] () -- C:\WINDOWS\System32\alsndmgr.wav
[2011/12/22 15:47:05 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2011/12/22 15:46:11 | 000,421,888 | ---- | C] () -- C:\WINDOWS\System32\ac3filter.acm
[2011/12/22 15:46:11 | 000,000,659 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\Media Player Classic.lnk
[2011/12/22 15:45:40 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/22 15:35:49 | 000,001,524 | ---- | C] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/12/22 15:35:49 | 000,001,506 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/22 15:33:52 | 000,285,176 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/12/22 15:33:52 | 000,285,176 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/12/22 15:33:52 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/12/22 15:33:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvdrswr.lk
[2011/12/22 15:33:43 | 002,130,002 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2011/12/22 15:33:43 | 000,003,250 | ---- | C] () -- C:\WINDOWS\System32\nvinfo.pb
[2011/12/22 15:32:35 | 000,001,537 | ---- | C] () -- C:\WINDOWS\System32\nvide.nvu
[2011/12/22 15:32:23 | 000,003,596 | ---- | C] () -- C:\WINDOWS\System32\nvnrm.nvu
[2011/12/22 15:32:22 | 000,001,348 | R--- | C] () -- C:\WINDOWS\System32\nvsmb.nvu
[2011/12/22 15:31:49 | 000,012,544 | ---- | C] () -- C:\WINDOWS\System32\drivers\nmgms.sys
[2011/12/22 15:29:40 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Evan\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/12/22 15:29:33 | 000,000,707 | ---- | C] () -- C:\Documents and Settings\Evan\Start Menu\Programs\Internet Explorer.lnk
[2011/12/22 15:29:26 | 000,000,642 | ---- | C] () -- C:\Documents and Settings\Evan\Start Menu\Programs\Outlook Express.lnk
[2011/12/22 15:29:17 | 000,001,503 | ---- | C] () -- C:\Documents and Settings\Evan\Start Menu\Programs\Remote Assistance.lnk
[2011/12/22 15:29:17 | 000,000,692 | ---- | C] () -- C:\Documents and Settings\Evan\Start Menu\Programs\Windows Media Player.lnk
[2011/12/22 15:28:28 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2011/12/22 15:27:44 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/12/22 15:26:09 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2011/12/22 15:24:46 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/12/22 15:24:46 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2011/12/22 15:24:46 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2011/12/22 15:24:46 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2011/12/22 15:24:46 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2011/12/22 15:24:42 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/12/22 15:24:42 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/12/22 15:24:40 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2011/12/22 15:23:27 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2011/12/22 15:23:16 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
[2011/12/22 15:22:48 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2011/12/22 15:22:48 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2011/12/22 15:22:42 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2011/12/22 15:22:30 | 000,004,639 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.exe
[2011/12/22 15:22:19 | 000,376,320 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msinfo.dll
[2011/12/22 15:21:29 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2011/12/22 15:21:25 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/12/22 15:21:03 | 000,001,890 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2011/12/22 15:20:51 | 000,001,988 | ---- | C] () -- C:\WINDOWS\System32\ticrf.rat
[2011/12/22 15:20:48 | 000,074,715 | ---- | C] () -- C:\WINDOWS\System32\IE7Eula.rtf
[2011/12/22 15:20:48 | 000,008,798 | ---- | C] () -- C:\WINDOWS\System32\icrav03.rat
[2011/12/22 15:20:29 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
[2011/12/22 15:20:29 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
[2011/12/22 15:20:29 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2011/12/22 15:20:28 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
[2011/12/22 15:20:28 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
[2011/12/22 15:20:28 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
[2011/12/22 15:20:28 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
[2011/12/22 15:20:28 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
[2011/12/22 15:20:28 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
[2011/12/22 15:20:28 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
[2011/12/22 15:20:28 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
[2011/12/22 15:20:25 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2011/12/22 15:20:25 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2011/12/22 15:20:24 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2011/12/22 15:20:18 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2011/12/22 15:16:34 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2011/12/22 15:16:30 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2011/12/22 15:16:28 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2011/12/22 15:16:27 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\korwbrkr.lex
[2011/12/22 15:16:27 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2011/12/22 15:16:27 | 000,002,060 | ---- | C] () -- C:\WINDOWS\System32\noise.jpn
[2011/12/22 15:16:27 | 000,001,486 | ---- | C] () -- C:\WINDOWS\System32\noise.kor
[2011/12/22 15:16:19 | 000,211,938 | ---- | C] () -- C:\WINDOWS\System32\lcphrase.tbl
[2011/12/22 15:16:19 | 000,146,126 | ---- | C] () -- C:\WINDOWS\System32\array30.tab
[2011/12/22 15:16:19 | 000,116,285 | ---- | C] () -- C:\WINDOWS\System32\msdayi.tbl
[2011/12/22 15:16:19 | 000,110,566 | ---- | C] () -- C:\WINDOWS\System32\arphr.tbl
[2011/12/22 15:16:19 | 000,044,370 | ---- | C] () -- C:\WINDOWS\System32\acode.tbl
[2011/12/22 15:16:19 | 000,044,370 | ---- | C] () -- C:\WINDOWS\System32\a234.tbl
[2011/12/22 15:16:19 | 000,043,242 | ---- | C] () -- C:\WINDOWS\System32\phoncode.tbl
[2011/12/22 15:16:19 | 000,024,114 | ---- | C] () -- C:\WINDOWS\System32\lcptr.tbl
[2011/12/22 15:16:19 | 000,018,600 | ---- | C] () -- C:\WINDOWS\System32\arrayhw.tab
[2011/12/22 15:16:19 | 000,016,312 | ---- | C] () -- C:\WINDOWS\System32\arptr.tbl
[2011/12/22 15:16:19 | 000,004,071 | ---- | C] () -- C:\WINDOWS\System32\phon.tbl
[2011/12/22 15:16:19 | 000,002,714 | ---- | C] () -- C:\WINDOWS\System32\phonptr.tbl
[2011/12/22 15:16:19 | 000,001,460 | ---- | C] () -- C:\WINDOWS\System32\a15.tbl
[2011/12/22 15:16:19 | 000,000,700 | ---- | C] () -- C:\WINDOWS\System32\dayiptr.tbl
[2011/12/22 15:16:19 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\dayiphr.tbl
[2011/12/22 15:16:14 | 001,223,500 | ---- | C] () -- C:\WINDOWS\System32\WINZM.MB
[2011/12/22 15:16:13 | 001,783,864 | ---- | C] () -- C:\WINDOWS\System32\WINPY.MB
[2011/12/22 15:16:13 | 001,564,868 | ---- | C] () -- C:\WINDOWS\System32\WINSP.MB
[2011/12/22 15:16:10 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2011/12/22 15:16:10 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2011/12/22 15:16:00 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2011/12/22 13:34:49 | 000,001,362 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/12/22 13:34:46 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/12/22 13:34:28 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2011/12/22 13:34:05 | 000,141,702 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2011/12/22 13:34:05 | 000,110,116 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2011/12/22 13:34:05 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2011/12/22 13:34:05 | 000,031,965 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2011/12/22 13:34:05 | 000,031,281 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2011/12/22 13:34:05 | 000,024,209 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat
[2011/12/22 13:34:05 | 000,013,753 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2011/12/22 13:34:05 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2011/12/22 13:34:05 | 000,011,651 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat
[2011/12/22 13:34:05 | 000,009,581 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2011/12/22 13:34:05 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2011/12/22 13:34:05 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2011/12/22 13:34:05 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2011/12/22 13:34:05 | 000,007,245 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2011/12/22 13:34:04 | 002,012,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2011/12/22 13:34:04 | 001,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT
[2011/12/22 13:34:04 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2011/12/22 13:34:04 | 000,502,724 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2011/12/22 13:34:04 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2011/12/22 13:33:28 | 000,097,456 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/22 13:32:43 | 000,000,211 | -HS- | C] () -- C:\boot.ini
[2011/12/22 13:32:40 | 000,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/12/18 12:32:30 | 1140,688,280 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\tokyoloadjav.SHKD357.avi
[2011/11/27 00:30:26 | 000,006,532 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\41575_174225367792_6810_n.jpg
[2011/11/27 00:21:12 | 000,061,330 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\n522132253_2497396_1905.jpg
[2008/12/19 22:15:58 | 004,338,246 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/12/18 00:41:18 | 000,884,237 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2008/12/18 00:22:58 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2008/12/18 00:22:48 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/12/18 00:17:34 | 000,239,247 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2008/12/17 23:59:54 | 000,560,802 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2007/04/15 21:22:16 | 000,162,155 | RHS- | C] () -- C:\WINDOWS\System32\ddtbkk.dll
[2006/11/02 23:10:16 | 000,080,912 | ---- | C] () -- C:\WINDOWS\System32\sherlock2.exe
[2004/10/04 00:50:54 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/08/04 00:07:22 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/02 13:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/03/31 03:47:44 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\nl_msgs.dll
[2004/03/31 03:47:41 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\nl_msgc.dll
[2001/08/23 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 12:00:00 | 000,311,934 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 12:00:00 | 000,040,196 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 12:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011/12/22 18:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2011/12/22 15:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Evan\Application Data\LockTime
[2011/12/22 18:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Evan\Application Data\Azureus

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2011/12/22 15:49:12 | 000,000,000 | ---D | M](C:\Documents and Settings\Evan\Desktop\sewen.org-?????????????691P) -- C:\Documents and Settings\Evan\Desktop\sewen.org-台湾童颜巨乳美女徐湘婷最全691P
[2011/12/22 15:49:11 | 000,000,000 | ---D | C](C:\Documents and Settings\Evan\Desktop\sewen.org-?????????????691P) -- C:\Documents and Settings\Evan\Desktop\sewen.org-台湾童颜巨乳美女徐湘婷最全691P

< End of report >
  • 0

#28
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Could you install service pack 3 and then let me know what problems remain
  • 0

#29
Tazeris

Tazeris

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
I am waiting for my friend to install SP3.. please wait
  • 0

#30
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
No problems, how is the computer behaving at the moment ?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP