Thank you very much for this forum.
My computer will not run MBAM or get on the internet. My antivirus is also shut down and will not start. I noticed a rogue .exe file running in my processes called 297441164:1936213486.exe.
I just ran TFC and then OTL
Below is my OTL log
Thank you,
Happy
OTL logfile created on: 8/25/2011 10:32:09 AM - Run 2
OTL by OldTimer - Version 3.2.26.5 Folder = D:\Documents and Settings\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.42 Mb Total Physical Memory | 626.15 Mb Available Physical Memory | 61.24% Memory free
2.40 Gb Paging File | 2.17 Gb Available in Paging File | 90.21% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 30.26 Gb Total Space | 11.07 Gb Free Space | 36.59% Space Free | Partition Type: NTFS
Drive D: | 39.11 Gb Total Space | 5.66 Gb Free Space | 14.48% Space Free | Partition Type: NTFS
Drive F: | 889.75 Mb Total Space | 36.81 Mb Free Space | 4.14% Space Free | Partition Type: FAT
Computer Name: IBM-T43V062 | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found -- C:\WINDOWS\297441164:1936213486.exe
PRC - [2011/08/25 10:08:36 | 000,580,096 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Desktop\OTL.exe
PRC - [2009/05/27 12:00:24 | 000,753,664 | ---- | M] (Apple Inc.) -- C:\Program Files\AirPort\APAgent.exe
PRC - [2009/05/13 16:48:22 | 000,109,568 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009/03/02 13:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008/04/13 20:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/02/14 14:17:28 | 000,110,592 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2005/08/08 14:01:40 | 000,086,016 | ---- | M] (IBM Corporation) -- C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
PRC - [2005/08/02 19:12:44 | 000,081,920 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
PRC - [2005/08/02 19:06:54 | 000,032,768 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
PRC - [2005/08/02 19:02:20 | 001,372,160 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
PRC - [2005/08/02 18:17:30 | 000,722,480 | ---- | M] (IBM) -- C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
PRC - [2005/07/05 15:57:12 | 000,077,824 | ---- | M] () -- C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
PRC - [2005/06/06 21:26:22 | 000,040,960 | ---- | M] () -- C:\WINDOWS\system32\TpKmpSvc.exe
PRC - [2004/10/14 09:11:10 | 001,388,544 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
PRC - [2002/09/20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
========== Modules (No Company Name) ==========
MOD - [2011/05/28 22:04:56 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009/11/03 16:51:42 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2009/11/03 16:51:26 | 000,039,712 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll
MOD - [2009/01/28 16:03:49 | 000,326,401 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2008/06/20 12:02:47 | 000,245,248 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll
MOD - [2006/06/12 14:50:24 | 000,136,704 | ---- | M] () -- C:\Program Files\ThinkVantage\SMA\7z\7-zip.dll
MOD - [2006/04/14 12:04:58 | 000,876,544 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\Libeay32.dll
MOD - [2006/04/14 12:04:58 | 000,208,965 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2006/04/14 12:04:58 | 000,053,322 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\IntStngs.dll
MOD - [2005/08/02 19:12:44 | 000,081,920 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
MOD - [2005/08/02 19:06:54 | 000,032,768 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
MOD - [2005/08/02 19:03:56 | 000,139,264 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\CDRecord.dll
MOD - [2005/08/02 19:02:20 | 001,372,160 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
MOD - [2005/08/02 19:01:04 | 000,155,648 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\ui.dll
MOD - [2005/08/02 19:00:58 | 000,069,632 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\zlib.dll
MOD - [2005/08/02 18:58:08 | 000,671,744 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rr_res.dll
MOD - [2005/07/12 11:53:38 | 000,208,896 | ---- | M] () -- C:\Program Files\Lenovo\PkgMgr\HOTKEY\tpfnf7.dll
MOD - [2005/07/05 15:57:12 | 000,077,824 | ---- | M] () -- C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
MOD - [2005/06/16 23:23:08 | 000,024,576 | ---- | M] () -- C:\WINDOWS\system32\tphklock.dll
MOD - [2005/06/06 21:26:22 | 000,040,960 | ---- | M] () -- C:\WINDOWS\system32\TpKmpSvc.exe
MOD - [2005/04/14 01:01:00 | 000,073,728 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\PWRMGRIF.DLL
MOD - [2005/04/14 01:01:00 | 000,032,768 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\US\PWRMGRRT.DLL
MOD - [2003/07/03 23:49:30 | 000,024,576 | ---- | M] () -- C:\Program Files\Lenovo\PkgMgr\HOTKEY_2\tphk_2k.dll
MOD - [2001/10/28 17:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (WMConnectCDS)
SRV - File not found [On_Demand | Stopped] -- -- (PsaSrv)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2009/07/21 14:34:33 | 000,185,089 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009/05/13 16:48:22 | 000,109,568 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2008/04/13 20:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (W3SVC)
SRV - [2008/04/13 20:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (MSFtpsvc)
SRV - [2008/04/13 20:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (IISADMIN)
SRV - [2005/09/04 16:18:44 | 000,069,632 | ---- | M] (Macromedia) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service)
SRV - [2005/08/02 19:12:44 | 000,081,920 | ---- | M] () [Auto | Running] -- C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe -- (TVT Scheduler)
SRV - [2005/08/02 19:02:20 | 001,372,160 | ---- | M] () [Auto | Running] -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe -- (TVT Backup Service)
SRV - [2005/08/02 18:17:30 | 000,722,480 | ---- | M] (IBM) [Auto | Running] -- C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe -- (TSSCoreService)
SRV - [2005/06/06 21:26:22 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\TpKmpSvc.exe -- (TpKmpSVC)
SRV - [2002/09/20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))
SRV - [1998/06/06 00:00:00 | 000,034,036 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Visual Studio\COMMON\Tools\VS-Ent98\Vanalyzr\VARPC.EXE -- (Visual Studio Analyzer RPC bridge)
========== Driver Services (SafeList) ==========
DRV - [2009/07/28 16:33:56 | 000,055,656 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009/05/11 10:12:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009/03/30 10:33:07 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2009/02/13 12:35:05 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2006/04/27 16:45:00 | 000,014,848 | ---- | M] (Lenovo, Ltd. and IBM Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\TPDiskPM.sys -- (TPDiskPM)
DRV - [2006/04/14 13:04:08 | 000,013,568 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/04/05 19:38:22 | 002,208,512 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2006/03/30 15:03:00 | 000,006,784 | ---- | M] (Lenovo, Ltd. and IBM Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TPInput.sys -- (TPInput)
DRV - [2006/03/09 17:20:10 | 000,152,064 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2006/01/21 22:44:54 | 001,273,856 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/10/18 17:53:24 | 000,998,656 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/10/18 17:52:38 | 000,242,304 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2005/10/18 17:52:30 | 000,721,280 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/09/05 08:55:15 | 000,016,256 | ---- | M] (Lenovo) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\psadd.sys -- (psadd)
DRV - [2005/08/31 03:40:00 | 000,007,168 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\TSMAPIP.SYS -- (TSMAPIP)
DRV - [2005/08/31 02:50:00 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SMAPINT.SYS -- (Smapint)
DRV - [2005/08/31 02:50:00 | 000,009,340 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\TDSMAPI.SYS -- (TDSMAPI)
DRV - [2005/08/02 18:15:38 | 000,013,184 | ---- | M] (IBM) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ibmfilter.sys -- (ibmfilter)
DRV - [2005/08/02 18:00:22 | 000,014,336 | ---- | M] (National Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nsctpm11.sys -- (TPM11)
DRV - [2005/04/14 01:01:00 | 000,004,442 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\TPPWRIF.SYS -- (TPPWRIF)
DRV - [2004/05/19 19:41:26 | 000,013,757 | ---- | M] (National Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NscTpmDD.sys -- (portio)
DRV - [2003/09/19 01:47:00 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (Pfc)
DRV - [2003/08/21 22:25:52 | 000,094,600 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2303: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2361: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1465: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/08/23 20:45:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/08/23 20:45:37 | 000,000,000 | ---D | M]
[2008/08/29 02:25:03 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2011/08/24 20:32:06 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\2x311ay5.default\extensions
[2009/08/22 02:04:31 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\2x311ay5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/08/24 20:32:06 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- D:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\2x311ay5.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/07/25 22:21:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/07/26 22:02:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/08/23 20:45:34 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/08/23 20:45:28 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/06/08 19:19:25 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
O1 HOSTS File: ([2010/02/06 22:20:59 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O4 - HKLM..\Run: [AirPort Base Station Agent] C:\Program Files\AirPort\APAgent.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BootSkin Startup Jobs] C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe ()
O4 - HKLM..\Run: [KeyAccess] C:\WINDOWS\keyacc32.exe ()
O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (IBM Corp.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TP4EX] C:\WINDOWS\System32\TP4EX.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (Lenovo)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll (Apple Inc.)
O9 - Extra Button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\PkgMgr.exe (Lenovo Group Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} http://fpdownload.ma...are/awswaxd.cab (Macromedia Authorware Web Player Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=48835 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.micros...ntent/opuc2.cab (Office Update Installation Engine)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1125866187999 (MUWebControl Class)
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} https://www.ibm.com/...ntent/AcpIR.cab (IASRunner Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://webcsd.sacred...sCamControl.ocx (CamImage Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} https://webmail.factset.com/dwa7W.cab (Domino Web Access 7 Control)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O20 - AppInit_DLLs: (C:\WINDOWS\katrack.dll) - C:\WINDOWS\katrack.dll (Sassafras Software Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - notifyf2.dll - C:\WINDOWS\System32\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - tphklock.dll - C:\WINDOWS\System32\tphklock.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\DefaultBackground.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\DefaultBackground.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/06/27 18:28:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/08/25 10:20:35 | 000,446,464 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Desktop\TFC.exe
[2011/08/25 10:08:34 | 000,580,096 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Desktop\OTL.exe
[2011/08/24 22:45:33 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/08/24 22:45:33 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/08/24 22:45:29 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/08/10 21:31:32 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
[2011/08/10 21:31:27 | 000,237,568 | ---- | C] (www.helixcommunity.org) -- C:\WINDOWS\System32\yv12vfw.dll
[2011/08/10 21:31:27 | 000,151,552 | ---- | C] (fccHandler) -- C:\WINDOWS\System32\ac3acm.acm
[2011/08/10 20:54:25 | 000,000,000 | ---D | C] -- D:\Documents and Settings\User\Application Data\Media Player Classic
[2011/08/10 20:48:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2011/08/10 20:47:27 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Media Player Classic - Home Cinema
[2011/08/10 20:47:25 | 000,000,000 | ---D | C] -- C:\Program Files\Media Player Classic - Home Cinema
[2011/08/08 23:02:16 | 000,000,000 | R--D | C] -- D:\Documents and Settings\All Users\Documents\My Music
[2011/07/28 13:33:44 | 000,000,000 | R--D | C] -- D:\Documents and Settings\User\Recent
[2011/07/26 22:07:11 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/07/26 22:07:11 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\PDFCreator
[2011/07/26 22:07:11 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Internet Tools
[2011/07/26 22:07:08 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Sony
[2011/07/26 22:07:08 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Sony
[2011/07/26 22:07:05 | 000,000,000 | ---D | C] -- D:\Documents and Settings\User\Application Data\vlc
[2011/07/26 22:07:05 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2011/07/26 22:06:39 | 000,000,000 | ---D | C] -- C:\Program Files\MSDN
[2011/07/26 22:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio .NET 2003
[2011/07/26 22:02:13 | 000,000,000 | ---D | C] -- C:\Program Files\PDFCreator
[2011/07/26 22:02:12 | 000,000,000 | ---D | C] -- C:\Program Files\Software Metrics
[2011/07/26 22:02:10 | 000,000,000 | ---D | C] -- C:\Program Files\PuTTY
[2011/07/26 22:02:09 | 000,000,000 | ---D | C] -- C:\Program Files\Sassafras K2
[2011/07/26 22:02:07 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2011/07/26 22:02:04 | 000,000,000 | ---D | C] -- C:\Program Files\Smart NTFS Recovery
[2011/07/26 22:02:04 | 000,000,000 | ---D | C] -- C:\Program Files\Smart Flash Recovery
[2011/07/26 22:02:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sonic
[2011/07/26 22:01:02 | 000,000,000 | ---D | C] -- C:\Program Files\Analog Devices
[2011/07/26 21:59:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2011/07/26 21:57:41 | 000,000,000 | ---D | C] -- C:\Mikes Torrents
[2011/07/26 21:49:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\(null)
[2011/07/26 21:49:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Lenovo
[2011/07/26 21:48:30 | 000,000,000 | ---D | C] -- C:\DRIVERS
[2011/07/26 21:48:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\save$$updater
[2011/07/26 21:47:29 | 000,000,000 | ---D | C] -- D:\My Documents\Downloads
[1 D:\My Documents\*.tmp files -> D:\My Documents\*.tmp -> ]
[1 D:\Documents and Settings\Desktop\*.tmp files -> D:\Documents and Settings\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/08/25 10:31:41 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/08/25 10:31:27 | 000,002,048 | ---- | M] () -- C:\WINDOWS\bootstat.dat
[2011/08/25 10:31:27 | 000,000,000 | ---- | M] () -- C:\WINDOWS\297441164
[2011/08/25 10:31:24 | 1072,156,672 | -HS- | M] () -- C:\hiberfil.sys
[2011/08/25 10:20:36 | 000,446,464 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Desktop\TFC.exe
[2011/08/25 10:08:36 | 000,580,096 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Desktop\OTL.exe
[2011/08/24 23:14:16 | 000,043,408 | ---- | M] () -- C:\WINDOWS\System32\c_74222.nl_
[2011/08/24 22:45:33 | 000,000,672 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/24 22:29:06 | 000,036,864 | ---- | M] () -- D:\Documents and Settings\All Users\Application Data\KeyAccess Audit
[2011/08/24 22:28:58 | 002,469,040 | ---- | M] () -- D:\Documents and Settings\User\Local Settings\Application Data\KeyAccess Offline
[2011/08/24 22:19:04 | 000,087,040 | ---- | M] () -- D:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/22 20:42:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/10 21:18:30 | 000,469,086 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/08/10 21:18:30 | 000,076,726 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/08/10 21:15:25 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/08/10 20:47:27 | 000,001,728 | ---- | M] () -- D:\Documents and Settings\Desktop\Media Player Classic - Home Cinema.lnk
[2011/08/09 23:10:07 | 000,110,004 | ---- | M] () -- D:\My Documents\DSCN0173.JPG
[2011/08/09 23:09:01 | 000,047,741 | ---- | M] () -- D:\My Documents\DSCN0110.JPG
[2011/08/09 23:07:18 | 000,071,406 | ---- | M] () -- D:\My Documents\DSCN0196.JPG
[2011/08/09 23:06:24 | 000,127,371 | ---- | M] () -- D:\My Documents\Picture 901.jpg
[2011/08/09 23:05:51 | 000,087,708 | ---- | M] () -- D:\My Documents\DSCN0763.JPG
[2011/08/09 23:05:37 | 000,173,381 | ---- | M] () -- D:\My Documents\DSCN0758.JPG
[2011/08/09 23:04:14 | 000,078,112 | ---- | M] () -- D:\My Documents\101.JPG
[2011/08/09 23:03:18 | 000,097,475 | ---- | M] () -- D:\My Documents\085.JPG
[2011/08/09 23:01:22 | 000,099,055 | ---- | M] () -- D:\My Documents\DSC_0069.JPG
[2011/08/09 23:00:54 | 000,129,930 | ---- | M] () -- D:\My Documents\DSCN0133.JPG
[2011/08/09 23:00:18 | 000,075,617 | ---- | M] () -- D:\My Documents\DSCN0152.JPG
[2011/08/09 22:59:08 | 000,177,386 | ---- | M] () -- D:\My Documents\DSCN0142.JPG
[2011/08/09 22:58:49 | 000,151,382 | ---- | M] () -- D:\My Documents\DSCN0137.JPG
[2011/08/08 04:00:00 | 000,074,752 | ---- | M] () -- C:\WINDOWS\System32\ff_vfw.dll
[2011/08/08 04:00:00 | 000,000,038 | ---- | M] () -- C:\WINDOWS\avisplitter.ini
[2011/07/26 22:09:24 | 000,375,264 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[1 D:\My Documents\*.tmp files -> D:\My Documents\*.tmp -> ]
[1 D:\Documents and Settings\Desktop\*.tmp files -> D:\Documents and Settings\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/08/24 23:14:16 | 000,043,408 | ---- | C] () -- C:\WINDOWS\System32\c_74222.nl_
[2011/08/24 23:14:10 | 1072,156,672 | -HS- | C] () -- C:\hiberfil.sys
[2011/08/24 22:45:33 | 000,000,672 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/24 22:29:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\297441164
[2011/08/23 20:45:39 | 000,000,628 | ---- | C] () -- D:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/08/10 21:31:29 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2011/08/10 21:31:27 | 000,650,752 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/08/10 21:31:27 | 000,243,200 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/08/10 21:31:26 | 000,074,752 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2011/08/10 20:47:27 | 000,001,728 | ---- | C] () -- D:\Documents and Settings\Desktop\Media Player Classic - Home Cinema.lnk
[2011/08/09 23:10:05 | 000,110,004 | ---- | C] () -- D:\My Documents\DSCN0173.JPG
[2011/08/09 23:09:01 | 000,047,741 | ---- | C] () -- D:\My Documents\DSCN0110.JPG
[2011/08/09 23:07:18 | 000,071,406 | ---- | C] () -- D:\My Documents\DSCN0196.JPG
[2011/08/09 23:06:23 | 000,127,371 | ---- | C] () -- D:\My Documents\Picture 901.jpg
[2011/08/09 23:05:51 | 000,087,708 | ---- | C] () -- D:\My Documents\DSCN0763.JPG
[2011/08/09 23:05:36 | 000,173,381 | ---- | C] () -- D:\My Documents\DSCN0758.JPG
[2011/08/09 23:04:14 | 000,078,112 | ---- | C] () -- D:\My Documents\101.JPG
[2011/08/09 23:03:17 | 000,097,475 | ---- | C] () -- D:\My Documents\085.JPG
[2011/08/09 23:01:21 | 000,099,055 | ---- | C] () -- D:\My Documents\DSC_0069.JPG
[2011/08/09 23:00:53 | 000,129,930 | ---- | C] () -- D:\My Documents\DSCN0133.JPG
[2011/08/09 23:00:17 | 000,075,617 | ---- | C] () -- D:\My Documents\DSCN0152.JPG
[2011/08/09 22:59:07 | 000,177,386 | ---- | C] () -- D:\My Documents\DSCN0142.JPG
[2011/08/09 22:58:48 | 000,151,382 | ---- | C] () -- D:\My Documents\DSCN0137.JPG
[2011/08/08 23:20:30 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2011/07/26 23:49:34 | 000,036,864 | ---- | C] () -- D:\Documents and Settings\All Users\Application Data\KeyAccess Audit
[2010/06/22 21:53:53 | 000,082,260 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2008/05/27 19:46:18 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008/02/20 00:52:57 | 000,000,050 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/11/14 21:24:14 | 000,003,584 | ---- | C] () -- C:\WINDOWS\System32\wceprv.dll
[2007/11/05 00:51:35 | 000,001,156 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2007/11/04 12:17:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2007/10/14 17:55:20 | 000,087,040 | ---- | C] () -- D:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/05 14:32:48 | 000,005,021 | ---- | C] () -- D:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/09/01 09:08:50 | 002,469,040 | ---- | C] () -- D:\Documents and Settings\User\Local Settings\Application Data\KeyAccess Offline
[2006/08/08 13:14:05 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\FPCALL.dll
[2006/06/12 12:27:00 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\DEVMAN.DLL
[2006/01/31 18:00:13 | 000,000,203 | ---- | C] () -- C:\WINDOWS\SpssLM.ini
[2006/01/31 14:55:32 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2005/09/05 08:56:52 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\drivers\psasrv.exe
[2005/09/04 16:57:51 | 000,036,939 | ---- | C] () -- C:\WINDOWS\System32\insrepim.exe
[2005/07/06 00:45:08 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\notifyf2.dll
[2005/07/05 12:33:11 | 000,007,357 | ---- | C] () -- C:\WINDOWS\cfgall.ini
[2005/07/05 01:32:04 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\SmaSeed.exe
[2005/07/05 00:46:45 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\TpKmpSvc.exe
[2005/07/05 00:46:12 | 000,009,340 | ---- | C] () -- C:\WINDOWS\System32\drivers\TDSMAPI.SYS
[2005/07/05 00:15:14 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2005/07/05 00:15:14 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2005/07/05 00:15:14 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2005/07/05 00:15:14 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2005/07/05 00:15:14 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2005/07/05 00:15:14 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2005/07/05 00:12:38 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/07/04 23:15:58 | 000,001,313 | ---- | C] () -- D:\Documents and Settings\User\Application Data\vitalsource KEY Prefs
[2005/06/29 19:16:00 | 000,000,000 | ---- | C] () -- D:\Documents and Settings\User\Application Data\dm.ini
[2005/06/28 12:09:09 | 000,000,127 | ---- | C] () -- D:\Documents and Settings\User\Local Settings\Application Data\fusioncache.dat
[2005/06/28 10:35:37 | 000,000,126 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2005/06/28 10:26:43 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2005/06/27 22:52:48 | 000,000,780 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/06/27 21:13:00 | 000,073,782 | ---- | C] () -- C:\WINDOWS\System32\ibmpmsvc.exe
[2005/06/27 21:12:17 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2005/06/27 21:12:13 | 000,469,086 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005/06/27 21:12:13 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2005/06/27 21:12:13 | 000,076,726 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005/06/27 21:12:13 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2005/06/27 21:12:12 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2005/06/27 21:12:10 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005/06/27 21:12:09 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2005/06/27 21:12:01 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2005/06/27 21:12:01 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2005/06/27 21:11:52 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2005/06/27 21:11:42 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2005/06/27 20:17:19 | 000,000,351 | ---- | C] () -- C:\WINDOWS\TrayServerData.ini
[2005/06/27 20:16:35 | 000,007,840 | ---- | C] () -- C:\WINDOWS\System32\mcdmsg4.dll
[2005/06/27 18:53:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\frontpg.ini
[2005/06/27 18:52:28 | 000,038,576 | ---- | C] () -- C:\WINDOWS\System32\w3ctrs.ini
[2005/06/27 18:52:28 | 000,010,225 | ---- | C] () -- C:\WINDOWS\System32\axperf.ini
[2005/06/27 18:52:28 | 000,007,909 | ---- | C] () -- C:\WINDOWS\System32\ftpctrs.ini
[2005/06/27 18:52:27 | 000,011,435 | ---- | C] () -- C:\WINDOWS\System32\infoctrs.ini
[2005/06/27 18:52:27 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/06/27 18:49:59 | 000,016,384 | ---- | C] () -- C:\WINDOWS\PWMBTHLP.EXE
[2005/06/27 18:49:59 | 000,004,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2005/06/27 18:49:05 | 000,002,086 | ---- | C] () -- C:\WINDOWS\System32\SMBIOS.bin
[2005/06/27 18:30:31 | 000,002,048 | ---- | C] () -- C:\WINDOWS\bootstat.dat
[2005/06/27 18:25:31 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/06/27 14:19:37 | 000,004,346 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/06/27 14:18:45 | 000,375,264 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/06/11 11:47:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\fpprintmon.dll
[2005/06/10 17:59:16 | 000,095,617 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2005/06/01 13:00:00 | 000,331,776 | ---- | C] () -- C:\WINDOWS\keyacc32.exe
[2005/04/27 09:53:10 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\pwdmon.dll
[2004/11/08 20:12:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/12 20:11:26 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock.dll
[2004/01/09 09:10:32 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\AIBMRUNL.dll
[2003/06/24 14:43:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/08 23:28:42 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\TpScrLk.exe
[2002/03/19 18:30:00 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\mag.dll
[2002/03/19 17:30:00 | 000,216,576 | ---- | C] () -- C:\WINDOWS\System32\PowerCalc.exe
[2000/09/01 13:00:00 | 000,001,519 | ---- | C] () -- C:\WINDOWS\keyacc.ini
[2000/06/13 14:30:06 | 000,222,720 | ---- | C] () -- C:\WINDOWS\System32\spss_lmd.exe
[1998/12/06 16:56:04 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\verinst.exe
[1998/06/10 00:00:00 | 000,015,120 | ---- | C] () -- C:\WINDOWS\System32\REPUTIL.DLL
[1998/05/18 00:00:00 | 000,014,017 | ---- | C] () -- C:\WINDOWS\JAUTOEXP.INI
========== LOP Check ==========
[2006/08/09 15:32:01 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\DyKnow
[2005/07/05 00:10:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\ibm
[2011/07/26 22:07:08 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Sony
[2006/08/09 14:48:23 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Sophos
[2010/02/14 18:56:20 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\TEMP
[2005/09/05 09:13:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\ThinkVantage
[2010/01/04 21:52:43 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/09/07 16:12:04 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2006/01/31 11:30:25 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\Desktop Sidebar
[2006/01/31 15:12:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\Dev-Cpp
[2008/03/12 22:42:32 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\Flickr
[2007/09/23 16:36:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\HorizonWimba
[2005/07/05 00:29:02 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\IBM
[2005/07/05 12:21:44 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\InterVideo
[2005/07/05 00:28:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\Leadertech
[2010/09/25 14:00:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\Publish Providers
[2010/09/25 14:00:59 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\Sony
[2005/09/05 09:13:40 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\ThinkVantage
[2011/08/25 00:05:04 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\uTorrent
[2006/01/31 12:52:43 | 000,000,000 | ---D | M] -- D:\Documents and Settings\User\Application Data\Vital Source Technologies
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 816 bytes -> C:\WINDOWS\297441164:1936213486.exe
@Alternate Data Stream - 125 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 110 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >