I'll post your log because it's easy for us to analyze it...
OTL logfile created on: 04/01/2012 13:02:27 - Run 5
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\HP_Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1.50 Gb Total Physical Memory | 0.66 Gb Available Physical Memory | 43.95% Memory free
3.60 Gb Paging File | 2.90 Gb Available in Paging File | 80.53% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 180.31 Gb Total Space | 102.45 Gb Free Space | 56.82% Space Free | Partition Type: NTFS
Drive D: | 5.99 Gb Total Space | 2.09 Gb Free Space | 34.98% Space Free | Partition Type: FAT32
Drive G: | 149.05 Gb Total Space | 48.82 Gb Free Space | 32.76% Space Free | Partition Type: NTFS
Computer Name: UNIX | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/01/04 11:55:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.scr
PRC - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/12/24 17:50:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/11/28 15:58:39 | 002,976,200 | ---- | M] (Zemana Ltd.) -- C:\Program Files\AntiLogger\AntiLogger.exe
PRC - [2011/09/03 00:00:10 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/06/15 15:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/11/06 21:24:30 | 001,867,888 | ---- | M] (PeerBlock, LLC) -- C:\STUFF\PeerBlock\peerblock.exe
PRC - [2010/05/31 11:42:52 | 019,317,672 | ---- | M] (Firetrust Ltd) -- C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
PRC - [2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ========== MOD - [2011/11/18 10:16:01 | 008,527,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/10/12 14:14:08 | 018,058,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\e5f8e311d5fbef90d3f6f641e893d898\System.ServiceModel.ni.dll
MOD - [2011/10/12 14:10:54 | 000,221,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\7a684c3b60526afb62a0969ada9c94cd\System.ServiceProcess.ni.dll
MOD - [2011/10/12 14:10:18 | 001,021,952 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\df89410d8f28b685778b11afe075c80d\System.Runtime.DurableInstancing.ni.dll
MOD - [2011/10/12 14:10:16 | 000,143,360 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\e3135e7811b6403f9cdfb759a339924c\SMDiagnostics.ni.dll
MOD - [2011/10/12 14:10:14 | 002,647,040 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\05153a9ff2b30a737faba58a3e88229c\System.Runtime.Serialization.ni.dll
MOD - [2011/10/12 12:55:43 | 000,317,952 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\SMSvcHost\6298828cba3cda0587dce31f24da69f3\SMSvcHost.ni.exe
MOD - [2011/10/12 12:36:54 | 001,782,272 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\bf5ca252df4083e6c48dc3e9f3273cf5\System.Xaml.ni.dll
MOD - [2011/10/12 11:41:59 | 005,617,664 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\1924bdaf130f882ceaf9d7b880602d22\System.Xml.ni.dll
MOD - [2011/10/12 11:41:52 | 000,982,528 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\096f1b3839e7d6dfe2598941329c08dc\System.Configuration.ni.dll
MOD - [2011/10/12 11:41:39 | 007,069,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\acf4f694ab9c0b1802e83e5cd726812f\System.Core.ni.dll
MOD - [2011/10/12 11:41:14 | 009,086,464 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\f477a17590634925c583632d171e2726\System.ni.dll
MOD - [2011/10/12 11:40:59 | 014,408,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\e360aa959e1b83be7026670d129c0a93\mscorlib.ni.dll
MOD - [2011/09/03 00:00:12 | 001,000,920 | ---- | M] () -- C:\Program Files\Mozilla Firefox\js3250.dll
MOD - [2011/02/24 01:57:18 | 000,555,112 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nView\nvShell.dll
MOD - [2010/10/25 14:13:50 | 000,109,472 | ---- | M] () -- C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn\components\WCFirefoxExtn.dll
MOD - [2010/07/04 21:32:38 | 000,010,752 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerCOM.dll
MOD - [2010/05/28 12:57:36 | 000,801,976 | ---- | M] () -- C:\Program Files\FireTrust\MailWasher Pro\ContactsLib.dll
MOD - [2010/04/19 07:48:28 | 000,277,904 | ---- | M] () -- C:\Program Files\FireTrust\MailWasher Pro\sqlite3.dll
MOD - [2009/08/25 16:51:10 | 000,155,320 | ---- | M] () -- C:\Program Files\FireTrust\MailWasher Pro\mailprefs.dll
MOD - [2009/08/16 16:06:02 | 000,141,312 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009/06/25 14:40:04 | 000,977,080 | ---- | M] () -- C:\Program Files\FireTrust\MailWasher Pro\MCore.dll
MOD - [2009/01/20 14:20:00 | 000,102,400 | ---- | M] () -- C:\Program Files\IDM Computer Solutions\UltraEdit\ue32ctmn.dll
MOD - [2008/09/12 16:39:34 | 000,611,936 | ---- | M] () -- C:\Program Files\FireTrust\MailWasher Pro\MailAnalysis.dll
MOD - [2006/03/09 14:38:56 | 000,155,648 | ---- | M] () -- C:\Program Files\FireTrust\MailWasher Pro\ssleay32.dll
MOD - [2006/03/09 14:38:48 | 000,684,032 | ---- | M] () -- C:\Program Files\FireTrust\MailWasher Pro\libeay32.dll
MOD - [2003/05/23 14:15:48 | 000,024,621 | ---- | M] () -- C:\Program Files\WS_FTP Pro\nsftpch.dll
MOD - [2003/05/23 14:02:34 | 000,135,214 | ---- | M] () -- C:\Program Files\WS_FTP Pro\wsftplib.dll
MOD - [2003/05/23 14:01:42 | 000,049,197 | ---- | M] () -- C:\Program Files\WS_FTP Pro\wshosts.dll
MOD - [2003/03/20 10:01:32 | 000,839,680 | ---- | M] () -- C:\Program Files\WS_FTP Pro\libeay32.dll
MOD - [2003/03/20 10:01:32 | 000,159,744 | ---- | M] () -- C:\Program Files\WS_FTP Pro\ssleay32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (StatusAgent)
SRV - File not found [Disabled | Stopped] -- -- (RichVideo)
SRV - File not found [Disabled | Stopped] -- -- (Pml Driver HPZ12)
SRV - File not found [Disabled | Stopped] -- -- (NMSAccess)
SRV - File not found [On_Demand | Stopped] -- -- (MySQL2)
SRV - File not found [Disabled | Stopped] -- -- (KService)
SRV - File not found [Disabled | Stopped] -- -- (EpsonBidirectionalService)
SRV - File not found [Disabled | Stopped] -- -- (EpsonBidirectionalAgent)
SRV - File not found [Disabled | Stopped] -- -- (AppMgmt)
SRV - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/10/14 15:37:12 | 001,479,488 | ---- | M] (TuneUp Software) [Disabled | Stopped] -- C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2011/05/17 09:40:26 | 000,066,560 | ---- | M] (Nalpeiron Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\system32\nlssrv32.exe -- (nlsX86cc)
SRV - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2011/04/11 13:44:44 | 000,112,800 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\IPROSetMonitor.exe -- (Intel® PROSet Monitoring Service) Intel®
SRV - [2011/04/08 05:14:00 | 002,218,600 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2007/11/26 13:47:40 | 000,598,856 | ---- | M] (Webroot Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Webroot\Washer\WasherSvc.exe -- (wwEngineSvc)
SRV - [2007/09/26 18:24:42 | 000,012,800 | ---- | M] (Agere Systems) [Disabled | Stopped] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2007/05/23 18:29:36 | 000,122,880 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\WINDOWS\System32\Crypserv.exe -- (Crypkey License)
SRV - [2007/01/31 13:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Disabled | Stopped] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2001/08/09 02:01:00 | 000,090,112 | ---- | M] (SEIKO EPSON CORPORATION) [Disabled | Stopped] -- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe -- (EPSONStatusAgent2)
SRV - [2000/05/16 02:00:00 | 000,060,416 | ---- | M] (SEIKO EPSON CORPORATION) [Disabled | Stopped] -- C:\WINDOWS\system32\E_S00RP2.EXE -- (EPSON_PM_RPCV2_02) EPSON V3 Service2(02)
========== Driver Services (SafeList) ========== DRV - [2012/01/04 12:30:14 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EACB7702-1777-470D-8F33-E5308A97F5AF}\MpKsl65b34ef9.sys -- (MpKsl65b34ef9)
DRV - [2012/01/04 12:18:29 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EACB7702-1777-470D-8F33-E5308A97F5AF}\MpKsla559aea1.sys -- (MpKsla559aea1)
DRV - [2012/01/04 12:17:19 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EACB7702-1777-470D-8F33-E5308A97F5AF}\MpKslec3e77a5.sys -- (MpKslec3e77a5)
DRV - [2012/01/04 09:36:51 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EACB7702-1777-470D-8F33-E5308A97F5AF}\MpKsle9e742e5.sys -- (MpKsle9e742e5)
DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/11/28 15:58:43 | 000,059,096 | ---- | M] (Zemana Ltd.) [Kernel | System | Running] -- C:\Program Files\AntiLogger\AntiLog32.sys -- (AntiLog32)
DRV - [2011/11/23 20:45:42 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2011/10/13 16:33:58 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2011/05/03 15:33:46 | 006,404,712 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2010/11/06 21:24:30 | 000,019,056 | ---- | M] () [Kernel | On_Demand | Running] -- C:\STUFF\PeerBlock\pbfilter.sys -- (pbfilter)
DRV - [2010/06/19 07:30:12 | 000,014,848 | ---- | M] (Siliten) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\InputFilter_FlexDef2b.sys -- (InputFilter_Hid_FlexDef2b) Siliten HID Devices(FlexDef2b)
DRV - [2010/05/11 12:24:49 | 000,017,134 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\PCANDIS5.SYS -- (PCANDIS5)
DRV - [2009/08/13 14:07:12 | 001,163,328 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/04/13 23:26:50 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008/04/13 23:23:10 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2007/07/26 08:25:12 | 000,039,808 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SRS_SSCFilter_i386.sys -- (SRS_SSCFilter) SRS Labs Audio Sandbox (WDM)
DRV - [2007/07/18 15:40:06 | 000,264,576 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8187B.sys -- (RTL8187B)
DRV - [2007/05/01 21:15:54 | 000,016,896 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\ckldrv.sys -- (NetworkX)
DRV - [2007/04/11 11:43:35 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2007/02/16 00:57:04 | 000,034,760 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2006/12/15 16:09:12 | 000,019,840 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\DaVinciDr.sysbolloxwhatsit -- (DaVinciDr)
DRV - [2006/12/13 19:02:22 | 000,513,152 | ---- | M] (Windows ® 2000/XP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SndTDriverV32.sys -- (SndTDriverV32)
DRV - [2006/11/29 04:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\APLMp50.sys -- (APLMp50)
DRV - [2005/12/12 16:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2)
DRV - [2004/08/04 04:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2002/07/17 07:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (ASPI32)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.co.uk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.co.uk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.co.uk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.co.ukIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.co.uk
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.co.uk
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = www.google.co.uk
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = www.google.co.uk
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.ukIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = www.google.co.uk
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaulturl: "
http://search.babylo...=browsersearch"FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.co.uk/"FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}:7.0
FF - prefs.js..extensions.enabledItems:
[email protected]:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems:
[email protected]:0.9c
FF - prefs.js..extensions.enabledItems:
[email protected]:1.3.3
FF - prefs.js..extensions.enabledItems:
[email protected]:2.2.6
FF - prefs.js..extensions.enabledItems: {0ac8a0b2-074e-407f-9742-e13b9e509c27}:1.3
FF - prefs.js..extensions.enabledItems: {5384767E-00D9-40E9-B72F-9CC39D655D6F}:1.4.1.0
FF - prefs.js..extensions.enabledItems: {6d96bb5e-1175-4ebf-8ab5-5f56f1c79f65}:0.9.5
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.13
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.serviceCapture.settings.network.proxy.http: ""
FF - prefs.js..extensions.serviceCapture.settings.network.proxy.http_port: 0
FF - prefs.js..extensions.serviceCapture.settings.network.proxy.no_proxies_on: "localhost, 127.0.0.1"
FF - prefs.js..extensions.serviceCapture.settings.network.proxy.share_proxy_settings: false
FF - prefs.js..extensions.serviceCapture.settings.network.proxy.socks: ""
FF - prefs.js..extensions.serviceCapture.settings.network.proxy.socks_port: 0
FF - prefs.js..extensions.serviceCapture.settings.network.proxy.ssl: ""
FF - prefs.js..extensions.serviceCapture.settings.network.proxy.ssl_port: 0
FF - prefs.js..extensions.serviceCapture.settings.network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\WINDOWS\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: File not found
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Documents and Settings\HP_Owner\Application Data\Octoshape\Octoshape Streaming Services\sua-1010122-0-npoctoshape.dll (Octoshape ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\
[email protected]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/04/25 09:30:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.22\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/02 23:21:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.22\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/21 14:29:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.14\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/11/10 17:16:44 | 000,000,000 | ---D | M]
[2011/09/16 17:10:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Extensions
[2010/07/06 18:44:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/09/16 17:10:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Extensions\
[email protected][2012/01/04 12:07:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions
[2011/03/15 17:29:48 | 000,000,000 | ---D | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\{0ac8a0b2-074e-407f-9742-e13b9e509c27}
[2011/08/05 18:37:19 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2011/10/15 14:01:15 | 000,000,000 | ---D | M] (Google Analytics Opt-out Browser Add-on) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\{6d96bb5e-1175-4ebf-8ab5-5f56f1c79f65}
[2011/09/15 12:41:45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}
[2011/09/06 14:15:30 | 000,000,000 | ---D | M] (Password Exporter) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2011/12/27 20:07:39 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/11/12 11:23:00 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/02/18 16:59:44 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\
[email protected][2011/11/04 01:59:37 | 000,000,000 | ---D | M] (MAFIAAFire Redirector) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\
[email protected][2011/10/15 14:01:14 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:creator="Matthew David Kesack" em:description="Upload images from the web directly to your Photobucket account." em:homepageURL="
http://www.photobucket.com/" em:iconURL="chrome://photobucket/content/images/pb-logo.png" em:id="
[email protected]" em:name="Photobucket Uploader" em:version="1.3.3">) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\
[email protected][2011/12/15 11:11:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\extensions\
[email protected][2011/10/26 19:36:13 | 000,001,903 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\searchplugins\btjunkie.xml
[2011/12/28 18:37:45 | 000,006,404 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\searchplugins\gallica-bnf.xml
[2011/12/31 15:16:33 | 000,006,498 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\searchplugins\gutenberg.xml
[2011/04/30 14:54:41 | 000,012,703 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\searchplugins\imdb.xml
[2011/04/30 15:00:26 | 000,001,597 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\searchplugins\the-pirate-bay.xml
[2011/12/29 14:26:20 | 000,002,057 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\dumjqzdw.default\searchplugins\youtube-video-search.xml
[2012/01/04 12:07:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/27 09:56:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/09/15 12:28:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
[2011/04/25 09:30:00 | 000,000,000 | ---D | M] (Adobe Acrobat - Create PDF) -- C:\PROGRAM FILES\ADOBE\ACROBAT 10.0\ACROBAT\BROWSER\WCFIREFOXEXTN
[2011/09/15 12:28:28 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/07/12 16:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2010/02/01 17:00:05 | 000,002,191 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/09/04 12:12:15 | 000,003,195 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Complitly.xml
O1 HOSTS File: ([2012/01/03 17:29:40 | 000,005,649 | RH-- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 spywar.com
O1 - Hosts: 127.0.0.1 123spywar.com
O1 - Hosts: 127.0.0.1 72.247.206.146
O1 - Hosts: 127.0.0.1 regnow.com
O1 - Hosts: 127.0.0.1 www.regnow.com
O1 - Hosts: 127.0.0.1 plimus.com
O1 - Hosts: 127.0.0.1 78.192.70.254 #moronic redirect
O1 - Hosts: 127.0.0.1 www.plimus.com
O1 - Hosts: 127.0.0.1 209.87.178.183
O1 - Hosts: 127.0.0.1 203.128.93.234
O1 - Hosts: 127.0.0.1 69.64.155.133
O1 - Hosts: 127.0.0.1 66.244.251.240 #ftp turd
O1 - Hosts: 127.0.0.1 66.244.192.0/18
O1 - Hosts: 127.0.0.1 BIGPIPEINC.COM
O1 - Hosts: 127.0.0.1 66.244.251.30
O1 - Hosts: 127.0.0.1 ad.doubleclick.net
O1 - Hosts: 127.0.0.1 www.voyages.netfirms.com
O1 - Hosts: 127.0.0.1 www.netfirms.com
O1 - Hosts: 127.0.0.1 3dns.adobe.com
O1 - Hosts: 127.0.0.1 3dns-1.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com
O1 - Hosts: 127.0.0.1 3dns-5.adobe.com
O1 - Hosts: 128 more lines...
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [AntiLogger] C:\Program Files\AntiLogger\AntiLogger.exe (Zemana Ltd.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [PeerBlock] C:\STUFF\PeerBlock\peerblock.exe (PeerBlock, LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\InfoDelivery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: nousernameinstartmenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: nosimplestartmenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: nochangestartmenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: norecentdochistory = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: maxrecentdocs = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: eset.eu ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: secunia.com ([]https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6A1D0A68-C5F2-401A-81CD-EB6210573F1F}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{70CD94B5-9D8C-486E-B8E8-3D3AFB6444E7}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7A545EDF-3EBE-41C5-B268-01AB4F12860F}: DhcpNameServer = 15.243.128.51 15.243.160.51
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/11/09 20:20:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | --S- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2007/05/15 12:34:42 | 000,000,000 | ---D | M] - G:\autorun -- [ NTFS ]
O33 - MountPoints2\{a9d5e89e-5821-11df-ba47-0018e770a587}\Shell - "" = AutoRun
O33 - MountPoints2\{a9d5e89e-5821-11df-ba47-0018e770a587}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: SSHNAS - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ========== [2012/01/04 11:56:36 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.scr
[2012/01/04 11:27:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\richard
[2012/01/03 19:05:54 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\HP_Owner\Recent
[2012/01/03 16:14:01 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/12/31 17:31:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Secunia PSI
[2011/12/31 17:27:56 | 000,000,000 | ---D | C] -- C:\Program Files\Secunia
[2011/12/31 12:17:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinPatrol
[2011/12/31 11:19:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Start Menu\Programs\The KMPlayer
[2011/12/30 10:35:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Application Data\Malwarebytes
[2011/12/30 10:32:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/12/30 10:32:08 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/12/30 10:32:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/12/29 20:02:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\New Folder (2)
[2011/12/29 15:29:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\Kindle hack
[2011/12/29 13:32:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Application Data\redsn0w
[2011/12/29 11:05:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Application Data\SystemSpeedBooster
[2011/12/29 11:05:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SystemSpeedBooster
[2011/12/29 11:05:17 | 000,000,000 | ---D | C] -- C:\Program Files\SystemSpeedBooster
[2011/12/27 12:14:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Kindle Collection Manager
[2011/12/27 12:14:21 | 000,000,000 | ---D | C] -- C:\Program Files\Kindle Collection Manager
[2011/12/23 17:15:31 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/12/23 14:19:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\WindSolutions
[2011/12/20 14:34:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\New Folder
[2011/12/19 22:52:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Socusoft
[2011/12/19 22:40:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Application Data\DxO Labs
[2011/12/19 22:39:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\DxO_Labs
[2011/12/19 22:39:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\My Documents\DxO Optics Pro v7 logs
[2011/12/18 16:06:00 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{2954F7C6-7A4E-4504-8DC4-C1DC7D251C94}
[2011/12/11 17:49:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Start Menu\Programs\Spell Checker For OE 2.1
[2011/12/06 12:33:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Desktop\glasses_files
[2011/12/06 10:15:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HP_Owner\Application Data\Apowersoft
[2011/12/05 18:35:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\MyLanViewer
[2011/12/05 18:35:03 | 000,000,000 | ---D | C] -- C:\Program Files\MyLanViewer
[2009/02/22 11:49:56 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\HP_Owner\Application Data\pcouffin.sys
[2007/06/01 13:06:15 | 000,047,616 | ---- | C] ( ) -- C:\WINDOWS\System32\Zipdll.dll
========== Files - Modified Within 30 Days ========== [2012/01/04 13:10:56 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2012/01/04 11:55:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Owner\Desktop\OTL.scr
[2012/01/04 09:57:36 | 000,419,246 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\1201041732.TIF
[2012/01/04 09:41:03 | 000,000,202 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/01/04 09:38:27 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/04 09:38:06 | 004,074,416 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/04 09:36:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/03 22:54:34 | 000,000,185 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Kindle (K).lnk
[2012/01/03 17:53:11 | 000,006,026 | ---- | M] () -- C:\Documents and Settings\HP_Owner\My Documents\cc_20120103_175307.reg
[2012/01/03 17:29:40 | 000,005,649 | RH-- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2012/01/03 17:29:40 | 000,005,649 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Copy of HOSTS
[2012/01/03 17:29:40 | 000,005,649 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Copy (3) of HOSTS
[2012/01/03 17:29:40 | 000,005,649 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Copy (2) of HOSTS
[2012/01/03 16:14:07 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/01/03 15:02:36 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/01/03 13:35:09 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/01/02 17:36:06 | 000,001,786 | --S- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2011/12/31 12:15:55 | 000,000,693 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/12/31 11:50:03 | 000,057,908 | ---- | M] () -- C:\Documents and Settings\HP_Owner\My Documents\cc_20111231_114957.reg
[2011/12/31 09:37:48 | 000,507,216 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/12/31 09:37:48 | 000,090,010 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/12/30 22:14:55 | 006,323,796 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\social_engineering_hadnagy_christopher.epub
[2011/12/30 20:44:31 | 000,000,185 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Kindle (G).lnk
[2011/12/30 19:57:54 | 000,000,839 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Hallmark Card Studio 2009.exe.lnk
[2011/12/30 19:27:02 | 000,001,170 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\WD Passport.lnk
[2011/12/30 11:01:37 | 000,167,096 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\scan.pdf
[2011/12/30 11:00:02 | 006,394,058 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\scan.jpg
[2011/12/30 10:55:02 | 006,083,675 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\2Scan-111230-0001.jpg
[2011/12/29 23:28:46 | 000,060,795 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\sad dog.jpeg
[2011/12/29 23:23:15 | 000,066,799 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\8_big.jpg
[2011/12/29 15:11:09 | 000,032,834 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\1112293036.TIF
[2011/12/29 15:10:36 | 000,032,834 | ---- | M] () -- C:\Documents and Settings\HP_Owner\My Documents\1112293036.TIF
[2011/12/19 22:41:15 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/12/18 16:06:08 | 000,034,704 | ---- | M] () -- C:\WINDOWS\syscall.dat
[2011/12/18 10:32:58 | 000,048,948 | ---- | M] () -- C:\Documents and Settings\HP_Owner\My Documents\cc_20111218_103254.reg
[2011/12/18 10:27:52 | 000,001,646 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\Kindle.lnk
[2011/12/17 13:45:47 | 000,000,124 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2011/12/14 12:35:02 | 000,056,832 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/14 11:45:53 | 000,000,187 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\KINGSTON (G).lnk
[2011/12/13 16:26:39 | 000,000,184 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\STICK (G).lnk
[2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/12/08 16:45:31 | 000,165,890 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\eye clinic 12-2011.pdf
[2011/12/06 12:33:48 | 000,012,531 | ---- | M] () -- C:\Documents and Settings\HP_Owner\Desktop\glasses.htm
========== Files Created - No Company Name ========== [2012/01/04 09:57:35 | 000,419,246 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\1201041732.TIF
[2012/01/04 09:41:33 | 000,000,390 | -H-- | C] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2012/01/04 09:36:16 | 004,074,416 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/03 22:54:34 | 000,000,185 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\Kindle (K).lnk
[2012/01/03 17:53:09 | 000,006,026 | ---- | C] () -- C:\Documents and Settings\HP_Owner\My Documents\cc_20120103_175307.reg
[2012/01/03 16:14:07 | 000,000,210 | ---- | C] () -- C:\Boot.bak
[2012/01/03 13:33:08 | 000,001,691 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/12/31 11:49:59 | 000,057,908 | ---- | C] () -- C:\Documents and Settings\HP_Owner\My Documents\cc_20111231_114957.reg
[2011/12/30 22:15:15 | 006,323,796 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\social_engineering_hadnagy_christopher.epub
[2011/12/30 19:57:54 | 000,000,839 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\Hallmark Card Studio 2009.exe.lnk
[2011/12/30 11:01:37 | 000,167,096 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\scan.pdf
[2011/12/30 10:59:55 | 006,394,058 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\scan.jpg
[2011/12/30 10:54:56 | 006,083,675 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\2Scan-111230-0001.jpg
[2011/12/29 23:28:46 | 000,060,795 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\sad dog.jpeg
[2011/12/29 23:23:11 | 000,066,799 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\8_big.jpg
[2011/12/29 15:11:09 | 000,032,834 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\1112293036.TIF
[2011/12/29 15:10:36 | 000,032,834 | ---- | C] () -- C:\Documents and Settings\HP_Owner\My Documents\1112293036.TIF
[2011/12/25 16:58:04 | 000,000,185 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\Kindle (G).lnk
[2011/12/20 01:51:58 | 000,719,890 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/12/18 10:32:57 | 000,048,948 | ---- | C] () -- C:\Documents and Settings\HP_Owner\My Documents\cc_20111218_103254.reg
[2011/12/14 11:45:53 | 000,000,187 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\KINGSTON (G).lnk
[2011/12/13 16:26:39 | 000,000,184 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\STICK (G).lnk
[2011/12/08 16:45:31 | 000,165,890 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\eye clinic 12-2011.pdf
[2011/12/06 12:33:47 | 000,012,531 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Desktop\glasses.htm
[2011/11/16 23:32:43 | 000,650,752 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/11/16 23:32:43 | 000,243,200 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/11/16 23:32:43 | 000,074,752 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2011/11/12 19:05:29 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2011/11/02 16:48:10 | 000,000,001 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\llftool.4.12.agreement
[2011/10/14 11:55:10 | 000,185,344 | ---- | C] () -- C:\WINDOWS\System32\drivers\KeDetective130.sys
[2011/10/05 20:33:56 | 000,034,704 | ---- | C] () -- C:\WINDOWS\syscall.dat
[2011/09/17 18:40:09 | 002,116,894 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2011/09/17 17:52:32 | 000,259,604 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/09/17 17:52:32 | 000,259,604 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/09/17 17:52:31 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/08/29 10:31:51 | 002,123,582 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2011/05/05 19:52:15 | 000,003,620 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\PassportPhotoStudio
[2011/04/30 13:18:39 | 000,000,368 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Setting.dat
[2011/04/30 13:18:39 | 000,000,022 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\UserFlag.ini
[2010/12/11 14:22:58 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2010/11/08 21:32:12 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\winscp.rnd
[2010/10/03 11:58:34 | 000,000,391 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2010/08/29 09:30:15 | 000,000,058 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Images.fl
[2010/07/31 20:23:13 | 000,000,235 | ---- | C] () -- C:\WINDOWS\teleprompt.ini
[2010/07/13 17:40:56 | 000,000,025 | ---- | C] () -- C:\WINDOWS\libem.INI
[2010/06/26 11:08:38 | 000,000,058 | ---- | C] () -- C:\WINDOWS\System32\msadio.dll
[2010/05/22 22:00:19 | 000,160,951 | ---- | C] () -- C:\WINDOWS\System32\drivers\gtipdsp_.bin
[2010/04/21 08:05:48 | 000,000,034 | ---- | C] () -- C:\WINDOWS\hdd.ini
[2010/04/01 17:51:10 | 000,000,376 | ---- | C] () -- C:\WINDOWS\mozregistry.dat
[2010/02/18 12:50:16 | 000,103,424 | ---- | C] () -- C:\WINDOWS\System32\DCLibrary_nat.dll
[2010/02/08 14:04:33 | 000,000,058 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\ducon.xml
[2010/01/27 23:57:34 | 000,000,058 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\ducon1.xml
[2010/01/27 23:53:13 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\users.xml
[2010/01/27 23:52:50 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2010/01/04 16:35:58 | 000,000,066 | ---- | C] () -- C:\WINDOWS\Aurora MPEG To DVD.INI
[2010/01/04 16:11:56 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\FoxImager.dll
[2009/12/31 17:55:49 | 000,445,072 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/12/21 09:55:19 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\oeattach.dll
[2009/12/08 21:43:20 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2009/12/03 17:01:22 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2009/09/17 10:20:50 | 000,416,824 | ---- | C] () -- C:\WINDOWS\System32\[bleep] - pwNative.exe
[2009/09/17 10:20:49 | 000,016,456 | ---- | C] () -- C:\WINDOWS\System32\[bleep] - pwdrvio.sys
[2009/09/17 10:20:49 | 000,011,088 | ---- | C] () -- C:\WINDOWS\System32\[bleep] - pwdspio.sys
[2009/08/26 12:28:07 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\MAS
[2009/08/26 12:28:07 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Displays
[2009/08/17 09:09:37 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RBRegEx350.dll
[2009/08/17 09:09:37 | 000,067,072 | ---- | C] () -- C:\WINDOWS\System32\LP0310.dll
[2009/08/17 09:09:37 | 000,061,952 | ---- | C] () -- C:\WINDOWS\System32\rbap350.dll
[2009/08/17 09:09:37 | 000,041,472 | ---- | C] () -- C:\WINDOWS\System32\MBSPlugin.DLL
[2009/08/17 09:09:37 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\RBShell400.dll
[2009/08/17 09:09:37 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\MBSRegistryPlugin.DLL
[2009/08/17 09:09:37 | 000,035,328 | ---- | C] () -- C:\WINDOWS\System32\MBSFolderPlugin.DLL
[2009/08/17 09:09:37 | 000,031,744 | ---- | C] () -- C:\WINDOWS\System32\MBSMacTTPlugin.DLL
[2009/08/17 09:09:37 | 000,029,184 | ---- | C] () -- C:\WINDOWS\System32\LP0301Gestalt.dll
[2009/08/17 09:09:37 | 000,028,160 | ---- | C] () -- C:\WINDOWS\System32\MBSRegPlugin.DLL
[2009/08/17 09:09:37 | 000,028,160 | ---- | C] () -- C:\WINDOWS\System32\LP0301ResFork.dll
[2009/08/17 09:09:37 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\LP0301LinkFile.dll
[2009/07/31 12:38:54 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2009/06/22 11:11:41 | 001,936,528 | ---- | C] () -- C:\WINDOWS\System32\ltmm15.dll
[2009/06/17 10:13:30 | 000,508,224 | ---- | C] () -- C:\WINDOWS\System32\ICCProfiles.dll
[2009/06/11 15:10:44 | 000,006,211 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2009/06/11 13:39:40 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/06/09 12:05:26 | 000,004,767 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2009/06/05 15:27:29 | 000,005,027 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ypkpiykb.yyrbollox
[2009/06/04 19:17:34 | 000,001,044 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\vso_ts_preview.xml
[2009/04/30 13:20:38 | 000,000,990 | --S- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\systemfl.$dk
[2009/04/27 23:07:55 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\ptlx55.dat.{5728B11F-B697-47AA-9C1B-8ECB545B5193}
[2009/04/24 17:32:05 | 000,000,181 | ---- | C] () -- C:\WINDOWS\System32\FOLESVR.DLL
[2009/04/10 18:36:55 | 000,000,031 | ---- | C] () -- C:\WINDOWS\System32\Days5.ini
[2009/03/23 11:52:28 | 000,000,121 | ---- | C] () -- C:\WINDOWS\winzipme.ini
[2009/03/23 11:51:15 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\addurl41.DLL
[2009/03/23 11:51:15 | 000,018,432 | ---- | C] () -- C:\WINDOWS\System32\winwatch.DLL
[2009/03/10 14:46:52 | 000,000,228 | ---- | C] () -- C:\WINDOWS\System32\edacded0_x.dat
[2009/03/05 10:37:26 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\wmpeq10.dll
[2009/03/05 10:37:25 | 002,179,072 | ---- | C] () -- C:\WINDOWS\System32\eq10core.dll
[2009/03/05 10:37:25 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ospitray.exe
[2009/02/22 11:49:56 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\pcouffin.cat
[2009/02/22 11:49:56 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\pcouffin.inf
[2009/02/16 00:47:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CleaningLab.INI
[2009/02/16 00:45:59 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2009/02/10 17:06:45 | 004,762,112 | ---- | C] () -- C:\WINDOWS\System32\NCMedia.dll
[2009/01/21 17:07:54 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/01/05 23:09:55 | 000,000,042 | ---- | C] () -- C:\WINDOWS\AlchemyMindworksUpdateList.INI
[2009/01/05 23:09:19 | 000,212,992 | ---- | C] () -- C:\WINDOWS\ALCHUNIN.EXE
[2008/12/17 15:21:11 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Textart.INI
[2008/11/14 18:57:11 | 000,000,307 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2008/11/04 19:02:16 | 000,383,238 | ---- | C] () -- C:\WINDOWS\System32\libmp3lame-0.dll
[2008/10/28 15:33:43 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2008/10/25 17:12:14 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\inst.exe
[2008/10/24 09:36:07 | 000,000,079 | ---- | C] () -- C:\WINDOWS\xptools.ini
[2008/10/24 09:34:53 | 000,259,584 | ---- | C] () -- C:\WINDOWS\System32\xtbaksm.datbollox
[2008/10/24 09:34:53 | 000,000,510 | ---- | C] () -- C:\WINDOWS\System32\xtupdate.datbollox
[2008/09/13 13:40:03 | 000,000,109 | ---- | C] () -- C:\WINDOWS\cncscore.ini
[2008/09/03 09:20:02 | 000,000,031 | ---- | C] () -- C:\WINDOWS\System32\RpDays.ini
[2008/08/18 12:10:48 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\pdfeditor.dat
[2008/08/14 18:24:54 | 003,657,728 | ---- | C] () -- C:\WINDOWS\System32\mkl_wavearts.dll
[2008/08/07 17:47:50 | 000,086,016 | ---- | C] () -- C:\WINDOWS\OPDIRDEL.exe
[2008/08/07 12:38:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2008/08/06 15:07:06 | 000,000,068 | ---- | C] () -- C:\WINDOWS\MyProg.ini
[2008/07/10 22:32:51 | 000,000,004 | ---- | C] () -- C:\WINDOWS\vx86036.dat
[2008/07/10 21:52:04 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2008/07/09 18:24:12 | 000,000,235 | ---- | C] () -- C:\WINDOWS\Crypkey.ini
[2008/07/09 18:24:12 | 000,000,049 | ---- | C] () -- C:\WINDOWS\ukid.INI
[2008/07/09 18:24:09 | 000,027,648 | ---- | C] () -- C:\WINDOWS\Setup_ck.exe
[2008/07/09 18:24:09 | 000,018,432 | ---- | C] () -- C:\WINDOWS\Setup_ck.dll
[2008/07/09 18:24:09 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2008/07/09 18:24:09 | 000,011,776 | ---- | C] () -- C:\WINDOWS\Ckrfresh.exe
[2008/07/03 13:02:07 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLbx.DAT
[2008/05/11 11:43:09 | 000,011,114 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\MainApp.dll
[2008/04/17 12:26:10 | 000,000,065 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\Salut et Fraternite
[2008/04/07 18:08:50 | 000,000,004 | R-S- | C] () -- C:\Documents and Settings\All Users\Application Data\sysqcl0.dat
[2008/04/06 18:11:48 | 000,000,100 | ---- | C] () -- C:\WINDOWS\ProductKeyExplorer.INI
[2008/03/27 17:56:32 | 000,000,058 | ---- | C] () -- C:\WINDOWS\System32\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2008/03/27 17:56:32 | 000,000,058 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2008/03/25 13:58:42 | 000,000,031 | ---- | C] () -- C:\WINDOWS\UKCpInfo.sys
[2008/03/25 12:10:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\WT12sptlEN.INI
[2008/03/24 11:25:14 | 000,000,056 | R-S- | C] () -- C:\WINDOWS\System32\A5B17BFFE2.sys
[2008/03/23 17:18:42 | 000,000,268 | R--- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\MIDI Drivers
[2008/03/23 17:18:42 | 000,000,268 | R--- | C] () -- C:\Documents and Settings\All Users\Application Data\Mallets
[2008/03/23 17:18:42 | 000,000,012 | R--- | C] () -- C:\Documents and Settings\All Users\Application Data\Synth Leads
[2008/03/23 16:07:28 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLbz.DAT
[2008/03/20 18:32:29 | 000,003,350 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sysbollox
[2008/03/20 18:32:29 | 000,000,088 | R-S- | C] () -- C:\Documents and Settings\All Users\Application Data\7577757C02.sysbollox
[2008/03/03 16:11:56 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\PDF2IMG.dat
[2008/02/18 19:21:30 | 000,000,045 | ---- | C] () -- C:\WINDOWS\dhp_2545.dat
[2008/02/17 13:16:44 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\CNMVS1U.DLL
[2008/02/17 12:25:39 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\CNMVS2F.DLL
[2008/01/31 23:55:20 | 000,000,109 | ---- | C] () -- C:\WINDOWS\System32\OSENXPSUITE2005.INI
[2008/01/28 17:48:45 | 000,000,256 | ---- | C] () -- C:\WINDOWS\onlineeye.INI
[2008/01/27 10:55:29 | 000,073,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\sentinel.sysbollox
[2008/01/27 10:55:29 | 000,002,421 | ---- | C] () -- C:\WINDOWS\System32\drivers\enport.sysbollox
[2007/12/10 09:02:20 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2007/12/10 00:01:19 | 000,025,600 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe.vir
[2007/12/05 22:20:01 | 000,008,194 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\atrans.bin
[2007/11/30 14:53:15 | 000,000,144 | ---- | C] () -- C:\WINDOWS\Eudcedit.ini
[2007/11/24 17:55:07 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.EXE
[2007/10/29 20:30:06 | 000,000,004 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\sysqcl1129139270.dat
[2007/10/25 16:30:04 | 000,008,575 | ---- | C] () -- C:\WINDOWS\System32\D125UFW.INI
[2007/10/03 18:59:01 | 000,000,205 | ---- | C] () -- C:\WINDOWS\pdf2word.INI
[2007/09/25 13:09:04 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\PUTTY.RND
[2007/09/22 10:36:16 | 000,081,321 | ---- | C] () -- C:\WINDOWS\SGTBox.INI
[2007/09/15 18:35:45 | 000,003,982 | ---- | C] () -- C:\WINDOWS\87t98.sys
[2007/09/15 18:35:45 | 000,000,112 | ---- | C] () -- C:\WINDOWS\cd-lock.ini
[2007/09/14 11:15:42 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\msvcrt88.dll
[2007/09/14 11:09:25 | 000,000,070 | ---- | C] () -- C:\WINDOWS\pdf2rtf.INI
[2007/09/14 11:09:09 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\pdf2word.dat
[2007/09/14 11:03:20 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\pdf2html.DAT
[2007/09/14 11:02:38 | 000,000,145 | ---- | C] () -- C:\WINDOWS\PDF2HTML.INI
[2007/09/14 09:55:30 | 000,101,159 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2007/09/14 09:55:30 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2007/09/14 09:55:30 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2007/09/14 09:55:30 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2007/09/14 09:55:30 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2007/09/14 09:55:30 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2007/09/14 09:55:30 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2007/09/14 09:55:30 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2007/09/14 09:55:30 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2007/09/14 09:55:30 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2007/09/14 09:55:30 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2007/09/14 09:55:30 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2007/09/14 09:55:30 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2007/09/14 09:55:30 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2007/09/14 09:55:30 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2007/09/14 09:55:30 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2007/09/14 09:55:30 | 000,000,099 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2007/09/14 09:54:18 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE R240R245EU.ini
[2007/09/14 08:05:12 | 000,112,688 | ---- | C] () -- C:\WINDOWS\System32\SHW32.DLL
[2007/09/14 08:05:12 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\ODMA32.dll
[2007/09/14 08:05:12 | 000,011,934 | ---- | C] () -- C:\WINDOWS\System32\pixpnr.dll
[2007/09/14 08:05:12 | 000,002,016 | ---- | C] () -- C:\WINDOWS\System32\sg5w30.dll
[2007/09/14 08:05:11 | 000,214,899 | ---- | C] () -- C:\WINDOWS\System32\aplib2.dll
[2007/09/14 08:05:11 | 000,046,512 | ---- | C] () -- C:\WINDOWS\System32\epsn.dll
[2007/09/14 08:05:11 | 000,034,144 | ---- | C] () -- C:\WINDOWS\System32\aplib1.dll
[2007/09/14 08:05:11 | 000,012,126 | ---- | C] () -- C:\WINDOWS\System32\pixpcz.dll
[2007/09/14 08:05:11 | 000,006,784 | ---- | C] () -- C:\WINDOWS\System32\accupage.dll
[2007/09/13 18:18:35 | 000,000,043 | ---- | C] () -- C:\WINDOWS\SETSCAN.INI
[2007/09/13 18:18:34 | 000,009,948 | ---- | C] () -- C:\WINDOWS\pixcache.ini
[2007/09/09 16:22:20 | 000,000,066 | ---- | C] () -- C:\WINDOWS\Power Video Converter.INI
[2007/09/09 15:49:57 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\W7409A4F3207fd2F2.bin
[2007/09/03 22:24:28 | 000,000,028 | ---- | C] () -- C:\WINDOWS\SWIFTREC.INI
[2007/09/03 10:27:26 | 000,000,001 | ---- | C] () -- C:\WINDOWS\explore256.dllbollox
[2007/09/02 11:45:27 | 000,162,304 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar36.dll
[2007/09/02 11:45:27 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\ztvunace26.dll
[2007/08/19 17:25:58 | 000,000,004 | ---- | C] () -- C:\WINDOWS\jknradee.sysbollox
[2007/08/16 07:54:38 | 000,081,920 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\ezpinst.exe
[2007/08/09 09:30:14 | 000,000,604 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\T2
[2007/08/09 09:30:14 | 000,000,604 | ---- | C] () -- C:\Program Files\STLL Notifier
[2007/07/29 18:53:40 | 000,000,022 | ---- | C] () -- C:\WINDOWS\OP70.INI
[2007/07/29 16:30:54 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\CNMVS47.DLL
[2007/07/26 08:25:14 | 000,039,808 | R--- | C] () -- C:\WINDOWS\System32\drivers\SRS_SSCFilter_i386.sys
[2007/07/26 08:25:08 | 000,047,360 | R--- | C] () -- C:\WINDOWS\System32\drivers\Surroundhp_kern_i386.sys
[2007/07/26 08:25:08 | 000,042,112 | R--- | C] () -- C:\WINDOWS\System32\drivers\csiidecoder_kern_i386.sys
[2007/07/26 08:25:06 | 000,047,104 | R--- | C] () -- C:\WINDOWS\System32\drivers\tshd4_kern_i386.sys
[2007/07/23 11:49:16 | 000,190,512 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2007/07/22 13:14:23 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\UNRAR3.dll
[2007/07/21 12:01:46 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\systeminfo3.dll
[2007/07/21 11:50:42 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\SystemInfo32.sys
[2007/07/21 11:50:10 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\SysEngine2.SYS
[2007/06/13 11:34:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2007/06/01 13:06:15 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Zipit.dll
[2007/05/31 15:56:13 | 000,440,832 | ---- | C] () -- C:\WINDOWS\rapidui.exe
[2007/05/27 16:42:49 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\gif89.dll
[2007/05/27 16:30:43 | 000,000,197 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2007/05/25 17:51:56 | 000,000,731 | ---- | C] () -- C:\WINDOWS\Fantastic Flame Screensaver.ini
[2007/05/18 15:56:51 | 000,000,009 | ---- | C] () -- C:\WINDOWS\System32\dxl.dat
[2007/05/17 12:33:58 | 000,000,102 | ---- | C] () -- C:\WINDOWS\pu32i.ini
[2007/04/29 18:33:59 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2007/04/27 17:13:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\STMMain.INI
[2007/04/27 13:58:36 | 000,000,227 | ---- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2007/04/27 13:58:27 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/04/27 13:55:22 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_InstantSHareJPG.ini
[2007/04/27 13:55:11 | 000,000,217 | ---- | C] () -- C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini
[2007/04/27 13:54:11 | 000,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2007/04/22 10:55:21 | 000,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2007/04/18 16:41:17 | 000,000,660 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/04/11 16:46:16 | 000,000,107 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2007/04/11 16:46:15 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\pdfmona.dll
[2007/04/11 16:46:15 | 000,051,716 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2007/04/01 23:02:00 | 000,000,145 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT3.DAT
[2007/03/28 14:11:45 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\EEBAPI.dll
[2007/03/28 14:11:45 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\EEBDSCVR.dll
[2007/03/28 14:11:45 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\EBAPI.dll
[2007/03/24 17:30:26 | 000,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/03/24 16:39:01 | 000,056,832 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/03/23 13:50:33 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2007/03/23 09:40:20 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\msvcrt10.dll
[2007/03/22 23:27:28 | 000,000,124 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2007/03/22 16:24:36 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\smrgdf.exe
[2007/03/22 12:22:10 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\FTPStubInstUtils.dll
[2007/03/21 09:04:37 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\PFP120JPR.{PB
[2007/03/21 09:04:37 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\PFP120JCM.{PB
[2007/03/21 09:03:11 | 000,001,786 | --S- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2007/03/21 08:52:24 | 000,000,630 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/03/20 23:01:39 | 000,000,874 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
[2007/03/20 16:08:45 | 000,000,145 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT.DAT
[2007/03/20 14:33:21 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\fusioncache.dat
[2007/03/20 14:28:09 | 000,053,248 | ---- | C] () -- C:\WINDOWS\AppRun.exe
[2007/03/20 14:28:09 | 000,000,540 | ---- | C] () -- C:\WINDOWS\AppRun.ini
[2007/03/20 14:27:38 | 000,160,963 | ---- | C] () -- C:\WINDOWS\System32\drivers\gtipdsp.bin
[2007/03/20 13:35:52 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2007/01/28 08:03:02 | 001,366,104 | ---- | C] () -- C:\WINDOWS\System32\ltwen14n.dll
[2006/12/15 16:09:12 | 000,019,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\DaVinciDr.sysbolloxwhatsit
[2006/11/02 16:10:16 | 000,080,912 | ---- | C] () -- C:\WINDOWS\System32\sherlock2.exe
[2006/07/24 05:37:06 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\Tao.Platform.Windows.dll
[2006/07/24 05:36:26 | 002,441,216 | ---- | C] () -- C:\WINDOWS\System32\Tao.OpenGl.dll
[2006/04/03 07:41:06 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\Zip.dll
[2005/05/09 23:52:32 | 000,022,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys
[2005/02/05 19:46:00 | 000,004,608 | ---- | C] () -- C:\WINDOWS\fgexec.dll
[2005/01/02 12:00:34 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/01/02 11:39:28 | 000,016,358 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2005/01/02 11:39:20 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2005/01/02 11:30:22 | 000,000,056 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2005/01/02 11:16:28 | 000,072,881 | ---- | C] () -- C:\WINDOWS\hpiins01.dat
[2005/01/02 10:59:46 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2005/01/02 10:56:10 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\pythoncom22.dll
[2005/01/02 10:56:10 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\pywintypes22.dll
[2005/01/02 10:55:47 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2004/11/09 20:39:12 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/11/09 20:25:42 | 000,507,216 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/11/09 20:25:42 | 000,090,010 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/11/09 20:19:44 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/11/09 20:17:58 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/10/08 07:15:38 | 000,000,485 | ---- | C] () -- C:\WINDOWS\System32\Codejock.CommandBars.9510.lic
[2004/08/04 18:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 12:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/06/25 02:10:06 | 000,000,439 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/09/05 05:22:25 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\msddlhas.dll
[2002/05/12 15:02:32 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\accesspv.dll
[2002/03/21 13:39:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL
[2001/08/23 23:12:28 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 23:11:02 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/01 14:18:16 | 000,029,600 | ---- | C] () -- C:\WINDOWS\System32\mxntdfg.exe
[2001/07/06 22:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2000/01/07 00:00:00 | 000,024,448 | ---- | C] () -- C:\WINDOWS\sysgtime.dll
[2000/01/07 00:00:00 | 000,024,448 | ---- | C] () -- C:\WINDOWS\System32\proclsvr.drv
[1999/01/22 19:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1996/04/03 19:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ========== [2007/10/14 12:22:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
[2007/04/11 11:43:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2011/07/22 10:42:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/01/27 23:42:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2012/01/03 14:58:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2009/02/10 16:38:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bassic Technologies
[2010/07/27 21:50:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DFX
[2010/11/28 17:04:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Mender
[2007/11/29 15:56:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Droppix
[2011/03/28 10:35:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DShield
[2011/03/28 11:06:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVDRanger
[2009/01/01 13:10:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eboostr
[2008/07/03 13:02:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2009/11/14 10:00:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2009/03/19 12:11:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Iceni
[2011/12/31 12:17:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/09/16 15:33:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\install_clap
[2007/11/04 17:54:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Laconic Software
[2008/10/19 19:14:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/07/29 08:11:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MAGIX
[2009/03/06 22:08:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mixesoft
[2009/11/24 15:22:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2010/09/30 23:34:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nuance
[2011/05/27 11:21:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\onOne Software
[2008/11/14 18:57:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PacketTrap Networks
[2008/10/09 07:51:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PaperlessPrinter Data
[2009/09/26 13:01:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PPLiveVA
[2011/04/25 09:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/10/03 11:58:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/01/22 14:07:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/01/15 17:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Serif
[2007/09/25 17:32:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skyline
[2011/08/28 09:59:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2011/12/19 22:52:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Socusoft
[2008/09/13 16:21:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SolarWinds
[2009/09/03 15:15:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2007/09/01 15:05:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SRS Labs
[2011/01/03 10:21:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STDUConverter
[2011/12/29 11:05:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SystemSpeedBooster
[2012/01/03 14:57:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/09/27 09:36:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TrackLogs
[2011/10/16 14:22:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2007/09/17 19:06:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2008/07/03 13:02:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2007/03/20 13:37:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/02/25 16:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viper
[2009/04/02 10:50:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VSO
[2007/12/27 19:20:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2008/02/27 16:24:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Watermark Factory
[2011/12/23 15:40:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindSolutions
[2011/08/30 14:46:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2011/08/30 14:47:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZipEC
[2009/07/25 23:12:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WNR
[2010/09/30 23:34:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zeon
[2011/12/18 16:06:00 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{2954F7C6-7A4E-4504-8DC4-C1DC7D251C94}
[2009/10/22 15:13:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{2EF4F8EB-1FF3-45C7-93BC-054FBE99D9E2}
[2011/10/16 14:20:30 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2010/10/19 17:35:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/06/19 07:34:42 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/09/22 10:52:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/26 14:21:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/12/19 13:01:18 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2012/01/04 13:10:56 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\Tasks\MpIdleTask.job
[2012/01/04 13:02:44 | 000,032,242 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: EXPLORER.EXE >[2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe
[2007/06/13 11:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
< MD5 for: SVCHOST.EXE >[2008/04/14 04:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 04:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 04:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2011/12/24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
< MD5 for: USERINIT.EXE >[2008/04/14 04:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 04:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 04:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2011/12/24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /mp /s > < hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/09/03 00:00:07 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/09/03 00:00:07 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/09/03 00:00:07 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/09/03 00:00:10 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/09/03 00:00:10 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/09/03 00:00:10 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/11/04 11:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/11/04 11:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/11/04 11:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Safari\Safari.exe" /reinstall [2010/06/04 11:15:16 | 002,387,768 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Safari\Safari.exe" /hideicons [2010/06/04 11:15:16 | 002,387,768 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Safari\Safari.exe" /showicons [2010/06/04 11:15:16 | 002,387,768 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files\Safari\Safari.exe" [2010/06/04 11:15:16 | 002,387,768 | ---- | M] (Apple Inc.)
< hklm\software\clients\startmenuinternet|command /64 /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/09/03 00:00:07 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/09/03 00:00:07 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/09/03 00:00:07 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/09/03 00:00:10 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/09/03 00:00:10 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/09/03 00:00:10 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/11/04 11:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/11/04 11:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/11/04 11:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Safari\Safari.exe" /reinstall [2010/06/04 11:15:16 | 002,387,768 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Safari\Safari.exe" /hideicons [2010/06/04 11:15:16 | 002,387,768 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Safari\Safari.exe" /showicons [2010/06/04 11:15:16 | 002,387,768 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files\Safari\Safari.exe" [2010/06/04 11:15:16 | 002,387,768 | ---- | M] (Apple Inc.)
========== Files - Unicode (All) ==========[2008/07/16 13:09:20 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?½) -- C:\WINDOWS\System32\½
[2008/07/10 08:57:10 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?½) -- C:\WINDOWS\System32\½
========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\wuweb.dll:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\cdintf251.dll:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\explore256.dllbollox:SummaryInformation
@Alternate Data Stream - 72 bytes -> C:\WINDOWS:241D7D5958580AAB
@Alternate Data Stream - 384 bytes -> C:\WINDOWS:nlsPreferences
@Alternate Data Stream - 368 bytes -> C:\Documents and Settings\HP_Owner\Local Settings\Application Data\desktop.ini:722b2b1c349a06abf0e866180e5a7e63
@Alternate Data Stream - 324 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
@Alternate Data Stream - 188 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ECF54A0E
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D2F2F703
@Alternate Data Stream - 177 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1AAB2E68
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A31FAD21
@Alternate Data Stream - 171 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C5760A8B
@Alternate Data Stream - 170 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:80337C03
@Alternate Data Stream - 167 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CE11B51
@Alternate Data Stream - 160 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:93C2F41D
@Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0CE7F3C9
@Alternate Data Stream - 154 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3D74A13
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7D43E156
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0574215C
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D95ACC7D
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9B013599
@Alternate Data Stream - 1223 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:sZG6btm8sNvtGbhyFoFc
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD
@Alternate Data Stream - 1133 bytes -> C:\Program Files\Outlook Express:IkktNRZxNmvxl2zcHPLdkE
@Alternate Data Stream - 1133 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:IyCycU393Fg3Ez53YHxliuR
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2FD2AC7E
@Alternate Data Stream - 1097 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:pG1RrPbyIQkHrAbtrgsANncM9wv
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2BE9FEFC
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 1016 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:snSwEzxZjOLL9CgDl7r7VLOojD
< End of report >