OTL.LOG
OTL logfile created on: 7/04/2012 2:25:03 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\admin-su\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
510.73 Mb Total Physical Memory | 298.19 Mb Available Physical Memory | 58.38% Memory free
1.22 Gb Paging File | 0.93 Gb Available in Paging File | 76.39% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 52.92 Gb Free Space | 71.02% Space Free | Partition Type: NTFS
Drive E: | 3.72 Gb Total Space | 2.80 Gb Free Space | 75.31% Space Free | Partition Type: FAT32
Computer Name: SERVER | User Name: admin-su | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/04/07 13:14:06 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin-su\Desktop\OTL.com
PRC - [2011/10/05 10:18:37 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011/10/05 10:18:29 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/10/05 10:18:17 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011/10/05 10:18:17 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/03/18 01:26:14 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2011/03/18 01:24:50 | 001,043,968 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ========== MOD - [2011/10/05 10:18:31 | 000,398,288 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2011/10/05 10:18:29 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/10/05 10:18:17 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/03/18 01:26:14 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- (vsmon)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/03/10 15:11:24 | 000,137,416 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/09/15 23:55:04 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011/09/15 23:55:03 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/06/17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/05/13 10:02:32 | 000,532,224 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2008/03/17 11:03:46 | 000,101,376 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2002/12/20 21:50:54 | 000,061,408 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\viaraid.sys -- (viaraid)
DRV - [2001/08/17 23:28:12 | 000,488,383 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_V124.sys -- (V124)
DRV - [2001/08/17 23:28:12 | 000,050,751 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_TONE.sys -- (Tones)
DRV - [2001/08/17 23:28:10 | 000,542,879 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_MSFT.sys -- (hsf_msft)
DRV - [2001/08/17 23:28:10 | 000,057,471 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_SAMP.sys -- (Rksample)
DRV - [2001/08/17 23:28:08 | 000,391,199 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_K56K.sys -- (K56)
DRV - [2001/08/17 23:28:06 | 000,289,887 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_FALL.sys -- (Fallback)
DRV - [2001/08/17 23:28:06 | 000,199,711 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_FAXX.sys -- (SoftFax)
DRV - [2001/08/17 23:28:06 | 000,115,807 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_FSKS.sys -- (Fsks)
DRV - [2001/08/17 23:28:04 | 000,067,167 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_BSC2.sys -- (basic2)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...ferrer:source?} IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...Box&Form=IE8SRCIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Gmail = C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
O1 HOSTS File: ([2003/03/31 22:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Mobile Partner] C:\Program Files\3 MobileBroadband\3 MobileBroadband.exe ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/03/10 12:13:23 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2012/04/07 14:17:09 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012/04/07 14:17:10 | 000,000,000 | ---D | M] - E:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{67022981-6a6d-11e1-85df-91647d583422}\Shell - "" = AutoRun
O33 - MountPoints2\{67022981-6a6d-11e1-85df-91647d583422}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{67022981-6a6d-11e1-85df-91647d583422}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{67022982-6a6d-11e1-85df-91647d583422}\Shell - "" = AutoRun
O33 - MountPoints2\{67022982-6a6d-11e1-85df-91647d583422}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{67022982-6a6d-11e1-85df-91647d583422}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{b84a80fe-6a5d-11e1-85dd-da0c9b9811f6}\Shell - "" = AutoRun
O33 - MountPoints2\{b84a80fe-6a5d-11e1-85dd-da0c9b9811f6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b84a80fe-6a5d-11e1-85dd-da0c9b9811f6}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ========== [2012/04/07 14:24:12 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\admin-su\Desktop\OTL.com
[2012/04/07 14:17:09 | 000,000,000 | ---D | C] -- C:\autorun.inf
[2012/04/07 14:16:35 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\admin-su\My Documents\OTL.com
[2012/04/06 14:27:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\tmp2
[2012/04/06 13:37:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Support Tools
[2012/04/06 13:37:19 | 000,000,000 | ---D | C] -- C:\Program Files\SumatraPDF
[2012/04/06 08:27:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2012/04/06 00:28:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\tmp
[2012/03/29 06:38:20 | 000,000,000 | ---D | C] -- C:\Program Files\Support Tools
[2012/03/25 15:44:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\Application Data\SumatraPDF
[2012/03/14 13:28:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\My Documents\Pinnacle Studio
[2012/03/14 13:28:33 | 000,000,000 | R--D | C] -- C:\Documents and Settings\admin-su\My Documents\My Videos
[2012/03/14 13:21:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\admin-su\My Documents\Fin Plan_x
[2012/03/14 13:21:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\admin-su\My Documents\Dons Folder
[2012/03/14 13:21:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\My Documents\Downloads
[2012/03/13 07:26:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2012/03/11 19:08:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\My Documents\asus
[2012/03/11 15:13:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Convert Doc
[2012/03/11 15:13:51 | 000,487,424 | ---- | C] (SoftInterface.COM) -- C:\WINDOWS\System32\PDFConverterX.ocx
[2012/03/11 15:13:51 | 000,208,896 | ---- | C] (BCL Technologies) -- C:\WINDOWS\System32\beconv.dll
[2012/03/11 15:13:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Resource
[2012/03/11 15:13:50 | 001,047,552 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_dox.dll
[2012/03/11 15:13:50 | 000,706,048 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_doc.dll
[2012/03/11 15:13:50 | 000,687,104 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_pdf.dll
[2012/03/11 15:13:50 | 000,582,144 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_rtf.dll
[2012/03/11 15:13:50 | 000,573,440 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_htm.dll
[2012/03/11 15:13:50 | 000,435,200 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_css.dll
[2012/03/11 15:13:50 | 000,220,160 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_png.flt
[2012/03/11 15:13:50 | 000,187,904 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_jpg.flt
[2012/03/11 15:13:50 | 000,155,136 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_ic.dll
[2012/03/11 15:13:50 | 000,101,376 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_tif.flt
[2012/03/11 15:13:50 | 000,052,736 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_gif.flt
[2012/03/11 15:13:50 | 000,044,032 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_wmf.flt
[2012/03/11 15:13:49 | 001,119,232 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16.dll
[2012/03/11 15:13:49 | 000,380,928 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx4ole16.ocx
[2012/03/11 15:13:49 | 000,327,680 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_obj.dll
[2012/03/11 15:13:49 | 000,241,664 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_tls.dll
[2012/03/11 15:13:49 | 000,106,496 | ---- | C] (Skogen) -- C:\WINDOWS\System32\SeeThroughPicture.ocx
[2012/03/11 15:13:49 | 000,074,752 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_bmp.flt
[2012/03/11 15:13:49 | 000,065,536 | ---- | C] (The Imaging Source Europe GmbH) -- C:\WINDOWS\System32\tx16_wnd.dll
[2012/03/11 15:13:46 | 000,000,000 | ---D | C] -- C:\Program Files\Softinterface, Inc
[2012/03/10 22:05:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2012/03/10 22:05:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2012/03/10 22:05:28 | 000,000,000 | R--D | C] -- C:\Program Files
[2012/03/10 22:05:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2012/03/10 22:05:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2012/03/10 22:05:12 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2012/03/10 22:05:12 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu
[2012/03/10 22:05:12 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents
[2012/03/10 22:05:12 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates
[2012/03/10 22:05:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2012/03/10 22:05:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop
[2012/03/10 22:05:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2012/03/10 22:05:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2012/03/10 22:04:56 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2012/03/10 22:04:56 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data
[2012/03/10 22:04:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings
[2012/03/10 22:01:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\OemDir
[2012/03/10 22:01:23 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2012/03/10 22:01:23 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2012/03/10 22:01:23 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web
[2012/03/10 22:01:23 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2012/03/10 22:01:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2012/03/10 19:41:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\Start Menu\Programs\Google Chrome
[2012/03/10 19:30:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\Local Settings\Application Data\Google
[2012/03/10 19:25:58 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\admin-su\PrivacIE
[2012/03/10 17:49:59 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2012/03/10 17:49:24 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\admin-su\My Documents\mbam-setup-1.51.2.1300.exe
[2012/03/10 17:49:24 | 006,055,875 | ---- | C] (LIGHTNING UK!) -- C:\Documents and Settings\admin-su\My Documents\SetupImgBurn_2.5.6.0.exe
[2012/03/10 17:49:24 | 004,763,136 | ---- | C] (Krzysztof Kowalczyk) -- C:\Documents and Settings\admin-su\My Documents\SumatraPDF-1.8-install.exe
[2012/03/10 17:42:22 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/03/10 17:37:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office Tools
[2012/03/10 17:37:02 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2012/03/10 17:36:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Designer
[2012/03/10 17:36:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\ShellNew
[2012/03/10 17:36:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/03/10 16:29:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\My Documents\Downloaded
[2012/03/10 14:56:22 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\admin-su\IETldCache
[2012/03/10 14:32:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2012/03/10 14:32:32 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012/03/10 13:24:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2012/03/10 13:24:29 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2012/03/10 13:07:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2012/03/10 13:05:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\3 MobileBroadband
[2012/03/10 13:05:28 | 000,872,192 | ---- | C] (DiBcom SA) -- C:\WINDOWS\System32\drivers\mod7700.sys
[2012/03/10 13:05:28 | 000,103,168 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbfake.sys
[2012/03/10 13:05:28 | 000,101,376 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbmdm.sys
[2012/03/10 13:05:28 | 000,100,992 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbnet.sys
[2012/03/10 13:05:28 | 000,024,448 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewdcsc.sys
[2012/03/10 13:04:45 | 000,000,000 | ---D | C] -- C:\Program Files\3 MobileBroadband
[2012/03/10 12:58:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ZoneAlarm
[2012/03/10 12:58:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ZoneLabs
[2012/03/10 12:58:06 | 000,000,000 | ---D | C] -- C:\Program Files\Zone Labs
[2012/03/10 12:57:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs
[2012/03/10 12:55:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\Application Data\Avira
[2012/03/10 12:55:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2012/03/10 12:55:20 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2012/03/10 12:55:18 | 000,137,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2012/03/10 12:55:18 | 000,074,640 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2012/03/10 12:55:18 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avkmgr.sys
[2012/03/10 12:55:18 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012/03/10 12:55:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2012/03/10 12:52:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2012/03/10 12:52:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012/03/10 12:45:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-us
[2012/03/10 12:45:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2012/03/10 12:45:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\provisioning
[2012/03/10 12:45:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2012/03/10 12:45:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\peernet
[2012/03/10 12:45:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2012/03/10 12:45:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2012/03/10 12:44:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2012/03/10 12:42:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic
[2012/03/10 12:41:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2012/03/10 12:40:15 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2012/03/10 12:40:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\EHome
[2012/03/10 12:36:39 | 009,287,264 | ---- | C] (Softinterface, Inc. ) -- C:\Documents and Settings\admin-su\My Documents\CD.EXE
[2012/03/10 12:23:44 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2012/03/10 12:18:14 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2012/03/10 12:18:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\Application Data\Identities
[2012/03/10 12:18:07 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2012/03/10 12:18:06 | 000,000,000 | R--D | C] -- C:\Documents and Settings\admin-su\My Documents\My Pictures
[2012/03/10 12:18:06 | 000,000,000 | R--D | C] -- C:\Documents and Settings\admin-su\My Documents\My Music
[2012/03/10 12:18:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\Local Settings\Application Data\Microsoft
[2012/03/10 12:18:03 | 000,000,000 | --SD | C] -- C:\Documents and Settings\admin-su\Application Data\Microsoft
[2012/03/10 12:18:03 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\admin-su\SendTo
[2012/03/10 12:18:03 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\admin-su\Recent
[2012/03/10 12:18:03 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\admin-su\Application Data
[2012/03/10 12:18:03 | 000,000,000 | R--D | C] -- C:\Documents and Settings\admin-su\Start Menu\Programs\Startup
[2012/03/10 12:18:03 | 000,000,000 | R--D | C] -- C:\Documents and Settings\admin-su\Start Menu
[2012/03/10 12:18:03 | 000,000,000 | R--D | C] -- C:\Documents and Settings\admin-su\My Documents
[2012/03/10 12:18:03 | 000,000,000 | R--D | C] -- C:\Documents and Settings\admin-su\Favorites
[2012/03/10 12:18:03 | 000,000,000 | R--D | C] -- C:\Documents and Settings\admin-su\Start Menu\Programs\Accessories
[2012/03/10 12:18:03 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\admin-su\Cookies
[2012/03/10 12:18:03 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\admin-su\Templates
[2012/03/10 12:18:03 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\admin-su\PrintHood
[2012/03/10 12:18:03 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\admin-su\NetHood
[2012/03/10 12:18:03 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\admin-su\Local Settings
[2012/03/10 12:18:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin-su\Desktop
[2012/03/10 12:16:16 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/03/10 12:16:15 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2012/03/10 12:16:15 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2012/03/10 12:16:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2012/03/10 12:16:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2012/03/10 12:14:37 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2012/03/10 12:14:37 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2012/03/10 12:13:46 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2012/03/10 12:13:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2012/03/10 12:13:29 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2012/03/10 12:13:29 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2012/03/10 12:12:45 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM
[2012/03/10 12:12:37 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2012/03/10 12:12:37 | 000,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2012/03/10 12:12:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2012/03/10 12:11:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2012/03/10 12:11:45 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2012/03/10 12:11:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2012/03/10 12:11:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2012/03/10 12:11:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2012/03/10 12:11:38 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2012/03/10 12:11:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2012/03/10 12:11:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\PCHealth
[2012/03/10 12:11:32 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2012/03/10 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2012/03/10 12:11:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2012/03/10 12:11:27 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2012/03/10 12:11:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2012/03/10 12:11:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2012/03/10 12:11:22 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2012/03/10 12:11:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2012/03/10 12:11:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2012/03/10 12:11:02 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2012/03/10 12:11:01 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012/03/10 12:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services
[2012/03/10 12:11:00 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2012/03/10 12:10:57 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2012/03/10 12:10:53 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2012/03/10 12:10:25 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2012/03/10 12:10:25 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2012/03/10 12:10:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2012/03/10 12:10:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2012/03/10 12:10:04 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/04/07 14:13:49 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/04/07 14:11:00 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1715567821-725345543-1005UA.job
[2012/04/07 13:35:00 | 000,000,990 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1715567821-725345543-1004UA.job
[2012/04/07 13:20:08 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\admin-su\My Documents\30kr1xnx.exe
[2012/04/07 13:14:06 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin-su\My Documents\OTL.com
[2012/04/07 13:14:06 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin-su\Desktop\OTL.com
[2012/04/07 12:56:30 | 000,132,597 | ---- | M] () -- C:\Documents and Settings\admin-su\My Documents\Flash_Disinfector.exe
[2012/04/06 19:35:00 | 000,000,938 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1715567821-725345543-1004Core.job
[2012/04/06 17:11:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1715567821-725345543-1005Core.job
[2012/04/06 14:42:51 | 000,312,220 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/04/06 14:42:51 | 000,040,224 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/04/06 14:41:04 | 000,161,936 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/04/05 15:09:46 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/03/16 16:47:22 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/03/15 07:26:44 | 000,000,376 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2012/03/14 15:06:59 | 000,006,656 | ---- | M] () -- C:\Documents and Settings\admin-su\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/14 12:07:41 | 000,000,052 | ---- | M] () -- C:\WINDOWS\SW_Win3112X32.DLL
[2012/03/13 17:13:40 | 000,000,828 | ---- | M] () -- C:\Documents and Settings\admin-su\Application Data\Microsoft\Internet Explorer\Quick Launch\EXCEL.lnk
[2012/03/13 07:38:57 | 000,002,287 | ---- | M] () -- C:\Documents and Settings\admin-su\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/03/13 07:38:56 | 000,002,309 | ---- | M] () -- C:\Documents and Settings\admin-su\Desktop\Google Chrome.lnk
[2012/03/12 08:46:30 | 000,000,804 | ---- | M] () -- C:\Documents and Settings\admin-su\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/03/11 15:13:55 | 000,000,826 | ---- | M] () -- C:\Documents and Settings\admin-su\Desktop\Convert Doc.lnk
[2012/03/10 17:43:12 | 000,000,828 | ---- | M] () -- C:\Documents and Settings\admin-su\Desktop\EXCEL.lnk
[2012/03/10 17:42:13 | 000,000,840 | ---- | M] () -- C:\Documents and Settings\admin-su\Desktop\WORD.lnk
[2012/03/10 17:37:03 | 000,001,730 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2012/03/10 15:11:24 | 000,137,416 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2012/03/10 14:56:32 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\admin-su\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/03/10 13:09:38 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
[2012/03/10 13:05:40 | 000,000,790 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\3 MobileBroadband.lnk
[2012/03/10 12:58:35 | 000,420,800 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2012/03/10 12:58:16 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2012/03/10 12:58:16 | 000,000,731 | ---- | M] () -- C:\Documents and Settings\admin-su\Desktop\ZoneAlarm Security.lnk
[2012/03/10 12:55:35 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira Control Center.lnk
[2012/03/10 12:52:57 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2012/03/10 12:46:53 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2012/03/10 12:42:39 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2012/03/10 12:42:39 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2012/03/10 12:35:39 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\admin-su\Desktop\My Computer.lnk
[2012/03/10 12:18:16 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\admin-su\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/03/10 12:18:12 | 000,025,065 | ---- | M] () -- C:\WINDOWS\System32\wmpscheme.xml
[2012/03/10 12:15:47 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2012/03/10 12:15:01 | 000,000,386 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2012/03/10 12:13:23 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/03/10 12:13:23 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2012/03/10 12:13:23 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2012/03/10 12:13:23 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2012/03/10 12:13:23 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2012/03/10 12:13:21 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012/03/10 12:13:21 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012/03/10 12:13:20 | 000,299,552 | ---- | M] () -- C:\WINDOWS\WMSysPrx.prx
[2012/03/10 12:13:16 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2012/03/10 12:11:23 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012/03/09 09:54:26 | 009,287,264 | ---- | M] (Softinterface, Inc. ) -- C:\Documents and Settings\admin-su\My Documents\CD.EXE
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/04/07 14:16:36 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\admin-su\My Documents\30kr1xnx.exe
[2012/04/07 14:16:36 | 000,132,597 | ---- | C] () -- C:\Documents and Settings\admin-su\My Documents\Flash_Disinfector.exe
[2012/03/25 15:44:41 | 000,001,586 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\SumatraPDF.lnk
[2012/03/16 17:06:41 | 000,000,974 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1715567821-725345543-1005UA.job
[2012/03/16 17:06:41 | 000,000,922 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1715567821-725345543-1005Core.job
[2012/03/13 17:13:40 | 000,000,828 | ---- | C] () -- C:\Documents and Settings\admin-su\Application Data\Microsoft\Internet Explorer\Quick Launch\EXCEL.lnk
[2012/03/11 15:14:08 | 000,000,052 | ---- | C] () -- C:\WINDOWS\SW_Win3112X32.DLL
[2012/03/11 15:13:55 | 000,000,826 | ---- | C] () -- C:\Documents and Settings\admin-su\Desktop\Convert Doc.lnk
[2012/03/11 15:13:51 | 003,203,072 | ---- | C] () -- C:\WINDOWS\System32\beconvlib.dll
[2012/03/11 15:13:51 | 000,385,119 | ---- | C] () -- C:\WINDOWS\System32\english.dic
[2012/03/11 15:13:51 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\bprgcomm.dll
[2012/03/11 15:13:51 | 000,102,400 | ---- | C] ( ) -- C:\WINDOWS\System32\bclnap.dll
[2012/03/11 15:13:51 | 000,006,728 | ---- | C] () -- C:\WINDOWS\System32\easyconverter.rsc
[2012/03/11 15:13:50 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\CSVSpecialProcessing.dll
[2012/03/11 15:13:50 | 000,000,530 | ---- | C] () -- C:\WINDOWS\System32\tx16_ic.ini
[2012/03/11 15:13:49 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\SII_PDF.dll
[2012/03/11 15:13:49 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\SARzilla.dll
[2012/03/11 15:13:49 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\DVM.dll
[2012/03/11 15:13:49 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\RegisterExe.exe
[2012/03/10 22:05:34 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2012/03/10 22:05:31 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012/03/10 22:05:30 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2012/03/10 22:05:30 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2012/03/10 22:05:29 | 000,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2012/03/10 22:05:29 | 000,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2012/03/10 22:05:16 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2012/03/10 22:05:10 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2012/03/10 22:05:10 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2012/03/10 22:05:10 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2012/03/10 22:05:10 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2012/03/10 22:05:10 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2012/03/10 22:05:10 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2012/03/10 22:04:42 | 000,161,936 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/10 22:03:53 | 000,000,211 | RHS- | C] () -- C:\boot.ini
[2012/03/10 22:03:51 | 000,000,386 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2012/03/10 19:41:25 | 000,002,309 | ---- | C] () -- C:\Documents and Settings\admin-su\Desktop\Google Chrome.lnk
[2012/03/10 19:41:25 | 000,002,287 | ---- | C] () -- C:\Documents and Settings\admin-su\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/03/10 19:30:29 | 000,000,990 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1715567821-725345543-1004UA.job
[2012/03/10 19:30:29 | 000,000,938 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1715567821-725345543-1004Core.job
[2012/03/10 17:50:15 | 000,001,924 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
[2012/03/10 17:42:29 | 000,000,828 | ---- | C] () -- C:\Documents and Settings\admin-su\Desktop\EXCEL.lnk
[2012/03/10 17:42:13 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\admin-su\Desktop\WORD.lnk
[2012/03/10 17:37:29 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012/03/10 17:37:03 | 000,002,030 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Excel.lnk
[2012/03/10 17:37:03 | 000,002,022 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Word.lnk
[2012/03/10 17:37:03 | 000,001,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2012/03/10 16:26:25 | 000,006,656 | ---- | C] () -- C:\Documents and Settings\admin-su\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/10 13:26:55 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/03/10 13:26:55 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/03/10 13:09:41 | 000,013,646 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak
[2012/03/10 13:05:40 | 000,000,790 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\3 MobileBroadband.lnk
[2012/03/10 12:58:16 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2012/03/10 12:58:16 | 000,000,731 | ---- | C] () -- C:\Documents and Settings\admin-su\Desktop\ZoneAlarm Security.lnk
[2012/03/10 12:58:06 | 000,420,800 | ---- | C] () -- C:\WINDOWS\System32\vsconfig.xml
[2012/03/10 12:55:35 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira Control Center.lnk
[2012/03/10 12:52:30 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2012/03/10 12:46:02 | 000,010,457 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.hta
[2012/03/10 12:46:02 | 000,001,771 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.css
[2012/03/10 12:46:02 | 000,000,855 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpocm.inf
[2012/03/10 12:46:01 | 000,613,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.chm
[2012/03/10 12:46:01 | 000,354,468 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud1.wav
[2012/03/10 12:46:01 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud7.wav
[2012/03/10 12:46:01 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud6.wav
[2012/03/10 12:46:01 | 000,300,969 | ---- | C] () -- C:\WINDOWS\System32\dllcache\viz.wmv
[2012/03/10 12:46:01 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud9.wav
[2012/03/10 12:46:01 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud8.wav
[2012/03/10 12:46:01 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud3.wav
[2012/03/10 12:46:01 | 000,086,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud5.wav
[2012/03/10 12:46:01 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud4.wav
[2012/03/10 12:46:01 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud2.wav
[2012/03/10 12:46:01 | 000,067,374 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.adm
[2012/03/10 12:46:01 | 000,029,070 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmp.inf
[2012/03/10 12:46:01 | 000,023,195 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplay.chm
[2012/03/10 12:46:01 | 000,017,489 | ---- | C] () -- C:\WINDOWS\System32\dllcache\videobg.gif
[2012/03/10 12:46:01 | 000,017,272 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmdm.inf
[2012/03/10 12:46:01 | 000,008,677 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm7.gif
[2012/03/10 12:46:01 | 000,007,892 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm9.gif
[2012/03/10 12:46:01 | 000,007,636 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm2.gif
[2012/03/10 12:46:01 | 000,007,369 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm4.gif
[2012/03/10 12:46:01 | 000,006,769 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmfsdk.inf
[2012/03/10 12:46:01 | 000,006,241 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm3.gif
[2012/03/10 12:46:01 | 000,006,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm6.gif
[2012/03/10 12:46:01 | 000,005,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm1.gif
[2012/03/10 12:46:01 | 000,005,290 | ---- | C] () -- C:\WINDOWS\System32\dllcache\vidsamp.gif
[2012/03/10 12:46:01 | 000,004,193 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm8.gif
[2012/03/10 12:46:01 | 000,002,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm5.gif
[2012/03/10 12:46:01 | 000,002,469 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplay.gif
[2012/03/10 12:46:01 | 000,002,450 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpause.gif
[2012/03/10 12:46:01 | 000,002,375 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplayh.gif
[2012/03/10 12:46:01 | 000,002,371 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpauseh.gif
[2012/03/10 12:46:01 | 000,000,420 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmploc.js
[2012/03/10 12:46:00 | 000,572,557 | ---- | C] () -- C:\WINDOWS\System32\dllcache\rtuner.wmv
[2012/03/10 12:46:00 | 000,375,519 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nuskin.wmv
[2012/03/10 12:46:00 | 000,077,307 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plyr_err.chm
[2012/03/10 12:46:00 | 000,066,725 | ---- | C] () -- C:\WINDOWS\System32\dllcache\revert.wmz
[2012/03/10 12:46:00 | 000,023,829 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tourbg.gif
[2012/03/10 12:46:00 | 000,022,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npds.zip
[2012/03/10 12:46:00 | 000,018,286 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.inf
[2012/03/10 12:46:00 | 000,003,187 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tour.js
[2012/03/10 12:46:00 | 000,002,778 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogoh.gif
[2012/03/10 12:46:00 | 000,002,545 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogo.gif
[2012/03/10 12:46:00 | 000,001,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst6.wpl
[2012/03/10 12:46:00 | 000,001,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst5.wpl
[2012/03/10 12:46:00 | 000,001,474 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst3.wpl
[2012/03/10 12:46:00 | 000,001,451 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst12.wpl
[2012/03/10 12:46:00 | 000,001,448 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst4.wpl
[2012/03/10 12:46:00 | 000,001,398 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taon.gif
[2012/03/10 12:46:00 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taonh.gif
[2012/03/10 12:46:00 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoff.gif
[2012/03/10 12:46:00 | 000,001,367 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoffh.gif
[2012/03/10 12:46:00 | 000,001,250 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst1.wpl
[2012/03/10 12:46:00 | 000,001,148 | ---- | C] () -- C:\WINDOWS\System32\dllcache\snd.htm
[2012/03/10 12:46:00 | 000,001,049 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst2.wpl
[2012/03/10 12:46:00 | 000,001,046 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst7.wpl
[2012/03/10 12:46:00 | 000,001,036 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst8.wpl
[2012/03/10 12:46:00 | 000,000,908 | ---- | C] () -- C:\WINDOWS\System32\dllcache\skins.inf
[2012/03/10 12:46:00 | 000,000,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst11.wpl
[2012/03/10 12:46:00 | 000,000,787 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst10.wpl
[2012/03/10 12:46:00 | 000,000,784 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst9.wpl
[2012/03/10 12:46:00 | 000,000,783 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst13.wpl
[2012/03/10 12:46:00 | 000,000,775 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst14.wpl
[2012/03/10 12:46:00 | 000,000,733 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst15.wpl
[2012/03/10 12:46:00 | 000,000,403 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npdrmv2.zip
[2012/03/10 12:45:59 | 000,457,607 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mdlib.wmv
[2012/03/10 12:45:59 | 000,381,425 | ---- | C] () -- C:\WINDOWS\System32\dllcache\copycd.wmv
[2012/03/10 12:45:59 | 000,184,959 | ---- | C] () -- C:\WINDOWS\System32\dllcache\compact.wmz
[2012/03/10 12:45:59 | 000,009,585 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.css
[2012/03/10 12:45:59 | 000,008,298 | ---- | C] () -- C:\WINDOWS\System32\dllcache\contents.htm
[2012/03/10 12:45:59 | 000,006,878 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.js
[2012/03/10 12:45:59 | 000,005,971 | ---- | C] () -- C:\WINDOWS\System32\dllcache\events.js
[2012/03/10 12:45:59 | 000,000,999 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bktrh.gif
[2012/03/10 12:45:59 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnth.gif
[2012/03/10 12:45:59 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnt.gif
[2012/03/10 12:45:59 | 000,000,772 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cntd.gif
[2012/03/10 12:45:59 | 000,000,760 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapph.gif
[2012/03/10 12:45:59 | 000,000,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapp.gif
[2012/03/10 12:45:50 | 000,118,272 | ---- | C] () -- C:\WINDOWS\System32\mpeg2data.ax
[2012/03/10 12:42:49 | 000,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2012/03/10 12:42:49 | 000,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
[2012/03/10 12:42:48 | 000,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
[2012/03/10 12:36:34 | 083,477,336 | ---- | C] () -- C:\Documents and Settings\admin-su\My Documents\avira_free_antivirus_en.exe
[2012/03/10 12:36:32 | 046,973,440 | ---- | C] () -- C:\Documents and Settings\admin-su\My Documents\zaSetup_92_106_000_en.exe
[2012/03/10 12:35:39 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\admin-su\Desktop\My Computer.lnk
[2012/03/10 12:18:16 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\admin-su\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/03/10 12:18:12 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\admin-su\Start Menu\Programs\Outlook Express.lnk
[2012/03/10 12:18:10 | 000,000,804 | ---- | C] () -- C:\Documents and Settings\admin-su\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/03/10 12:18:07 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\admin-su\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/03/10 12:18:07 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\admin-su\Start Menu\Programs\Internet Explorer.lnk
[2012/03/10 12:18:03 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\admin-su\Start Menu\Programs\Remote Assistance.lnk
[2012/03/10 12:18:03 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\admin-su\Start Menu\Programs\Windows Media Player.lnk
[2012/03/10 12:15:47 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2012/03/10 12:15:01 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012/03/10 12:14:33 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2012/03/10 12:14:18 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2012/03/10 12:14:12 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2012/03/10 12:14:11 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2012/03/10 12:14:10 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2012/03/10 12:14:03 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2012/03/10 12:13:59 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2012/03/10 12:13:49 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2012/03/10 12:13:23 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/03/10 12:13:23 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2012/03/10 12:13:23 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2012/03/10 12:13:23 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2012/03/10 12:13:23 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2012/03/10 12:13:21 | 000,025,065 | ---- | C] () -- C:\WINDOWS\System32\wmpscheme.xml
[2012/03/10 12:13:21 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2012/03/10 12:13:21 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2012/03/10 12:13:20 | 000,299,552 | ---- | C] () -- C:\WINDOWS\WMSysPrx.prx
[2012/03/10 12:12:23 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
[2012/03/10 12:11:55 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2012/03/10 12:11:55 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2012/03/10 12:11:50 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2012/03/10 12:11:23 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012/03/10 12:11:02 | 000,000,829 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2012/03/10 12:11:01 | 000,001,846 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN Explorer.lnk
[2012/03/10 12:10:40 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
[2012/03/10 12:10:40 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
[2012/03/10 12:10:40 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
[2012/03/10 12:10:40 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
[2012/03/10 12:10:40 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
[2012/03/10 12:10:40 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
[2012/03/10 12:10:40 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
[2012/03/10 12:10:40 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
[2012/03/10 12:10:40 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
[2012/03/10 12:10:40 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2012/03/10 12:10:40 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
[2012/03/10 12:10:38 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2012/03/10 12:10:37 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2012/03/10 12:10:36 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2012/03/10 12:10:29 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
========== LOP Check ========== [2012/03/25 15:44:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin-su\Application Data\SumatraPDF
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: EXPLORER.EXE >[2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2003/03/31 22:00:00 | 001,004,032 | ---- | M] (Microsoft Corporation) MD5=A82B28BFC2E4455FE43022A498C0EF0A -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: SVCHOST.EXE >[2003/03/31 22:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) MD5=0F7D9C87B0CE1FA520473119752C6F79 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: USERINIT.EXE >[2008/04/14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
[2003/03/31 22:00:00 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=E931E0A2B8BF0019DB902E98D03662CB -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >[2003/03/31 22:00:00 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /mp /s > < hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command\\: "C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012/03/10 19:21:44 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/12/16 22:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/12/16 22:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/12/16 22:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\MSN Explorer\shell\open\command\\: "C:\Program Files\MSN\MSNCoreFiles\MSN6.EXE" [2003/03/31 22:00:00 | 000,094,208 | ---- | M] (Microsoft Corporation)
< hklm\software\clients\startmenuinternet|command /64 /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\chrome.exe\shell\open\command\\: "C:\Documents and Settings\admin-su\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012/03/10 19:21:44 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/12/16 22:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/12/16 22:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/12/16 22:23:08 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\MSN Explorer\shell\open\command\\: "C:\Program Files\MSN\MSNCoreFiles\MSN6.EXE" [2003/03/31 22:00:00 | 000,094,208 | ---- | M] (Microsoft Corporation)
< End of report >