Thanks for the help, Doug
Can you tell me what you found wrong?
OTL logfile created on: 5/10/2012 9:18:14 AM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
495.00 Mb Total Physical Memory | 308.00 Mb Available Physical Memory | 62.00% Memory free
395.00 Mb Paging File | 334.00 Mb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 89.85 Gb Free Space | 80.38% Space Free | Partition Type: NTFS
Drive D: | 123.75 Mb Total Space | 117.94 Mb Free Space | 95.30% Space Free | Partition Type: FAT32
Drive X: | 284.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand] -- -- (AppMgmt)
SRV - [2012/03/26 18:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2011/09/13 10:38:53 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2005/09/11 17:21:52 | 000,065,536 | ---- | M] (New Boundary Technologies, Inc.) [Auto] -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS -- (PrismXL)
SRV - [2004/03/18 20:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (USBSANDIS)
DRV - File not found [Kernel | On_Demand] -- -- (UsbSADObex)
DRV - File not found [Kernel | On_Demand] -- -- (USBSADModem)
DRV - File not found [Kernel | On_Demand] -- -- (UsbSADDiag)
DRV - File not found [Kernel | On_Demand] -- -- (PORTMON)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | On_Demand] -- -- (PCTINDIS5)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand] -- -- (lgcpo)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand] -- -- (ddxgb)
DRV - File not found [Kernel | On_Demand] -- -- (cpuz135)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - File not found [Kernel | On_Demand] -- -- (cdc_ecm)
DRV - [2012/05/06 08:10:53 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/09/13 10:38:50 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/09/13 10:38:50 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2008/12/04 09:17:15 | 000,627,072 | R--- | M] (Ralink Technology, Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WUSB54GCv3.sys -- (WUSB54GCv3)
DRV - [2008/09/04 17:03:54 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\PCASp50.sys -- (PCASp50)
DRV - [2008/08/22 13:05:42 | 000,026,760 | R--- | M] () [Kernel | On_Demand] -- C:\WINDOWS\System32\drivers\swmsflt.sys -- (swmsflt)
DRV - [2008/04/14 01:26:50 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2004/10/07 21:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/08/04 01:31:32 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/07/14 16:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2002/01/11 10:54:54 | 000,047,616 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\Haspnt.sys -- (Haspnt)
DRV - [2001/08/17 09:28:00 | 000,871,388 | ---- | M] (BCM) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\BCMDM.sys -- (BCMModem)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\1_john_smith_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKU\1_john_smith_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\1_john_smith_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.co...ie=utf8&oe=utf8IE - HKU\1_john_smith_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKU\1_john_smith_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\Administrator.JOHN-RJB6SXQFOI_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Guest_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Lazer_Graphics_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\Lazer_Graphics_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Restore =
http://www.yahoo.comIE - HKU\Lazer_Graphics_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Lazer_Graphics_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\Lazer_Graphics_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =
IE - HKU\LocalService.NT_AUTHORITY_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\NetworkService.NT_AUTHORITY_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@DailyBibleGuide.com/Plugin: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\
[email protected]: C:\Program Files\DailyBibleGuide\bar\1.bin [2012/02/26 12:42:18 | 000,000,000 | ---D | M]
Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (US Job Search Toolbar) - {f409caa5-db4f-48aa-a238-ca307c481237} - C:\Program Files\usjobsearchtoolbar\vmntemplateX.dll ()
O3 - HKLM\..\Toolbar: (US Job Search Toolbar) - {f409caa5-db4f-48aa-a238-ca307c481237} - C:\Program Files\usjobsearchtoolbar\vmntemplateX.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Lexmark 3100 Series] C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [LXBRKsk] C:\Program Files\Lexmark 3100 Series\lxbrksk.exe ( )
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SpySpotter System Defender] File not found
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0000.1082\en-us\bin\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\1_john_smith_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\1_john_smith_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 08 00 00 00 [binary data]
O7 - HKU\Administrator.JOHN-RJB6SXQFOI_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Guest_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Lazer_Graphics_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Lazer_Graphics_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = [binary data]
O7 - HKU\LocalService.NT_AUTHORITY_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService.NT_AUTHORITY_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_26.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://active.macrom...tor/cabs/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.mi...b?1310159303093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0}
http://download.spys...rcabinstall.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\javascript\Software - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/11 17:08:30 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ========== [2012/05/10 08:05:30 | 002,237,440 | R--- | C] (OldTimer Tools) -- C:\OTLPE.exe
[2012/05/10 08:05:26 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/05/09 17:32:37 | 000,077,568 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\ati.sys
[2012/05/09 17:32:36 | 000,097,354 | ---- | C] (Bay Networks, Inc.) -- C:\WINDOWS\System32\dllcache\aspndis3.sys
[2012/05/09 17:32:36 | 000,096,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ati.dll
[2012/05/09 17:32:35 | 000,026,496 | ---- | C] (Advanced System Products, Inc.) -- C:\WINDOWS\System32\dllcache\asc.sys
[2012/05/09 17:32:35 | 000,022,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asc3350p.sys
[2012/05/09 17:32:35 | 000,014,848 | ---- | C] (Advanced System Products, Inc.) -- C:\WINDOWS\System32\dllcache\asc3550.sys
[2012/05/09 17:32:27 | 000,036,224 | ---- | C] (ADMtek Incorporated.) -- C:\WINDOWS\System32\dllcache\an983.sys
[2012/05/09 17:32:27 | 000,006,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\apmbatt.sys
[2012/05/09 17:32:26 | 000,016,969 | ---- | C] (AmbiCom, Inc.) -- C:\WINDOWS\System32\dllcache\amb8002.sys
[2012/05/09 17:32:26 | 000,012,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\amsint.sys
[2012/05/09 17:32:25 | 000,027,678 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\ali5261.sys
[2012/05/09 17:32:25 | 000,026,624 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\alifir.sys
[2012/05/09 17:32:25 | 000,005,248 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\aliide.sys
[2012/05/09 17:32:24 | 000,056,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aic78xx.sys
[2012/05/09 17:32:24 | 000,055,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aic78u2.sys
[2012/05/09 17:32:23 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aha154x.sys
[2012/05/09 17:32:18 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agcgauge.ax
[2012/05/09 17:31:47 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adpu160m.sys
[2012/05/09 17:31:46 | 000,046,112 | ---- | C] (Adaptec, Inc ) -- C:\WINDOWS\System32\dllcache\adptsf50.sys
[2012/05/09 17:31:46 | 000,010,880 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\admjoy.sys
[2012/05/09 17:31:45 | 000,747,392 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8830.sys
[2012/05/09 17:31:45 | 000,553,984 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8820.sys
[2012/05/09 17:31:44 | 000,584,448 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8810.sys
[2012/05/09 17:31:44 | 000,020,160 | ---- | C] (ADMtek Incorporated) -- C:\WINDOWS\System32\dllcache\adm8511.sys
[2012/05/09 17:31:44 | 000,007,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adicvls.sys
[2012/05/09 17:31:42 | 000,061,440 | ---- | C] (Color Flatbed Scanner) -- C:\WINDOWS\System32\dllcache\acerscad.dll
[2012/05/09 17:31:41 | 000,297,728 | ---- | C] (Silicon Integrated Systems Corp.) -- C:\WINDOWS\System32\dllcache\ac97sis.sys
[2012/05/09 17:31:41 | 000,084,480 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\ac97via.sys
[2012/05/09 17:31:40 | 000,096,256 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\ac97intc.sys
[2012/05/09 17:31:39 | 000,462,848 | ---- | C] (Aureal Inc.) -- C:\WINDOWS\System32\dllcache\a3dapi.dll
[2012/05/09 17:31:39 | 000,231,552 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\ac97ali.sys
[2012/05/09 17:31:39 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\abp480n5.sys
[2012/05/09 17:31:38 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\8514a.dll
[2012/05/09 17:31:37 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\61883.sys
[2012/05/09 17:31:37 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\4mmdat.sys
[2012/05/09 17:31:36 | 000,148,352 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2012/05/09 17:31:35 | 000,762,780 | ---- | C] (3Com, Inc.) -- C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2012/05/09 17:31:35 | 000,689,216 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2012/05/09 17:31:35 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2012/05/09 17:31:34 | 000,053,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\1394bus.sys
[2012/05/09 17:31:10 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\s3legacy.dll
[2012/05/09 17:30:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012/05/08 20:02:31 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Lazer Graphics\Desktop\OTL.scr
[2012/05/06 08:10:53 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/05/05 22:33:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lazer Graphics\Start Menu\Programs\Revo Uninstaller
[2012/05/05 22:33:58 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2012/05/05 22:33:29 | 000,000,000 | R--D | C] -- C:\Documents and Settings\LocalService.NT AUTHORITY\Favorites
[2012/05/05 22:31:46 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\LocalService.NT AUTHORITY\IETldCache
[2012/05/05 16:13:34 | 000,000,000 | ---D | C] -- C:\NBRT
[2012/05/05 10:00:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\PCHealth
[2012/05/01 20:00:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Application Data\Malwarebytes
[2012/05/01 19:59:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/05/01 19:59:37 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/05/01 19:57:00 | 010,063,000 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\My Documents\mbam-setup-1.61.0.1400.exe
[2012/05/01 19:51:30 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\IECompatCache
[2012/05/01 19:51:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Application Data\Adobe
[2012/05/01 19:50:35 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\IETldCache
[2012/05/01 19:50:10 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Application Data\Microsoft
[2012/05/01 19:50:10 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Application Data
[2012/05/01 19:50:10 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Cookies
[2012/05/01 19:50:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Application Data\Sun
[2012/05/01 19:50:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Application Data\Macromedia
[2012/05/01 19:50:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\SendTo
[2012/05/01 19:50:09 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Start Menu\Programs\Startup
[2012/05/01 19:50:09 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Start Menu
[2012/05/01 19:50:09 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Start Menu\Programs\Accessories
[2012/05/01 19:50:09 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Templates
[2012/05/01 19:50:09 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Recent
[2012/05/01 19:50:09 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\PrintHood
[2012/05/01 19:50:09 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\NetHood
[2012/05/01 19:50:09 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Local Settings
[2012/05/01 19:50:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\My Documents
[2012/05/01 19:50:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Local Settings\Application Data\Microsoft
[2012/05/01 19:50:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Favorites
[2012/05/01 19:50:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Desktop
[2012/05/01 19:43:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2012/05/01 18:21:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lazer Graphics\My Documents\Denny's
[2012/05/01 13:03:23 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012/04/30 10:29:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\Macromedia
[2012/04/30 10:28:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\Adobe
[2012/04/26 18:55:06 | 000,000,000 | -H-D | C] -- C:\Recycl
[2012/04/23 19:28:28 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\NetworkService.NT AUTHORITY\IETldCache
[2012/04/23 19:28:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\NetworkService.NT AUTHORITY\Favorites
[2007/08/11 16:47:24 | 000,118,784 | ---- | C] ( ) -- C:\Program Files\CutStudioPlugin.aip
[2005/11/19 20:05:24 | 000,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\flashshl.dll
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/05/09 17:30:25 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/05/09 17:29:57 | 000,000,023 | ---- | M] () -- C:\WINDOWS\FLASHKSK.INI
[2012/05/09 17:29:47 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/05/09 17:19:18 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{35E7ABF2-0DA8-4115-A68A-32400ED5601E}.job
[2012/05/08 23:00:56 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/05/08 19:54:28 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\Desktop\1mxbgq6q.exe
[2012/05/08 19:54:08 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\Desktop\2vhzfnmm.exe
[2012/05/08 19:52:24 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lazer Graphics\Desktop\OTL.scr
[2012/05/06 22:49:51 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/05/06 18:31:23 | 092,549,811 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\My Documents\Backup 5-5-2012.zip
[2012/05/06 17:41:36 | 010,402,561 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\My Documents\BLACKHAWK TRUCK.zip
[2012/05/06 08:10:53 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/05/05 22:33:59 | 000,000,917 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\Desktop\Revo Uninstaller.lnk
[2012/05/05 17:23:50 | 085,983,232 | -HS- | M] () -- C:\NBRTPage.sys
[2012/05/05 10:01:06 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/05/05 10:01:04 | 000,001,698 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/05/01 19:59:42 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/01 19:59:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/05/01 19:57:57 | 010,063,000 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\My Documents\mbam-setup-1.61.0.1400.exe
[2012/05/01 19:45:43 | 000,000,302 | RHS- | M] () -- C:\boot.ini
[2012/05/01 18:24:53 | 000,000,030 | ---- | M] () -- C:\WINDOWS\Iedit.INI
[2012/05/01 12:51:07 | 000,140,488 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\My Documents\benson.cst
[2012/04/26 17:14:31 | 000,038,204 | ---- | M] () -- C:\a1ba.reg
[2012/04/26 17:14:31 | 000,014,752 | ---- | M] () -- C:\a2ba.reg
[2012/04/25 19:23:03 | 000,091,915 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\My Documents\hOWE TRAILERS 1.cst
[2012/04/25 17:03:59 | 000,002,347 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Adobe Reader X.lnk
[2012/04/20 18:56:17 | 000,429,207 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\My Documents\blake vangsness.cst
[2012/04/18 11:02:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/04/12 04:11:09 | 000,444,494 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/04/12 04:11:09 | 000,072,370 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/04/12 04:03:05 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/04/10 23:50:58 | 001,036,907 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\My Documents\Howe Jason.cst
[2012/04/10 22:07:18 | 000,292,693 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\My Documents\lazer custom graphics race car.cst
[2012/04/10 22:02:41 | 000,129,076 | ---- | M] () -- C:\Documents and Settings\Lazer Graphics\My Documents\karate guy 1.cst
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/05/08 22:41:23 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Lazer Graphics\Desktop\1mxbgq6q.exe
[2012/05/08 22:41:20 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Lazer Graphics\Desktop\2vhzfnmm.exe
[2012/05/06 17:41:27 | 010,402,561 | ---- | C] () -- C:\Documents and Settings\Lazer Graphics\My Documents\BLACKHAWK TRUCK.zip
[2012/05/06 17:40:43 | 092,549,811 | ---- | C] () -- C:\Documents and Settings\Lazer Graphics\My Documents\Backup 5-5-2012.zip
[2012/05/05 22:33:59 | 000,000,917 | ---- | C] () -- C:\Documents and Settings\Lazer Graphics\Desktop\Revo Uninstaller.lnk
[2012/05/05 16:13:33 | 085,983,232 | -HS- | C] () -- C:\NBRTPage.sys
[2012/05/05 10:27:55 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/05/05 10:01:04 | 000,001,698 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/05/01 19:59:42 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/01 19:50:10 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Start Menu\Programs\Remote Assistance.lnk
[2012/05/01 19:50:10 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Administrator.JOHN-RJB6SXQFOI\Start Menu\Programs\Windows Media Player.lnk
[2012/04/26 17:14:30 | 000,038,204 | ---- | C] () -- C:\a1ba.reg
[2012/04/26 17:14:30 | 000,014,752 | ---- | C] () -- C:\a2ba.reg
[2012/03/30 13:39:38 | 000,130,228 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/07/14 19:46:44 | 000,000,848 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2010/07/27 15:21:09 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Lazer Graphics\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/02 18:00:48 | 000,026,760 | R--- | C] () -- C:\WINDOWS\System32\drivers\swmsflt.sys
[2007/12/07 22:20:38 | 000,000,814 | ---- | C] () -- C:\WINDOWS\EReg077.dat
[2007/12/07 22:20:18 | 000,001,671 | ---- | C] () -- C:\WINDOWS\Powerup.ini
[2007/08/11 16:47:36 | 000,017,426 | ---- | C] () -- C:\Program Files\CutStudioPlugIn.gms
[2007/08/11 16:47:36 | 000,000,384 | ---- | C] () -- C:\Program Files\CutStudioPlugIn.bmp
[2007/08/11 16:47:24 | 000,066,053 | ---- | C] () -- C:\Program Files\CSAIPin_e.chm
[2007/02/18 23:32:24 | 000,000,030 | ---- | C] () -- C:\WINDOWS\Iedit.INI
[2006/09/10 19:35:22 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/09/08 21:29:05 | 000,004,413 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\QTSBandwidthCache
[2005/11/28 23:45:27 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2005/11/28 23:43:14 | 000,000,028 | ---- | C] () -- C:\WINDOWS\atid.ini
[2005/11/19 20:05:24 | 000,000,023 | ---- | C] () -- C:\WINDOWS\FLASHKSK.INI
[2005/11/19 20:05:23 | 000,003,206 | ---- | C] () -- C:\WINDOWS\LXBRCAH.ini
[2005/11/19 20:05:23 | 000,000,468 | ---- | C] () -- C:\WINDOWS\LXBRFMT.INI
[2005/11/19 20:05:22 | 000,021,504 | ---- | C] () -- C:\WINDOWS\LXBRSET.EXE
[2005/11/19 20:05:22 | 000,004,608 | ---- | C] () -- C:\WINDOWS\DelShell.exe
[2005/11/19 20:05:20 | 000,002,178 | ---- | C] () -- C:\WINDOWS\System32\LXBRSET.INI
[2005/11/19 20:01:49 | 000,000,462 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2005/11/19 20:00:31 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxbrvs.dll
[2005/11/19 20:00:04 | 000,000,181 | ---- | C] () -- C:\WINDOWS\System32\lxbrcoin.ini
[2005/11/11 18:08:09 | 000,000,097 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2005/11/11 17:57:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2005/11/04 21:21:02 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2005/10/19 23:07:11 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2005/10/19 22:57:09 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/09/11 18:07:30 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2005/09/11 17:24:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/09/11 17:05:25 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/09/11 09:54:31 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/09/11 09:53:00 | 001,031,168 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/04/15 09:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2003/04/15 09:00:00 | 000,005,114 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2003/03/31 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2003/03/31 08:00:00 | 000,444,494 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2003/03/31 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2003/03/31 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2003/03/31 08:00:00 | 000,072,370 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2003/03/31 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2003/03/31 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2003/03/31 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2003/03/31 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/01/07 18:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/04/30 08:46:24 | 000,015,312 | R--- | C] () -- C:\WINDOWS\System32\RaCoInst.dat
[2002/01/11 10:54:54 | 000,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2002/01/03 21:50:39 | 000,000,137 | ---- | C] () -- C:\Documents and Settings\Lazer Graphics\Local Settings\Application Data\fusioncache.dat
[2002/01/02 21:00:12 | 000,104,292 | ---- | C] () -- C:\WINDOWS\hpoins04.dat
[2002/01/02 21:00:12 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat
[1997/06/13 22:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ========== [2007/02/18 23:29:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\1 john smith\Application Data\Ulead Systems
[2010/07/02 18:01:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lazer Graphics\Application Data\AT&T
[2011/07/08 16:07:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lazer Graphics\Application Data\Auslogics
[2010/07/27 16:03:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lazer Graphics\Application Data\Bytemobile
[2010/07/27 15:27:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lazer Graphics\Application Data\DBUpdater
[2011/08/29 22:21:33 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Lazer Graphics\Application Data\Home Safety Essentials
[2010/07/02 18:00:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lazer Graphics\Application Data\Sierra Wireless
[2007/08/31 22:25:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lazer Graphics\Application Data\Ulead Systems
[2011/08/23 09:03:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lazer Graphics\Application Data\usjobsearchtoolbar
[2011/08/15 18:46:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lazer Graphics\Application Data\vmntemplate
[2010/07/02 18:01:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\Bytemobile
[2010/07/02 18:04:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\Bytemobile
[2011/09/23 16:50:16 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\86bd12
[2010/07/28 17:58:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\AT&T
[2007/08/12 17:35:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Broderbund LLC
[2007/08/12 17:34:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Broderbund Software
[2011/08/23 23:26:29 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\HSMAIAE
[2012/01/22 12:00:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\kalu
[2007/08/12 17:35:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Riverdeep Interactive Learning Limited
[2007/06/14 01:23:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Roland DG Corporation
[2007/02/18 23:22:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ulead Systems
[2005/11/28 23:46:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
[2011/09/14 11:16:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/05/09 17:19:18 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{35E7ABF2-0DA8-4115-A68A-32400ED5601E}.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe >[2011/07/12 22:55:05 | 002,237,440 | R--- | M] (OldTimer Tools) -- C:\OTLPE.exe
< MD5 for: ACPI.IN_ >[2003/03/31 07:00:00 | 000,001,377 | ---- | M] () MD5=75254860AED9FF9A67C5A0E4F22C66A7 -- C:\I386\ACPI.IN_
< MD5 for: ACPI.INF >[2003/03/31 08:00:00 | 000,004,727 | ---- | M] () MD5=51FE7D176D893D40FE7A4036B2D9C982 -- C:\WINDOWS\inf\acpi.inf
[2003/03/31 08:00:00 | 000,004,727 | ---- | M] () MD5=51FE7D176D893D40FE7A4036B2D9C982 -- C:\WINDOWS\ServicePackFiles\i386\acpi.inf
[2003/03/31 08:00:00 | 000,004,727 | ---- | M] () MD5=51FE7D176D893D40FE7A4036B2D9C982 -- C:\WINNT\inf\acpi.inf
< MD5 for: ACPI.PNF >[2005/10/16 02:08:53 | 000,012,512 | ---- | M] () MD5=5920141B9E3B57B4F3B5CEBD680BE907 -- C:\WINDOWS\inf\acpi.PNF
[2003/10/06 16:03:26 | 000,012,488 | ---- | M] () MD5=C9AF0AEA22D5CAD0A5197866941F0F36 -- C:\WINNT\inf\acpi.PNF
< MD5 for: ACPI.SY_ >[2003/03/31 07:00:00 | 000,091,571 | ---- | M] () MD5=BC9B3904AB09EA8AB9AB5E44FE6E292C -- C:\I386\ACPI.SY_
< MD5 for: ACPI.SYS >[2008/04/14 01:06:36 | 000,187,776 | ---- | M] (Microsoft Corporation) MD5=8FD99680A539792A30E97944FDAECF17 -- C:\WINDOWS\ServicePackFiles\i386\acpi.sys
[2008/04/14 01:06:36 | 000,187,776 | ---- | M] (Microsoft Corporation) MD5=8FD99680A539792A30E97944FDAECF17 -- C:\WINDOWS\system32\dllcache\acpi.sys
[2003/03/31 08:00:00 | 000,179,328 | ---- | M] (Microsoft Corporation) MD5=94DDD4B3ACBD7A9558E1762CD58386F9 -- C:\WINNT\system32\drivers\acpi.sys
[2004/08/04 02:07:38 | 000,187,776 | ---- | M] (Microsoft Corporation) MD5=A10C7534F7223F4A73A948967D00E69B -- C:\WINDOWS\$NtServicePackUninstall$\acpi.sys
[2008/04/14 01:06:36 | 000,187,776 | ---- | M] (Microsoft Corporation) MD5=D8FB7D1C3F5BFA3F53FE9CC6367E9E99 -- C:\WINDOWS\system32\drivers\acpi.sys
< MD5 for: EXPLORER.EXE >[2008/04/14 06:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/14 06:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/14 06:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
[2004/08/04 03:56:49 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2003/03/31 08:00:00 | 001,004,032 | ---- | M] (Microsoft Corporation) MD5=A82B28BFC2E4455FE43022A498C0EF0A -- C:\WINNT\explorer.exe
< MD5 for: SVCHOST.EXE >[2012/04/04 16:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2003/03/31 08:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) MD5=0F7D9C87B0CE1FA520473119752C6F79 -- C:\WINNT\system32\svchost.exe
[2008/04/14 06:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 06:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\svchost.exe
[2008/04/14 06:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2004/08/04 03:56:57 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: USERINIT.EXE >[2004/08/04 03:56:57 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 06:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 06:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
[2003/03/31 08:00:00 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=E931E0A2B8BF0019DB902E98D03662CB -- C:\WINNT\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2004/08/04 03:56:57 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/04/04 16:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2003/03/31 07:00:00 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB -- C:\WINNT\$NtUninstallQ814696$\winlogon.exe
[2003/03/31 08:00:00 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB -- C:\WINNT\system32\winlogon.exe
[2004/05/26 21:38:46 | 000,483,328 | ---- | M] (Microsoft Corporation) MD5=E7F9D2E4E4A94A6F58014E5FFA16A65E -- C:\WINNT\SoftwareDistribution\Download\0bfb0fd6d1529228f4175fc177388244\sp1qfe\winlogon.exe
[2008/04/14 06:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 06:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe
[2008/04/14 06:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 06:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WMIPRVSE.EX_ >[2003/03/31 07:00:00 | 000,064,751 | ---- | M] () MD5=AB3145059C2658FFD8A46A64B1471ED4 -- C:\I386\WMIPRVSE.EX_
< MD5 for: WMIPRVSE.EXE >[2004/08/04 03:56:57 | 000,218,112 | ---- | M] (Microsoft Corporation) MD5=075EA6C849AB0FE416A3D6DD65C3CF41 -- C:\WINDOWS\$NtServicePackUninstall$\wmiprvse.exe
[2004/08/04 03:56:57 | 000,218,112 | ---- | M] (Microsoft Corporation) MD5=075EA6C849AB0FE416A3D6DD65C3CF41 -- C:\WINNT\system32\wbem\wmiprvse.exe
[2008/04/14 06:42:42 | 000,218,112 | ---- | M] (Microsoft Corporation) MD5=0FFAE66E6D5B1C87CBD22D1F3B6079FD -- C:\WINDOWS\$NtUninstallKB956572$\wmiprvse.exe
[2008/04/14 06:42:42 | 000,218,112 | ---- | M] (Microsoft Corporation) MD5=0FFAE66E6D5B1C87CBD22D1F3B6079FD -- C:\WINDOWS\ServicePackFiles\i386\wmiprvse.exe
[2008/04/14 06:42:42 | 000,218,112 | ---- | M] (Microsoft Corporation) MD5=0FFAE66E6D5B1C87CBD22D1F3B6079FD -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\wmiprvse.exe
[2009/02/06 06:10:02 | 000,227,840 | ---- | M] (Microsoft Corporation) MD5=798A9E6828997EEF4517ADA8A2259831 -- C:\WINDOWS\system32\dllcache\wmiprvse.exe
[2009/02/06 06:10:02 | 000,227,840 | ---- | M] (Microsoft Corporation) MD5=798A9E6828997EEF4517ADA8A2259831 -- C:\WINDOWS\system32\wbem\wmiprvse.exe
[2009/02/06 06:15:13 | 000,227,840 | ---- | M] (Microsoft Corporation) MD5=F520AB392D58C0A1070268032D809382 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\wmiprvse.exe
< MD5 for: WMIPRVSE.EXE-28F301A9.PF >[2012/05/09 17:19:19 | 000,057,012 | ---- | M] () MD5=F9894C3AAD1C38AA0019C11B4012A5F5 -- C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf
< %systemroot%\*. /mp /s >< End of report >