Not sure if it will help, but here is a link to the original question: http://www.geekstogo...ed/page__st__30
Now this system was used when I got it, but since it didn't seem to have any problems, I just used it 'as is' without any wipe and reload, and other than general internet, it's not used for much.
IN the process of working with CompCav and OTL and others we managed to get OTL to run, non standard, and discovered there are definite signs of infections, and so I'm posting here for help. This is going to be a learning experience for me as well, and my Geek U teacher is aware of the unusual circumstances. So if you could help me to work thru this without messing it up even worse, I would greatly appreciate it.
Below are the OTL logs and I will add a reply with the extras log to make it easier to review.
Before reading thru them keep in mind that in order to get OTL to run I had to use the following settings in OTL:
Select Scan All Users
Under Services select None
Under Drivers select None
Select Lop Check and Purity Check
Under Extra Registry select Use SafeList
Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Local\AutoProxyCache /s
CREATERESTOREPOINT
OTL logfile created on: 7/23/2012 9:00:31 AM - Run 3
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\John\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.44 Gb Total Physical Memory | 0.98 Gb Available Physical Memory | 68.32% Memory free
1.95 Gb Paging File | 1.55 Gb Available in Paging File | 79.86% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 160.40 Gb Free Space | 86.10% Space Free | Partition Type: NTFS
Computer Name: STANLEY-B78766E | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/07/23 08:52:18 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\John\Desktop\OTL.exe
PRC - [2012/07/04 22:49:03 | 001,028,776 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Charter Security Suite\Anti-Virus\fssm32.exe
PRC - [2012/07/04 22:49:00 | 000,561,832 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32.exe
PRC - [2011/11/30 03:28:49 | 000,135,608 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe
PRC - [2011/08/11 19:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2011/07/12 12:08:14 | 000,018,432 | ---- | M] () -- C:\Documents and Settings\John\Application Data\QuickTime\IE\QuickTimeUpdater.exe
PRC - [2011/05/03 17:56:02 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
PRC - [2009/08/05 11:58:52 | 000,186,976 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Charter Security Suite\Common\FSMA32.EXE
PRC - [2009/08/05 11:58:50 | 000,076,384 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Charter Security Suite\Common\FSLAUNCH.EXE
PRC - [2009/08/05 11:56:10 | 000,215,648 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe
PRC - [2008/08/26 19:02:24 | 000,014,336 | ---- | M] (Agere Systems) -- C:\Program Files\LSI SoftModem\agrsmsvc.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/10/23 08:50:35 | 000,046,640 | R--- | M] (AOL LLC) -- C:\Program Files\Common Files\aol\acs\AOLacsd.exe
PRC - [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
========== Modules (No Company Name) ==========
MOD - [2012/07/04 22:51:34 | 000,030,888 | ---- | M] () -- C:\Program Files\Charter Security Suite\Anti-Virus\minifilter\hashlib_x86.dll
MOD - [2012/06/21 06:11:11 | 011,817,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll
MOD - [2012/06/21 06:08:46 | 012,433,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll
MOD - [2012/06/21 06:08:23 | 001,592,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll
MOD - [2012/05/10 03:14:01 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\92d58f840f549f9bd880783d43db7e3c\System.Runtime.Remoting.ni.dll
MOD - [2012/05/10 03:13:34 | 000,025,600 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\016444dfc5f7e3d11c776f2fbc7a4594\Accessibility.ni.dll
MOD - [2012/05/10 03:07:57 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012/05/10 03:07:36 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2011/11/03 11:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2011/07/12 12:08:26 | 000,223,232 | ---- | M] () -- C:\Documents and Settings\John\Application Data\QuickTime\IE\sqlite3.dll
MOD - [2011/07/12 12:08:14 | 000,018,432 | ---- | M] () -- C:\Documents and Settings\John\Application Data\QuickTime\IE\QuickTimeUpdater.exe
MOD - [2009/08/05 11:59:08 | 000,199,264 | ---- | M] () -- C:\Program Files\Charter Security Suite\Spam Control\fsas.dll
MOD - [2009/08/05 11:58:30 | 000,330,336 | ---- | M] () -- \\?\c:\program files\charter security suite\hips\fshook32.dll
MOD - [2009/08/05 11:58:30 | 000,236,128 | ---- | M] () -- \\?\c:\program files\charter security suite\hips\fsumi.dll
MOD - [2009/05/26 09:48:24 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3309.28601__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2009/05/26 09:48:24 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3309.28603__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2009/05/26 09:48:24 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3309.28626__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2009/05/26 09:48:23 | 000,073,728 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3309.28604__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2009/05/26 09:48:21 | 000,106,496 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3343.28330__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2009/05/26 09:48:21 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3343.28328__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2009/05/26 09:48:21 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3309.28614__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2009/05/26 09:48:21 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3309.28626__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2009/05/26 09:48:21 | 000,014,848 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll
MOD - [2009/05/26 09:48:21 | 000,013,312 | ---- | M] () -- C:\WINDOWS\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll
MOD - [2009/05/26 09:48:20 | 000,057,344 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3343.28199__90ba9c70f846762e\CLI.Component.SkinFactory.dll
MOD - [2009/05/26 09:48:19 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3343.28329__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2008/04/13 20:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 20:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2004/08/10 08:00:00 | 000,268,288 | ---- | M] () -- C:\WINDOWS\system32\sbe.dll
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://search.aol.co...e=tb50TB50CLie7
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-220523388-1647877149-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-220523388-1647877149-725345543-1003\..\SearchScopes,DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKU\S-1-5-21-220523388-1647877149-725345543-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKU\S-1-5-21-220523388-1647877149-725345543-1003\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://search.aol.co...e=tb50TB50CLie7
IE - HKU\S-1-5-21-220523388-1647877149-725345543-1003\..\SearchScopes\{FD9D2D24-074E-46F5-93AB-EBA56AF0962F}: "URL" = http://www.google.co...age={startPage}
IE - HKU\S-1-5-21-220523388-1647877149-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2009/07/15 17:43:07 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Charter Security Suite\NRS\[email protected] [2012/07/04 22:55:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
O1 HOSTS File: ([2012/06/25 14:39:13 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\Charter Security Suite\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O2 - BHO: (QuickTime) - {D26AE2EA-3F14-42DF-AC75-14380C4ACFD0} - C:\Documents and Settings\John\Application Data\QuickTime\IE\QuickTime.dll (Apple Inc.)
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\Charter Security Suite\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\Charter Security Suite\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files\Charter Security Suite\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-220523388-1647877149-725345543-1003..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-220523388-1647877149-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-220523388-1647877149-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-220523388-1647877149-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-220523388-1647877149-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O15 - HKU\S-1-5-21-220523388-1647877149-725345543-1003\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKU\S-1-5-21-220523388-1647877149-725345543-1003\..Trusted Domains: com.tw ([asia.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-220523388-1647877149-725345543-1003\..Trusted Domains: com.tw ([global.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-220523388-1647877149-725345543-1003\..Trusted Domains: com.tw ([www.msi] http in Trusted sites)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1340811782687 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} http://liveupdate.ms...ine/install.cab (WebSDev Control)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.h...nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ADE2205F-57FA-4CD3-8DB4-99DA7343A9B4}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/22 15:11:43 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: xmlprov - %SystemRoot%\System32\xmlprov.dll File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/07/23 08:52:17 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\John\Desktop\OTL.exe
[2012/07/17 15:48:10 | 000,000,000 | ---D | C] -- C:\FRST
[2012/07/13 15:04:42 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\John\Desktop\dds.exe
[2012/07/04 22:46:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Application Data\f-secure
[2012/07/04 22:43:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Charter Security Suite
[2012/07/04 22:37:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\F-Secure
[2012/07/04 22:35:31 | 000,080,000 | ---- | C] (F-Secure Corporation) -- C:\WINDOWS\System32\drivers\fsdfw.sys
[2012/07/04 22:31:24 | 000,000,000 | ---D | C] -- C:\Program Files\Charter Security Suite
[2012/07/04 22:28:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\fssg
[2012/07/04 22:25:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\f-secure
[2012/07/04 21:30:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Malwarebytes
[2012/07/04 21:29:12 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/06/27 12:05:52 | 000,426,184 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/06/25 14:51:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012/06/25 14:12:52 | 000,000,000 | RHSD | C] -- C:\cmdcons
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/23 08:52:18 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\John\Desktop\OTL.exe
[2012/07/20 17:57:40 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/07/20 17:57:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/07/20 17:57:07 | 000,185,816 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/07/20 16:55:44 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/07/13 15:06:20 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\John\Desktop\dds.exe
[2012/07/04 22:56:10 | 000,044,184 | ---- | M] () -- C:\WINDOWS\System32\drivers\fsbts.sys
[2012/07/04 22:43:21 | 000,001,976 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Charter Security Suite.lnk
[2012/07/04 22:35:38 | 000,449,122 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/07/04 22:35:37 | 000,075,048 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/07/04 21:38:13 | 000,022,716 | ---- | M] () -- C:\Documents and Settings\John\Application Data\wklnhst.dat
[2012/06/27 12:09:29 | 000,000,494 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Computer Tutor Remote Help.lnk
[2012/06/27 12:07:27 | 000,000,433 | RHS- | M] () -- C:\boot.ini
[2012/06/27 12:05:52 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/06/27 12:05:52 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/06/26 09:07:19 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/06/25 14:39:13 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/04 22:43:21 | 000,001,976 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Charter Security Suite.lnk
[2012/07/04 22:36:50 | 000,044,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\fsbts.sys
[2012/06/27 12:09:29 | 000,000,494 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Computer Tutor Remote Help.lnk
[2012/06/27 11:40:54 | 000,000,361 | ---- | C] () -- C:\Documents and Settings\John\Desktop\Shortcut to My Documents.lnk
[2012/06/27 11:40:27 | 000,037,888 | ---- | C] () -- C:\Documents and Settings\John\Desktop\Juanita Resume.wps
[2012/06/27 11:13:06 | 000,015,360 | ---- | C] () -- C:\Documents and Settings\John\My Documents\Service call Quitting time.wps
[2012/06/27 11:12:52 | 000,009,728 | ---- | C] () -- C:\Documents and Settings\John\My Documents\Quote for Cagle.wps
[2012/06/27 11:12:46 | 000,010,240 | ---- | C] () -- C:\Documents and Settings\John\My Documents\Pam and Randy invoice.wps
[2012/06/27 11:08:22 | 000,010,752 | ---- | C] () -- C:\Documents and Settings\John\My Documents\GCHS spay and neuter.wps
[2012/06/27 11:08:22 | 000,009,728 | ---- | C] () -- C:\Documents and Settings\John\My Documents\GCHS Cond. repair.wps
[2012/06/27 11:07:58 | 000,029,184 | ---- | C] () -- C:\Documents and Settings\John\My Documents\Ellwood Dr invoice.wps
[2012/06/27 11:04:57 | 000,010,752 | ---- | C] () -- C:\Documents and Settings\John\My Documents\#1 Bl Cantwell.wps
[2012/06/27 11:04:56 | 000,011,776 | ---- | C] () -- C:\Documents and Settings\John\My Documents\#% BLCANTWELL.wps
[2012/06/25 14:13:11 | 000,000,317 | ---- | C] () -- C:\Boot.bak
[2012/06/25 14:13:05 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/02/16 01:22:36 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/01/17 16:29:53 | 000,000,065 | ---- | C] () -- C:\WINDOWS\ixiqoyejamiyum.dll
[2011/01/17 04:17:53 | 000,000,065 | ---- | C] () -- C:\WINDOWS\emebebag.dll
[2011/01/16 03:53:53 | 000,000,065 | ---- | C] () -- C:\WINDOWS\oxupuzegixoret.dll
[2011/01/14 05:07:53 | 000,000,065 | ---- | C] () -- C:\WINDOWS\unejasuq.dll
[2011/01/13 20:59:53 | 000,000,065 | ---- | C] () -- C:\WINDOWS\exogebute.dll
[2010/09/27 10:41:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ufujorecewekife.dll
[2010/09/27 08:39:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\aweqemej.dll
[2010/09/27 06:37:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ivufisequpalir.dll
[2010/09/27 04:35:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\amesuzupijaf.dll
[2010/09/27 02:33:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\elogizoyowohow.dll
[2010/09/27 00:31:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ihemuligizoyowoh.dll
[2010/09/26 22:29:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\acoriwitatuxo.dll
[2010/09/26 20:27:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\urofiwuzoza.dll
[2010/09/26 18:25:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\unolifasufoli.dll
[2010/09/26 16:23:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oyerowig.dll
[2010/09/26 14:21:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uxapilidarex.dll
[2010/09/26 12:19:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\evexazivaz.dll
[2010/09/26 10:17:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\onodoleq.dll
[2010/09/26 08:15:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\adevalanah.dll
[2010/09/26 06:13:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oguqewid.dll
[2010/09/26 04:11:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ucecefuhe.dll
[2010/09/26 02:09:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ipohoriqowaqifi.dll
[2010/09/26 00:07:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\onaluwenu.dll
[2010/09/25 22:05:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\amotazet.dll
[2010/09/25 20:03:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oyeyesubasebiwey.dll
[2010/09/25 18:01:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uwonalul.dll
[2010/09/25 15:59:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\igetezezuqujarow.dll
[2010/09/25 13:57:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ezowumifo.dll
[2010/09/25 11:55:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\igitafapititefe.dll
[2010/09/25 09:53:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iqosuwul.dll
[2010/09/25 07:51:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\epabefovahu.dll
[2010/09/25 05:49:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iporesoxiwuv.dll
[2010/09/25 03:47:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\umefulohoqusiw.dll
[2010/09/25 01:45:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eqolevetecof.dll
[2010/09/24 23:43:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ojuwusehih.dll
[2010/09/24 21:41:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ofaqafot.dll
[2010/09/24 19:39:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\azekurub.dll
[2010/09/24 17:37:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\axopexom.dll
[2010/09/24 15:35:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eqasifiziwesi.dll
[2010/09/24 13:33:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oyoqisefac.dll
[2010/09/24 11:31:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\epecazuw.dll
[2010/09/19 09:01:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ugawixanimi.dll
[2010/09/19 06:59:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oxugereciyozo.dll
[2010/09/19 04:57:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\epikidon.dll
[2010/09/19 02:55:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\agevepas.dll
[2010/09/19 00:53:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\usuxidigibavuk.dll
[2010/09/18 22:51:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\useradew.dll
[2010/09/18 20:49:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ipacarez.dll
[2010/09/18 18:47:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\afohixusoyaqoxi.dll
[2010/09/18 16:45:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\equduxox.dll
[2010/09/18 14:43:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ihikikik.dll
[2010/09/18 12:41:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\asagavopiwamikux.dll
[2010/09/18 10:39:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\olikuvayadepir.dll
[2010/09/18 08:37:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uguhadajakucuraq.dll
[2010/09/18 06:35:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\itenipucov.dll
[2010/09/18 04:33:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\awevixipabu.dll
[2010/09/18 02:31:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\areyoxiyalogu.dll
[2010/09/18 00:29:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ufabakezako.dll
[2010/09/17 22:27:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uyagaxeyu.dll
[2010/09/17 20:25:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uxiruvozer.dll
[2010/09/17 18:23:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\otezodulipor.dll
[2010/09/17 16:21:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ihufepov.dll
[2010/09/17 14:19:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ibewopikebeg.dll
[2010/09/17 12:17:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\axakoxevo.dll
[2010/09/17 10:15:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oyivakad.dll
[2010/09/17 08:13:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\urosikuno.dll
[2010/09/17 06:11:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\igiruxec.dll
[2010/09/17 04:09:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\evujodohujeh.dll
[2010/09/17 02:07:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ejequvetidacir.dll
[2010/09/17 00:05:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\itupopeg.dll
[2010/09/16 22:03:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\acejudoyatupek.dll
[2010/09/16 20:01:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ogezakoboxagijo.dll
[2010/09/16 17:59:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ozeceris.dll
[2010/09/16 15:57:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iyupoxaziguquxu.dll
[2010/09/16 13:55:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ipujokilomini.dll
[2010/09/16 11:53:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\udebidovug.dll
[2010/09/16 09:51:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uwanevud.dll
[2010/09/16 07:49:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ajumudivos.dll
[2010/09/16 05:47:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\asuyivoqubub.dll
[2010/09/16 03:45:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\osuwareheguri.dll
[2010/09/16 01:43:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ehizixuqoto.dll
[2010/09/15 23:41:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iqifikaha.dll
[2010/09/15 21:39:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\atiwikisoxe.dll
[2010/09/15 19:37:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ufuxavowiyelukig.dll
[2010/09/15 17:35:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eqalidemawixor.dll
[2010/09/15 15:33:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oruvadazaderirif.dll
[2010/09/15 13:31:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ovafipul.dll
[2010/09/15 11:29:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eqanojow.dll
[2010/09/15 09:27:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\etaruxile.dll
[2010/09/15 07:25:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ukupikep.dll
[2010/09/15 05:23:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\axuxaxed.dll
[2010/09/15 03:21:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\akoyelukig.dll
[2010/09/15 01:29:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ecolarej.dll
[2010/09/14 23:27:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\axirifucipisozoq.dll
[2010/09/14 21:25:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\asezewujonafaz.dll
[2010/09/14 19:23:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\asiqizoqosi.dll
[2010/09/14 17:21:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\umopevog.dll
[2010/09/14 15:19:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uzijilesoqa.dll
[2010/09/14 13:17:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ojedezenocopo.dll
[2010/09/14 11:15:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iqicuwusehihev.dll
[2010/09/14 09:13:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uluhefozujec.dll
[2010/09/14 07:11:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\azanerulat.dll
[2010/09/14 05:09:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ozorawaxozuv.dll
[2010/09/14 03:07:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iheguzel.dll
[2010/09/14 01:05:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\otumilap.dll
[2010/09/13 23:03:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\okuyazada.dll
[2010/09/13 21:01:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ibojazij.dll
[2010/09/13 18:59:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uzizafit.dll
[2010/09/13 16:57:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\utefarip.dll
[2010/09/13 14:55:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oliwaruy.dll
[2010/09/13 12:53:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\obegufag.dll
[2010/09/13 10:51:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\aridalumihu.dll
[2010/09/13 08:49:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\akovolovolovo.dll
[2010/09/13 06:47:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\itefaveleriweso.dll
[2010/09/13 04:45:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\elasuliz.dll
[2010/09/13 02:43:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\arerifad.dll
[2010/09/13 00:41:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ibovuroviloxegir.dll
[2010/09/12 22:39:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\otuxomodoruvoz.dll
[2010/09/12 20:37:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ekidawevevuk.dll
[2010/09/12 18:35:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\axajiliqu.dll
[2010/09/12 16:33:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\osutuzuh.dll
[2010/09/12 14:31:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ugucosaq.dll
[2010/09/12 12:29:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\anoxisigiha.dll
[2010/09/12 10:27:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\itenoweturet.dll
[2010/09/12 08:25:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\icemoxobuz.dll
[2010/09/12 06:23:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ebehofusocac.dll
[2010/09/12 04:21:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ejajirazoh.dll
[2010/09/12 02:19:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ogesozomufavele.dll
[2010/09/12 00:17:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ozigevop.dll
[2010/09/11 22:15:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\etamoledunumulo.dll
[2010/09/11 20:13:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ihayezevuqana.dll
[2010/09/11 18:11:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ohodifexemexiz.dll
[2010/09/11 16:09:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\anuvifoh.dll
[2010/09/11 14:07:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\adofewoq.dll
[2010/09/11 12:05:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uzesofihutafuzac.dll
[2010/09/11 10:03:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\imajazetijoki.dll
[2010/09/11 08:01:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ehodilaweti.dll
[2010/09/11 05:59:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\exirezate.dll
[2010/09/11 03:57:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\atimazizufe.dll
[2010/09/11 01:55:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\isajefif.dll
[2010/09/10 23:53:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iheteriwed.dll
[2010/09/10 21:51:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\omucimafeyut.dll
[2010/09/08 16:28:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ehuhibew.dll
[2010/09/08 14:26:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ecijumafuxuja.dll
[2010/09/08 12:24:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\aqokimup.dll
[2010/09/08 10:22:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ebepuwido.dll
[2010/09/08 08:24:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\arotigokidonot.dll
[2010/09/08 06:18:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ibesuyaxukow.dll
[2010/09/06 02:13:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\afonizokizi.dll
[2010/09/06 00:08:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\edakuvom.dll
[2010/09/05 22:06:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uripediwihe.dll
[2010/09/05 20:04:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ixehawagurin.dll
[2010/09/05 18:02:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\inotowuwuqecuz.dll
[2010/09/05 16:03:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\adacafofoceq.dll
[2010/09/05 14:01:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ezapuwowoh.dll
[2010/09/05 11:56:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\imisulej.dll
[2010/09/05 09:54:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ohibozer.dll
[2010/08/28 16:36:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ogiraxijumafuxu.dll
[2010/08/22 17:32:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\okopoxubacepexo.dll
[2010/08/19 21:02:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ajifepuxekuvay.dll
[2010/08/19 19:00:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ecuqiqurihik.dll
[2010/08/19 17:02:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\owakuhoxaj.dll
[2010/08/19 16:55:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ewuxuquxojapon.dll
[2010/08/12 03:24:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uhuxosokarad.dll
[2010/08/05 18:17:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\acojihano.dll
[2010/07/30 08:56:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ikazuyufomor.dll
[2010/07/30 06:54:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\udixagawoy.dll
[2010/07/30 04:52:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ukoseyomebuf.dll
[2010/07/30 02:50:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ahanoyiv.dll
[2010/07/30 00:52:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\igovuwoxutapimo.dll
[2010/07/29 22:46:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\atexamecusura.dll
[2010/07/29 20:44:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\esowitatuxofumu.dll
[2010/07/29 18:46:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ubezubohidozo.dll
[2010/07/29 16:40:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\owoqogun.dll
[2010/07/29 14:38:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\egiyesicogotobuh.dll
[2010/07/29 12:36:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ifoxiyet.dll
[2010/07/29 10:34:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\okalugaw.dll
[2010/07/29 08:36:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ukotamaga.dll
[2010/07/29 06:34:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ezibomuredi.dll
[2010/07/29 04:32:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ojonawifu.dll
[2010/07/29 02:26:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\apuqotiw.dll
[2010/07/29 00:24:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\azagogajekumibol.dll
[2010/07/28 22:26:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eyamosarevegub.dll
[2010/07/28 20:24:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uhoyonoxuxab.dll
[2010/07/28 18:18:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ebojegohewateb.dll
[2010/07/28 17:05:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ejiqodadujo.dll
[2010/07/28 15:03:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\enizudanawoza.dll
[2010/07/28 13:01:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\akamevocogi.dll
[2010/07/28 10:59:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\otoyejuhediqadun.dll
[2010/07/28 08:57:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ipepiriqurejad.dll
[2010/07/28 06:58:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ihelukigatekudat.dll
[2010/07/28 04:53:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ulekixuy.dll
[2010/07/28 02:51:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\alusidub.dll
[2010/07/28 00:49:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ihejuduli.dll
[2010/07/27 22:47:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uvoqaviv.dll
[2010/07/27 20:45:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\alocadis.dll
[2010/07/27 18:43:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ebamajapimogud.dll
[2010/07/27 16:41:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\itayoradiyub.dll
[2010/07/27 14:39:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\arihaxovab.dll
[2010/07/27 12:37:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ebatoxicedoj.dll
[2010/07/27 10:35:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oguxudipotafa.dll
[2010/07/27 08:33:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ulelepetiyogovi.dll
[2010/07/27 06:31:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ubawudehibewa.dll
[2010/07/27 04:29:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ovemadoyadomipu.dll
[2010/07/27 02:27:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ekikukub.dll
[2010/07/27 00:25:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\axevaxit.dll
[2010/07/26 22:23:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ajiloxeg.dll
[2010/07/26 20:21:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ukerurul.dll
[2010/07/26 18:19:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ehuyaparohijepu.dll
[2010/07/26 16:17:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\acuxevuqa.dll
[2010/07/26 14:18:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\imilodipoki.dll
[2010/07/26 12:13:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iyocupodo.dll
[2010/07/26 10:11:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\usogajekumibol.dll
[2010/07/26 08:09:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ulokexaquvetidac.dll
[2010/07/26 06:07:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ozohukuhoxajed.dll
[2010/07/26 04:05:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\otinujuqodih.dll
[2010/07/26 02:06:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eqomipob.dll
[2010/07/26 00:01:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ukasodamape.dll
[2010/07/25 21:59:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uzabivebaxiti.dll
[2010/07/25 19:57:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\agativol.dll
[2010/07/25 17:55:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uvirexowexul.dll
[2010/07/25 15:53:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\itugirifad.dll
[2010/07/25 13:51:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\odisarevegub.dll
[2010/07/25 11:49:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ebubixudum.dll
[2010/07/25 09:47:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uxokodur.dll
[2010/07/25 07:45:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\otivipeji.dll
[2010/07/25 05:43:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\okisevih.dll
[2010/07/25 03:41:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ibirediqa.dll
[2010/07/25 01:39:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ibonokec.dll
[2010/07/24 23:37:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iworukem.dll
[2010/07/24 21:35:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\emopixoh.dll
[2010/07/24 19:33:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ecijekumiboludos.dll
[2010/07/24 17:31:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ukotudiwo.dll
[2010/07/24 15:29:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\izucepexominopa.dll
[2010/07/24 13:27:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\itupadew.dll
[2010/07/24 11:25:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eludadodexadape.dll
[2010/07/24 09:26:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\uxebukukaseg.dll
[2009/07/22 21:16:19 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\John\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/28 21:23:17 | 000,022,716 | ---- | C] () -- C:\Documents and Settings\John\Application Data\wklnhst.dat
[2009/05/22 15:27:26 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\John\Local Settings\Application Data\fusioncache.dat
========== LOP Check ==========
[2009/05/22 15:27:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DIGStream
[2011/11/23 16:45:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Manager
[2009/05/26 16:22:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2012/07/04 22:33:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\f-secure
[2012/07/04 22:29:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fssg
[2009/07/11 21:03:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nova
[2009/05/30 13:37:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2012/05/03 21:11:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedyPC Software
[2011/11/23 16:48:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UAB
[2009/08/03 11:22:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/03/29 21:31:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\DriverCure
[2012/07/04 22:46:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\f-secure
[2010/03/22 10:46:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\MSNInstaller
[2011/07/25 23:13:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\PhotoScape
[2009/08/02 15:14:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Skinux
[2012/03/29 21:31:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\SpeedyPC Software
[2009/05/28 21:23:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Template
[2011/11/23 17:06:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Tific
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2009/07/08 17:07:46 | 090,666,697 | ---- | M] (Aladdin Systems, Inc.) -- C:\Novasoftware_1.exe
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/10 08:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
< MD5 for: SERVICES >
[2004/08/10 08:00:00 | 000,007,116 | ---- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A -- C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.CFG >
[2012/04/04 01:53:54 | 000,585,987 | ---- | M] () MD5=7BAB089A4F862C6BC86E0201D5BF1779 -- C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R--- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E -- C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 13:14:03 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009/02/06 06:22:21 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD -- C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
[2009/02/06 07:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 07:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\services.exe
[2004/08/10 08:00:00 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\$NtUninstallKB956572_0$\services.exe
< MD5 for: SERVICES.EXE-2F433351.PF >
[2012/07/20 17:58:37 | 000,009,908 | ---- | M] () MD5=2EB8969E7F0220BCC9D8D51AB85A3859 -- C:\WINDOWS\Prefetch\SERVICES.EXE-2F433351.pf
< MD5 for: SERVICES.LNK >
[2009/05/28 16:53:00 | 000,001,602 | ---- | M] () MD5=37AC63691C61B61FBFF86828B62FD89D -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2004/08/10 08:00:00 | 000,033,464 | ---- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 -- C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.SBS >
[2011/03/01 03:58:46 | 000,034,818 | ---- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B -- C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: SVCHOST.EXE >
[2008/04/13 20:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\erdnt\cache\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2004/08/10 08:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: USERINIT.EXE >
[2004/08/10 08:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\erdnt\cache\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004/08/10 08:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Local\AutoProxyCache /s >
< End of report >