OTL logfile created on: 10/7/2009 1:45:15 PM - Run 2
OTL by OldTimer - Version 3.0.18.4 Folder = C:\Documents and Settings\camster98\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.49 Gb Total Physical Memory | 0.71 Gb Available Physical Memory | 47.80% Memory free
3.34 Gb Paging File | 2.54 Gb Available in Paging File | 76.12% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 55.66 Gb Free Space | 74.68% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CAMERON-CAF0EDC
Current User Name: camster98
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/07/20 14:59:24 | 00,057,344 | R--- | M] (iS3, Inc.) -- C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
PRC - [2008/08/20 18:18:34 | 00,905,216 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
PRC - [2009/09/15 05:49:40 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/09/15 05:56:43 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/08/20 18:38:30 | 00,860,160 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe
PRC - [2008/08/20 18:08:02 | 00,466,944 | ---- | M] (Intel® Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2008/08/20 18:28:34 | 00,348,160 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\WLKeeper.exe
PRC - [2009/02/06 05:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2009/02/06 05:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2009/09/29 13:18:46 | 00,157,120 | R--- | M] (iS3, Inc.) -- C:\Program Files\STOPzilla!\STOPzilla.exe
PRC - [2008/04/14 00:42:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2007/05/10 12:22:32 | 00,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
PRC - [2008/08/20 18:27:36 | 01,368,064 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
PRC - [2008/08/20 18:09:12 | 01,191,936 | ---- | M] (Intel® Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
PRC - [2007/03/30 22:00:16 | 00,162,584 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\hkcmd.exe
PRC - [2007/03/30 21:59:36 | 00,138,008 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxpers.exe
PRC - [2007/07/20 18:55:46 | 01,228,800 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2009/09/15 05:56:48 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/09/21 16:36:12 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2008/05/01 23:15:46 | 00,015,872 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2009/09/15 11:42:42 | 01,998,576 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2008/05/27 00:19:14 | 00,123,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2007/03/30 21:59:26 | 00,252,696 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxsrvc.exe
PRC - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2001/08/23 07:00:00 | 00,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\unsecapp.exe
PRC - [2009/09/21 16:36:08 | 10,309,408 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunes.exe
PRC - [2009/08/24 15:15:03 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008/04/14 00:42:42 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe
PRC - [2009/10/04 20:05:40 | 00,472,064 | ---- | M] ( ) -- C:\Documents and Settings\camster98\My Documents\Downloads\RootRepeal.exe
PRC - [2009/10/04 20:05:48 | 00,520,704 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\camster98\My Documents\Downloads\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2008/07/25 13:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/09/15 05:49:40 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2009/09/15 05:56:43 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/09/15 05:56:28 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Stopped])
SRV - [2009/09/15 05:54:13 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Stopped])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/07/25 13:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/08/20 18:38:30 | 00,860,160 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng [Auto | Running])
SRV - [2008/07/29 23:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/04/14 00:42:04 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008/07/29 21:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2008/07/29 21:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2006/10/26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2008/08/20 18:08:02 | 00,466,944 | ---- | M] (Intel® Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc [Auto | Running])
SRV - [2008/08/20 18:18:34 | 00,905,216 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe -- (S24EventMonitor [Auto | Running])
SRV - [2009/07/20 14:59:24 | 00,057,344 | R--- | M] (iS3, Inc.) -- C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe -- (szserver [Auto | Running])
SRV - [2008/08/20 18:28:34 | 00,348,160 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\WLKeeper.exe -- (WLANKEEPER [Auto | Running])
SRV - [2006/10/18 22:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...p...&ar=msnhome
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.2
FF - prefs.js..extensions.enabledItems: FasterFox_Lite@BigRedBrent:3.8.2Lite
FF - prefs.js..extensions.enabledItems: [email protected]:1.4.3
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:3.3.16
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:0.0.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.07
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.1.07282009_url_fix
FF - prefs.js..extensions.enabledItems: [email protected]:2.1.4
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20090918
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - prefs.js..extensions.enabledItems: [email protected]:0.6.20090630
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/10/03 23:17:19 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/06 20:20:57 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/05 13:29:30 | 00,000,000 | ---D | M]
[2009/10/03 16:02:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Extensions
[2009/10/03 16:02:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/10/06 20:22:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions
[2009/10/03 16:32:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2009/10/06 20:21:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/10/03 16:32:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2009/10/03 16:32:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/10/03 16:32:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/10/03 16:42:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions\FasterFox_Lite@BigRedBrent
[2009/10/03 16:32:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions\[email protected]
[2009/10/03 16:38:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions\[email protected]
[2009/10/03 16:39:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions\SkipScreen@SkipScreen
[2009/10/03 16:40:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\mozilla\Firefox\Profiles\naep4b2z.default\extensions\[email protected]
[2009/10/03 16:01:59 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/10/03 16:01:59 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/08/24 15:15:25 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/24 15:15:26 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/08/24 15:15:27 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2009/10/04 11:54:30 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/10/04 11:54:30 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/10/04 11:54:30 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/10/04 11:54:30 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/10/04 11:54:31 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/10/04 11:54:31 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/10/04 11:54:31 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2009/08/24 13:45:46 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/24 13:45:46 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/24 13:45:46 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/24 13:45:46 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/24 13:45:46 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/24 13:45:46 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/24 13:45:46 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (GigagetIEHelper Class) - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\System32\gigagetbho_v10.dll (Giganology Inc.)
O2 - BHO: (ZILLAbar Browser Helper Object) - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll (iS3, Inc)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O3 - HKLM\..\Toolbar: (STOPzilla) - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll (iS3, Inc)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\camster98\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\camster98\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm ()
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1254603245274 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/03 00:10:58 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: BtwSrv - Service key not found. File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 14 Days ==========
[2009/10/02 16:56:57 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data
[2009/10/04 11:54:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/10/04 11:53:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2009/10/04 11:54:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/10/04 04:42:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Intel
[2009/10/03 16:26:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/10/02 16:56:57 | 00,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/10/05 13:22:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2009/10/05 00:40:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SITEguard
[2009/10/03 17:18:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/10/06 22:15:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/10/03 16:00:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/10/03 23:18:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/10/03 17:18:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ZILLAbar
[2009/10/03 00:20:12 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\camster98\Application Data
[2009/10/03 16:14:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Adobe
[2009/10/04 11:55:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Apple Computer
[2009/10/05 10:38:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Audacity
[2009/10/04 05:49:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Dell
[2009/10/05 20:54:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\dvdcss
[2009/10/05 15:36:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Hardcore
[2009/10/07 13:16:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Help
[2009/10/03 00:20:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Identities
[2009/10/04 04:38:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\InstallShield
[2009/10/04 04:42:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Intel
[2009/10/05 15:38:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Juce VST Host
[2009/10/03 16:47:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Macromedia
[2009/10/03 16:26:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Malwarebytes
[2009/10/03 00:20:12 | 00,000,000 | --SD | C] -- C:\Documents and Settings\camster98\Application Data\Microsoft
[2009/10/03 16:02:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Mozilla
[2009/10/04 20:18:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Notepad++
[2009/10/05 13:37:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\OpenCandy
[2009/10/05 15:37:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Sawer
[2009/10/03 16:44:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\STOPzilla!
[2009/10/06 22:15:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\SUPERAntiSpyware.com
[2009/10/04 18:00:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\TeamViewer
[2009/10/03 16:20:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\uTorrent
[2009/10/05 09:55:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\vlc
[2009/10/03 16:20:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Windows Desktop Search
[2009/10/05 16:42:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\Windows Search
[2009/10/03 16:28:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\WinRAR
[2009/10/04 01:39:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Application Data\YTK Enhanced
[2009/10/03 00:20:12 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data
[2009/10/04 11:53:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data\Apple
[2009/10/04 11:52:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data\Apple Computer
[2009/10/05 06:00:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data\ApplicationHistory
[2009/10/07 13:16:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data\Help
[2009/10/03 16:20:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data\Identities
[2009/10/03 00:20:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data\Microsoft
[2009/10/05 13:22:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data\Microsoft Help
[2009/10/03 16:02:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data\Mozilla
[2009/10/04 01:44:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data\Yahoo
[2009/10/05 11:17:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Local Settings\Application Data\Yahoo!
[2009/10/02 16:57:50 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files
[2009/10/04 11:53:16 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2009/10/05 13:28:51 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2009/10/04 04:40:53 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2009/10/04 04:42:20 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2009/10/03 17:18:14 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\iS3
[2009/10/02 16:57:50 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2009/10/03 00:08:39 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2009/10/02 16:57:55 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2009/10/03 00:08:43 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2009/10/02 16:57:51 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2009/10/03 00:07:40 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2009/10/06 22:15:08 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2009/10/02 16:57:50 | 00,000,000 | R--D | C] -- C:\Program Files
[2009/10/03 16:21:25 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/10/04 11:53:42 | 00,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2009/10/06 09:30:13 | 00,000,000 | ---D | C] -- C:\Program Files\Audacity
[2009/10/05 10:37:39 | 00,000,000 | ---D | C] -- C:\Program Files\Audacity 1.3 Beta (Unicode)
[2009/10/04 11:54:37 | 00,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2009/10/04 04:39:14 | 00,000,000 | ---D | C] -- C:\Program Files\Broadcom
[2009/10/06 22:23:12 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/10/02 16:57:50 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files
[2009/10/06 23:23:32 | 00,000,000 | ---D | C] -- C:\Program Files\COMODO
[2009/10/03 00:06:58 | 00,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2009/10/04 04:38:43 | 00,000,000 | ---D | C] -- C:\Program Files\Dell
[2009/10/04 20:25:56 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/10/06 09:47:43 | 00,000,000 | ---D | C] -- C:\Program Files\FileZilla FTP Client
[2009/10/05 13:26:13 | 00,000,000 | ---D | C] -- C:\Program Files\Giganology
[2009/10/04 15:02:05 | 00,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2009/10/05 13:33:39 | 00,000,000 | ---D | C] -- C:\Program Files\Image-Line
[2009/10/04 04:41:07 | 00,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2009/10/04 04:37:48 | 00,000,000 | ---D | C] -- C:\Program Files\Intel
[2009/10/03 00:07:36 | 00,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2009/10/04 11:54:58 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/10/04 11:54:55 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/10/06 09:30:04 | 00,000,000 | ---D | C] -- C:\Program Files\Lame for Audacity
[2009/10/07 09:31:46 | 00,000,000 | ---D | C] -- C:\Program Files\MagicDisc
[2009/10/04 19:13:50 | 00,000,000 | ---D | C] -- C:\Program Files\MagicISO
[2009/10/03 16:26:26 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/03 00:06:24 | 00,000,000 | ---D | C] -- C:\Program Files\Messenger
[2009/10/03 00:11:19 | 00,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2009/10/05 13:22:40 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2009/10/07 13:27:11 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft SDKs
[2009/10/07 09:53:21 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Windows 7 Upgrade Advisor
[2009/10/05 13:29:29 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2009/10/05 13:28:20 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2009/10/03 00:08:24 | 00,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2009/10/03 16:01:57 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2009/10/03 16:25:57 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009/10/03 00:05:33 | 00,000,000 | ---D | C] -- C:\Program Files\MSN
[2009/10/03 00:06:20 | 00,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2009/10/03 00:07:52 | 00,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2009/10/04 20:18:27 | 00,000,000 | ---D | C] -- C:\Program Files\Notepad++
[2009/10/03 00:06:42 | 00,000,000 | ---D | C] -- C:\Program Files\Online Services
[2009/10/03 00:07:48 | 00,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2009/10/05 13:35:07 | 00,000,000 | ---D | C] -- C:\Program Files\Outsim
[2009/10/04 11:54:07 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2009/10/03 16:25:52 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/10/03 16:06:58 | 00,000,000 | ---D | C] -- C:\Program Files\Safer Networking
[2009/10/04 04:41:07 | 00,000,000 | ---D | C] -- C:\Program Files\SigmaTel
[2009/10/03 16:44:04 | 00,000,000 | ---D | C] -- C:\Program Files\STOPzilla!
[2009/10/06 22:15:32 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/10/04 18:00:04 | 00,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2009/10/07 13:32:58 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/10/03 00:20:19 | 00,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2009/10/04 19:57:23 | 00,000,000 | ---D | C] -- C:\Program Files\Unlocker
[2009/10/03 16:20:22 | 00,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2009/10/07 13:18:57 | 00,000,000 | ---D | C] -- C:\Program Files\VB Decompiler Lite
[2009/10/04 17:04:57 | 00,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2009/10/06 09:51:25 | 00,000,000 | ---D | C] -- C:\Program Files\VirtualDJ
[2009/10/04 16:57:17 | 00,000,000 | ---D | C] -- C:\Program Files\vixy.net
[2009/10/05 13:35:11 | 00,000,000 | ---D | C] -- C:\Program Files\VstPlugins
[2009/10/03 16:19:47 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2009/10/03 00:06:28 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2009/10/03 00:06:27 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2009/10/03 00:05:31 | 00,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2009/10/03 00:09:30 | 00,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2009/10/07 13:16:00 | 00,000,000 | ---D | C] -- C:\Program Files\WinHex
[2009/10/03 16:28:37 | 00,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2009/10/03 00:11:19 | 00,000,000 | ---D | C] -- C:\Program Files\xerox
[2009/10/03 23:18:30 | 00,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2009/10/07 13:38:18 | 00,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe
[2009/10/07 13:38:18 | 00,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe
[2009/10/07 13:38:18 | 00,135,168 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swreg.exe
[2009/10/07 13:38:18 | 00,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe
[2009/10/07 13:38:18 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe
[2009/10/07 13:38:18 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe
[2009/10/07 13:38:18 | 00,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe
[2009/10/07 13:38:18 | 00,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe
[2009/10/07 13:38:18 | 00,079,360 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swxcacls.exe
[2009/10/07 13:38:18 | 00,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/10/07 13:38:18 | 00,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe
[2009/10/07 09:31:47 | 00,116,736 | ---- | C] (MagicISO, Inc.) -- C:\WINDOWS\System32\drivers\mcdbus.sys
[2009/10/07 09:24:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\My Documents\hjsplit
[2009/10/06 09:51:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\My Documents\VirtualDJ
[2009/10/06 09:20:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Desktop\abc
[2009/10/05 13:36:00 | 00,225,280 | ---- | C] (Propellerhead Software AB) -- C:\WINDOWS\System32\rewire.dll
[2009/10/05 13:35:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\My Documents\Image-Line
[2009/10/05 13:27:00 | 00,000,000 | ---D | C] -- C:\TDdownload
[2009/10/05 13:26:18 | 00,086,016 | ---- | C] (Giganology Inc.) -- C:\WINDOWS\System32\gigagetbho_v10.dll
[2009/10/05 13:23:10 | 00,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2009/10/05 13:21:57 | 00,000,000 | RH-D | C] -- C:\MSOCache
[2009/10/05 12:01:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2009/10/04 22:59:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\Desktop\cotts
[2009/10/04 20:26:10 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/10/04 19:45:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\images
[2009/10/04 15:54:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\My Documents\camerons documents
[2009/10/04 15:04:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\My Documents\gegl-0.0
[2009/10/04 05:49:40 | 00,016,128 | ---- | C] (Dell Inc) -- C:\WINDOWS\System32\drivers\APPDRV.SYS
[2009/10/04 05:49:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2009/10/04 05:49:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang
[2009/10/04 05:49:02 | 00,000,000 | ---D | C] -- C:\Intel
[2009/10/04 04:41:08 | 00,146,944 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\st325602.dll
[2009/10/04 04:37:49 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2009/10/04 04:37:05 | 00,000,000 | ---D | C] -- C:\dell
[2009/10/03 23:16:35 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2009/10/03 23:15:02 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP
[2009/10/03 16:35:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/10/03 16:34:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2009/10/03 16:33:54 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/10/03 16:26:27 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/03 16:26:26 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/10/03 16:26:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/10/03 16:25:30 | 00,000,000 | ---D | C] -- C:\d02976ceb65ce766ee
[2009/10/03 16:24:57 | 00,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2009/10/03 16:24:35 | 00,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2009/10/03 16:22:41 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/10/03 16:21:56 | 00,052,368 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/10/03 16:21:56 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/10/03 16:21:55 | 00,027,408 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/10/03 16:21:53 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2009/10/03 16:21:52 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2009/10/03 16:21:52 | 00,094,160 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/10/03 16:21:52 | 00,093,424 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2009/10/03 16:21:52 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/10/03 16:21:29 | 01,279,968 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2009/10/03 16:19:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2009/10/03 16:06:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\My Documents\TagsRevisited
[2009/10/03 16:04:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\camster98\My Documents\Downloads
[2009/10/03 16:00:35 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2009/10/03 16:00:33 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2009/10/03 15:53:59 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2009/10/03 00:20:16 | 00,000,000 | R--D | C] -- C:\Documents and Settings\camster98\My Documents\My Pictures
[2009/10/03 00:20:16 | 00,000,000 | R--D | C] -- C:\Documents and Settings\camster98\My Documents\My Music
[2009/10/03 00:19:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2009/10/03 00:19:26 | 00,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2009/10/03 00:19:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/10/03 00:13:09 | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2009/10/03 00:13:09 | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2009/10/03 00:13:09 | 00,029,184 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2009/10/03 00:12:02 | 00,057,856 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimgd.dll
[2009/10/03 00:12:02 | 00,045,056 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunid.dll
[2009/10/03 00:12:02 | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucmd.dll
[2009/10/03 00:11:50 | 00,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2009/10/03 00:11:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2009/10/03 00:09:42 | 00,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2009/10/03 00:09:42 | 00,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2009/10/03 00:09:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2009/10/03 00:08:40 | 00,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2009/10/03 00:08:35 | 00,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2009/10/03 00:08:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2009/10/03 00:07:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2009/10/03 00:07:35 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2009/10/03 00:06:50 | 00,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2009/10/03 00:05:32 | 00,281,088 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe
[2009/10/03 00:05:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2009/10/03 00:05:25 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2009/10/03 00:05:23 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2009/10/03 00:05:08 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2009/10/02 16:58:20 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2009/10/02 16:57:56 | 00,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2009/10/02 16:57:50 | 00,000,000 | R--D | C] -- C:\Program Files
[2009/10/02 16:57:03 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2009/10/02 16:57:03 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2009/10/02 16:56:31 | 00,000,000 | -HSD | C] -- C:\System Volume Information
[2009/10/02 16:56:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings
[2009/10/02 16:49:38 | 00,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2009/10/02 16:49:38 | 00,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2009/10/02 16:49:38 | 00,000,000 | R--D | C] -- C:\WINDOWS\Web
[2009/10/02 16:49:38 | 00,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\system32
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\system
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\security
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\repair
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\pchealth
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Network Diagnostic
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\mui
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Media
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\L2Schemas
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\java
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\ime
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Help
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\ehome
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Config
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\addins
[2009/10/02 16:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS
========== Files - Modified Within 14 Days ==========
[2009/10/07 13:39:43 | 00,002,582 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2009/10/07 13:39:38 | 00,000,926 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\Install Microsoft Visual C++ 2008 Express Edition with SP1.lnk
[2009/10/07 13:32:58 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\HijackThis.lnk
[2009/10/07 13:10:00 | 00,001,216 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2009/10/07 11:44:13 | 00,550,666 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/10/07 11:44:13 | 00,462,296 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/10/07 11:44:13 | 00,078,458 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/10/07 11:41:17 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/07 11:40:04 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/07 11:39:56 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/07 11:39:19 | 00,149,648 | ---- | M] () -- C:\WINDOWS\System32\drivers\sfi.dat
[2009/10/07 09:53:22 | 00,001,966 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\Windows 7 Upgrade Advisor Beta.lnk
[2009/10/07 09:31:59 | 00,000,652 | ---- | M] () -- C:\Documents and Settings\camster98\Start Menu\Programs\Startup\MagicDisc.lnk
[2009/10/07 09:31:59 | 00,000,640 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\MagicDisc.lnk
[2009/10/07 06:14:54 | 00,028,256 | ---- | M] () -- C:\Documents and Settings\camster98\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/10/07 04:23:11 | 00,148,400 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/10/06 22:23:12 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\CCleaner.lnk
[2009/10/06 22:15:39 | 00,000,780 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/10/06 15:34:25 | 02,254,903 | ---- | M] () -- C:\Documents and Settings\camster98\My Documents\trippy.mp3
[2009/10/06 10:03:35 | 00,000,724 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\Virtual DJ Trial.lnk
[2009/10/05 14:04:28 | 00,000,574 | ---- | M] () -- C:\Documents and Settings\camster98\My Documents\pm2.rtf
[2009/10/05 14:04:27 | 00,000,546 | ---- | M] () -- C:\Documents and Settings\camster98\My Documents\pm.rtf
[2009/10/05 13:35:53 | 00,000,792 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\FL Studio 9.lnk
[2009/10/05 13:26:15 | 00,000,744 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\Gigaget.lnk
[2009/10/05 10:37:47 | 00,000,729 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\Audacity 1.3 Beta (Unicode).lnk
[2009/10/05 01:20:47 | 05,877,236 | -H-- | M] () -- C:\Documents and Settings\camster98\Local Settings\Application Data\IconCache.db
[2009/10/05 00:40:05 | 00,000,734 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/10/04 23:10:47 | 00,003,584 | ---- | M] () -- C:\Documents and Settings\camster98\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/04 20:25:59 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\camster98\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/04 20:25:57 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\NTREGOPT.lnk
[2009/10/04 20:25:57 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\ERUNT.lnk
[2009/10/04 20:18:33 | 00,000,720 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Notepad++.lnk
[2009/10/04 19:48:19 | 00,131,731 | ---- | M] () -- C:\WINDOWS\System32\dbsinit.exe
[2009/10/04 19:44:12 | 00,000,034 | ---- | M] () -- C:\WINDOWS\System32\wwp.htm
[2009/10/04 19:13:52 | 00,001,486 | ---- | M] () -- C:\Documents and Settings\camster98\Desktop\MagicISO.lnk
[2009/10/04 18:00:06 | 00,000,879 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TeamViewer 4.lnk
[2009/10/04 17:05:19 | 00,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2009/10/04 15:02:26 | 00,000,790 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\GIMP 2.lnk
[2009/10/04 11:55:41 | 00,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/10/04 11:54:22 | 00,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/10/04 11:53:45 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/04 04:38:48 | 00,000,005 | ---- | M] () -- C:\WINDOWS\System32\drivers\DELL_LAT_D520.MRK
[2009/10/04 04:38:48 | 00,000,005 | ---- | M] () -- C:\WINDOWS\System32\drivers\1028_DELL_LAT_D520.MRK
[2009/10/03 23:18:55 | 00,000,812 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2009/10/03 16:26:30 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/03 16:21:56 | 00,001,709 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/10/03 16:21:52 | 00,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/10/03 16:20:23 | 00,000,630 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2009/10/03 16:19:52 | 00,001,787 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2009/10/03 16:02:05 | 00,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2009/10/03 16:02:00 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/10/03 00:14:34 | 00,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2009/10/03 00:13:49 | 00,000,283 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2009/10/03 00:10:58 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009/10/03 00:10:58 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/10/03 00:10:58 | 00,000,000 | ---- | M] () -- C:\WINDOWS\control.ini
[2009/10/03 00:10:58 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/10/03 00:10:58 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/10/03 00:10:55 | 00,000,507 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/10/03 00:10:50 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/10/03 00:10:50 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/10/03 00:10:49 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2009/10/03 00:10:39 | 00,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2009/10/03 00:09:42 | 00,000,488 | RH-- | M] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2009/10/03 00:09:42 | 00,000,488 | RH-- | M] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\WindowsShell.Manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2009/10/03 00:07:09 | 00,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/10/03 00:06:55 | 00,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini
[2009/10/03 00:06:55 | 00,000,036 | ---- | M] () -- C:\WINDOWS\vb.ini
[2009/10/03 00:02:11 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/10/02 16:58:01 | 00,004,444 | ---- | M] () -- C:\WINDOWS\System32\pid.PNF
[2009/10/02 16:57:49 | 00,000,231 | ---- | M] () -- C:\WINDOWS\system.ini
========== Files - No Company Name ==========
[2009/10/07 13:39:42 | 00,002,582 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2009/10/07 13:39:38 | 00,000,926 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\Install Microsoft Visual C++ 2008 Express Edition with SP1.lnk
[2009/10/07 13:38:18 | 00,075,776 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe
[2009/10/07 13:38:18 | 00,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe
[2009/10/07 13:38:18 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe
[2009/10/07 13:32:58 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\HijackThis.lnk
[2009/10/07 11:40:26 | 00,001,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2009/10/07 09:53:22 | 00,001,966 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\Windows 7 Upgrade Advisor Beta.lnk
[2009/10/07 09:31:59 | 00,000,652 | ---- | C] () -- C:\Documents and Settings\camster98\Start Menu\Programs\Startup\MagicDisc.lnk
[2009/10/07 09:31:59 | 00,000,640 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\MagicDisc.lnk
[2009/10/07 04:23:03 | 00,149,648 | ---- | C] () -- C:\WINDOWS\System32\drivers\sfi.dat
[2009/10/06 22:23:12 | 00,001,548 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\CCleaner.lnk
[2009/10/06 22:15:39 | 00,000,780 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/10/06 15:32:35 | 02,254,903 | ---- | C] () -- C:\Documents and Settings\camster98\My Documents\trippy.mp3
[2009/10/06 09:51:30 | 00,000,724 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\Virtual DJ Trial.lnk
[2009/10/05 14:04:28 | 00,000,574 | ---- | C] () -- C:\Documents and Settings\camster98\My Documents\pm2.rtf
[2009/10/05 14:04:24 | 00,000,546 | ---- | C] () -- C:\Documents and Settings\camster98\My Documents\pm.rtf
[2009/10/05 13:35:52 | 00,000,792 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\FL Studio 9.lnk
[2009/10/05 13:26:15 | 00,000,744 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\Gigaget.lnk
[2009/10/05 10:38:38 | 04,057,299 | ---- | C] () -- C:\Documents and Settings\camster98\My Documents\4Front Bass Module.dll
[2009/10/05 10:37:47 | 00,000,729 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\Audacity 1.3 Beta (Unicode).lnk
[2009/10/04 23:10:46 | 00,003,584 | ---- | C] () -- C:\Documents and Settings\camster98\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/04 20:25:59 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\camster98\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/04 20:25:57 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\NTREGOPT.lnk
[2009/10/04 20:25:57 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\ERUNT.lnk
[2009/10/04 20:18:33 | 00,000,720 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Notepad++.lnk
[2009/10/04 19:45:15 | 00,131,731 | ---- | C] () -- C:\WINDOWS\System32\dbsinit.exe
[2009/10/04 19:44:12 | 00,000,034 | ---- | C] () -- C:\WINDOWS\System32\wwp.htm
[2009/10/04 19:13:52 | 00,001,486 | ---- | C] () -- C:\Documents and Settings\camster98\Desktop\MagicISO.lnk
[2009/10/04 18:00:06 | 00,000,879 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TeamViewer 4.lnk
[2009/10/04 17:05:19 | 00,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2009/10/04 15:02:26 | 00,000,790 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\GIMP 2.lnk
[2009/10/04 12:01:57 | 00,028,256 | ---- | C] () -- C:\Documents and Settings\camster98\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/10/04 11:55:41 | 00,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/10/04 11:54:22 | 00,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/10/04 11:53:45 | 00,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/04 05:49:09 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4814.dll
[2009/10/04 05:49:09 | 00,025,472 | ---- | C] () -- C:\WINDOWS\System32\igxpxs32.vp
[2009/10/04 05:49:09 | 00,002,096 | ---- | C] () -- C:\WINDOWS\System32\igxpxk32.vp
[2009/10/04 05:49:07 | 00,121,232 | ---- | C] () -- C:\WINDOWS\System32\IScrNBR.bmp
[2009/10/04 05:49:07 | 00,121,232 | ---- | C] () -- C:\WINDOWS\System32\IScrNB.bmp
[2009/10/04 04:38:48 | 00,000,005 | ---- | C] () -- C:\WINDOWS\System32\drivers\DELL_LAT_D520.MRK
[2009/10/04 04:38:48 | 00,000,005 | ---- | C] () -- C:\WINDOWS\System32\drivers\1028_DELL_LAT_D520.MRK
[2009/10/04 04:38:43 | 00,000,666 | ---- | C] () -- C:\WINDOWS\speed.reg
[2009/10/03 23:18:55 | 00,000,812 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2009/10/03 16:26:30 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/03 16:21:56 | 00,001,709 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/10/03 16:21:29 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2009/10/03 16:20:23 | 00,000,630 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2009/10/03 16:19:52 | 00,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2009/10/03 16:02:05 | 00,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/10/03 16:02:00 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/10/03 00:34:01 | 05,877,236 | -H-- | C] () -- C:\Documents and Settings\camster98\Local Settings\Application Data\IconCache.db
[2009/10/03 00:20:13 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\camster98\Application Data\desktop.ini
[2009/10/03 00:19:26 | 00,000,006 | -H-- | C] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/03 00:14:34 | 00,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2009/10/03 00:13:49 | 00,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/10/03 00:13:33 | 00,028,288 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xjis.nls
[2009/10/03 00:13:04 | 00,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prcp.nls
[2009/10/03 00:13:03 | 00,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prc.nls
[2009/10/03 00:13:02 | 00,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2009/10/03 00:12:42 | 00,047,066 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ksc.nls
[2009/10/03 00:12:41 | 01,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2009/10/03 00:12:35 | 00,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2009/10/03 00:12:34 | 00,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2009/10/03 00:12:31 | 00,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2009/10/03 00:12:16 | 13,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2009/10/03 00:12:09 | 00,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2009/10/03 00:12:05 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2009/10/03 00:11:53 | 00,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2009/10/03 00:11:49 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_864.nls
[2009/10/03 00:11:49 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_862.nls
[2009/10/03 00:11:49 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_858.nls
[2009/10/03 00:11:49 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_720.nls
[2009/10/03 00:11:49 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_870.nls
[2009/10/03 00:11:49 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_708.nls
[2009/10/03 00:11:49 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28596.nls
[2009/10/03 00:11:48 | 00,180,770 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20932.nls
[2009/10/03 00:11:48 | 00,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20949.nls
[2009/10/03 00:11:48 | 00,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20936.nls
[2009/10/03 00:11:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21027.nls
[2009/10/03 00:11:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21025.nls
[2009/10/03 00:11:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20924.nls
[2009/10/03 00:11:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20880.nls
[2009/10/03 00:11:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20871.nls
[2009/10/03 00:11:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20838.nls
[2009/10/03 00:11:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20833.nls
[2009/10/03 00:11:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20424.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20423.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20420.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20297.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20290.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20285.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20284.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20280.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20278.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20277.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20273.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20269.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20108.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20107.nls
[2009/10/03 00:11:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20106.nls
[2009/10/03 00:11:46 | 00,187,938 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20005.nls
[2009/10/03 00:11:46 | 00,186,402 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20001.nls
[2009/10/03 00:11:46 | 00,185,378 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20003.nls
[2009/10/03 00:11:46 | 00,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20004.nls
[2009/10/03 00:11:46 | 00,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20000.nls
[2009/10/03 00:11:46 | 00,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20002.nls
[2009/10/03 00:11:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20105.nls
[2009/10/03 00:11:45 | 00,189,986 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1361.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1149.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1148.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1147.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1146.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1145.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1144.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1143.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1142.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1141.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1140.nls
[2009/10/03 00:11:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1047.nls
[2009/10/03 00:11:44 | 00,195,618 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10002.nls
[2009/10/03 00:11:44 | 00,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10003.nls
[2009/10/03 00:11:44 | 00,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10008.nls
[2009/10/03 00:11:44 | 00,162,850 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10001.nls
[2009/10/03 00:11:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10021.nls
[2009/10/03 00:11:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10005.nls
[2009/10/03 00:11:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10004.nls
[2009/10/03 00:11:43 | 00,082,172 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bopomofo.nls
[2009/10/03 00:11:43 | 00,066,728 | ---- | C] () -- C:\WINDOWS\System32\dllcache\big5.nls
[2009/10/03 00:10:58 | 00,002,626 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/10/03 00:10:58 | 00,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2009/10/03 00:10:58 | 00,000,000 | RHS- | C] () -- C:\IO.SYS
[2009/10/03 00:10:58 | 00,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2009/10/03 00:10:58 | 00,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2009/10/03 00:10:50 | 00,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/10/03 00:10:50 | 00,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/10/03 00:10:49 | 00,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2009/10/03 00:09:42 | 00,000,488 | RH-- | C] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2009/10/03 00:09:42 | 00,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\WindowsShell.Manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2009/10/03 00:09:35 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2009/10/03 00:09:15 | 04,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
[2009/10/03 00:08:52 | 00,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2009/10/03 00:08:52 | 00,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2009/10/03 00:08:46 | 00,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2009/10/03 00:07:59 | 00,376,832 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msinfo.dll
[2009/10/03 00:07:09 | 00,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/10/03 00:06:03 | 00,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
[2009/10/03 00:06:03 | 00,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
[2009/10/03 00:06:03 | 00,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
[2009/10/03 00:06:03 | 00,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
[2009/10/03 00:06:03 | 00,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
[2009/10/03 00:06:03 | 00,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
[2009/10/03 00:06:03 | 00,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
[2009/10/03 00:06:03 | 00,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
[2009/10/03 00:06:03 | 00,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2009/10/03 00:06:02 | 00,093,702 | ---- | C] () -- C:\WINDOWS\System32\subrange.uce
[2009/10/03 00:06:02 | 00,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
[2009/10/03 00:06:02 | 00,060,458 | ---- | C] () -- C:\WINDOWS\System32\ideograf.uce
[2009/10/03 00:06:02 | 00,016,740 | ---- | C] () -- C:\WINDOWS\System32\shiftjis.uce
[2009/10/03 00:06:02 | 00,012,876 | ---- | C] () -- C:\WINDOWS\System32\korean.uce
[2009/10/03 00:06:02 | 00,008,484 | ---- | C] () -- C:\WINDOWS\System32\kanji_2.uce
[2009/10/03 00:06:02 | 00,006,948 | ---- | C] () -- C:\WINDOWS\System32\kanji_1.uce
[2009/10/03 00:06:02 | 00,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
[2009/10/03 00:06:01 | 00,024,006 | ---- | C] () -- C:\WINDOWS\System32\gb2312.uce
[2009/10/03 00:06:01 | 00,022,984 | ---- | C] () -- C:\WINDOWS\System32\bopomofo.uce
[2009/10/03 00:05:59 | 00,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2009/10/03 00:05:59 | 00,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2009/10/03 00:05:58 | 00,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2009/10/03 00:05:52 | 00,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2009/10/02 16:58:01 | 00,004,444 | ---- | C] () -- C:\WINDOWS\System32\pid.PNF
[2009/10/02 16:57:52 | 01,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2009/10/02 16:57:52 | 00,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2009/10/02 16:57:51 | 00,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2009/10/02 16:57:51 | 00,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2009/10/02 16:57:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28603.nls
[2009/10/02 16:57:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls
[2009/10/02 16:57:46 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_857.nls
[2009/10/02 16:57:46 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_857.nls
[2009/10/02 16:57:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28599.nls
[2009/10/02 16:57:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10081.nls
[2009/10/02 16:57:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28599.nls
[2009/10/02 16:57:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10081.nls
[2009/10/02 16:57:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28595.nls
[2009/10/02 16:57:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10017.nls
[2009/10/02 16:57:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10007.nls
[2009/10/02 16:57:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28595.NLS
[2009/10/02 16:57:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10017.nls
[2009/10/02 16:57:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10007.nls
[2009/10/02 16:57:42 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_869.nls
[2009/10/02 16:57:42 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_737.nls
[2009/10/02 16:57:42 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_869.nls
[2009/10/02 16:57:42 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_737.nls
[2009/10/02 16:57:42 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_875.nls
[2009/10/02 16:57:42 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28597.nls
[2009/10/02 16:57:42 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10006.nls
[2009/10/02 16:57:42 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_875.nls
[2009/10/02 16:57:42 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28597.NLS
[2009/10/02 16:57:42 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10006.nls
[2009/10/02 16:57:41 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_866.nls
[2009/10/02 16:57:41 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_855.nls
[2009/10/02 16:57:41 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_866.nls
[2009/10/02 16:57:41 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_855.nls
[2009/10/02 16:57:41 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28594.nls
[2009/10/02 16:57:41 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28594.NLS
[2009/10/02 16:57:39 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_852.nls
[2009/10/02 16:57:39 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_852.nls
[2009/10/02 16:57:39 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10082.nls
[2009/10/02 16:57:39 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10029.nls
[2009/10/02 16:57:39 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10010.nls
[2009/10/02 16:57:39 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10082.nls
[2009/10/02 16:57:39 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10029.nls
[2009/10/02 16:57:39 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10010.nls
[2009/10/02 16:57:37 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20127.nls
[2009/10/02 16:57:37 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_20127.nls
[2009/10/02 16:57:33 | 00,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2009/10/02 16:57:19 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2009/10/02 16:57:18 | 00,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2009/10/02 16:57:18 | 00,112,918 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2009/10/02 16:57:18 | 00,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2009/10/02 16:57:18 | 00,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2009/10/02 16:57:18 | 00,026,991 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat
[2009/10/02 16:57:18 | 00,014,433 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat
[2009/10/02 16:57:18 | 00,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2009/10/02 16:57:18 | 00,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2009/10/02 16:57:18 | 00,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2009/10/02 16:57:18 | 00,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2009/10/02 16:57:17 | 01,296,669 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT
[2009/10/02 16:57:17 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/10/02 16:57:17 | 00,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2009/10/02 16:57:17 | 00,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2009/10/02 16:57:17 | 00,034,063 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2009/10/02 16:57:17 | 00,016,535 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2009/10/02 16:57:17 | 00,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2009/10/02 16:57:17 | 00,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2009/10/02 16:57:16 | 02,144,487 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2009/10/02 16:57:16 | 00,522,220 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2009/10/02 16:56:30 | 00,148,400 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/10/02 16:55:44 | 00,000,211 | -HS- | C] () -- C:\boot.ini
[2009/10/02 16:55:39 | 00,000,283 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
========== LOP Check ==========
[2009/10/07 09:45:24 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/10/04 11:55:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/10/04 04:42:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intel
[2009/10/05 10:03:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SITEguard
[2009/10/07 13:45:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/10/04 02:39:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ZILLAbar
[2009/10/07 13:16:06 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\camster98\Application Data
[2009/10/07 13:39:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\Audacity
[2009/10/04 05:49:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\Dell
[2009/10/05 21:41:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\dvdcss
[2009/10/05 15:36:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\Hardcore
[2009/10/04 04:42:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\Intel
[2009/10/05 15:38:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\Juce VST Host
[2009/10/05 01:16:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\Notepad++
[2009/10/05 13:37:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\OpenCandy
[2009/10/05 15:37:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\Sawer
[2009/10/03 16:44:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\STOPzilla!
[2009/10/04 18:19:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\TeamViewer
[2009/10/07 09:31:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\uTorrent
[2009/10/03 16:20:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\Windows Desktop Search
[2009/10/05 16:42:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\Windows Search
[2009/10/04 01:40:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\camster98\Application Data\YTK Enhanced
[2009/10/04 11:53:45 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/23 07:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/10/07 11:40:04 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %systemroot%\system32\eventlog.dll >
[2008/04/14 00:41:54 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll
< %systemroot%\system32\scecli.dll >
[2008/04/14 00:42:06 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\netlogon.dll >
< %systemroot%\system32\cngaudit.dll >
< %systemroot%\system32\sceclt.dll >
< %systemroot%\ntelogon.dll >
< %systemroot%\system32\logevent.dll >
< End of report >
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/07 13:42
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA8828000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA666000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA80AB000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa89106b8
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa8910574
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa8910a52
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa891014c
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa891064e
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa891008c
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa89100f0
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa891076e
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa891072e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa89108ae
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xa89cd0b0
==EOF==