"System Security 2012" is holding my computer for ransom.
First showed up on November 6th.
Between all of the pop-ups and screen grey-outs,
I've managed to get Norton 360 installed and updated.
I've run NPE and FixTDSS.
Pop-ups have stopped but Norton is still reporting:
"Threat requiring manual removal detected: System Infected: Tidserv Activity 2."
I tried to post this from the infected computer twice last night but started getting redirects so I am posting from work. Computer is also bogged way down and slow to respond to mouse clicks.
Below is pasted OTL.txt - if you would like the EXTRAS file also, please let me know.
Anything you can do greatly appreciated.
Thanks and regards, Ken
OTL logfile created on: 11/13/2011 1:47:40 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Master\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.80 Mb Total Physical Memory | 99.43 Mb Available Physical Memory | 19.47% Memory free
1.22 Gb Paging File | 0.51 Gb Available in Paging File | 41.45% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 42.94 Gb Total Space | 27.91 Gb Free Space | 64.99% Space Free | Partition Type: NTFS
Drive D: | 19.86 Gb Total Space | 12.97 Gb Free Space | 65.31% Space Free | Partition Type: NTFS
Computer Name: MOBILEONE | User Name: Master | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/13 13:46:52 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Master\Desktop\OTLscr.scr
PRC - [2011/04/16 16:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\5.1.0.29\ccsvchst.exe
PRC - [2010/10/29 13:49:28 | 000,505,064 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2008/09/30 14:06:50 | 000,485,208 | ---- | M] (Nikon Corporation) -- C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
PRC - [2008/04/13 16:12:31 | 000,017,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ping.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/10/08 14:18:04 | 000,995,328 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2007/10/08 14:13:36 | 001,101,824 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2007/10/08 14:09:26 | 000,659,456 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2006/02/23 11:41:02 | 000,100,032 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2004/03/12 16:32:38 | 000,086,098 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
PRC - [2004/02/20 14:12:34 | 000,032,768 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\ISB Utility\ISBMgr.exe
PRC - [2004/02/19 18:51:36 | 000,274,432 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\HotKey Utility\HKWnd.exe
PRC - [2004/02/12 23:01:24 | 000,098,304 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\HotKey Utility\HKServ.exe
PRC - [2004/01/17 03:36:44 | 000,135,168 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
PRC - [2003/12/11 23:03:06 | 000,167,936 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
PRC - [2003/12/05 12:32:56 | 000,077,824 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\Giga Pocket\shwserv.exe
PRC - [2003/12/05 12:32:06 | 000,090,112 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\Giga Pocket\RM_SV.exe
PRC - [2003/11/07 17:21:28 | 000,114,688 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\Apoint.exe
PRC - [2003/10/06 19:26:10 | 000,229,376 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\usbsircs\USBsircs.exe
PRC - [2003/09/19 17:42:00 | 000,974,848 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
PRC - [2003/09/19 17:42:00 | 000,061,440 | ---- | M] () -- C:\WINDOWS\ATK0100\Hcontrol.exe
PRC - [2003/06/25 10:24:48 | 000,049,152 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\HP Software Update\hpwuSchd.exe
PRC - [2003/02/26 11:08:42 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\ApntEx.exe
PRC - [2002/08/20 10:29:26 | 000,040,960 | ---- | M] (Easy Systems Japan Ltd.) -- C:\WINDOWS\system32\ezSP_Px.exe
PRC - [2002/03/14 16:46:58 | 000,045,056 | ---- | M] (Primax Electronics Ltd.) -- C:\WINDOWS\system32\ico.exe
========== Modules (No Company Name) ==========
MOD - [2008/06/20 08:02:47 | 000,245,248 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll
MOD - [2008/06/20 08:02:47 | 000,245,248 | ---- | M] () -- \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2008/03/24 20:50:40 | 000,355,112 | ---- | M] () -- C:\WINDOWS\system32\msjetoledb40.dll
MOD - [2007/10/08 14:03:22 | 000,245,760 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2007/05/17 14:42:26 | 001,167,360 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\acAuth.dll
MOD - [2004/03/03 12:29:58 | 000,086,016 | ---- | M] () -- C:\WINDOWS\system32\ati2evxx.dll
MOD - [2003/12/05 12:32:06 | 000,024,576 | ---- | M] () -- C:\Program Files\Sony\Giga Pocket\RM_SVps.dll
MOD - [2003/09/19 17:42:00 | 000,974,848 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
MOD - [2003/09/19 17:42:00 | 000,061,440 | ---- | M] () -- C:\WINDOWS\ATK0100\Hcontrol.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/04/16 16:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe -- (N360)
SRV - [2006/02/23 11:41:02 | 002,045,632 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -- (LiveUpdate)
SRV - [2006/02/23 11:41:02 | 000,100,032 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)
SRV - [2004/11/02 16:59:50 | 000,316,544 | ---- | M] (Symantec Corporation) [Auto | Stopped] -- C:\Program Files\Common Files\Symantec Shared\Security Center\symwsc.exe -- (SymWSC)
SRV - [2004/03/12 16:33:54 | 000,118,784 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe -- (VAIO Entertainment Aggregation and Control Service)
SRV - [2004/03/12 16:32:38 | 000,086,098 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe -- (VAIO Entertainment File Import Service)
SRV - [2004/03/12 16:11:34 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe -- (VAIO Entertainment TV Device Arbitration Service)
SRV - [2004/03/12 15:57:42 | 000,278,528 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe -- (VAIO Entertainment UPnP Client Adapter)
SRV - [2004/03/12 11:20:34 | 001,691,648 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\vaio media integrated server\VMISrv.exe -- (VAIOMediaPlatform-IntegratedServer-AppServer)
SRV - [2004/03/05 12:35:34 | 000,184,320 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\vaio media integrated server\Platform\VmGateway.exe -- (VAIOMediaPlatform-Mobile-Gateway)
SRV - [2004/02/25 04:22:06 | 000,737,280 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe -- (VAIOMediaPlatform-VideoServer-UPnP) VAIO Media Video Server (UPnP)
SRV - [2004/02/25 04:22:06 | 000,737,280 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe -- (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP)
SRV - [2004/02/25 04:12:38 | 000,057,344 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe -- (VAIOMediaPlatform-VideoServer-HTTP) VAIO Media Video Server (HTTP)
SRV - [2004/02/25 04:12:38 | 000,057,344 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe -- (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP)
SRV - [2004/02/04 13:29:58 | 000,118,784 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Giga Pocket\halsv.exe -- (Sony TV Tuner Controller)
SRV - [2003/12/09 05:38:14 | 000,065,625 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe -- (PACSPTISVR)
SRV - [2003/12/09 05:32:58 | 000,065,622 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe -- (SPTISRV)
SRV - [2003/12/05 12:32:56 | 000,077,824 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\Giga Pocket\shwserv.exe -- (Giga Pocket Hardware Detector)
SRV - [2003/12/05 12:32:06 | 000,090,112 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Sony\Giga Pocket\RM_SV.exe -- (Sony TV Tuner Manager)
SRV - [2003/10/30 11:48:10 | 001,286,144 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe -- (VAIOMediaPlatform-VideoServer-AppServer)
SRV - [2003/08/11 00:07:38 | 000,065,795 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\hpzipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - [2011/11/10 19:55:22 | 000,106,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/11/10 19:55:21 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/11/08 20:25:23 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20111112.009\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/11/08 20:25:18 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20111112.009\NAVENG.SYS -- (NAVENG)
DRV - [2011/11/07 21:05:02 | 000,126,584 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/11/04 15:36:18 | 000,356,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20111111.030\IDSXpx86.sys -- (IDSxpx86)
DRV - [2011/10/27 23:14:16 | 000,818,808 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20111027.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2011/03/30 19:00:09 | 000,516,216 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\N360\0501000.01D\SRTSP.SYS -- (SRTSP)
DRV - [2011/03/30 19:00:09 | 000,050,168 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0501000.01D\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2011/03/21 16:39:49 | 000,369,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMTDI.SYS -- (SYMTDI)
DRV - [2011/03/14 18:31:23 | 000,744,568 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMEFA.SYS -- (SymEFA)
DRV - [2011/01/26 22:47:10 | 000,340,088 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMDS.SYS -- (SymDS)
DRV - [2010/11/15 17:45:33 | 000,136,312 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0501000.01D\Ironx86.SYS -- (SymIRON)
DRV - [2009/10/20 10:10:08 | 000,040,552 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\hotcore3.sys -- (hotcore3)
DRV - [2007/08/27 11:10:36 | 000,012,288 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2007/07/25 17:44:28 | 002,210,048 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2004/10/07 17:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/03/19 18:10:54 | 000,224,896 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SONYTVC.sys -- (SONYTVC)
DRV - [2004/03/04 12:51:20 | 000,064,512 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifmsony.sys -- (tifmsony)
DRV - [2004/03/03 12:31:22 | 000,679,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/02/13 18:40:16 | 000,610,796 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/02/09 14:58:06 | 000,401,408 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS)
DRV - [2004/01/02 02:52:00 | 001,646,720 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w22n51.sys -- (w22n51) Intel®
DRV - [2003/10/14 16:08:22 | 000,197,120 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2003/10/14 16:05:48 | 000,679,808 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2003/10/14 16:04:16 | 001,043,072 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2003/09/29 13:31:38 | 000,094,601 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2003/09/19 17:42:00 | 000,005,786 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)
DRV - [2003/03/14 10:12:50 | 000,279,680 | ---- | M] (OPEN INTERFACE.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\oivmvcom.sys -- (oibtvcom)
DRV - [2003/01/06 17:20:14 | 000,015,616 | ---- | M] (OPEN INTERFACE.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\oivmctrl.sys -- (oivmctrl)
DRV - [2002/11/18 17:20:44 | 000,030,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gv3.sys -- (gv3)
DRV - [2002/06/28 18:21:40 | 000,017,251 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PELMOUSE.SYS -- (pelmouse)
DRV - [2001/08/17 04:51:22 | 000,037,040 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SonyPI.sys -- (SPI)
DRV - [2001/07/24 10:34:34 | 000,007,520 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PELUSBlf.SYS -- (pelusblf)
DRV - [2000/12/05 16:18:02 | 000,003,952 | R--- | M] (Sony Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\DMICall.sys -- (DMICall)
DRV - [2000/11/09 19:15:08 | 000,048,896 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SonyNC.sys -- (SNC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Master\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2910: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Master\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2011/11/08 17:14:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_3_6 [2011/11/13 07:08:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape 7.02\Extensions\\Components: C:\Program Files\Netscape\Netscape\Components [2008/12/28 10:35:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape 7.02\Extensions\\Plugins: C:\Program Files\Netscape\Netscape\Plugins [2011/06/29 06:48:11 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Documents and Settings\Master\Application Data\Move Networks [2009/11/25 19:05:45 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Netscape 7.02\Extensions\\Components: C:\Program Files\Netscape\Netscape\Components [2008/12/28 10:35:17 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Netscape 7.02\Extensions\\Plugins: C:\Program Files\Netscape\Netscape\Plugins [2011/06/29 06:48:11 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2011/11/09 22:08:24 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\ips\ipsbho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] "rundll32.exe" irprops.cpl,,BluetoothAuthenticationAgent File not found
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe (Easy Systems Japan Ltd.)
O4 - HKLM..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe ()
O4 - HKLM..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe (Sony Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\WINDOWS\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [nH0qaTGzF8234A] C:\WINDOWS\system32\WfbIKedU1.exe File not found
O4 - HKLM..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [VAIO Update 2] C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
O4 - HKCU..\Run: [ISMPack8] "C:\Program Files\ISM2\ISMPack8.exe" File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Remocon Driver.lnk = C:\Program Files\Sony\usbsircs\USBsircs.exe (Sony Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\system32\wshbth.dll File not found
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} http://supportsoft.a...ad/tgctlins.cab (Support.com Installer)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://activation.rr...ads/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} http://www.alternati.../00/alttiff.cab (AlternaTIFF ActiveX)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1193877428180 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1238513359353 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {A305FBA3-4A87-483D-A53B-138F9F635357} http://ciscdb.sel.so...tect/PCInfo.CAB (PCInfo.CMClass)
O16 - DPF: {C77FB8C0-8B6D-440E-AC26-2BD39E97E8F2} http://speedtest.ade...TESTACTIVEX.CAB (SpdTCtl Class)
O16 - DPF: {CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://www.adobe.com...obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmi...inAxControl.CAB (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8ECCEF79-9DEE-4EE4-9179-745645BF2969}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\Master\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Master\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/03/26 18:11:49 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{c6118c00-a26d-11df-9f48-080046da2185}\Shell\AutoRun\command - "" = G:\Get_Started_for_Win.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/13 13:46:35 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Master\Desktop\OTLscr.scr
[2011/11/13 11:25:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Start Menu\Programs\HiJackThis
[2011/11/09 20:47:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\pvUJ1scHq
[2011/11/09 20:47:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\gQAX5jQXymZtOrI
[2011/11/08 20:59:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\P2edvJ1sY0aT9R8
[2011/11/08 20:59:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\NZ4tnL3fI2dUwY
[2011/11/08 20:38:42 | 001,932,256 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Master\Desktop\FixTDSS.exe
[2011/11/08 20:13:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\ZB8olFBoEViW
[2011/11/08 20:13:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\OAX5ymP4nLrb2v1
[2011/11/08 19:59:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\UTNpR8E7WCuQ5Q5
[2011/11/08 19:59:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\xL3rfIKevJw
[2011/11/08 17:14:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\DGN9pRF8lD7kCjX
[2011/11/08 17:14:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\cgnOLrfI3fI2v1c
[2011/11/08 16:42:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Local Settings\Application Data\NPE
[2011/11/08 16:39:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\Tific
[2011/11/08 16:38:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Local Settings\Application Data\Symantec
[2011/11/08 16:34:49 | 002,562,040 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Master\Desktop\NPE.exe
[2011/11/08 16:12:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\YyhmP4gO3fI2v
[2011/11/08 16:12:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\VnOL3Kv1s
[2011/11/07 22:05:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\r4tgO3rbKevJsHa
[2011/11/07 22:05:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\ElEFBolD7kS6Q5m
[2011/11/07 21:35:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\My Documents\Symantec
[2011/11/07 21:30:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\BV7iS6uQXym4n3b
[2011/11/07 21:30:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\HOL3rbI2fI2
[2011/11/07 21:13:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/11/07 21:13:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/11/07 21:13:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/11/07 21:05:03 | 000,126,584 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2011/11/07 21:05:03 | 000,060,872 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2011/11/07 21:04:37 | 000,744,568 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symefa.sys
[2011/11/07 21:04:37 | 000,369,784 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symtdi.sys
[2011/11/07 21:04:37 | 000,331,384 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symtdiv.sys
[2011/11/07 21:04:37 | 000,296,568 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symnets.sys
[2011/11/07 21:04:36 | 000,516,216 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0501000.01D\srtsp.sys
[2011/11/07 21:04:36 | 000,340,088 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symds.sys
[2011/11/07 21:04:36 | 000,050,168 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0501000.01D\srtspx.sys
[2011/11/07 21:04:35 | 000,136,312 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0501000.01D\ironx86.sys
[2011/11/07 21:02:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360\0501000.01D
[2011/11/07 21:00:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
[2011/11/07 20:59:34 | 000,000,000 | ---D | C] -- C:\Program Files\Norton 360
[2011/11/07 20:59:33 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2011/11/07 20:59:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Norton 360
[2011/11/07 20:57:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2011/11/07 20:50:06 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2011/11/07 20:50:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2011/11/07 20:45:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\NwscY0qxG9zFoD
[2011/11/07 20:45:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\fgnOLtgO3fKeU
[2011/11/07 18:30:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\BujQA5ymZtnLf
[2011/11/07 18:30:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\JkWSCikS6jA5m4n
[2011/11/07 16:44:12 | 000,000,000 | ---D | C] -- C:\NBRT
[2011/11/07 16:39:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\z4tgnL3fI2dUwYq
[2011/11/07 16:39:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\n8olEViW6jA5m4n
[2011/11/06 17:32:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\jFB8oED7kS6jXPt
[2011/11/06 17:32:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\KnOL3fbKrb
[2011/11/06 17:18:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\hlD7iWS7kSuQ5m4
[2011/11/06 17:18:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\B8VEk6A5hPOKJcq
[2011/11/06 17:13:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\jSC6uAXyZg3n3
[2011/11/06 17:13:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\DXym4gtLf2JsaGz
[2011/11/06 17:10:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\r7ikWC6jA5hPtOr
[2011/11/06 17:10:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\CxTGNpzF8lD
[2011/11/06 17:10:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\u4tnfedUwcHqT9R
[2011/11/06 17:10:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\UikWS6uQXymZgL
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/13 14:12:00 | 000,000,366 | ---- | M] () -- C:\WINDOWS\tasks\Symantec NetDetect.job
[2011/11/13 14:04:33 | 000,006,192 | ---- | M] () -- C:\{EF20FA85-E5E2-4BB0-94F0-75E394882A2A}
[2011/11/13 13:46:52 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Master\Desktop\OTLscr.scr
[2011/11/13 13:42:34 | 000,148,483 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\OTL.exe
[2011/11/13 13:41:34 | 000,031,016 | ---- | M] () -- C:\{D13AD4D8-E9F6-4C42-BDD6-CD9DCC7B0B5D}
[2011/11/13 13:25:35 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/11/13 12:56:43 | 000,031,128 | ---- | M] () -- C:\{11F85857-A17D-40BD-8405-1DE1D15CED7A}
[2011/11/13 12:49:10 | 000,002,539 | ---- | M] () -- C:\Documents and Settings\Master\Application Data\Microsoft\Internet Explorer\Quick Launch\Lori email.lnk
[2011/11/13 11:57:20 | 000,006,192 | ---- | M] () -- C:\{925ADB1A-73F8-47D2-89C0-E3425BA2B0EC}
[2011/11/13 11:37:51 | 000,006,192 | ---- | M] () -- C:\{047A39B3-68A9-408E-AC83-F613C74A846F}
[2011/11/13 11:26:29 | 000,002,449 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\HiJackThis.lnk
[2011/11/13 09:51:33 | 000,006,192 | ---- | M] () -- C:\{6169566C-31EB-41A7-99B5-BDDE2BE3DCF6}
[2011/11/13 09:09:03 | 000,006,192 | ---- | M] () -- C:\{2A0DD5A0-5A3C-4745-8E31-1935DC3B937F}
[2011/11/13 07:08:52 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/13 07:08:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/13 07:08:29 | 535,678,976 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/12 21:41:14 | 000,006,192 | ---- | M] () -- C:\{E601309A-60D9-4CE0-A38F-506D400DD2C6}
[2011/11/12 21:26:31 | 000,031,744 | ---- | M] () -- C:\{132E73FA-5EE4-4E30-BE99-853A87AFDC14}
[2011/11/12 20:28:37 | 000,006,192 | ---- | M] () -- C:\{B88FDC18-95E4-4587-98F3-342200DA2942}
[2011/11/12 19:57:29 | 000,006,192 | ---- | M] () -- C:\{CF8F422B-442F-45FF-8330-AC0A1F87D283}
[2011/11/12 19:35:43 | 000,006,192 | ---- | M] () -- C:\{0D8712D4-B08C-4724-A3F3-4AF590282D6F}
[2011/11/12 19:25:40 | 000,006,192 | ---- | M] () -- C:\{A117FCBD-D698-4689-BBC9-D5F331B1CE2F}
[2011/11/12 19:15:28 | 000,006,192 | ---- | M] () -- C:\{A987ED71-8836-4D1D-9811-BFC50DA0F955}
[2011/11/12 18:32:09 | 000,006,192 | ---- | M] () -- C:\{55459539-6714-44B3-878B-8C487A3CC485}
[2011/11/12 18:11:00 | 000,006,192 | ---- | M] () -- C:\{A053E252-95C0-4E12-9EDA-ED3D46F93715}
[2011/11/12 17:49:58 | 000,006,192 | ---- | M] () -- C:\{2897AA25-8201-4BD3-9425-2A7D29BF29F2}
[2011/11/12 17:20:12 | 000,006,192 | ---- | M] () -- C:\{4F35E1EC-59E2-4A3B-AE7C-CF604C2CD533}
[2011/11/12 16:27:51 | 000,006,192 | ---- | M] () -- C:\{DA62E0B4-B167-45C4-801A-AA40823616F4}
[2011/11/12 16:16:55 | 000,006,192 | ---- | M] () -- C:\{36B769E7-162D-4099-A97D-02E8D7AF765F}
[2011/11/12 13:19:30 | 000,006,192 | ---- | M] () -- C:\{984B3819-E2C0-42EE-A63D-5A950CDC5374}
[2011/11/12 13:07:37 | 000,006,192 | ---- | M] () -- C:\{CC6DD585-3CEC-4B57-8E97-17016186DAB7}
[2011/11/12 12:57:54 | 000,006,192 | ---- | M] () -- C:\{4EA88700-BC29-4D9E-B7B9-A40BF2515B43}
[2011/11/11 16:51:37 | 000,006,192 | ---- | M] () -- C:\{D888FE9F-EF68-463C-A530-642FD4DAD660}
[2011/11/11 14:48:16 | 000,006,192 | ---- | M] () -- C:\{84DD3F56-806A-4469-A802-5BF17CADBC1E}
[2011/11/11 13:25:37 | 000,008,976 | ---- | M] () -- C:\{187640F1-E4B3-449C-8078-F78CC170F32F}
[2011/11/11 08:49:46 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Master\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/11/10 23:14:28 | 000,676,694 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\Cat.DB
[2011/11/10 22:41:46 | 000,006,192 | ---- | M] () -- C:\{F4B0E654-1E47-4C65-8BCB-950CA5D8D1A0}
[2011/11/10 21:04:17 | 000,006,192 | ---- | M] () -- C:\{1C24970D-9E9B-44E5-A518-060201AA04B7}
[2011/11/09 22:26:48 | 000,001,470 | ---- | M] () -- C:\Documents and Settings\Master\Application Data\SMRResults210.dat
[2011/11/09 22:09:36 | 000,000,211 | ---- | M] () -- C:\boot.ini
[2011/11/09 22:08:24 | 000,001,260 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.bak
[2011/11/09 22:08:24 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/11/08 20:38:50 | 001,932,256 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Master\Desktop\FixTDSS.exe
[2011/11/08 16:42:01 | 002,562,040 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Master\Desktop\NPE.exe
[2011/11/07 21:05:02 | 000,126,584 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2011/11/07 21:05:02 | 000,060,872 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2011/11/07 21:05:02 | 000,007,468 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2011/11/07 21:05:02 | 000,000,806 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2011/11/07 21:04:49 | 000,001,900 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2011/11/07 21:02:52 | 000,001,848 | ---- | M] () -- C:\Documents and Settings\Master\Application Data\ldr.ini
[2011/11/07 18:42:36 | 606,076,928 | -HS- | M] () -- C:\NBRTPage.sys
[2011/11/06 17:14:40 | 000,445,082 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/11/06 17:14:40 | 000,072,792 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/10/27 20:44:00 | 000,000,480 | ---- | M] () -- C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Master at 8 44 PM.job
[2011/10/22 15:56:39 | 000,000,804 | ---- | M] () -- C:\Documents and Settings\Master\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/10/22 15:56:39 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\Windows Media Player.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/13 13:42:16 | 000,148,483 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\OTL.exe
[2011/11/13 13:41:34 | 000,031,016 | ---- | C] () -- C:\{D13AD4D8-E9F6-4C42-BDD6-CD9DCC7B0B5D}
[2011/11/13 12:56:43 | 000,031,128 | ---- | C] () -- C:\{11F85857-A17D-40BD-8405-1DE1D15CED7A}
[2011/11/13 11:57:20 | 000,006,192 | ---- | C] () -- C:\{925ADB1A-73F8-47D2-89C0-E3425BA2B0EC}
[2011/11/13 11:37:51 | 000,006,192 | ---- | C] () -- C:\{047A39B3-68A9-408E-AC83-F613C74A846F}
[2011/11/13 09:51:33 | 000,006,192 | ---- | C] () -- C:\{6169566C-31EB-41A7-99B5-BDDE2BE3DCF6}
[2011/11/13 09:09:03 | 000,006,192 | ---- | C] () -- C:\{2A0DD5A0-5A3C-4745-8E31-1935DC3B937F}
[2011/11/12 21:41:14 | 000,006,192 | ---- | C] () -- C:\{E601309A-60D9-4CE0-A38F-506D400DD2C6}
[2011/11/12 21:26:31 | 000,031,744 | ---- | C] () -- C:\{132E73FA-5EE4-4E30-BE99-853A87AFDC14}
[2011/11/12 20:28:37 | 000,006,192 | ---- | C] () -- C:\{B88FDC18-95E4-4587-98F3-342200DA2942}
[2011/11/12 19:57:29 | 000,006,192 | ---- | C] () -- C:\{CF8F422B-442F-45FF-8330-AC0A1F87D283}
[2011/11/12 19:35:43 | 000,006,192 | ---- | C] () -- C:\{0D8712D4-B08C-4724-A3F3-4AF590282D6F}
[2011/11/12 19:25:40 | 000,006,192 | ---- | C] () -- C:\{A117FCBD-D698-4689-BBC9-D5F331B1CE2F}
[2011/11/12 19:15:28 | 000,006,192 | ---- | C] () -- C:\{A987ED71-8836-4D1D-9811-BFC50DA0F955}
[2011/11/12 18:32:09 | 000,006,192 | ---- | C] () -- C:\{55459539-6714-44B3-878B-8C487A3CC485}
[2011/11/12 18:11:00 | 000,006,192 | ---- | C] () -- C:\{A053E252-95C0-4E12-9EDA-ED3D46F93715}
[2011/11/12 17:49:58 | 000,006,192 | ---- | C] () -- C:\{2897AA25-8201-4BD3-9425-2A7D29BF29F2}
[2011/11/12 17:20:12 | 000,006,192 | ---- | C] () -- C:\{4F35E1EC-59E2-4A3B-AE7C-CF604C2CD533}
[2011/11/12 16:27:51 | 000,006,192 | ---- | C] () -- C:\{DA62E0B4-B167-45C4-801A-AA40823616F4}
[2011/11/12 16:16:55 | 000,006,192 | ---- | C] () -- C:\{36B769E7-162D-4099-A97D-02E8D7AF765F}
[2011/11/12 13:19:30 | 000,006,192 | ---- | C] () -- C:\{984B3819-E2C0-42EE-A63D-5A950CDC5374}
[2011/11/12 13:07:37 | 000,006,192 | ---- | C] () -- C:\{CC6DD585-3CEC-4B57-8E97-17016186DAB7}
[2011/11/12 12:57:49 | 000,006,192 | ---- | C] () -- C:\{4EA88700-BC29-4D9E-B7B9-A40BF2515B43}
[2011/11/11 16:51:37 | 000,006,192 | ---- | C] () -- C:\{D888FE9F-EF68-463C-A530-642FD4DAD660}
[2011/11/11 14:48:16 | 000,006,192 | ---- | C] () -- C:\{84DD3F56-806A-4469-A802-5BF17CADBC1E}
[2011/11/11 13:25:37 | 000,008,976 | ---- | C] () -- C:\{187640F1-E4B3-449C-8078-F78CC170F32F}
[2011/11/10 22:41:46 | 000,006,192 | ---- | C] () -- C:\{F4B0E654-1E47-4C65-8BCB-950CA5D8D1A0}
[2011/11/10 21:04:17 | 000,006,192 | ---- | C] () -- C:\{1C24970D-9E9B-44E5-A518-060201AA04B7}
[2011/11/09 22:26:47 | 000,001,470 | ---- | C] () -- C:\Documents and Settings\Master\Application Data\SMRResults210.dat
[2011/11/08 16:09:48 | 535,678,976 | -HS- | C] () -- C:\hiberfil.sys
[2011/11/07 21:15:28 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/11/07 21:05:32 | 000,676,694 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\Cat.DB
[2011/11/07 21:05:03 | 000,007,468 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2011/11/07 21:05:03 | 000,000,806 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2011/11/07 21:04:49 | 000,001,900 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2011/11/07 21:04:37 | 000,007,877 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symnetv.cat
[2011/11/07 21:04:37 | 000,007,458 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symnet.cat
[2011/11/07 21:04:37 | 000,003,373 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symefa.inf
[2011/11/07 21:04:37 | 000,001,474 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symnetv.inf
[2011/11/07 21:04:37 | 000,001,446 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symnet.inf
[2011/11/07 21:04:36 | 000,007,456 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symefa.cat
[2011/11/07 21:04:36 | 000,007,454 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\srtspx.cat
[2011/11/07 21:04:36 | 000,007,450 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\srtsp.cat
[2011/11/07 21:04:36 | 000,002,792 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symds.inf
[2011/11/07 21:04:36 | 000,001,389 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\srtspx.inf
[2011/11/07 21:04:36 | 000,001,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\srtsp.inf
[2011/11/07 21:04:36 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\isolate.ini
[2011/11/07 21:04:35 | 000,007,528 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\iron.cat
[2011/11/07 21:04:35 | 000,000,742 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\iron.inf
[2011/11/07 21:03:21 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0501000.01D\symds.cat
[2011/11/07 16:44:11 | 606,076,928 | -HS- | C] () -- C:\NBRTPage.sys
[2011/11/06 17:10:25 | 000,001,848 | ---- | C] () -- C:\Documents and Settings\Master\Application Data\ldr.ini
[2011/09/05 09:39:27 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT
[2011/08/21 14:23:07 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2011/06/01 21:10:22 | 000,000,007 | ---- | C] () -- C:\WINDOWS\System32\mkghj.dll
[2010/04/25 13:03:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX.INI
[2010/02/21 09:19:57 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Multipressor
[2010/02/21 09:19:57 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Master\Application Data\Mallets
[2010/02/21 08:08:44 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\MediaFolder
[2010/02/21 08:08:44 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Master\Application Data\Machines
[2008/06/21 15:47:07 | 000,034,468 | ---- | C] () -- C:\WINDOWS\hpomdl03.dat
[2008/06/21 15:47:07 | 000,028,922 | ---- | C] () -- C:\WINDOWS\hpoins03.dat
[2007/11/04 08:07:46 | 000,616,379 | -HS- | C] () -- C:\WINDOWS\System32\jfkolrqq.ini
[2007/11/02 14:46:19 | 000,578,905 | -HS- | C] () -- C:\WINDOWS\System32\inujqinv.ini
[2007/10/30 09:02:14 | 000,577,927 | -HS- | C] () -- C:\WINDOWS\System32\etsbpddq.ini
[2007/05/28 11:04:12 | 000,000,188 | ---- | C] () -- C:\WINDOWS\guitar.ini
[2007/03/22 18:11:06 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2007/03/07 22:08:13 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2006/05/22 15:09:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
[2006/04/07 16:15:32 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\pnpchk.exe
[2006/04/07 16:10:11 | 000,000,008 | ---- | C] () -- C:\WINDOWS\usrwiz.ini
[2005/10/29 12:51:08 | 000,684,032 | ---- | C] () -- C:\WINDOWS\libeay32.dll
[2005/10/29 12:51:08 | 000,155,648 | ---- | C] () -- C:\WINDOWS\ssleay32.dll
[2004/10/02 13:10:10 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/10/02 12:36:11 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2004/09/18 19:51:20 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Master\Local Settings\Application Data\fusioncache.dat
[2004/09/11 11:18:08 | 000,024,576 | ---- | C] () -- C:\Documents and Settings\Master\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/04/12 21:02:58 | 000,000,069 | ---- | C] () -- C:\WINDOWS\System32\Sony XBRITE.ini
[2004/04/12 21:02:34 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/04/12 20:55:42 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\Px.ini
[2004/04/12 20:49:20 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2004/04/12 20:49:20 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2004/04/12 20:49:20 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2004/04/12 20:49:20 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2004/04/12 20:49:20 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2004/04/12 20:49:20 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2004/03/29 13:32:10 | 000,000,921 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2004/03/29 13:30:11 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\Cpuinf32.dll
[2004/03/29 13:24:04 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\TDI-SonyOMG.dll
[2004/03/29 13:23:18 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\pxhpinst.exe
[2004/03/29 13:22:38 | 000,090,832 | ---- | C] () -- C:\WINDOWS\NSUninst.exe
[2004/03/29 13:22:34 | 000,009,192 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2004/03/29 11:05:09 | 001,137,512 | ---- | C] () -- C:\WINDOWS\q323183_wxp_sp2_x86_enu.exe
[2004/03/29 10:53:40 | 000,526,184 | ---- | C] () -- C:\WINDOWS\q329692.exe
[2004/03/29 10:46:52 | 000,236,392 | ---- | C] () -- C:\WINDOWS\q329112.exe
[2004/03/29 10:44:37 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/03/29 10:38:10 | 000,000,032 | ---- | C] () -- C:\WINDOWS\System32\elcric.dat
[2004/03/26 18:43:26 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/03/26 18:23:07 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2004/03/26 18:18:00 | 000,000,800 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/03/26 18:13:52 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/03/26 18:09:55 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/03/26 16:59:46 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\e1000msg.dll
[2004/03/26 16:59:42 | 000,372,428 | ---- | C] () -- C:\WINDOWS\System32\drivers\SNYTVC6.DAT
[2004/03/26 16:59:42 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2004/03/26 16:59:28 | 000,005,786 | ---- | C] () -- C:\WINDOWS\System32\drivers\ATKACPI.sys
[2004/03/26 16:59:20 | 000,397,312 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.exe
[2004/03/26 16:59:20 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
[2004/03/26 16:59:02 | 000,000,730 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2004/03/26 16:58:41 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/03/26 16:58:41 | 000,445,082 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/03/26 16:58:41 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/03/26 16:58:41 | 000,072,792 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/03/26 16:58:41 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/03/26 16:58:41 | 000,004,530 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/03/26 16:58:40 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/03/26 16:58:38 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/03/26 16:58:38 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/03/26 16:58:34 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/03/26 16:58:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/03/26 10:04:38 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/03/26 10:03:53 | 000,188,200 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/08/11 00:07:40 | 000,565,248 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2003/07/23 08:53:30 | 000,373,967 | ---- | C] () -- C:\WINDOWS\ml-uninstall-v10.exe
[2003/01/07 14:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/11/14 12:58:04 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2002/11/14 12:58:04 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2002/11/14 12:58:02 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2002/11/14 12:58:02 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2002/11/14 12:58:02 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
[2002/08/06 11:55:37 | 000,024,576 | ---- | C] () -- C:\WINDOWS\ml-WA3Shutdown.exe
[2002/06/12 12:21:12 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\winchip.dll
[2002/04/02 17:08:34 | 000,311,108 | ---- | C] () -- C:\WINDOWS\ml-cleanup.exe
[2002/04/02 17:08:32 | 000,036,868 | ---- | C] () -- C:\WINDOWS\ml-winamp-shutdown.exe
========== LOP Check ==========
[2010/02/21 08:08:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Automatic Filter
[2010/02/21 09:19:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bubble Noise
[2010/08/07 13:59:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/06/03 12:35:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CA
[2010/08/07 14:28:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\copypart
[2010/02/21 09:19:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2010/08/07 14:28:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\explauncher
[2010/08/07 14:28:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\launcher
[2010/02/21 08:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2004/09/18 11:11:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OLYMPUS
[2010/08/07 14:29:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\redistpart
[2010/02/21 09:19:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2008/03/21 15:46:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/28 11:04:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2006/01/29 18:35:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\.bittorrent
[2011/11/06 17:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\B8VEk6A5hPOKJcq
[2011/11/07 18:30:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\BujQA5ymZtnLf
[2011/11/07 21:30:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\BV7iS6uQXym4n3b
[2011/11/08 17:14:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\cgnOLrfI3fI2v1c
[2005/05/14 11:16:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Common Files
[2011/11/06 17:10:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\CxTGNpzF8lD
[2011/11/08 17:14:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\DGN9pRF8lD7kCjX
[2011/11/06 17:13:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\DXym4gtLf2JsaGz
[2011/11/07 22:05:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\ElEFBolD7kS6Q5m
[2011/11/07 20:45:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\fgnOLtgO3fKeU
[2010/08/07 10:11:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\GARMIN
[2011/11/09 20:47:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\gQAX5jQXymZtOrI
[2011/11/06 17:18:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\hlD7iWS7kSuQ5m4
[2011/11/07 21:30:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\HOL3rbI2fI2
[2006/06/30 15:07:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\InterVideo
[2011/11/06 17:32:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\jFB8oED7kS6jXPt
[2011/11/07 18:30:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\JkWSCikS6jA5m4n
[2011/11/06 17:13:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\jSC6uAXyZg3n3
[2011/11/06 17:32:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\KnOL3fbKrb
[2004/09/11 11:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Leadertech
[2011/11/07 16:39:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\n8olEViW6jA5m4n
[2010/04/25 12:57:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Nikon
[2011/11/07 20:45:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\NwscY0qxG9zFoD
[2011/11/08 20:59:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\NZ4tnL3fI2dUwY
[2011/11/08 20:13:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\OAX5ymP4nLrb2v1
[2011/11/08 20:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\P2edvJ1sY0aT9R8
[2011/11/09 20:52:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\pvUJ1scHq
[2011/11/07 22:05:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\r4tgO3rbKevJsHa
[2011/11/06 17:10:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\r7ikWC6jA5hPtOr
[2006/12/31 14:57:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Roni Music
[2004/09/21 20:02:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Template
[2011/11/08 16:39:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Tific
[2011/11/06 17:10:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\u4tnfedUwcHqT9R
[2011/11/06 17:10:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\UikWS6uQXymZgL
[2011/11/08 19:59:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\UTNpR8E7WCuQ5Q5
[2008/03/21 15:46:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Viewpoint
[2011/11/08 16:12:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\VnOL3Kv1s
[2011/11/08 19:59:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\xL3rfIKevJw
[2011/11/08 16:12:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\YyhmP4gO3fI2v
[2011/11/07 16:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\z4tgnL3fI2dUwYq
[2011/11/08 20:13:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\ZB8olFBoEViW
[2011/10/27 20:44:00 | 000,000,480 | ---- | M] () -- C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Master at 8 44 PM.job
[2004/10/01 17:50:01 | 000,000,258 | ---- | M] () -- C:\WINDOWS\Tasks\Registration reminder 3.job
========== Purity Check ==========
< End of report >