Gringo, below is otl log. I am still having to download these programs onto my smartphone and then to move to computer as I can't download to computer.
OTL logfile created on: 10/13/2011 4:44:10 AM - Run 5
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: | Country: | Language: | Date Format:
3.00 Gb Total Physical Memory | 2.45 Gb Available Physical Memory | 81.80% Memory free
4.34 Gb Paging File | 3.96 Gb Available in Paging File | 91.27% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 2.84 Gb Free Space | 3.82% Space Free | Partition Type: NTFS
Drive F: | 7.39 Gb Total Space | 1.50 Gb Free Space | 20.31% Space Free | Partition Type: FAT32
Computer Name: WXP-G5N1Q91 | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
========== Modules (No Company Name) ========== MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll ()
MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
MOD - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\3.1.26.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
MOD - C:\Program Files\Flip Video\FlipShare\Core.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\qca2.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtGui4.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtCore4.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtXml4.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtSql4.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.61.0__db937bc2d44ff139\System.Data.SQLite.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\log4net\1.2.10.0__1b44e1d426115821\log4net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\2.0.445.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll ()
MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll ()
========== Win32 Services (SafeList) ========== SRV - (MSDTC) -- File not found
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (vToolbarUpdater) -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (FlipShare Service) -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (ACDaemon) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2) -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
========== Driver Services (SafeList) ========== DRV - (MBAMProtector) -- C:\WINDOWS\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) -- C:\WINDOWS\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) -- C:\WINDOWS\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (BVRPMPR5) -- C:\WINDOWS\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (NVHDA) -- C:\WINDOWS\System32\drivers\nvhda32.sys (NVIDIA Corporation)
DRV - (HTCAND32) -- C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV - (WUSB54GCv3) -- C:\WINDOWS\System32\DRIVERS\WUSB54GCv3.sys (Ralink Technology, Corp.)
DRV - (Changer) -- C:\WINDOWS\System32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) -- C:\WINDOWS\System32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (ArcCD) -- C:\WINDOWS\System32\drivers\ArcCD.sys (ArcSoft Inc.)
DRV - (ArcUdfs) -- C:\WINDOWS\System32\drivers\ArcUdfs.sys (ArcSoft Inc.)
DRV - (Afc) -- C:\WINDOWS\System32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (Symmpi) -- C:\WINDOWS\System32\DRIVERS\symmpi.sys (LSI Logic)
DRV - (ati2mtag) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (aarich) -- C:\WINDOWS\system32\DRIVERS\aarich.sys (Adaptec, Inc.)
DRV - (b57w2k) -- C:\WINDOWS\System32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (a320raid) -- C:\WINDOWS\System32\DRIVERS\a320raid.sys (Adaptec, Inc.)
DRV - (senfilt) -- C:\WINDOWS\System32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (aac) -- C:\WINDOWS\System32\DRIVERS\aac.sys (Adaptec, Inc.)
DRV - (fasttx2k) -- C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (vmscsi) -- C:\WINDOWS\System32\drivers\vmscsi.sys (VMware, Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Paul\Application Data\Move Networks\plugins\npqmp071705000014.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@photodex.com/PhotodexPresenter: C:\Program Files\Photodex Presenter\npPxPlay.dll ( )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{F1A95211-58FD-4FD2-9F54-92535BF5C26A}: C:\Documents and Settings\Paul\Local Settings\Application Data\{F1A95211-58FD-4FD2-9F54-92535BF5C26A}
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/28 18:32:35 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2011/10/12 20:42:13 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Fast Browser Search Toolbar Helper) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll File not found
O3 - HKLM\..\Toolbar: (Fast Browser Search Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll File not found
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Fast Browser Search Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll File not found
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Fast Browser Search Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll File not found
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ArcSoft MediaImpression Monitor] C:\Program Files\Kodak\MediaImpression\ArcMonitor.exe (ArcSoft, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\RunOnce: [AFD] C:\WINDOWS\Regedit.exe /s "C:\ComboFix\SW_AFD.reg" File not found
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Administrator\Application Data [2010/07/02 06:02:29 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Administrator\Cookies [2011/10/07 20:31:51 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Administrator\Desktop [2011/10/11 20:37:48 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Administrator\Favorites [2009/05/31 23:52:52 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Administrator\IECompatCache [2010/06/20 00:00:46 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Administrator\IETldCache [2010/06/19 23:07:37 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Administrator\Local Settings [2011/10/12 20:44:53 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Administrator\My Documents [2009/05/30 07:08:31 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Administrator\NetHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Administrator\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\Administrator\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\Administrator\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\Administrator\PrintHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Administrator\PrivacIE [2011/10/07 20:31:04 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Administrator\Recent [2011/10/07 20:32:12 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Administrator\SendTo [2006/07/28 13:17:21 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu [2006/07/28 06:03:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Administrator\Templates [2006/07/28 13:09:47 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Administrator\UserData [2009/05/30 07:20:07 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\All Users\Application Data [2011/09/26 15:42:54 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\All Users\Bank of America [2009/06/19 02:47:05 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\All Users\Desktop [2011/10/11 21:14:26 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\All Users\Documents [2010/08/28 19:37:37 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\All Users\DRM [2009/06/20 22:54:20 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\All Users\Favorites [2006/07/28 06:03:42 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\All Users\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\All Users\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu [2011/05/08 17:55:39 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\All Users\Templates [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\Application Data [2011/10/12 20:06:11 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\Cookies [2011/04/28 19:46:37 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\Desktop [2010/07/02 00:05:18 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\Favorites [2010/07/02 00:05:30 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\IETldCache [2010/07/02 00:05:12 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\Local Settings [2011/10/12 20:44:53 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\My Documents [2010/07/02 00:05:29 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\NetHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\bleepingputer\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\bleepingputer\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\bleepingputer\PrintHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\PrivacIE [2010/07/04 19:35:59 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\Recent [2010/07/02 00:05:29 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\SendTo [2006/07/28 13:17:21 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\Start Menu [2006/07/28 06:03:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\bleepingputer\Templates [2006/07/28 13:09:47 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Cara\Application Data [2011/09/19 20:44:27 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Cara\Cookies [2011/10/07 07:51:55 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Cara\Desktop [2011/03/11 19:32:42 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Cara\Favorites [2011/07/23 09:02:07 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Cara\IECompatCache [2011/10/07 07:47:09 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Cara\IETldCache [2010/04/10 18:14:11 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Cara\Local Settings [2011/10/12 20:44:53 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Cara\My Documents [2011/10/11 20:37:34 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Cara\NetHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Cara\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\Cara\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\Cara\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\Cara\PrintHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Cara\PrivacIE [2010/04/10 18:15:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Cara\Recent [2011/08/07 15:37:52 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Cara\SendTo [2006/07/28 13:17:21 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Cara\Start Menu [2006/07/28 06:03:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Cara\Templates [2006/07/28 13:09:47 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Cara\UserData [2009/12/24 04:21:28 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Default User\Application Data [2010/01/17 18:54:20 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Default User\Cookies [2011/10/13 03:08:18 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Default User\Desktop [2006/07/28 06:03:42 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Default User\Favorites [2006/07/28 13:17:34 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Default User\Local Settings [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Default User\My Documents [2006/07/28 13:17:33 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Default User\NetHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Default User\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\Default User\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\Default User\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\Default User\PrintHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Default User\Recent [2006/07/28 13:17:33 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Default User\SendTo [2006/07/28 13:17:21 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Default User\Start Menu [2006/07/28 06:03:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Default User\Templates [2006/07/28 13:09:47 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\delia\Application Data [2011/09/21 17:34:34 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\delia\Cookies [2011/09/21 17:52:53 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\delia\Desktop [2011/07/14 11:33:02 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\delia\Favorites [2010/04/24 00:12:30 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\delia\IETldCache [2010/04/24 00:12:28 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\delia\Local Settings [2011/10/12 20:44:53 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\delia\My Documents [2011/10/11 20:37:39 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\delia\NetHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\delia\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\delia\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\delia\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\delia\PrintHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\delia\PrivacIE [2010/04/24 00:13:32 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\delia\Recent [2011/05/15 19:29:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\delia\SendTo [2011/07/14 11:33:02 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\delia\Start Menu [2006/07/28 06:03:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\delia\Templates [2006/07/28 13:09:47 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\delia\UserData [2009/06/02 05:10:12 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\LocalService\Application Data [2011/10/08 23:54:02 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\LocalService\Cookies [2011/10/12 20:48:48 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\LocalService\Favorites [2011/10/09 00:11:25 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\LocalService\IETldCache [2010/08/12 06:48:44 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\LocalService\Local Settings [2011/10/12 20:44:53 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\LocalService\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\LocalService\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\LocalService\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\NetworkService\Application Data [2006/07/28 13:16:58 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\NetworkService\Cookies [2011/10/12 20:49:07 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\NetworkService\Favorites [2010/06/19 08:54:50 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\NetworkService\IETldCache [2010/04/06 04:01:14 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\NetworkService\Local Settings [2011/10/12 20:44:53 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\NetworkService\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\NetworkService\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\NetworkService\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\Patrick\Application Data [2011/09/20 13:04:03 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Patrick\Cookies [2011/09/29 18:00:50 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Patrick\Desktop [2011/10/11 20:37:44 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Patrick\Favorites [2010/04/18 17:16:28 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Patrick\IETldCache [2010/04/18 17:16:25 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Patrick\Local Settings [2011/10/12 20:44:53 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Patrick\My Documents [2011/10/11 20:23:22 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Patrick\NetHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Patrick\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\Patrick\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\Patrick\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\Patrick\PrintHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Patrick\PrivacIE [2010/04/18 17:17:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Patrick\Recent [2011/01/03 17:31:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Patrick\SendTo [2006/07/28 13:17:21 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Patrick\Start Menu [2006/07/28 06:03:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Patrick\Templates [2006/07/28 13:09:47 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Patrick\UserData [2009/12/31 22:01:12 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Paul\Application Data [2011/10/12 20:41:23 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Paul\Cookies [2011/10/10 19:05:32 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Paul\Desktop [2011/10/08 09:30:54 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Paul\Favorites [2011/10/08 08:31:19 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Paul\IECompatCache [2010/04/06 04:02:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Paul\IETldCache [2010/04/06 04:00:39 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Paul\Local Settings [2010/11/25 11:58:38 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul\My Documents [2011/10/12 20:06:10 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Paul\NetHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\Paul\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\Paul\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\Paul\pool.bin ()
O4 - Startup: C:\Documents and Settings\Paul\PrintHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul\PrivacIE [2010/04/06 04:02:20 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Paul\Recent [2011/10/08 09:33:10 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Paul\SendTo [2009/06/11 01:07:57 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Paul\Start Menu [2009/06/11 01:08:00 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Paul\Templates [2009/06/11 01:07:29 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul\UserData [2009/06/02 06:09:44 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\Application Data [2011/10/10 22:21:13 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\Cookies [2011/10/10 22:13:38 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\Desktop [2011/10/10 22:19:45 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\Favorites [2011/10/10 22:20:23 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\Local Settings [2011/10/10 22:13:38 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\My Documents [2011/10/10 22:23:21 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\Recent [2011/10/10 22:19:45 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\Start Menu [2011/10/10 22:19:45 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91\Templates [2011/10/10 22:13:38 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Application Data [2011/10/12 20:25:30 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Cookies [2011/10/11 20:14:20 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Desktop [2011/10/13 04:43:52 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Favorites [2011/10/11 20:46:53 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Local Settings [2011/10/11 20:21:27 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\My Documents [2011/10/12 07:46:49 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\NetHood [2011/10/12 07:46:49 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\PrintHood [2011/10/12 07:46:49 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Recent [2011/10/11 20:20:25 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\SendTo [2011/10/12 07:46:49 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Start Menu [2011/10/11 20:20:25 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Templates [2011/10/11 20:14:20 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\sheila\Application Data [2011/10/12 20:06:11 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\sheila\Cookies [2011/10/06 20:01:31 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\sheila\Desktop [2011/09/07 10:49:15 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\sheila\Favorites [2010/04/07 19:44:33 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\sheila\IETldCache [2010/04/07 19:44:06 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\sheila\Local Settings [2011/10/12 20:44:53 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\sheila\My Documents [2011/10/11 20:33:14 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\sheila\NetHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\sheila\NTUSER.DAT ()
O4 - Startup: C:\Documents and Settings\sheila\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\sheila\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\sheila\PrintHood [2006/07/28 06:03:42 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\sheila\PrivacIE [2010/04/07 19:47:19 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\sheila\Recent [2010/10/27 20:30:34 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\sheila\SendTo [2006/07/28 13:17:21 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\sheila\Start Menu [2006/07/28 06:03:42 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\sheila\Templates [2006/07/28 13:09:47 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\sheila\UserData [2009/06/02 06:04:05 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\TEMP\Application Data [2011/10/07 20:37:19 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\TEMP\Desktop [2011/06/25 21:45:23 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\TEMP\Favorites [2011/10/07 20:17:37 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\TEMP\Local Settings [2011/06/25 21:45:13 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\TEMP\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\TEMP\ntuser.dat ()
O4 - Startup: C:\Documents and Settings\TEMP\ntuser.ini ()
O4 - Startup: C:\Documents and Settings\TEMP\Recent [2011/06/25 21:45:23 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Documents and Settings\TEMP\Start Menu [2011/06/25 21:45:23 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\TEMP.WXP-G5N1Q91\Cookies [2011/10/10 20:34:52 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\TEMP.WXP-G5N1Q91\Favorites [2011/10/10 20:33:30 | 000,000,000 | R--D | M]
O4 - Startup: C:\Documents and Settings\TEMP.WXP-G5N1Q91\Local Settings [2011/10/10 20:35:23 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\TEMP.WXP-G5N1Q91.000\Application Data [2011/10/10 23:04:27 | 000,000,000 | ---D | M]
O4 - Startup: C:\Documents and Settings\TEMP.WXP-G5N1Q91.000\Cookies [2011/10/10 23:04:31 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Documents and Settings\TEMP.WXP-G5N1Q91.000\Local Settings [2011/10/10 23:04:08 | 000,000,000 | ---D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2835520393-2346535299-1512314548-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2835520393-2346535299-1512314548-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2835520393-2346535299-1512314548-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7}
http://www.photodex.com/pxplay.cab (Photodex Presenter AX control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{51E9D222-B091-46D6-8673-80AC4F763B02}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/06/04 21:25:21 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/10/12 20:49:07 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\NetworkService\Cookies
[2011/10/12 20:48:48 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\LocalService\Cookies
[2011/10/12 20:44:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/10/12 19:27:41 | 000,138,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\afd.sys
[2011/10/12 07:46:49 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\SendTo
[2011/10/12 07:46:49 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\PrintHood
[2011/10/12 07:46:49 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\NetHood
[2011/10/11 21:58:30 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\My Documents
[2011/10/11 21:14:09 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/10/11 21:14:09 | 000,000,000 | ---D | C] -- \Config.Msi
[2011/10/11 21:08:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Local Settings\Application Data\Apple Computer
[2011/10/11 21:02:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Local Settings\Application Data\Adobe
[2011/10/11 20:47:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Local Settings\Application Data\HP
[2011/10/11 20:47:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Local Settings\Application Data\AskToolbar
[2011/10/11 20:47:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Local Settings\Application Data\Google
[2011/10/11 20:46:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Application Data
[2011/10/11 20:20:25 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Recent
[2011/10/11 20:20:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Favorites
[2011/10/11 20:20:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Start Menu
[2011/10/11 20:20:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Desktop
[2011/10/11 20:14:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Templates
[2011/10/11 20:14:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Cookies
[2011/10/11 20:14:19 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Local Settings
[2011/10/11 20:14:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Local Settings\Application Data\Microsoft
[2011/10/10 23:04:48 | 000,000,000 | ---D | C] -- C:\AVG2012
[2011/10/10 23:04:48 | 000,000,000 | ---D | C] -- \AVG2012
[2011/10/10 20:33:09 | 000,000,000 | ---D | C] -- C:\ArcSoft
[2011/10/10 20:33:09 | 000,000,000 | ---D | C] -- \ArcSoft
[2011/10/09 00:11:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\LocalService\Favorites
[2011/10/08 09:31:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/08 09:31:22 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/10/08 09:31:22 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/10/08 08:37:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/09/26 15:43:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Rosetta Stone
[2011/09/26 15:42:54 | 000,000,000 | ---D | C] -- C:\Program Files\Rosetta Stone
[2011/09/26 15:42:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Rosetta Stone
[2011/09/26 15:36:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2011/09/26 15:36:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2011/09/26 15:31:58 | 000,000,000 | ---D | C] -- C:\Program Files\Elaborate Bytes
[2011/09/26 15:31:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Elaborate Bytes
[2011/09/17 06:46:37 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes Agent
[2011/09/16 21:25:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search
[2011/09/16 21:25:11 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search
[2011/09/16 20:26:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\doubleTwist
[2011/09/16 20:26:47 | 000,060,273 | ---- | C] (Open Source Software community project) -- C:\WINDOWS\System32\pthreadGC2.dll
[2011/09/16 20:26:46 | 000,000,000 | ---D | C] -- C:\Program Files\ffdshow
[2010/11/22 20:31:28 | 003,137,976 | ---- | C] (McAfee, Inc.) -- C:\Program Files\DMSetup.exe
[2010/11/08 20:01:32 | 266,313,336 | ---- | C] (Lexia Learning Systems, Inc.) -- C:\Program Files\LexiaReading_7.0.1_us.exe
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/10/13 04:45:00 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{52508262-3DA4-4112-9E03-487C0ACF1BFB}.job
[2011/10/13 04:26:17 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/10/13 04:26:07 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/13 04:14:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/13 04:01:00 | 000,000,232 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/10/13 03:24:56 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/10/13 03:24:52 | 000,212,080 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/13 03:24:51 | 3219,271,680 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/13 03:08:17 | 000,432,778 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/10/13 03:08:17 | 000,067,734 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/10/13 03:01:59 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/10/12 20:42:13 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/10/12 15:28:25 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/10/11 21:25:44 | 000,002,393 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2011/10/11 20:59:14 | 000,003,584 | ---- | M] () -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/10 23:04:04 | 000,248,739 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2011/10/10 22:32:12 | 000,035,262 | ---- | M] () -- C:\WINDOWS\Administrator.acl
[2011/10/08 09:31:25 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/07 11:46:06 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/05 18:41:34 | 000,000,028 | ---- | M] () -- C:\WINDOWS\MotionDVSTUDIO.INI
[2011/10/03 04:35:11 | 005,971,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2011/09/26 15:32:21 | 000,000,903 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Virtual CloneDrive.lnk
[2011/09/26 11:41:20 | 000,611,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\uiautomationcore.dll
[2011/09/26 11:41:20 | 000,220,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oleacc.dll
[2011/09/26 11:41:14 | 000,020,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\oleaccrc.dll
[2011/09/26 11:41:14 | 000,020,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oleaccrc.dll
[2011/09/18 22:49:03 | 000,000,063 | ---- | M] () -- C:\1.html
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/10/12 20:48:35 | 3219,271,680 | -HS- | C] () -- C:\hiberfil.sys
[2011/10/12 20:48:35 | 3219,271,680 | -HS- | C] () -- \hiberfil.sys
[2011/10/11 21:30:00 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/10/11 20:59:14 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Paul.WXP-G5N1Q91.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/10 22:32:12 | 000,035,262 | ---- | C] () -- C:\WINDOWS\Administrator.acl
[2011/10/08 09:31:25 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/26 15:32:21 | 000,000,903 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Virtual CloneDrive.lnk
[2011/09/18 20:04:32 | 000,000,063 | ---- | C] () -- C:\1.html
[2011/09/18 20:04:32 | 000,000,063 | ---- | C] () -- \1.html
[2011/09/16 20:26:48 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2011/04/14 21:03:27 | 000,000,056 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsidmv.dat
[2010/09/13 21:37:13 | 000,000,992 | ---- | C] () -- C:\WINDOWS\hpomdl40.dat.temp
[2010/09/13 20:11:29 | 000,640,704 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/28 18:25:45 | 000,201,755 | ---- | C] () -- C:\WINDOWS\hpoins40.dat
[2010/08/28 18:25:45 | 000,000,992 | ---- | C] () -- C:\WINDOWS\hpomdl40.dat
[2010/07/05 10:40:14 | 000,053,364 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/06/26 16:15:08 | 000,000,281 | ---- | C] () -- \Boot.bak
[2010/06/26 16:15:02 | 000,260,272 | RHS- | C] () -- \cmldr
[2010/06/26 16:07:41 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/06/26 16:07:23 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/06/26 16:07:23 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/06/26 16:07:23 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/06/26 16:07:23 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/06/19 16:41:23 | 000,983,040 | ---- | C] () -- \ffastunT.ffl
[2010/06/17 12:48:27 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2010/03/08 05:18:24 | 000,000,039 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2010/01/16 23:24:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2009/09/18 18:19:42 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
[2009/08/05 19:50:00 | 001,597,690 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2009/06/29 21:32:29 | 000,008,074 | ---- | C] () -- C:\WINDOWS\extend.dat
[2009/06/26 04:30:03 | 008,892,928 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\atscie.msi
[2009/06/26 04:03:58 | 000,015,312 | R--- | C] () -- C:\WINDOWS\System32\RaCoInst.dat
[2009/06/25 06:13:49 | 000,001,048 | ---- | C] () -- \net_save.dna
[2009/06/11 01:12:25 | 004,468,736 | -H-- | C] () -- \ffastun0.ffx
[2009/06/11 01:12:25 | 000,229,376 | -H-- | C] () -- \ffastun.ffo
[2009/06/11 01:12:25 | 000,004,890 | -H-- | C] () -- \ffastun.ffa
[2009/06/11 01:10:20 | 000,983,040 | -H-- | C] () -- \ffastun.ffl
[2009/06/11 01:07:53 | 000,000,611 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/06/11 01:07:53 | 000,000,022 | ---- | C] () -- C:\WINDOWS\exchng.ini
[2009/06/07 06:05:27 | 000,000,028 | ---- | C] () -- C:\WINDOWS\MotionDVSTUDIO.INI
[2009/06/07 05:55:59 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Title.INI
[2009/05/30 08:09:21 | 000,905,290 | R--- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2009/05/30 07:57:08 | 000,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2009/05/30 07:57:08 | 000,000,034 | ---- | C] () -- C:\WINDOWS\System32\BD5250DN.DAT
[2009/05/30 02:05:10 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/05/30 01:55:14 | 000,114,630 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2007/11/07 08:12:28 | 000,232,960 | ---- | C] () -- \VC_RED.MSI
[2007/11/07 08:09:22 | 001,442,522 | ---- | C] () -- \VC_RED.cab
[2007/11/07 08:03:18 | 000,097,296 | ---- | C] () -- \install.res.1036.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | C] () -- \install.res.3082.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | C] () -- \install.res.1031.dll
[2007/11/07 08:03:18 | 000,095,248 | ---- | C] () -- \install.res.1040.dll
[2007/11/07 08:03:18 | 000,091,152 | ---- | C] () -- \install.res.1033.dll
[2007/11/07 08:03:18 | 000,081,424 | ---- | C] () -- \install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | ---- | C] () -- \install.res.1042.dll
[2007/11/07 08:03:18 | 000,076,304 | ---- | C] () -- \install.res.1028.dll
[2007/11/07 08:03:18 | 000,075,792 | ---- | C] () -- \install.res.2052.dll
[2007/11/07 08:00:40 | 000,005,686 | ---- | C] () -- \vcredist.bmp
[2007/11/07 08:00:40 | 000,001,110 | ---- | C] () -- \globdata.ini
[2007/11/07 08:00:40 | 000,000,843 | ---- | C] () -- \install.ini
[2006/09/24 19:55:20 | 000,004,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\WinIo.sys
[2006/09/24 19:53:02 | 000,000,798 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/07/28 13:34:06 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\e1000msg.dll
[2006/07/28 13:16:22 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/07/28 13:13:37 | 000,000,050 | ---- | C] () -- \AUTOEXEC.BAT
[2006/07/28 13:13:37 | 000,000,000 | RHS- | C] () -- \MSDOS.SYS
[2006/07/28 13:13:37 | 000,000,000 | RHS- | C] () -- \IO.SYS
[2006/07/28 13:13:37 | 000,000,000 | ---- | C] () -- \CONFIG.SYS
[2006/07/28 13:10:30 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/07/28 06:04:06 | 000,004,346 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/07/28 06:03:01 | 000,212,080 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/07/28 06:02:35 | 000,000,327 | RHS- | C] () -- \boot.ini
[2004/08/12 09:36:06 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/12 09:36:06 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/12 09:28:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/12 09:26:08 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/12 09:26:07 | 000,432,778 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/12 09:26:06 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/12 09:26:05 | 000,067,734 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/12 09:25:13 | 000,250,048 | RHS- | C] () -- \ntldr
[2004/08/12 09:25:07 | 000,047,564 | RHS- | C] () -- \NTDETECT.COM
[2004/08/12 09:24:57 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/12 09:22:08 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/12 09:22:01 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/12 09:18:55 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/12 09:18:32 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[1997/07/11 08:00:00 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\WRKGADM.EXE
[1997/07/11 08:00:00 | 000,031,232 | ---- | C] () -- C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 08:00:00 | 000,025,600 | ---- | C] () -- C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 08:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 08:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 08:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
< End of report >